Cellular Service Credential Transfer via Secure Local Connection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for mechanisms to efficiently transfer cellular service account credentials, such as SIM or eSIM credentials, between wireless devices, allowing users to seamlessly switch or transfer services between devices without requiring complex authentication or interaction with mobile network operator servers.

Innovation Solution

The method involves establishing a secure connection between source and target devices, using a transfer token and trust flag to authenticate and transfer cellular service credentials, either through proximity-based connections like WPAN or WLAN, or via a network-based cloud service like iCloud, allowing for one-click or interactive mode transfers, and utilizing shared secret keys for trust validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual authentication with mobile network operator servers is used to transfer cellular service credentials, then security is maintained, but user interaction complexity and transfer time increase

Engineering Contradiction:
ImprovesecurityVSAvoidtransfer time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication actions by establishing trust relationships and generating authentication credentials (such as certificates or tokens) in advance during device setup or previous interactions with the network. This preliminary authentication data is stored locally, enabling rapid credential transfer without real-time server interaction, thus reducing transfer time while maintaining security through pre-validated authentication mechanisms

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between the source device, target device, and mobile network operator server. This intermediary system uses pre-established trust relationships and authentication credentials to verify device identities and authorize credential transfers, eliminating the need for direct manual authentication with the operator server during each transfer, thereby reducing time while preserving security through the intermediary's validation process

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex authentication procedures are used to transfer cellular service credentials, then security is ensured, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service credential transfer by allowing devices to automatically authenticate and transfer cellular service credentials using pre-stored authentication data and trust relationships. The source device can initiate and complete the credential transfer process autonomously by presenting valid authentication credentials to the target device, eliminating the need for manual user authentication or complex interaction procedures, thus improving ease of operation while maintaining security through automated cryptographic verification

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Complex authentication procedures are performed in advance to establish trust relationships and store authentication credentials locally on devices. This preliminary action includes generating, storing, and validating certificates or tokens during device provisioning or previous secure interactions. When credential transfer is needed, these pre-established credentials enable automatic authentication without requiring users to navigate complex authentication interfaces or enter sensitive information, thereby improving ease of operation while ensuring security through pre-validated authentication mechanisms

Inventive Principle:
Principle #10Preliminary action

3Productivity

If direct device-to-device transfer without server interaction is used, then transfer efficiency improves, but reliability of authentication may deteriorate

Engineering Contradiction:
Improvetransfer efficiencyVSAvoidauthentication reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that mediates between the source device, target device, and mobile network operator server. This intermediary system uses pre-established trust relationships and authentication credentials to verify device identities and authorize credential transfers, eliminating the need for direct manual authentication with the operator server during each transfer, thereby reducing time while preserving security through the intermediary's validation process

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11671833B2Cellular service account transfer and authentication
Publication Date: 2023.06.06 APPLE INC
  • US11671833B2 patent drawing
  • US11671833B2 patent drawing
  • US11671833B2 patent drawing

AI summary

Embodiments described herein relate to transfer of credentials between two mobile wireless devices that are within proximity of each other, via a secure local connection, or via a network-based cloud service, where the two mobile wireless devices are not in proximity to each other. Transfer of credentials can include communication between a source device, a target device, and/or one more network-based servers, which can include mobile network operator (MNO) managed servers, such as an entitlement server, a web-sheet server, an authentication server, a provisioning server, a subscription management data preparation (SM-DP+) server, a home subscriber server (HSS), and/or an authentication server, as well as third-party managed servers, such as a cloud service server and/or an identification services server. Authentication can be based at least in part on one or more tokens and/or a trust flag obtained by the source device and provided to the target device.