PKI-Enabled SIM Identity Management for Hardware-Light Key Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional PKI frameworks face challenges in securing sensitive data and key pairs due to hardware dependency, cost, and integration issues, compromising flexibility and security in mass applications.

Innovation Solution

A system and method for PKI-enabled Subscriber Identification Module (SIM) that verifies user documents, generates digital identities linked with demographic information, and stores them securely in SIMs via middleware, minimizing reliance on third-party servers and hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional PKI frameworks use dedicated hardware dongles (smart cards, USB tokens) to secure key pairs, then security of key pairs is improved, but hardware cost, system complexity, and integration difficulty increase

Engineering Contradiction:
Improvesecurity of key pairsVSAvoidhardware dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from dedicated hardware dongles and relocates it to the SIM card, which is already integrated in mobile devices. This removes the need for separate hardware security devices while maintaining security through the SIM's secure element and tamper-resistant design.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The SIM card is transformed from a single-function communication module to a multi-functional security device that can store key pairs, digital certificates, and perform cryptographic operations. This universal approach eliminates the need for separate hardware dongles across different applications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If conventional PKI frameworks use dedicated hardware dongles for key storage, then authentication security is improved, but implementation cost and ease of operation deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidintegration with applications
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the communication function and security function into a single SIM card device. This integration eliminates the need to manage separate hardware dongles and simplifies application integration, as developers only need to interface with the SIM card's existing APIs.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The SIM card provides self-service security by automatically managing key pairs and digital certificates within its secure environment. Applications can utilize these security services directly without requiring additional hardware management or complex integration procedures.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If conventional PKI frameworks store key pairs in local memory or third-party servers, then accessibility is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveaccessibility of key pairsVSAvoidsecurity of sensitive data
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a nested security structure where the SIM card's secure element contains the key pairs and certificates, which are then accessible to applications through controlled interfaces. This nested architecture provides both security (through the secure element) and accessibility (through standardized APIs).

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS12387012B2System and method for identity management
Publication Date: 2025.08.12 JIO PLATFORMS LTD
  • US12387012B2 patent drawing
  • US12387012B2 patent drawing
  • US12387012B2 patent drawing

AI summary

The present disclosure provides a system and a method for Public Key Infrastructure (PKI) enabled Subscriber Information Management (SIM) for digital identity management. The method includes receiving a request for issuance of a digital identity for the SIM associated with a user. Responsive to an affirmative verification of a set of documents, the method includes transmitting user information determined from the verified set of documents and a predetermined signal to a Certification Authority (CA). Further, the digital identity is generated upon receiving a Certifying Signing Request (CSR) from an end-entity and a second predetermined signal from a verification source. The generated digital identity is transmitted to the end-entity and to the SIM via a middleware.