IoT Device Network Authentication via Companion UE

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies cannot satisfy the requirement of remotely obtaining an operator credential for Internet of Things (IoT) devices that do not have a pre-issued credential, making it difficult for them to access a cellular network.

Innovation Solution

A terminal device without a pre-issued credential can obtain a shared key for network authentication by using a companion device that holds a credential, through a Diffie-Hellman key exchange process, allowing it to access the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If IoT devices are delivered without pre-configured credentials to reduce costs and simplify deployment, then operational costs and deployment complexity are reduced, but the ability to remotely download operator credentials is lost

Engineering Contradiction:
Improvedeployment simplicityVSAvoidnetwork access capability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent introduces a companion UE as an intermediary device that bridges the IoT device and the network. The companion UE holds the credential and assists the IoT device in obtaining authentication credentials through key exchange protocols, enabling the IoT device to access the network without having a pre-configured credential

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional SIM cards are used in IoT devices to ensure security and stability, then authentication security is improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the credential storage function from the IoT device itself and places it in the companion UE. The IoT device only needs to store temporary authentication credentials obtained through key exchange, while the permanent credential remains in the companion UE, significantly reducing the IoT device's complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The companion UE acts as an intermediary that handles credential management and authentication operations, allowing the IoT device to benefit from secure authentication without incorporating a complex SIM card or credential management system

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If eSIM with remote credential configuration is used to enable flexible network access, then adaptability is improved, but the requirement for initial credential configuration increases device complexity

Engineering Contradiction:
Improveremote credential configuration capabilityVSAvoidinitial credential requirement
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The companion UE serves as an intermediary that enables remote credential configuration for the IoT device without requiring the IoT device itself to have initial credentials. The companion UE uses its own credential to facilitate the credential download process to the IoT device

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service credential provisioning where the IoT device can autonomously obtain credentials through the companion UE without manual configuration or pre-provisioning, making the credential acquisition process automatic and simplifying deployment

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables IoT devices to access a cellular network by establishing a secure authentication channel without requiring a pre-configured credential, simplifying the initial network attachment process and reducing operational costs.

Implementation Method 1

a terminal device not having a credential pre-issued by an operator may obtain, from the server in a DH key exchange manner by using another terminal device holding a credential, a shared key used for authentication with an operator network

Methodology Applied
Scientific EffectDiffie-Hellman key exchange:

Data Source

PatentEP3493502B1Supplying an IOT-device with an authentication key
Publication Date: 2021.06.09 HUAWEI TECH CO LTD
  • EP3493502B1 patent drawingFigure 1~2
  • EP3493502B1 patent drawingFigure 3~4
  • EP3493502B1 patent drawingFigure 5~7

AI summary

This application discloses a mobile network authentication method, a terminal device, a server, and a network authentication entity. The method includes: receiving, by a first terminal device, a DH public key and a first ID that are sent by at least one second terminal device; sending, by the first terminal device, a first message to a server, where the first message includes a DH public key of each second terminal device of the at least one second terminal device and a first ID of the second terminal device; receiving, by the first terminal device, a second message sent by the server, where the second message includes a DH public key of the server and a second ID of the second terminal device that is generated by the server; and sending, by the first terminal device, the second ID of the second terminal device and the DH public key of the server to the second terminal device. In this way, even if a terminal device does not have a credential pre-issued by an operator network, the terminal device can still obtain a credential of the operator network.