CIoT Device Provisioning via Secure Element

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cellular Internet of Things (CIoT) user equipment (UE) technologies face challenges in efficiently provisioning and securely connecting low-power, low-cost devices to cellular networks, particularly in scenarios requiring short-lived connections and limited resource consumption, while ensuring secure authentication and efficient network access.

Innovation Solution

The solution involves a process for provisioning CIoT UE devices using a secure connection between the device and a cloud service provider (CSP), involving a secure element with a master key, and utilizing interfaces like Sh/S6m for enhanced security, allowing for efficient attachment to a cellular network and authentication within the evolved packet core (EPC) network, enabling device-to-device communication and machine-type communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cellular network provisioning is used for CIoT devices, then network connectivity is achieved, but security vulnerabilities and high power consumption occur

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the authentication and key management functions from the conventional cellular network provisioning process and implements them locally within a secure element of the CIoT device. This extraction allows the device to perform secure authentication independently without relying on power-intensive conventional provisioning procedures, thereby improving both security and reducing power consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure element as an intermediary component between the CIoT device and the cellular network. This secure element contains a master key and handles authentication operations, acting as a mediator that enables secure network access while minimizing the power consumption of the main device processor and enhancing overall security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure authentication protocols are implemented for CIoT devices, then network security is improved, but device complexity and provisioning overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-provisioning the secure element with a master key during device manufacturing or initial setup. This preliminary provisioning of security credentials simplifies subsequent authentication processes, as the device already possesses the necessary security materials without requiring complex real-time provisioning procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The secure element performs self-service authentication operations using the pre-provisioned master key. The device automatically handles authentication and key management functions without requiring complex external provisioning procedures, thereby improving security while reducing provisioning complexity and overhead.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If traditional network attachment procedures are used, then device connectivity is established, but vulnerability to denial-of-service attacks occurs

Engineering Contradiction:
Improvenetwork access efficiencyVSAvoiddenial-of-service attack susceptibility
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing secure authentication and authorization checks before allowing network attachment. The secure element verifies credentials and establishes secure contexts in advance, preventing unauthorized or malicious devices from exploiting vulnerabilities in traditional attachment procedures, thereby countering denial-of-service attacks before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent provides beforehand cushioning by establishing secure authentication frameworks and protective measures prior to network attachment. The pre-provisioned master key and secure authentication protocols create a protective buffer that shields the network from denial-of-service attacks, ensuring that even if attachment procedures are attempted by malicious devices, they cannot compromise network security.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS10271191B2Procedures to provision and attach a cellular internet of things device to a cloud service provider
Publication Date: 2019.04.23 APPLE INC
  • US10271191B2 patent drawing
  • US10271191B2 patent drawing
  • US10271191B2 patent drawing

AI summary

A cellular IoT (CIoT) device can comprise a coverage and/or processing constrained device e.g., devices operating primarily MTC or M2M (e.g., sensor devices, controller devices, etc.). These devices can have limited or no user interface, and can be used for machines or devices with little mobility. CIoT devices can be deployed in usage scenarios such as home automation (e.g., security, appliances, energy packages, etc.), industry automation, and smart cities with low-power devices (e.g., devices having a battery life of several years), and can be easily installed and operated in challenging coverage conditions, such as lower or basement levels of buildings. CIoT devices can be provisioned to connect to a cellular carrier network and an associated CSP. The CSP can execute end2end solutions (e.g., service portal, service sign-up, etc.) while the cellular carrier can provide the bulk data pipe to the CSP.