Mobile Station Secure Link Between Terminal and Security Element

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SIM lock systems in mobile stations are vulnerable to tampering and manipulation, particularly due to the use of secret unlock codes and cryptographic algorithms that can be compromised, leading to unauthorized unlocking of SIM locks.

Innovation Solution

A mobile station with a secure connection between the terminal and a removable or permanently implemented security element, utilizing a secret key stored in the security element and a corresponding verification key in the terminal's secure runtime environment, establishes an end-to-end secure connection channel for verifying the binding, ensuring secure operation and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional SIM lock systems use secret unlock codes stored in the terminal, then the SIM lock can be implemented, but the system becomes vulnerable to tampering and unauthorized unlocking

Engineering Contradiction:
Improvesecurity of SIM lockVSAvoidvulnerability to tampering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure element (SE) as an intermediary component between the terminal and the SIM lock verification process. The SE contains a secure verification key that mediates the authentication between the terminal and the network, preventing direct storage of unlock codes in the terminal and thus eliminating the vulnerability to tampering.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the conventional mechanical/code-based SIM lock system with a cryptographic system. Instead of storing secret unlock codes in the terminal, the system uses public-key cryptography where the terminal stores only a public verification key, and the secret private key is held in the secure element, substituting the mechanical code verification with cryptographic authentication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If cryptographic algorithms are used for SIM lock verification, then security is improved, but the algorithms can still be compromised by attacks

Engineering Contradiction:
Improvesecurity verificationVSAvoidcryptographic attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the cryptographic key management into separate components: the terminal stores only the public verification key, while the private key is segmented and stored in the secure element. This segmentation ensures that even if cryptographic algorithms are attacked, the private key remains protected in the secure element, preventing compromise of the SIM lock verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to the security architecture by introducing a secure element as a separate hardware component. This dimensional change moves the private key storage from the terminal's software space to a dedicated hardware secure element, providing an additional layer of protection against cryptographic attacks that target the terminal's processing capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If the terminal stores verification keys in its memory, then the SIM lock verification can be performed, but the verification process can be manipulated and tampered with

Engineering Contradiction:
Improveverification processVSAvoidverification integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The secure element acts as an intermediary that performs the critical verification operation. Instead of the terminal's memory storing and processing the private verification key, the secure element mediates the verification process by providing the private key only when needed and protecting it from manipulation, thus ensuring verification integrity while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the terminal's software-based key storage and verification mechanism with a hardware-based secure element. This substitution ensures that the verification process cannot be manipulated through software exploits, as the private key resides in a hardware component with physical protection mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP2862340B1Mobile station with link between a terminal and a security element
Publication Date: 2018.09.19 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP2862340B1 patent drawingFigure 1~3
  • EP2862340B1 patent drawingFigure 4

AI summary

The invention relates to a mobile station comprising a terminal (ME) and a security element ((U)(SIM)) which can be operated, removed or securely implemented in the terminal (ME), a link being provided between the terminal (ME) and the security element ((U)(SIM)) and being verifiable by means of a secret key (PrK; KST) and by means of the verification key (Puk; KSA). The terminal (ME) comprises a secured runtime environment (TEE), and the verification key (PuK; KST) is stored in the secured runtime environment (TEE).