Method and Apparatus for Enabling Machine To Machine Communication
Abstract
A method and apparatus for performing secure Machine-to-Machine (M2M) provisioning and communication is disclosed. In particular a temporary private identifier, or provisional connectivity identification (PCID), for uniquely identifying machine-to-machine equipment (M2ME) is also disclosed. Additionally, methods and apparatus for use in validating, authenticating and provisioning a M2ME is also disclosed. The validation procedures disclosed include an autonomous, semi-autonomous, and remote validation are disclosed. The provisioning procedures include methods for re-provisioning the M2ME. Procedures for updating software, and detecting tampering with the M2ME are also disclosed.
Claims
exact text as granted — not AI-modified1 - 14 . (canceled)
15 . A method performed by a wireless device, comprising:
initiating secure communications with a first wireless network, using a provisional connectivity identifier (PCID), to obtain operational access to a desired wireless network; establishing, via the first wireless network, a protected IP-based connection with a first functional entity reachable via the first wireless network; establishing, over the protected IP-based connection, a security association with a second functional entity reachable via the first wireless network; receiving, from the second functional entity via the protected IP-based connection, a profile, wherein the profile comprises an identity and at least one credential for use in authenticating with and operationally accessing the desired wireless network; and provisioning the received profile on the wireless device.
16 . The method of claim 15 , further comprising:
activating the received profile; initiating authentication with the desired wireless network using the identity and the at least one credential provided in the profile; deriving a shared secret using the at least one credential provided in the profile; and communicating with the desired wireless network using the derived shared secret.
17 . The method of claim 15 , wherein the at least one credential comprises a public-private keyset associated with the desired wireless network.
18 . The method of claim 15 , wherein the profile received from the second functional entity via the protected IP-based connection is securely protected by the second functional entity.
19 . The method of claim 15 , wherein the profile is configured to enable the wireless device to operationally access the desired wireless network.
20 . The method of claim 15 , wherein the first functional entity comprises a Discovery and Registration Function (DRF).
21 . The method of claim 15 , wherein the second functional entity comprises a Downloading and Provisioning Function (DPF).
22 . The method of claim 15 , further comprising updating connectivity parameters used for communications during receiving the profile and during any subsequent update of the profile.
23 . The method of claim 15 , wherein the secure communications with the first wireless network are for the limited purpose of receiving the profile.
24 . The method of claim 15 , wherein the desired wireless network is one of the first wireless network or another wireless network.
25 . The method of claim 15 , wherein the PCID indicates an intent of the wireless device to obtain operational access to the desired wireless network.
26 . A wireless device comprising a processor, a transmitter, and a receiver, wherein the wireless device is configured to perform operations comprising:
initiating secure communications with a first wireless network, using a provisional connectivity identifier (PCID), to obtain operational access to a desired wireless network; establishing, via the first wireless network, a protected IP-based connection with a first functional entity reachable via the first wireless network; establishing, over the protected IP-based connection, a security association with a second functional entity reachable via the first wireless network; receiving, from the second functional entity via the protected IP-based connection, a profile, wherein the profile comprises an identity and at least one credential for use in authenticating with and operationally accessing the desired wireless network; and provisioning the received profile on the wireless device.
27 . The wireless device of claim 26 , where the wireless device is configured to perform further operations comprising:
activating the received profile; initiating authentication with the desired wireless network using the identity and the at least one credential provided in the profile; deriving a shared secret using the at least one credential provided in the profile; and communicating with the desired wireless network using the derived shared secret.
28 . The wireless device of claim 26 , wherein the at least one credential comprises a public-private keyset associated with the desired wireless network.
29 . The wireless device of claim 26 , wherein the wireless device comprises a trusted environment (TRE), and wherein the trusted environment performs the initiating, establishing, receiving, and provisioning.
30 . The wireless device of claim 29 , where the wireless device is configured to perform further operations comprising verifying an integrity of the TRE and an integrity of the received profile.
31 . The wireless device of claim 26 , wherein the first functional entity comprises a Discovery and Registration Function (DRF).
32 . The wireless device of claim 26 , wherein the second functional entity comprises a Downloading and Provisioning Function (DPF).
33 . The wireless device of claim 26 , wherein the secure communications with the first wireless network are for the limited purpose of receiving the profile.
34 . The wireless device of claim 26 , wherein the desired wireless network is one of the first wireless network or another wireless network.Join the waitlist — get patent alerts
Track US2018242129A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.