摘要:
A system (200) is disclosed for managing a communication network subscription identifier associated with a device. The system comprises a Core Network node (210) configured to provide a subscription identifier for the device to a Device Management node with management responsibility for the device. The system further comprises a Verification node (230) configured to receive from the Device Management node the subscription identifier and a characteristic of the device, and to bind the subscription identifier to the characteristic such that the subscription identifier is uniquely associated with the characteristic. The system further comprises a Network Access node configured to obtain the subscription identifier from the device. The Verification node (230), Network Access node (220) and Core Network node (210) are configured to cooperate to verify that the device from which the Network Access node obtained the subscription identifier is in possession of the characteristic that is bound to the subscription identifier.
摘要:
There is provided mechanisms for handling subscription profiles for a set of wireless devices. A method is performed by an MNO entity. The method comprises obtaining a single request for handling subscription profiles for the set of wireless devices. The method comprises performing, with a profile provisioning server, a preparation procedure for the set of wireless devices wherein a common batch profile handling parameter for the set of wireless devices is created, and whereby the set of wireless devices are associated with at least one matching identifier for tracking actions relating to the handling of the subscription profiles at the MNO entity and the profile provisioning server.
摘要:
There is presented mechanisms for profile handling of a communications device (300). A method is performed by a local profile assistant (200a) of a proxy device (200). The method comprises obtaining an indication of handling a profile of the communications device (300). The method comprises establishing a first secure communications link with a local profile assistant of the communications device. The method comprises establishing a second secure communications link with a subscription management entity (430) of the communications device. The method comprises receiving information pertaining to handling of the profile by the local profile assistant of the communications device, the information being received from the subscription management entity over the second secure communications link. The method comprises providing the information to the local profile assistant of the communications device over the first secure communications link.
摘要:
A method of establishing a session key at a communication device is disclosed, wherein the session key is to be shared between the communication device and a network application function (NAF) and wherein a service bootstrap key and an associated transaction identifier, previously derived by application of a general bootstrapping architecture (GBA) procedure, are shared between the communication device and a bootstrapping server function (BSF). The method comprises acquiring a NAF identifier associated with the NAF, deriving a NAF specific key based on the NAF identifier and the service bootstrap key, deriving the session key based on the NAF specific key and one or more key defining parameters, wherein the key defining parameters are accessible by the communication device and by the NAF and are non- accessible by the BSF, and transmitting an attach request message and the transaction identifier towards the NAF for establishment of the session key at the NAF. Corresponding method at a network application function, arrangements, communication device and access network node are also disclosed.
摘要:
There is provided mechanisms for handling download of a subscription profile from a pool of subscription profiles. The subscription profiles of the pool of subscription profiles are served by an MNO entity. A method is performed by a subscription management entity. The subscription management entity manages the pool of subscription profiles. The pool of subscription profiles has its own pool identifier. The method comprises obtaining a request from a communication device for download of one of the subscription profiles from the pool of subscription profiles. The method comprises enabling download to the communication device of one of the subscription profiles from the pool of subscription profiles. The method comprises filling up the pool of subscription profiles so that total number of subscription profiles in the pool of subscription profiles remains unchanged.
摘要:
There is provided mechanisms for handling credentials of an IoT SAFE applet. A method is performed by a communication device. The communication device stores the IoT SAFE applet in a first security domain of a subscription module in the communication device. The first security domain is free from any subscription profile and is different from any security domain of the subscription module for storing subscription profiles. The IoT SAFE applet is independent from any MNO. The communication device is without credentials for the IoT SAFE applet for establishing secure communication for the communication device with a network node. The method comprises obtaining credentials for the IoT SAFE applet from the network node. The method comprises storing the credentials in the first security domain of the subscription module. The credentials are, after successful storage, accessible only from within the first security domain. The method comprises establishing, using the IoT SAFE applet and at least one of the credentials, secure communication for the communication device with the network node.
摘要:
A method (100) for performing an authentication procedure between a verifying device and a responding device is disclosed, the verifying and responding devices being provisioned with security credentials. The method, performed by the verifying device, comprises generating an authentication challenge (110), delivering the authentication challenge to the responding device (120), receiving an authentication response from the responding device (130), and verifying the authentication response (140). According to the method, at least one of the authentication challenge or authentication response is encoded as a sequence of qubits and delivered over a quantum communication channel between the verifying device and the responding device (120A, 120B, 130A, 130B). Also disclosed are methods for delivering and receiving a message over a quantum communication channel, and devices for performing authentication and message exchange methods.
摘要:
Methods for communication for a device and a transport node are disclosed, the transport node facilitating communication between the device and a server. The method (100) for the device comprises assembling a message for sending to the server via the transport node (120), the message comprising a message payload, an application layer header, and a signature, wherein at least one of the message payload or a part of the application layer header is encrypted. The method further comprises retrieving a compression context identifier corresponding to the application layer header (130), replacing the application layer header in the message with the retrieved compression context identifier (140) and forwarding the message to the transport node (150). The method (200) for the transport node comprises retrieving an application layer header corresponding to the compression context identifier (220), and replacing the compression context identifier in the message with the retrieved application layer header (230).
摘要:
This disclosure provides a method, performed in a wireless device 60, for obtaining initial access to a network 700, 800 in order to establish a connection to a server 80 connected to the network 700, 800. The wireless device 60 stores a device public key and a device private key. The server 80 stores the device public key. The method comprises transmitting S1 an initial access request to a network node 70 of the network 700, 800 and receiving S2 an authentication request from the network node 70, the authentication request comprising a challenge. The method comprises generating S4 a device authenticator based on the challenge and the device public key, and transmitting S5 an authentication response to the network node 70. The authentication response comprises the device authenticator. The method comprises receiving S6 an initial access response from the network node 70, the initial access response comprising an indicator of whether the initial access is granted or denied.
摘要:
There is provided mechanisms for downloading an operational subscription profile to a communication device. A method is performed by the communication device. The communication device has an EID and is provided with a provisioning subscription profile. The method comprises obtaining a temporary PSI for the provisioning subscription profile, wherein the temporary PSI is based on the EID. The method comprises providing, whilst using the provisioning subscription profile, the temporary PSI to a first MNO as part of performing network attachment with the first MNO. The first MNO is selected based on the temporary PSI. The method comprises obtaining, whilst using the provisioning subscription profile and as part of performing network access authentication for the network attachment, an operational PSI from an eSIM server via the first MNO. The method comprises providing, whilst using the provisioning subscription profile, the operational PSI to a second MNO as part of establishing initial network connectivity with the second MNO. The second MNO is selected based on the operational PSI. The method comprises downloading, whilst using the initial network connectivity and the provisioning subscription profile, the operational subscription profile from the eSIM server via the second MNO to the communication device.