Secure Element Lock Policy for Subscriber Identity Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network service access control mechanisms fail to effectively protect subscriber identity while restricting access to network services, as they require frequent updates when subscriber identities are encrypted.

Innovation Solution

Implementing a lock mechanism that encrypts a portion of the subscription permanent identifier (SUPI) within a tamper-resistant hardware secure element, allowing only authorized processing circuitry external to the secure element to access necessary information for enforcing device-level lock policies, using a false SUPI with dummy values for the MSIN portion and separate storage of MCC and MNC as elementary files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If the SUPI is encrypted to protect subscriber identity, then subscriber identity privacy is improved, but lock mechanism reliability deteriorates due to frequent updates required

Engineering Contradiction:
Improvesubscriber identity privacyVSAvoidlock mechanism reliability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent segments the SUPI into two parts: the concealed identifier (first portion) stored encrypted in the UICC for privacy protection, and the accessible identifier (second portion) stored in plaintext in the baseband processor for reliable lock mechanism operations. This segmentation allows both encrypted storage for privacy and plaintext access for reliability without requiring frequent updates.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the entire SUPI is stored in the UICC for secure access control, then security is improved, but processing circuitry access to lock policy information deteriorates

Engineering Contradiction:
Improveaccess control securityVSAvoidprocessing circuitry access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the second portion of the SUPI (accessible identifier) from the UICC and stores it separately in the baseband processor's memory. This extraction allows the processing circuitry to directly access lock policy information without requiring UICC decryption operations, improving ease of operation while the first portion remains securely stored in the UICC for maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Loss of information

If a false SUPI with dummy MSIN values is used, then subscriber identity protection is improved, but lock policy enforcement accuracy may deteriorate

Engineering Contradiction:
Improvesubscriber identity protectionVSAvoidlock policy enforcement accuracy
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The patent applies local quality by making different parts of the identifier serve different functions: the first portion (MCC/MNC) contains real network identification information for accurate lock policy enforcement, while the second portion (MSIN) uses dummy values for privacy protection. This localized differentiation allows both identity protection and accurate policy enforcement to coexist.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11405788B2Wireless network service access control with subscriber identity protection
Publication Date: 2022.08.02 APPLE INC
  • US11405788B2 patent drawing
  • US11405788B2 patent drawing
  • US11405788B2 patent drawing

AI summary

A device level lock policy, which applies to all smart secure platform (SSP) applications of a mobile device, is used to determine whether a particular SSP application can be activated. A tamper resistant hardware secure element (SE) includes a primary platform with a low level operating system (OS) and one or more SSP applications within one or more secondary platform bundles that include secondary platforms with high level OSs specific to the secondary platform bundles. The low level OS enforces the device level lock policy for all secondary platform bundles by verifying whether a lock policy for the SSP application is consistent with the device level lock policy. When verification succeeds, activation is allowed, and when verification fails, activation is disallowed. Subscription identifiers are not provided in unencrypted form to processing circuitry of the mobile device external to the tamper resistant hardware SE to provide subscriber identity privacy protection.