Electronic Device Network Lock Security with Local Signature Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network lock security schemes in electronic devices face challenges in maintaining security without a device root key certificate, especially in joint development manufacturing scenarios, and require server-based operations that incur high maintenance costs.
Innovation Solution
An electronic device is configured with an application processor, communication processor, and a security sub-system that allows the communication processor to generate and verify signatures independently, using a nonce value and network lock data without relying on a server, enhancing offline-based 3GPP network lock security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a server-based operation scheme is used for network lock security, then security can be maintained using device root key certificate, but server maintenance costs increase
Solution Approach 1:
The communication processor is designed to independently generate and verify network lock signatures without requiring external server assistance. The device uses its own stored signature to verify incoming network lock requests, making the system self-sufficient and eliminating server maintenance requirements while maintaining security
Solution Approach 2:
The signature verification functionality is extracted from the server and embedded directly into the communication processor. This allows the device to perform security verification locally without depending on external server infrastructure, thereby reducing maintenance costs while preserving security
2Ease of manufacture
If joint development manufacturing is used without device root key certificate injection, then manufacturing flexibility is improved, but network lock signature security cannot be maintained
Solution Approach 1:
Instead of requiring a unique device root key certificate for each device, the system uses a shared signature stored in the communication processor that can be copied across multiple devices. This allows joint development manufacturing where the same security credentials can be used across different device batches without requiring individual certificate injection
Solution Approach 2:
The communication processor independently verifies network lock requests using its own embedded signature, without needing external verification infrastructure. This self-verification capability enables manufacturing flexibility while maintaining security consistency across all devices
Data Source
AI summary
An electronic device may include: an application processor, a communication processor, and a security subsystem for processing a security function related to the application processor or the communication processor. The security subsystem may decrypt, based on reception of a request for decrypting a nonce value from the communication processor, the nonce value and transmit the decrypted nonce value to the communication processor, and may generate a signature using the nonce value and network lock data based on reception of a request for network lock signature from the communication processor and transmit the generated signature to the communication processor. The communication processor may receive a signature value generated from the security subsystem, compare a signature value pre-stored in the application processor with a signature value received from the security subsystem, and determine whether to restrict use of the electronic device based on whether the signature value pre-stored in the application processor and the signature value received from the security subsystem are matched to each other.


