IoT Device Provisioning via SIM Subscription Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for provisioning Internet devices, especially IoT devices, face challenges due to resource constraints, high costs, and complexity in authentication and certificate management, particularly in scenarios where devices lack sufficient resources or are constrained by bandwidth and processing power.
Innovation Solution
A method that stores an association between a mobile subscription and its owner, allowing authorized devices to access restricted network resources by verifying subscription ownership, which includes provisioning access credentials and routing traffic through a connectivity server, without the need for pre-stored provisioning server locations or computationally heavy certificate exchanges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate-based authentication is used for provisioning enterprise devices, then security is improved, but device complexity and resource requirements increase
Solution Approach 1:
The patent extracts the authentication credentials from the device and stores them in a separate SIM card. The authentication data is provisioned to the SIM card by the mobile operator, not to the device itself. This separates the complex certificate management from the constrained IoT device, allowing secure authentication without burdening the device with certificate storage and processing capabilities.
Solution Approach 2:
The SIM card acts as an intermediary between the mobile operator and the enterprise device. It holds the authentication credentials and performs the authentication process, mediating the security requirements without requiring the enterprise device to directly handle complex certificate exchanges. The device simply uses the SIM card for authentication purposes.
2Reliability
If SIM-based authentication techniques (AP-SIM and GBA) are used, then authentication capability is improved, but bandwidth and resource requirements increase beyond available resources in constrained IoT devices
Solution Approach 1:
The patent implements a simplified authentication approach where the SIM card stores authentication data that enables basic authentication without requiring the full complexity of AP-SIM or GBA protocols. The device only needs to support minimal authentication functionality, relying on the SIM card to handle the heavier authentication logic and resource requirements.
3Productivity
If device-specific credentials are automatically provisioned during manufacturing, then provisioning efficiency is improved, but adaptability to different owners and networks decreases
Solution Approach 1:
The SIM card serves multiple functions: it provides mobile network authentication, stores enterprise device credentials, and enables authentication with different owners. The same SIM card can be re-provisioned by different mobile operators and used with different enterprise devices, making the authentication system universal and adaptable rather than device-specific.
Solution Approach 2:
The authentication credentials in the SIM card are dynamic and can be updated or re-provisioned remotely by the mobile operator. This allows the same physical SIM card to adapt to different owners, networks, and devices over time, rather than being statically bound to a single device during manufacturing.
Data Source
Figure 1
Figure 2~3
Figure 4A
AI summary
Network equipment has at least one memory and processor which perform: storing an association between a mobile subscription of a mobile communication network of a mobile operator and a subscription owner; detecting a request from a cellular communication enabled device for providing data connectivity to a restricted network resource to which the subscription owner is authorized to access; and detecting whether the cellular communication enabled device transmitted the request using the subscription for which the association was stored between the mobile subscription and the subscription owner; and if yes, providing the data connectivity to the restricted network resource, otherwise not providing the data connectivity to the restricted network resource.