Secure IoT Ownership Transfer via Roll-over Token
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current machine-to-machine (M2M) and Internet of Things (IoT) devices face challenges in securely and efficiently transferring ownership and updating credentials, particularly when switching between owners, as existing methods are costly, inefficient, and not suitable for devices without Universal Integrated Circuit Cards (UICC) or SIM cards, and do not provide secure communication over the Internet.
Innovation Solution
The system employs a roll-over token and a reset server to facilitate the transfer of ownership by generating and updating credentials, using a combination of symmetric and public key-based credentials, and establishing a secure channel between device management servers, allowing for secure and efficient ownership transfer without the need for physical UICC cards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If UICC-based authentication is used for secure communication, then security is improved, but cost increases and credential switching becomes difficult
Solution Approach 1:
The patent creates a virtual copy of the UICC authentication functionality through software-based credentials ( certificates and private keys) stored in the device's secure storage. This allows the device to replicate the security functions of a physical UICC card without the hardware cost, enabling UICC-like authentication in devices that never had physical cards or in cost-sensitive applications.
Solution Approach 2:
The patent replaces the mechanical/physical UICC card system with a software-based credential system. Instead of physically inserting and removing cards to switch credentials, the system uses digital certificates and cryptographic keys that can be programmatically updated and managed, eliminating the need for physical card handling while maintaining security.
2Reliability
If UICC-based authentication is used, then security is improved, but credential switching to new owners becomes inefficient
Solution Approach 1:
The patent enables virtual copying of credential sets between owners. The new owner's credentials can be provisioned by copying or generating equivalent cryptographic credential pairs (certificates and private keys) that replicate the authentication functionality, allowing rapid credential switching without physical card replacement.
Solution Approach 2:
The patent implements preliminary credential provisioning where the new owner's credentials are prepared and staged before the actual ownership transfer. The credential update process is initiated in advance, allowing the device to switch to new credentials seamlessly during the ownership transition without service interruption.
3Reliability
If UICC cards are required for authentication, then security is improved, but compatibility with devices without UICC slots is lost
Solution Approach 1:
The patent replaces the mechanical UICC card slot requirement with software-based credential storage in the device's internal secure storage. This substitution allows any device with sufficient storage and processing capability to perform UICC-equivalent authentication, making the system compatible with devices that never had physical card slots, including many IoT devices.
Solution Approach 2:
The patent creates a universal credential system that can operate across different device types regardless of whether they have physical UICC slots. The software-based credential architecture provides multi-functionality, supporting authentication in both traditional mobile devices and modern IoT devices without UICC compatibility requirements.
4Reliability
If manual credential updating is used for ownership transfer, then security control is improved, but complexity and time consumption increase
Solution Approach 1:
The patent implements self-service credential updating where the device automatically manages its own credential transitions during ownership transfer. The device can autonomously generate new credential pairs, update its authentication credentials, and notify relevant parties without requiring manual intervention from security personnel or administrators, reducing complexity while maintaining security control.
Solution Approach 2:
The patent incorporates feedback mechanisms where the device reports credential update status and authentication events to the network and relevant parties. This automated feedback loop ensures security control is maintained through real-time monitoring and verification of credential changes, eliminating the need for complex manual verification procedures.
Data Source
AI summary
Systems, methods, and/or techniques for transferring ownership or rolling-over machine-to-machine (M2M) and/or internet of things (IoT) devices from a first owner to a second owner may be disclosed. For example, at a M2M and/or IoT device, a roll-over token and/or a message with the roll-over token may be received. The roll-over token may be configured to be used to transfer ownership and/or update credentials, and/or the roll-over token may be configured to be requested by a first device management server (DMS) associated with the first owner and/or may be generated by a reset server (RS), for example, in response to the request by the first DMS. A validity of the roll-over token may be checked or determined.


