Delegation Process for Mobile Device Management Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device management systems face challenges in efficiently managing devices as they move across different geographic areas covered by different service providers, leading to increased communication overhead and lack of seamless service management.

Innovation Solution

The method involves delegating device management control between device management servers using a delegation process, which includes signaling exchanges and the generation of temporary delegation keys to ensure secure transfer of management responsibilities, allowing for full or partial control to be temporarily or permanently transferred between servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If device management control is centralized on a single server, then service management is simplified, but communication overhead increases and service continuity deteriorates when devices move across geographic areas

Engineering Contradiction:
Improveservice management complexityVSAvoidservice continuity time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The patent segments device management control by introducing multiple management servers distributed across different geographic areas. Each server manages devices within its specific region, dividing the centralized management function into regional segments. This segmentation reduces communication overhead for roaming devices and maintains service continuity without requiring a single centralized server to handle all communications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a delegation mechanism where a primary management server acts as an intermediary to transfer control to a secondary management server when a device moves to a different geographic area. The delegation process includes generating temporary delegation keys and updating access control lists, allowing seamless handover of management responsibilities while maintaining security and reducing direct communication overhead between roaming devices and distant servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of energy

If device management control is transferred between servers, then communication overhead is reduced for roaming devices, but security risks increase due to potential hijacking

Engineering Contradiction:
Improvecommunication energy overheadVSAvoidmanagement control security
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent implements preliminary security actions before control transfer by generating temporary delegation keys and updating access control lists in advance. The primary management server prepares the delegation credentials and securely transmits them to the device before the actual control transfer occurs. This preliminary preparation ensures that security measures are in place before the handover, preventing potential hijacking during the transition period.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes security parameters during the delegation process by using temporary delegation keys with limited validity periods and specific scope restrictions. The access control lists are updated with time-bound and scope-bound credentials, transforming the security model from static long-term authentication to dynamic temporary authentication. This parameter change reduces the window of opportunity for security breaches while enabling seamless control transfer.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If temporary delegation keys are generated for control transfer, then security is improved, but device complexity increases

Engineering Contradiction:
Improvemanagement control securityVSAvoiddelegation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal delegation framework that handles multiple scenarios (full control transfer, partial control transfer, temporary delegation, permanent delegation) through a single standardized process. The same delegation key generation mechanism and access control list update procedure are used across different delegation types, reducing the need for separate complex protocols for each scenario. This universal approach simplifies the overall device complexity while maintaining strong security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2553873B1Methods and apparatus to transfer management control of a client between servers
Publication Date: 2018.10.31 BLACKBERRY LTD
  • EP2553873B1 patent drawingFigure 1
  • EP2553873B1 patent drawingFigure 2~3
  • EP2553873B1 patent drawingFigure 4

AI summary

An example method to be performed by an Open Mobile Alliance (OMA) Device Management (DM) server (104a) involves participating in mutual authentication (406) with a second OMA DM server (104b) and sending (408) a notification to the second OMA DM server (104b) for notifying the second OMA DM server (104b) to proceed with a delegation process. In addition, information (424) is sent to a DM client (106) for modifying an access control list (ACL).