Host Server Mediates Mobile Digital Certificate Acquisition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods for obtaining digital certificates on mobile communication devices are manual and cumbersome, requiring significant processing power and involving weak control and distribution from the administrator's perspective in communication networks.
Innovation Solution
A method where the mobile device establishes a communication session with a host server, which requests and obtains a digital certificate from a certificate authority on behalf of the device, reducing processing power and enhancing certificate management efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the mobile device manually obtains a digital certificate, then the device has full control over the certificate acquisition process, but the process becomes cumbersome and requires significant processing power
Solution Approach 1:
The patent introduces a server as an intermediary between the mobile device and the certificate authority. The server handles the complex certificate enrollment process, including generating certificate signing requests and receiving signed certificates, while the mobile device only needs to send simple requests and receive responses. This mediator approach eliminates the need for the mobile device to perform complex cryptographic operations, significantly reducing processing power consumption and simplifying the user operation.
2Productivity
If the mobile device manually manages certificate distribution, then the device has autonomy, but certificate control and distribution efficiency deteriorates
Solution Approach 1:
The server acts as a centralized intermediary that manages certificate distribution to multiple mobile devices. It receives signed certificates from the certificate authority and automatically distributes them to the appropriate devices. This centralized approach improves distribution efficiency by eliminating manual configuration on each device while maintaining administrative control through the server's ability to manage and track certificate deployment across the organization.
Solution Approach 2:
The mobile device sends a simple enrollment request to the server, which then automatically completes the entire certificate acquisition process without requiring user intervention. The device receives the signed certificate automatically and configures itself. This self-service approach streamlines the process from a complex manual procedure to an automated one-step user action, significantly improving productivity.
3Reliability
If the mobile device performs complete certificate enrollment procedures, then the device ensures security, but the acquisition time and complexity increase
Solution Approach 1:
The server as an intermediary maintains security by implementing proper certificate enrollment procedures on behalf of the mobile device. It generates secure certificate signing requests using the device's public key, receives the signed certificates from the certificate authority through secure channels, and distributes them safely. This approach preserves the security requirements of complete enrollment procedures while reducing the time the user experiences, as the complex security-critical operations are performed automatically in the background by the server.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In one illustrative scenario, a mobile device receives configuration information which includes information for use in constructing a request message for obtaining a digital certificate from a certificate authority (CA). After receipt of the configuration information, the mobile device constructs the request message for the digital certificate and causes it to be sent to a host server of a communication network. In response, the host server requests and obtains the digital certificate from the CA on behalf of the mobile device, and thereafter "pushes" the received digital certificate to the mobile device. The mobile device receives the digital certificate and stores it for use in subsequent communications. The host server may be part of a local area network (LAN) which includes a wireless LAN (WLAN) adapted to authenticate the mobile device based on the digital certificate, so that the mobile device may obtain access to the WLAN.