Mobile Device Credentialing via Centralized Directory Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for provisioning mobile devices with subscription credentials are complex and do not efficiently simplify manufacturing, sales, and registration for secure over-the-air activation.
Innovation Solution
A centralized device directory server pre-configures mobile devices with temporary device identifiers and secret keys, allowing temporary access to any network for obtaining permanent subscription credentials through cooperation with a credential server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If conventional SIM card distribution methods are used, then network operator control is maintained, but manufacturing and activation complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-configuring mobile devices with temporary subscription credentials during manufacturing, before the device is activated by the end user. This allows the device to be prepared in advance with basic identification information, enabling streamlined activation processes later without requiring complex real-time provisioning during manufacturing.
Solution Approach 2:
The patent introduces a centralized device directory server as an intermediary between manufacturers, network operators, and credential servers. This intermediary coordinates the provisioning process, managing temporary credentials and facilitating secure communication between parties, thereby reducing overall system complexity while maintaining control.
2Loss of time
If temporary credentials are used for over-the-air provisioning, then activation speed improves, but security requirements increase
Solution Approach 1:
Security measures are implemented in advance during device manufacturing, where temporary credentials and cryptographic keys are securely embedded in hardware security modules. This preliminary security configuration enables rapid activation without compromising security, as the foundational security infrastructure is already in place before activation occurs.
Solution Approach 2:
The patent replaces physical SIM card insertion with electronic credential verification systems. Hardware security modules and cryptographic authentication mechanisms substitute for mechanical SIM card handling, enabling faster over-the-air provisioning while maintaining or enhancing security through digital authentication protocols.
3Reliability
If permanent credentials are provisioned immediately, then network access security is ensured, but manufacturing flexibility decreases
Solution Approach 1:
Instead of provisioning permanent credentials immediately during manufacturing, the system uses preliminary temporary credentials that enable basic network access. This allows manufacturers to produce devices generically without being tied to specific network operators, maintaining manufacturing flexibility while still ensuring secure network access through the temporary credential system.
Solution Approach 2:
The credential system transitions dynamically from temporary credentials during manufacturing and initial activation to permanent credentials after network operator registration. This dynamic credential management allows the system to adapt to different operational phases, maintaining both manufacturing flexibility and network security at appropriate stages.
Data Source
AI summary
Methods and systems taught herein allow mobile device manufacturers to preconfigure mobile devices for subscription with any network operator having access to a centralized device directory server. The directory server stores device records, each including a preliminary subscription identity. Manufacturers individually provision new mobile devices with these preliminary subscription identities, and network operators preliminarily register subscribers by submitting requests to the directory server that cause it to link individual device records with the appropriate credential server addresses. Mobile devices gain temporary network access by submitting their preliminary subscription identities, which get passed along to the directory server for verification. In turn, the directory server generates authentication vectors giving the mobile devices temporary network access, and returns the appropriate credential server addresses. The mobile devices use the address information to submit secure requests for permanent subscription credentials, and the involved credential servers securely return permanent subscription credentials responsive to valid requests.


