Secure Device Management Applet for IoT Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT device management solutions face challenges in securely and seamlessly provisioning and managing industrial IoT devices, particularly those with multiple hardware components, due to the lack of a plug-and-play mechanism and the vulnerability of storing provisioning parameters outside secure elements, leading to scalability issues and security risks.

Innovation Solution

A secure device management applet (SDMA) is introduced, which allows for secure and seamless provisioning of IoT devices to a device manager, updating firmware/software, configuring, and sending telemetry data, while being stored within a security domain of an eUICC or in separate secure elements, enabling zero-touch life cycle management with minimal user input.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If provisioning parameters are stored outside secure elements for ease of access, then provisioning process is simplified, but security risks increase

Engineering Contradiction:
Improveprovisioning processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments provisioning parameters into two categories: secure parameters (stored in secure elements like eUICC) and non-secure parameters (stored in non-secure memory). This segmentation allows the system to maintain security for critical authentication data while enabling easy access for operational parameters, thus resolving the contradiction between security and ease of operation.

Inventive Principle:
Principle #1Segmentation

2Productivity

If manual provisioning is used for each device, then security control is maintained, but scalability is reduced

Engineering Contradiction:
ImprovescalabilityVSAvoidmanual provisioning
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements self-service provisioning where the device automatically retrieves provisioning parameters from the secure element and configures itself to connect to the apparatus manager. This eliminates the need for manual provisioning of each device while maintaining security through the use of secure elements, thereby enabling scalable deployment of multiple devices.

Inventive Principle:
Principle #25Self-service

3Reliability

If separate secure elements are used for each provisioning function, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsecure element structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses a universal secure element (eUICC) that can store multiple profiles including both mobile network operator profiles and apparatus manager provisioning profiles. This multi-functional approach allows the secure element to handle different provisioning functions without requiring separate secure elements for each function, thus maintaining security while avoiding increased device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240430664A1Apparatus, method, and computer program
Publication Date: 2024.12.26 NOKIA TECHNOLOGIES OY
  • US20240430664A1 patent drawing
  • US20240430664A1 patent drawing
  • US20240430664A1 patent drawing

AI summary

The disclosure relates to an apparatus configured to receive (1400), from a subscriber identity module manager, a mobile network operator profile comprising first provisioning parameters to provision the apparatus to a mobile network operator and a module comprising second provisioning parameters to provision the apparatus to an apparatus manager; provision (1402) the apparatus to the mobile network operator using the first provisioning parameters; and provision (1404) the apparatus to the apparatus manager using the second provisioning parameters.