Subscriber Module Authorization for Secure IoT Profile Download

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current subscription profile download methods for IoT devices lack secure authorization mechanisms, making them vulnerable to unauthorized profile downloads and malware attacks.

Innovation Solution

Implementing authorization of SM-DS events or profile download operations using authorization secrets, ensuring that only authorized profiles are downloaded and protecting against malware by verifying second authorization information against a first authorization secret within the subscriber module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authorization verification mechanisms are implemented for subscription profile download, then security against unauthorized access and malware is improved, but device complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring the subscriber module with a first authorization secret during device provisioning, before any profile download operations occur. This allows the device to immediately verify authorization tokens received from subscription management entities without requiring complex runtime authorization negotiations, thus enhancing security while minimizing processing overhead during actual profile downloads.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authorization secrets are stored in the subscriber module for verification, then protection against unauthorized profile downloads is improved, but the risk of secret exposure and malware attacks increases

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authorization token mechanism that mediates between the subscription management entity and the subscriber module. Instead of the subscriber module directly exposing or using its first authorization secret for verification, the system uses a second authorization token generated by the subscription management entity. This token serves as a secure intermediary that proves authorization without requiring the subscriber module to expose its secret, thus maintaining security while reducing vulnerability to malware attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple authorization verification steps are added to the profile download procedure, then security against malware-induced profile changes is improved, but download time and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring the subscriber module with the first authorization secret during device provisioning, before any profile download operations occur. This allows the device to immediately verify authorization tokens received from subscription management entities without requiring complex runtime authorization negotiations, thus enhancing security while minimizing processing overhead during actual profile downloads.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex mechanical verification processes with cryptographic token verification. Instead of implementing multiple iterative verification steps or human intervention, the system uses cryptographic authorization tokens that can be verified through efficient mathematical operations. This substitution dramatically reduces the time required for authorization verification while maintaining strong security against malware-induced profile changes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250193654A1Download of a Subscription Profile to a Communication Device
Publication Date: 2025.06.12 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250193654A1 patent drawing
  • US20250193654A1 patent drawing
  • US20250193654A1 patent drawing

AI summary

There is provided mechanisms for subscription profile download. A method is performed by a communication device. The subscriber module of the communication device is configured with a first authorization secret. The method comprises receiving, as part of performing a subscription profile download procedure, second authorization information from a subscription management entity. The second authorization information is generated using a second authorization secret. The method comprises downloading the subscription profile only if the second authorization information, according to a matching criterion, matches the first authorization secret.