SIM Activation Code via Voice Channel for Secure Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure data exchange using SIM cards in mobile networks are not secure enough, particularly due to vulnerabilities in transmitting passwords and one-time codes, and are often cumbersome and difficult to implement.

Innovation Solution

A method that generates an activation code on a SIM card only when needed, encrypts data using this code, and transmits it securely via a voice channel, ensuring the code is never saved or transmitted insecurely, using high-security OTA servers and encryption algorithms like 3DES or HMAC.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passwords or one-time codes are transmitted via SMS or data channels, then data exchange can occur, but security is compromised because passwords become visible to network operators and vulnerable to interception

Engineering Contradiction:
ImprovesecurityVSAvoidease of data exchange
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a voice channel as an intermediary transmission medium. Instead of directly transmitting passwords through vulnerable data channels, the system uses voice calls with automated voice recognition to convey activation codes. This intermediary approach masks the actual password transmission, making it invisible to network operators and resistant to traditional interception methods while maintaining ease of use through automated processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical/data-based transmission system with a voice-based acoustic channel. By substituting the data channel transmission mechanism with voice call transmission, the system exploits the different security characteristics of voice networks, where passwords are not visible to operators and are protected from interception, thus improving security without significantly impacting ease of operation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If activation codes are generated and stored on the SIM card, then security is improved because codes are always on the correct device, but device complexity increases due to requiring SIM card integration and activation code generator

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the SIM card's existing multi-functionality by integrating the activation code generator into this already-present component. Rather than adding a separate security device, the system utilizes the SIM card's universal role in identification, authentication, and now code generation. This approach improves security by keeping codes on the correct device while minimizing additional complexity by reusing existing infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If one-time passwords are used for each transaction, then security against unauthorized interception is improved, but loss of time increases due to generating and managing new passwords for each access

Engineering Contradiction:
ImprovesecurityVSAvoidtime for password management
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling the SIM card to automatically generate activation codes without requiring user intervention for password management. The system autonomously handles code generation, transmission via voice channel, and validation, eliminating the time-consuming manual processes of remembering, storing, and entering multiple one-time passwords while maintaining the security benefits of single-use codes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring the SIM card with activation code generator capabilities and pre-establishing voice channel transmission protocols. This preparation allows subsequent authentication transactions to proceed quickly without the time penalty of setting up security mechanisms during each interaction, thus maintaining both security and efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP1971161B1Secure data exchange method
Publication Date: 2019.05.01 VODAFONE HOLDING GMBH
  • EP1971161B1 patent drawingFigure 1

AI summary

The method involves registering a user (60) by a voice communication in a data processing system (22), and transferring a password and username to the user. An activation code (70) is generated by an activation code generator (56) provided in a subscriber identity module (SIM) card (54) of a mobile device (10). The activation code is transferred to the system over a secure personal computer (PC) connection (92). Data are encoded by using the code in the system, and the encoded data are sent to the SIM card over an over-the-air (OTA) server (16). The data are decoded by the card using the code.