USIM-Based Key Derivation for Multi-Device Subscription Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need to efficiently manage 3GPP subscriptions across multiple User Equipment (UE) devices without compromising security, as current methods require separate subscriptions for each device, leading to unnecessary costs and resource usage.

Innovation Solution

A method and apparatus that allow multiple communication devices to share a single subscription by using a Universal Subscriber Identity Module (USIM) to generate unique keys for each device, enabling secure communication with a 3GPP network using a single subscription identity and access protection keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate subscriptions are assigned to each UE device, then security is maintained, but cost and resource usage increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidsubscription information storage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple UE devices under a single subscription identity, allowing multiple devices to share one subscription instead of each requiring a separate subscription. This reduces the quantity of subscription information stored in the network while maintaining security through device-specific key derivation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single subscription identity serves multiple functions by enabling access for multiple different UE devices. The subscription becomes universal across devices, with each device deriving its own access keys from the shared subscription, eliminating the need for device-specific subscriptions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate subscriptions are assigned to each UE device, then device-specific security is ensured, but additional cost is incurred for each subscription

Engineering Contradiction:
Improvedevice-specific securityVSAvoidsubscription cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent changes the parameter structure by deriving device-specific security keys dynamically from a single subscription identity rather than using static device-specific subscriptions. Each UE device generates its own access keys through key derivation functions using the shared subscription, maintaining device-specific security without incurring additional subscription costs.

Inventive Principle:
Principle #35Parameter changes

3Quantity of substance

If multiple UEs share a single subscription, then cost and resource usage are reduced, but security management complexity increases

Engineering Contradiction:
Improvesubscription information storageVSAvoidsecurity management
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments the security management into two layers: a shared subscription identity layer for cost efficiency and device-specific key derivation layer for security. Each UE device performs independent key derivation from the shared subscription, creating segmented security contexts that simplify overall management while maintaining device-specific security.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If separate subscriptions are used for each UE, then network access control is simplified, but communication resources are wasted

Engineering Contradiction:
Improvenetwork access controlVSAvoidcommunication resources
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent creates virtual copies of the subscription access rights for each UE device through key derivation, rather than creating physical separate subscriptions. Each device receives derived keys that function as copies of the original subscription credentials, enabling network access control without duplicating the full subscription infrastructure and reducing resource waste.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2460371B1Method and apparatus for creating security context and managing communication in mobile communication network
Publication Date: 2020.04.08 SAMSUNG ELECTRONICS CO LTD
  • EP2460371B1 patent drawingFigure 1
  • EP2460371B1 patent drawingFigure 2
  • EP2460371B1 patent drawingFigure 3

AI summary

A method and apparatus for establishing communication between a plurality of communication devices and a communication network using a single subscription is provided. The method receives a first request from a second communication device to get a subscription identity and capabilities of subscription for accessing the communication network using subscription of the first communication device. The method then sends the first request to a Universal Subscriber Identity Module (USIM) associated with the first communication device. Thereafter, the method receives a response from the USIM including subscription identity, access protection keys and capabilities of the subscription. Then the method generates unique key for the second communication device based on the response received from the USIM. The method then sends the response along with the generated unique key to the second communication device to establish communication between the second communication device and the communication network using the subscription of first communication device.