Mobile Secure Agent Certificate Authority Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional mobile wireless devices face challenges in securely collecting and transmitting private data while protecting users from unauthorized data leaks and verifying the authenticity of data collection profiles.

Innovation Solution

A system comprising mobile secure agents, a unified mobile security certificate authority, and encrypted data packages ensures secure transmission only to authorized recipients by using certificates and SSL tunnels, with authentication and revocation mechanisms to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data collection profiles are transmitted and executed by agents in conventional mobile devices, then data collection functionality is improved, but security against unauthorized data leaks deteriorates

Engineering Contradiction:
Improvedata collection functionalityVSAvoidsecurity against unauthorized data leaks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by signing data collection profiles with a certificate authority before they are installed and executed on mobile devices. This advance authentication ensures that only authorized profiles can be executed, preventing unauthorized data collection before it can occur. The profiles are validated and authenticated in advance, so when they are executed by agents, the security risk is already mitigated.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A certificate authority acts as an intermediary between profile producers and mobile devices. The certificate authority signs and authenticates data collection profiles, creating a trusted intermediary layer that verifies the provenance and authorization of profiles before they are executed on devices. This intermediary mechanism prevents unauthorized profiles from being executed while allowing legitimate profiles to function normally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If connectedness and support services are enhanced, then user service quality is improved, but privacy protection deteriorates

Engineering Contradiction:
Improveuser service qualityVSAvoidprivacy exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by implementing security measures specifically at the profile execution level rather than throughout the entire device. Data collection profiles are individually authenticated and signed, so security is applied locally to each profile's data collection operations. This allows connectedness and support services to function through authenticated profiles while privacy is protected through localized security enforcement at the point of data collection.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter of profile authentication by introducing digital signatures and certificate verification. Profiles are transformed from unauthenticated code to cryptographically verified entities. This parameter change ensures that only profiles with valid cryptographic authentication can execute data collection, thereby protecting privacy while maintaining service functionality through properly authenticated profiles.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If data transmission is enabled to multiple collectors, then data utility is improved, but risk of data leaks to unauthorized recipients increases

Engineering Contradiction:
Improvedata transmission flexibilityVSAvoidunauthorized data access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication by signing profiles with specific data package collector identifiers before transmission. The certificate authority verifies and binds the profile to authorized collectors in advance. This preliminary binding ensures that data can be transmitted to multiple authorized collectors according to the profile's specifications, while unauthorized collectors cannot receive the data because their identifiers are not bound to the authenticated profile.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12021856B2Unified mobile security system and method of operation
Publication Date: 2024.06.25 AT&T INTELLECTUAL PROPERTY I L P
  • US12021856B2 patent drawing
  • US12021856B2 patent drawing
  • US12021856B2 patent drawing

AI summary

A mobile secure agent on a wireless device executes one or more authenticated data collection profiles provisioned by a private profile producer. Each data package can only be transmitted to a collector certificated by the same private profile producer. Update profiles are signed and provisioned through a tunnel initiated from the mobile secure agent. A Certificate Authority provides libraries, anchors, and certificates in a key management message module to each mobile secure agent which enables revocation and replacement of certificates. Data stored in this way on a wireless device may only be transmitted in encrypted form to an authenticated destination.