Cellular Service Credential Transfer via Secure Local Connection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for mechanisms to efficiently transfer cellular service account credentials, such as SIM or eSIM credentials, between wireless devices, allowing users to seamlessly switch or transfer services between devices without requiring complex authentication or interaction with mobile network operator servers.
Innovation Solution
The method involves establishing a secure connection between source and target devices, using a transfer token and trust flag to authenticate and transfer cellular service credentials, either through proximity-based connections like WPAN or WLAN, or via a network-based cloud service like iCloud, allowing for one-click or interactive mode transfers, and utilizing shared secret keys for trust validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual authentication with mobile network operator servers is used to transfer cellular service credentials, then security is maintained, but user interaction complexity and transfer time increase
Solution Approach 1:
The system performs preliminary authentication actions by establishing trust relationships and generating authentication credentials (such as certificates or tokens) in advance during device setup or previous interactions with the network. This preliminary authentication data is stored locally, enabling rapid credential transfer without real-time server interaction, thus reducing transfer time while maintaining security through pre-validated authentication mechanisms
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that mediates between the source device, target device, and mobile network operator server. This intermediary system uses pre-established trust relationships and authentication credentials to verify device identities and authorize credential transfers, eliminating the need for direct manual authentication with the operator server during each transfer, thereby reducing time while preserving security through the intermediary's validation process
2Reliability
If complex authentication procedures are used to transfer cellular service credentials, then security is ensured, but ease of operation deteriorates
Solution Approach 1:
The system enables self-service credential transfer by allowing devices to automatically authenticate and transfer cellular service credentials using pre-stored authentication data and trust relationships. The source device can initiate and complete the credential transfer process autonomously by presenting valid authentication credentials to the target device, eliminating the need for manual user authentication or complex interaction procedures, thus improving ease of operation while maintaining security through automated cryptographic verification
Solution Approach 2:
Complex authentication procedures are performed in advance to establish trust relationships and store authentication credentials locally on devices. This preliminary action includes generating, storing, and validating certificates or tokens during device provisioning or previous secure interactions. When credential transfer is needed, these pre-established credentials enable automatic authentication without requiring users to navigate complex authentication interfaces or enter sensitive information, thereby improving ease of operation while ensuring security through pre-validated authentication mechanisms
3Productivity
If direct device-to-device transfer without server interaction is used, then transfer efficiency improves, but reliability of authentication may deteriorate
Solution Approach 1:
The patent introduces an intermediary authentication mechanism that mediates between the source device, target device, and mobile network operator server. This intermediary system uses pre-established trust relationships and authentication credentials to verify device identities and authorize credential transfers, eliminating the need for direct manual authentication with the operator server during each transfer, thereby reducing time while preserving security through the intermediary's validation process
Data Source
AI summary
Embodiments described herein relate to transfer of credentials between two mobile wireless devices that are within proximity of each other, via a secure local connection, or via a network-based cloud service, where the two mobile wireless devices are not in proximity to each other. Transfer of credentials can include communication between a source device, a target device, and/or one more network-based servers, which can include mobile network operator (MNO) managed servers, such as an entitlement server, a web-sheet server, an authentication server, a provisioning server, a subscription management data preparation (SM-DP+) server, a home subscriber server (HSS), and/or an authentication server, as well as third-party managed servers, such as a cloud service server and/or an identification services server. Authentication can be based at least in part on one or more tokens and/or a trust flag obtained by the source device and provided to the target device.


