Certificate-Based Access Control for Mobile Device Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control mechanisms in wireless communication devices, such as those using Access Control Lists (ACLs), are complex and not suitable for multiple management authorities, especially on platforms like Android where they lack support for operations like retrieving and storing connectivity settings, leading to increased complexity and limitations in device management.

Innovation Solution

Implementing certificate-based access control at the management object (MO) level, where mobile devices are provisioned with certificates bound to specific MOs, allowing access based on valid certificates used in secure communication sessions, reducing complexity and information exchange compared to node-level ACLs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If node-level Access Control Lists (ACLs) are used for access control, then flexibility in controlling individual node access is improved, but device management complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoiddevice management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments access control from the node level to the management object level. Instead of managing ACLs for each individual node, the system creates access control policies at the management object level that automatically apply to all nodes within that object. This segmentation reduces the number of access control decisions from potentially hundreds of nodes to a manageable number of management objects, directly reducing device management complexity while preserving access control flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces management object-level policies as an intermediary layer between the server and individual nodes. These policies act as mediators that automatically enforce access control decisions across multiple nodes without requiring the server to evaluate ACLs for each node individually. This intermediary mechanism simplifies the access control process by consolidating authorization logic at the management object level.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If ACL mechanisms are implemented on all platforms, then access control capability is improved, but platform compatibility and API support requirements increase complexity

Engineering Contradiction:
Improveaccess control capabilityVSAvoidplatform support complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the management object-level access control policy mechanism universal across different platforms. By implementing access control at the management object level rather than relying on platform-specific node-level ACL implementations, the system achieves consistent access control capability across Android, iOS, and other platforms without requiring platform-specific API support for ACLs. This universal approach eliminates the need for platform-specific access control implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If certificates are bound to management objects instead of nodes, then access control information exchange is reduced, but the binding mechanism complexity increases

Engineering Contradiction:
Improveaccess control information exchangeVSAvoidcertificate binding mechanism
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges the certificate binding mechanism with the existing management object structure. Instead of creating a separate complex binding system, the patent integrates access control policies directly into management objects, allowing certificates to be bound to management objects through existing OMA DM provisioning mechanisms. This merging approach reduces the need for separate binding infrastructure while maintaining secure certificate-based access control.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUSRE47020E1Certificate based access control in open mobile alliance device management
Publication Date: 2018.08.28 SONY GROUP CORP
  • USRE47020E1 patent drawing
  • USRE47020E1 patent drawing
  • USRE47020E1 patent drawing

AI summary

A wireless communication device provides a method of certificate-based access control. Particularly, the device establishes a secure communications session with a device management server. Rather than use access control lists to control access to the functions and services on the device, however, the device uses the certificate that was employed to establish the secure session to control access.