Removable Storage Device Authentication for Mobile Terminal Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile terminal security systems face challenges in providing strong access control to secure applications and data without burdening users with complex passwords or PINs, and they struggle with managing Trusted Platform Modules (TPMs) and Mobile Trusted Modules (MTMs, which can lead to unowned engines and compromised security due to forgotten authorization data.

Innovation Solution

A method using a removable storage device, such as a SIM, to manage access to domains by obtaining and verifying authorization data, ensuring access is granted only when the user is authenticated, and using this data to control access to multiple domains, thereby simplifying the authentication process and reducing the need for multiple passwords or PINs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple PINs or passwords are used to protect different domains, then security is improved, but user burden increases and security is diminished due to weak passwords

Engineering Contradiction:
ImprovesecurityVSAvoiduser burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple authentication credentials (PINs and passwords for different domains) into a single secure element. The secure element stores multiple authentication data sets and manages them centrally, allowing the terminal to access different domains using a single unified authentication mechanism rather than requiring separate PINs for each domain.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure element autonomously manages multiple authentication credentials without requiring user intervention. It automatically selects and provides the appropriate authentication data based on which domain needs to be accessed, eliminating the need for users to manually manage multiple PINs or passwords.

Inventive Principle:
Principle #25Self-service

2Reliability

If strong complex passwords are enforced, then security is improved, but ease of operation deteriorates due to increased complexity

Engineering Contradiction:
ImprovesecurityVSAvoidpassword complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the complexity of password management from the user interface and relocates it to the secure element. Strong authentication credentials are generated and stored in the secure element, which then manages them automatically. The user interacts with a simplified interface that does not require direct handling of complex passwords.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If authorization data is stored in the terminal, then access control is enabled, but security is compromised if the terminal is lost or stolen

Engineering Contradiction:
Improveaccess controlVSAvoidterminal loss risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure element as an intermediary between the terminal and the authorization data. The secure element is a dedicated security module that stores authentication credentials and provides them to the terminal only when appropriate. Even if the terminal is lost or stolen, the secure element can be separately protected or removed, preventing unauthorized access to the authorization data.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If a removable storage device is used to store authorization data, then security is improved against terminal loss, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent utilizes an existing removable storage device (such as a SIM card or USB stick) that the user already possesses and uses for other purposes. By storing authorization data on this existing device, the system gains enhanced security without adding entirely new hardware components. The removable storage device serves multiple functions: its original purpose plus secure storage of authentication credentials.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2063378B1Telecommunications device security
Publication Date: 2020.04.22 VODAFONE GRP PLC
  • EP2063378B1 patent drawingFigure 1
  • EP2063378B1 patent drawingFigure 2
  • EP2063378B1 patent drawingFigure 3

AI summary

A terminal having one or more domains to which access is controlled by the presence of a removable attachment, particularly a smart card such as a SIM card or UICC. Authorisation data or information relating to such data may be stored on the removable storage device and used as part of a verification test. If the verification test generates a positive verification result, the removable storage device provides an indication of whether the user is authorised to access the one or more domains. Access to the one or more domains is thus controlled such that domains can only be activated when a SIM or other removable storage device is present. The present invention also relates to a removable attachment for use with such a terminal, and a method of providing functions trusted by a third party in the terminal, particularly a terminal for use with a cellular or mobile telecommunications network.