CMP-DMP Dual-Token Security for eSIM Device Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure device onboarding processes lack security across entities, risking exposure of secrets/keys and compromising trust between enterprises and wireless devices, leading to potential unauthorized access and misconfiguration.
Innovation Solution
A security schema involving a Connectivity Management Platform (CMP) and Device Management Platform (DMP) generates user-specific and organization-specific access tokens to authenticate and verify the ownership of eSIMs, ensuring secure device provisioning without manual intervention, using dual verification mechanisms to establish trust between users, organizations, and devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing secure device onboarding processes are used, then device provisioning can be performed, but security is compromised and secrets/keys are exposed
Solution Approach 1:
The system segments authentication credentials into two separate tokens: a first token generated by the CMP containing a first secret, and a second token generated by the DMP containing a second secret. This segmentation ensures that no single entity possesses both secrets, preventing complete compromise of the authentication system even if one token is exposed.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the CMP and DMP act as mediators between the wireless device and the network. The dual-token system serves as an intermediary layer that verifies both the device's identity and the operator's authorization without exposing underlying secrets, thereby enhancing security while enabling device provisioning.
2Productivity
If manual intervention is used for device provisioning, then configuration can be customized, but the process is time-consuming and error-prone
Solution Approach 1:
The system enables self-service device provisioning through automated token verification. The wireless device autonomously presents the first token to the CMP and the second token to the DMP, which automatically verify the tokens and complete the provisioning process without manual intervention. This eliminates configuration errors associated with manual processes while maintaining high customization through the token-based authorization system.
3Reliability
If dual verification mechanisms are implemented, then trust is established between entities, but system complexity increases
Solution Approach 1:
The verification process is segmented into two independent but complementary steps: CMP verification of the first token and DMP verification of the second token. This segmentation distributes complexity across multiple specialized components rather than concentrating it in a single complex verification system, making the overall process more manageable and reliable.
Solution Approach 2:
The dual-token system serves multiple functions simultaneously: it establishes trust between the device and network, verifies operator authorization, enables secure provisioning, and provides audit capabilities. This multi-functionality justifies the added complexity by delivering comprehensive security and operational benefits in a unified framework.
4Reliability
If access tokens are generated for each user and organization, then unauthorized access is prevented, but computational overhead increases
Solution Approach 1:
Access tokens are generated in advance during device provisioning and stored securely in the wireless device. The first token from CMP and second token from DMP are created beforehand, eliminating the need for real-time computational verification of user credentials during actual access attempts. This preliminary action shifts computational overhead to the provisioning phase, making subsequent access control operations more efficient.
Data Source
AI summary
Presented herein are a system and secure device onboarding techniques. A Connectivity Management Platform (CMP) receives a request for an access token that includes a user identifier, a customer organization identifier, and an authorization code from a Device Management Platform (DMP), verifies the authorization code, queries an enterprise server using the user identifier and the customer organization identifier to confirm the user belongs to the customer organization, generates the access token, stores the access token in an authentication datastore, and transmits the access token to DMP. The CMP receives a provisioning request including an eSIM identifier of a device and an access token from the DMP, verifies the access token, obtains a customer organization identifier based thereon, queries an enterprise server using the eSIM identifier and the customer organization identifier to confirm the device belongs to the customer organization, and facilitates secure provisioning of the device with an eSIM profile.


