Embedded Controller Chain of Trust for iSIM Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems face challenges in securely authenticating and managing integrated subscriber identification module (iSIM) content, particularly in establishing a chain of trust to protect against system-level attacks and ensure secure wireless network access.

Innovation Solution

The implementation of a chain of trust system using an embedded controller (EC) to validate hardware, firmware, and software components during the boot process, ensuring secure access to iSIM content and managing authentication and authorization keys, with remote management capabilities via a switched multimegabit data service (SM-DS) for secure wireless network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the operating system (OS) manages iSIM content directly, then ease of operation is improved, but security against system-level attacks deteriorates

Engineering Contradiction:
ImproveiSIM content managementVSAvoidsecurity against system-level attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides iSIM management into two separate components: an embedded controller (EC) that handles secure authentication and authorization, and the operating system that handles general management operations. This segmentation allows the EC to isolate critical security functions from the OS, preventing system-level attacks from compromising iSIM content while maintaining ease of operation through OS-level interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The embedded controller acts as an intermediary between the operating system and the iSIM content. The EC validates authentication and authorization keys before allowing the OS to access or manage iSIM content, thereby providing a security buffer that protects against system-level attacks while still enabling convenient OS-based management operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication keys are stored in accessible memory, then ease of operation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveauthentication accessVSAvoidunauthorized access to authentication keys
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts authentication and authorization keys from general system memory and places them exclusively in the embedded controller's protected memory space. This extraction ensures that authentication keys remain inaccessible to the operating system and potential attackers, while the EC can still perform authentication operations efficiently when needed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The embedded controller creates a secure, isolated environment for storing and processing authentication keys. This inert environment prevents unauthorized access by the operating system and external attackers, while still allowing legitimate authentication operations to proceed through the EC's controlled interfaces.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Reliability

If the embedded controller manages all iSIM content securely, then security is improved, but device complexity increases

Engineering Contradiction:
ImproveiSIM content securityVSAvoiddual controller architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The embedded controller is designed to perform multiple functions: it manages authentication keys, validates authorization, and interfaces with both the operating system and iSIM content. By consolidating these security-critical functions into a single multi-functional component, the patent reduces the need for additional security hardware while maintaining strong security protections.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11665546B2Systems and methods of executing a chain of trust with an embedded controller to secure functionalities of an integrated subscriber identification module (iSIM)
Publication Date: 2023.05.30 DELL PROD LP
  • US11665546B2 patent drawing
  • US11665546B2 patent drawing
  • US11665546B2 patent drawing

AI summary

A method of securing functionalities of an integrated subscriber identification module (iSIM) on an information handling system may include with an embedded controller (EC), detecting a powering-up process at the information handling system and determine a chain of trust access keys during bootup; with the execution of the EC, detecting and activating a wireless wide area network (WWAN) module; with the execution of the EC, detecting and accessing an integrated subscriber identity module (iSIM); with the execution of the EC, authenticating access to iSIM content including authorization information and carrier profile information with the chain of trust access keys generated from encryption keys based on digital signatures; and sending the authorization information and carrier profile information form the iSIM to the WWAN module for authentication, wirelessly, with a switched multimegabit data service (SM-DS) server associated with the carrier profile.