USIM Operator Change Authentication via Key Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3GPP architecture for remote initial provisioning of Universal Subscriber Identity Modules (USIMs) and operator changes in M2M communication is complex and insecure, leading to issues like 'slamming' and denial-of-service attacks, with no flexible authentication mechanism to prevent unauthorized operator changes in unattended devices.
Innovation Solution
A method using a device key and one-way functions to derive multiple keys for secure provisioning and operator changes, ensuring only authorized owners can initiate and manage these processes, with key hierarchies and authentication mechanisms to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a PVA certificate is installed as a trusted certificate in an M2M device at manufacture time, then the device can be provisioned by operators with PVA-signed certificates, but this creates security gaps allowing illegal operator changes (slamming) without user consent
Solution Approach 1:
The patent segments the authentication function by introducing a separate authentication function identifier (AFID) and authentication function key (AFK) structure. Instead of relying on a single PVA certificate, the system divides authentication into multiple independent authentication functions, each with its own key pair. This allows the device to distinguish between different authentication functions and prevents unauthorized operator changes while maintaining legitimate provisioning flexibility.
Solution Approach 2:
The patent implements preliminary action by pre-configuring the device with a root key and a hierarchical key structure during manufacture. The device is also pre-programmed with the authentication function identification mechanism. This preliminary setup enables the device to autonomously verify operator authentication credentials without requiring physical SIM replacement or user intervention, thereby preventing slamming while maintaining operational flexibility.
2Ease of operation
If physical SIM/USIM card replacement is used to change operator, then operator change is achieved, but this method is difficult for unattended devices and requires physical access which does not guarantee authorization
Solution Approach 1:
The patent replaces the mechanical physical SIM card replacement process with a wireless authentication mechanism. The device communicates authentication credentials to the operator through the network using the AFID/AFK system. This substitution eliminates the need for physical access to the device while maintaining secure authorization verification, making operator change feasible for unattended devices.
Solution Approach 2:
The patent introduces the authentication function key (AFK) and authentication function identifier (AFID) as intermediary elements between the device and the operator. These intermediaries enable secure communication and verification without requiring direct physical contact or SIM card handling. The AFK acts as a digital key that mediates the authentication process, ensuring authorized operator changes while enabling remote operation.
3Productivity
If remote management of M2M devices is implemented, then management costs are reduced, but the existing 3GPP architecture becomes complex and leaves security gaps
Solution Approach 1:
The patent implements universality by designing a multi-functional authentication framework that handles multiple operations through a single unified mechanism. The AFID/AFK system serves multiple purposes: operator authentication, service authentication, and authorization control. This universal approach simplifies the remote management architecture compared to separate specialized protocols, while maintaining security against various attack vectors.
4Adaptability or versatility
If unauthenticated discovery function is allowed to divert devices to operator networks, then device mobility is enabled, but this causes denial-of-service attacks on the network
Solution Approach 1:
The patent applies preliminary anti-action by implementing authentication verification before the discovery function can execute any network redirection. The device first verifies the authentication status using the AFID/AFK mechanism before allowing any operator change or network attachment. This preliminary security check prevents unauthenticated discovery functions from causing denial-of-service attacks while preserving legitimate device mobility and operator change capabilities.
Data Source
Figure 1
Figure 2A~2B
Figure 3
AI summary
A system, method, and owner node for securely changing a mobile device (31) from an old owner (61) to a new owner (62), or from an old operator network (81) to a new operator network (82). The old owner initiates the change of owner or operator. The old owner or operator then commands the mobile device (31) to change a currently active first key to a second key. The second key is then transferred to the new owner or operator. The new owner or operator then commands the mobile device to change the second key to a third key for use between the mobile device and the new owner or operator. Upon completion of the change, the new owner (62) or operator (82)does not know the first key in use before the change, and the old owner (61) or operator (81) does not know the third key in use after the change.