Mobile Station Secure Link Between Terminal and Security Element
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SIM lock systems in mobile stations are vulnerable to tampering and manipulation, particularly due to the use of secret unlock codes and cryptographic algorithms that can be compromised, leading to unauthorized unlocking of SIM locks.
Innovation Solution
A mobile station with a secure connection between the terminal and a removable or permanently implemented security element, utilizing a secret key stored in the security element and a corresponding verification key in the terminal's secure runtime environment, establishes an end-to-end secure connection channel for verifying the binding, ensuring secure operation and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional SIM lock systems use secret unlock codes stored in the terminal, then the SIM lock can be implemented, but the system becomes vulnerable to tampering and unauthorized unlocking
Solution Approach 1:
The patent introduces a secure element (SE) as an intermediary component between the terminal and the SIM lock verification process. The SE contains a secure verification key that mediates the authentication between the terminal and the network, preventing direct storage of unlock codes in the terminal and thus eliminating the vulnerability to tampering.
Solution Approach 2:
The patent replaces the conventional mechanical/code-based SIM lock system with a cryptographic system. Instead of storing secret unlock codes in the terminal, the system uses public-key cryptography where the terminal stores only a public verification key, and the secret private key is held in the secure element, substituting the mechanical code verification with cryptographic authentication.
2Reliability
If cryptographic algorithms are used for SIM lock verification, then security is improved, but the algorithms can still be compromised by attacks
Solution Approach 1:
The patent segments the cryptographic key management into separate components: the terminal stores only the public verification key, while the private key is segmented and stored in the secure element. This segmentation ensures that even if cryptographic algorithms are attacked, the private key remains protected in the secure element, preventing compromise of the SIM lock verification.
Solution Approach 2:
The patent adds a new dimension to the security architecture by introducing a secure element as a separate hardware component. This dimensional change moves the private key storage from the terminal's software space to a dedicated hardware secure element, providing an additional layer of protection against cryptographic attacks that target the terminal's processing capabilities.
3Ease of operation
If the terminal stores verification keys in its memory, then the SIM lock verification can be performed, but the verification process can be manipulated and tampered with
Solution Approach 1:
The secure element acts as an intermediary that performs the critical verification operation. Instead of the terminal's memory storing and processing the private verification key, the secure element mediates the verification process by providing the private key only when needed and protecting it from manipulation, thus ensuring verification integrity while maintaining ease of operation.
Solution Approach 2:
The patent replaces the terminal's software-based key storage and verification mechanism with a hardware-based secure element. This substitution ensures that the verification process cannot be manipulated through software exploits, as the private key resides in a hardware component with physical protection mechanisms.
Data Source
Figure 1~3
Figure 4
AI summary
The invention relates to a mobile station comprising a terminal (ME) and a security element ((U)(SIM)) which can be operated, removed or securely implemented in the terminal (ME), a link being provided between the terminal (ME) and the security element ((U)(SIM)) and being verifiable by means of a secret key (PrK; KST) and by means of the verification key (Puk; KSA). The terminal (ME) comprises a secured runtime environment (TEE), and the verification key (PuK; KST) is stored in the secured runtime environment (TEE).