Mobile Device Certificate Management via CA Imitation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management of mobile devices in enterprise environments is challenging due to the variety of device types, applications, and network security concerns, particularly in deploying, configuring, and controlling access to enterprise network services.

Innovation Solution

A mobile device management system that negotiates with a certificate authority to obtain and install certificates on mobile devices, ensuring authorized access to enterprise network services by imitating the device and transmitting enrollment messages, and utilizing a control client to manage and log data for security and configuration purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If mobile devices are provided with broad access to enterprise network services, then device functionality and user productivity are improved, but network security and control over unauthorized access deteriorate

Engineering Contradiction:
Improvedevice functionalityVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a certificate authority (CA) as an intermediary between mobile devices and enterprise network services. The CA issues digital certificates to devices, acting as a trusted mediator that verifies device identity and authorization before allowing network access. This resolves the contradiction by enabling broad device functionality while maintaining security through the CA's verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the mobile device management system monitors device status, certificate validity, and network access requests. Based on this feedback, the system dynamically controls access permissions, allowing or denying network access according to current device authorization state. This enables flexible security control that maintains both productivity and network security.

Inventive Principle:
Principle #23Feedback

2Productivity

If certificate management is automated through system negotiation, then deployment efficiency and configuration speed are improved, but system complexity and control mechanisms deteriorate

Engineering Contradiction:
Improvedeployment efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The mobile device management system performs self-service operations by autonomously negotiating with the certificate authority to obtain certificates for mobile devices. The system automatically handles certificate issuance, installation, and management without requiring manual intervention, thereby improving deployment efficiency while the centralized management approach keeps overall system complexity manageable.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring and pre-issuing certificates to mobile devices before they need to access enterprise network services. This advance preparation streamlines the deployment process and reduces on-site configuration complexity, allowing devices to be quickly deployed and configured.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If control agents are installed on mobile devices to manage configurations, then management capability and security control are improved, but device autonomy and operational flexibility deteriorate

Engineering Contradiction:
Improvemanagement capabilityVSAvoiddevice autonomy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The control agent installed on mobile devices operates with local quality by executing management functions specific to each device's context and requirements. The agent provides targeted security controls and configuration management tailored to individual devices while allowing devices to maintain their primary operational autonomy. This resolves the contradiction by providing necessary management capability without compromising device independence.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9917698B2Management of certificates for mobile devices
Publication Date: 2018.03.13 IVANTI INC
  • US9917698B2 patent drawing
  • US9917698B2 patent drawing
  • US9917698B2 patent drawing

AI summary

One embodiment of the present disclosure provides a method that includes accessing, by a mobile device management system, a profile for a mobile device. The method also includes negotiating, by the mobile device management system, with a certificate authority to obtain a certificate for the mobile device. The negotiating with the certificate authority includes imitating the mobile device based on the profile. The negotiating with the certificate authority also includes, based at least on the imitation, transmitting one or more certificate enrollment messages to the certificate authority. The negotiating with the certificate authority further includes, based on the one or more messages, receiving, at the mobile device management system, the certificate for the mobile device. The method further includes transmitting the certificate to a control agent hosted on the mobile device for installation.