Non-provisioned IoT Device Cellular Subscription Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to efficiently integrate non-provisioned cellular Internet of Things (IoT) devices into existing users' network operator and service provider accounts, particularly in challenging coverage conditions such as indoors or basements, and lack efficient security authentication processes.

Innovation Solution

The system employs out-of-band communication methods like NFC, Bluetooth Low Energy, or Low Power Wi-Fi to establish a security association between non-provisioned IoT devices and users' smartphones, enabling verification through a certificate authority and secure connection to the cellular network, allowing for easy addition of devices to both network and service provider accounts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cellular network provisioning methods are used for IoT devices, then network security is maintained, but operational time and complexity increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidoperational time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring IoT devices with security certificates and authentication credentials during manufacturing. This allows devices to be rapidly provisioned upon activation without requiring time-consuming network-based security setups, thus reducing operational time while maintaining security through pre-established credentials

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary provisioning server that acts as a mediator between the cellular network and IoT devices. This server handles security authentication and credential distribution, separating the security function from the main provisioning process and enabling faster device integration without compromising network security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If non-provisioned IoT devices are integrated into existing accounts, then ease of operation improves, but device complexity and security verification requirements increase

Engineering Contradiction:
Improveease of device additionVSAvoidsecurity verification process
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the device provisioning process with the user's existing account authentication. By combining device registration with the user's established credentials and security context, the system simplifies the operational process while maintaining comprehensive security verification through the integrated authentication framework

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If out-of-band communication methods are used for device activation, then ease of operation improves, but use of energy increases

Engineering Contradiction:
Improveease of device activationVSAvoidenergy consumption
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The patent employs periodic action by using out-of-band communication (such as NFC or Bluetooth) only during the initial device activation and provisioning phase. After provisioning is complete, the system transitions to standard cellular communication for ongoing operations, thus minimizing energy consumption while maintaining ease of operation during the critical activation phase

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11026086B2Systems, methods and devices for adding non-provisioned cellular devices to a subscription
Publication Date: 2021.06.01 APPLE INC
  • US11026086B2 patent drawing
  • US11026086B2 patent drawing
  • US11026086B2 patent drawing

AI summary

Non-pre-provisioned cellular Internet of things (IoT) devices can be added to an existing user's subscription with an operator and a service provider. The procedure can include obtaining a security association between a device and a user's smartphone using the operator's network. The operator and the service provider can verify the device with a certificate authority. In one embodiment, the smartphone reads (302) a URL pointer to the device certification and sends it (304) to the MME. The MME forwards (306) the URL to the HSS. The HSS verifies (312) the certificate and derives security credentials including the Master key K′. The HSS also derives another key K″ used to establish security context between the IoT device and the smartphone. The device uses its key deriving function KDF with K′ and Rand to generate K″.