Identity Module Initial Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mechanisms for providing initial network authentication to communications devices, particularly in constrained IoT devices, face challenges such as lack of user interfaces, reliance on temporary open networks, and the need for additional interfaces for configuration, which complicates secure and efficient initial connectivity and subscription management.

Innovation Solution

A method and system for initial network authentication using an identity module with remote subscription profile download capabilities, involving a message exchange with an authentication server to establish a master session key for secure communication, leveraging existing credentials and interfaces for mutual authentication and secure profile download.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network authentication mechanisms are used for constrained IoT devices, then security can be maintained, but additional interfaces and user interactions are required, increasing device complexity and cost

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identity module credentials are designed to serve dual purposes: traditional network authentication and the novel remote subscription profile download authentication. By making the credentials universal, the system eliminates the need for separate authentication interfaces while maintaining security, directly resolving the contradiction between security and device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service authentication where the identity module automatically performs mutual authentication with the authentication server using its embedded credentials. This eliminates the need for external configuration interfaces or user interactions, reducing device complexity while maintaining secure authentication

Inventive Principle:
Principle #25Self-service

2Ease of operation

If temporary open networks are used for initial connectivity, then devices can connect without additional interfaces, but network security and reliability are compromised

Engineering Contradiction:
Improveease of operationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The identity module is pre-provisioned with credentials during manufacturing that enable both initial network connectivity and subsequent secure authentication. This preliminary action eliminates the need to rely on temporary open networks, allowing devices to securely connect to closed networks from the first boot while maintaining ease of operation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication server acts as an intermediary that verifies the identity module credentials and establishes secure communication channels. This intermediary mechanism enables constrained devices to access closed secure networks without requiring additional interfaces or user configuration, resolving the contradiction between ease of operation and network security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate authentication interfaces are added for initial connectivity, then network security is improved, but device cost and complexity increase

Engineering Contradiction:
Improvenetwork securityVSAvoidease of manufacture
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The identity module credentials are designed to serve dual purposes: traditional network authentication and the novel remote subscription profile download authentication. By making the credentials universal, the system eliminates the need for separate authentication interfaces while maintaining security, directly resolving the contradiction between security and device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the authentication function and subscription profile download function into a single unified process using the same identity module credentials. This consolidation eliminates the need for separate hardware interfaces or additional security modules, maintaining network security while improving ease of manufacture

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11863663B2Initial network authorization for a communications device
Publication Date: 2024.01.02 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11863663B2 patent drawing
  • US11863663B2 patent drawing
  • US11863663B2 patent drawing

AI summary

There is provided mechanisms for initial network authentication between a communications device and a network. A method is performed by the communications device. The communications device comprises an identity module supporting remote subscription profile download. The identity module comprises credentials for remote subscription profile download. The method comprises performing a first message exchange with an authentication server. The first message exchange comprises an identity module challenge obtained from the identity module being transmitted to the authentication server from the communications device. The method comprises receiving a second message from the authentication server. The second message comprises an ephemeral public key of the authentication server, an authentication server challenge and an authentication server signature. The authentication server signature is based on the ephemeral public key of the authentication server, the authentication server challenge, and the identity module challenge and follows a format used for handling remote subscription profile download to the identity module. The method comprises transmitting a third message towards the authentication server. The third message comprises an ephemeral public key of the communications device and an identity module signature. The identity module signature is based on the identity module credentials used for remote subscription profile download and is based on the ephemeral public key of the communications device and the authentication server challenge and follows the format used for remote subscription profile download to the identity module. The method comprises generating a master session key (MSK) from a shared secret established using the ephemeral public key of the authentication server and a private key corresponding to the ephemeral public key of the communications device. The MSK is for use when establishing secure communication between the communications device and the network.