Shared IMSI SIM Provisioning for Cellular Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of mobile consumer devices burdens mobile operators and original equipment manufacturers with the cost of storing and provisioning unique international mobile subscriber identity (IMSI) data, especially since current methods require non-cellular network availability and unique IMSIs for each device, which can be costly and impractical for low-cost devices without non-cellular functionality.
Innovation Solution
A method using a shared IMSI for provisioning a group of embedded SIM devices, where a device-specific key is derived for authentication, allowing for cellular remote provisioning without the need for unique identifiers, and utilizing a device root key to perform an Authentication and Key Agreement (AKA) procedure for network attachment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If unique IMSIs are assigned to each device for authentication, then device identity and network security are ensured, but storage costs and provisioning complexity increase significantly
Solution Approach 1:
The patent combines multiple device identities (IMSIs) into a single shared IMSI that can be used by multiple devices. Instead of each device having a unique IMSI stored in the HLR, a group of devices shares a common IMSI, thereby reducing the storage burden on operators while maintaining authentication capability through device-specific keys.
Solution Approach 2:
The shared IMSI serves multiple functions: it acts as the common identifier for a group of devices in the HLR, while device-specific keys provide individual authentication. This universal identifier approach allows the system to handle multiple devices with a single stored identity, reducing provisioning complexity and storage requirements.
2Reliability
If non-cellular networks are required for provisioning, then device-specific IMSIs can be provisioned securely, but accessibility is reduced for devices without non-cellular functionality
Solution Approach 1:
The patent extracts the requirement for non-cellular network connectivity from the provisioning process. By using a shared IMSI that can be provisioned over the cellular network itself, the solution removes the dependency on separate non-cellular networks, making provisioning accessible to all devices regardless of their connectivity capabilities.
Solution Approach 2:
Instead of requiring devices to have non-cellular functionality for secure provisioning, the patent inverts the approach by enabling secure provisioning through the cellular network using shared IMSIs. This allows even low-cost devices without non-cellular modules to be provisioned securely.
3Reliability
If device-specific IMSIs are requested from operators during manufacturing, then proper authentication credentials can be obtained, but the provisioning process becomes more complex and time-consuming
Solution Approach 1:
The patent applies preliminary action by pre-configuring devices with a shared IMSI and authentication credentials before deployment. Instead of requiring individual IMSI assignment during manufacturing, devices are pre-provisioned with the shared identity and necessary keys, streamlining the manufacturing process and improving productivity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
There is provided a device comprising a key request module and a key receive module. The key request module is configured to transmit a key request to a provisioning server, and the key receive module is configured to receive a device root key associated with the device from the provisioning server. The device also comprises an authentication request transmit module configured to transmit an authentication request comprising an international mobile subscriber identity (IMSI) and a device identifier identifying the device to a first home subscriber server (HSS). The device also comprises an authentication under key agreement (AKA) module configured to perform an AKA procedure using the device root key. The key request module, the key receive module, the authentication request transmit module and the AKA module thereby authenticate the device for subscriber identity module (SIM) provisioning of the device.