Communication Device Network Credential Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for providing network credentials to communication devices are costly and inflexible, particularly for ultra-low cost terminals like those needed for the Internet of Things, and existing software-based SIM simulations face difficulties in replicating full SIM functionality and managing remote provisioning.
Innovation Solution
A method and system where a communication device stores identities associated with itself and a provisioning agent, transmitting a registration request to a network to receive network credentials, which are then encrypted and securely transmitted, allowing the device to access communication resources without initial bearer details being installed during manufacturing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If initial bearer details are installed on each terminal during manufacture, then network credentials are available for immediate use, but manufacturing complexity increases and flexibility for network operator changes is reduced
Solution Approach 1:
The terminal is pre-configured with a unique identifier and cryptographic keys during manufacture, but not full network credentials. This preliminary action enables the terminal to autonomously register with a network operator later, avoiding the need to install complete bearer details during manufacturing while still preparing the terminal for immediate network access.
Solution Approach 2:
The terminal autonomously performs network registration and credential acquisition without requiring manual configuration or pre-installed network credentials. The terminal uses its pre-configured identifier and keys to self-register with a network operator, obtaining credentials independently, which reduces manufacturing complexity while maintaining ease of operation.
2Ease of manufacture
If software-based SIM simulation is used, then terminal cost is reduced, but difficulties arise in simulating full SIM functionality and managing remote provisioning
Solution Approach 1:
The invention extracts the essential security and identification functions from the traditional SIM card concept, implementing only the critical elements (unique identifier, cryptographic keys for authentication) in software within the terminal. This selective extraction reduces terminal cost while maintaining sufficient functionality for network access and security.
Solution Approach 2:
The invention changes the implementation parameters of SIM functionality from hardware-based (physical SIM card) to software-based (virtual SIM), and further to a hybrid approach where minimal security parameters (keys and identifiers) are stored in secure terminal memory. This parameter change reduces cost while maintaining security and functionality through cryptographic authentication mechanisms.
3Ease of manufacture
If eUICC is embedded in the terminal, then terminal cost is reduced, but initial bearer details must be installed during manufacture which reduces flexibility
Solution Approach 1:
The invention implements a dynamic credential acquisition process where the terminal can register with and switch between different network operators after manufacture. Unlike static eUICC solutions requiring pre-configured bearer details, this approach allows the terminal to dynamically obtain credentials from any network operator, enhancing adaptability while maintaining cost efficiency through software-based implementation.
Solution Approach 2:
The terminal is designed with universal compatibility to work with multiple network operators without requiring operator-specific hardware or pre-installed credentials. The software-based identifier and key system can authenticate with any network operator that supports the registration protocol, providing multi-functionality and flexibility while keeping terminal cost low.
Data Source
AI summary
A method for providing a communication device with credentials to enable it to access communication resources provided by a network operator, the method comprising storing, on the communication device, an indication of (i) an identity associated with the communication device; and (ii) an identity associated with a provisioning agent, transmitting, from the communication device to a communication network, a registration request that identifies the communication device and the provisioning agent, the provisioning agent providing, in response to the registration request, credentials to enable the communication device to access communication resources provided by a network operator and transmitting said credentials from the communication network to the communication device.


