Secure Server Communication via SIM-Based Key Bootstrapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing security methods are inadequate for ensuring secure communication between servers, as they either require user involvement, rely on computationally heavy PKI solutions, or restrict processing capabilities, and lack user control over key management and verification.

Innovation Solution

A bootstrapping protocol using a Subscriber Identity Module (SIM) to generate a shared key for secure server-to-server communication, based on a context associated with the user terminal, allowing key management decoupling from the infrastructure provider and enabling verification of key usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional PKI solutions are used for key management in cloud computing, then security can be provided, but computational overhead increases and user control over key management is lost

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts key management functionality from the cloud infrastructure provider and relocates it to the user's SIM card. The SIM card generates and stores encryption keys locally, eliminating the need for users to rely on the cloud provider's PKI infrastructure. This extraction resolves the contradiction by providing security through user-controlled key management while avoiding the computational overhead of traditional PKI solutions in the cloud environment.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The SIM card acts as an intermediary between the user and the cloud infrastructure, managing encryption keys locally. Instead of direct key management between user and cloud provider (which creates dependency and computational burden), the SIM card mediates this relationship by generating keys locally and enabling secure communication without requiring heavy PKI operations in the cloud.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data are encrypted locally before cloud storage, then security is improved, but processing capabilities in the cloud are restricted

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing capabilities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security function from the processing function. Encryption/decryption operations are performed locally by the SIM card, while computation and data processing are performed in the cloud. This segmentation allows both security and processing capabilities to coexist without conflict, as each operates in its designated domain.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The SIM card provides self-service by generating and managing encryption keys locally without requiring cloud infrastructure involvement. This enables security operations to be performed independently of cloud processing capabilities, allowing the cloud to focus on computation while the SIM card handles cryptographic operations.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If cloud providers manage keys centrally, then key distribution is simplified, but user control and verification of key usage are lost

Engineering Contradiction:
Improvekey distributionVSAvoiduser control over key management
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent inverts the traditional key management model by shifting control from the cloud provider to the user's SIM card. Instead of the cloud provider distributing and managing keys centrally (which simplifies their operations but removes user control), the SIM card generates and retains control of keys, with the cloud infrastructure merely receiving encrypted data. This inversion resolves the contradiction by prioritizing user control while maintaining operational simplicity through automated local key generation.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP2767029B1Secure communication
Publication Date: 2015.07.01 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2767029B1 patent drawingFigure 1
  • EP2767029B1 patent drawingFigure 2
  • EP2767029B1 patent drawingFigure 3

AI summary

A method comprising the use of a bootstrapping protocol to define a security relationship between a first server and a second server, the first and second servers co-operating to provide a service to a user terminal. A bootstrapping protocol is used to generate a shared key for securing communication between the first server and the second server. The shared key is based on a context of the bootstrapping protocol, and the context is associated with a Subscriber Identity Module (SIM) associated with the user terminal and provides a base for the shared key. A method of the invention may, for example, be employed within a computing/service network such as a "cloud", and in particular for communications between two servers in the cloud that are co-operating to provide a service to a user.