Host Server Mediates Mobile Digital Certificate Acquisition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for obtaining digital certificates on mobile communication devices are manual and cumbersome, requiring significant processing power and involving weak control and distribution from the administrator's perspective in communication networks.

Innovation Solution

A method where the mobile device establishes a communication session with a host server, which requests and obtains a digital certificate from a certificate authority on behalf of the device, reducing processing power and enhancing certificate management efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the mobile device manually obtains a digital certificate, then the device has full control over the certificate acquisition process, but the process becomes cumbersome and requires significant processing power

Engineering Contradiction:
Improvecertificate acquisition processVSAvoidprocessing power consumption
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The patent introduces a server as an intermediary between the mobile device and the certificate authority. The server handles the complex certificate enrollment process, including generating certificate signing requests and receiving signed certificates, while the mobile device only needs to send simple requests and receive responses. This mediator approach eliminates the need for the mobile device to perform complex cryptographic operations, significantly reducing processing power consumption and simplifying the user operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the mobile device manually manages certificate distribution, then the device has autonomy, but certificate control and distribution efficiency deteriorates

Engineering Contradiction:
Improvecertificate distribution efficiencyVSAvoidcertificate management control
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The server acts as a centralized intermediary that manages certificate distribution to multiple mobile devices. It receives signed certificates from the certificate authority and automatically distributes them to the appropriate devices. This centralized approach improves distribution efficiency by eliminating manual configuration on each device while maintaining administrative control through the server's ability to manage and track certificate deployment across the organization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The mobile device sends a simple enrollment request to the server, which then automatically completes the entire certificate acquisition process without requiring user intervention. The device receives the signed certificate automatically and configures itself. This self-service approach streamlines the process from a complex manual procedure to an automated one-step user action, significantly improving productivity.

Inventive Principle:
Principle #25Self-service

3Reliability

If the mobile device performs complete certificate enrollment procedures, then the device ensures security, but the acquisition time and complexity increase

Engineering Contradiction:
Improvecertificate securityVSAvoidcertificate acquisition time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The server as an intermediary maintains security by implementing proper certificate enrollment procedures on behalf of the mobile device. It generates secure certificate signing requests using the device's public key, receives the signed certificates from the certificate authority through secure channels, and distributes them safely. This approach preserves the security requirements of complete enrollment procedures while reducing the time the user experiences, as the complex security-critical operations are performed automatically in the background by the server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2096829B1Methods and apparatus for use in obtaining a digital certificate for a mobile communication device
Publication Date: 2010.12.08 BLACKBERRY LTD
  • EP2096829B1 patent drawingFigure 1
  • EP2096829B1 patent drawingFigure 2
  • EP2096829B1 patent drawingFigure 3

AI summary

In one illustrative scenario, a mobile device receives configuration information which includes information for use in constructing a request message for obtaining a digital certificate from a certificate authority (CA). After receipt of the configuration information, the mobile device constructs the request message for the digital certificate and causes it to be sent to a host server of a communication network. In response, the host server requests and obtains the digital certificate from the CA on behalf of the mobile device, and thereafter "pushes" the received digital certificate to the mobile device. The mobile device receives the digital certificate and stores it for use in subsequent communications. The host server may be part of a local area network (LAN) which includes a wireless LAN (WLAN) adapted to authenticate the mobile device based on the digital certificate, so that the mobile device may obtain access to the WLAN.