Hardware Encryption Device Authentication for Mobile Terminal Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption methods for mobile terminals do not effectively protect key data such as network locking information, making them vulnerable to hacking and tampering after being sold to different markets.

Innovation Solution

A mobile terminal encryption method and hardware encryption device that authenticates between a hardware encryption device and a main control chip using stored authentication data, allowing the main control chip to load encryption data only if authentication is successful, thereby preventing unauthorized access and tampering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption data is stored in the mobile terminal, then data protection is improved, but key data such as network locking information remains vulnerable to hacking and tampering

Engineering Contradiction:
Improvedata protectionVSAvoidhacking and tampering vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the protection system into two independent parts: authentication data stored in the main control chip and encryption data stored in the hardware encryption device. This segmentation ensures that even if one part is compromised, the other remains protected, thereby resolving the vulnerability to hacking and tampering while maintaining data protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hardware encryption device as an intermediary between the main control chip and the encryption data. This intermediary device independently verifies authentication data and controls access to encryption data, preventing direct access and tampering while ensuring reliable data protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication mechanism is implemented between hardware encryption device and main control chip, then security against unauthorized access is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication verification function from the main control chip and places it in the hardware encryption device. This separation allows the authentication mechanism to be implemented independently with dedicated hardware, improving security while managing system complexity through functional modularity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The hardware encryption device performs self-verification of authentication data without requiring complex external verification systems. The device independently compares authentication data with stored reference data and controls access accordingly, simplifying the overall system architecture while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2693789B1Mobile terminal encryption method, hardware encryption device and mobile terminal
Publication Date: 2019.12.25 HUAWEI DEVICE CO LTD
  • EP2693789B1 patent drawingFigure 1~2
  • EP2693789B1 patent drawingFigure 3~5

AI summary

The present invention belongs to the field of mobile communications technologies and specifically discloses a mobile terminal encryption method, a hardware encryption device, and a mobile terminal, aiming to prevent a hacker from easily acquiring or tampering key data in the mobile terminal and protect the interests of a terminal manufacturer and an operator by means of hardware encryption. The method in embodiments of the present invention includes: performing, according to stored authentication data, authentication between the hardware encryption device and a main control chip of the mobile terminal, where the hardware encryption device stores encryption data and the authentication data; if the authentication succeeds, permitting, by the hardware encryption device, the main control chip to load the encryption data; and if the authentication fails, prohibiting, by the hardware encryption device, the main control chip from loading the encryption data. The embodiments of the present invention may be applied to a mobile terminal encryption technology and a network locking technology.