Mobile Device Security Certificate Enrollment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securing communication between newly-deployed mobile devices and organizational resources are either time-consuming and vulnerable to attacks, particularly with challenge-and-response-based authentication protocols.
Innovation Solution
A method where a mobile device generates a device security certificate with a unique key and identifier, which is validated by an authentication server to establish a secure connection, enabling the enrollment of additional certificates for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If challenge-and-response-based authentication protocols are used for remote certificate provision, then mobile devices can be authenticated remotely, but the system becomes vulnerable to attacks and complex
Solution Approach 1:
The patent extracts the vulnerable challenge-response authentication mechanism and replaces it with a direct certificate-based authentication approach. The mobile device generates or receives a security certificate and uses it directly for authentication without engaging in complex challenge-response exchanges, thereby removing the security vulnerability while maintaining remote authentication capability
Solution Approach 2:
The patent introduces a trusted certificate authority as an intermediary that issues security certificates to both the mobile device and the authentication server. This intermediary enables secure authentication by providing a trusted third party that vouches for the identity of communicating parties, replacing the need for vulnerable direct challenge-response protocols
2Reliability
If security certificates are provided manually by the IT department, then the mobile device can be securely authenticated, but the process becomes time-consuming and requires physical possession transfer
Solution Approach 1:
The patent enables the mobile device to self-provision security certificates automatically. The device can generate its own certificate or receive it automatically from a certificate authority without requiring manual intervention from IT staff or physical possession transfer, thereby maintaining security while dramatically improving provisioning speed and productivity
Solution Approach 2:
The patent implements preliminary action by pre-configuring the mobile device with security certificates before the device is activated or before it needs to access organizational resources. This can be done automatically through remote provisioning systems that prepare authentication credentials in advance, eliminating the need for time-consuming manual certificate distribution
3Reliability
If manual certificate provision is used, then security can be maintained, but the member must physically give up possession of the mobile device
Solution Approach 1:
The mobile device performs self-service by automatically obtaining and configuring security certificates without requiring the user to physically hand over the device to IT staff. The device can autonomously communicate with certificate authorities and authentication servers to complete the provisioning process, maintaining security while preserving user convenience and device possession
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
The present disclosure is drawn to systems and methods for activating a mobile device in an enterprise mobile management context. The mobile device is configured to generate a first device security certificate which comprises a device key and an identifier of the mobile device. The device key corresponds to a shared secret known to the mobile device and to an authentication server. The mobile device sends the first device security certificate to the authentication server. The authentication server validates the mobile device by comparing the device key to a server key and by locating the identifier in a list of known identifiers. When the mobile device is validated, the authentication server sends a first server security certificate to the mobile device. The first device and server security certificates may then be used to establish a secure connection, over which a second set of device and server certificates may be enrolled.