Secure Application Execution on Untrusted Devices via SIM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for establishing a secure environment on untrusted mobile devices are costly due to the need for additional space for trusted platform modules and SIM cards, which are limited in functionality and vulnerable to key generation weaknesses.

Innovation Solution

A method for executing a secure application on untrusted user equipment with a protected region involves establishing a secure and authenticated communication channel between a trusted device and the user equipment, providing secure application information, checking its correctness, and initiating execution within the protected region, using conventional SIM cards and leveraging remote trust anchors to avoid the need for embedded trusted platform modules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If trusted platform module chips are embedded within mobile devices to establish a root of trust, then security guarantees are improved, but device cost and complexity increase due to additional space requirements

Engineering Contradiction:
Improvesecurity guaranteesVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses a SIM card as a copy or alternative implementation of trusted platform module functionality. Instead of embedding expensive TPM chips in each device, the invention leverages the existing SIM card infrastructure to provide equivalent security functions including key storage, authentication, and secure application execution, thereby reducing device complexity and cost while maintaining security guarantees

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The invention makes the SIM card multi-functional by enabling it not only for traditional mobile network authentication but also for hosting secure applications, storing cryptographic keys, and providing trusted execution environment. This universal approach eliminates the need for separate TPM hardware while achieving the same security objectives

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If SIM cards are used to embed secret keys for authentication, then device cost is reduced, but security reliability deteriorates due to cloning vulnerability and weak key generation algorithms

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent transforms the static SIM card into a dynamic secure execution environment by enabling it to load and execute secure applications from a trusted device. The SIM card transitions from a passive storage medium to an active computing platform that can dynamically update its software footprint, thereby improving security reliability while maintaining low device complexity

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention performs preliminary actions by pre-configuring the SIM card with a secure application from a trusted device before the secure operation needs to execute. The secure application is prepared and transferred in advance through a secure communication channel, ensuring the SIM card is ready to provide secure services without requiring real-time configuration during critical operations

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If static computing environments are used for trusted computing, then security attestation is simplified, but adaptability to mobile computing environments deteriorates

Engineering Contradiction:
Improvedevice complexityVSAvoidadaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamics to the trusted computing model by enabling secure applications to be updated and reconfigured in the SIM card through secure communication with a trusted device. This dynamic capability allows the system to adapt to mobile computing environments where requirements change, while maintaining the simplicity of static attestation mechanisms

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention introduces a trusted device as an intermediary that bridges static security policies with dynamic mobile operations. The trusted device prepares and transfers secure applications to the SIM card, mediating between the static security requirements and the dynamic needs of mobile computing, thereby achieving both simplified attestation and environmental adaptability

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9609000B2Method and system for executing a secure application on an untrusted user equipment
Publication Date: 2017.03.28 NEC CORP
  • US9609000B2 patent drawing
  • US9609000B2 patent drawing
  • US9609000B2 patent drawing

AI summary

A method for executing a secure application on an untrusted user equipment having storage means with at least one protected region includes establishing a secure or authenticated communication channel between a trusted device and the user equipment. Secure application information of the secure application is provided via the communication channel to be executed on the user equipment. Correctness of the secure application information is checked. Execution of the secure application is initiated on the user equipment via the communication channel such that the secure application is stored in the protected region of the storage means.