Mobile Device Digital Certificate Management via Server Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional procedures for obtaining digital certificates on mobile devices are manual and cumbersome, requiring significant processing power and lacking efficient control and distribution from the administrator's perspective in communication networks.

Innovation Solution

A method where a mobile device establishes a communication session with a host server to receive configuration information for obtaining a digital certificate from a certificate authority, with the host server acting as an intermediary to request and push the certificate to the device, reducing processing load and enhancing administrative control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual procedures are used for obtaining digital certificates on mobile devices, then administrative control is enhanced, but processing power requirements and operational complexity increase

Engineering Contradiction:
Improveease of certificate managementVSAvoidprocessing power consumption
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The patent introduces a server as an intermediary between the mobile device and the certificate authority. The server handles the complex certificate enrollment process, including generating certificate signing requests, receiving certificates from the CA, and pushing them to the mobile device. This mediator approach transfers the processing burden from the resource-constrained mobile device to the more capable server, resolving the contradiction between ease of operation and processing power consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual certificate enrollment is performed on mobile devices, then device autonomy is maintained, but operational complexity and time requirements increase

Engineering Contradiction:
Improvecertificate distribution efficiencyVSAvoidoperational complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-configuring the mobile device with server information and automatically initiating the certificate enrollment process when the device connects to the network. The server proactively pushes the certificate to the device once received from the CA, eliminating the need for manual user intervention at each step. This preliminary automation reduces both operational complexity and the time required for certificate distribution.

Inventive Principle:
Principle #10Preliminary action

3Loss of time

If the mobile device directly obtains certificates from the certificate authority, then processing speed may be faster, but power consumption and operational complexity increase

Engineering Contradiction:
Improvecertificate acquisition timeVSAvoidoperational simplicity
Core Design Contradiction:
Loss of timeVSEase of operation

Solution Approach 1:

The server acts as an intermediary that streamlines the certificate acquisition process. While the mobile device does not directly communicate with the certificate authority, the server efficiently manages the enrollment workflow, including preparing requests, receiving responses from the CA, and distributing certificates to devices. This intermediary approach maintains relatively fast certificate acquisition while significantly simplifying device operations and reducing power consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10356083B2Methods and apparatus for use in enabling a mobile communication device with a digital certificate
Publication Date: 2019.07.16 MALIKIE INNOVATIONS LTD
  • US10356083B2 patent drawing
  • US10356083B2 patent drawing
  • US10356083B2 patent drawing

AI summary

A mobile communication device causes a communication session to be established with a host server of a communication network. The mobile device performs communication operations in the communication session for activating a communication service, such as a data synchronization service, with the host server. In the communication session, the mobile device also receives configuration information which includes information for use in constructing a request message for obtaining a digital certificate from a certificate authority (CA). After receipt of the configuration information, the mobile device constructs the request message for the digital certificate and causes it to be sent to the host server. In response, the host server requests and obtains the digital certificate from the CA on behalf of the mobile device, and thereafter “pushes” the received digital certificate to the mobile device. The mobile device receives the digital certificate and stores it for use in subsequent communications.