Mobile Device Security Certificate Enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing communication between newly-deployed mobile devices and organizational resources are either time-consuming and vulnerable to attacks, particularly with challenge-and-response-based authentication protocols.

Innovation Solution

A method where a mobile device generates a device security certificate with a unique key and identifier, which is validated by an authentication server to establish a secure connection, enabling the enrollment of additional certificates for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If challenge-and-response-based authentication protocols are used for remote certificate provision, then mobile devices can be authenticated remotely, but the system becomes vulnerable to attacks and complex

Engineering Contradiction:
Improveremote authentication capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the vulnerable challenge-response authentication mechanism and replaces it with a direct certificate-based authentication approach. The mobile device generates or receives a security certificate and uses it directly for authentication without engaging in complex challenge-response exchanges, thereby removing the security vulnerability while maintaining remote authentication capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a trusted certificate authority as an intermediary that issues security certificates to both the mobile device and the authentication server. This intermediary enables secure authentication by providing a trusted third party that vouches for the identity of communicating parties, replacing the need for vulnerable direct challenge-response protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security certificates are provided manually by the IT department, then the mobile device can be securely authenticated, but the process becomes time-consuming and requires physical possession transfer

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice provisioning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables the mobile device to self-provision security certificates automatically. The device can generate its own certificate or receive it automatically from a certificate authority without requiring manual intervention from IT staff or physical possession transfer, thereby maintaining security while dramatically improving provisioning speed and productivity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary action by pre-configuring the mobile device with security certificates before the device is activated or before it needs to access organizational resources. This can be done automatically through remote provisioning systems that prepare authentication credentials in advance, eliminating the need for time-consuming manual certificate distribution

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual certificate provision is used, then security can be maintained, but the member must physically give up possession of the mobile device

Engineering Contradiction:
Improvecertificate provisioning securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile device performs self-service by automatically obtaining and configuring security certificates without requiring the user to physically hand over the device to IT staff. The device can autonomously communicate with certificate authorities and authentication servers to complete the provisioning process, maintaining security while preserving user convenience and device possession

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3433997B1Activation of mobile devices in enterprise mobile management
Publication Date: 2021.06.09 HUAWEI TECH CO LTD
  • EP3433997B1 patent drawingFigure 1
  • EP3433997B1 patent drawingFigure 2
  • EP3433997B1 patent drawingFigure 3A

AI summary

The present disclosure is drawn to systems and methods for activating a mobile device in an enterprise mobile management context. The mobile device is configured to generate a first device security certificate which comprises a device key and an identifier of the mobile device. The device key corresponds to a shared secret known to the mobile device and to an authentication server. The mobile device sends the first device security certificate to the authentication server. The authentication server validates the mobile device by comparing the device key to a server key and by locating the identifier in a list of known identifiers. When the mobile device is validated, the authentication server sends a first server security certificate to the mobile device. The first device and server security certificates may then be used to establish a secure connection, over which a second set of device and server certificates may be enrolled.