SIM Application Toolkit Authentication for IoT Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures for IoT devices are vulnerable to fraud and hacking, as they rely on storing identities and secrets within the devices, making them susceptible to identity theft and unauthorized access to communication networks.
Innovation Solution
The implementation of a Subscriber Identity Module (SIM) or embedded SIM (eSIM) application toolkit (SAT) that mediates access to security credentials, using a new functionality to authenticate IoT devices and other electronic devices into various communication network domains, generating and verifying authentication vectors and session keys to secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security credentials (identities and secrets) are stored within IoT devices, then authentication capability is provided, but security is weakened due to vulnerability to fraud and hacking
Solution Approach 1:
The patent extracts security credentials (identities and secrets) from the IoT device itself and stores them in a remote authentication server. The device only holds references to these credentials, not the credentials themselves, thereby removing the vulnerability source while maintaining authentication capability.
Solution Approach 2:
The patent introduces an authentication server as an intermediary between the IoT device and the network domain. This server mediates the authentication process by verifying credentials remotely, eliminating the need for devices to store sensitive security information locally.
2Reliability
If SIM application toolkit mediates access to security credentials, then security is enhanced by restricting access, but device complexity increases
Solution Approach 1:
The SIM application toolkit acts as an intermediary layer between the application and the SIM card, managing authentication workflows. While this adds a software layer, it keeps the hardware SIM card simple and secure, and the complexity is centralized in a manageable software component.
Solution Approach 2:
The authentication system enables devices to authenticate themselves automatically without manual intervention. The SIM application toolkit handles the complex authentication sequences autonomously, reducing operational complexity despite increased system sophistication.
Data Source
AI summary
A method of authenticating access of an electronic device to an application server based on a subscriber identity module (SIM) associated with the electronic device. The method receiving an authentication challenge from an application executing on the device by a SIM application toolkit (SAT) executing on the device, transmitting a random number and an authentication value of the challenge to a SIM of the device by the SAT, receiving a response from the SIM by the SAT, transmitting an authentication response to the application by the SAT, where the authentication response comprises the response received from the SIM, generating an application key by the SAT based at least in part on the response received from the SIM, and transmitting the application key to the application by the SAT, whereby the application executing on the electronic device establishes a communication session with an application server via an access communication network.


