Mobile Device Credentialing via PKI Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for provisioning mobile devices with subscription credentials are complex, lack sufficient security, and require significant trust between competitive actors, failing to simplify manufacturing, sales, and registration processes for secure over-the-air provisioning.
Innovation Solution
A credentialing server system that uses preliminary access credentials to verify trusted communication devices, employing a Public Key Infrastructure (PKI) and independent authentication servers to securely download subscription credentials, allowing network operators to control the credentialing process while utilizing external registration and provisioning servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If conventional SIM card distribution and activation methods are used, then network operators can control subscription access, but the provisioning process becomes complex and time-consuming for manufacturers and distributors
Solution Approach 1:
The patent implements preliminary action by pre-provisioning devices with temporary credentials (TMSI, temporary keys) during manufacturing. This allows devices to be activated over-the-air without physical SIM card distribution, enabling manufacturers to prepare devices in advance with basic identification information that can be later replaced with full subscription credentials through automated network provisioning
Solution Approach 2:
The patent segments the credentialing process into distinct phases: initial device identification with temporary credentials, network-based verification and authorization, and final subscription credential provisioning. This segmentation allows different actors (manufacturers, distributors, network operators) to perform their respective functions independently without requiring synchronized manual intervention
2Productivity
If over-the-air provisioning is implemented to simplify manufacturing, then activation becomes faster, but security risks increase without proper verification mechanisms
Solution Approach 1:
The patent introduces an intermediary authorization server that acts as a trusted third party between the device and network operator. This server verifies device credentials, checks authorization policies, and mediates the credentialing process, ensuring that only authorized devices receive subscription credentials while maintaining fast automated provisioning
Solution Approach 2:
The patent implements feedback mechanisms where the authorization server continuously verifies device credentials and monitoring information during the provisioning process. The system receives feedback from network operators about device authorization status and adjusts credential issuance accordingly, creating a closed-loop security system that maintains high provisioning speed
3Adaptability or versatility
If multiple external servers are used for registration and provisioning, then system flexibility increases, but trust requirements between competitive actors increase
Solution Approach 1:
The patent uses the authorization server as a neutral intermediary that enables multiple external servers (registration servers, provisioning servers) from different actors to interact securely. The authorization server implements standardized verification protocols that allow competitive actors to work together without requiring bilateral trust relationships, as each actor only needs to trust the standardized protocol implemented by the authorization server
Data Source
AI summary
Methods and systems taught herein allow communication device manufacturers to preconfigure communication devices to use preliminary access credentials to gain temporary network access for downloading subscription credentials, and particularly allow the network operator issuing the subscription credentials to verify that individual devices requesting credentials are trusted. In one or more embodiments, a credentialing server is owned or controlled by the network operator, and is used by the network operator to verify that subscription credentials are issued only to trusted communication devices, even though such devices may be referred to the credentialing server by an external registration server and may be provisioned by an external provisioning server. Particularly, the credentialing server interrogates requesting devices for their device certificates and submits these device certificates to an external authorization server, e.g., an independent OCSP server, for verification. A common Public Key Infrastructure (PKI) may be used for operator and device certificates.


