3 ms·
They never needed it from a technical perspective, it's there to make provisioning easier. Because the carriers were pretty decoupled from the baseband ecosyst
by trelliscoded 9y ago
They never needed it from a technical perspective, it's there to make provisioning easier. Because the carriers were pretty decoupled from the baseband ecosystem, there wasn't a really good way to get the subscriber keys into the radio hardware unless the carrier stuck their nose in the supply chain somehow. Because baseband vendors all hate each other, there wasn't a lot of interest in cooperating to create a standard to do something like that. Plus, Gemalto kept trying to throw monkey wrenches into the committees by doing some quite frankly pretty messed up things.
Regardless, profit is important and someone had to get squeezed out of the BoM of these things being manufacturing in the billions. It finally happened because of a combination of improvements to system on chip security, CMs cracking down on security, and the carriers hauling their EDI based provisioning systems into the 21st century. As a result, carriers can now securely provision devices after manufacturing. AT&T is kind of a jerk about it though, they do some stuff to the SIM when you onboard an unlocked device sometimes to tie it to their network.
I'm still not entirely clear how the keys get distributed in a SIMless world though. The process I use to onboard stuff into Verizon's IoT cloud involves me uploading a CSV file to a server somewhere and making some REST requests, but it's just IMSIs. The virtual UICC in the products like your watch works pretty much the same way, according to my chip vendor. But they have a multicarrier solution where the virtual UICC already knows about the major networks, so maybe they're exchanging keys as part of the OTA activation flow and securing it with a hardware key they give to the carriers in a HSM or something. Or maybe the manufacturers are getting HSMs at the factory and doing it right in the manufacturing process. I tried to wrap my head around the 3GPP documents on the subject and I just got more and more confused.
There's definitely a vendor proprietary aspect to what's going on though, because I can see the OTA provisioning packets in QXDM and it says it doesn't know how to decode them.