Over-the-Air IoT Device Personalization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large-scale radio networks, such as IoT and mobile phone networks, end devices require personalized security information to join a network, but existing methods involve third-party SIM card manufacturers, which is not feasible for IoT devices without SIM cards and requires manufacturer involvement, necessitating over-the-air personalization without device manufacturer involvement.
Innovation Solution
The method involves presetting end devices with factory settings to securely connect to a network, allowing only the device and service provider to exchange security-sensitive information, using a first set of network credentials for secure communications and a second set of credentials provided over-the-air for personalized access, reducing operator and customer effort and lowering costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If end devices use traditional SIM card personalization methods, then security personalization is achieved, but device complexity increases and manufacturer involvement is required
Solution Approach 1:
The patent extracts the SIM card functionality and replaces it with over-the-air credential delivery. Instead of requiring physical SIM cards or manufacturer-built-in personalization, the system delivers network credentials directly to the device through wireless communication, simplifying the device structure while maintaining security personalization.
Solution Approach 2:
The patent introduces an over-the-air provisioning system as an intermediary between the network operator and the end device. This mediator delivers credentials wirelessly, eliminating the need for physical SIM cards or manufacturer involvement in personalization, thus reducing device complexity while ensuring secure authentication.
2Reliability
If end devices require manufacturer involvement for personalization, then security credentials are properly configured, but ease of manufacture deteriorates and costs increase
Solution Approach 1:
The patent enables devices to self-configure through over-the-air credential delivery. The device automatically receives and configures network credentials without requiring manufacturer intervention or complex assembly processes, making manufacturing simpler and more cost-effective while ensuring proper credential configuration.
Solution Approach 2:
The system performs credential configuration after device deployment rather than during manufacturing. Network credentials are delivered over-the-air to already-deployed devices, eliminating the need for manufacturers to integrate personalization capabilities and simplifying the manufacturing process while ensuring credentials are properly configured.
3Reliability
If security-sensitive information is exchanged between device and service provider, then end-to-end encryption is achieved, but network operator security control is reduced
Solution Approach 1:
The patent segments the network architecture into public network infrastructure and private service provider networks. The over-the-air credential delivery and end-to-end encryption occur within the service provider's secure network, separating these sensitive operations from the public network operator infrastructure. This allows end-to-end encryption without requiring network operator eavesdropping capability.
Data Source
AI summary
Embodiments of the present invention may provide the capability to personalize end devices over-the-air (OTA) without the involvement of device manufacturers, for example, in a federated large scale wireless IoT network, such as LoRaWAN. Preset with factory settings, end devices may securely connect to the network before they are finally personalized for their target service. Security sensitive personalization information may only be exchanged between device and service provider. The process may require relatively little effort by the network operator and end customers, may lower personalization costs, and may provide a security model that is attractive for a wide range of IoT applications.


