Over-the-Air IoT Device Personalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large-scale radio networks, such as IoT and mobile phone networks, end devices require personalized security information to join a network, but existing methods involve third-party SIM card manufacturers, which is not feasible for IoT devices without SIM cards and requires manufacturer involvement, necessitating over-the-air personalization without device manufacturer involvement.

Innovation Solution

The method involves presetting end devices with factory settings to securely connect to a network, allowing only the device and service provider to exchange security-sensitive information, using a first set of network credentials for secure communications and a second set of credentials provided over-the-air for personalized access, reducing operator and customer effort and lowering costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If end devices use traditional SIM card personalization methods, then security personalization is achieved, but device complexity increases and manufacturer involvement is required

Engineering Contradiction:
Improvesecurity personalizationVSAvoidpersonalization process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the SIM card functionality and replaces it with over-the-air credential delivery. Instead of requiring physical SIM cards or manufacturer-built-in personalization, the system delivers network credentials directly to the device through wireless communication, simplifying the device structure while maintaining security personalization.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an over-the-air provisioning system as an intermediary between the network operator and the end device. This mediator delivers credentials wirelessly, eliminating the need for physical SIM cards or manufacturer involvement in personalization, thus reducing device complexity while ensuring secure authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If end devices require manufacturer involvement for personalization, then security credentials are properly configured, but ease of manufacture deteriorates and costs increase

Engineering Contradiction:
Improvecredential configurationVSAvoidpersonalization process
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent enables devices to self-configure through over-the-air credential delivery. The device automatically receives and configures network credentials without requiring manufacturer intervention or complex assembly processes, making manufacturing simpler and more cost-effective while ensuring proper credential configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs credential configuration after device deployment rather than during manufacturing. Network credentials are delivered over-the-air to already-deployed devices, eliminating the need for manufacturers to integrate personalization capabilities and simplifying the manufacturing process while ensuring credentials are properly configured.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security-sensitive information is exchanged between device and service provider, then end-to-end encryption is achieved, but network operator security control is reduced

Engineering Contradiction:
Improveend-to-end encryptionVSAvoidnetwork operator eavesdropping capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network architecture into public network infrastructure and private service provider networks. The over-the-air credential delivery and end-to-end encryption occur within the service provider's secure network, separating these sensitive operations from the public network operator infrastructure. This allows end-to-end encryption without requiring network operator eavesdropping capability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10244392B2Over-the-air personalization of network devices
Publication Date: 2019.03.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10244392B2 patent drawing
  • US10244392B2 patent drawing
  • US10244392B2 patent drawing

AI summary

Embodiments of the present invention may provide the capability to personalize end devices over-the-air (OTA) without the involvement of device manufacturers, for example, in a federated large scale wireless IoT network, such as LoRaWAN. Preset with factory settings, end devices may securely connect to the network before they are finally personalized for their target service. Security sensitive personalization information may only be exchanged between device and service provider. The process may require relatively little effort by the network operator and end customers, may lower personalization costs, and may provide a security model that is attractive for a wide range of IoT applications.