Security Element Key Replacement After Authentication Failure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The theft of output files containing authentication secrets compromises network security, allowing attackers to spy on network exchanges and erode user trust in mobile network operators.

Innovation Solution

A method for replacing authentication parameters in a security element involves storing a first parameter, transmitting it to the operator, and upon authentication failure, replacing it with a second parameter using a remote platform, without requiring an indicator to be sent to the security element.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an indicator is transmitted to the security element to authorize key replacement, then the security element can replace the first authentication parameter with a second parameter, but the workload of the remote platform increases

Engineering Contradiction:
Improveauthentication securityVSAvoidremote platform workload
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security element autonomously determines whether to replace the authentication parameter by checking if authentication fails and if the indicator is present in its memory, without requiring the remote platform to actively transmit authorization commands. The security element serves itself by making the replacement decision locally based on pre-stored indicators and authentication results.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The indicator authorizing key replacement is pre-transmitted to the security element before authentication failure occurs. This preliminary action allows the security element to have the authorization ready in advance, eliminating the need for real-time authorization requests and responses during the authentication failure event, thus reducing remote platform workload.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the first authentication parameter is stolen by an attacker, then network security is compromised and privacy is violated, but transmitting the parameter via Internet exposes it to theft

Engineering Contradiction:
Improvenetwork securityVSAvoidparameter theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system proactively monitors authentication failures and pre-prepares a second authentication parameter before the first parameter is compromised. When authentication fails, the security element can immediately switch to the second parameter, preventing attackers from using stolen first parameters to access the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication parameter is dynamically changed from the first parameter to a second parameter when authentication failure is detected and the indicator is present. This parameter change ensures that even if the first parameter is stolen, attackers cannot use it to authenticate, as the system has already transitioned to a new parameter.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12476804B2Method of replacing a current key in a security element and corresponding security element
Publication Date: 2025.11.18 THALES DIS FRANCE SA
  • US12476804B2 patent drawing
  • US12476804B2 patent drawing

AI summary

The disclosure concerns a method of replacing a current key in a security element co-operating with a terminal in a network operated by a network operator, the method includes trying to decrypt the encrypted message by using the current key; selecting in a table stored in the secure element another key and try to decrypt the encrypted message by using the other key; replacing atomically the current key by the rescue key and do not use the current key anymore, the rescue key replacing the current key and, otherwise, try to decrypt the encrypted message by using another rescue key of the window if such another rescue key exists, until all rescue keys have been selected and used for decrypting the encrypted message and, if none of the rescue keys permit to decrypt the encrypted message, select the blocking key; and blocking the corresponding functionality of the security element.