Mobile Device Initial Certificate Enrollment via Biometric Relay

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In highly secured wireless communication systems, the initial certificate enrollment process for mobile devices is cumbersome and insecure, often requiring manual operations and reliance on trusted third-party TPM chips, which is not feasible in government and public safety systems where inter-organization trust is not permitted.

Innovation Solution

A method and apparatus that enables initial certificate enrollment through a trusted mobile device establishing wireless connections with an infrastructure and another mobile device, using biometric data to verify identities and obtain digital certificates, thereby facilitating secure and automated enrollment without relying on external trust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual operations are used for initial certificate enrollment, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile device performs self-enrollment by automatically generating certificates using biometric authentication and cryptographic operations, eliminating the need for manual administrator intervention while maintaining security through cryptographic verification of biometric data

Inventive Principle:
Principle #25Self-service

2Ease of operation

If TPM chip is used for initial certificate enrollment, then ease of operation is improved, but adaptability deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidadaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent extracts the trust anchor functionality from external TPM chips and implements it natively within the mobile device using built-in secure elements and biometric authentication, eliminating dependency on external hardware while maintaining cryptographic security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile device's secure element and biometric authentication system serve multiple functions including key generation, certificate signing, and identity verification, replacing the specialized TPM chip functionality with a multi-functional integrated solution that works across different organizations and systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automated enrollment is implemented, then productivity is improved, but reliability deteriorates

Engineering Contradiction:
ImproveproductivityVSAvoidreliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements cryptographic feedback mechanisms where the mobile device verifies the authenticity of enrollment responses and the infrastructure verifies biometric data integrity through digital signatures, ensuring automated processes maintain security and reliability

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9882726B2Method and apparatus for initial certificate enrollment in a wireless communication system
Publication Date: 2018.01.30 MOTOROLA SOLUTIONS INC
  • US9882726B2 patent drawing
  • US9882726B2 patent drawing
  • US9882726B2 patent drawing

AI summary

A method and apparatus are provided for initial certification enrollment in a wireless communication system. A first mobile device establishes a first wireless connection with an infrastructure and a second wireless connection with a second mobile device. The first mobile device receives, from the second mobile device, a first certification request that includes a request for a digital certificate for the second mobile device and first biometric data associated with a user of the first mobile device. The first mobile device obtains second biometric data associated with a user of the second mobile device and conveys a second certification request to the infrastructure that includes the request for the digital certificate for the second mobile device and the first and second biometric data. The first mobile device then receives, from the infrastructure, the digital certificate for the second mobile device and forwards, to the second mobile device, the digital certificate.