IoT Key Distribution Without USIM Cards

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for secure communication in IoT devices that do not support USIM cards are ineffective, as they rely on root keys stored in USIM cards, which low-cost IoT devices cannot implement, leading to insecure communication channels.

Innovation Solution

A key distribution and authentication method where a service center server generates unique keys for terminal devices using various parameter sets, including random numbers, fresh parameters, and shared keys, allowing these devices to perform mutual authentication with network authentication servers, establishing secure communication channels without requiring USIM cards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If AKA protocol-based authentication is used, then secure communication is achieved, but USIM card support is required which increases device complexity and cost

Engineering Contradiction:
Improvecommunication securityVSAvoiddevice structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functionality from the USIM card dependency. Instead of requiring a USIM card to store the root key, the system extracts the root key storage function to a remote key management server, allowing terminal devices to perform authentication without physical USIM cards while maintaining security through cloud-based key management

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a key management server as an intermediary between the network and terminal devices. This mediator generates, manages, and distributes authentication keys to terminals, enabling devices without USIM cards to participate in secure authentication through the AKA protocol by receiving keys from this intermediate authority

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If USIM cards are deployed in all devices, then authentication capability is improved, but device cost and complexity increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoiddevice cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent creates a universal authentication system where the key management server serves multiple functions: generating keys for new devices, distributing keys to existing devices, updating keys, and managing device lifecycles. This multi-functional approach eliminates the need for each device to have dedicated USIM card infrastructure, reducing manufacturing complexity while maintaining broad authentication capability across diverse device types

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces the physical USIM card with a virtual key representation stored and managed remotely. Instead of each device needing a physical security element, the system uses cryptographic copies of authentication credentials that can be securely distributed and managed through the key management server, enabling low-cost devices to achieve the same authentication capability

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11240218B2Key distribution and authentication method and system, and apparatus
Publication Date: 2022.02.01 HUAWEI TECH CO LTD
  • US11240218B2 patent drawing
  • US11240218B2 patent drawing
  • US11240218B2 patent drawing

AI summary

This application provides a key distribution and authentication method, system, and an apparatus. The method includes: a service center server distributes different keys to terminal devices, and then the terminal devices perform mutual authentication with the network authentication server based on respective keys and finally obtain communication keys for communication between the terminal devices and a functional network element. This provides a method for establishing a secure communication channel for the terminal device, having a broad application range.