Hybrid SIM Architecture Segmentation for Carrier Flexibility and Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device authentication systems face challenges in balancing security and flexibility, particularly with software-based SIM implementations that lack robustness and hardware-based solutions that constrain device space and carrier compatibility.

Innovation Solution

A hybrid SIM implementation that leverages a small amount of trusted hardware in conjunction with secure software to perform SIM-related operations, providing a secure, flexible, and portable solution by separating sensitive and less sensitive tasks between hardware and software components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software-based SIM implementations are used, then device space constraints are alleviated and carrier flexibility is improved, but security of sensitive functions and information is compromised

Engineering Contradiction:
Improvecarrier flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments SIM functionality into two parts: a software-based SIM application provider that handles non-sensitive operations (provisioning, updates, carrier flexibility) and a trusted execution environment that handles sensitive operations (authentication, encryption). This segmentation allows the system to achieve both carrier flexibility through software and security through hardware-based trusted execution.

Inventive Principle:
Principle #1Segmentation

2Reliability

If hardware-based SIM implementations are used, then security is improved, but device space is consumed and carrier portability is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidcarrier portability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the SIM system into a portable software component that can be updated and switched between carriers, and a static trusted execution environment that provides security. The software SIM application can be provisioned with different carrier information, enabling carrier portability while the TEE maintains security credentials.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces the physical hardware SIM card with a software-based implementation that runs within a trusted execution environment. This substitution eliminates the need for physical SIM card slots and removable cards, while maintaining security through the TEE's protected memory and processing capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If a hybrid SIM implementation is implemented, then both security and flexibility are achieved, but device complexity increases

Engineering Contradiction:
ImproveflexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the software-based SIM application with the hardware-based trusted execution environment into a unified hybrid SIM system. The software SIM runs within the protected boundaries of the TEE, combining the flexibility of software with the security of hardware in a single integrated architecture.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10389868B2Device authentication systems and methods
Publication Date: 2019.08.20 INTERTRUST TECH CORP
  • US10389868B2 patent drawing
  • US10389868B2 patent drawing
  • US10389868B2 patent drawing

AI summary

This disclosure relates to, among other things, systems and methods for authenticating a device with a network carrier using secure hardware and software systems. Embodiments disclosed herein may provide for a hybrid SIM implementation that uses both trusted software and hardware. A hybrid SIM implementation consistent with aspects of the disclosed embodiments may leverage a relatively small amount of trusted hardware in conjunction with secure software to perform SIM-related operations. In various embodiments, such a hybrid solution may provide a SIM implementation that is more secure than solutions implemented by software alone, while still relating retaining some of the benefits of software solutions including improved update flexibility and/or carrier portability.