Bootstrap Server Device Management Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device management bootstrap methods for mobile communication devices are inadequate for open market devices, as they require prior knowledge of operator or service-specific settings, and may pose security risks, especially in scenarios where the device's future operator or service is unknown.
Innovation Solution
A method where a mobile communication device sends a request to a bootstrap server with selection information such as mobile country and network codes, or service configurations, to retrieve and apply the correct bootstrap data, using a secure channel like HTTPS, allowing flexible bootstrap procedures across different operators and services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a customized bootstrap is used to provision DM settings at manufacture, then the device management configuration is precise and reliable for specific operators, but the device cannot be used with different operators or services (lack of adaptability)
Solution Approach 1:
The patent applies preliminary action by pre-configuring multiple operator-specific and service-specific bootstrap packages in the device's memory before deployment. When the device is manufactured, all necessary DM settings for various operators are already prepared and stored. The device then selects the appropriate pre-configured package based on the detected operator ID, eliminating the need for manual configuration or a priori knowledge of the operator. This resolves the contradiction by maintaining reliability through pre-validated settings while achieving adaptability through multiple pre-prepared options.
2Ease of operation
If bootstrap settings are provisioned from the network (OTA bootstrap), then the device can be configured remotely and updated, but security risks arise as the device cannot verify the trusted source of bootstrap packages
Solution Approach 1:
The patent introduces an intermediary verification mechanism where the selected bootstrap package is validated against a trusted certificate authority (CA) stored in the device. The DM server acts as an intermediary that provides signed bootstrap packages, and the device verifies these signatures using the pre-stored CA certificate. This intermediary verification layer resolves the contradiction by enabling remote configuration delivery while ensuring the authenticity and trustworthiness of the bootstrap source through cryptographic verification.
3Device complexity
If a single bootstrap server is used for all devices, then the system architecture is simple, but it cannot provide operator-specific or service-specific bootstrap data (lack of adaptability)
Solution Approach 1:
The patent applies segmentation by dividing the bootstrap data into multiple operator-specific packages, each containing DM settings tailored to specific operators and services. The single bootstrap server stores and manages these segmented packages, and the device selects the appropriate segment based on the detected operator ID. This segmentation approach resolves the contradiction by maintaining simple server architecture while providing adaptability through organized, operator-specific data segments.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A mobile communication device (100) sends a request (402) to a bootstrap server (310). The request (402) indicates selection information for selecting bootstrap data at the bootstrap server (310). The bootstrap server (310) selects the bootstrap data and sends the selected bootstrap data (404) to the mobile communication device (100). The mobile communication device (100) receives the selected bootstrap data (404) and, depending on the received bootstrap data (404), configures settings for management of the mobile communication device by a device management server (210).