Remote UICC Provisioning via Dynamic Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge in Machine-to-Machine (M2M) applications is the inability to easily change network subscriptions on embedded universal integrated circuit cards (UICCs) in communication devices, necessitating secure and remote provisioning of access credentials while preserving security, flexibility, and end-user benefits across GSM, 3GPP, and 3GPP2 systems.
Innovation Solution
A method and system for secured remote provisioning of UICCs, involving a request for remote provisioning with a machine identifier and PLMN identifier, dynamic generation of security keys, and provisioning of an international mobile subscriber identity (IMSI) using shared key management servers and operator networks, ensuring secure key management and subscription changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If UICC is embedded in communication device to enable M2M applications, then device security and stability are improved, but ability to change network subscriptions becomes problematic
Solution Approach 1:
The system segments the UICC functionality by introducing a separate provisioning system that can remotely update the embedded UICC. The UICC is divided into a static embedded portion (providing security) and a dynamically provisioned portion (enabling subscription changes). This allows the embedded UICC to maintain security while enabling remote subscription management through a provisioning server that can download and install new network credentials.
Solution Approach 2:
A remote provisioning system acts as an intermediary between the network operator and the embedded UICC. This intermediary enables secure remote provisioning of network credentials without requiring physical access to the embedded UICC. The provisioning system receives provisioning data from the operator, secures it, and delivers it to the UICC, thus enabling subscription changes while maintaining the security benefits of the embedded card.
2Adaptability or versatility
If remote provisioning mechanism is introduced to enable subscription changes, then adaptability is improved, but security risks increase
Solution Approach 1:
The system performs preliminary actions by pre-configuring the embedded UICC with provisioning capabilities and security credentials before remote provisioning occurs. The UICC is pre-programmed with a provisioning application that can securely receive and process remote provisioning commands. This preliminary setup ensures that when remote provisioning occurs, the security infrastructure is already in place to handle the subscription changes securely.
Solution Approach 2:
The invention replaces the mechanical/physical system of UICC replacement with an electronic/remote provisioning system. Instead of physically removing and inserting UICCs, the system uses electronic delivery of provisioning data over the network. This substitution maintains security through encrypted communication channels and authentication mechanisms while enabling remote subscription changes without physical access to the device.
3Reliability
If physical UICC replacement is used to change network operator, then security is maintained, but ease of operation deteriorates
Solution Approach 1:
The system enables self-service by allowing the embedded UICC to automatically receive and process provisioning data from the remote provisioning system without user intervention. The UICC contains a provisioning application that can autonomously receive provisioning commands, validate them, and update its credentials. This eliminates the need for users to manually replace UICCs while maintaining security through automated authentication and encryption protocols.
Data Source
AI summary
The present invention provides a method and system for secured remote provisioning of a universal integrated circuit card of a user equipment. A system includes a user equipment for initiating a request for remote provisioning of an universal integrated circuit card (UICC) in the user equipment, where the request for remote provisioning includes a machine identifier (MID) associated with the user equipment and a public land mobile network (PLMN) identifier (ID) associated with an network operator. The system also includes at least one shared key management server for dynamically generating security keys and an operator shared key using the security keys, the MID. Moreover, the system includes an operator network for generating a subscription key using the operator shared key and an international mobile subscriber identity (IMSI), and provisioning the IMSI in a secured manner to the UICC of the user equipment using the security keys.


