System and method for secure-core silicon mobile end-points to determine KYC and kyt
Patent Information
- Application Number
- PCT/US2025/024215
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-10
- Filing Date
- 2025-04-11
- Publication Date
- 2026-09-17
Smart Images

Figure US2025024215_17092026_PF_FP_ABST
Abstract
Description
PCT / US25 / 24215 11 April 2025 (11.04.2025)System and Method for Secure-Core Silicon Mobile End-Points to Determine KYC and KYTBACKGROUND OF THE INVENTION
[0001] The global economy based on the U. S. dollar is often referred to as a "hard currency" due to the political and economic stability of the United States. At this time, more than two dozen countries recognize the U. S. dollar as legal tender. Changes in state of the U. S.'s domestic economy, economic regulation, political gyrations, and deliberate manipulation to influence, sanctions, nations, organizations, and at times individuals may introduce uncertainty around the world. This dichotomy is not sustainable for an inclusive global economy.
[0002] There are at least 27 countries that accept U. S. dollars as legal tender, either officially or unofficially. Most nations recognize the U. S. dollar as hard currency, which is money that is issued by a nation that is seen as politically and economically stable and widely accepted around the world as a form of payment. However, with mounting national debt and changes in U. S. policy that have promoted globalization since the end of World War II over seventy-five years ago, an increasing number of countries and international organizations have been considering alternatives to the U. S. dollar for their national and supranational economic activities.
[0003] In more recent times, there has been a new Industry Revolution: The International Telecommunication Union ( ITU) defines the Tactile Internet as an internet network that combines ultra-low latency with extremely high availability, reliability, and security. It believes the Tactile Internet represents a "revolutionary level of development for society, economics and culture."
[0004] The mobile internet allowed us to exchange data and multimedia content on the move. The next step is the loT, which enables the interconnection of smart devices. The Tactile Internet is the next evolution that will enable the control of the loT in real time. It will add a new dimension to human-to-machine interaction by enabling tactile and haptic sensations and, at the same time, revolutionize the interaction of machines.
[0005] The Tactile Internet will enable humans and machines to interact with their environment, in real time, while on the move and within a certain spatial communication range. It will unleash the full potential of the fourth industrial revolution, dubbed Industry 4.0 (moving beyond Web 3.0), and revolutionize the way we learn and work through the Internet of Skills, aka Human 4.0.
[0006] Proponents of the Tactile Internet argue that it should build on areas where machines are strong and humans are weak, so that the machines complement rather than substitute humans. As the power of the machines increases, the value of the human input should also grow.PCT / US25 / 24215 11 April 2025 (11.04.2025)
[0007] Current State of The Art ID Verification: Government Passports, Driver Licenses, and National IDs (IDs), among other identification documents, serve as credible identification documents, but they have limitations when it comes to proving a person's true identity.
[0008] IDs are primarily designed for international and domestic travel, banking, asset management, taxation, succession, and investing, but are not designed to meet the modern age of digitalization. Government IDs establish the holder's citizenship and street address along with a picture of the person. All of this data is "static” in the digital economy that demands continuous authentication of many factors required to combat fraud, crime, terrorism, and inefficiencies and hacks in current ID and KYC systems.
[0009] IDs are vulnerable to Al-generated fake IDs, which have become a highly concerning issue, especially when it comes to remote identity verification, which is normal in the digital economy and world infrastructures.
[0010] OnlyFake in the dark web application uses neural networks to generate realistic fake ID images. It aims to fool remote identity verification tools. For instance, sites like Bitcoin, which require only a photo of a Government ID for sign-up, are at risk from customers using Al-generated fake IDs to create false identities. However, our investigation revealed that the images produced by OnlyFake were far from visually passable IDs and would likely fail to scan or fool an ID scanner.
[0011] Telegram Channel fraudsters have been discussing Al-created fake IDs on a Telegram channel. One such linked site is Passport Cloud, which offers a user-friendly interface for generating fake IDs. While Al may have been used to create visual templates, these IDs are useless in brick-and-mortar scenarios or when attempting to bypass ID authentication. They lack ultraviolet or infrared markings, making them detectable in physical situations.
[0012] Creating a Fake ID Using Al, you input your information into the system. This includes your name, personal data, photo, and birth date. The system then generates a fake ID that looks like the real thing. OnlyFake's process users enter their name, biographical data, upload a photo (or choose one from OnlyFake's archives), and select an Al-generated signature. In minutes, OnlyFake generates images of the fake ID's front and back, which users can attempt to upload to websites requiring ID verification.
[0013] Authenticity limitations in these Al-generated fake IDs lack ultraviolet or infrared markings, rendering them ineffective in physical scenarios. They can only be used where an image of an ID canPCT / US25 / 24215 11 April 2025 (11.04.2025)be uploaded.
[0014] In summary, while Al-generated fake IDs exist, their limitations make them unsuitable for most practical purposes. Businesses should continue to enhance their fraud detection and identity verification solutions to stay ahead of evolving threats. IDs contain essential information such as the holder's name, photo, nationality, and passport number. While this information is valuable, it doesn't provide a comprehensive picture of a person's identity.
[0015] Lack of biometrics is also a challenge. Although modern IDs include biometric features (such as facial recognition and fingerprint templates and scans), these features are not always used for routine identity checks. Everyday identity verification often relies on additional biometrics (like fingerprints or retinal scans) that passports do not capture.
[0016] With the era of real-time services, including real-time payment and real-time ledger settlement, now offered in the global banking systems, remote and digital identification can be important. IDs are critical, but only the first step. Using mobile technology, standardized in every country in the world, offers a new dimension to capture and analyze mobile radio frequency transmissions and sensor readings from mobile device MEMs devices to capture and identify unique patterns to prove the true identity of any person using a mobile phone operating 4G LTE and 5G radio frequency transmission spectrum.
[0017] Another challenge arises in more modern times and that's climate change. In the development discourse, a basic needs model focuses on the measurement of what is believed to be an eradicable level of poverty. Development programs following the basic needs approach do not invest in economically productive activities that will help a society carry its own weight in the future, rather they focus on ensuring each household meets its basic needs even if economic growth must be sacrificed today. These programs focus more on subsistence than fairness. Nevertheless, in terms of "measurement", the basic needs or absolute approach is important. The 1995 world summit on social development in Copenhagen had, as one of its principal declarations, that all nations of the world should develop measures of both absolute and relative poverty and should gear national policies to "eradicate absolute poverty by a target date specified by each country in its national context. " It is not in the interest of politicians to ever reach this goal of eradicating both absolute and relative poverty. Reducing the political, unneeded, criminal, and terrorist influences can be achieved in the global supply chain that operates transparently, and all counterparties to all transactions are known and legal.
[0018] Government regulatory agencies, such as the Securities and Exchange CommissionPCT / US25 / 24215 11 April 2025 (11.04.2025)in the United States, Financial Conduct Authority (FCA) in the United Kingdom, Securities & Commodities Authority (SCA), in the United Arab Emirates, The Australian Securities and Investments Commission (ASIC), in Australia, among other securities regulation agencies in the world, provide "accredited type" or sophisticated investor is an investor with a special status under financial regulation laws. The definition of an accredited investor, and the consequences of being classified as such, vary between countries. In the United States the SEC regulates two classes of investors, either Reg. D or Reg. A., the issue is that no interoperable methods and systems exist to quickly determine in the age of digitalization, (i) inclusive, by social development goal, status, (ii) real-time capture of secured debt: unsecured debt: income over specified time period: assets: liquidity options: timing, (iii) identification methods outside of government ID verification, and (iv) complete immutable payment transaction history.SUMMARY OF THE INVENTION
[0019] The intent of this system (and method) is to democratize economic services by providing access to basic and fair financial services for people who are unbanked or underbanked, such as those with disabilities, minorities, or marginalized groups. The method leverages blockchain-based processes, embedded in smart legal contracts using on-chain internal bank-ledger transactions.
[0020] The System and Method will incorporate blockchain smart legal contracts to automatically adjust the supply and demand balancing trade finance and consumer lending down to a single person.
[0021] The system to tokenize deposits at the core of internal-ledger of central, commercial, development, and regional fiat currency banks aims to provide an alternative to the high volatility, outside remittance type money services, and low usability of other e-tokens (cryptocurrency, Bitcoin, and stable-coins) as a medium of global digitalization exchange using on-chain smart legal contracts. This system creates decentralized financial and asset management services that allow anyone to access and use blockchain technology and smart legal contracts to ensure the security, transparency, and accountability of the internal-bank real-time services and provide globally inclusive opportunities for the people of the world by building local economies never before possible.
[0022] It would also allow users to choose from a variety of lending options according to theirPCT / US25 / 24215 11 April 2025 (11.04.2025)preferences and needs, so users could have more financial inclusion and empowerment, as well as access to a global network of peers who can trade and exchange value with each other. The platform would also reduce the barriers and costs of entry for accessing and using tokenized deposits, such as regulatory compliance, intermediaries, and fees.
[0023] Two challenges in the digital and blockchain economy are properly identifying people and businesses, especially for micro-SMEs and SMEs (MSME).
[0024] Digital and digitalization-represented assets may have unclear, transitional, and contested states of ownership. A hybrid system like that described may deploy such applications as an escrow and repatriation method that allows digital assets to be processed through a dual or multi-party oversight process to ensure equitable and auditable distribution of assets to one or more parties. The process can employ Know Your Customer / Know Your Business (KYC / KYB) procedures, automated and human-in-the-loop processes, and provide for digital and digitally represented assets to support people and MSMEs globally.
[0025] The system, using equivalent methods for human identification by use of on-chain data-processing protocols managing immutable data layers for software-node-chain methods and hardware secure-core-silicon methods to achieve the promise of the Tactile Internet will have applications, including but limited to, automation, robotics and telepresence are already growing in importance in industrial applications like smart factories and the remote operation of industrial machinery enabling the efficient manufacturing of highly customized products, remote precious metals and stones mining in high-risk areas, and remote inspection, geological reports as to provide adequate background information to inform mining operations, compliance, black-listed: sanctioned unmined assets, contract management, location of the site(s), the general site setting, the proposed land use, and the purpose and scope of the geologic investigation to provide remote management for instant liquidity with captive fiat-cash deposits in ATMs to assets in the ground for financial: risk: compliance: rate of liquidity to time ratios.
[0026] This invention also teaches novel methods to achieve robust Know Your Customer and Know Your Transaction in the digitalization economy.
[0027] The system may also help provide economic rights asserted through the Articles of the United Nations Universal Declaration of Human Rights. The United Nations aims to maintain international peace and security, promote cooperation among nations, and protect human rights. This method provides a way for any organization, public or private, to provide more financially inclusive and empowering financial services, as well as access to a global network of peers who canPCT / US25 / 24215 11 April 2025 (11.04.2025)trade and exchange value with each other. The cloud-based blockchain promises that, but does not reach the population of the world to be truly effective. A hybrid mobile network, SIM, and Cloud Consensus System and Method operating together in harmony has a logical high potential of achieving this.
[0028] The hybrid approach would enhance users' rights to privacy, freedom of movement, and freedom of expression. It would support various use cases that could benefit human rights, such as supply chain transparency, voting, digital identity, and land rights management, among the properly loT Tethered real-world assets. These use cases could improve users' rights to work, education, participation, and security.
[0029] A secure communication system for mobile devices in a packet-based wireless mobile network with identity security of both user and transaction includes: a system controller of the secure communication system that is an entity that can transact, wherein the system controller issues and controls encryption keys to customers for secure transactions; a first SIM device in the packet-based wireless mobile network wherein the first SIM device captures quality of service data, user identity data and transaction data; a second SIM device in the packet-based network that is separated from the first SIM device and receives captured data from the first SIM device and stores captured data as immutable data; and a packet-based communication network with data packets wirelessly transmitted in standard packets on-chain node consensus processing, wherein captured data from the first SIM device and the second SIM device are analyzed and data elements that establish a hybrid pattern for user identity and transaction authorization are performed under authority of the system controller before issuing encryption keys.BRIEF DESCRIPTION OF THE DRAWINGS
[0030] FIG. 1 illustrates a three-encryption-key multi-signature process is a cryptographic method where three separate keys are used to authorize and validate a transaction or operation.
[0031] FIG. 2 illustrates a system architecture in which a Subscriber Identity Module (SIM)-based Applet is configured to collect data from a mobile equipment and a mobile network.
[0032] FIG. 3 illustrates the sensory environments of this invention, which includes 309 SIM, 310 Mobile Equipment (ME), MEMS device, and 311 User Input to authenticate end users and transactions in a continuous authentication method.
[0033] FIG. 4 illustrates the sensory, measurements, and extraction capabilities of 413 SIM arePCT / US25 / 24215 11 April 2025 (11.04.2025)managed by a firmware embedded 414 Applet, in most implementations Java Card coding language.DETAILED DESCRIPTION OF THE INVENTION
[0034] So that the manner in which the recited features, advantages and objects of the present invention are attained and can be understood in detail, a more particular description of the present invention, summarized above, may be had by reference to the embodiments thereof which are illustrated in the appended drawings.
[0035] It is to be noted, however, that the appended drawings illustrate only typical embodiments of this invention and are therefore not to be considered limiting of its scope, for the present invention may admit to other equally effective embodiments.
[0036] FIG. 1 illustrates a three-encryption-key multi-signature process as a cryptographic method where three separate keys are used to authorize and validate a transaction or operation. It typically involves the following steps: 101 HSM Key 1 Generation - Three unique encryption keys (public-private key pairs) may be created, often assigned to different parties for added security and decentralization.
[0037] 102 CLOUD Key 2 Multi-Signature Authentication - A transaction or message requires a predefined threshold (e.g., 2-of-3 or 3-of-3) of the available keys to sign before it is considered valid.
[0038] 103 SIM Key 3 Verification and Execution - The system verifies the required number of signatures using the corresponding public keys and executes the transaction if the authentication criteria are met.
[0039] This process enhances security, prevents single points of failure, and is novel when the SIM provides the means for Verification and Execution used in cryptocurrency wallets, secure communications, and logical access control systems. The HSM Key 1 HSM may comply with FIPS 140-2 Level 3 or 4 (or the newer FIPS 140-3) to be approved for sensitive key management in government and regulated industries. Cryptographic modules may implement approved key generation methods using NIST-approved algorithms.
[0040] FIG. 2 illustrates a system architecture in which a Subscriber Identity Module (SIM)-based Applet is configured to collect data from a mobile equipment and a mobile network. The collected data is securely stored and managed on a permissioned blockchain network, implemented using a 204 Quorum blockchain. As depicted, transactions propagate through both 205 public and 206 private states within the system. The architecture incorporates secure enclaves 207, which functionPCT / US25 / 24215 11 April 2025 (11.04.2025)as isolated, trusted execution environments. These enclaves operate as virtual hardware security modules (HSMs) to execute cryptographic operations, including encryption and decryption, within a segregated processing space, thereby mitigating exposure of sensitive information to unauthorized access even in the event of system compromise. Additionally, transaction managers 208 are configured to coordinate encryption, processing, and secure data transmission between network components. The transaction managers enforce access control policies and ensure that only authorized entities within the network can retrieve or modify data. This mechanism maintains system integrity, enhances trust, and facilitates transparency across the blockchain ecosystem.
[0041] Stepwise, FIG. 2 shows the following steps.
[0042] 1. Private Transaction Submission (Private Tx AB). The Dapp, which could be a SIM applet application, submits a private transaction containing SIM information to Quorum Node A 204.
[0043] 2. Transaction Payload Storage (TxPayloadStore). Quorum Node A sends the transaction payload to the Transaction Manager A 208 for storage.
[0044] 3. Encryption / Decryption Request. Transaction Manager A 208 sends an encryption request to Enclave A 207 to secure the transaction data.
[0045] 4. Transaction Response from Enclave A 207. Enclave A 207 processes the request and returns an encrypted transaction response to Transaction Manager A 208.
[0046] 5. Storing the Encrypted Transaction Payload. The encrypted transaction payload is stored in Transaction Manager A 208.
[0047] 6. Transaction Hash Generation. A hash of the transaction is generated and sent from Transaction Manager A 208 to Quorum Node A 204.
[0048] 7. Ethereum Transaction Submission. Quorum Node A 204 submits the transaction (Ethereum Tx for example) following the Ethereum protocol, ensuring consensus among blockchain nodes.
[0049] 8. Block Containing Transaction Data. A new block containing the transaction (Blockl23 w / Tx AB) is created and added to the blockchain. A request is sent to Transaction Manager A 208 to retrieve the original transaction payload.
[0050] 9. Transaction Payload Request (TxPayloadRequest). A request is sent to Transaction Manager A 208 to retrieve the original transaction payload.
[0051] 10. Decryption Request to Enclave A 207. Transaction Manager A 208 sends a decryption request to Enclave A 207 to retrieve the original transaction payload.
[0052] 11. Decryption Response (TxResponse). Enclave A 207 returns the decrypted transactionPCT / US25 / 24215 11 April 2025 (11.04.2025)payload to Transaction Manager A 208.12. Transaction Payload Response (TxPayloadResp). The original transaction payload is sent back to Quorum Node A 206, completing the retrieval process.
[0053] FIG. 3 illustrates the environments of this system, which includes 309 SIM, 310 Mobile Equipment (ME), MEMS device, and 311 User Input to authenticate end users and transactions in a continuous authentication method. The system creates an adaptive security framework that continuously monitors and verifies the authenticity of users based on a combination of hardware and software components.
[0054] 309 SIM Authentication: The 309 SIM module or device provides a sensor for measuring radio frequency transmissions, mobile network elements, and 310 Mobile Equipment (ME) as defined in the technical specification as Metric Capture I (MCI).
[0055] 310 ME: The mobile equipment and mobile apps act as cross-reference points to the SIM. The 309 SIM is a form of temper-resistant silicon. Measurements from the 309 SIM are more reliable than the 310 ME and cloud environments. These cross-reference elements may use GPS vs. Base Station Triangulation, for accurate geolocation, device usage patterns, among others.
[0056] 312 MEMS Sensors: The MEMS device gathers environmental and physiological data such as motion, pressure, temperature, and gyroscopic readings as referenced in the technical specification as Metric Capture II (MC II). These sensors enable behavioral analysis, ensuring that authentication factors are not easily spoofed.
[0057] 311 User Input: The system and method capture direct user inputs such as keystroke dynamics, touchscreen interactions, and voice commands. This four-dimensional continuous authentication is used to identify anomalies and fraudulent activity prior to it occurring. This 311 User Input is defined as Metric Capture III (MCIII).
[0058] FIG 4. illustrates the sensory, measurements, and extraction capabilities of 413 SIM are managed by a firmware embedded 414 Applet, in most implementations Java Card coding language.414 The Applet is a system and method to determine measurements contained in Capture I (MCI).415 Bearer Service Usage available to the 310 ME are USSD, SMS, Binary-SMS, UDP, Bearer Independent Protocol (BIP) and IP / TCPIP. The 414 Applet measures elements in Capture I (MCI), encrypts the measurements, and all encrypted data is transferred between the Applet and 417 Server. 416 User Input (UI) captures measurements defined in Metric Capture III (MCIII).
[0059] In the era of cloud computing, where server execution and storage software reside in a unified ecosystem, vulnerabilities arise. Encryption key generation, distribution, signing, andPCT / US25 / 24215 11 April 2025 (11.04.2025)
[0060] root-of-truth recovery all occur within this cloud environment. However, this centralized approach lacks the redundancy and separation necessary for robust security. To address this, the system employs secure-core silicon mobile endpoints, ensuring that no single entity has full control over the software execution environment.
[0061] Additionally, existing private and public blockchain technologies may fail to verify data records for correctness and authorization before storing them in immutable data. The solution herein bridges this gap by combining MN, IC, and NC elements, creating a secure and authenticated environment for on-chain transactions and data storage.
[0062] This system presents a novel fusion of Mobile Network (MN), Internet Cloud (IC), and Node Consensus (NC) components: (i) Mobile Network (MN), the system operates within the mobile network environment, (ii) Internet Cloud (IC), the cloud-based services play a crucial role in data processing and storage, and (iii) Node Consensus (NC) is the process of decentralized consensus mechanisms to ensure trust, agreement, and immutable data recordation among network nodes.
[0063] Secure-Core Silicon Mobile End-Points: Serve as trust anchors, ensuring the security of critical data. They monitor mobile network traffic, environmental probes, and user input. By analyzing radio frequency data transmission patterns and physical behavior and environment, a unique pattern is created.
[0064] On-Chain Transactions may use three encryption keys in three different logical and physical locations that two keys are used to sign and authorize on-chain transactions in a multi-signature framework. Smart legal contracts can be self-executed creating a manifestation of mutual assent by two or more persons to one another. This represents a meeting of the minds with a common intention and is established through offer and acceptance. In the case of smart legal contracts related to this system, the "agreement" may follow common law structure and interpretation.
[0065] Tamper-Resistant-Silicon or Secure-Core-Silicon are both Mobile End-Points, which is defined as the secure storage, processing, and communication of sensitive data, including Encryption Keys to create a Secure Execution Environment (SEE). These Mobile End-Points are SIMs and Hardware Security Modules (HSMs) and act as the data source of truth or Root of Trust to verify and authorize human transactions, based on standards and government compliance involved with Know Your Customer (KYC) and Know Your Transaction (KYT). The Mobile End-Points provide continuous data to determine the irregularities in cloud only execution environments compared to the Mobile End-Points. More specifically, HSMs provide a backup and core encryptionPCT / US25 / 24215 11 April 2025 (11.04.2025)key management system for SIM Applets. The SIM Applets deploy QES 256-bit encryption, the AES encryption keys are created, managed, and establish communication with SIM Applets, via a Server, to assign AES encryption keys.
[0066] An HSM is a specialized cryptographic processor designed to safeguard the entire lifecycle of cryptographic keys. These trust anchors play a critical role in protecting the cryptographic infrastructure of security-conscious organizations worldwide. Purpose: HSMs are dedicated devices that securely manage, process, and store cryptographic keys. They serve as the guardians of sensitive keys, ensuring their confidentiality, integrity, and availability. Use cases involve transaction security. Enterprises use HSMs to secure financial transactions, payment processing, and digital currency operations. Identity Protection with HSMs play a vital role in managing digital certificates, ensuring secure authentication, and protecting user identities. HSMs excel at provisioning encryption, decryption, digital signing, and authentication services for various applications.
[0067] HSMs play a part in smart legal contract systems that execute smart legal contracts securely, mainly in the area of off-network key restoration for backup purposes and onsite off-network transaction authentication. HSMs are tamper resistant where physically hardened against tampering, making them resistant to attacks.
[0068] HSMs securely store cryptographic keys, preventing unauthorized access. Cryptographic operations: play a critical role for HSMs to perform encryption, decryption, and other cryptographic functions.
[0069] Root of Trust:
[0070] HSMs establish a trusted foundation for cryptographic operations.
[0071] Key Lifecycle Management:
[0072] HSMs handle key generation, distribution, and retirement.
[0073] HSM Java Card Applets:
[0074] An HSM Java Card Applet is a software program that runs on a Java Card (a secure microcontroller). It provides HSM functionality within the Java Card environment. Common applications include digital signatures, encryption, authentication, and certificate management.
[0075] Two notable HSM Java Card Applets:
[0076] SmartCard-HSM: An open-source applet supporting RSA and ECC keys, PKCS#11, CSP-Minidriver,and OpenSC. Available as a USB key, smart card, plug-in, or MicroSD card.
[0077] RIscRIpt / HSMApplet: A custom applet implementing a subset of the PKCS#11 interface,PCT / US25 / 24215 11 April 2025 (11.04.2025)supporting RSA keys and SHA-256 hashing. Designed for low-resource Java Cards.
[0078] HSMs are critical components in securing sensitive data and ensuring the trustworthiness of cryptographic operations. Authentication and KYC / KYT:
[0079] The SIM and HSM (Secure-Core Silicon Mobile End-Points) manage Know-Your-Customer (KYC) and Know-Your-Transaction (KYT). Continuous transaction-by-transaction authentication enhances security.
[0080] Hardware Security Module (HSM):
[0081] An HSM is a specialized cryptographic processor designed to safeguard the entire lifecycle of cryptographic keys. These trust anchors play a critical role in protecting the cryptographic infrastructure of security-conscious organizations worldwide. Here are the key aspects of HSMs. Purpose: HSMs are dedicated devices that securely manage, process, and store cryptographic keys. They serve as the guardians of sensitive keys, ensuring their confidentiality, integrity, and availability. Use cases involve transaction security. Enterprises use HSMs to secure financial transactions, payment processing, and digital currency operations. Identity Protection with HSMs play a vital role in managing digital certificates, ensuring secure authentication, and protecting user identities. HSMs excel at provisioning encryption, decryption, digital signing, and authentication services for various applications.
[0082] HSMs play a major part of smart legal contract of systems that execute smart legal contracts securely, mainly in the area of off-network key restoration for backup purposes and onsite off-network transaction authentication. HSMs are tamper resistant where physically hardened against tampering, making them resistant to attacks.
[0083] HSMs securely store cryptographic keys, preventing unauthorized access. Cryptographic operations: play a critical role for HSMs to perform encryption, decryption, and other cryptographic functions.
[0084] Root of Trust:
[0085] HSMs establish a trusted foundation for cryptographic operations.
[0086] Key Lifecycle Management:
[0087] HSMs handle key generation, distribution, and retirement.
[0088] HSM Java Card Applets:
[0089] An HSM Java Card Applet is a software program that runs on a Java Card (a secure microcontroller). It provides HSM functionality within the Java Card environment. CommonPCT / US25 / 24215 11 April 2025 (11.04.2025)applications include digital signatures, encryption, authentication, and certificate management.
[0090] Two notable HSM Java Card Applets:
[0091] SmartCard-HSM: An open-source applet supporting RSA and ECC keys, PKCS#11, CSP-Minidriver, and OpenSC. Available as a USB key, smart card, plug-in, or MicroSD card.
[0092] RIscRIpt / HSMApplet: A custom applet implementing a subset of the PKCS#11 interface, supporting RSA keys and SHA-256 hashing. Designed for low-resource Java Cards.
[0093] HSMs are critical components in securing sensitive data and ensuring the trustworthiness of cryptographic operations.
[0094] System Identification Module (SIM):
[0095] A SIM is an integrated circuit (IC) based on secure-core-silicon. It can provide tamperresistant, immutable storage of data within hardware. Here are the key aspects of SIMs:
[0096] Functions include Identity and Authentication. SIMs securely store an International Mobile Subscriber Identity (IMSI)number and its related key. Mobile Subscriber Identification: SIMs enable mobile devices (such as phones and laptops) to identify and authenticate subscribers on mobile networks.
[0097] Physical Form: The actual physical card housing the SIM may be Universal Integrated Circuit Card (UICC). UICCs are typically made of PVC with embedded contacts and semiconductors.
[0098] The SIM itself is the primary component within the UICC.
[0099] Terminology and Terms:
[0100] Although technically accurate to refer to the IC as the SIM, in practice, the term " SIM card" is still commonly used to describe the entire UICC unit.
[0101] SIM Application Toolkit (SAT) Applet:
[0102] Embedded within both pSIM (physical SIM) and SIM platforms.
[0103] Enables direct and secure communication via Over-the-Air (OTA) channels. Managed by Mobile Network Operators (MNOs) globally.
[0104] Secure Execution Environments: pSIM and qSIM are standardized secure execution environments for Java Card Applets. These environments ensure the integrity and confidentiality of SIM-based operations.
[0105] Leveraging Industry Standards:
[0106] This invention builds upon industry-standard SIM Application Toolkit APIs and utilizes the Oracle Java Card programming language.
[0107] SIMs play a crucial role in mobile communication, ensuring secure identification,PCT / US25 / 24215 11 April 2025 (11.04.2025)authentication, and transaction capabilities across various devices.
[0108] Cloud Environment Overview:
[0109] Web Frontend: Language: TypeScript. Framework: React.js. State Management: Redux (for managing application state)
[0110] Server Backend:
[0111] Language: TypeScript (Node.js): Framework: Nest.js (for building the API).
[0112] Database: Type: MySQL (relational database): Mobile Application: Platform: Crossplatform (iOS and Android): Development Framework: React Native (enables cross-platform mobile app development with a shared codebase). Cloud Server (AWS Focus ): Platform: Amazon Web Services (AWS). AWS is chosen for its extensive services and global infrastructure.
[0113] Compute: Service: AWS EC2 (Elastic Compute Cloud). Provides scalable compute capacity (virtual servers).
[0114] Storage: Service: AWS S3 (Simple Storage Service): Used for object storage and data backup.
[0115] Database: Service: AWS RDS (Relational Database Service): Provides managed relational database services (MySQL in this case): CI / CD. Tools: Terraform (for infrastructure as code) with GitHub Actions (for continuous integration and continuous deployment). Serverless Functions: Service: AWS Lambda Executes code in response to events (e.g., API requests, file uploads): Key Management Service (KMS):
[0116] Service: AWS KMS: Manages cryptographic keys, specifically for secure wallet key storage. Essential for protecting sensitive blockchain transaction information. API Management: Service: AWS API Gateway: Creates, publishes, and secures APIs. Acts as a front door for your backend services.
[0117] Monitoring Service: AWS CloudWatch: Monitors resources, logs, and metrics. Provides insights into system performance and health: Cloud environment is a powerful combination of services and tools, allowing you to build scalable, secure, and reliable applications.
[0118] Blockchain Software Components:
[0119] Blockchain Network: Platform: Ethereum. Purpose: Supports smart legal contract capabilities and has a robust community.
[0120] Smart Legal Contract Development Language: Solidity Development Tools: HardhatPCT / US25 / 24215 11 April 2025 (11.04.2025)(for building and testing smart legal contracts). Consensus Mechanism for Private Networks (PoA).
[0121] Platform: Quorum
[0122] Consensus Algorithm: Proof of Authority (PoA) Requires two out of three keys to authorize on-chain Quorum transactions. Interacting with Smart Legal Contracts: Libraries: Web3.js or ethers.js (in the React environment). These libraries facilitate communication with smart contracts on the Ethereum network: Hashing in Blockchain
[0123] Hashing is a cryptographic technique that maps arbitrary-size data (such as text or files) to fixed-size values. The output of a hash function is called a hash value or hash code. Hashing ensures data integrity and security.
[0124] Properties of Cryptographic Hash Functions: Data Integrity: Hashes ensure that data (e.g., transactions) remains unchanged. Block Linking: Each block contains a hash of the previous block, creating a secure chain (the blockchain): Merkle Trees: Hashes are used to efficiently verify transactions within a block: Public Key Cryptography: Hashing connects public keys to private keys, preventing the derivation of private keys from public keys: Hashing is a fundamental building block of blockchain technology. It provides security, integrity, and trust within the decentralized network.
[0125] Encryption Key Framework: To deploy smart legal contracts, three encryption keys (SLC Key) in separate logical and physical locations provides governance, management, regulatory compliance, and execution for on-chain encryption key management in Cloud, HSM, and SIM software operating environments. This is a multi-signature digital framework, which takes two keys to sign and hash each on-chain transaction.
[0126] Three Dimensional Identification (3DI):
[0127] 3DI is defined as capturing critical identification and authentication data from three separate software processing environments (i) SIM / Mobile Network, (ii) MEMs Device, and (iii) User Input.
[0128] SIM / Mobile Network: Metric Capture I (MCI):Based on McGregor, et al. U. S. Patent Number 7,596,373 incorporated herein by reference as if fully set forth herein, the following data elements are captured based on mobile network, SIM, and smartphone interactions. This invention receives at least one data element from the Metric Capture I table below.3DI involves capturing critical identification and authentication data from three separate software processing environments. These environments include:PCT / US25 / 24215 11 April 2025 (11.04.2025)
[0129] SIM / Mobile Network:
[0130] Metric Capture I (MCI): Based on interactions within the mobile network, SIM card, and smartphone.
[0131] Captures essential data elements related to identification and authentication.
[0132] While the specific data elements from Metric Capture I are not provided here, the goal is to integrate information from these three distinct sources to enhance identification and security.
[0133] Method Description: Objective: Capturing data elements associated with Know Your Customer (KYC) and Know Your Transaction (KYT) in 3DI environments for blockchain transactions.
[0134] Components Involved: Mobile Communications Device: Within a mobile communications network.
[0135] SIM (Subscriber Identity Module): Captures data elements generated by each of MCI, MCII, and MCIII.
[0136] Process: The SIM captures relevant data elements (MCI, MCII, and MCIII). The SIM stores these data elements. The SIM establishes a 3DI communication channel (3DI COMMS) to transmit the collected data elements to the MC (Master Control) verification server. Once verified, two encryption keys are used to authorize and hash the transaction.
[0137] This method aims to enhance security and trust in blockchain transactions by leveraging 3DI environments and SIM-based data capture.
[0138] SIM / Mobile Network: Metric Capture I (MCI):
[0139] Based on McGregor et al. Pat. No. 7,596,373, the following data elements are captured based on mobile network, SIM, and smartphone interactions.
[0140] This invention receives at least one data element from the Metric Capture I, in Table 1 below:TABLE 1PCT / US25 / 24215 11 April 2025 (11.04.2025)Network Terminal Memory Dropped Transitions Usage (e.g. Connections, (Moving From 2G, dynamic) Connection Time 2.5G, or 3G) (i.e. success and failure) Energy per Chip Received Signal Signal to Noise Ratio Strength Indicator Interference Ratio (ECNR) (RSSI) (SIR) Battery Strength Packet Frame Error Rate Retransmission for Voice (FER)Block Error Rate Bit Error Rate Packet Loss for Data (BLER) (BER)OneWay Delay Round Trip Delay Inter-packet Delay (Jitter) Bandwidth Configuration (e.g. Identification (e.g.model of terminal, SIMOS version, OS -IMEI, MSISDN, type, and loaded and ICCID) applications, etc.)WiFi and RTLS Base Station Digital Rights Triangulation Triangulation Management Geolocation GeolocationLocation and Network (e.g., Data Timestamp network Communication transitions or (e.g., monitoring roaming) IP stack layers such as the physical layer)PCT / US25 / 24215 11 April 2025 (11.04.2025)Mobile Handset'sHardware Radio
[0141] MEMS Device: Metric Capture II (MCII):
[0142] The Micro-Electro-Mechanical Systems (MEMS) provides sensor capabilities to measure and receive at least one data element from the Metric Capture II in Table 2 below: TABLE 2Accelera Accelerator measures acceleration forces acting on the mobile tor: device. At its core, an accelerometer includes of a proof mass, a small, movable mass suspended within the mobile device. When the smartphone experiences acceleration (such as tilting or shaking), the proof mass moves from its normal position. One example of measurement, capacitive sensors detect movement by measuring the change in electrical capacitance caused by the proof mass's displacement.Gyrosco The gyroscope measures the rotation rate of the smartphone pe around its axes (roll, pitch, and yaw). The gyroscope relies on capacitance sensors. Example sample rotations up to 6,000 times per second, generating a new measured value every 0.16 millisecond.Gas Electrochemical reaction of gas molecules on the electrode surface when gas molecules interact with the sensor surface, they induce changes in potential difference or current between the electrodes. These changes are proportional to the concentration of the gas, allowing the sensor to detect its presence and measure its concentration. Gas sensors include Metal Oxide Sensors (MOS), these sensors detect gas concentration by measuring the resistance change ofPCT / US25 / 24215 11 April 2025 (11.04.2025)metal oxide due to gas adsorption. For example, they can detect gasses like C02, NOx, S02, and formaldehyde.Piezoelectric Sensors, these sensors utilize the piezoelectric effect to detect gas molecules. Various types include Piezoelectric Microcantilevers. These tiny structures bend when gas molecules interact with their surface. Surface Acoustic Waves (SAW), gas- induced changes in acoustic waves are detected, Quartz Crystal Microbalance (QCM), gas adsorption alters the crystal's resonance frequency, and Piezoelectric Micromachined Ultrasonic Transducer (PMUT): Detects gas-induced changes.Pressur Sensors detect pressure by monitoring the deformation of a e diaphragm. The diaphragm is a thin, flexible structure made from materials like silicon or polymers when subjected to pressure, the diaphragm bends or flexes, causing a change in its electrical properties. Example sensors include, Piezoresistive a conductive sensing element directly fabricated onto the diaphragm. Changes in resistance of these conductors provide a measure of the applied pressure.These sensors are widely used in applications like automotive, medical devices, and household appliances and Capacitive conducting layers are deposited on the diaphragm and the bottom of a cavity to create a capacitor. Deformation of the diaphragm changes the spacing between the conductors, altering the capacitance.Temper Thermocouples, these are contact-based sensors that generate a ature voltage proportional to the temperature difference between two dissimilar metals, Thermistors, these semiconductor-based sensors exhibit a change in resistance with temperature. They are sensitive and widely used in applications like climate control and medical devices, and sensors use the expansion or contraction of temperature-sensitive materials (such as diaphragms or beams) to detect temperature changes. The metallic layer onPCT / US25 / 24215 11 April 2025 (11.04.2025)these structures changes its electrical resistance due to the diaphragm's shape alterations.Light Optical MEMS integrates mechanical elements, electronics, and sensors on a silicon substrate through microfabrication. It enables unprecedented miniaturization and integration in optical systems. These devices combine electrical, mechanical, and optical systems to detect and manipulate optical signals at the micron level.Fabricating optical MEMS involves techniques like bulk and surface micromachining and deep X-ray lithography.Magneti A MEMS magnetic actuator is a device that utilizesc microelectromechanical systems (MEMS) to convert an electric Actuate current into a mechanical output. It achieves this by employing the rs well-known Lorentz Force Equation or the principles of magnetism.The Lorentz Force Equation describes the interaction between a current-carrying conductor and a static magnetic field. When a current flows through the conductor, the magnetic field around it generates a force. This force can be harnessed to cause the displacement of a mechanical structure within the MEMS device. These magnetic actuators find applications in various MEMS systems, including sensors, switches, and micro-actuators. Magnetic Sensors (Magnetometers): Magnetic sensors in MEMS devices determine the strength and direction of a magnetic field using the Lorentz force. When a looped electrical current passes through a magnetic field, the resulting force causes the loop to flex proportionally to the field's strength. These movements can be detected either electronically or optically.PCT / US25 / 24215 11 April 2025 (11.04.2025)Humidit Capacitive Humidity is sensed using capacitance in MEMS humidity y sensors. The basic structure of a capacitive humidity sensor Sensors includes of the following components: Electrode: Initially deposited on a substrate (usually silicon).Humidity- Sensitive Dielectric Layer: A thin layer (usually made of a moisture-sensitive polymer) deposited on top of the electrode.Moisture-Permeable Electrode: Added on top of the dielectric layer. Protective Layer: Covers the sensor to shield it from contamination andcondensation. When the humidity-sensitive dielectric absorbs water vapor, its dielectric constant increases, leading to an increase in capacitance.Conversely, at lower humidity levels, the dielectric gives up some water, causing the capacitance to decrease. The change in capacitance is nearly linear with relative humidity (RH) and is only slightly affected by temperature. MEMS IC sensors include circuitry to convert the capacitance measurement into a digital or analog output. These sensors are manufactured using integrated circuit (IC) methods. Long-term stability is generally good in normal applications, and the small capacitance ensures accurate measurements. MEMS humidity sensors find applications in weather monitoring, air conditioning, food storage, warehousing, and industrial processes.
[0143] User Input: Metric Capture III (MCIII):
[0144] All user input, except for mobile sensors and cameras, is direct from the SIM to the Mobile Device, bypassing iOS, Android, Firefox OS, and other Mobile Device operating system providers.
[0145] User Input involves various data captures based on the authorized user input. At least one User Input is captured as referenced in the Metric Capture III Table 3 below:TABLE 3PCT / US25 / 24215 11 April 2025 (11.04.2025)Password / PIN (static) User and system generatedOne Time password TOTP and HOTPSecure Send Point: Human to An authentication protocol where Machine Challenge Response the verifier sends the claimant a challenge (usually a random value or a nonce) that the claimant combines with a secret (often by hashing the challenge and a shared secret together, or byPCT / US25 / 24215 11 April 2025 (11.04.2025)applying a private key operation tothe challenge) to generate aresponse that is sent to the verifier.The verifier can independentlyverify the response generated bythe Claimant (such as by recomputing the hash of thechallenge and the shared secretand comparing to the response, or performing a public key operationon the response) and establish thatthe Claimant possesses andcontrols the secret.Fingerprint Recognition Sensors include capacitance,optical, and ultrasound.Facial Recognition Optical mobile device camera.Retna Recognition Optical mobile device camera.Box Recognition Capture of box image for KnowYour Box in an on-chainrecordation as an ERC 721.Gait Recognition Hand movements, waving patterns,and other activity patterns canhelp distinguish smartphoneowners from other users,providing passive and continuousauthentication.
[0146] 3DI Communication Means (3 DI COMMS):
[0147] 3DI communications originates its host communication via SIM Applet software. Once s least one of MCI, M C II, and MCIII is captures, the SIM Applet established an external connection via:
[0148] IMS Messaging:
[0149] IMS stands for IP Multimedia Subsystem. It’s a standardized architecturalPCT / US25 / 24215 11 April 2025 (11.04.2025)framework designed to deliver IP multimedia services. IMS was developed by the wireless standards body 3rd Generation Partnership Project (3GPP) as part of the vision for evolving mobile networks beyond GSM (2G). Its original formulation (3GPP Rel-5) aimed to deliver Internet services over GPRS (2.5G). Later updates extended support to networks beyond GPRS, including Wireless LAN, CDMA2000, and fixed lines. IMS uses IETF protocols like the Session Initiation Protocol (SIP). Examples of global standards based on IMS include: MMTel: Basis for Voice over LTE (VoLTE), Wi-Fi Calling (VoWIFI), Video over LTE (ViLTE), SMS / MMS over WiFi and LTE, Rich Communication Services (RCS), also known as joyn or Advanced Messaging.
[0150] DTMF:
[0151] A DTMF (Dual Tone Multi-frequency) message is a telecommunication signaling system that uses the voice-frequency band over telephone lines. It allows communication between telephone equipment, other communication devices, and switching centers. DTMF uses a set of eight audio frequencies transmitted in pairs to represent 16 signals. These signals correspond to the ten digits (0-9), the letters A to D, and the symbols # and *. When you press a key on a telephone keypad, it generates two tones of specific frequencies. These tones are used for various purposes, including accessing voicemail (entering passwords) and navigating Interactive Voice Response (IVR) systems used by large companies like banks.
[0152] USSD:
[0153] USSD (Unstructured Supplementary Service Data), is a communication protocol used in mobile devices and networks. USSD is part of the Global System for Mobile Communications (GSM) digital cellular standard. Similar to SMS and MMS, USSD enables communication without requiring a dedicated app. Unlike SMS, which involves back-and-forth text messaging between two phones, USSD establishes a real-time connection between your phone and a mobile network or server.PCT / US25 / 24215 11 April 2025 (11.04.2025)
[0154] SMS:
[0155] SMS, or Short Message Service, is a fundamental protocol used by cellular phones to send and receive text messages over 2G, 3G, 4G, or 5G networks. Unlike app-based messaging services that rely on internet connections, SMS operates directly within the cellular network. SMS enables the exchange of short text messages (up to 160 characters) between mobile devices.
[0156] Initially designed for GSM networks, SMS continued to function across various technologies, including CDMA, HSPA, 4G LTE, and 5G. The SMS standard defines the information sent in a text message, including the message length, timestamp, destination phone number, and the actual message content.
[0157] Internet Protocol:
[0158] The Internet Protocol (IP) is a fundamental set of rules governing the exchange of data packets across interconnected networks. IP ensures that data packets can travel across networks and reach their intended destinations. Data traversing the Internet is divided into smaller pieces called packets. Each packet carries an IP address, which helps routers direct them to the correct location.
[0159] An IP address is a unique identifier assigned to devices or domains connecting to the Internet. For example, an IP address might look like 192.168.1.1. DNS resolvers translate human-readable domain names into IP addresses.
[0160] Verification Server:
[0161] The Verification Server (VS) is a System and Method for determining atmospheric conditions around the world to validate and cross reference the MEMS devices that detect such atmospheric conditions in close vicinity to determine KYC. Weather patterns cause radio frequency (RF) interference, and saturation: pressure propagation and cause interference and signal saturation in communication systems that can be cross referenced with RF packet-data and subpacket chip energy composite. Systems and methods for determining RF KYC against mobile network and SIM RF measurements:
[0162] Rain Attenuation: Raindrops can absorb and scatter RF signals, leading to attenuation or weakening of the signal as it travels through the atmosphere. This attenuation is more pronounced at higher frequencies and can reduce the range and reliability of wireless communication systems, particularly for satellite communications and terrestrial microwave links.
[0163] Fog and Mist: Atmospheric moisture in the form of fog or mist can also scatter RF signals, causing signal loss and degradation. In dense fog conditions, the scattering effect can be significant, particularly at higher frequencies.
[0164] Snow: Similar to rain, falling snow can attenuate RF signals and cause signal degradation, especially in heavy snowfall conditions. Snow accumulation on antennas andPCT / US25 / 24215 11 April 2025 (11.04.2025)transmission lines can also affect the performance of communication systems.
[0165] Tropospheric Ducting: Certain weather conditions, such as temperature inversions in the lower atmosphere, can create a phenomenon known as tropospheric ducting. This can cause RF signals to be trapped and propagate over long distances, leading to interference and distortion in communication systems.
[0166] Thunderstorms and Lightning: Thunderstorms can generate electromagnetic interference (EMI) and induce electrical disturbances in RF circuits and transmission lines.Lightning strikes can directly damage antennas and other RF equipment, leading to signal disruption and equipment failure.
[0167] Solar Activity: Solar flares and geomagnetic storms can influence ionospheric conditions and affect the propagation of HF (high frequency) radio waves. These solar-induced disturbances can cause signal fading, polarization changes, and increased noise levels in radio communication.
[0168] To mitigate the effects of weather-related interference and saturation in RF communication systems, engineers employ various techniques such as antenna diversity, frequency hopping, power control, and adaptive modulation schemes. Additionally, accurate weather forecasting and monitoring can help operators anticipate and prepare for adverse weather conditions that may impact RF communication links. The comparison of the MEMS capture weather related with the global weather sensing systems to determine KYC.
[0169] These global weather systems provide methods to provide an array of instruments to sense and determine atmospheric conditions via computers around the world to detect weather in specific locations through a network of various technologies collectively known as weather forecasting and monitoring systems.
[0170] Satellites: Weather satellites orbiting the Earth capture images and data about cloud cover, temperature, precipitation, and other atmospheric conditions. These satellites provide a global view of weather patterns and can track storms, hurricanes, and other weather phenomena over large areas.
[0171] Radar: Doppler radar systems are used to detect precipitation, such as rain, snow, and hail, as well as the movement and intensity of storms. Radar data can provide detailed information about the location, intensity, and direction of precipitation in real-time.
[0172] Weather Stations: Ground-based weather stations are distributed across the globe to collect data on temperature, humidity, air pressure, wind speed, and wind direction. Automated weather stations continuously monitor these parameters and transmit the data to central databases for analysis.
[0173] Weather Balloons: Radiosondes are instruments attached to weather balloons thatPCT / US25 / 24215 11 April 2025 (11.04.2025)are released into the atmosphere to collect data on temperature, humidity, and pressure at various altitudes. This data is transmitted back to ground stations for analysis and used to improve weather forecasting models.
[0174] Weather Models: Computers use mathematical models of the atmosphere based on principles of physics to simulate and predict future weather conditions. These models incorporate data from satellites, radar, weather stations, and other sources to generate forecasts for specific locations.
[0175] Remote Sensing: Other remote sensing technologies, such as LiDAR (Light Detection and Ranging) and GPS (Global Positioning System), are also used to gather data on atmospheric conditions, terrain, and vegetation, which can influence weather patterns.
[0176] Crowdsourced Data: In addition to official weather monitoring systems, data from personal weather stations, weather apps, social media, and other sources are often aggregated and analyzed to improve the accuracy of weather forecasts, especially in areas with limited monitoring infrastructure.
[0177] EMBODIMENTS
[0178] 1. A secure communication system for mobile devices operating in a packetbased wireless mobile network, providing identity authentication of a user, mobile device, and transactions, the system comprising:
[0179] a system controller including an entity capable of conducting transactions, wherein the system controller issues and manages encryption keys associated with a SIM device to facilitate secure transactions;
[0180] a SIM device within the packet-based wireless mobile network, configured to capture Metric Capture I, Metric Capture II, and Metric Capture III data elements; and
[0181] a verification server, separate from the SIM device, within the packet-based wireless mobile network, configured to receive captured data from the SIM device, store the captured data, and perform analysis by cross-referencing the captured data against cloud-only data for irregularities to authenticate the user, mobile device, and transaction.
[0182] 2. The system of embodiment 1, wherein at least one of the Metric Capture I measurements is captured and analyzed as a data element for establishing the irregularity patterns for user identity, mobile device identity, and transaction authorization.
[0183] 3. The system of embodiment 1, wherein the mobile device includes one or more micro-electro-mechanical system sensors that capture at least one Metric Capture II data elements that are transmitted via UART, SPI, and / or I2C to the SIM.
[0184] 4. The system of embodiment 1, wherein the mobile device includes a means to communicate Metric Capture III data elements to the SIM as a unique factor input of the user.PCT / US25 / 24215 11 April 2025 (11.04.2025)
[0185] 5. The system of embodiment 1, wherein a user input method of Metric Capture III triggers the SIM to transmit data packets to measure the round-trip signal-to-interference ratio to capture a unique pattern for a unique signing of each transaction.
[0186]
[0187] 6. The system of embodiment 1, wherein near real-time user identity authentication is determined by the data captured by the SIM device, wherein the SIM device becomes a parent certificate authority in issuing certificates to control domains within internet protocol systems.
[0188] 7. The system of embodiment 1, wherein mobile device micro-electro-mechanical system sensors provide at least one Metric Capture II as unique pattern for unique signing of each transaction when requested by the SIM device
[0189] 8. A secure communication system for mobile devices operating in a packetbased wireless mobile network, providing identity authentication of the user, mobile device, and transactions, the system comprising:
[0190] a system controller, an entity capable of conducting transactions, wherein the system controller issues and manages encryption keys associated with a SIM device to facilitate secure transactions;
[0191] an immutable data recordation method using private node blockchain, separate from the SIM device, to record data elements consisting of Metric Capture I, Metric Capture II, and Metric Capture III data elements captured by the SIM device.
[0192] 9. The system of embodiment 8, wherein once user identity is established, transaction authorization is established, and encryption multiple keys are issued to complete and sign each blockchain transaction, and an identified user's transaction is completed in the packet-based communication system in near real-time.
[0193] 10. The system of embodiment 8, wherein the SIM manages cryptographic keys, specifically for secure wallet creation, key storage, and multi-signature signing policy where at three user identities are known in a three key signing policy for blockchain transactions.
[0194] 11. A secure communication system for mobile devices in a packet-based wireless mobile network with identity security of both user and transaction comprising:
[0195] a system controller of the secure communication system that is an entity that can transact, wherein the system controller issues and controls encryption keys to customers for secure transactions;
[0196] a first SIM device in the packet-based wireless mobile network wherein the first SIM device captures quality of service data, user identity data and transaction data;
[0197] a second SIM device in the packet-based network that is separated from the first SIMPCT / US25 / 24215 11 April 2025 (11.04.2025)device and receives captured data from the first SIM device and stores captured data as immutable data; and
[0198] a packet-based communication network with data packets wirelessly transmitted in standard packets on-chain node consensus processing, wherein captured data from the first SIM device and the second SIM device are analyzed and data elements that establish a hybrid pattern for user identity and transaction authorization are performed under authority of the system controller before issuing encryption keys.
[0199] 12. The system of embodiment 11, wherein the second SIM device is stationary.
[0200] 13. The system of embodiment 11, wherein the quality of service has QOS metrics and at least one QOS metric of significance is captured and analyzed as a data element for establishing the hybrid pattern for user identity and transaction authorization.
[0201] 14. The system of embodiment 11, wherein the first SIM device is a mobile wireless device that includes one or more micro-electro-mechanical sensors that capture and analyze environmental data from the first SIM device location and generates a data element for establishing the hybrid pattern for user identity and transaction authorization.
[0202]
[0203] 15. The system of embodiment 11, wherein the first SIM device has user security input controls wherein activation of one or more of the input controls is captured and analyzed to generate a data element for user identification.
[0204] 16. The system of embodiment 11, wherein the system controller has at least one dedicated cryptographic processor that analyzes generated data elements from the first SIM device and the second SIM device to establish user identity and transaction authorization enabling issuance and maintenance of encryption keys.
[0205]
[0206] 17. The system of embodiment 16, wherein once user identity is established, transaction authorization is established and encryption keys are issued, the identified user's transaction is completed in the packet-based communication system in near real time.
[0207]
[0208] 18. A method of secure communication by mobile devices in a packet-based wireless network to determine identity of users and authorization of financial transactions by a controlling service provider comprising the steps of:
[0209] providing a first SIM device having a processor that processes data received by the first SIM processor relating to identity of a user and authorization of a transaction;
[0210] providing a second SIM device having a processor, the second SIM device being remote from the first SIM device and communicating with the first SIM device;PCT / US25 / 24215 11 April 2025 (11.04.2025)
[0211] selecting data processed by the first SIM device relating to identity of users and authorization of financial transactions wherein the selected data includes data relating to quality of service, data relating to a user input and data relating to the environment of the first SIM when in use;
[0212] sharing with the second SIM the selected data processed by the first SIM device wherein a data element for quality of service, a data element for user input and a data element for the environment of use are generated;
[0213] securing encryption keys under control of a service provider in a hardware security module for account key backup and restoration;
[0214] processing the data element related to quality of service, the data element relating to environment of use and the data element relating to user direct to SIM input to determine patterns of use unique to a particular use of the first SIM device and the second SIM device in a packet-based wireless network; and
[0215] issuing encrypted keys to verify identity authorize transactions in a packet- based communication system in near real time.
[0216] 19. The method of embodiment 18, further comprising providing endpoint security at least between the first SIM device and the second SIM device wherein extracted data elements are transformed into an immutable form, including by blockchain methods, and the immutable form is protected from unauthorized removal by the service provider.
[0217]
[0218] 20. A secure communication system for mobile devices in a packet-based wireless mobile network with identity security of both user and transaction comprising:
[0219] a system controller system of the secure communication system that is an entity that can transact, wherein the system controller issues and controls encryption keys to customers for secure transactions;
[0220] a first SIM device in the packet-based wireless mobile network wherein the first SIM device captures quality of service data, user identity data and transaction data, wherein the quality of service data has QOS metrics and at least one QOS metric of significance is captured and analyzed as a data element for establishing the hybrid pattern for user identity and transaction authorization, and wherein the first SIM device has user security input controls wherein activation of one or more of the input controls is captured and analyzed to generate a data element for user identification;
[0221] a second SIM device in the packet-based network that is separated from the first SIM device and receives captured data from the first SIM device and stores captured data as immutable data;
[0222] a packet-based communication network with data packets wirelessly transmitted in standard packets on-chain, wherein captured data from the first SIM device and thePCT / US25 / 24215 11 April 2025 (11.04.2025)second SIM device are analyzed and data elements that establish a hybrid pattern for user identity and transaction authorization are performed under authority of the system controller, and, once user identity is established, transaction authorization is established and encryption keys are issued, the identified user's transaction is completed in the packet-based communication system in near real time.
Claims
CLAIMSWe claim:
1. A secure communication system for mobile devices operating in a packet-based wireless mobile network, providing identity authentication of a user, mobile device, and transactions, the system comprising:a system controller including an entity capable of conducting transactions, wherein the system controller issues and manages encryption keys associated with a SIM device to facilitate secure transactions;a SIM device within the packet-based wireless mobile network, configured to capture Metric Capture I, Metric Capture II, and Metric Capture III data elements; anda verification server, separate from the SIM device, within the packet-based wireless mobile network, configured to receive captured data from the SIM device, store the captured data, and perform analysis by cross-referencing the captured data against cloud-only data for irregularities to authenticate the user, mobile device, and transaction.
2. The system of claim 1, wherein at least one of the Metric Capture I measurements is captured and analyzed as a data element for establishing the irregularity patterns for user identity, mobile device identity, and transaction authorization.
3. The system of claim 1, wherein the mobile device includes one or more micro-electro-mechanical system sensors that capture at least one Metric Capture II data elements that are transmitted via UART, SPI, and / or I2C to the SIM.
4. The system of claim 1, wherein the mobile device includes a means to communicate Metric Capture III data elements to the SIM as a unique factor input of the user.
5. The system of claim 1, wherein a user input method of Metric Capture III triggers the SIM to transmit data packets to measure the round-trip signal-to-interference ratio to capture a unique pattern for a unique signing of each transaction.
6. The system of claim 1, wherein near real-time user identity authentication is determined by the data captured by the SIM device, wherein the SIM device becomes a parent certificate authority in issuing certificates to control domains within internet protocol systems.
7. The system of claim 1, wherein mobile device micro-electro-mechanical system sensors provide at least one Metric Capture II as unique pattern for unique signing of each transaction when requested by the SIM device8. A secure communication system for mobile devices operating in a packet-based wireless mobile network, providing identity authentication of the user, mobile device, and transactions, the system comprising:a system controller, an entity capable of conducting transactions, wherein the system controller issues and manages encryption keys associated with a SIM device to facilitate secure transactions;an immutable data recordation method using a private node blockchain, separate from the SIM device, to record data elements consisting of Metric Capture I, Metric Capture II, and Metric Capture III data elements captured by the SIM device.
9. The system of claim 8, wherein once user identity is established, transaction authorization is established, and encryption multiple keys are issued to complete and sign each blockchain transaction, and an identified user's transaction is completed in the packet-based communication system in near real-time.
10. The system of claim 8, wherein the SIM manages cryptographic keys, specifically for secure wallet creation, key storage, and multi-signature signing policy where at three user identities are known in a three key signing policy for blockchain transactions.
11. A secure communication system for mobile devices in a packet-based wireless mobile network with identity security of both user and transaction comprising:a system controller of the secure communication system that is an entity that can transact, wherein the system controller issues and controls encryption keys to customers for secure transactions;a first SIM device in the packet-based wireless mobile network wherein the first SIM device captures quality of service data, user identity data and transaction data;a second SIM device in the packet-based network that is separated from the first SIM device and receives captured data from the first SIM device and stores captured data as immutable data; anda packet-based communication network with data packets wirelessly transmitted in standard packets on-chain node consensus processing, wherein captured data from the first SIMdevice and the second SIM device are analyzed and data elements that establish a hybrid pattern for user identity and transaction authorization are performed under authority of the system controller before issuing encryption keys.
12. The system of claim 11, wherein the second SIM device is stationary.
13. The system of claim 11, wherein the quality of service has QOS metrics and at least one QOS metric of significance is captured and analyzed as a data element for establishing the hybrid pattern for user identity and transaction authorization.
14. A method of secure communication by mobile devices in a packet-based wireless network to determine identity of users and authorization of financial transactions by a controlling service provider comprising the steps of:providing a first SIM device having a processor that processes data received by the first SIM processor relating to identity of a user and authorization of a transaction;providing a second SIM device having a processor, the second SIM device being remote from the first SIM device and communicating with the first SIM device;selecting data processed by the first SIM device relating to identity of users and authorization of financial transactions wherein the selected data includes data relating to quality of service, data relating to a user input and data relating to the environment of the first SIM when in use;sharing with the second SIM the selected data processed by the first SIM device wherein a data element for quality of service, a data element for user input and a data element for the environment of use are generated;securing encryption keys under control of a service provider in a hardware security module for account key backup and restoration;processing the data element related to quality of service, the data element relating to environment of use and the data element relating to user direct to SIM input to determine patterns of use unique to a particular use of the first SIM device and the second SIM device in a packet-based wireless network; andissuing encrypted keys to verify identity authorize transactions in a packet- based communication system in near real time.
15. A secure communication system for mobile devices in a packet-based wireless mobile network with identity security of both user and transaction comprising:a system controller system of the secure communication system that is an entity that can transact, wherein the system controller issues and controls encryption keys to customers for secure transactions;a first SIM device in the packet-based wireless mobile network wherein the first SIM device captures quality of service data, user identity data and transaction data, wherein the quality of service data has QOS metrics and at least one QOS metric of significance is captured and analyzed as a data element for establishing the hybrid pattern for user identity and transaction authorization, and wherein the first SIM device has user security input controls wherein activation of one or more of the input controls is captured and analyzed to generate a data element for user identification; a second SIM device in the packet-based network that is separated from the first SIM device and receives captured data from the first SIM device and stores captured data as immutable data;a packet-based communication network with data packets wirelessly transmitted in standard packets on-chain, wherein captured data from the first SIM device and the second SIM device are analyzed and data elements that establish a hybrid pattern for user identity and transaction authorization are performed under authority of the system controller, and once user identity is established, transaction authorization is established and encryption keys are issued, the identified user’s transaction is completed in the packet-based communication system in near real time.