Key Derivation for Secure SIM Network Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SIM card technologies are limited in their ability to switch between multiple wireless telecommunications networks without compromising security, as they require physical exchange or multiple pre-loaded keys, which is impractical and insecure, especially for embedded SIMs.
Innovation Solution
A method and module that uses a reversible key derivation algorithm with a unique master key and seed value, allowing secure derivation of network authentication keys on-demand without storing or transmitting the keys, ensuring integrity and security through authenticated encryption and integrity protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If physical exchange of SIM cards is used to switch networks, then network switching capability is improved, but device complexity and logistical difficulty increase
Solution Approach 1:
The patent extracts the network authentication capability from the physical SIM card form factor. Instead of requiring physical SIM card exchange, the invention derives authentication keys (Ki) programmatically from a master key stored in the terminal equipment. This separates the authentication function from the physical card, enabling network switching without physical intervention.
Solution Approach 2:
The patent introduces a key derivation mechanism as an intermediary between the master key and network authentication keys. Rather than storing multiple Ki values or physically exchanging SIM cards, the system uses a deterministic key derivation function that generates appropriate Ki values based on the selected network's identification, serving as a virtual mediator for network switching.
2Adaptability or versatility
If multiple Ki values are pre-loaded on SIM card to enable multi-network support, then network adaptability is improved, but security is worsened due to key transmission and storage risks
Solution Approach 1:
The patent performs preliminary key derivation by storing only a master key in the terminal equipment before network switching is needed. When network switching is required, the system derives the appropriate Ki value at that moment using the master key and the target network's identification. This eliminates the need to pre-load multiple Ki values, thereby preventing security risks associated with key transmission and storage while maintaining multi-network capability.
3Ease of operation
If SIM card is embedded into device to improve integration, then ease of operation is improved, but ability to replace SIM for network switching is worsened
Solution Approach 1:
The patent extracts the network authentication function from the physical SIM card and embeds it directly into the terminal equipment's memory and processing units. The master key and key derivation function are integrated into the device, eliminating the need for a removable SIM card while maintaining authentication capability. This allows embedded SIM integration without sacrificing network switching ability.
Solution Approach 2:
The patent creates a virtual copy of the SIM card's authentication functionality within the terminal equipment. Instead of relying on a physical SIM card that can be removed and replaced, the system implements the authentication logic and key management software-based, effectively copying the SIM's function into the device itself. This enables network switching through software operations rather than physical card replacement.
4Reliability
If conventional SIM stores only single MNO authentication keys, then security is improved by limiting key exposure, but adaptability to switch networks is worsened
Solution Approach 1:
The patent changes the parameter of key storage from storing multiple fixed Ki values to storing a single master key with key derivation capability. The system derives different Ki values dynamically based on the target network's identification parameters. This parameter change maintains security by limiting exposure to one master key while enabling adaptability to switch between multiple networks through cryptographic derivation.
Data Source
Figure 1
Figure 2
AI summary
To facilitate a change in network authentication key (Ki) for use by a smart card (SIM) during authentication on a cellular telecommunications network,there is provided a smart card management scheme that combines key derivation with over the air (OTA) provisioning. This scheme ensures both that the Ki is never transmitted OTA and that the Ki is stored in two locations only : on the SIM and at an authentication centre (AuC).