Secure Device Security Information Loading via Network Quarantine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for loading security information onto devices after manufacture are prone to security risks and increased complexity, especially when done over public networks, as they rely on third-party intervention and lack initial security measures to protect the download process.

Innovation Solution

A method involving a quarantine state in the mobile network to secure the download of security information using SMS or USSD messages, where the device is initially locked to a specific access point, and only after successful download, it can access the endpoint server, ensuring secure communication without pre-manufactured certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security information is loaded onto the device after shipping to the customer, then the security information can be tailored to the customer's needs, activities, and local laws, but there is a significant security risk since there is no existing security material in the device to protect the transport and downloading

Engineering Contradiction:
Improvesecurity information customizationVSAvoiddownload security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The device is pre-configured with a quarantine state and pre-authentication mechanisms before security information is downloaded. The authentication message is prepared and sent in advance, triggering the registration process that enables secure downloading. This preliminary setup ensures that even though no security information is present initially, the device has the necessary infrastructure in place to securely receive it.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using SMS or USSD messages as a trusted channel between the device and the network. This intermediary communication method provides a secure pathway for downloading security information without requiring pre-existing security material on the device. The intermediary acts as a bridge that establishes trust before the actual security information transfer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the device downloads security information over a public network, then connectivity and flexibility are improved, but the security risk increases significantly

Engineering Contradiction:
Improvedownload accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The network access is segmented into two distinct states: quarantine state and operation state. In the quarantine state, the device can only access specific authentication services (SMS/USSD) but is restricted from accessing the endpoint server or general public network resources. After successful authentication and security information download, the device transitions to the operation state where full network access is granted. This segmentation allows public network accessibility while maintaining security during the vulnerable download phase.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies preliminary anti-action by implementing network-level restrictions that prevent the device from accessing unauthorized resources before security information is downloaded. The quarantine state actively blocks access to the endpoint server and other protected resources, countering potential unauthorized access attempts before they can occur. This preemptive restriction neutralizes the security risks inherent in public network downloading.

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of manufacture

If a third party is involved in loading security material onto the device, then the manufacturing process is simplified, but the risk of improper treatment and security material leak or modification increases

Engineering Contradiction:
Improvesecurity information loadingVSAvoidsecurity material compromise
Core Design Contradiction:
Ease of manufactureVSObject-generated harmful factors

Solution Approach 1:

The device performs self-service by autonomously authenticating itself to the network and downloading its own security information without requiring third-party intervention. The device sends its own authentication message, receives the security information directly from the network, and completes the provisioning process independently. This eliminates the need for manufacturers or third parties to handle security material, thereby removing the risk of improper treatment, leaks, or modifications during the loading process.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10389748B2Secure loading security information for encrypting communications between a device and an end point server
Publication Date: 2019.08.20 ESEYE
  • US10389748B2 patent drawing
  • US10389748B2 patent drawing
  • US10389748B2 patent drawing

AI summary

A method of distributing security information to a device quarantines the device and then, in the quarantine state, downloads security information using a method protected by the inherent security in the mobile network such as USSD or SMS.