Secure SIM Data Transfer Between Processors
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems lack robust security measures for protecting sensitive data, such as SIM personalization information, especially when transferring data between processors in devices like cellular telephones, where security levels vary between more-secure and less-secure processors.
Innovation Solution
Implementing a secure data transfer protocol between a more-secure apps processor and a less-secure modem processor using hardware-based security features, including secure storage, authentication, and confidentiality mechanisms, such as random challenge protocols and asymmetric cryptographic processes, to ensure the secure transfer of sensitive data like SIM personalization information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is transferred between processors with different security levels, then interoperability and data utilization are improved, but security of sensitive data deteriorates
Solution Approach 1:
A secure data transfer protocol acts as an intermediary mechanism between the more-secure apps processor and less-secure modem processor. The protocol includes authentication steps where the modem processor authenticates itself to the apps processor, and confidentiality steps where data is encrypted before transfer. This intermediary protocol resolves the contradiction by enabling interoperability while maintaining security through structured communication rules.
Solution Approach 2:
The data transfer process is segmented into distinct security zones: a more-secure apps processor handling sensitive SIM personalization data, a secure data transfer protocol for authenticated communication, and a less-secure modem processor for non-sensitive operations. This segmentation allows each component to operate at its appropriate security level while maintaining overall system security through controlled interfaces.
2Reliability
If hardware-based security features are implemented, then security of sensitive data is improved, but device complexity increases
Solution Approach 1:
The patent combines multiple security functions into integrated hardware-based security features within the apps processor. Rather than adding separate security modules, the security capabilities (secure storage, authentication, encryption) are merged into the existing processor architecture. This merging approach improves security while minimizing the increase in device complexity by leveraging existing hardware resources.
3Reliability
If secure storage and authentication protocols are used, then confidentiality of data is improved, but data transfer efficiency deteriorates
Solution Approach 1:
Authentication is performed as a preliminary action before data transfer begins. The modem processor authenticates itself to the apps processor in advance, establishing trusted communication channels. This preliminary authentication allows subsequent data transfers to proceed more efficiently since the security handshake only needs to occur once, rather than with each transfer operation.
Solution Approach 2:
The data transfer protocol dynamically changes parameters based on security requirements and data sensitivity. For highly sensitive SIM personalization data, stronger encryption and authentication parameters are applied. For less sensitive data, lighter security parameters are used. This parameter adaptation maintains confidentiality while optimizing transfer efficiency based on actual security needs.
Data Source
AI summary
An electronic circuit 120 includes a more-secure processor (600) having hardware based security (138) for storing data. A less-secure processor (200) eventually utilizes the data. By a data transfer request-response arrangement (2010, 2050, 2070, 2090) between the more-secure processor (600) and the less-secure processor (200), the more-secure processor (600) confers greater security of the data on the less-secure processor (200). A manufacturing process makes a handheld device (110) having a storage space (222), a less-secure processor (200) for executing modem software and a more-secure processor (600) having a protected application (2090) and a secure storage (2210). A manufacturing process involves generating a per-device private key and public key pair, storing the private key in a secure storage (2210) where it can be accessed by the protected application (2090), combining the public key with the modem software to produce a combined software, signing the combined software; and storing the signed combined software into the storage space (222). Other processes of manufacture, processes of operation, circuits, devices, wireless and wireline communications products, wireless handsets and systems are disclosed and claimed.


