Integrated Identity Module Secure Credential Upload via Encrypted Tunnel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless network authentication methods, relying on SIM cards and UICC, are restrictive and lack secure over-the-air provisioning capabilities for 2G, 3G, and LTE networks, making it difficult to remotely manage and switch network operators for machine-to-machine devices without compromising security.

Innovation Solution

A method involving an authentication server and integrated identity module that securely uploads subscriber credentials using an X.509 certificate, tunnel establishment protocol stack, and client authentication, establishing a secured tunnel for opaque credential transfer, allowing remote configuration and operator switching without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIM cards or UICCs are used for authentication in 2G, 3G, and LTE networks, then high security is achieved, but the system becomes very restricting and requires manual card changes when switching network operators

Engineering Contradiction:
ImprovesecurityVSAvoidoperator switching
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses a virtual copy of subscriber credentials (IMSI, authentication keys) stored in a database on the authentication server, which can be remotely provisioned to the UICC. This virtual credential copy allows operator switching without physical card changes while maintaining security through encrypted over-the-air transfers.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an authentication server as an intermediary between the subscriber and network operators. This server stores credential databases and manages remote provisioning, enabling secure operator switching without requiring manual SIM card changes while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If remote over-the-air provisioning is implemented for credential transfer, then ease of operation and operator switching are improved, but security is compromised due to difficulty in ensuring high enough security in over-the-air transfer

Engineering Contradiction:
Improveremote provisioningVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent establishes security infrastructure in advance by implementing X.509 certificate-based authentication and TLS-encrypted communication channels before any credential transfer occurs. This preliminary security setup ensures that subsequent over-the-air provisioning operations maintain high security standards while enabling remote operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the security parameters of over-the-air communication by implementing mutual authentication using X.509 certificates and establishing TLS-encrypted tunnels. These parameter changes transform insecure wireless communication into a secure channel suitable for credential transfer, enabling remote provisioning without security compromise.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If physical SIM card changes are required for operator switching, then security is maintained, but device complexity and time consumption increase for large-scale deployments

Engineering Contradiction:
ImprovesecurityVSAvoidcard change time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates virtual copies of subscriber credentials in a database on the authentication server and enables remote provisioning of these credentials to the UICC. This eliminates the need for physical card changes, reducing time consumption and operational complexity while maintaining security through encrypted credential transfer and mutual authentication mechanisms.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2538707B1Method for uploading subscriber credentials and associated equipment
Publication Date: 2019.08.28 ALCATEL LUCENT SA
  • EP2538707B1 patent drawingFigure 1
  • EP2538707B1 patent drawingFigure 2
  • EP2538707B1 patent drawingFigure 3

AI summary

The present invention refers to a method for uploading subscriber credentials from a remote authentication server of a network operator (NOi) onto a user equipment equipped with a integrated identity module via a network wherein said integrated identity module comprises means to establish a secured tunnel with the authentication server and wherein said method comprises the following steps: - installing a tunnel establishment protocol stack, an X.509 certificate and a client authentication into the integrated identity module; - establishing a secured connection between the authentication server and the user equipment using the client authentication; - establishing a secured tunnel between the integrated identity module and the authentication server through the established secured connection using the X.509 certificate; - uploading the subscriber credentials from the authentication server onto the integrated identity module through the established secured tunnel.