SIM-Generated PSKs for Constrained M2M Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for IoT devices connected to WWANs, such as LTE and GSM networks, face challenges in ensuring end-to-end data security, authenticity, and integrity, particularly due to vulnerabilities in existing PKI methods and the complexity of asymmetric encryption, which are computationally intensive and difficult to implement on constrained devices like M2M devices.

Innovation Solution

The use of a SIM card with excess storage space to generate a Pre-Shared Key (PSK) for TLS-PSK cryptographic protocols, bypassing cumbersome PKI methods and potential security flaws, thereby establishing a secure end-to-end data session without the need to share pre-shared keys, thus minimizing the risk of key compromise and simplifying key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric encryption and PKI methods are used for security, then security strength is improved, but computational complexity and implementation difficulty increase significantly on constrained devices

Engineering Contradiction:
Improvesecurity strengthVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic operations from the constrained M2M device and relocates them to a more capable entity (the SIM card or network server). The SIM card performs the computationally intensive asymmetric encryption and key generation operations, while the M2M device only needs to store and use the resulting symmetric keys, dramatically reducing the computational burden on the constrained device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The SIM card acts as an intermediary between the M2M device and the network infrastructure. It handles the complex PKI operations and key management, mediating between the device's limited capabilities and the security requirements of the network. The SIM card generates and manages cryptographic keys, performing authentication and encryption operations that would be too complex for the M2M device itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If pre-shared keys are distributed to devices, then key management is simplified, but the risk of key compromise increases

Engineering Contradiction:
Improvekey management simplicityVSAvoidkey compromise risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The SIM card performs self-service by autonomously generating cryptographic key pairs and managing the private keys without requiring external distribution or manual configuration. The private keys never leave the SIM card, and the SIM card automatically manages key rotation, storage, and usage, eliminating the security risks associated with key distribution while maintaining operational simplicity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The cryptographic keys are generated in advance by the SIM card during device provisioning, before the M2M device needs to communicate with the network. This preliminary key generation and configuration eliminates the need for secure key distribution channels, as keys are already in place and never transmitted in plaintext, reducing the risk of compromise during deployment.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security keys are updated frequently, then security is enhanced, but operational complexity and key management overhead increase

Engineering Contradiction:
Improvesecurity enhancementVSAvoidkey management overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The SIM card autonomously manages key updates without requiring manual intervention or complex coordination with the M2M device. When key updates are needed, the SIM card generates new key pairs, manages the transition, and continues to provide security services seamlessly. This self-managed approach enables frequent key rotation to enhance security while minimizing the operational burden on the system.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10172000B2Method and system for managing security keys for user and M2M devices in a wireless communication network environment
Publication Date: 2019.01.01 M2MD TECHNOLOGIES INC
  • US10172000B2 patent drawing
  • US10172000B2 patent drawing
  • US10172000B2 patent drawing

AI summary

Pre Shared Keys (“PSK”) for application and data session security are generated using application authentication secret values stored in a SIM device/card. The SIM internally uses the secret values as inputs to a security algorithm engine, but the secret values are not accessible outside of the SIM. The application authentication secret values cannot be used to authenticate the SIM, or a device that includes the SIM, to a communication network. Rather, symmetric keys and keying material are generated for use by applications outside of the standard and conventional wireless networking uses of a SIM device. Updated PSKs are generated at different network endpoints such that the PSKs are generated individually and separately at the endpoints; the ‘preshared’ keys are not actually shared. Thus, a client endpoint and a server endpoint, or an endpoint associated with the server, independently generate the same PSK without the PSK being transmitted between the endpoints.