Secure Device Management Channel via Unique Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack secure and efficient methods to uniquely identify and communicate with client devices across varying locations, hindering effective device management and secure communication channels.

Innovation Solution

A unique identification system, referred to as innodevID, is issued to each device, enabling secure communication using the innodevID@service_domain/serviceID address convention, which allows for real-time device control and information exchange over secure channels like TLS and SSL, ensuring persistent logical connections regardless of device location changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional communication methods are used without unique identification, then device communication is simpler, but secure and reliable device management cannot be achieved

Engineering Contradiction:
Improvesecure communicationVSAvoidcommunication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication system is segmented into distinct components: unique device identifiers (innodevID), service domain identifiers, service identifiers, and protocol layers (TLS/SSL). This segmentation allows each component to be optimized independently for security while maintaining overall system manageability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Unique device identifiers and security credentials are assigned to devices in advance during device provisioning, before the devices need to communicate. This preliminary action enables immediate secure communication without requiring complex authentication negotiations at the time of connection

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If devices switch between connection types (mobile data to WiFi), then device mobility and flexibility improve, but communication channel persistence deteriorates

Engineering Contradiction:
Improveconnection flexibilityVSAvoidcommunication channel
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The system transitions from relying on physical connection stability to maintaining connections through a logical dimension - using persistent logical session identifiers that remain valid regardless of the physical communication medium. This allows the same logical connection to persist across different network interfaces and connection types

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If location-independent device communication is implemented, then device management flexibility improves, but identification and communication reliability worsens

Engineering Contradiction:
Improvelocation independenceVSAvoididentification accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A universal device identifier (innodevID) is created that serves multiple functions: unique device identification, communication channel establishment, and session persistence across different locations and network types. This single identifier replaces multiple location-dependent identification methods, ensuring consistent and reliable device identification regardless of geographic location or network environment

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9912730B2Secured communication channel between client device and device management service
Publication Date: 2018.03.06 QUALCOMM INC
  • US9912730B2 patent drawing
  • US9912730B2 patent drawing
  • US9912730B2 patent drawing

AI summary

Systems and methods are described that comprise issuing a request to a client device from a platform. The request is an electronic message that includes an electronic link. An acknowledgement is received from the client device, and the acknowledgement is generated upon activation of the electronic link. A secure channel is established between the platform and a client application of the client device upon receipt of the acknowledgement. Establishment of the secure channel comprises the client application logging into a care application of the platform with a device identification that was received from the platform during an enrollment transaction. A session is conducted over the secure channel, and the session comprises the care application remotely controlling the client device via the client application.