SIM Card Group Association via Trusted Processor Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SIM card management systems fail to prevent unauthorized use while allowing flexibility for use across multiple authorized mobile communications devices within an organization, as they often require administrative intervention and dedicated labs for transfers.
Innovation Solution
Implementing a trusted electronic processor in mobile communications devices that decrypts a hashed value from the SIM card using a stored second key, enabling authentication and association with a group of devices, allowing operation only when the device's IMEI matches the stored value, and using a hash function to ensure secure communication network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a SIM card is locked to a single mobile communications device, then unauthorized use is prevented, but flexibility for use across multiple authorized devices is lost
Solution Approach 1:
The authentication mechanism is segmented into two parts: a public hash function stored in the SIM card and a private key stored in the mobile device. This segmentation allows the SIM to be associated with multiple devices while maintaining security, as each device has its own private key but all share the same public hash function.
Solution Approach 2:
Instead of the SIM card storing the device identifier (IMEI) and locking to a single device, the invention inverts the approach by having the mobile device store authentication keys and the SIM card store only the public hash function. This inversion enables multi-device usage while maintaining security.
2Adaptability or versatility
If a SIM card is transferred between authorized devices, then device flexibility is maintained, but administrative intervention and dedicated lab operations are required
Solution Approach 1:
The system enables self-service authentication where the mobile device automatically performs authentication with the SIM card using stored keys and the hash function. This eliminates the need for administrative intervention and dedicated lab operations when transferring SIM cards between devices.
Solution Approach 2:
The private authentication keys are preliminarily stored in the mobile devices during initial setup. This preliminary action enables automatic authentication during device transfers without requiring real-time administrative intervention or specialized equipment.
3Reliability
If a dedicated SIM programmer and administrator password are used for IMEI erasure, then security is maintained, but operational complexity and time loss increase
Solution Approach 1:
The complex IMEI erasure operation is extracted and replaced with a simpler key-based authentication mechanism. The private keys are stored in the mobile devices, and authentication is performed automatically during device-SIM card interaction, eliminating the need for dedicated SIM programmers and complex administrative procedures.
Data Source
AI summary
Method and apparatus for associating a subscriber identity module to a group of mobile communications devices is provided. One embodiment provides a method including receiving the hashed value from the SIM card and decrypting, using the trusted electronic processor, the hashed value based on a second key stored on the mobile communications device to generate a response. The method also includes sending, using the trusted electronic processor, the response to the SIM card and receiving, at the trusted electronic processor, an acknowledgement from the SIM card indicating that the response matches an expected response.


