Authentication Certificate Generation for Communication Security Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic devices lack a method to authenticate communication-related security data, leading to instances of hacking and tampering, such as nefarious acquisition of identification numbers and illegal release of network access locks, as well as network lock manipulation and data manipulation.

Innovation Solution

An electronic device and method that generate a certificate for authenticating communication-related security data, including IMEI, network lock/SIM lock information, and other sensitive data, through an authentication server, enhancing security by preventing unauthorized access and manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device identification numbers and use authority locks are used for authentication, then device identification and network access control are enabled, but the system becomes vulnerable to hacking and tampering with security data

Engineering Contradiction:
Improveauthentication securityVSAvoidhacking and tampering vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by generating authentication certificates and encrypting security data (IMEI, network lock information, SIM lock information, LDU information) before they are stored in the electronic device. This pre-encryption and certificate generation prevents unauthorized access and tampering, as the data remains protected until the authentication process is initiated.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication server as an intermediary between the electronic device and the network. The server verifies certificates and authenticates security data, preventing direct access attacks. The intermediary validates the encrypted data and certificates before allowing network access, thereby reducing vulnerability to hacking.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If LDU information is fused in OTP area to restrict communication processor function, then display terminal security is ensured, but the communication processor cannot be reused

Engineering Contradiction:
Improvedisplay terminal securityVSAvoidcommunication processor reuseability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by generating authentication certificates and encrypting LDU information before fusing it in the OTP area. This pre-authentication approach allows the communication processor to be securely reused, as the encrypted LDU information and certificates enable verification of authorized usage without permanently disabling the processor.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the state of LDU information from plaintext to encrypted form, and introduces certificate-based authentication parameters. This transformation allows the LDU information to serve dual purposes: maintaining security when fused in OTP area while enabling authenticated reuse of the communication processor through certificate verification.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3926992B1Electronic device, and authentication method in electronic device
Publication Date: 2024.05.01 SAMSUNG ELECTRONICS CO LTD
  • EP3926992B1 patent drawingFigure 1
  • EP3926992B1 patent drawingFigure 2
  • EP3926992B1 patent drawingFigure 3

AI summary

An electronic device and an authentication method in the electronic device are provided. The electronic device includes a communication circuit; and at least one processor operatively connected to the communication circuit. The at least one processor may be configured to confirm the occurrence of an authentication event for communication-related security data; in response to the occurrence of the authentication event, confirm at least one piece of communication-related security data stored in a designated area of the electronic device confirmed piece of communication-related security data, to an authentication server by means of the communication circuit; receive a certificate, generated based on at least one communication-related security data included in the transmitted certificate request message from the authentication server through the communication circuit; and authenticate use authority of the communication-related security data, based on the received certificate.