Mobile Device Credentialing via PKI Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for provisioning mobile devices with subscription credentials are complex, lack sufficient security, and require significant trust between competitive actors, failing to simplify manufacturing, sales, and registration processes for secure over-the-air provisioning.

Innovation Solution

A credentialing server system that uses preliminary access credentials to verify trusted communication devices, employing a Public Key Infrastructure (PKI) and independent authentication servers to securely download subscription credentials, allowing network operators to control the credentialing process while utilizing external registration and provisioning servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If conventional SIM card distribution and activation methods are used, then network operators can control subscription access, but the provisioning process becomes complex and time-consuming for manufacturers and distributors

Engineering Contradiction:
Improvedevice provisioning processVSAvoidactivation time
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-provisioning devices with temporary credentials (TMSI, temporary keys) during manufacturing. This allows devices to be activated over-the-air without physical SIM card distribution, enabling manufacturers to prepare devices in advance with basic identification information that can be later replaced with full subscription credentials through automated network provisioning

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the credentialing process into distinct phases: initial device identification with temporary credentials, network-based verification and authorization, and final subscription credential provisioning. This segmentation allows different actors (manufacturers, distributors, network operators) to perform their respective functions independently without requiring synchronized manual intervention

Inventive Principle:
Principle #1Segmentation

2Productivity

If over-the-air provisioning is implemented to simplify manufacturing, then activation becomes faster, but security risks increase without proper verification mechanisms

Engineering Contradiction:
Improveprovisioning speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary authorization server that acts as a trusted third party between the device and network operator. This server verifies device credentials, checks authorization policies, and mediates the credentialing process, ensuring that only authorized devices receive subscription credentials while maintaining fast automated provisioning

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms where the authorization server continuously verifies device credentials and monitoring information during the provisioning process. The system receives feedback from network operators about device authorization status and adjusts credential issuance accordingly, creating a closed-loop security system that maintains high provisioning speed

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If multiple external servers are used for registration and provisioning, then system flexibility increases, but trust requirements between competitive actors increase

Engineering Contradiction:
Improvesystem flexibilityVSAvoidtrust between actors
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent uses the authorization server as a neutral intermediary that enables multiple external servers (registration servers, provisioning servers) from different actors to interact securely. The authorization server implements standardized verification protocols that allow competitive actors to work together without requiring bilateral trust relationships, as each actor only needs to trust the standardized protocol implemented by the authorization server

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8516133B2Method and system for mobile device credentialing
Publication Date: 2013.08.20 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US8516133B2 patent drawing
  • US8516133B2 patent drawing
  • US8516133B2 patent drawing

AI summary

Methods and systems taught herein allow communication device manufacturers to preconfigure communication devices to use preliminary access credentials to gain temporary network access for downloading subscription credentials, and particularly allow the network operator issuing the subscription credentials to verify that individual devices requesting credentials are trusted. In one or more embodiments, a credentialing server is owned or controlled by the network operator, and is used by the network operator to verify that subscription credentials are issued only to trusted communication devices, even though such devices may be referred to the credentialing server by an external registration server and may be provisioned by an external provisioning server. Particularly, the credentialing server interrogates requesting devices for their device certificates and submits these device certificates to an external authorization server, e.g., an independent OCSP server, for verification. A common Public Key Infrastructure (PKI) may be used for operator and device certificates.