Secure Mobile Service Transfer via Shared Key
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless network systems face challenges in securely transferring services between mobile devices, as they often require users to inform administrators or connect to trusted computers, limiting convenience and exposing sensitive information to potential attackers.
Innovation Solution
A method is introduced where a shared key is generated using a master key unique to the server and the first mobile device, allowing secure transfer of service data from the first mobile device to a second device through an alternate communication mechanism independent of the server, enabling convenient and secure service activation on the target device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If service data is copied from the source device, then the transfer process is simplified, but key information may be exposed to attackers
Solution Approach 1:
The patent extracts only the necessary service authorization information (service ID, policy data) from the source device without copying sensitive key material. The target device receives minimal data required for service activation while the source device retains control over key management, thus simplifying transfer while preventing information exposure.
Solution Approach 2:
The patent introduces a server as an intermediary that facilitates service transfer by verifying service authorization and managing key distribution. The server acts as a trusted mediator that enables the transfer process without requiring direct copying of sensitive data between devices, thus simplifying user operation while maintaining security.
2Reliability
If the user contacts the administrator or connects to a trusted computer for service transfer, then service security is maintained, but user convenience is restricted
Solution Approach 1:
The patent enables the mobile devices to perform service transfer autonomously using built-in security credentials (device certificates, keys). The source and target devices can directly communicate and complete the transfer process without requiring external assistance from administrators or trusted computers, thus maintaining security through cryptographic verification while significantly improving user convenience.
3Reliability
If administrative intervention is required for service transfer, then service authorization is verified, but transfer time and complexity increase
Solution Approach 1:
The patent implements preliminary service authorization verification during the initial service setup phase, where the server pre-validates service permissions and stores authorization data. When service transfer is initiated, the pre-verified authorization information is quickly transmitted to the target device without requiring real-time administrative intervention, thus maintaining authorization verification while reducing transfer time.
Data Source
AI summary
A method for securely transferring a service from a first mobile device to a second mobile device, the service being associated with a server configured for facilitating provisioning of services to mobile devices over a wireless communications network. The method includes generating in the first mobile device a shared key, the shared key being generated using a master key unique to the server and to the first mobile device, the master key being accessible by the server and by the first mobile device; and sending said shared key from the first mobile device to the second mobile device using an alternate communication mechanism independent from the server.


