SIM Card Asymmetric Authentication for IMSI Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user authentication methods for Internet services are insecure, particularly when using telecommunications terminals with identity modules, as they can be manipulated, and require users to manage multiple usernames and passwords, which is cumbersome and insecure.

Innovation Solution

A method using asymmetric cryptographic methods to authenticate telecommunications terminals by assigning a key pair to the identity module and a server device, where the identity information is signed or encrypted using private keys, ensuring secure and tamper-proof transmission of IMSI numbers across network structures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional username and password authentication is used for Internet services, then users can access services, but security is compromised and users must manage multiple credentials

Engineering Contradiction:
Improveauthentication securityVSAvoiduser credential management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an identity module (SIM card) as an intermediary authentication device that stores cryptographic key pairs. This mediator handles authentication securely without requiring users to manage multiple usernames and passwords, thus improving both security and ease of operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical system of manual username/password management with cryptographic methods using asymmetric encryption. The identity module automatically handles key pairs and digital signatures, substituting manual credential management with automated cryptographic authentication

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If asymmetric cryptographic methods are implemented for authentication, then security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidcryptographic key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identity module autonomously generates and manages cryptographic key pairs without requiring external intervention. The module self-services the complex task of key management, storing private keys securely and automatically performing cryptographic operations, thus reducing the perceived complexity for users

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If identity information is transmitted across network structures, then service accessibility is improved, but manipulation risk increases

Engineering Contradiction:
Improvenetwork service accessibilityVSAvoididentity information manipulation
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by signing identity information with digital signatures before transmission. This pre-authentication prevents manipulation during network transmission, as any alteration would invalidate the signature, thus countering potential harmful factors before they can occur

Inventive Principle:
Principle #9Preliminary anti-action

4Reliability

If electronic identity cards with NFC readers are used for authentication, then identification security is improved, but cost and availability are worsened

Engineering Contradiction:
Improveidentification securityVSAvoidreader device cost and availability
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent makes the identity module (SIM card) serve multiple functions: it acts as both the authentication credential and the cryptographic processing unit. This universal approach eliminates the need for separate NFC readers, as the smartphone itself handles cryptographic operations, reducing additional hardware costs

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2749003B1Method for authenticating a telecommunication terminal comprising an identity module on a server device in a telecommunication network, use of an identity module, identity module and computer program
Publication Date: 2018.06.27 DEUTSCHE TELEKOM AG
  • EP2749003B1 patent drawingFigure 1

AI summary

The invention describes a method for authenticating a telecommunication terminal comprising an identity module on a server device in a telecommunication network, wherein a piece of identity information explicitly associated with the identity module is used for authentication by using the properties of an asymmetric cryptographical method, wherein the identity module has an associated first key pair, comprising a first public key and a first private key, wherein the server device has an associated second key pair, comprising a second public key and a second private key, wherein the method has the following steps: -- a first method step involves a memory area of the identity module being used -- to store the first private key and -- to store the first public key and -- to store a first signature, wherein the first signature is provided by signing the first public key using the second private key on the basis of the cryptographical method, -- a second method step involves the identity information explicitly associated with the identity module being generated by the identity module and a second signature being generated, wherein the second signature is provided by signing the identity information using the first private key on the basis of the cryptographical method, -- a third method step involves the first public key, the identity information and the first and second signatures being transmitted to the server device, -- a fourth method step involves the server device - verifying the authenticity of the first public key using the second public key and - checking the authenticity of the identity information using the verified first public key.