Secure SIM Data Transfer Between Processors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems lack robust security measures for protecting sensitive data, such as SIM personalization information, especially when transferring data between processors in devices like cellular telephones, where security levels vary between more-secure and less-secure processors.

Innovation Solution

Implementing a secure data transfer protocol between a more-secure apps processor and a less-secure modem processor using hardware-based security features, including secure storage, authentication, and confidentiality mechanisms, such as random challenge protocols and asymmetric cryptographic processes, to ensure the secure transfer of sensitive data like SIM personalization information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is transferred between processors with different security levels, then interoperability and data utilization are improved, but security of sensitive data deteriorates

Engineering Contradiction:
ImproveinteroperabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A secure data transfer protocol acts as an intermediary mechanism between the more-secure apps processor and less-secure modem processor. The protocol includes authentication steps where the modem processor authenticates itself to the apps processor, and confidentiality steps where data is encrypted before transfer. This intermediary protocol resolves the contradiction by enabling interoperability while maintaining security through structured communication rules.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The data transfer process is segmented into distinct security zones: a more-secure apps processor handling sensitive SIM personalization data, a secure data transfer protocol for authenticated communication, and a less-secure modem processor for non-sensitive operations. This segmentation allows each component to operate at its appropriate security level while maintaining overall system security through controlled interfaces.

Inventive Principle:
Principle #1Segmentation

2Reliability

If hardware-based security features are implemented, then security of sensitive data is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security functions into integrated hardware-based security features within the apps processor. Rather than adding separate security modules, the security capabilities (secure storage, authentication, encryption) are merged into the existing processor architecture. This merging approach improves security while minimizing the increase in device complexity by leveraging existing hardware resources.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If secure storage and authentication protocols are used, then confidentiality of data is improved, but data transfer efficiency deteriorates

Engineering Contradiction:
ImproveconfidentialityVSAvoidtransfer efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Authentication is performed as a preliminary action before data transfer begins. The modem processor authenticates itself to the apps processor in advance, establishing trusted communication channels. This preliminary authentication allows subsequent data transfers to proceed more efficiently since the security handshake only needs to occur once, rather than with each transfer operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The data transfer protocol dynamically changes parameters based on security requirements and data sensitivity. For highly sensitive SIM personalization data, stronger encryption and authentication parameters are applied. For less sensitive data, lighter security parameters are used. This parameter adaptation maintains confidentiality while optimizing transfer efficiency based on actual security needs.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7940932B2Methods, apparatus, and systems for securing SIM (subscriber identity module) personalization and other data on a first processor and secure communication of the SIM data to a second processor
Publication Date: 2011.05.10 TEXAS INSTRUMENTS INC
  • US7940932B2 patent drawing
  • US7940932B2 patent drawing
  • US7940932B2 patent drawing

AI summary

An electronic circuit 120 includes a more-secure processor (600) having hardware based security (138) for storing data. A less-secure processor (200) eventually utilizes the data. By a data transfer request-response arrangement (2010, 2050, 2070, 2090) between the more-secure processor (600) and the less-secure processor (200), the more-secure processor (600) confers greater security of the data on the less-secure processor (200). A manufacturing process makes a handheld device (110) having a storage space (222), a less-secure processor (200) for executing modem software and a more-secure processor (600) having a protected application (2090) and a secure storage (2210). A manufacturing process involves generating a per-device private key and public key pair, storing the private key in a secure storage (2210) where it can be accessed by the protected application (2090), combining the public key with the modem software to produce a combined software, signing the combined software; and storing the signed combined software into the storage space (222). Other processes of manufacture, processes of operation, circuits, devices, wireless and wireline communications products, wireless handsets and systems are disclosed and claimed.