IoT Device Identity Profile Provisioning via Secure Element

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for provisioning IoT devices with identity profiles are complex and require a special provisioning network, making it difficult to securely bind devices to a network in the field.

Innovation Solution

A system that uses a provisioning key and device identifier stored on the device to initiate non-provisioned communication with a profile provisioner, which obtains a security key from a provisioning server to establish a secure connection with an identity profile issuer, allowing the device to receive its identity profile for provisioned communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a special provisioning network is used to securely provision IoT devices with identity profiles, then device security and network binding are improved, but system complexity and provisioning cost increase

Engineering Contradiction:
Improvedevice securityVSAvoidprovisioning system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the provisioning key storage function from the network infrastructure and places it directly on the device in a secure element. This eliminates the need for a complex special provisioning network while maintaining security, as the device itself now holds the cryptographic credentials needed for secure communication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a simplified intermediary model where the secure element on the device acts as the mediator between the device and the network. Instead of requiring a complex provisioning network infrastructure, the secure element with stored provisioning keys directly enables authenticated communication, reducing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If SIM cards are used to store identity profiles for device identification and security, then device authentication and network security are improved, but device cost and physical complexity increase

Engineering Contradiction:
Improvedevice authenticationVSAvoiddevice physical complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the identity profile storage function from the physical SIM card and integrates it into the device's secure element. This eliminates the need for a removable SIM card while maintaining authentication security, as the provisioning keys are stored securely within the device itself.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges the SIM card's identity profile storage function with the device's secure element. By combining these functions into a single integrated secure storage mechanism within the device, the patent eliminates the need for separate SIM cards while maintaining authentication capabilities.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If embedded SIM remote provisioning architecture is used to provision devices not bound to a network, then device provisioning capability is improved, but system complexity and provisioning infrastructure requirements increase

Engineering Contradiction:
Improvedevice provisioning capabilityVSAvoidprovisioning infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-provisioning the device with provisioning keys in the secure element before the device is activated or deployed. This allows the device to immediately establish secure communication without requiring complex runtime provisioning infrastructure, as the cryptographic credentials are already in place.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3360358B1Identity profile provisioning technique
Publication Date: 2020.07.22 HUAWEI TECH CO LTD
  • EP3360358B1 patent drawingFigure 1A
  • EP3360358B1 patent drawingFigure 1B
  • EP3360358B1 patent drawingFigure 1C

AI summary

An apparatus for providing an identity profile to a device includes an interface and at least one processor. The device is provisionable for communicating over a network using the identity profile. The interface is adapted for provisioned and non-provisioned communications with devices connected to the network. The devices have respective provisioning keys and provisioning device identifiers. The processor executes code instructions to: i) receive, from a device by non-provisioned communications, a request for an identity profile. The request includes a respective provisioning device identifier of the device; ii) obtain a security key from a provisioning server. The security key is based on a provisioning key indexed to the respective provisioning device identifier and is used for establishing a secure connection with the device; and iii) instruct a profile issuer to send the identity profile to the device over a secure connection established using the security key.