Modem Authentication Command Segmentation for Multi-PIN UICC Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication protocols, such as AT commands, are inadequate for handling scenarios where a UICC contains multiple smart card applications secured by different PIN codes, particularly when the ISIM and USIM applications use separate PINs and different global key references, leading to difficulties in user verification and access to IMS networks.
Innovation Solution
The proposed solution involves modifying and extending existing command set structures to include new AT commands and parameters that allow for independent management and authentication of multiple PIN codes, enabling the modem to identify and actuate specific PIN-related tasks for each application, such as entering, checking, and changing PINs for both USIM and ISIM applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing AT commands are used for PIN authentication, then simple single-PIN authentication is supported, but multiple independent PIN codes for different applications cannot be managed
Solution Approach 1:
The authentication command is segmented into distinct components: a command portion (e.g., +CPIN) and a parameter portion that includes an application identifier. This segmentation allows the same command structure to be reused for different applications by simply changing the parameter, enabling multiple independent PIN management without creating entirely separate command sets for each application.
Solution Approach 2:
The extended AT command structure is designed to be universal across multiple smart card applications. By incorporating an application identifier parameter, a single command format can authenticate PINs for different applications (e.g., USIM, ISIM, RCSIM) stored on the same UICC, making the authentication mechanism multi-functional rather than application-specific.
2Ease of operation
If a single PIN or universal PIN is used for all applications, then authentication is simplified, but independent authentication for each application cannot be achieved
Solution Approach 1:
The authentication system implements local quality by allowing each application to have its own distinct PIN code while maintaining a unified command interface. The application identifier parameter enables the system to selectively apply different authentication credentials (different PINs) to different applications, providing localized authentication quality for each application while keeping the overall system manageable through a single command structure.
3Adaptability or versatility
If separate authentication procedures are implemented for each application, then independent authentication is achieved, but the authentication process becomes more complex
Solution Approach 1:
The authentication command structure is designed as a universal interface that handles multiple applications through a single parameter (application identifier). This multi-functional design allows the same command format to initiate authentication for any application on the UICC by simply specifying the target application in the parameter, thereby achieving independent authentication procedures without proportionally increasing command management complexity.
Data Source
AI summary
This disclosure presents a modem for use at a terminal for accessing first and second communication networks that comprises a device interface for connecting to a subscriber identity device that stores first and second subscriber identity applications, and first and second pieces of user authentication data, separate from one another, for effecting independent first and second user authentication procedures for the first and second applications, respectively. A processing unit executes the first application to provide access to the first network when the first authentication procedure has been completed, and executes the second application to provide access to the second network when the second authentication procedure has been completed. An actuation component responds to an authentication command received via a host interface to identify at least one of the first and second pieces of user authentication data to perform an authentication task in relation to the identified user authentication data.


