Mobile Device Certificate Management via CA Imitation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The management of mobile devices in enterprise environments is challenging due to the variety of device types, applications, and network security concerns, particularly in deploying, configuring, and controlling access to enterprise network services.
Innovation Solution
A mobile device management system that negotiates with a certificate authority to obtain and install certificates on mobile devices, ensuring authorized access to enterprise network services by imitating the device and transmitting enrollment messages, and utilizing a control client to manage and log data for security and configuration purposes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If mobile devices are provided with broad access to enterprise network services, then device functionality and user productivity are improved, but network security and control over unauthorized access deteriorate
Solution Approach 1:
The patent introduces a certificate authority (CA) as an intermediary between mobile devices and enterprise network services. The CA issues digital certificates to devices, acting as a trusted mediator that verifies device identity and authorization before allowing network access. This resolves the contradiction by enabling broad device functionality while maintaining security through the CA's verification process.
Solution Approach 2:
The system implements feedback mechanisms where the mobile device management system monitors device status, certificate validity, and network access requests. Based on this feedback, the system dynamically controls access permissions, allowing or denying network access according to current device authorization state. This enables flexible security control that maintains both productivity and network security.
2Productivity
If certificate management is automated through system negotiation, then deployment efficiency and configuration speed are improved, but system complexity and control mechanisms deteriorate
Solution Approach 1:
The mobile device management system performs self-service operations by autonomously negotiating with the certificate authority to obtain certificates for mobile devices. The system automatically handles certificate issuance, installation, and management without requiring manual intervention, thereby improving deployment efficiency while the centralized management approach keeps overall system complexity manageable.
Solution Approach 2:
The system performs preliminary actions by pre-configuring and pre-issuing certificates to mobile devices before they need to access enterprise network services. This advance preparation streamlines the deployment process and reduces on-site configuration complexity, allowing devices to be quickly deployed and configured.
3Reliability
If control agents are installed on mobile devices to manage configurations, then management capability and security control are improved, but device autonomy and operational flexibility deteriorate
Solution Approach 1:
The control agent installed on mobile devices operates with local quality by executing management functions specific to each device's context and requirements. The agent provides targeted security controls and configuration management tailored to individual devices while allowing devices to maintain their primary operational autonomy. This resolves the contradiction by providing necessary management capability without compromising device independence.
Data Source
AI summary
One embodiment of the present disclosure provides a method that includes accessing, by a mobile device management system, a profile for a mobile device. The method also includes negotiating, by the mobile device management system, with a certificate authority to obtain a certificate for the mobile device. The negotiating with the certificate authority includes imitating the mobile device based on the profile. The negotiating with the certificate authority also includes, based at least on the imitation, transmitting one or more certificate enrollment messages to the certificate authority. The negotiating with the certificate authority further includes, based on the one or more messages, receiving, at the mobile device management system, the certificate for the mobile device. The method further includes transmitting the certificate to a control agent hosted on the mobile device for installation.


