Selective SIM Invalidation for Roaming Security and Service Continuity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless devices face security risks and performance issues due to SIM invalidation, which can occur unexpectedly, leading to limited or no service, especially when roaming or encountering rogue networks.

Innovation Solution

A user equipment (UE) determines whether to invalidate or block a SIM based on connection rejection messages, network identity, relationship with the network, and availability of alternative networks, allowing selective management of SIM and network connections to prevent unnecessary service disruptions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE automatically invalidates the SIM upon receiving a connection rejection message, then the security risk is reduced and rogue networks are blocked, but the service continuity is disrupted and legitimate networks may be incorrectly blocked

Engineering Contradiction:
ImprovesecurityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by differentiating the invalidation action based on network identity. Instead of a uniform invalidation response to all rejection messages, the system selectively invalidates only rogue networks while preserving access to legitimate networks. This is achieved by evaluating network identity characteristics and applying invalidation only where security risks are present, thus maintaining service continuity for authorized networks while blocking malicious ones.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements feedback by continuously monitoring connection rejection messages and evaluating them against stored network identity information. This feedback loop allows the UE to make informed decisions about SIM invalidation based on the specific characteristics of each rejection message and the known identity of the rejecting network, preventing premature or incorrect invalidation of legitimate networks.

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If the UE blocks the SIM after multiple connection rejections, then denial-of-service attacks are prevented, but legitimate network access is lost and service outage occurs

Engineering Contradiction:
Improvedenial-of-service attacksVSAvoidservice availability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-storing network identity information in the UE before connection attempts are made. This allows the system to evaluate rejection messages against known legitimate network identities in advance, preventing incorrect blocking of authorized networks. The preliminary storage of network identities enables rapid comparison and decision-making during connection attempts, blocking malicious networks while preserving access to legitimate ones.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the parameter of network evaluation from simple rejection counting to identity-based discrimination. Instead of blocking based solely on the number of rejections received, the system modifies its behavior by incorporating network identity verification as a critical parameter, allowing it to distinguish between legitimate networks that may temporarily reject connections and rogue networks that should be permanently blocked.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the UE validates SIM frequently to ensure network legitimacy, then security is improved and rogue networks are detected, but the device complexity and processing overhead increase

Engineering Contradiction:
Improvenetwork authenticationVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent reduces processing overhead by performing preliminary validation of network identities before connection attempts. By pre-storing and pre-evaluating network identity information, the system avoids complex real-time validation during connection processes. This preliminary action allows the UE to quickly compare rejection messages against stored identities, maintaining high security while minimizing processing requirements during actual connections.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11265839B2Avoiding subscriber identity module invalidation
Publication Date: 2022.03.01 APPLE INC
  • US11265839B2 patent drawing
  • US11265839B2 patent drawing
  • US11265839B2 patent drawing

AI summary

Embodiments are presented herein of apparatuses, systems, and methods for a user equipment device (UE) and/or cellular network to avoid invalidation of a subscriber identity module (SIM). A UE may initiate a connection with the network. The network may reject the connection attempt. The UE may selectively determine whether to invalidate the SIM, network, or both. The UE may consider various factors such as details of the connection rejection message, identity of the network, its relationship to the network (e.g., whether the network is a preferred network, etc.), a number of connection rejections received, time remaining on one or more timers, availability of other networks, etc.