SIM Card Group Association via Trusted Processor Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SIM card management systems fail to prevent unauthorized use while allowing flexibility for use across multiple authorized mobile communications devices within an organization, as they often require administrative intervention and dedicated labs for transfers.

Innovation Solution

Implementing a trusted electronic processor in mobile communications devices that decrypts a hashed value from the SIM card using a stored second key, enabling authentication and association with a group of devices, allowing operation only when the device's IMEI matches the stored value, and using a hash function to ensure secure communication network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a SIM card is locked to a single mobile communications device, then unauthorized use is prevented, but flexibility for use across multiple authorized devices is lost

Engineering Contradiction:
Improveprevention of unauthorized useVSAvoidflexibility for use across multiple authorized devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication mechanism is segmented into two parts: a public hash function stored in the SIM card and a private key stored in the mobile device. This segmentation allows the SIM to be associated with multiple devices while maintaining security, as each device has its own private key but all share the same public hash function.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of the SIM card storing the device identifier (IMEI) and locking to a single device, the invention inverts the approach by having the mobile device store authentication keys and the SIM card store only the public hash function. This inversion enables multi-device usage while maintaining security.

Inventive Principle:
Principle #13The other way round (Inversion)

2Adaptability or versatility

If a SIM card is transferred between authorized devices, then device flexibility is maintained, but administrative intervention and dedicated lab operations are required

Engineering Contradiction:
Improvedevice flexibilityVSAvoidadministrative intervention and dedicated lab operations
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system enables self-service authentication where the mobile device automatically performs authentication with the SIM card using stored keys and the hash function. This eliminates the need for administrative intervention and dedicated lab operations when transferring SIM cards between devices.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The private authentication keys are preliminarily stored in the mobile devices during initial setup. This preliminary action enables automatic authentication during device transfers without requiring real-time administrative intervention or specialized equipment.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a dedicated SIM programmer and administrator password are used for IMEI erasure, then security is maintained, but operational complexity and time loss increase

Engineering Contradiction:
ImprovesecurityVSAvoidoperational complexity and time loss
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The complex IMEI erasure operation is extracted and replaced with a simpler key-based authentication mechanism. The private keys are stored in the mobile devices, and authentication is performed automatically during device-SIM card interaction, eliminating the need for dedicated SIM programmers and complex administrative procedures.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10104078B1Method and apparatus for associating sim card with a group of mobile communications devices
Publication Date: 2018.10.16 MOTOROLA SOLUTIONS INC
  • US10104078B1 patent drawing
  • US10104078B1 patent drawing
  • US10104078B1 patent drawing

AI summary

Method and apparatus for associating a subscriber identity module to a group of mobile communications devices is provided. One embodiment provides a method including receiving the hashed value from the SIM card and decrypting, using the trusted electronic processor, the hashed value based on a second key stored on the mobile communications device to generate a response. The method also includes sending, using the trusted electronic processor, the response to the SIM card and receiving, at the trusted electronic processor, an acknowledgement from the SIM card indicating that the response matches an expected response.