IoT Device Identity Profile Provisioning via Secure Element
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for provisioning IoT devices with identity profiles are complex and require a special provisioning network, making it difficult to securely bind devices to a network in the field.
Innovation Solution
A system that uses a provisioning key and device identifier stored on the device to initiate non-provisioned communication with a profile provisioner, which obtains a security key from a provisioning server to establish a secure connection with an identity profile issuer, allowing the device to receive its identity profile for provisioned communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a special provisioning network is used to securely provision IoT devices with identity profiles, then device security and network binding are improved, but system complexity and provisioning cost increase
Solution Approach 1:
The patent extracts the provisioning key storage function from the network infrastructure and places it directly on the device in a secure element. This eliminates the need for a complex special provisioning network while maintaining security, as the device itself now holds the cryptographic credentials needed for secure communication.
Solution Approach 2:
The patent introduces a simplified intermediary model where the secure element on the device acts as the mediator between the device and the network. Instead of requiring a complex provisioning network infrastructure, the secure element with stored provisioning keys directly enables authenticated communication, reducing overall system complexity.
2Reliability
If SIM cards are used to store identity profiles for device identification and security, then device authentication and network security are improved, but device cost and physical complexity increase
Solution Approach 1:
The patent extracts the identity profile storage function from the physical SIM card and integrates it into the device's secure element. This eliminates the need for a removable SIM card while maintaining authentication security, as the provisioning keys are stored securely within the device itself.
Solution Approach 2:
The patent merges the SIM card's identity profile storage function with the device's secure element. By combining these functions into a single integrated secure storage mechanism within the device, the patent eliminates the need for separate SIM cards while maintaining authentication capabilities.
3Adaptability or versatility
If embedded SIM remote provisioning architecture is used to provision devices not bound to a network, then device provisioning capability is improved, but system complexity and provisioning infrastructure requirements increase
Solution Approach 1:
The patent applies preliminary action by pre-provisioning the device with provisioning keys in the secure element before the device is activated or deployed. This allows the device to immediately establish secure communication without requiring complex runtime provisioning infrastructure, as the cryptographic credentials are already in place.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
An apparatus for providing an identity profile to a device includes an interface and at least one processor. The device is provisionable for communicating over a network using the identity profile. The interface is adapted for provisioned and non-provisioned communications with devices connected to the network. The devices have respective provisioning keys and provisioning device identifiers. The processor executes code instructions to: i) receive, from a device by non-provisioned communications, a request for an identity profile. The request includes a respective provisioning device identifier of the device; ii) obtain a security key from a provisioning server. The security key is based on a provisioning key indexed to the respective provisioning device identifier and is used for establishing a secure connection with the device; and iii) instruct a profile issuer to send the identity profile to the device over a secure connection established using the security key.