Subscriber Module Subscription Profile Download Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current subscription profile download procedures for IoT devices lack secure and computationally efficient mechanisms, making them vulnerable to malware attacks that can trigger rogue subscription profile downloads and installations.
Innovation Solution
A method for secure subscription profile download and installation involves obtaining and validating download and installation data that identifies the SM-DP+ or SM-DS entity, ensuring that only authorized profiles are downloaded and installed, and using signed data to protect against malware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If subscription profile download is enabled for IoT devices without user interface, then automated profile handling and batch device management are achieved, but security vulnerability to malware attacks increases
Solution Approach 1:
The system performs preliminary actions by obtaining and validating download and installation data before the actual subscription profile download. The validation of the OID (Object Identifier) ensuring it points to an authorized SM-DP+ or SM-DS entity is done in advance, preventing malware from redirecting to rogue entities during the download process.
Solution Approach 2:
The patent introduces an intermediary validation mechanism that acts as a mediator between the IoT device and the SM-DP+ entity. The download and installation data serves as an intermediary credential that verifies the authenticity of the download source, preventing direct malware interference in the download process.
2Reliability
If validation of download and installation data is implemented, then security against rogue profiles is improved, but computational overhead increases
Solution Approach 1:
The system uses copied and verified identifier data (OID) from trusted sources rather than performing complex real-time verification. The download and installation data contains pre-validating information that can be checked through comparison and verification of identifiers, which is computationally lighter than full cryptographic validation.
Data Source
AI summary
There is provided mechanisms for subscription profile download and installation. A method is performed by a subscriber module. The method comprises obtaining download and installation data (DID), for the subscription profile. The DID identifies an OID of an SM-DP+ entity and/or an SM-DS entity, for the subscriber module to use when downloading and installing the subscription profile. The method comprises validating the DID to ensure the DID is acceptable by the subscriber module for use in the subscription profile download and installation. The method comprises downloading the subscription profile from an SM-DP+ entity. The SM-DP+ entity from which the subscription profile is to be downloaded from is either given by the OID identified by the DID when the OID is of the SM-DP+ entity, or is given by an event record received by the subscriber module from the SM-DS entity when the OID identified by the DID is of the SM-DS entity and wherein the SM-DS entity is given by the OID identified by the DID. The method comprises installing the subscription profile in the subscriber module.


