USIM Operator Change Authentication via Key Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP architecture for remote initial provisioning of Universal Subscriber Identity Modules (USIMs) and operator changes in M2M communication is complex and insecure, leading to issues like 'slamming' and denial-of-service attacks, with no flexible authentication mechanism to prevent unauthorized operator changes in unattended devices.

Innovation Solution

A method using a device key and one-way functions to derive multiple keys for secure provisioning and operator changes, ensuring only authorized owners can initiate and manage these processes, with key hierarchies and authentication mechanisms to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a PVA certificate is installed as a trusted certificate in an M2M device at manufacture time, then the device can be provisioned by operators with PVA-signed certificates, but this creates security gaps allowing illegal operator changes (slamming) without user consent

Engineering Contradiction:
Improveoperator provisioning flexibilityVSAvoidsecurity against unauthorized operator changes
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authentication function by introducing a separate authentication function identifier (AFID) and authentication function key (AFK) structure. Instead of relying on a single PVA certificate, the system divides authentication into multiple independent authentication functions, each with its own key pair. This allows the device to distinguish between different authentication functions and prevents unauthorized operator changes while maintaining legitimate provisioning flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-configuring the device with a root key and a hierarchical key structure during manufacture. The device is also pre-programmed with the authentication function identification mechanism. This preliminary setup enables the device to autonomously verify operator authentication credentials without requiring physical SIM replacement or user intervention, thereby preventing slamming while maintaining operational flexibility.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If physical SIM/USIM card replacement is used to change operator, then operator change is achieved, but this method is difficult for unattended devices and requires physical access which does not guarantee authorization

Engineering Contradiction:
Improveoperator change processVSAvoidauthorization verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical physical SIM card replacement process with a wireless authentication mechanism. The device communicates authentication credentials to the operator through the network using the AFID/AFK system. This substitution eliminates the need for physical access to the device while maintaining secure authorization verification, making operator change feasible for unattended devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces the authentication function key (AFK) and authentication function identifier (AFID) as intermediary elements between the device and the operator. These intermediaries enable secure communication and verification without requiring direct physical contact or SIM card handling. The AFK acts as a digital key that mediates the authentication process, ensuring authorized operator changes while enabling remote operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If remote management of M2M devices is implemented, then management costs are reduced, but the existing 3GPP architecture becomes complex and leaves security gaps

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidprovisioning architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing a multi-functional authentication framework that handles multiple operations through a single unified mechanism. The AFID/AFK system serves multiple purposes: operator authentication, service authentication, and authorization control. This universal approach simplifies the remote management architecture compared to separate specialized protocols, while maintaining security against various attack vectors.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If unauthenticated discovery function is allowed to divert devices to operator networks, then device mobility is enabled, but this causes denial-of-service attacks on the network

Engineering Contradiction:
Improvedevice network mobilityVSAvoiddenial-of-service attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing authentication verification before the discovery function can execute any network redirection. The device first verifies the authentication status using the AFID/AFK mechanism before allowing any operator change or network attachment. This preliminary security check prevents unauthenticated discovery functions from causing denial-of-service attacks while preserving legitimate device mobility and operator change capabilities.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP2340654B1Method for securely changing a mobile device from an old owner to a new owner.
Publication Date: 2018.04.25 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2340654B1 patent drawingFigure 1
  • EP2340654B1 patent drawingFigure 2A~2B
  • EP2340654B1 patent drawingFigure 3

AI summary

A system, method, and owner node for securely changing a mobile device (31) from an old owner (61) to a new owner (62), or from an old operator network (81) to a new operator network (82). The old owner initiates the change of owner or operator. The old owner or operator then commands the mobile device (31) to change a currently active first key to a second key. The second key is then transferred to the new owner or operator. The new owner or operator then commands the mobile device to change the second key to a third key for use between the mobile device and the new owner or operator. Upon completion of the change, the new owner (62) or operator (82)does not know the first key in use before the change, and the old owner (61) or operator (81) does not know the third key in use after the change.