Secure Certificate Distribution via Intermediary Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The use of third-party operated services for managing enterprise devices can compromise sensitive information due to potential interception and access by third-party operators during data transmission.
Innovation Solution
A secure data distribution method where a client device provides a public encryption key to a third-party managed service, which relays it to a data repository, allowing the sensitive data to be encrypted and then returned to the client device, ensuring protection from interception.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If third-party operated services are used for managing enterprise devices, then device management functionality is improved, but security and confidentiality of sensitive information deteriorates due to potential interception by third-party operators
Solution Approach 1:
The patent introduces a certificate authority (CA) as an intermediary that issues digital certificates to both the third-party service provider and the client device. This CA acts as a trusted mediator that enables secure communication without requiring the third-party operator to have direct access to sensitive data, thus resolving the contradiction between enabling third-party management functionality and preventing data interception.
Solution Approach 2:
The patent replaces traditional mechanical data transmission methods with cryptographic encryption mechanisms. By using public key infrastructure and digital certificates, the system substitutes direct data transmission with encrypted communication channels, preventing third-party operators from intercepting sensitive information while maintaining the ability to manage enterprise devices remotely.
2Ease of operation
If sensitive data is transmitted through third-party services, then service accessibility is improved, but data confidentiality deteriorates due to potential exposure during transmission
Solution Approach 1:
The patent implements preliminary action by having the third-party service provider obtain a digital certificate from the trusted CA before any sensitive data transmission occurs. This pre-established cryptographic identity and encryption capability allows the system to maintain service accessibility while ensuring data confidentiality through encrypted transmission channels from the outset.
Solution Approach 2:
The trusted CA serves as an intermediary that facilitates secure data transmission between the third-party service and the client device. By mediating the establishment of cryptographic trust, the CA enables sensitive data to be transmitted through the third-party service without exposing it to interception, thus maintaining both accessibility and confidentiality.
3Extent of automation
If third-party operators have access to privileged information, then management capability is improved, but security risks increase due to potential misuse of sensitive data
Solution Approach 1:
The patent extracts the sensitive data from the third-party operator's direct access by using encrypted transmission channels. The third-party provider can manage enterprise devices automatically without having direct access to privileged information, as the data is encrypted end-to-end between the client device and the trusted CA, thus maintaining automation capability while eliminating security risks.
Solution Approach 2:
The patent substitutes direct data access mechanisms with cryptographic encryption and digital certificate verification. This replacement allows the third-party service provider to perform management functions through encrypted communications rather than direct access to sensitive data, maintaining automation capability while ensuring that data remains confidential and secure throughout the transmission process.
Data Source
AI summary
Disclosed are various embodiments for securely distributing certificates or encryption keys. A management service can receive an enrollment request from a client device. The management service can then send a key request to a certificate provider, the key request comprising a user identifier. The management service can also send a skeleton payload to an enterprise gateway. In response, the management service can receive an encrypted profile from the enterprise gateway, the encrypted profile comprising the skeleton payload with an encryption key inserted by the enterprise gateway into the skeleton payload. Finally, the management service can send the encrypted profile to the client device.


