Smart Card Remote Personalization via Temporary Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for personalizing UICC cards are not adaptable for embedding in devices before shipping or for Machine to Machine (M2M) applications, as they require physical intervention and do not allow users to choose their mobile network operator while maintaining authentication key confidentiality.

Innovation Solution

A method for initial personalization of a smart card that involves sending a temporary international identity and authentication key to a home location register, allowing the card to authenticate and negotiate an initial authentication key with a personalization server, enabling remote configuration without physical intervention or over-the-air key transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical personalization of UICC cards is performed in operator premises, then authentication key confidentiality is maintained, but adaptability for M2M and pre-embedded devices is lost

Engineering Contradiction:
Improveauthentication key confidentialityVSAvoidadaptability for M2M and pre-embedded devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

A personalization server acts as an intermediary between the operator and the UICC card. The server enables remote personalization by receiving personalization data from the operator and securely transmitting it to the UICC card through the communication device, eliminating the need for physical card handling while maintaining security through encrypted over-the-air transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/physical personalization process with an electronic/digital system. Instead of physically programming cards in operator premises, the personalization data is transmitted electronically over the air to the UICC card, substituting mechanical card handling with wireless communication and digital data transmission.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If remote personalization is implemented, then adaptability for M2M and pre-embedded devices is improved, but risk of authentication key interception increases

Engineering Contradiction:
Improveremote personalization capabilityVSAvoidrisk of authentication key interception
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the state of authentication keys from static to dynamic. Instead of using fixed authentication keys that could be intercepted and reused, the system generates temporary authentication keys that are valid only for specific personalization sessions. These temporary keys are automatically invalidated after use, preventing interception attacks.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary generation of temporary authentication keys before the actual personalization process. These temporary keys are prepared in advance and used to secure the communication channel during personalization, ensuring that even if the communication is intercepted, the captured data cannot be reused without the temporary keys.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If temporary authentication keys are used for remote personalization, then security against interception is improved, but complexity of the personalization process increases

Engineering Contradiction:
Improvesecurity against interceptionVSAvoidcomplexity of personalization process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The UICC card performs self-personalization by automatically receiving and processing personalization data from the personalization server. The card autonomously executes the personalization process without requiring manual intervention or complex external equipment, simplifying the overall process despite using temporary authentication keys.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The personalization server provides a universal platform that handles multiple personalization operations through a single interface. The server manages temporary key generation, secure data transmission, and card personalization in one integrated system, reducing the need for multiple separate systems and procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9288310B2Smart card initial personnalization with local generation of keys
Publication Date: 2016.03.15 ALCATEL LUCENT SA
  • US9288310B2 patent drawing
  • US9288310B2 patent drawing
  • US9288310B2 patent drawing

AI summary

A method and system for initial personalization of a smart card coupled with a communication device of a user who is not yet a subscriber of any telecommunication network are disclosed. A temporary international identity and a temporary authentication key are stored in the smart card and in a home location register connected to a roaming entity of a telecommunication network. A series of signals are exchanged between the smart card, the roaming entity, an application server and a personalization server to establish a secure session between the smart card and the personalization server. During the secure session, the smart card receives a message containing an initial international identity from the personalization server, and replaces the temporary international identity and the temporary authentication key by the initial international identity and the initial authentication key.