Device Authenticity via Certificate Authority Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers of mobile communication services lack a means to authenticate the legitimacy of mobile communication devices accessing their networks, which can lead to security breaches and loss of trust due to outsourcing of device manufacturing, where unauthorized components may be installed without knowledge of the provider or end user.

Innovation Solution

A digital certificate with a digital signature of an authority is installed on each mobile communication device during manufacturing, containing device-specific data, allowing verification of the device's authenticity rather than just the user or exchangeable components, and can be transmitted to service providers upon request for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If device manufacturing is outsourced to third parties, then manufacturing productivity increases, but device security and authenticity control deteriorate

Engineering Contradiction:
Improvemanufacturing productivityVSAvoiddevice security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by embedding authentication credentials (such as secure elements, cryptographic keys, or authenticity verification mechanisms) into the device during the manufacturing process itself, before the device is deployed. This ensures that security features are pre-configured and cannot be added later, resolving the contradiction by maintaining security controls even when manufacturing is outsourced.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that acts as a mediator between the service provider and the manufactured device. This intermediary (such as a certificate authority or verification server) validates the device's authenticity credentials, allowing the service provider to maintain security control without directly managing the manufacturing process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication focuses on user credentials, then ease of operation is maintained, but device-level security control is insufficient

Engineering Contradiction:
Improveauthentication convenienceVSAvoiddevice authenticity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges user-level authentication with device-level authentication into a unified system. The device contains embedded credentials that work alongside user credentials, creating a multi-layered authentication approach. This resolves the contradiction by maintaining user convenience while adding device-level security verification transparently in the background.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9112703B2Use of certificate authority to control a device's access to services
Publication Date: 2015.08.18 MALIKIE INNOVATIONS LTD
  • US9112703B2 patent drawing
  • US9112703B2 patent drawing
  • US9112703B2 patent drawing

AI summary

A mobile communications device having a digital certificate authenticating the device itself is proposed. A server for authenticating the device and a method of authenticating the device are also disclosed. The device comprises a transmitter, a processor, a memory and a computer readable medium. The memory includes a certificate certifying the authenticity of the mobile communications device, the certificate comprising device-specific data and a digital signature signed by an authority having control of the authenticity of the mobile communications device. The computer readable medium has computer readable instructions stored thereon that when executed configure the processor to instruct the transmitter to transmit a copy of the certificate to a service provider in response to a request to authenticate the mobile communications device with the service provider.