Cloud SIM Management for Private Mobile Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing subscriber identification modules (SIMs) for private mobile networks is challenging due to the need for unique key exchanges and secure operations, especially when the number of SIMs requested is less than a typical batch, and there are thousands of private mobile networks, requiring efficient key management and secure transmission.

Innovation Solution

A method and device for SIM management in a private mobile network using a cloud computing system, where Ki and OPc values are generated and exchanged through APIs, allowing secure SIM operations, with a transport key for encrypted communications, and conflict checks to prevent overlapping IMSI values, enabling secure storage and transmission of SIM operations details.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional SIM ceremonies are used for each private mobile network, then security is maintained through key exchange, but the complexity and time required for managing thousands of private networks increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the SIM management process by introducing a cloud-based SIM management service that handles key generation and distribution separately from the private mobile network operations. This divides the complex SIM ceremony process into manageable components: the cloud service generates master keys and distributes them to SIM partners, while each private network receives only the specific keys it needs, reducing overall management complexity while maintaining security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cloud-based SIM management service as an intermediary between the network provider and SIM partners. This intermediary automates the key exchange process, generating keys on behalf of thousands of private networks and distributing them through APIs, thereby eliminating the need for manual SIM ceremonies at each network and reducing management complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If SIMs are issued in large batches for global networks, then efficiency is improved, but the impact of compromised SIMs affects a larger number of devices

Engineering Contradiction:
ImproveSIM issuance efficiencyVSAvoidcompromise impact
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments SIM keys into two parts: a master key stored securely in the cloud and device-specific keys stored on individual SIMs. This allows SIMs to be issued in batches efficiently while ensuring that if one SIM is compromised, only that specific device's key is affected, not the entire batch or global network keys

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by giving each SIM its own unique device-specific key derived from the master key, rather than using a single global key for all SIMs. This ensures that security compromise is localized to individual devices while maintaining efficient batch processing capabilities through the cloud-based key management system

Inventive Principle:
Principle #3Local quality

3Reliability

If unique keys are generated for each private mobile network, then security is enhanced, but the time and resources required for key management increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the cloud-based SIM management service pre-generate master keys and establish key derivation relationships before private networks are created. When a private network is instantiated, the system can quickly derive and distribute the specific keys needed without performing a complete key exchange ceremony, significantly reducing key management time while maintaining unique security for each network

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service by enabling the cloud-based SIM management service to automatically generate and distribute keys to SIM partners and private networks through automated APIs, eliminating the need for manual key management intervention and reducing the time and resources required for key management across thousands of networks

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11785468B2Subscriber identification module (SIM) management for cloud-based private mobile networks
Publication Date: 2023.10.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11785468B2 patent drawing
  • US11785468B2 patent drawing
  • US11785468B2 patent drawing

AI summary

The present disclosure relates to devices, methods, and systems for subscriber identification module (SIM) management for a private mobile network. The methods and systems may include a private mobile network service on a cloud computing system. Users of the cloud computing system may use the private mobile network service to create a private mobile network. The private mobile network service may facilitate the creation of the private mobile network by providing interfaces for secure communications with the users of the cloud computing system, the SIM service partners, and the packet core partners. The mobile network service may also manage the SIM cards for the private mobile networks by coordinating the transmission of the SIM operation details for the SIM cards.