Secure Application Registration via Jump Server and Manual Activation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing registration methods for communication applications lack sufficient security, making them vulnerable to unauthorized tampering and cyber-attacks, especially for frequently used enterprise applications.

Innovation Solution

A secure registration method involving a two-factor authentication process for administrators to access an application server, generating and manually transferring an activation code to user devices, ensuring only authorized users can activate downloaded applications, with logging of all administrator activities for accountability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional registration methods are used for communication applications, then the registration process is simple and quick, but the security level is insufficient and vulnerable to unauthorized tampering

Engineering Contradiction:
Improvesecurity levelVSAvoidregistration process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A jump server is introduced as an intermediary between the administrator and the application server. The jump server establishes a secure channel and enables the administrator to remotely access the application server without direct exposure, thereby enhancing security while managing the registration process

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The registration process is segmented into distinct phases: administrator authentication via two-factor authentication, secure access through jump server, activation code generation on application server, and manual code transfer to user device. This segmentation allows each step to be secured independently while maintaining overall process simplicity

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the application server is made accessible to users for direct downloads, then the ease of application distribution is improved, but the security risk increases due to potential unauthorized access

Engineering Contradiction:
Improveapplication distribution easeVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The jump server acts as an intermediary that allows the administrator to access the application server securely without exposing the application server directly to user devices. This maintains secure control while enabling application distribution

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Applications are pre-downloaded to user devices in an inactive state before activation. The activation code mechanism ensures that while the application is present on the device, it cannot be executed until properly activated through the secure registration process

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11416586B2Secure communication application registration process
Publication Date: 2022.08.16 SAUDI ARABIAN OIL CO
  • US11416586B2 patent drawing
  • US11416586B2 patent drawing

AI summary

A method for registering and activating an application downloaded to a user device, the application being provided from an application server of an enterprise. The method comprises generating an activation code for activating downloaded applications which are pending activation, storing the generated activation code on the application server, the first server not being accessible to the user and only being accessible to a jump server, enabling an administrator to access the jump server using two-factor authentication, accessing the first sever via the jump server, responding to a command by the administrator, provided through a remote connection between the jump server and the application server, by electronically communicating to the administrator activation codes associated with applications pending activation, and completing registration and activation of the application by providing a manually transferred code into the user device. The activation code is manually transferred from the administrator to the user.