Mobile Device Delegate for Isolated Gateway Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing headless information handling systems, such as IoT gateways, that become isolated from external networks and resources is challenging due to their inaccessible nature, making conventional device management unworkable.
Innovation Solution
A device management method using a device manager that generates split cryptographic keys, allowing a mobile device to act as a delegate for managing a gateway device by decrypting encrypted metadata, enabling trusted policy and setting delivery even when the gateway is isolated from the enterprise's device management resource.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a gateway device is deployed at a remote or inaccessible location to perform monitoring or facilitation functions, then the device can operate independently in the field, but the device becomes isolated from external device management resources, making conventional device management unworkable
Solution Approach 1:
A mobile device acts as an intermediary between the isolated gateway device and the device management server. The mobile device establishes a local connection with the gateway and communicates management commands through it, enabling device management without direct access to the gateway from external management resources.
Solution Approach 2:
Device management credentials and cryptographic keys are pre-configured on the gateway device during initial setup before it becomes isolated. This preliminary configuration enables the gateway to authenticate and communicate with mobile devices that present valid credentials, allowing management operations to proceed without real-time connection to external management resources.
2Reliability
If conventional device management resources are used to manage an isolated gateway device, then the device can maintain centralized control, but the management process becomes challenging or unworkable due to network inaccessibility
Solution Approach 1:
The mobile device serves as a trusted intermediary that bridges the gap between centralized management requirements and the isolated gateway's network unavailability. It relays management commands and data between the gateway and the external management ecosystem, maintaining centralized control through indirect communication.
Solution Approach 2:
Cryptographic credentials including device identifiers, authentication keys, and encryption certificates are pre-provisioned on the gateway device before deployment. This allows the gateway to securely authenticate mobile devices and establish encrypted communication channels without requiring real-time connection to credential issuance authorities.
3Ease of operation
If a mobile device is designated as a management delegate for an isolated gateway, then device management becomes feasible in remote locations, but secure authentication and authorization between the mobile device and gateway must be established without external verification
Solution Approach 1:
The gateway device is pre-configured with a database of authorized mobile device identifiers and cryptographic keys during initial setup. When a mobile device attempts to connect, the gateway autonomously verifies its credentials against this pre-stored authorization data, enabling secure authentication without external verification services.
Solution Approach 2:
The gateway device stores copies of authorized mobile device credentials and cryptographic keys locally in its secure storage. This local copy of authorization data enables the gateway to independently verify mobile device identities and establish secure sessions without requiring real-time connection to central authentication authorities.
Data Source
AI summary
A device manager establishes a mobile device and a gateway as managed devices. The device manager generates management metadata and a split cryptographic key. The management metadata may include information identifying the mobile device. The metadata may include a gateway key part and a mobile key part which, in combination, are sufficient to decrypt information encrypted with the management split key. The device manager may encrypt the management metadata using the management split key. The device manager may send the gateway key part and the encrypted management metadata to the gateway and the mobile key part to the mobile device. Subsequent delivery of the mobile key part to the gateway, by the mobile device, enables the gateway to decrypt the encrypted management metadata and recognize the mobile device as a management device delegate sanctioned by the device manager to perform delegated management of the gateway.


