Hardware Component Security via Shared Secret Initialization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing communication between hardware components in mobile devices, such as USIM and radio cards, are inadequate as they either require pre-provisioned security keys or rely on complex asymmetric key operations, making them vulnerable to malware attacks and difficult to manage when components are distributed across different organizations.

Innovation Solution

Establishing a shared secret during the initialization of the mobile device, which is used to secure communication between components, ensuring that only authorized hardware can access and use this secret, thereby preventing malware from eavesdropping or impersonating legitimate communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-provisioned security keys are used to secure communication between hardware components, then communication security is established, but the system becomes vulnerable to malware attacks and complex to manage when components are distributed across different organizations

Engineering Contradiction:
Improvecommunication securityVSAvoidvulnerability to malware attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing a shared secret key between hardware components during the initialization phase of the mobile device, before any software or malware can be executed. This preliminary key exchange occurs at the hardware level during boot-up, ensuring that security measures are in place before potential malware attacks can occur. The shared secret is established through a specific sequence of operations involving the USIM card and radio card that must be completed during initialization, preventing subsequent malware from compromising the security channel.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If pre-provisioned security keys are used to secure communication between hardware components, then communication security is established, but the system becomes difficult to manage when components are distributed across different organizations

Engineering Contradiction:
Improvecommunication securityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the hardware components to automatically establish and manage their own security channel during device initialization. The USIM card and radio card autonomously exchange cryptographic material and establish a shared secret without requiring manual intervention or complex provisioning processes. This self-organizing mechanism eliminates the need for centralized management of security keys across distributed components, significantly reducing operational complexity while maintaining strong security.

Inventive Principle:
Principle #25Self-service

3Reliability

If asymmetric key operations are used to secure communication between hardware components, then communication security is improved, but the system becomes more complex and requires more computational resources

Engineering Contradiction:
Improvecommunication securityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transitioning from asymmetric key operations to symmetric key operations for the actual data encryption. After the initial key exchange during initialization establishes a shared secret, the system uses this symmetric key for all subsequent communication between hardware components. This parameter change from asymmetric to symmetric cryptography maintains strong security while significantly reducing computational complexity and resource requirements for ongoing communication operations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9154946B2Secure coupling of hardware components
Publication Date: 2015.10.06 KONINK KPN NV
  • US9154946B2 patent drawing
  • US9154946B2 patent drawing
  • US9154946B2 patent drawing

AI summary

A method and a system for securing communication between at least a first and a second hardware components of a mobile device is described. The method includes establishing a first shared secret between the first and the second hardware components during an initialization of the mobile device and, following the initialization of the mobile device, using the first shared secret or a derivative thereof to secure the communication between the first and the second hardware components.