iOS VoIP Certificate Binding via External SIM and CA Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices with iOS operating systems cannot directly access subscriber identity modules, limiting the usability, convenience, and security of end-to-end encryption (E2EE) Voice over Internet Protocol (VoIP) communications due to the lack of an application program interface (API) for interacting with the subscriber identity module.

Innovation Solution

A certificate requesting method utilizing a mobile device with both a built-in and external security chip, where a public key pair is generated, a certificate signing request is created, and a confirmation code is signed with the external private key, allowing for the issuance of a public key certificate that associates the subscriber identity with both security chips, enabling secure key exchange for E2EE VoIP communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the operating system does not provide API access to the subscriber identity module, then security is maintained through hardware isolation, but usability and convenience are reduced due to inability to perform E2EE key exchange

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a certificate authority server as an intermediary that issues digital certificates binding the built-in security chip's public key to the external SIM card's identity. This mediator enables the iOS system to access E2EE functionality without directly accessing the SIM card, maintaining security isolation while providing usability through certificate-based authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent separates the security functions into two distinct components: the built-in security chip for key generation and storage (maintaining hardware isolation), and the external SIM card for identity management. This segmentation allows each component to operate independently within its security boundaries while achieving combined E2EE functionality

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If direct API access to subscriber identity module is provided, then ease of operation improves for E2EE operations, but device complexity increases due to system integration requirements

Engineering Contradiction:
Improveease of operationVSAvoidsystem integration
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The certificate authority server acts as an intermediary that simplifies the interaction between the iOS system and the external SIM card. Instead of requiring direct API access and complex system integration, the system uses certificate-based communication where the CA server mediates key exchange and authentication, reducing device complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the built-in security chip is used for key generation, then security is enhanced through hardware isolation, but adaptability is reduced due to inability to access keys from external security modules

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal certificate binding mechanism that works across different security chip configurations. The digital certificate issued by the CA server can bind the built-in security chip's public key to external SIM card identity, enabling the system to adapt to various security module arrangements while maintaining security through hardware-based key protection

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240073038A1Certificate requesting method, certificate issuing method, certificate system and computer-readable medium thereof
Publication Date: 2024.02.29 CHT SECURITY CO LTD
  • US20240073038A1 patent drawing
  • US20240073038A1 patent drawing
  • US20240073038A1 patent drawing

AI summary

A certificate requesting method, a certificate issuing method, a certificate system and a computer-readable medium thereof are provided, in which subscriber identity identification information, a private key and a public key certificate bound to a first security chip are converted into a private key bound to a second security chip via an online identity authentication procedure, and the corresponding public key certificate is issued by a certificate authority server, so as to improve the usability, the convenience and the security thereof.