SIM-Generated PSKs for Constrained M2M Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security solutions for IoT devices connected to WWANs, such as LTE and GSM networks, face challenges in ensuring end-to-end data security, authenticity, and integrity, particularly due to vulnerabilities in existing PKI methods and the complexity of asymmetric encryption, which are computationally intensive and difficult to implement on constrained devices like M2M devices.
Innovation Solution
The use of a SIM card with excess storage space to generate a Pre-Shared Key (PSK) for TLS-PSK cryptographic protocols, bypassing cumbersome PKI methods and potential security flaws, thereby establishing a secure end-to-end data session without the need to share pre-shared keys, thus minimizing the risk of key compromise and simplifying key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If asymmetric encryption and PKI methods are used for security, then security strength is improved, but computational complexity and implementation difficulty increase significantly on constrained devices
Solution Approach 1:
The patent extracts the cryptographic operations from the constrained M2M device and relocates them to a more capable entity (the SIM card or network server). The SIM card performs the computationally intensive asymmetric encryption and key generation operations, while the M2M device only needs to store and use the resulting symmetric keys, dramatically reducing the computational burden on the constrained device.
Solution Approach 2:
The SIM card acts as an intermediary between the M2M device and the network infrastructure. It handles the complex PKI operations and key management, mediating between the device's limited capabilities and the security requirements of the network. The SIM card generates and manages cryptographic keys, performing authentication and encryption operations that would be too complex for the M2M device itself.
2Ease of operation
If pre-shared keys are distributed to devices, then key management is simplified, but the risk of key compromise increases
Solution Approach 1:
The SIM card performs self-service by autonomously generating cryptographic key pairs and managing the private keys without requiring external distribution or manual configuration. The private keys never leave the SIM card, and the SIM card automatically manages key rotation, storage, and usage, eliminating the security risks associated with key distribution while maintaining operational simplicity.
Solution Approach 2:
The cryptographic keys are generated in advance by the SIM card during device provisioning, before the M2M device needs to communicate with the network. This preliminary key generation and configuration eliminates the need for secure key distribution channels, as keys are already in place and never transmitted in plaintext, reducing the risk of compromise during deployment.
3Reliability
If security keys are updated frequently, then security is enhanced, but operational complexity and key management overhead increase
Solution Approach 1:
The SIM card autonomously manages key updates without requiring manual intervention or complex coordination with the M2M device. When key updates are needed, the SIM card generates new key pairs, manages the transition, and continues to provide security services seamlessly. This self-managed approach enables frequent key rotation to enhance security while minimizing the operational burden on the system.
Data Source
AI summary
Pre Shared Keys (“PSK”) for application and data session security are generated using application authentication secret values stored in a SIM device/card. The SIM internally uses the secret values as inputs to a security algorithm engine, but the secret values are not accessible outside of the SIM. The application authentication secret values cannot be used to authenticate the SIM, or a device that includes the SIM, to a communication network. Rather, symmetric keys and keying material are generated for use by applications outside of the standard and conventional wireless networking uses of a SIM device. Updated PSKs are generated at different network endpoints such that the PSKs are generated individually and separately at the endpoints; the ‘preshared’ keys are not actually shared. Thus, a client endpoint and a server endpoint, or an endpoint associated with the server, independently generate the same PSK without the PSK being transmitted between the endpoints.


