CMP-DMP Dual-Token Security for eSIM Device Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure device onboarding processes lack security across entities, risking exposure of secrets/keys and compromising trust between enterprises and wireless devices, leading to potential unauthorized access and misconfiguration.

Innovation Solution

A security schema involving a Connectivity Management Platform (CMP) and Device Management Platform (DMP) generates user-specific and organization-specific access tokens to authenticate and verify the ownership of eSIMs, ensuring secure device provisioning without manual intervention, using dual verification mechanisms to establish trust between users, organizations, and devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing secure device onboarding processes are used, then device provisioning can be performed, but security is compromised and secrets/keys are exposed

Engineering Contradiction:
ImprovesecurityVSAvoidexposure of secrets/keys
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments authentication credentials into two separate tokens: a first token generated by the CMP containing a first secret, and a second token generated by the DMP containing a second secret. This segmentation ensures that no single entity possesses both secrets, preventing complete compromise of the authentication system even if one token is exposed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the CMP and DMP act as mediators between the wireless device and the network. The dual-token system serves as an intermediary layer that verifies both the device's identity and the operator's authorization without exposing underlying secrets, thereby enhancing security while enabling device provisioning.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual intervention is used for device provisioning, then configuration can be customized, but the process is time-consuming and error-prone

Engineering Contradiction:
Improvedevice provisioning speedVSAvoidconfiguration errors
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system enables self-service device provisioning through automated token verification. The wireless device autonomously presents the first token to the CMP and the second token to the DMP, which automatically verify the tokens and complete the provisioning process without manual intervention. This eliminates configuration errors associated with manual processes while maintaining high customization through the token-based authorization system.

Inventive Principle:
Principle #25Self-service

3Reliability

If dual verification mechanisms are implemented, then trust is established between entities, but system complexity increases

Engineering Contradiction:
Improvetrust establishmentVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification process is segmented into two independent but complementary steps: CMP verification of the first token and DMP verification of the second token. This segmentation distributes complexity across multiple specialized components rather than concentrating it in a single complex verification system, making the overall process more manageable and reliable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The dual-token system serves multiple functions simultaneously: it establishes trust between the device and network, verifies operator authorization, enables secure provisioning, and provides audit capabilities. This multi-functionality justifies the added complexity by delivering comprehensive security and operational benefits in a unified framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If access tokens are generated for each user and organization, then unauthorized access is prevented, but computational overhead increases

Engineering Contradiction:
Improveaccess controlVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Access tokens are generated in advance during device provisioning and stored securely in the wireless device. The first token from CMP and second token from DMP are created beforehand, eliminating the need for real-time computational verification of user credentials during actual access attempts. This preliminary action shifts computational overhead to the provisioning phase, making subsequent access control operations more efficient.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12407678B2Security schema for secure device onboarding
Publication Date: 2025.09.02 CISCO TECHNOLOGY INC
  • US12407678B2 patent drawing
  • US12407678B2 patent drawing
  • US12407678B2 patent drawing

AI summary

Presented herein are a system and secure device onboarding techniques. A Connectivity Management Platform (CMP) receives a request for an access token that includes a user identifier, a customer organization identifier, and an authorization code from a Device Management Platform (DMP), verifies the authorization code, queries an enterprise server using the user identifier and the customer organization identifier to confirm the user belongs to the customer organization, generates the access token, stores the access token in an authentication datastore, and transmits the access token to DMP. The CMP receives a provisioning request including an eSIM identifier of a device and an access token from the DMP, verifies the access token, obtains a customer organization identifier based thereon, queries an enterprise server using the eSIM identifier and the customer organization identifier to confirm the device belongs to the customer organization, and facilitates secure provisioning of the device with an eSIM profile.