Secure OTA Provisioning via Intermediary Server and UICC
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication device provisioning methods lack secure and efficient mechanisms for over-the-air programming, particularly in ensuring the secure delivery and management of programming data across devices and networks.
Innovation Solution
The implementation of a secure services platform utilizing a Universal Integrated Circuit Card (UICC) and a Secure Device Processor (SDP) for authentication and encryption, enabling secure over-the-air programming through device-based traffic management and remote network management, with multiple HTTP-based OTA servers supporting secure provisioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional provisioning methods are used, then device provisioning can be performed, but security of data delivery is insufficient
Solution Approach 1:
The patent introduces a provisioning server as an intermediary component that mediates between the communication device and the network. This server implements secure message transmission protocols, cryptographic operations for key management, and controlled message forwarding to the secure element, thereby enhancing security without requiring direct complex interactions between all system components
Solution Approach 2:
The provisioning system is segmented into distinct functional modules: a provisioning server handling secure communication and cryptography, a communication device with separate components (processor, secure element), and a network component. This segmentation allows security functions to be concentrated in the server while device functions are distributed, improving overall security without uniformly increasing complexity across all components
2Reliability
If secure authentication and encryption are implemented, then data delivery security is improved, but provisioning process complexity increases
Solution Approach 1:
The provisioning server acts as a cryptographic intermediary that manages authentication and encryption operations. It generates session keys, performs cryptographic transformations on provisioning messages, and handles secure key exchange with both the communication device and the secure element, thereby centralizing security complexity in a dedicated component rather than distributing it throughout the entire system
Solution Approach 2:
The system performs preliminary authentication and key establishment actions before actual provisioning data transmission. The provisioning server establishes secure channels in advance, pre-processes cryptographic operations, and validates device identities before provisioning messages are exchanged, which streamlines the subsequent provisioning process and reduces overall process complexity despite the added security steps
3Reliability
If multiple HTTP-based OTA servers are used, then provisioning reliability is improved, but system complexity increases
Solution Approach 1:
The provisioning server is designed with universal functionality that can operate in multiple modes: it can function as a primary provisioning server, a backup server, or both simultaneously. The server implements universal protocols for communicating with both the communication device and the secure element, and can handle various types of provisioning messages through a unified interface, thereby reducing the need for separate specialized servers and simplifying multi-server system management
Data Source
AI summary
A system that incorporates the subject disclosure may perform, for example, obtaining programming data via an over-the-air programming message for use by a communication device, wherein the over-the-air programming message is obtained from, and encrypted by an over-the-air programming server. The over-the-air programming message is decrypted utilizing a first keyset obtained by a secure device processor processing the first keyset obtained from a remote management server via transmission by the over-the-air programming server, to generate a first-key decrypted over-the-air programming message. The decrypted over-the-air programming message is provided to a secure element to enable the secure element to further decrypt the first-key decrypted over-the-air programming message utilizing a second keyset, wherein the secure device processor does not have access to the second keyset. Other embodiments are disclosed.


