Subscription Identifier Binding for IoT Fraud Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The high cost of Universal Integrated Circuit Card (UICC) and embedded UICC (eUICC) technologies for IoT devices poses a significant obstacle to the widespread adoption of IoT, as they are expensive and offer lower security, making them prone to subscription fraud, especially when integrated tightly with modem or processing chip circuitry, which complicates strict security assurance and device management.
Innovation Solution
A system comprising a Core Network node, Device Management node, Verification node, and Network Access node that binds a subscription identifier to a device characteristic, ensuring unique association and verifying the device's possession of the characteristic before granting network access, thereby preventing cloned credentials from accessing the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If UICC and eUICC technologies are used to hold and protect subscriber credentials, then security is improved, but device cost increases significantly
Solution Approach 1:
The patent extracts the security function from the physical UICC/eUICC card and implements it as a virtual security module within the device. The subscription credentials are stored and protected by a security module that can be integrated into the device's existing processor, eliminating the need for separate expensive UICC/eUICC hardware while maintaining security functionality.
Solution Approach 2:
The patent combines the security functions previously requiring separate UICC/eUICC hardware with the device's existing processor and memory resources. By merging these functions into a unified security module that leverages existing device components, the solution reduces overall device cost while maintaining subscription protection capabilities.
2Ease of manufacture
If SIM functions are integrated in device modem or main processing chip (iUICC and MCIM), then device cost is reduced, but security assurance becomes difficult to implement
Solution Approach 1:
The patent segments the integrated chip into functionally separate logical domains: a secure credential storage area and a general processing area. This segmentation allows strict security assurance to be applied to the credential storage functions while permitting less restrictive design for other chip functions, resolving the contradiction between integration and security.
Solution Approach 2:
The patent applies different security levels to different parts of the integrated chip. The credential storage and authentication functions receive strict security assurance similar to UICC/eUICC, while other device functions operate with standard security measures. This localized quality approach enables cost-effective integration without compromising security where needed.
3Ease of manufacture
If tightly integrated SIM solutions are used to lower cost, then device cost decreases, but risk of subscription fraud increases due to difficulty in applying strict security assurance
Solution Approach 1:
The patent introduces an intermediary verification mechanism that binds subscription identifiers to device characteristics through a trusted verification node. This intermediary layer prevents subscription fraud by ensuring that even if credentials are extracted from a device, they cannot be successfully used in another device without matching the bound characteristics, thus mitigating fraud risk while maintaining cost benefits.
4Reliability
If subscription identifiers are bound to device characteristics for fraud prevention, then security against fraud is improved, but device management complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where devices automatically perform verification of their own characteristics against bound subscription identifiers. The device autonomously checks whether its characteristics match the binding requirements before attempting network authentication, reducing the need for complex external management interventions while maintaining fraud prevention capabilities.
Data Source
AI summary
A system is disclosed for managing a communication network subscription identifier associated with a device. The system comprises a Core Network node configured to provide a subscription identifier for the device to a Device Management node with management responsibility for the device. The system further comprises a Verification node configured to receive from the Device Management node the subscription identifier and a characteristic of the device, and to bind the subscription identifier to the characteristic such that the subscription identifier is uniquely associated with the characteristic. The system further comprises a Network Access node configured to obtain the subscription identifier from the device. The Verification node, Network Access node and Core Network node are configured to cooperate to verify that the device from which the Network Access node obtained the subscription identifier is in possession of the characteristic that is bound to the subscription identifier.


