S-USIM Voice Encryption Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In WCDMA 3G mobile communication networks, voice communication data is vulnerable to unauthorized access due to the transmission of plain text data outside wireless channels, and managing encryption and key management functions directly on mobile terminals can lead to mismatches between subscriber and key information.
Innovation Solution
A voice communication protection method using a Secure-Universal Subscriber Identity Module (S-USIM) for end-to-end protection, where session keys are generated based on synchronous data for secure voice communication, and voice-coded data is encrypted and decrypted using these keys, ensuring secure transmission and reception.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption function and key management function are directly installed in mobile communication terminal, then voice communication security can be implemented, but mismatch may occur between subscriber and key stored in terminal making management difficult
Solution Approach 1:
The system segments the security functions by separating the key management function from the terminal device and placing it in the S-USIM card. The terminal retains only the encryption function, while the S-USIM card stores and manages the keys. This segmentation resolves the contradiction by allowing secure encryption in the terminal without the complexity of key management, as the S-USIM card handles key storage and distribution independently.
Solution Approach 2:
The S-USIM card acts as an intermediary between the subscriber identity module and the terminal's encryption function. It mediates the key management process by storing subscriber information, generating session keys, and providing them to the terminal for encryption operations. This intermediary role eliminates the need for the terminal to directly manage keys, solving the management difficulty while maintaining security.
2Ease of operation
If plain text data is transmitted outside wireless channel, then communication simplicity is maintained, but vulnerability to unauthorized access by third party occurs
Solution Approach 1:
The system performs preliminary encryption of voice-coded data using session keys generated by the S-USIM card before transmission. This preliminary security action ensures that even though data is transmitted outside the secure wireless channel, it is already protected against unauthorized access. The encryption is applied in advance to all transmitted data, maintaining simplicity while eliminating vulnerability.
Solution Approach 2:
The system changes the state of the transmitted data from plain text to encrypted text by applying encryption transformations. This parameter change (from unencrypted to encrypted) maintains the simplicity of the transmission process while fundamentally altering the security characteristics of the data, making it resistant to unauthorized access during transmission.
Data Source
AI summary
A WCDMA 3G voice communication protection method and a terminal using the method are provided. The method is performed by a terminal operating in conjunction with an S-USIM for voice communication protection. When a calling terminal connects a voice communication channel to a called terminal, secure voice communication is prepared for by collecting information about relevant voice communication. At the calling terminal, synchronous data is set by exchanging the voice communication information with the called terminal, and a secure synchronization procedure is performed based on the set synchronous data. At each of S-USIMs that operate in conjunction with the calling and called terminals, a session key for secure voice communication is generated based on the synchronous data. Secure communication is performed by encrypting and transmitting voice-coded data to be transmitted based on the session key, and decrypting and reproducing received voice-coded data based on the session key.


