Mobile Network Secure Backup Key Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in securely backing up and retrieving sensitive data from mobile devices, particularly when changing SIM cards or terminals, as existing solutions do not adequately protect against data loss and unauthorized access.
Innovation Solution
A secure backup system for mobile telecommunication networks that divides the decryption key into parts stored in separate entities, with a Key Manager and Backup Manager, using a key recreation key to recreate the decryption key on the user's mobile station, ensuring only the user can access the data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is encrypted using a single decryption key stored on the mobile station, then decryption is simple and fast, but the system is vulnerable to key loss and unauthorized access
Solution Approach 1:
The decryption key is divided into multiple key parts (first key part, second key part, third key part) stored in separate entities (mobile station, backup entity, and either SIM card or network entity). This segmentation ensures that no single entity possesses the complete decryption capability, enhancing security while maintaining manageable key distribution.
2Reliability
If the decryption key is stored in multiple separate entities, then security is improved against key loss and unauthorized access, but key retrieval and data restoration becomes more complex
Solution Approach 1:
The system pre-establishes multiple storage locations for key parts before any data loss or security incident occurs. The first key part is stored on the mobile station, the second key part on the backup entity, and the third key part on either the SIM card or network entity. This preliminary distribution enables straightforward key reconstruction when needed, as all components are already in place and properly authenticated.
Solution Approach 2:
The invention introduces an intermediary entity (either the SIM card or network entity) that holds the third key part and facilitates key reconstruction. This intermediary acts as a mediator between the mobile station and backup entity, verifying user identity and coordinating the assembly of all key parts during data restoration, thereby simplifying the overall process.
3Reliability
If a key recreation key is required to reconstruct the decryption key, then security against unauthorized key recovery is enhanced, but the user loses flexibility in key management
Solution Approach 1:
The system implements different key management approaches for different scenarios. The key recreation key mechanism provides strong security for preventing unauthorized key derivation, while the distributed key part architecture provides flexibility for legitimate key recovery. Each entity (mobile station, backup entity, SIM card/network entity) has specific responsibilities and capabilities tailored to its role, optimizing both security and flexibility for its particular function.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The secure backup system of the invention is in a mobile telecommunication network and comprises at least one mobile station with data, a backup entity for storing a backup file of said data, and cryptographic means for encryption and decryption of said data. The cryptographic means contains a decryption key consisting of at least a first key part, a second key part and a key recreation key part, whereby the key parts are stored in different entities also comprised by the system.