Authentication Algorithm Update via Pre-stored Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Updating an authentication algorithm in a computer system, such as a GSM network, poses security risks due to the need to transmit non-proprietary algorithms across the network, especially when modifying pairs like IMSI/Ki and MSISDN/Ki stored in SIM cards and authentication centers.

Innovation Solution

A method involving the storage of a second inactive authentication algorithm in a memory element, allowing a seamless switch from the first algorithm to the second without transmitting the algorithm, by managing multiple accounts on the card and server, and synchronizing changes across the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the authentication algorithm is transmitted across the network for updating, then the algorithm can be updated in the card and authentication center, but security is compromised due to transmission of non-proprietary algorithms

Engineering Contradiction:
ImprovesecurityVSAvoidalgorithm update capability
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies preliminary action by pre-storing multiple authentication algorithms (including future versions) in the authentication algorithm storage unit of the SIM card before they are needed. When an algorithm update is required, the system simply switches to a pre-stored algorithm rather than transmitting a new one across the network, thus maintaining security while enabling updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the authentication algorithm update process into two independent parts: (1) storing multiple algorithms in the SIM card's authentication algorithm storage unit, and (2) switching between algorithms via a switching command. This segmentation allows the card to self-update without receiving algorithm transmissions, resolving the security contradiction.

Inventive Principle:
Principle #1Segmentation

2Productivity

If the authentication algorithm is updated by transmission, then the update can be performed, but time and network resources are consumed

Engineering Contradiction:
Improveupdate efficiencyVSAvoidupdate time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-loading multiple authentication algorithms into the SIM card during manufacturing or initial provisioning. This eliminates the need for time-consuming algorithm transmissions during operational updates, significantly reducing update time while maintaining high productivity through rapid algorithm switching.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by storing copies of multiple authentication algorithms (including current and future versions) directly in the SIM card's storage unit. This local copying enables instant algorithm switching without network transmission, improving update efficiency while minimizing time loss.

Inventive Principle:
Principle #26Copying

3Reliability

If multiple authentication algorithms are stored in the card, then algorithm switching becomes possible without transmission, but memory space is required

Engineering Contradiction:
Improvealgorithm update securityVSAvoidmemory space
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the authentication algorithm storage by dedicating a specific authentication algorithm storage unit within the SIM card's memory structure. This organized segmentation allows efficient storage of multiple algorithms while utilizing the card's existing memory capacity, achieving secure updates without excessive memory consumption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The SIM card's memory structure is designed with multi-functionality, where the authentication algorithm storage unit can accommodate multiple different authentication algorithms (current and future versions). This universal storage capability enables secure algorithm updates without requiring additional dedicated memory space for each algorithm version.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8031871B2Method of updating an authentication algorithm in a computer system
Publication Date: 2011.10.04 THALES DIS FRANCE SA
  • US8031871B2 patent drawing
  • US8031871B2 patent drawing
  • US8031871B2 patent drawing

AI summary

The invention relates to a method of updating an authentication algorithm in at least one data processing device (CARD, SERV) which can store a subscriber identity (IMSI1) which is associated with an authentication algorithm (Algo1) in a memory element of said device (CARD, SERV). The inventive method comprises the following steps, namely: a step whereby a second inactive (Algo2) authentication algorithm is pre-stored in a memory element of the device and a step for switching from the first algorithm (Algo1) to the second algorithm (Algo2) which can inhibit the first algorithm (Algo1) and activate the second (Algo2).