Proxy Profile Handling for Constrained IoT Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Constrained devices in communications networks face challenges in efficiently managing profiles, particularly in remote subscription changes and secure communication, due to limited resources and lack of user interfaces, which complicates the use of existing identity management technologies like eUICC and iUICC.

Innovation Solution

A proxy device is introduced to handle profile management by establishing secure communication links with both the local profile assistant and subscription management entities, allowing for remote profile provisioning and management without the need for HTTPS support in the constrained device, thereby reducing memory usage and costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing identity management technologies like eUICC and iUICC are used in constrained devices, then security and identity management capabilities are improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A proxy device is introduced as an intermediary between the constrained communications device and the subscription management entity. The proxy device handles HTTPS connections and profile management operations, while the constrained device only needs to communicate with the proxy using simpler protocols. This mediator approach maintains security capabilities without requiring the constrained device to implement complex HTTPS stacks or eUICC/iUICC functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If HTTPS support is implemented in constrained devices for secure communication, then security is improved, but memory usage increases

Engineering Contradiction:
ImprovesecurityVSAvoidmemory usage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The HTTPS protocol stack and related security functionality are extracted from the constrained communications device and relocated to the proxy device. The constrained device only needs to implement lightweight communication protocols for interacting with the proxy, while the proxy device handles all HTTPS operations including SSL/TLS encryption, certificate management, and secure profile downloads from the subscription management entity.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If remote profile management is enabled in constrained devices, then ease of operation is improved, but power consumption increases

Engineering Contradiction:
Improveease of operationVSAvoidpower consumption
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The proxy device is configured with stored profile information and authentication credentials, enabling it to autonomously manage profile operations without requiring continuous user interaction or device activation. The constrained device can initiate simple profile management requests, but the proxy device handles the complex communication with the subscription management entity using pre-stored credentials, reducing the need for frequent device wake-ups and power-intensive operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11595813B2Profile handling of a communications device
Publication Date: 2023.02.28 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11595813B2 patent drawing
  • US11595813B2 patent drawing
  • US11595813B2 patent drawing

AI summary

There is presented mechanisms for profile handling of a communications device (300). A method is performed by a local profile assistant (200a) of a proxy device (200). The method comprises obtaining an indication of handling a profile of the communications device (300). The method comprises establishing a first secure communications link with a local profile assistant of the communications device. The method comprises establishing a second secure communications link with a subscription management entity (430) of the communications device. The method comprises receiving information pertaining to handling of the profile by the local profile assistant of the communications device, the information being received from the subscription management entity over the second secure communications link. The method comprises providing the information to the local profile assistant of the communications device over the first secure communications link.