Key Derivation for Secure SIM Network Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SIM card technologies are limited in their ability to switch between multiple wireless telecommunications networks without compromising security, as they require physical exchange or multiple pre-loaded keys, which is impractical and insecure, especially for embedded SIMs.

Innovation Solution

A method and module that uses a reversible key derivation algorithm with a unique master key and seed value, allowing secure derivation of network authentication keys on-demand without storing or transmitting the keys, ensuring integrity and security through authenticated encryption and integrity protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If physical exchange of SIM cards is used to switch networks, then network switching capability is improved, but device complexity and logistical difficulty increase

Engineering Contradiction:
Improvenetwork switching capabilityVSAvoidlogistical complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the network authentication capability from the physical SIM card form factor. Instead of requiring physical SIM card exchange, the invention derives authentication keys (Ki) programmatically from a master key stored in the terminal equipment. This separates the authentication function from the physical card, enabling network switching without physical intervention.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a key derivation mechanism as an intermediary between the master key and network authentication keys. Rather than storing multiple Ki values or physically exchanging SIM cards, the system uses a deterministic key derivation function that generates appropriate Ki values based on the selected network's identification, serving as a virtual mediator for network switching.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple Ki values are pre-loaded on SIM card to enable multi-network support, then network adaptability is improved, but security is worsened due to key transmission and storage risks

Engineering Contradiction:
Improvemulti-network supportVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent performs preliminary key derivation by storing only a master key in the terminal equipment before network switching is needed. When network switching is required, the system derives the appropriate Ki value at that moment using the master key and the target network's identification. This eliminates the need to pre-load multiple Ki values, thereby preventing security risks associated with key transmission and storage while maintaining multi-network capability.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If SIM card is embedded into device to improve integration, then ease of operation is improved, but ability to replace SIM for network switching is worsened

Engineering Contradiction:
ImproveintegrationVSAvoidSIM replaceability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent extracts the network authentication function from the physical SIM card and embeds it directly into the terminal equipment's memory and processing units. The master key and key derivation function are integrated into the device, eliminating the need for a removable SIM card while maintaining authentication capability. This allows embedded SIM integration without sacrificing network switching ability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a virtual copy of the SIM card's authentication functionality within the terminal equipment. Instead of relying on a physical SIM card that can be removed and replaced, the system implements the authentication logic and key management software-based, effectively copying the SIM's function into the device itself. This enables network switching through software operations rather than physical card replacement.

Inventive Principle:
Principle #26Copying

4Reliability

If conventional SIM stores only single MNO authentication keys, then security is improved by limiting key exposure, but adaptability to switch networks is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork switching capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the parameter of key storage from storing multiple fixed Ki values to storing a single master key with key derivation capability. The system derives different Ki values dynamically based on the target network's identification parameters. This parameter change maintains security by limiting exposure to one master key while enabling adaptability to switch between multiple networks through cryptographic derivation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2652898B1Key derivation
Publication Date: 2018.05.30 VODAFONE IP LICENSING LTD
  • EP2652898B1 patent drawingFigure 1
  • EP2652898B1 patent drawingFigure 2
  • EP2652898B1 patent drawing

AI summary

To facilitate a change in network authentication key (Ki) for use by a smart card (SIM) during authentication on a cellular telecommunications network,there is provided a smart card management scheme that combines key derivation with over the air (OTA) provisioning. This scheme ensures both that the Ki is never transmitted OTA and that the Ki is stored in two locations only : on the SIM and at an authentication centre (AuC).