End Device Profile Provisioning with Temporary Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing third-party subscription management systems for end device profiles pose security risks due to the use of temporary and sensitive network information, which can compromise network and device security during activation and initial connectivity.

Innovation Solution

Implementing a third-party subscription management service that provisions temporary keysets, temporary USIMs, or blank USIMs, followed by updating them to permanent keysets or USIMs, ensuring secure activation and registration processes for end devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If third-party subscription management systems use temporary network information for activation, then device activation and initial connectivity are enabled, but security exposures and network security risks increase

Engineering Contradiction:
Improvedevice activationVSAvoidsecurity exposures
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary provisioning of temporary profiles and keysets before device activation, enabling seamless initial connectivity while maintaining security control. The temporary profile is pre-configured with limited permissions that are automatically upgraded after successful activation, eliminating the need for manual security configurations during the critical activation phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a subscription management system as an intermediary layer between the network and end devices. This intermediary provisions temporary profiles that act as secure mediators during activation, allowing devices to connect without exposing permanent network credentials. The temporary profile serves as a controlled bridge that is replaced after successful activation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If temporary keysets are used for initial connectivity, then device registration is enabled, but network information security is compromised

Engineering Contradiction:
Improvedevice registration speedVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The authentication credentials are segmented into temporary keysets for initial connectivity and permanent keysets for ongoing operation. The temporary keyset is provisioned separately and used only during the activation phase, then replaced by the permanent keyset. This segmentation allows fast registration while isolating permanent network credentials from exposure during the vulnerable activation window.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes the security parameters of the device profile during activation. Initially, the device operates with temporary credentials having limited scope and duration. Upon successful activation and registration, the system transitions the device to use permanent credentials with full network access permissions. This parameter change ensures both rapid onboarding and sustained security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12457484B2Method and system for third party subscription management of end device profiles
Publication Date: 2025.10.28 VERIZON PATENT & LICENSING INC
  • US12457484B2 patent drawing
  • US12457484B2 patent drawing
  • US12457484B2 patent drawing

AI summary

A method, a device, and a non-transitory storage medium are described in which a third party subscription management of end device profiles service is provided. The service may include obtaining a profile for a card of an end device from a third party device in which the profile includes a temporary element. For example, the temporary element may be a temporary keyset or a temporary USIM. During initial connectivity and activation with a core network, the card logic may obtain and update the profile with a permanent element for registration and activation procedures with the core network. In this way, security exposure with a third party device relating to a profile may be eliminated or minimized.