Delegation Process for Mobile Device Management Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile device management systems face challenges in efficiently managing devices as they move across different geographic areas covered by different service providers, leading to increased communication overhead and lack of seamless service management.
Innovation Solution
The method involves delegating device management control between device management servers using a delegation process, which includes signaling exchanges and the generation of temporary delegation keys to ensure secure transfer of management responsibilities, allowing for full or partial control to be temporarily or permanently transferred between servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If device management control is centralized on a single server, then service management is simplified, but communication overhead increases and service continuity deteriorates when devices move across geographic areas
Solution Approach 1:
The patent segments device management control by introducing multiple management servers distributed across different geographic areas. Each server manages devices within its specific region, dividing the centralized management function into regional segments. This segmentation reduces communication overhead for roaming devices and maintains service continuity without requiring a single centralized server to handle all communications.
Solution Approach 2:
The patent introduces a delegation mechanism where a primary management server acts as an intermediary to transfer control to a secondary management server when a device moves to a different geographic area. The delegation process includes generating temporary delegation keys and updating access control lists, allowing seamless handover of management responsibilities while maintaining security and reducing direct communication overhead between roaming devices and distant servers.
2Loss of energy
If device management control is transferred between servers, then communication overhead is reduced for roaming devices, but security risks increase due to potential hijacking
Solution Approach 1:
The patent implements preliminary security actions before control transfer by generating temporary delegation keys and updating access control lists in advance. The primary management server prepares the delegation credentials and securely transmits them to the device before the actual control transfer occurs. This preliminary preparation ensures that security measures are in place before the handover, preventing potential hijacking during the transition period.
Solution Approach 2:
The patent changes security parameters during the delegation process by using temporary delegation keys with limited validity periods and specific scope restrictions. The access control lists are updated with time-bound and scope-bound credentials, transforming the security model from static long-term authentication to dynamic temporary authentication. This parameter change reduces the window of opportunity for security breaches while enabling seamless control transfer.
3Reliability
If temporary delegation keys are generated for control transfer, then security is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal delegation framework that handles multiple scenarios (full control transfer, partial control transfer, temporary delegation, permanent delegation) through a single standardized process. The same delegation key generation mechanism and access control list update procedure are used across different delegation types, reducing the need for separate complex protocols for each scenario. This universal approach simplifies the overall device complexity while maintaining strong security.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
An example method to be performed by an Open Mobile Alliance (OMA) Device Management (DM) server (104a) involves participating in mutual authentication (406) with a second OMA DM server (104b) and sending (408) a notification to the second OMA DM server (104b) for notifying the second OMA DM server (104b) to proceed with a delegation process. In addition, information (424) is sent to a DM client (106) for modifying an access control list (ACL).