Trusted Remote Attestation for SIM-Bound Mobile Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing financial transactions conducted via wireless communication in consumer electronic devices face security issues due to the susceptibility of data transfer, including credit card and financial instrument information, and require cooperation among multiple parties to ensure secure over-the-air links.
Innovation Solution
The integration of a Trusted Integrity Manager (TIM) with a Trusted Service Manager (TSM) enhances security by validating and authenticating transactions using mobile devices, incorporating a Trusted Authentication Provider (TAP) to manage and verify data integrity, including time and geo-location, within an embedded secure element (eSE) to ensure secure financial transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If wireless communication is used for financial transactions, then convenience and speed are improved, but security and susceptibility to theft are worsened
Solution Approach 1:
The system segments the authentication process into multiple independent verification stages: device integrity verification by TRAA, SIM card validation by TIM, and transaction authorization by TSM. Each segment operates independently to verify specific security aspects, ensuring that no single point of failure compromises the entire transaction security while maintaining fast processing speed.
Solution Approach 2:
The patent introduces intermediary components (TRAA, TIM, TSM) that mediate between the wireless communication channel and the financial transaction system. These intermediaries verify device integrity, validate SIM cards, and authorize transactions without exposing sensitive financial data over the wireless channel, thus maintaining both speed and security.
2Reliability
If multiple parties are involved in the transaction system, then security verification is improved, but system complexity is worsened
Solution Approach 1:
The system divides the authentication and verification functions into separate modular components: TRAA for device integrity verification, TIM for SIM card management and validation, and TSM for transaction authorization. Each component has a specific security function and can be independently implemented and maintained, reducing overall system complexity while enhancing authentication security through multiple verification layers.
Solution Approach 2:
The TRAA automatically performs device integrity verification and SIM card validation without requiring manual intervention from users or other parties. The system components self-verify their integrity and automatically enforce security policies, reducing the operational complexity of managing multiple parties while maintaining high authentication security.
3Reliability
If device integrity verification is performed, then security against tampering is improved, but processing time is worsened
Solution Approach 1:
The system performs device integrity verification and SIM card validation as preliminary actions before the actual financial transaction takes place. The TRAA verifies device integrity and the TIM validates the SIM card during the initialization phase, so that when a transaction occurs, the authentication is already complete and can proceed immediately, minimizing verification time during the transaction itself.
Solution Approach 2:
The patent replaces manual or mechanical verification processes with automated electronic verification mechanisms. The TRAA and TIM use cryptographic verification and automated validation protocols to check device integrity and SIM card authenticity instantly, eliminating time-consuming manual verification steps while maintaining high security standards.
Data Source
AI summary
Systems and methods for use with a service provider and a consumer electronic device include a trusted remote attestation agent (TRAA) configured to perform a set of checking procedures or mechanisms to help ensure the security status of a consumer electronic device (e.g., a mobile terminal or phone) that holds financial instruments. The checking procedures may include: self-verifying integrity by the TRAA; checking for presence of a provisioning SIM card (one that was present when the financial instruments were enabled on the device); checking that a communication connection between the consumer electronic device and the service provider is available and active; and checking that communication connectivity to a home mobile network is available and active. The frequency of the checking mechanisms may be adjusted, for example, according to a risk-profile of a user associated with the device or the location (e.g., GPS location) of the device. The checks may be used, for example, to temporarily disable or limit the use of the financial instruments from the device.


