S-USIM Session Key Encryption for WCDMA Message Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In WCDMA 3G mobile communication networks, short text messages are vulnerable to unauthorized access due to plain text transmission, and subscriber information stored in USIMs can be easily transferred between devices, compromising security.
Innovation Solution
Implementing a secure-USIM (S-USIM) with key management and encryption/decryption functions to encrypt and decrypt short text messages, using session keys generated based on terminal and USIM information, providing end-to-end cryptographic security without altering the existing network infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If short text messages are transmitted in plain text in WCDMA 3G mobile communication, then transmission simplicity is maintained, but security against unauthorized access deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-storing encryption algorithms and session key generation mechanisms in the USIM card before message transmission. The terminal and correspondent terminal establish session keys in advance through the USIM, so that when messages are transmitted, the encryption is already prepared and can be applied automatically, maintaining transmission simplicity while ensuring security.
Solution Approach 2:
The patent introduces the USIM card as an intermediary between the terminal and the message transmission process. The USIM card acts as a security mediator that handles key generation, storage, and encryption/decryption operations, separating the security management functions from the main transmission process and enabling secure communication without complicating the user interface.
2Adaptability or versatility
If subscriber information is stored in USIM for easy device replacement, then user portability is improved, but security vulnerability to third-party access worsens
Solution Approach 1:
The patent segments the USIM functionality into two distinct parts: subscriber identification information (for portability) and security credentials (for encryption and authentication). This segmentation allows the USIM to provide both user portability across devices and robust security, as the security credentials remain protected and are used for cryptographic operations rather than being exposed for device identification purposes.
Solution Approach 2:
The patent introduces the security context and session key mechanisms as intermediaries between the subscriber information and the communication process. The USIM generates session-specific keys that act as intermediaries, allowing the system to use stored subscriber information for identification while protecting actual message content with dynamically generated encryption keys that are not stored in the USIM.
3Reliability
If end-to-end encryption is implemented for message security, then security against unauthorized access is improved, but device complexity increases
Solution Approach 1:
The patent extracts the complex encryption and decryption operations from the terminal device and places them in the USIM card. The terminal only needs to initiate encryption requests and receive encrypted/decrypted messages, while the computationally intensive cryptographic operations are performed by the USIM's secure element, reducing the complexity burden on the terminal device.
Solution Approach 2:
The patent implements self-service by enabling the USIM card to autonomously generate session keys, perform encryption, and handle decryption operations without requiring complex terminal-side cryptographic implementations. The USIM serves itself as the security processor, automatically managing the cryptographic lifecycle based on simple terminal requests, thereby reducing overall system complexity.
Data Source
AI summary
A mobile communication terminal used in wideband code division multiple access (WCDMA) 3G mobile communication includes: a communication terminal unit configured to receive a short text message from a user and transmit encrypted data generated by encrypting the short text message; and a secure-universal subscriber identity module (S-USIM) unit configured to generate a session key for encrypting the short text message, when receiving a request to encrypt the short text message from a communication terminal unit.


