SIM Card Secure Element for Enterprise Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current enterprise mobility management systems struggle to effectively manage and secure data on mobile devices due to increasing processing capabilities and storage capacities, leading to risks of data loss or misuse in unsecured environments, especially with varied application support and configuration requirements across different devices.

Innovation Solution

A SIM-based system that employs a scriptable management application stored within a SIM card to securely store and manage data, software applications, and device configurations, using a processor on the SIM card to execute scripts and validate user access based on dynamic security policies, ensuring secure storage and processing of sensitive information across different mobile devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If mobile devices are provided with increased processing capabilities and storage capacities, then productivity and functionality are improved, but security risks and vulnerability to data loss increase

Engineering Contradiction:
Improveprocessing capabilities and storage capacitiesVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the mobile device into two distinct security zones: a secure element (SE) for storing sensitive data and executing security-critical operations, and a non-secure environment for general applications. This segmentation isolates critical assets from potential threats while maintaining device functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure element as an intermediary component between the user/device and external systems. This SE acts as a trusted mediator that handles authentication, key management, and secure data storage, mediating all security-sensitive operations without exposing the main device environment to direct access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If employees use multiple applications on mobile devices to access business information, then productivity is improved, but complexity of device configuration and management increases

Engineering Contradiction:
Improveaccess to business informationVSAvoidconfiguration requirements
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The secure element provides universal security services that work across multiple applications and devices. By implementing standardized security functions (authentication, encryption, key management) in the SE, the system achieves multi-functionality without requiring separate configuration for each application or device type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The secure element autonomously manages security operations including key generation, storage, and authentication processes. This self-service capability eliminates the need for complex manual configuration and ongoing management of security settings across multiple devices and applications.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If data is stored on mobile devices in unsecured environments, then ease of access is improved, but risk of data loss or misuse increases

Engineering Contradiction:
Improveaccess to dataVSAvoiddata loss or misuse
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The secure element serves as an intermediary that enables easy data access while protecting against loss or misuse. It mediates all access requests by verifying authentication credentials and controlling data release, allowing users convenient access to authorized data while blocking unauthorized access attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different security qualities to different data and operations. The secure element provides high-security protection for sensitive data (keys, credentials, proprietary information) while allowing less restrictive access for non-sensitive operations, creating localized security zones within the device.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8126506B2System and method for securely managing data stored on mobile devices, such as enterprise mobility data
Publication Date: 2012.02.28 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8126506B2 patent drawing
  • US8126506B2 patent drawing
  • US8126506B2 patent drawing

AI summary

A system and method for managing data stored on mobile devices is described. In some cases, the system stores data, such as data under enterprise mobility management, within a secured memory location of a SIM card. In some cases, the system may request validation credentials before providing access to data stored in secure locations. In some cases, the system may review an access policy and request validation based on instructions from the access policy.