IoT Data Exchange via SIM BOOT-IMSI and Authentication Error Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for secured data exchange between IoT devices and IoT background systems over mobile communication networks are slow due to the overhead of the authentication procedure, especially when small amounts of data are transmitted, and the limited availability and cost of individually assigned IMSIs.

Innovation Solution

A method utilizing a BOOT-IMSI for attach requests and sending data in an authentication error message, allowing parallel data transmission during an incomplete attach and authentication procedure, thereby reducing communication overhead and eliminating the need for individually assigned IMSIs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional attach and authentication procedure is performed for secured data exchange, then security is ensured, but the communication speed becomes slow due to authentication overhead

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent pre-provisions multiple BOOT-IMSIs in the SIM card before the device needs to communicate. This preliminary preparation eliminates the need for real-time IMSI assignment or authentication completion, allowing the device to immediately use a pre-configured BOOT-IMSI for data transmission, thus resolving the contradiction between security (through pre-configured authentication credentials) and speed (by eliminating authentication delays).

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If individually assigned IMSIs are used for each mobile communication device, then device identification and authentication are enabled, but the cost increases and availability is limited

Engineering Contradiction:
Improvedevice identification capabilityVSAvoidnumber of available IMSIs
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent uses BOOT-IMSIs that are pre-provisioned in the SIM card as temporary identifiers during the attach procedure. These BOOT-IMSIs serve as functional copies that enable device identification and network attachment without requiring unique, permanently assigned IMSIs for each device. This copying approach allows multiple devices to use available BOOT-IMSI values temporarily, resolving the contradiction between device identification capability and the limited quantity of permanently assignable IMSIs.

Inventive Principle:
Principle #26Copying

3Reliability

If the complete attach and authentication procedure is executed, then secured communication is established, but the overhead is large compared to small amounts of data to be transmitted

Engineering Contradiction:
Improvesecured communicationVSAvoidprocedure overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and utilizes specific elements of the authentication procedure (the BOOT-IMSI provisioned in the SIM card and the challenge-response mechanism) while bypassing the need for complete traditional attach and authentication completion. By taking out only the essential security elements needed for small data transmissions and eliminating unnecessary procedural steps, the patent reduces procedure overhead while maintaining secured communication, resolving the contradiction between reliability and device complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4387168A1Secured exchange of data between an IoT device and an IoT background system over the attach procedure of a mobile communication network
Publication Date: 2024.06.19 GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
  • EP4387168A1 patent drawingFigure 1
  • EP4387168A1 patent drawingFigure 2
  • EP4387168A1 patent drawingFigure 2

AI summary

A method for secured exchange of data between an loT device and an loT background system over a mobile communication network, comprises the steps: a) ([4]) By the device provide data-read (DATA-READ) to the SIM; b) ([5]) By the SIM, provide a BOOT-IMSI to the device; c) ([6]) By the device, send an attach request using the BOOT-IMSI to the loT background system over the mobile communication network; d) ([7]) By the loT background system, provide, particularly receive or generate, a random SEED, and send to the SIM over the mobile communication network a challenge message for a challenge-response authentication procedure, the challenge message comprising the random SEED, RAND, AUTN; e) ([8]) By the SIM: - create a packet including the data-read (DATA-READ); - create an authentication error message and send the packet to the loT background system over the mobile network in the authentication error message; f) At the loT background system: - receive the packet and extract the data-read (DATA-READ).