M2M Device Secure Provisioning via Technician-Signed Cryptographic Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for provisioning services to machine-to-machine (M2M) devices within cellular networks face challenges such as high costs, form factor constraints, and security concerns due to the need for unique personalization of SIM cards, which can be compromised during distribution and configuration, leading to potential tampering and unauthorized use.
Innovation Solution
A system and method that eliminates the need for pre-loaded keys on M2M devices by using a technician device for secure provisioning, where cryptographic data is digitally signed and transmitted over secure interfaces, allowing for authentication and verification of the device and technician, and enabling secure key management without relying on traditional SIM card personalization centers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIM cards are individually personalized at a secure personalization centre, then device security is improved, but manufacturing costs and logistical complexity increase
Solution Approach 1:
The patent extracts the secure element functionality from the traditional SIM card form factor and integrates it directly into the device's application processor or modem. This eliminates the need for separate SIM personalization centers while maintaining security through hardware-based secure elements that are built-in during device manufacturing, thereby reducing manufacturing costs and logistical complexity.
Solution Approach 2:
The patent merges the secure element functions traditionally provided by SIM cards with the device's existing processing components. By combining these functions into a unified secure element within the device, the system eliminates the need for separate SIM card distribution and personalization infrastructure, reducing both cost and complexity while maintaining security.
2Productivity
If SIM cards are distributed directly to OEMs for integration, then logistics are simplified, but security risks during distribution and configuration increase
Solution Approach 1:
The patent implements preliminary security measures by establishing secure provisioning channels and authentication mechanisms before SIM cards are distributed to OEMs. The system pre-configures security policies, establishes trusted relationships between operators and OEMs, and implements cryptographic authentication that prevents unauthorized access or tampering during the distribution and configuration process.
3Adaptability or versatility
If traditional SIM card form factors are used, then compatibility is maintained, but device size and durability are constrained
Solution Approach 1:
The patent merges the SIM card functionality with the device's existing integrated circuits, eliminating the need for a separate physical SIM card slot. This integration maintains all traditional SIM functions while significantly reducing device size and eliminating durability issues associated with removable cards, as the secure element becomes an inherent part of the device's circuit board.
4Adaptability or versatility
If remote key negotiation is used, then provisioning flexibility is improved, but security verification becomes difficult
Solution Approach 1:
The patent implements feedback mechanisms where the secure element provides cryptographic proof of key storage and authentication status back to the provisioning system. During remote key negotiation, the device can verify that keys are properly stored in the secure element by receiving authentication challenges and providing cryptographic responses, allowing the operator to confirm secure storage without physical inspection.
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
Provisioning a subscription of a service to a device comprising: receiving a message from a device 210, the message protected by first provisioning data installed on the device 205. Authenticating the message 220 using data corresponding to the first provisioning data. On successful authentication 230, providing data enabling the device to recover protected second provisioning data from a subscription manager and providing the device with the protected second provisioning data 260. A second subscription manager may also be used. Optionally the message may comprise a signature verification key corresponding to a signature key of the device. A session key may be generated using Diffie-Hellman exchange and the second provisioning data may be provided to the device encrypted by a generated session key. The first provisioning data may comprise a group key, provided to a plurality of devices, and a device key, unique to the device. Part or all of the provisioning data may be stored within the secure execution environment (SEE) within the device. The OEM and SEE manufacturer may both provide key pairs, the OEM may provide the device key pair and the SEE manufacturer may provide the group key pairs. The device may be a Machine-to-Machine (M2M) device.