Secure Base Key Provisioning for Multi-Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The use of SIM cards in devices requires additional space and complexity for integrated circuits, and they are not flexible enough to support multiple subscribers or mobile networks, leading to inefficiencies in authentication processes.

Innovation Solution

A secure base key provisioning component, comprising a hardware component and embedded software, securely stores a unique base key that can decrypt encrypted sequences containing different authentication keys for various subscribers and networks, allowing a single base key to authenticate with multiple networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIM cards are used for authentication, then device authentication capability is provided, but additional space and circuit complexity are required

Engineering Contradiction:
Improveauthentication capabilityVSAvoidcircuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functionality from the physical SIM card and integrates it directly into the device's baseband processor. The authentication algorithms and security elements are moved from the removable SIM card to the device's integrated circuit, eliminating the need for separate SIM card hardware while maintaining authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges the SIM card's authentication functions with the device's baseband processor into a single integrated unit. The security elements, authentication algorithms, and communication interfaces are combined into one unified component, reducing overall system complexity while preserving authentication reliability.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If SIM cards are used for authentication, then authentication function is provided, but additional space is required in integrated circuit

Engineering Contradiction:
Improveauthentication functionVSAvoidintegrated circuit area
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The authentication functionality is extracted from the physical SIM card and embedded directly into the device's baseband processor. This eliminates the need for separate SIM card slots and reduces the overall integrated circuit area required for authentication components.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The baseband processor is designed to perform multiple functions including authentication, signal processing, and communication protocols. By making the baseband processor universal and multi-functional, the patent eliminates the need for dedicated SIM card hardware, thereby reducing integrated circuit area while maintaining authentication capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If traditional authentication methods are used, then single network authentication is supported, but flexibility for multiple networks is limited

Engineering Contradiction:
Improvemulti-network supportVSAvoidauthentication process efficiency
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements a universal authentication mechanism in the baseband processor that can handle multiple network protocols and authentication methods. The integrated authentication system supports both legacy SIM-based authentication and new multi-network authentication protocols, enabling seamless operation across different networks without requiring separate hardware for each network type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11539535B2Generating an authentication result by using a secure base key
Publication Date: 2022.12.27 CRYPTOGRAPHY RESEARCH INC
  • US11539535B2 patent drawing
  • US11539535B2 patent drawing
  • US11539535B2 patent drawing

AI summary

An encrypted sequence that includes an authentication key may be received. A base key stored at a device may be identified and the encrypted sequence may be decrypted with the base key to obtain the authentication key. A challenge value may be received and the authentication key may be combined with the challenge value to generate a device ephemeral key. An authentication result may be generated for the device based on a combination of the device ephemeral key and the challenge value. Furthermore, the authentication result may be transmitted to a mobile network to authenticate the device.