Transitive eSIM Bootstrapping via Trusted Bridge

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The eSIM bootstrapping process for new information handling systems is cumbersome, especially for devices without screens or limited input methods, requiring manual pairing which can be challenging and costly for corporate consumers.

Innovation Solution

A transitive bootstrapping method where a trusted and authenticated information handling system acts as a bridge to initiate the bootstrapping process for an untrusted new system, communicating with the trusted core network to retrieve and update the SIM profile, allowing direct communication once authenticated.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual pairing is used for eSIM bootstrapping, then network authentication can be achieved, but the process becomes cumbersome and challenging for devices without screens or limited input methods

Engineering Contradiction:
Improvenetwork authenticationVSAvoidpairing process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A trusted information handling system acts as an intermediary device between the new untrusted information handling system and the core network. The trusted system receives a request from the new system, initiates bootstrapping on behalf of the new system, and communicates with the core network to retrieve and install the SIM profile, thereby eliminating the need for manual pairing operations on the new device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trusted information handling system performs preliminary actions by pre-establishing trust credentials and being pre-authenticated with the core network. When a new system needs bootstrapping, the trusted system already has the necessary credentials in place to immediately initiate and complete the authentication process without requiring manual intervention from the new device.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual pairing is required for bootstrapping, then security authentication can be verified, but costs increase for corporate consumers

Engineering Contradiction:
Improvesecurity authenticationVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The new untrusted information handling system performs self-service bootstrapping by automatically requesting and receiving SIM profile installation through the trusted system. The system autonomously completes the authentication and provisioning process without requiring manual configuration or intervention, reducing deployment complexity and associated costs for corporate consumers.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If a trusted system acts as a bridge for bootstrapping, then the process is simplified for new devices, but additional system requirements are introduced

Engineering Contradiction:
Improvebootstrapping processVSAvoidsystem architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The trusted information handling system performs multiple functions: it serves as an authentication gateway, a communication bridge to the core network, and a provisioning agent for SIM profile installation. By consolidating these functions in a single trusted system, the solution simplifies the overall architecture compared to requiring bootstrapping capabilities in every new device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11934528B2System and method for providing transitive bootstrapping of an embedded subscriber identification module
Publication Date: 2024.03.19 DELL PROD LP
  • US11934528B2 patent drawing
  • US11934528B2 patent drawing
  • US11934528B2 patent drawing

AI summary

A system and method for establishing a bootstrap bridge via a network interface device at an information handling system to provide a transitive bootstrapping process for an untrusted (new) information handling system, wherein the bootstrap bridge comprises a temporary network enabler for communicating with the untrusted (new) information handling system and a secure gateway for communicating with a trusted core network, and wherein the bootstrap bridge receives an authentication request from the untrusted (new) information handling system via the temporary network enabler, wherein the authentication request includes an untrusted (new) information handling system identification (ID) with temporary authentication data loaded to the untrusted (new) information handling system upon manufacture, and the network interface device to transmit a request for challenge for the untrusted (new) information handling system ID to the trusted core network via the secure gateway on behalf of the untrusted (new) information handling system.