Secure Element Authentication for Shared SIM Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The sharing of a telephone number among multiple devices can lead to security and privacy issues, as unauthorized users can access the service by removing and reinserting a SIM card, resulting in unauthorized access and resource wastage.

Innovation Solution

A method using a secure element to authenticate users by generating and comparing sets of keys based on a provided token, ensuring only authorized users access the shared service by matching the configuration token, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple devices share the same telephone number and SIM card, then the user can receive calls concurrently on multiple devices, but unauthorized users can access the service by removing and reinserting the SIM card

Engineering Contradiction:
Improvemulti-device service accessVSAvoidservice security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authentication process by introducing device-specific credentials (unique codes or certificates) that are distributed to each authorized device. This allows the SIM card to be physically moved between devices while maintaining security, as each device must present its unique credential to authenticate. The segmentation separates the physical SIM card from the logical authentication mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication server that mediates between the SIM card and the network. Instead of direct SIM-to-network authentication, the server verifies device-specific credentials and manages the authorization process. This intermediary layer prevents unauthorized access even when the SIM card is physically present, as the server validates each device's unique credential before granting service access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the SIM card can be freely removed and reinserted, then device compatibility and flexibility are improved, but unauthorized access and resource wastage occur

Engineering Contradiction:
Improvedevice flexibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent implements preliminary action by pre-configuring each authorized device with unique credentials (device-specific codes or certificates) before the SIM card is moved. This pre-authentication setup ensures that when the SIM card is inserted into a new device, the authentication server can verify the device's legitimacy beforehand. The preliminary registration process binds specific devices to the SIM card's service rights, preventing unauthorized use while maintaining flexibility for authorized devices.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If traditional SIM card sharing is allowed, then multi-device access is enabled, but privacy breaches and security vulnerabilities arise

Engineering Contradiction:
Improveservice accessibilityVSAvoidprivacy breach
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by making each device's authentication credential unique and device-specific. Instead of a single shared authentication method for all devices, each device receives a tailored credential (unique code or certificate) that is locally stored and verified. This local differentiation ensures that even if one device is compromised, other devices remain secure, as their unique credentials are not accessible to unauthorized users.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12047506B2Systems and methods for user-based authentication
Publication Date: 2024.07.23 VERIZON PATENT & LICENSING INC
  • US12047506B2 patent drawing
  • US12047506B2 patent drawing
  • US12047506B2 patent drawing

AI summary

A device that includes a secure element or a secure environment receives a token for authenticating a user that has an account with a service provider. The device generates, based on the token, a set of keys that include at least a private key and a public key. The device performs a key authentication procedure to compare the set of keys and a configured set of keys and selects a public key, of the set of keys or the configured set of keys, based on a result of the key authentication procedure. The device causes a device identifier of the device and the public key to be provided to another device that uses the device identifier and the public key to perform an authentication procedure to authenticate the user. The device receives, from the other device, an indication of whether the device is connected to a network.