Policy-Based Access Control for Virtualized SIM Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtualized SIM operations in wireless communication systems face challenges such as security vulnerabilities, illicit use, and resource degradation due to the susceptibility of software-based access-control clients, which lack the security and uniqueness properties of traditional physical SIM cards.

Innovation Solution

An electronic device with a secure element that includes a processor, memory, and a credential-management module to specify and manage privileges for logical entities, ensuring secure communication by enforcing unique and conserved access-control elements through encryption and protocol-based transfers, and a policy-based framework for differentiating privileges and security protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtualized SIM operation is implemented to reduce device size and increase flexibility, then device functionality and adaptability are improved, but security and reliability deteriorate due to software susceptibility to corruption and sabotage

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the access-control functionality into a separate access-control element that can be independently managed and verified. This element contains cryptographic credentials and is distinct from the virtualized SIM software, allowing security verification without compromising device flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access-control element acts as an intermediary between the virtualized SIM software and the network. It provides a trusted layer that verifies the authenticity of access-control requests, mediating between the flexible software environment and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If virtualized SIM software is used to provide flexibility and reduce device size, then ease of manufacture and adaptability are improved, but the susceptibility to illicit use and resource degradation increases

Engineering Contradiction:
Improvedevice sizeVSAvoidillicit use
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by pre-configuring the access-control element with cryptographic credentials before the virtualized SIM becomes operational. This preliminary setup ensures that security measures are in place before any access-control operations occur, preventing illicit use from the outset.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the access-control element continuously verifies the authenticity of access requests and provides feedback to the network about the legitimacy of virtualized SIM operations. This real-time verification prevents resource degradation from illicit use.

Inventive Principle:
Principle #23Feedback

3Reliability

If traditional physical SIM cards are used to ensure security and uniqueness, then reliability and security are improved, but device size and functionality are reduced

Engineering Contradiction:
ImprovesecurityVSAvoiddevice size
Core Design Contradiction:
ReliabilityVSVolume of moving object

Solution Approach 1:

The system creates a cryptographic copy or representation of the traditional SIM functionality in the access-control element. This digital representation maintains the security properties of physical SIMs while enabling virtualized operation that reduces device size and increases flexibility.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The invention replaces the mechanical physical SIM card system with a software-based virtualized SIM system secured by cryptographic mechanisms. The access-control element uses digital credentials and cryptographic verification to substitute for the physical card's security functions, eliminating the need for removable hardware.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Adaptability or versatility

If software-based access-control clients are deployed to increase flexibility, then adaptability is improved, but manufacturing precision and control over software integrity are worsened

Engineering Contradiction:
ImproveflexibilityVSAvoidsoftware integrity
Core Design Contradiction:
Adaptability or versatilityVSManufacturing precision

Solution Approach 1:

The access-control element is pre-configured with cryptographic credentials and security policies during a controlled manufacturing or provisioning process. This preliminary configuration ensures software integrity is established before deployment, maintaining manufacturing precision while enabling post-deployment flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes key parameters of the virtualized SIM, such as cryptographic keys, security policies, and access-control credentials, to ensure each instance has unique and verified software integrity. These parameter changes are controlled through the access-control element, maintaining precision while allowing flexibility.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2923478B1Policy-based techniques for managing access control
Publication Date: 2019.08.14 APPLE INC
  • EP2923478B1 patent drawingFigure 1
  • EP2923478B1 patent drawingFigure 2
  • EP2923478B1 patent drawingFigure 3

AI summary

A policy-based framework is described. This policy-based framework may be used to specify the privileges for logical entities to perform operations associated with an access-control element (such as an electronic Subscriber Identity Module) located within a secure element in an electronic device. Note that different logical entities may have different privileges for different operations associated with the same or different access-control elements. Moreover, the policy-based framework may specify types of credentials that are used by the logical entities during authentication, so that different types of credentials may be used for different operations and/or by different logical entities. Furthermore, the policy-based framework may specify the security protocols and security levels that are used by the logical entities during authentication, so that different security protocols and security levels may be used for different operations and/or by different logical entities.