Wireless Handheld Device Authentication via Digital Certificate Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data centers face challenges in securely authenticating and authorizing wireless handheld devices for access to sensitive information handling systems, as existing solutions lack robust mechanisms to ensure secure communication and authentication within the data center environment.

Innovation Solution

A system comprising a mobile device with long and short range wireless communication controllers, a primary access controller, a validation server, and a data center management system, which uses security credentials and encryption keys to authenticate users and provide secure access, further enhanced by issuing a digital certificate to the mobile device for secure transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for wireless handheld devices in data centers, then device access is permitted, but security vulnerabilities and unauthorized access risks increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication actions by issuing digital certificates to mobile devices before they access the data center network. The certificate is provisioned in advance through a certificate authority server, enabling the device to prove its identity before any actual data access occurs. This preliminary security measure prevents unauthorized access while maintaining a manageable authentication process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a certificate authority server as an intermediary between the mobile device and the data center network. This intermediary issues and manages digital certificates, acting as a trusted third party that verifies device identity without requiring complex direct authentication protocols between the device and network resources. The intermediary simplifies the overall authentication architecture while enhancing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital certificates are issued to mobile devices for authentication, then security is enhanced, but system complexity and certificate management overhead increase

Engineering Contradiction:
Improvedevice authentication reliabilityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device is equipped with a certificate module that automatically manages its own digital certificate throughout the authentication process. The device can present its certificate independently, store it securely in local memory, and use it for mutual authentication without requiring manual intervention. This self-service capability reduces the operational burden of certificate management while maintaining high authentication reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The digital certificate serves multiple functions simultaneously: it authenticates the mobile device to the network, enables encrypted communication channels, and provides a basis for mutual authentication between device and server. This multi-functionality consolidates what would otherwise require separate authentication mechanisms into a single versatile credential, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If mutual authentication between mobile device and access point is implemented, then unauthorized access is prevented, but authentication time and processing overhead increase

Engineering Contradiction:
Improveaccess control securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The mutual authentication process is streamlined by having the mobile device present its digital certificate before any network access is attempted. The access point validates this pre-presented certificate against the certificate authority's public key, eliminating the need for iterative challenge-response protocols. This preliminary presentation of credentials reduces authentication time while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex mechanical authentication interactions with cryptographic verification. Instead of multiple back-and-forth authentication exchanges, the system uses public key infrastructure where the device's digital signature on its certificate provides immediate proof of identity. This substitution of cryptographic mechanisms for iterative authentication protocols significantly reduces processing time and overhead.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9961074B2System and method for providing an authentication certificate for a wireless handheld device a data center environment
Publication Date: 2018.05.01 DELL PROD LP
  • US9961074B2 patent drawing
  • US9961074B2 patent drawing
  • US9961074B2 patent drawing

AI summary

A system includes an access controller including a short range wireless communication controller to couple to a mobile device, and an access point including a long range wireless communication controller. The access point is coupled to the access controller via a secure link, and the access controller authenticates a user of the mobile device and provides access information from the mobile device to the access point via the secure link in response to authenticating the user. The access point couples to the mobile device using the access information to via the long range wireless communication controller and receives unique identification information associated with the mobile device from the mobile device. The system generates a digital certificate associated with the unique identification information and provides the digital certificate to the mobile device.