Remote Subscription Provisioning via Secure Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for remote subscription provisioning in wireless communication networks face challenges in securely transmitting sensitive parameters like keys, particularly due to the vulnerability of symmetric algorithm-based security, and require pre-provisioning multiple subscriptions, which complicates key management and roaming.
Innovation Solution
A method where only an initial subscription is remotely provisioned, with temporary subscriptions generated on both the network operator and UICC, using a key-generating seed to create definitive keys without transmitting them, ensuring secure access to network services without sharing sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If symmetric algorithm-based security is used for remote key transmission, then device cost is reduced, but security vulnerability increases
Solution Approach 1:
The patent replaces the traditional mechanical approach of transmitting keys over the air (OTA) with a physical delivery mechanism. The SIM card is pre-provisioned with keys in a controlled manufacturing environment and physically delivered to the user, eliminating the security vulnerabilities of wireless key transmission while maintaining low device costs.
Solution Approach 2:
The patent introduces a trusted intermediary (the operator's controlled environment) that facilitates secure key distribution. The SIM card is provisioned in a secure facility and physically handed over through trusted channels, acting as an intermediary that bridges the gap between key generation and device deployment without exposing keys to insecure transmission channels.
2Adaptability or versatility
If multiple subscriptions are pre-provisioned in the device, then roaming capability is improved, but key management complexity increases
Solution Approach 1:
The patent segments the subscription provisioning process into distinct phases: initial provisioning of a first subscription, and subsequent remote provisioning of additional subscriptions. This segmentation allows the device to start with a simple key management structure and progressively add complexity only when needed, rather than pre-loading all possible subscriptions.
Solution Approach 2:
The patent performs preliminary provisioning of a single initial subscription in a controlled manufacturing environment, establishing a secure foundation. This preliminary action enables subsequent remote provisioning operations to occur securely without requiring multiple subscriptions to be pre-installed, thus reducing initial key management complexity.
3Adaptability or versatility
If temporary subscription is issued for first remote access, then subscription flexibility is improved, but security risk increases due to key transmission
Solution Approach 1:
The patent performs preliminary provisioning of the SIM card with initial keys in a secure controlled environment before the device is activated. This preliminary action establishes a secure baseline that enables subsequent temporary subscription provisioning without requiring transmission of sensitive key material over the air, thus maintaining security while enabling subscription flexibility.
Solution Approach 2:
The patent replaces the wireless transmission mechanism for key delivery with physical delivery of the pre-provisioned SIM card. The initial keys are loaded in a controlled environment and the SIM card is physically handed over to the user, eliminating the security risks associated with wireless key transmission while maintaining the ability to provision temporary subscriptions securely.
Data Source
AI summary
The present disclosure relates to a method and system for the remote provisioning of an access subscription of a user to a wireless communication network, wherein at least one network operator provides communication services to mobile communication devices provided with a user UICC card. Data of a temporary subscription are generated from the data of an initial subscription which will subsequently allow generating data of a definitive subscription in a network operator and in the UICC card requesting a subscription from the former without the need of remotely transmitting sensitive data of the definitive subscription.


