Smart Card Remote Personalization via Temporary Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for personalizing UICC cards are not adaptable for embedding in devices before shipping or for Machine to Machine (M2M) applications, as they require physical intervention and do not allow users to choose their mobile network operator while maintaining authentication key confidentiality.
Innovation Solution
A method for initial personalization of a smart card that involves sending a temporary international identity and authentication key to a home location register, allowing the card to authenticate and negotiate an initial authentication key with a personalization server, enabling remote configuration without physical intervention or over-the-air key transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical personalization of UICC cards is performed in operator premises, then authentication key confidentiality is maintained, but adaptability for M2M and pre-embedded devices is lost
Solution Approach 1:
A personalization server acts as an intermediary between the operator and the UICC card. The server enables remote personalization by receiving personalization data from the operator and securely transmitting it to the UICC card through the communication device, eliminating the need for physical card handling while maintaining security through encrypted over-the-air transmission.
Solution Approach 2:
The patent replaces the mechanical/physical personalization process with an electronic/digital system. Instead of physically programming cards in operator premises, the personalization data is transmitted electronically over the air to the UICC card, substituting mechanical card handling with wireless communication and digital data transmission.
2Adaptability or versatility
If remote personalization is implemented, then adaptability for M2M and pre-embedded devices is improved, but risk of authentication key interception increases
Solution Approach 1:
The patent changes the state of authentication keys from static to dynamic. Instead of using fixed authentication keys that could be intercepted and reused, the system generates temporary authentication keys that are valid only for specific personalization sessions. These temporary keys are automatically invalidated after use, preventing interception attacks.
Solution Approach 2:
The system performs preliminary generation of temporary authentication keys before the actual personalization process. These temporary keys are prepared in advance and used to secure the communication channel during personalization, ensuring that even if the communication is intercepted, the captured data cannot be reused without the temporary keys.
3Reliability
If temporary authentication keys are used for remote personalization, then security against interception is improved, but complexity of the personalization process increases
Solution Approach 1:
The UICC card performs self-personalization by automatically receiving and processing personalization data from the personalization server. The card autonomously executes the personalization process without requiring manual intervention or complex external equipment, simplifying the overall process despite using temporary authentication keys.
Solution Approach 2:
The personalization server provides a universal platform that handles multiple personalization operations through a single interface. The server manages temporary key generation, secure data transmission, and card personalization in one integrated system, reducing the need for multiple separate systems and procedures.
Data Source
AI summary
A method and system for initial personalization of a smart card coupled with a communication device of a user who is not yet a subscriber of any telecommunication network are disclosed. A temporary international identity and a temporary authentication key are stored in the smart card and in a home location register connected to a roaming entity of a telecommunication network. A series of signals are exchanged between the smart card, the roaming entity, an application server and a personalization server to establish a secure session between the smart card and the personalization server. During the secure session, the smart card receives a message containing an initial international identity from the personalization server, and replaces the temporary international identity and the temporary authentication key by the initial international identity and the initial authentication key.


