Deriving Network Credentials for Unsubscribed IoT Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic devices without a subscription to a telecommunications network cannot access the network independently, relying on a gateway device with a subscription, which limits their functionality and requires a security module like a USIM.
Innovation Solution
An electronic device communicates with an authentication support system over a first network to obtain a derived device identifier and credential, based on a gateway device's identifier and credential, allowing it to access the telecommunications network without a direct subscription, using these derived parameters for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If electronic devices use the gateway device's subscription directly, then they can access the telecommunications network, but the gateway device's connection must be maintained for other devices which limits independence
Solution Approach 1:
The gateway device's subscription is segmented into multiple derived subscriptions, each assigned to specific electronic devices. This segmentation allows each device to have its own authentication credentials while the gateway maintains its master subscription, resolving the contradiction between device independence and connection stability.
Solution Approach 2:
Derived subscriptions are pre-configured and stored in electronic devices before they need to access the network independently. This preliminary action enables devices to authenticate autonomously without requiring real-time connection to the gateway, achieving both independence and reliability.
2Adaptability or versatility
If electronic devices have individual subscriptions, then they can access the network independently, but device complexity and cost increase
Solution Approach 1:
Instead of requiring full individual subscriptions, the system creates simplified derived subscriptions that copy only the necessary authentication elements from the gateway's master subscription. This reduces device complexity while maintaining independent access capability.
Solution Approach 2:
The derived subscription mechanism provides a universal solution that enables multiple device types (IoT devices, wearables, vehicles) to access the network independently without requiring full subscription management infrastructure, achieving multi-functionality with reduced complexity.
3Device complexity
If electronic devices lack security modules like USIM, then device cost and complexity are reduced, but they cannot authenticate with the telecommunications network
Solution Approach 1:
The authentication capability is extracted from the traditional USIM card format and implemented as software-based derived credentials stored in the device's memory. This extraction eliminates the need for physical security modules while maintaining authentication reliability through cryptographic verification of derived device credentials.
Data Source
Figure 1~2A
Figure 2B~2C
Figure 3
AI summary
The disclosure pertains to an electronic device, an authentication support system and a telecommunication system for a telecommunications network enabling the electronic device to access the telecommunications network without a subscription. One aspect of the disclosure involves the electronic device to provide an electronic device identifier over the first network to the authentication support system. The electronic device is also configured to receive at least a derived device identifier and a derived device credential from the authentication support system over the first network. The derived device identifier may be based on at least the gateway device identifier and the electronic device identifier. The derived device credential may be based on at least the gateway device credential and the electronic device identifier. The electronic device is configured to include the derived device identifier in the network access request and transmit the network access request including the derived device identifier to the second network. The derived device credential may also be stored in the electronic device to enable the electronic device to participate in an authentication procedure with the telecommunication system. The electronic device may be configured to participate in the authentication procedure with the telecommunication system over the second network in response to the network access request and to use the derived device credential received in the authentication procedure with the telecommunication system.