SIM Subscription Data Provisioning via Authentication Challenge

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices equipped with secure identification elements like SIMs often lack initial subscription data, making it difficult for them to attach to a mobile communications system without prior data provisioning, especially in M2M applications where embedding complete subscription data is not feasible.

Innovation Solution

Modifying the standard challenge-response authentication procedure in mobile communications systems to use the challenge as a carrier for subscription data, allowing devices to request and receive subscription data over-the-air using a mode indicator data element, which is forwarded to a subscription data providing unit, enabling the SIM to authenticate and attach to the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a mobile device uses a non-personalized SIM without initial subscription data, then device complexity and manufacturing cost are reduced, but the device cannot attach to the mobile communications system

Engineering Contradiction:
ImproveSIM personalization complexityVSAvoidnetwork attachment capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system performs preliminary provisioning of subscription data to the SIM card before the device needs to attach to the network. A provisioning server stores subscription data and delivers it to the SIM card in advance, so that when the device needs to attach, the subscription data is already available on the SIM card, enabling successful network attachment without requiring complex pre-personalization processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A provisioning server acts as an intermediary between the network operator and the mobile device. This intermediary stores subscription data and delivers it to the SIM card when needed, bridging the gap between devices with minimal initial data and the network requiring authenticated devices with proper subscription data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complete subscription data is embedded in the SIM during manufacturing, then the device can immediately attach to the network, but manufacturing cost and device complexity increase

Engineering Contradiction:
Improvenetwork attachment capabilityVSAvoidSIM personalization process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of performing SIM personalization with complete subscription data during manufacturing, the system performs preliminary provisioning of necessary subscription data to the SIM card before network attachment is needed. This reduces the burden on manufacturing processes while ensuring the device has sufficient data to attach to the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The provisioning process extracts and delivers only the necessary subscription data to the SIM card at the appropriate time, rather than embedding complete subscription data during manufacturing. This selective data delivery reduces manufacturing complexity while maintaining network attachment capability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If the challenge in authentication is used as a carrier for subscription data, then devices with minimal data can attach to the network, but the authentication procedure becomes more complex

Engineering Contradiction:
Improvedevice attachment flexibilityVSAvoidauthentication procedure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication challenge is given multiple functions: it serves both as the traditional authentication mechanism and as a carrier for delivering subscription data to the device. By making the challenge multi-functional, the system enables devices with minimal initial data to attach to the network without creating separate data delivery mechanisms, thus avoiding additional complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges the authentication challenge with the subscription data delivery function. Instead of treating these as separate processes, the challenge message is combined with subscription data, allowing simultaneous authentication and data provisioning in a single interaction, thereby reducing overall procedural complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9191818B2Methods and devices for OTA management of subscriber identity modules
Publication Date: 2015.11.17 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • US9191818B2 patent drawing
  • US9191818B2 patent drawing
  • US9191818B2 patent drawing

AI summary

Methods and devices in a mobile communications system for over the air management of mobile stations contain a secure identification element such as a subscriber identity module. A standard challenge-response authentication procedure is implemented in a mobile communications system not for its intended authentication purpose, but for providing a mobile station with subscription data. The standard challenge-response authentication procedure is modified in that the challenge is used as a carrier for subscription data. The challenge containing the subscription data is provided to the mobile station in response to a request of the mobile station to be allowed access or attachment to the mobile communications system containing a special mode indicator data element, which indicates to the mobile communications system that the mobile station is requesting subscription data and suitably forwarded to a data providing unit configured to provide subscription data.