Server-Mediated Device Transfer Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile phone anti-theft technologies lack security measures to prevent authorized users from maliciously using a kill switch during legal device transfers, potentially harming the legal transferee's data security.

Innovation Solution

A server-managed method where a device is set to a to-be-activated state, requiring specified user information for activation, ensuring that only the transferor or transferee can activate the device, thus preventing malicious data clearance during legal transfers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the kill switch function is enabled for anti-theft purposes, then device security against theft is improved, but the risk of malicious data clearance by authorized users during legal transfers increases

Engineering Contradiction:
Improvedevice security against theftVSAvoidmalicious data clearance by authorized users
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of user authority before allowing activation or data clearance operations. The server checks whether the user is the transferor, transferee, or service provider before permitting any kill switch actions, thus preventing malicious use by unauthorized users while maintaining the anti-theft function.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The server acts as an intermediary between users and the device, mediating all activation and data clearance operations. Instead of allowing direct access to kill switch functions, the server verifies user credentials and authorization status, thereby preventing malicious actions while enabling legitimate anti-theft operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the device remains in activated state during transfer, then the transferor can remotely control the device for anti-theft purposes, but the transferee's data security is compromised

Engineering Contradiction:
Improveanti-theft capabilityVSAvoidtransferee data security
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary authority verification before allowing the transferor to activate or clear data on the device. By checking user credentials and transfer status in advance, the system ensures that only authorized users can perform these operations, protecting the transferee's data while maintaining anti-theft capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The server provides feedback to users about their authorization status regarding device activation and data clearance operations. This feedback mechanism ensures that users understand their permissions and restrictions, preventing unauthorized actions while allowing legitimate anti-theft functions.

Inventive Principle:
Principle #23Feedback

3Loss of information

If the device is set to to-be-activated state during transfer, then malicious data clearance is prevented, but the device cannot be activated until transfer completion

Engineering Contradiction:
Improvetransferee data securityVSAvoiddevice activation delay
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system sets the device to to-be-activated state as a preliminary protective measure during the transfer process. This preliminary action protects the transferee's data from malicious clearance while the transfer is being completed, and the device is subsequently activated automatically upon successful transfer verification.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If remote activation control is implemented, then unauthorized activation is prevented, but the system complexity increases

Engineering Contradiction:
Improveactivation securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server acts as an intermediary that handles the complexity of activation control, verifying user credentials and authorization status before permitting device activation. This centralizes the complexity in the server rather than the device, maintaining simple device-side code while achieving robust security through server-mediated authentication and authorization checks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2981148B1Device management method, apparatus and system
Publication Date: 2020.02.26 HUAWEI TECH CO LTD
  • EP2981148B1 patent drawingFigure 1
  • EP2981148B1 patent drawingFigure 2
  • EP2981148B1 patent drawingFigure 3~4

AI summary

Embodiments of the present invention disclose a method, an apparatus, and a system for managing a device. A server receives a device transfer request message, where the device transfer request message includes transferee information of the device and information about the device; a to-be-transferred instruction is sent to the device according to the device transfer request message, where the to-be-transferred instruction includes the transferee information of the device; the to-be-transferred instruction is used to instruct the device to set an activated state of the device to a to-be-activated state; and after the device is set to the to-be-activated state, the device can be activated only by using specified user information, where the specified user information includes transferor information, of the device and/or the transferee information of the device. In this way, a transferor of a device cannot maliciously clear data of a transferee of the device, and therefore, security for using the device by the transferee of the device is ensured.