Feature Lock Mechanism for Secure Mobile Terminal Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile communication systems lack technical means for implementing limited access to user customizable settings on mobile terminals, particularly due to the absence of secure and trusted methods to prevent unauthorized updates, and SIM lock restrictions, which hinder third-party services from providing automated updates for customizable features.
Innovation Solution
A method and technical equipment that utilize a feature lock mechanism with secured check-up data and administrative check-up data, including public and secret keys or certificates, to authenticate and authorize configuration and managing messages, allowing secure storage and modification of customizable feature settings, such as ringing tones, background images, and browser settings, by a third party.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIM lock is implemented to ensure operator revenue, then operator revenue is protected, but access to customizable features by third parties is restricted
Solution Approach 1:
The patent segments the authorization system into multiple independent authorization codes stored in the terminal's memory. Each code can be associated with different operators or third-party service providers. This segmentation allows the terminal to maintain SIM lock for operator revenue protection while simultaneously enabling segmented access for multiple third-party services through different authorization codes, thus resolving the contradiction between operator revenue protection and third-party service access.
Solution Approach 2:
The patent introduces an intermediary authorization code system that mediates between the SIM lock restriction and third-party service access. The authorization codes act as intermediaries that verify the identity and rights of different entities (operators and third-party providers) before allowing access to customizable features. This intermediary mechanism enables the terminal to enforce SIM lock while also facilitating controlled third-party access through the authorization code verification process.
2Ease of operation
If automated update service is implemented for customizable features, then user convenience is improved, but security risks from unauthorized updates increase
Solution Approach 1:
The patent applies preliminary action by pre-storing multiple authorization codes in the terminal's memory before any automated updates occur. These authorization codes are prepared in advance and associated with different operators or service providers. When automated updates are implemented, the terminal first verifies the sender's authorization code against the pre-stored codes before allowing any configuration changes. This preliminary preparation of authorization mechanisms enables automated updates while preventing unauthorized modifications through prior verification.
Solution Approach 2:
The patent implements feedback through the authorization code verification process. When a configuration update message is received, the terminal sends a verification feedback by checking the message's authorization code against the stored codes. Only if the verification succeeds does the terminal proceed to apply the update. This feedback mechanism ensures that automated updates are convenient for users while maintaining security by verifying the authenticity and authorization of each update before application.
3Adaptability or versatility
If third-party services are allowed to modify terminal settings, then service versatility is enhanced, but system security and control are weakened
Solution Approach 1:
The patent applies local quality by assigning different authorization codes to different entities (operators and third-party service providers) with specific access rights. Each authorization code has localized quality in terms of its scope and permissions - operator codes maintain full control over SIM lock and network-related settings, while third-party codes are limited to specific customizable features. This localized authorization approach enhances service versatility by allowing third-party modifications while maintaining system security through code-specific permission control.
Solution Approach 2:
The patent segments the system security control into multiple independent authorization verification stages. Instead of a single monolithic security control, the system uses segmented authorization codes that can be independently verified. Each code represents a specific authorized entity and comes with its own set of permissions. This segmentation allows third-party services to modify terminal settings within their authorized scope while the overall system security is maintained through the distributed verification process that checks each code's validity and permissions individually.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A method and apparatus for providing a mobile terminal (100) with at least one feature setting. The method comprises steps of storing at least a first check-up data (200) in the mobile terminal; linking at least the first check-up data via a feature lock (202) with at least one feature setting (204), the feature lock protecting the at least one feature setting of the mobile terminal; in response to receiving a configuration message (208) in the mobile terminal, authenticating a sender of the configuration message with the first check-up data; and in response to the sender of the configuration message being authorised to modify the feature setting of the mobile terminal, supplying a configuration data included in the configuration message via the feature lock to be used by the mobile terminal.