Removable Storage Device Authentication for Mobile Terminal Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile terminal security systems face challenges in providing strong access control to secure applications and data without burdening users with complex passwords or PINs, and they struggle with managing Trusted Platform Modules (TPMs) and Mobile Trusted Modules (MTMs, which can lead to unowned engines and compromised security due to forgotten authorization data.
Innovation Solution
A method using a removable storage device, such as a SIM, to manage access to domains by obtaining and verifying authorization data, ensuring access is granted only when the user is authenticated, and using this data to control access to multiple domains, thereby simplifying the authentication process and reducing the need for multiple passwords or PINs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple PINs or passwords are used to protect different domains, then security is improved, but user burden increases and security is diminished due to weak passwords
Solution Approach 1:
The patent combines multiple authentication credentials (PINs and passwords for different domains) into a single secure element. The secure element stores multiple authentication data sets and manages them centrally, allowing the terminal to access different domains using a single unified authentication mechanism rather than requiring separate PINs for each domain.
Solution Approach 2:
The secure element autonomously manages multiple authentication credentials without requiring user intervention. It automatically selects and provides the appropriate authentication data based on which domain needs to be accessed, eliminating the need for users to manually manage multiple PINs or passwords.
2Reliability
If strong complex passwords are enforced, then security is improved, but ease of operation deteriorates due to increased complexity
Solution Approach 1:
The patent extracts the complexity of password management from the user interface and relocates it to the secure element. Strong authentication credentials are generated and stored in the secure element, which then manages them automatically. The user interacts with a simplified interface that does not require direct handling of complex passwords.
3Reliability
If authorization data is stored in the terminal, then access control is enabled, but security is compromised if the terminal is lost or stolen
Solution Approach 1:
The patent introduces a secure element as an intermediary between the terminal and the authorization data. The secure element is a dedicated security module that stores authentication credentials and provides them to the terminal only when appropriate. Even if the terminal is lost or stolen, the secure element can be separately protected or removed, preventing unauthorized access to the authorization data.
4Reliability
If a removable storage device is used to store authorization data, then security is improved against terminal loss, but device complexity increases
Solution Approach 1:
The patent utilizes an existing removable storage device (such as a SIM card or USB stick) that the user already possesses and uses for other purposes. By storing authorization data on this existing device, the system gains enhanced security without adding entirely new hardware components. The removable storage device serves multiple functions: its original purpose plus secure storage of authentication credentials.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A terminal having one or more domains to which access is controlled by the presence of a removable attachment, particularly a smart card such as a SIM card or UICC. Authorisation data or information relating to such data may be stored on the removable storage device and used as part of a verification test. If the verification test generates a positive verification result, the removable storage device provides an indication of whether the user is authorised to access the one or more domains. Access to the one or more domains is thus controlled such that domains can only be activated when a SIM or other removable storage device is present. The present invention also relates to a removable attachment for use with such a terminal, and a method of providing functions trusted by a third party in the terminal, particularly a terminal for use with a cellular or mobile telecommunications network.