SIM Application Toolkit Authentication for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures for IoT devices are vulnerable to fraud and hacking, as they rely on storing identities and secrets within the devices, making them susceptible to identity theft and unauthorized access to communication networks.

Innovation Solution

The implementation of a Subscriber Identity Module (SIM) or embedded SIM (eSIM) application toolkit (SAT) that mediates access to security credentials, using a new functionality to authenticate IoT devices and other electronic devices into various communication network domains, generating and verifying authentication vectors and session keys to secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security credentials (identities and secrets) are stored within IoT devices, then authentication capability is provided, but security is weakened due to vulnerability to fraud and hacking

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to fraud and hacking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts security credentials (identities and secrets) from the IoT device itself and stores them in a remote authentication server. The device only holds references to these credentials, not the credentials themselves, thereby removing the vulnerability source while maintaining authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication server as an intermediary between the IoT device and the network domain. This server mediates the authentication process by verifying credentials remotely, eliminating the need for devices to store sensitive security information locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If SIM application toolkit mediates access to security credentials, then security is enhanced by restricting access, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity of authentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The SIM application toolkit acts as an intermediary layer between the application and the SIM card, managing authentication workflows. While this adds a software layer, it keeps the hardware SIM card simple and secure, and the complexity is centralized in a manageable software component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system enables devices to authenticate themselves automatically without manual intervention. The SIM application toolkit handles the complex authentication sequences autonomously, reducing operational complexity despite increased system sophistication.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11751059B1Subscriber identification module (SIM) application authentication
Publication Date: 2023.09.05 T MOBILE INNOVATIONS LLC
  • US11751059B1 patent drawing
  • US11751059B1 patent drawing
  • US11751059B1 patent drawing

AI summary

A method of authenticating access of an electronic device to an application server based on a subscriber identity module (SIM) associated with the electronic device. The method receiving an authentication challenge from an application executing on the device by a SIM application toolkit (SAT) executing on the device, transmitting a random number and an authentication value of the challenge to a SIM of the device by the SAT, receiving a response from the SIM by the SAT, transmitting an authentication response to the application by the SAT, where the authentication response comprises the response received from the SIM, generating an application key by the SAT based at least in part on the response received from the SIM, and transmitting the application key to the application by the SAT, whereby the application executing on the electronic device establishes a communication session with an application server via an access communication network.