Retrospective SIM Implementation in Security Module
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for implementing SIM functionality in mobile phones are inflexible and require initial implementation during manufacturing or personalization, limiting user convenience and security, especially since they often rely on traditional chip cards and do not allow for later modifications or secure key management.
Innovation Solution
The SIM functionality is implemented as an application in a security module, where personalizing data is transmitted and decrypted using a user's secret key stored in the module, enabling flexible and secure access to mobile networks without the need for traditional SIM cards, with the option to generate keys within the module for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If SIM functionality is implemented during manufacturing or initial personalization in traditional chip cards, then the mobile phone can use the mobile radio network, but the system lacks flexibility and user independence
Solution Approach 1:
The patent implements SIM functionality dynamically by allowing the application to be loaded into the security module at any time after manufacturing, rather than being fixed during initial personalization. This enables the system to adapt to different users and providers flexibly while maintaining security through the module's protected environment.
Solution Approach 2:
The patent separates the SIM functionality into distinct components: the security module that stores secret keys and provides secure operations, and the application that can be loaded independently. This segmentation allows flexible implementation while maintaining security boundaries.
2Reliability
If personalizing data is transmitted in encrypted form and decrypted using a secret key stored in the security module, then security standards are maintained, but the complexity of key management increases
Solution Approach 1:
The security module autonomously manages its own secret keys and performs decryption operations internally. The module receives encrypted personalizing data and handles the decryption process using its stored secret key without external intervention, thereby maintaining high security while simplifying the overall system architecture.
Solution Approach 2:
The security module acts as an intermediary between the external environment and the sensitive personalizing data. It receives encrypted data, performs secure decryption using its internal secret key, and processes the data in its protected environment, isolating the complexity of key management within the module's secure boundary.
3Adaptability or versatility
If the SIM functionality is implemented as an application loaded into the security module, then flexibility is improved, but the risk of key exposure during transmission and loading increases
Solution Approach 1:
The patent applies preliminary protective measures by transmitting personalizing data in encrypted form and ensuring that decryption occurs only within the secure environment of the security module. The secret key never leaves the module, and the application is loaded in a controlled manner that prevents unauthorized access or exposure of sensitive data during the loading process.
Data Source
AI summary
The invention relates to a method for subsequently implementing a SIM functionality, with the help of which a mobile telephone (1) is enabled to use a mobile radio network, in a security module (3). Within the context of the method according to the invention the SIM functionality is realized in the form of an application, of which at least a first part is loaded into the security module (3). Furthermore, personalizing data, which are required for a use of the mobile radio network by the mobile telephone (1), are transmitted from a provider (2) to the security module (3) in encrypted form on the direct or indirect way. The encrypted personalizing data are decrypted by the security module (3) by means of a secret key of a user stored in the security module (3). The security module (3) is personalized by means of the decrypted personalizing data.

