DICE Virtual IMEI Generation via PUF for SIM-less Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cellular network technologies rely on physical SIM cards for device identification and access management, which can be cumbersome and insecure, especially in scenarios where device ownership changes or over-the-air programming is required.

Innovation Solution

The implementation of a Device Identifier Composition Engine (DICE) that generates a virtual IMEI using a physically unclonable function (PUF) and a trusted external certificate authority, allowing devices to securely bind the IMEI to the owner without the need for a physical SIM card, enabling secure access and management through a virtual IMEI system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical SIM cards are used for device identification and access management, then device ownership and access can be managed, but the system becomes cumbersome and insecure especially when device ownership changes or over-the-air programming is required

Engineering Contradiction:
ImprovesecurityVSAvoidoperational convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the SIM card functionality from the physical device and implements it virtually through the DICE module. The virtual IMEI is generated and stored in the DICE module instead of being tied to a physical SIM card, allowing the device to maintain secure identification and access management without the physical card. This extraction resolves the contradiction by eliminating the physical SIM card's operational inconveniences while preserving its security functions through virtual implementation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical/physical SIM card system with an electronic/virtual system. Instead of physically inserting and removing SIM cards, the system uses electronic generation and management of virtual IMEIs through the DICE module. This substitution eliminates the physical manipulation requirements while maintaining the core identification and access management functions, thereby improving ease of operation without compromising security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If physical SIM cards are used for device identification, then network access can be managed, but the system complexity increases and security is compromised in scenarios requiring over-the-air programming or ownership transfers

Engineering Contradiction:
Improveflexibility for ownership transfer and over-the-air programmingVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The DICE module serves multiple functions: it generates virtual IMEIs, stores them securely, enables over-the-air programming, and facilitates ownership transfers. This multi-functional approach consolidates what would otherwise require separate mechanisms into a single versatile component. The virtual IMEI system universally handles identification, access management, and ownership transfer scenarios, reducing overall system complexity while enhancing adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent creates a virtual copy of the SIM card's identification function through the generated virtual IMEI. Instead of relying on the physical SIM card's embedded identifier, the system generates a virtual representation that can be programmatically created, modified, and transferred. This copying approach simplifies the system by replacing complex physical card management with manageable digital data while maintaining all necessary identification and access control capabilities.

Inventive Principle:
Principle #26Copying

3Reliability

If virtual IMEI is generated using DICE and PUF, then secure SIM-less device identification is achieved, but the device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a nested structure where the DICE module contains the PUF (physically unclonable function) and the virtual IMEI generation logic. The PUF provides the foundational security layer, within which the DICE module operates to generate and manage virtual IMEIs. This nesting consolidates multiple security functions into a hierarchical structure, reducing the apparent system complexity while maintaining strong security through layered protection mechanisms.

Inventive Principle:
Principle #7Nested doll (Nesting)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides secure, SIM-less device identification and access management, facilitating efficient over-the-air programming and ownership transfers, while ensuring secure communication and billing associations with the device owner.

Implementation Method 1

The implementation of a Device Identifier Composition Engine (DICE) that generates a virtual IMEI using a physically unclonable function (PUF)

Methodology Applied
Scientific EffectPhysically unclonable function (PUF):

Data Source

PatentUS20220303769A1Enabling cellular network access via device identifier composition engine (DICE)
Publication Date: 2022.09.22 MICRON TECHNOLOGY INC
  • US20220303769A1 patent drawing
  • US20220303769A1 patent drawing
  • US20220303769A1 patent drawing

AI summary

The disclosed embodiments provide cryptographically secure International Mobile Equipment Identity (IMEI) numbers via a Device Composition Identifier Engine (DICE). In one embodiment, a method is disclosed comprising receiving, at a computing device, an IMEI number from a cellular network; generating, by the computing device, a digital certificate using the IMEI number, the digital certificate signed using a private key generated by a manufacturer of the computing device; and transmitting, by the computing device, the digital certificate to the cellular network when authenticating to the cellular network.