Mobile Device Credentialing via Centralized Directory Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for provisioning mobile devices with subscription credentials are complex and do not efficiently simplify manufacturing, sales, and registration for secure over-the-air activation.

Innovation Solution

A centralized device directory server pre-configures mobile devices with temporary device identifiers and secret keys, allowing temporary access to any network for obtaining permanent subscription credentials through cooperation with a credential server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If conventional SIM card distribution methods are used, then network operator control is maintained, but manufacturing and activation complexity increases

Engineering Contradiction:
Improvemanufacturing efficiencyVSAvoidprovisioning complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring mobile devices with temporary subscription credentials during manufacturing, before the device is activated by the end user. This allows the device to be prepared in advance with basic identification information, enabling streamlined activation processes later without requiring complex real-time provisioning during manufacturing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a centralized device directory server as an intermediary between manufacturers, network operators, and credential servers. This intermediary coordinates the provisioning process, managing temporary credentials and facilitating secure communication between parties, thereby reducing overall system complexity while maintaining control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If temporary credentials are used for over-the-air provisioning, then activation speed improves, but security requirements increase

Engineering Contradiction:
Improveactivation timeVSAvoidsecurity
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

Security measures are implemented in advance during device manufacturing, where temporary credentials and cryptographic keys are securely embedded in hardware security modules. This preliminary security configuration enables rapid activation without compromising security, as the foundational security infrastructure is already in place before activation occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces physical SIM card insertion with electronic credential verification systems. Hardware security modules and cryptographic authentication mechanisms substitute for mechanical SIM card handling, enabling faster over-the-air provisioning while maintaining or enhancing security through digital authentication protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If permanent credentials are provisioned immediately, then network access security is ensured, but manufacturing flexibility decreases

Engineering Contradiction:
Improvenetwork access securityVSAvoidmanufacturing flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of provisioning permanent credentials immediately during manufacturing, the system uses preliminary temporary credentials that enable basic network access. This allows manufacturers to produce devices generically without being tied to specific network operators, maintaining manufacturing flexibility while still ensuring secure network access through the temporary credential system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The credential system transitions dynamically from temporary credentials during manufacturing and initial activation to permanent credentials after network operator registration. This dynamic credential management allows the system to adapt to different operational phases, maintaining both manufacturing flexibility and network security at appropriate stages.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8064597B2Method and system for mobile device credentialing
Publication Date: 2011.11.22 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US8064597B2 patent drawing
  • US8064597B2 patent drawing
  • US8064597B2 patent drawing

AI summary

Methods and systems taught herein allow mobile device manufacturers to preconfigure mobile devices for subscription with any network operator having access to a centralized device directory server. The directory server stores device records, each including a preliminary subscription identity. Manufacturers individually provision new mobile devices with these preliminary subscription identities, and network operators preliminarily register subscribers by submitting requests to the directory server that cause it to link individual device records with the appropriate credential server addresses. Mobile devices gain temporary network access by submitting their preliminary subscription identities, which get passed along to the directory server for verification. In turn, the directory server generates authentication vectors giving the mobile devices temporary network access, and returns the appropriate credential server addresses. The mobile devices use the address information to submit secure requests for permanent subscription credentials, and the involved credential servers securely return permanent subscription credentials responsive to valid requests.