SIM Card Asymmetric Authentication for IMSI Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current user authentication methods for Internet services are insecure, particularly when using telecommunications terminals with identity modules, as they can be manipulated, and require users to manage multiple usernames and passwords, which is cumbersome and insecure.
Innovation Solution
A method using asymmetric cryptographic methods to authenticate telecommunications terminals by assigning a key pair to the identity module and a server device, where the identity information is signed or encrypted using private keys, ensuring secure and tamper-proof transmission of IMSI numbers across network structures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional username and password authentication is used for Internet services, then users can access services, but security is compromised and users must manage multiple credentials
Solution Approach 1:
The patent introduces an identity module (SIM card) as an intermediary authentication device that stores cryptographic key pairs. This mediator handles authentication securely without requiring users to manage multiple usernames and passwords, thus improving both security and ease of operation
Solution Approach 2:
The patent replaces the mechanical system of manual username/password management with cryptographic methods using asymmetric encryption. The identity module automatically handles key pairs and digital signatures, substituting manual credential management with automated cryptographic authentication
2Reliability
If asymmetric cryptographic methods are implemented for authentication, then security is improved, but device complexity increases
Solution Approach 1:
The identity module autonomously generates and manages cryptographic key pairs without requiring external intervention. The module self-services the complex task of key management, storing private keys securely and automatically performing cryptographic operations, thus reducing the perceived complexity for users
3Adaptability or versatility
If identity information is transmitted across network structures, then service accessibility is improved, but manipulation risk increases
Solution Approach 1:
The patent applies preliminary anti-action by signing identity information with digital signatures before transmission. This pre-authentication prevents manipulation during network transmission, as any alteration would invalidate the signature, thus countering potential harmful factors before they can occur
4Reliability
If electronic identity cards with NFC readers are used for authentication, then identification security is improved, but cost and availability are worsened
Solution Approach 1:
The patent makes the identity module (SIM card) serve multiple functions: it acts as both the authentication credential and the cryptographic processing unit. This universal approach eliminates the need for separate NFC readers, as the smartphone itself handles cryptographic operations, reducing additional hardware costs
Data Source
Figure 1
AI summary
The invention describes a method for authenticating a telecommunication terminal comprising an identity module on a server device in a telecommunication network, wherein a piece of identity information explicitly associated with the identity module is used for authentication by using the properties of an asymmetric cryptographical method, wherein the identity module has an associated first key pair, comprising a first public key and a first private key, wherein the server device has an associated second key pair, comprising a second public key and a second private key, wherein the method has the following steps: -- a first method step involves a memory area of the identity module being used -- to store the first private key and -- to store the first public key and -- to store a first signature, wherein the first signature is provided by signing the first public key using the second private key on the basis of the cryptographical method, -- a second method step involves the identity information explicitly associated with the identity module being generated by the identity module and a second signature being generated, wherein the second signature is provided by signing the identity information using the first private key on the basis of the cryptographical method, -- a third method step involves the first public key, the identity information and the first and second signatures being transmitted to the server device, -- a fourth method step involves the server device - verifying the authenticity of the first public key using the second public key and - checking the authenticity of the identity information using the verified first public key.