SIM Card Encryption Key Management via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SIM card security mechanisms require a large number of independent keys to manage access across different secure areas, leading to high costs and complexity in ensuring secure access for multiple third parties and service providers.

Innovation Solution

A method involving the provision of an encryption code by a first agency to a second agency, which encrypts data on a chip card, allowing secure transmission and decryption by a third party without direct access to the card, reducing the number of keys needed and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each party (network operator, TTPs, service providers) is provided with independent keys to access their respective areas on the SIM card, then security against eavesdropping is ensured, but the number of keys to be managed and distributed increases significantly, leading to high costs and complexity

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is segmented into different functional components: a first location (key management entity), a second location (encryption entity), and a third location (SIM card manufacturer). The key management function is separated from the encryption function, allowing independent keys to be used only for encryption while a separate access key controls chip card access. This segmentation reduces the complexity of managing multiple independent access keys while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary entity (the first location) is introduced to manage the encryption codes and distribute them to the second location. This intermediary handles the key management complexity centrally, while the actual SIM card production and data encryption are performed by separate entities. The intermediary acts as a mediator that coordinates between the access key holder (third location) and the encryption key holder (second location), reducing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple independent keys are provided to different parties for accessing different areas, then secure access control is achieved, but the cost of maintaining and distributing these keys increases significantly

Engineering Contradiction:
Improvesecure access controlVSAvoidkey distribution cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The encryption code serves multiple functions: it enables secure data encryption for service providers, allows TTPs to protect their security domains, and provides a foundation for access control without requiring separate independent keys for each function. By making the encryption code multi-functional, the system reduces the total number of keys needed while maintaining secure access control across different parties and areas.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service through the use of decryption codes stored on the chip card itself. The chip card can autonomously decrypt data using the decryption code provided during personalization, without requiring continuous external key management intervention. This self-service capability reduces the ongoing costs of key distribution and management while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If a large number of independent keys are distributed to ensure secure access for multiple third parties and service providers, then comprehensive security coverage is achieved, but the system becomes more complex and expensive to operate

Engineering Contradiction:
Improvesecurity coverageVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of providing each party with their own independent access key to the chip card, the system inverts the approach: the third location (SIM card manufacturer) is provided with an access key to write data, while the second location (service provider) holds the encryption key to protect the data. This inversion of traditional key distribution roles simplifies operational complexity while maintaining comprehensive security coverage, as the manufacturer can write data without needing multiple access keys for different service providers.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP2190232B1Method for providing data on at least one area of a chip card
Publication Date: 2015.07.01 VODAFONE HOLDING GMBH
  • EP2190232B1 patent drawingFigure 1
  • EP2190232B1 patent drawingFigure 2
  • EP2190232B1 patent drawingFigure 3

AI summary

The method involves providing encryption codes from a location to another location, and providing decryption codes corresponding to the encryption codes from the former location to a chip card i.e. subscriber identify module (SIM) card (10). The encryption codes are used for generating an encrypted data set from a data set. The encrypted data set is provided to a third location. The encrypted data set is transmitted to an area (45) of the card. The decryption codes are used for decryption of the encrypted data set in the data set on the card.