Updating a subscriber identity module
A method performed by a server, the method comprising transmitting a value to an authentication entity; receiving a first message from the authentication entity wherein the first message is generated using the value; deriving a pre-shared key using the first message; transmitting the value to a device over a network; encrypting a second message using the pre-shared key; and transmitting the encrypted second message over the network to the device
1 . A method performed by a server, the method comprising:
receiving, from a device over a network, an agent identifier and a subscriber identity module, SIM, identifier of a SIM on the device;
generating a random value;
transmitting the random value and the SIM identifier of the SIM to an authentication entity;
receiving an authentication response from the authentication entity wherein the authentication response is generated using the random value;
deriving a pre-shared key using the authentication response;
storing the derived pre-shared key in association with the agent identifier in a memory;
transmitting the random value to the device over the network;
encrypting a message using the pre-shared key; and
transmitting the encrypted message over the network to the device.
2 . The method of claim 1 , further comprising:
receiving an update request message over the network from the device, wherein the update request message comprises the agent identifier and is encrypted prior to transmission using the pre-shared key;
decrypting the update request message using the stored pre-shared key; and
transmitting an update response message as the message over the network to the device, wherein the update response message comprises update data and is encrypted using the stored pre-shared key.
3 . The method of claim 2 , wherein the update request message is decrypted with a first session key derived from the pre-shared key, and the update response message is encrypted with a second session key derived from the pre-shared key.
4 . The method of claim 1 , wherein the random value is a challenge.
5 . The method of claim 1 , wherein the authentication response comprises a signed response and a cipher key.
6 . The method of claim 5 , wherein the pre-shared key is derived further using at least one of the signed response and the cipher key.
7 . The method of claim 1 , wherein the message includes data to be used in the subscriber identity module, SIM, on the device.
8 . A server comprising at least one processor configured to:
receive, from a device over a network, an agent identifier and a subscriber identity module, SIM, identifier of a SIM on the device;
generate a random value;
transmit the random value and the SIM identifier of the SIM to an authentication entity;
receive an authentication response from the authentication entity wherein the authentication response is generated using the random value;
derive a pre-shared key using the authentication response;
store the derived pre-shared key in association with the agent identifier in a memory;
transmit the random value to the device over the network;
encrypt a message using the pre-shared key; and
transmit the encrypted message over the network to the device.
9 . A nontransitory computer readable medium storing a computer program, the computer program comprising code configured so as when executed on a processor of a server to perform the method of claim 1 .
10 . A method performed by a server, the method comprising:
transmitting a random value to an authentication entity;
receiving an authentication response from the authentication entity wherein the authentication response is generated using the random value;
deriving a pre-shared key using the authentication response;
transmitting the random value to a device over a network;
encrypting a message using the pre-shared key;
transmitting the encrypted message over the network to the device;
receiving an update request message over the network from the device, wherein the update request message comprises an agent identifier and is encrypted prior to transmission using the pre-shared key;
decrypting the update request message using the stored pre-shared key; and
transmitting an update response message as the message over the network to the device, wherein the update response message comprises update data and is encrypted using the stored pre-shared key.
11 . The method of claim 10 , wherein the update request message is decrypted with a first session key derived from the pre-shared key, and the update response message is encrypted with a second session key derived from the pre-shared key.
12 . The method of claim 10 , wherein the random value is a challenge.
13 . The method of claim 10 , wherein the authentication response comprises a signed response and a cipher key.
14 . The method of claim 13 , wherein the pre-shared key is derived further using at least one of the signed response and the cipher key.
15 . The method of claim 10 , wherein the message includes data to be used in the subscriber identity module, SIM, on the device.
16 . A nontransitory computer readable medium storing a computer program, the computer program comprising code configured so as when executed on a processor of a server to perform the method of claim 1 .