Mobile Device Trust Verification via Digital Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current client-server technologies face limitations in securely managing mobile code execution on devices, as users lack the sophistication to make informed decisions about resource access, leading to potential security risks from untrusted websites and malicious scripts.

Innovation Solution

Implementing digital certificates and signatures to establish trust between mobile devices and web servers, allowing devices to verify the identity and trustworthiness of servers through a chain of digital certificates, thereby controlling access to resources and ensuring secure execution of scripts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates and signatures are implemented to verify server identity and control resource access, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces digital certificates and signature verification mechanisms as intermediaries between the mobile device and web server. The certificate authority acts as a trusted mediator that issues digital certificates to servers, which the device then verifies before allowing resource access. This intermediary system resolves the contradiction by providing automated security verification without requiring users to manually assess trust, thereby improving security while keeping the user interface simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary verification of server identity through digital certificate validation before any resource access is granted. The mobile device checks the server's digital certificate and signature in advance of executing scripts or accessing resources. This preliminary security action ensures that only authenticated servers can interact with the device, improving security while automating the process so users don't need to understand the complexity of certificate verification.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If advanced client-side functionality is enabled through server-based scripting, then productivity is improved, but security risks increase due to users' inability to make informed decisions about resource access

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent enables the mobile device to automatically perform security verification of server identity and script source using digital certificates. Instead of relying on users to make informed decisions, the system provides self-service security validation where the device autonomously checks certificates and signatures. This allows advanced client-side functionality to be enabled while maintaining security through automated verification mechanisms that users don't need to understand or manage manually.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses digital certificates as an intermediary mechanism to bridge the gap between server-based functionality and client-side security. The certificate system acts as a mediator that provides verifiable proof of server identity and script source, allowing the device to safely execute advanced functionality from remote servers. This intermediary approach enables productivity improvements through server-based scripting while maintaining security through automated certificate verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2425370B1Method and apparatus to create a secure web browsing environment with privilege signing
Publication Date: 2015.08.26 QUALCOMM INC
  • EP2425370B1 patent drawingFigure 1
  • EP2425370B1 patent drawingFigure 2
  • EP2425370B1 patent drawingFigure 3A

AI summary

Devices and methods use digital certificates and digital signatures to enable computing devices, such as mobile devices, to trust a server attempting to access a resource on the computing device. The server may present the computing device with a digital certificate issued by a trusted third party which includes information so that the computing device can determine which resources the server should be trusted to access. The computing device can determine that the digital certificate was issued by a trusted third party by examining the chain of digital certificates that may link the server with an inherently trusted authority.