M2M Device Security via UICC Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Machine to Machine (M2M) communication networks are vulnerable to malicious devices that can scan signals and illegally join the network, capturing personal data from M2M devices, which poses a security risk and data integrity issue.

Innovation Solution

M2M devices encrypt data with a device ID and subscriber ID using a universal integrated circuit card (UICC) and generate data packets in a secure communication standard format, such as HTTPS, to authenticate devices and protect data, employing public key infrastructure (PKI) and hashing functions for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If M2M devices transmit data in clear text or with basic authentication, then communication simplicity is maintained, but security and data integrity are compromised against malicious devices

Engineering Contradiction:
Improvedata securityVSAvoidencryption implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-provisioning each M2M device with a unique device ID and subscriber ID during manufacturing or deployment. These credentials are stored securely in the device's memory or embedded module before the device enters service. This preliminary setup enables immediate secure authentication and encryption operations without requiring complex runtime key distribution or certificate management, thus enhancing data security while keeping the operational complexity manageable.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If M2M devices implement robust authentication and encryption protocols, then unauthorized access is prevented, but processing overhead and energy consumption increase

Engineering Contradiction:
Improveauthentication securityVSAvoidprocessing energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements self-service by enabling M2M devices to autonomously perform authentication and encryption operations using their pre-provisioned device ID and subscriber ID. Each device independently generates encryption keys and authenticates with the network without requiring external key distribution or manual security configuration. This self-contained approach ensures strong authentication security while minimizing processing overhead by avoiding repeated key exchange protocols or centralized authentication server dependencies.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If M2M networks use standardized communication protocols, then interoperability is improved, but vulnerability to signal scanning and illegal network joining increases

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidmalicious device intrusion
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing device-specific security characteristics within the standardized M2M communication framework. Each M2M device is provisioned with unique local identifiers (device ID and subscriber ID) that are embedded in the communication packets. This allows the network to maintain standardized protocol compatibility for broad interoperability while simultaneously enabling individual device authentication and authorization. The unique local identifiers prevent malicious devices from impersonating legitimate devices, as each device's security credentials are locally specific and verifiable by the network.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9986428B2Security management in M2M area network
Publication Date: 2018.05.29 KT CORP
  • US9986428B2 patent drawing
  • US9986428B2 patent drawing
  • US9986428B2 patent drawing

AI summary

The disclosure is related to a machine to machine (M2M) device and a security management method thereof. The M2M device includes an identification circuit. The identification circuit may be configured to encrypt data collected from a sensor with a device identification (ID) of the M2M device and at least one subscriber ID of the identification circuit and to generate a data packet in a predetermined communication standard format by including the encrypted data in a payload of the data packet.