Security Element Authentication Parameter Replacement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for updating authentication parameters in security elements used in telecommunication networks are complex, prone to parameter desynchronization, and vulnerable to attacks, leading to potential connectivity issues and increased churn among mobile network users.

Innovation Solution

A method for Over-The-Air (OTA) updating of authentication parameters in security elements, where a second authentication parameter is activated only upon failure of the initial parameter, ensuring secure and synchronized updates without direct server interaction, using a remote platform to manage the replacement process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If authentication parameters are transmitted through secured Internet channels during personalization, then security elements can be provisioned with authentication parameters, but the transmission channels and storage systems remain vulnerable to theft and compromise

Engineering Contradiction:
Improvepersonalization processVSAvoidtheft of authentication parameters
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-provisioning the security element with multiple authentication parameters during the personalization phase, before any potential compromise occurs. This allows the element to have backup parameters ready in advance, so that if one parameter is stolen or compromised, the element can immediately switch to an alternative parameter without requiring re-personalization or terminal replacement.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication parameters are updated synchronously in both security elements and backend infrastructure, then parameter consistency is maintained, but the complexity of coordination between distributed systems increases

Engineering Contradiction:
Improveparameter synchronizationVSAvoidupdate coordination system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring multiple authentication parameters in the security element before any update is needed. When an update is required, the system only needs to transmit new parameter values to the element, which automatically replaces the compromised parameter with a pre-prepared alternative. This eliminates the need for complex synchronous coordination between the element and backend infrastructure, as the element independently manages its parameter updates.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security elements are replaced when compromise is detected, then network security is maintained, but the cost increases significantly especially when elements are embedded in terminals

Engineering Contradiction:
Improvenetwork securityVSAvoidreplacement cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies the discarding and recovering principle by enabling the security element to discard a compromised authentication parameter and recover functionality by switching to an alternative parameter stored in the same element. This eliminates the need to physically replace the entire security element or terminal device, thereby recovering the investment in the original hardware while maintaining network security. The element effectively discards the stolen parameter and recovers service continuity using a backup parameter.

Inventive Principle:
Principle #34Discarding and recovering

4Reliability

If multiple authentication parameters are stored in the security element, then backup options are available for compromised parameters, but the storage requirements and management complexity increase

Engineering Contradiction:
Improveparameter backup availabilityVSAvoidstorage space for parameters
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies parameter changes by implementing a hierarchical parameter structure where one primary authentication parameter is supplemented by one or more alternative parameters. The system dynamically changes which parameter is active based on whether the primary parameter is compromised. This approach provides reliable backup availability while minimizing storage requirements, as only essential alternative parameters are stored rather than redundant copies of all possible parameters.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10959094B2Method of replacing at least one authentication parameter for authenticating a security element and corresponding security element
Publication Date: 2021.03.23 THALES DIS FRANCE SA
  • US10959094B2 patent drawing

AI summary

A method of replacing an authentication parameter for authenticating a security element co-operating with a terminal includes storing in the security element a first authentication parameter; transmitting to a mobile network operator the first authentication parameter for the operator to record it in its authentication system; on occurrence of an event, having a remote platform transmit to the security element an indicator informing the security element that it is authorized to replace the first authentication parameter with a second authentication parameter if its authentication fails; on occurrence of the event, having the entity transmit to the operator a second authentication parameter to replace the first authentication parameter; and in the event of subsequent failure of the security element to connect to the mobile network and if the indicator is present at the security element, replacing the first authentication parameter with the second authentication parameter at the security element.