Bootstrap Server SIM Authentication via Pre-shared Key Identifier
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in efficiently distributing unique pre-shared key data for subscriber identity modules (SIMs) across various devices and networks, especially in mass production scenarios where device-specific and SIM-specific data are unknown at the time of manufacturing, leading to complex and costly processes.
Innovation Solution
The method involves storing and transmitting pre-shared key identifier and secret information specific to the SIM, derived from SIM-specific data like IMSI, ICCID, and PINs, which are linked to the SIM during manufacturing and used for initial authentication with a bootstrap server, establishing a secure communication channel.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-shared key data are assigned uniquely to each subscriber identity module in mass production, then security and reliability are improved, but manufacturing complexity and cost increase
Solution Approach 1:
The patent applies preliminary action by pre-provisioning the SIM card with a persistent identifier and pre-shared key data during SIM manufacturing, before the device is even produced. This allows the authentication credentials to be ready in advance, eliminating the need for complex post-manufacturing key distribution processes. The bootstrap server is also pre-configured with the ability to retrieve these credentials using the persistent identifier.
Solution Approach 2:
The patent extracts the authentication credential management from the device manufacturing process and separates it into independent components: SIM-specific persistent identifiers are managed by the SIM manufacturer, while device-specific identifiers are managed by the device manufacturer. The bootstrap server acts as an intermediary that combines these identifiers to retrieve the appropriate pre-shared keys, eliminating the need for complex coordination between SIM and device manufacturers.
2Reliability
If device-specific and SIM-specific data are exchanged between manufacturers and network operators for authentication setup, then authentication reliability is improved, but production time and complexity increase
Solution Approach 1:
The bootstrap server serves as an intermediary that receives the persistent identifier from the SIM card and the device identifier from the device, then automatically retrieves the corresponding pre-shared key data without requiring direct communication or data exchange between the SIM manufacturer, device manufacturer, and network operator. This mediator approach eliminates time-consuming manual coordination while ensuring authentication reliability.
Solution Approach 2:
The system enables self-service by allowing the bootstrap server to automatically match the persistent identifier with the corresponding pre-shared key data using the device identifier, without requiring human intervention or complex coordination protocols. The authentication credentials are retrieved autonomously based on the identifiers provided by the SIM and device.
3Reliability
If unique pre-shared key records are generated for each SIM card, then security is improved, but manufacturing cost increases
Solution Approach 1:
The patent uses copying by creating a persistent identifier that is copied from the SIM card's unique identification data and stored in the device. This persistent identifier then serves as a key to retrieve the pre-shared key data from the bootstrap server. Instead of physically transferring or manually configuring unique key records, the system copies the identifier and uses it to access the corresponding security credentials, significantly reducing manufacturing complexity and cost while maintaining security.
Data Source
Figure 1
AI summary
The invention relates to a method for initial authentication, with respect to a bootstrap server entity of a mobile communication network, of a client communication device and/or of a subscriber identity module within the client communication device, wherein after the initial authentication, the client communication device is enabled or initialized to operationally communicate with the mobile communication network, wherein a device identifier information is assigned to the client communication device, wherein the method comprises the following steps: -- in a first step, a pre-shared key identifier information is stored to a subscriber identity module element as well as transmitted to the bootstrap server entity, -- in a second step, subsequent to the first step, the subscriber identity module element is associated with or built in or assigned to the client communication device as its subscriber identity module, -- in a third step, subsequent to the second step, the client communication device with its subscriber identity module initially communicates with the bootstrap server entity and transmits the device identifier information and the pre-shared key identifier information to the bootstrap server entity, wherein the client communication device and/or the subscriber identity module within the client communication device is initially authenticated by the bootstrap server entity in case that the pre-shared key identifier information is verified by the bootstrap server entity.