Integrated Identity Module Secure Credential Upload via Encrypted Tunnel
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless network authentication methods, relying on SIM cards and UICC, are restrictive and lack secure over-the-air provisioning capabilities for 2G, 3G, and LTE networks, making it difficult to remotely manage and switch network operators for machine-to-machine devices without compromising security.
Innovation Solution
A method involving an authentication server and integrated identity module that securely uploads subscriber credentials using an X.509 certificate, tunnel establishment protocol stack, and client authentication, establishing a secured tunnel for opaque credential transfer, allowing remote configuration and operator switching without manual intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIM cards or UICCs are used for authentication in 2G, 3G, and LTE networks, then high security is achieved, but the system becomes very restricting and requires manual card changes when switching network operators
Solution Approach 1:
The patent uses a virtual copy of subscriber credentials (IMSI, authentication keys) stored in a database on the authentication server, which can be remotely provisioned to the UICC. This virtual credential copy allows operator switching without physical card changes while maintaining security through encrypted over-the-air transfers.
Solution Approach 2:
The patent introduces an authentication server as an intermediary between the subscriber and network operators. This server stores credential databases and manages remote provisioning, enabling secure operator switching without requiring manual SIM card changes while maintaining high security standards.
2Ease of operation
If remote over-the-air provisioning is implemented for credential transfer, then ease of operation and operator switching are improved, but security is compromised due to difficulty in ensuring high enough security in over-the-air transfer
Solution Approach 1:
The patent establishes security infrastructure in advance by implementing X.509 certificate-based authentication and TLS-encrypted communication channels before any credential transfer occurs. This preliminary security setup ensures that subsequent over-the-air provisioning operations maintain high security standards while enabling remote operation.
Solution Approach 2:
The patent changes the security parameters of over-the-air communication by implementing mutual authentication using X.509 certificates and establishing TLS-encrypted tunnels. These parameter changes transform insecure wireless communication into a secure channel suitable for credential transfer, enabling remote provisioning without security compromise.
3Reliability
If physical SIM card changes are required for operator switching, then security is maintained, but device complexity and time consumption increase for large-scale deployments
Solution Approach 1:
The patent creates virtual copies of subscriber credentials in a database on the authentication server and enables remote provisioning of these credentials to the UICC. This eliminates the need for physical card changes, reducing time consumption and operational complexity while maintaining security through encrypted credential transfer and mutual authentication mechanisms.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention refers to a method for uploading subscriber credentials from a remote authentication server of a network operator (NOi) onto a user equipment equipped with a integrated identity module via a network wherein said integrated identity module comprises means to establish a secured tunnel with the authentication server and wherein said method comprises the following steps: - installing a tunnel establishment protocol stack, an X.509 certificate and a client authentication into the integrated identity module; - establishing a secured connection between the authentication server and the user equipment using the client authentication; - establishing a secured tunnel between the integrated identity module and the authentication server through the established secured connection using the X.509 certificate; - uploading the subscriber credentials from the authentication server onto the integrated identity module through the established secured tunnel.