Smart Card Remote Key Personalization via Secure Session

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices and equipment, such as sensors and vending machines, face challenges in easily changing mobile network operators due to the costly and impractical process of physically replacing Universal Integrated Circuit Cards (UICC) with new authentication keys, which compromises security and convenience.

Innovation Solution

A method for remotely reconfiguring UICC cards by establishing a secure session between the smart card, application server, and personalization server, allowing for the negotiation and replacement of authentication keys without physical intervention, enabling seamless switching between telecommunication network operators while maintaining confidentiality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical replacement of UICC card is used to change mobile network operator, then authentication key confidentiality is maintained, but device complexity and operational cost increase significantly

Engineering Contradiction:
Improveauthentication key confidentialityVSAvoiddifficulty to access device
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical/physical system of UICC card replacement with a remote digital personalization system. The smart card personalization server enables authentication key changes through wireless communication protocols, eliminating the need for physical card extraction, replacement, and reinsertion. This substitution maintains security while dramatically improving ease of operation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a smart card personalization server as an intermediary between the user and the authentication key management system. This server handles the secure generation, transmission, and installation of new authentication keys remotely, acting as a trusted mediator that eliminates the need for direct physical access to the device while maintaining confidentiality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual UICC card replacement is implemented, then authentication security is preserved, but time consumption and operational efficiency deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidtime for card replacement
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-generating authentication keys and personalization data on the smart card personalization server before they are needed. When a key change is requested, the system has already prepared the necessary credentials, enabling instantaneous remote deployment without time-consuming manual procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the time-consuming manual mechanical process of card replacement with an automated digital personalization system that can deploy new authentication keys remotely and instantly, eliminating the time loss associated with physical card handling.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If authentication keys are transmitted over the air, then ease of reconfiguration improves, but risk of key interception increases

Engineering Contradiction:
Improveremote reconfiguration capabilityVSAvoidrisk of authentication key interception
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication key transmission from the public wireless communication channel by performing the key generation and exchange process within the secure environment of the smart card personalization server. The keys are generated locally on the server and never exposed to the air interface, eliminating interception risks while maintaining remote reconfiguration capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The smart card personalization server acts as a secure intermediary that handles all authentication key operations within a protected environment. It mediates between the secure element and the external world, ensuring that keys never leave the secure boundary through vulnerable wireless channels, thus preventing interception while enabling remote access.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If smart cards are embedded in devices for security reasons, then device security improves, but ease of card replacement deteriorates

Engineering Contradiction:
Improvedevice securityVSAvoiddifficulty to replace card
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical card replacement system with a remote digital personalization system. This allows embedded smart cards to be reconfigured without physical access, maintaining the security benefits of embedding while eliminating the operational difficulties of replacement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service remote personalization where the smart card can be reconfigured through automated procedures initiated by the user or network operator, without requiring physical access to the device or intervention by service personnel.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9923716B2Smart card personnalization with local generation of keys
Publication Date: 2018.03.20 ALCATEL LUCENT SA
  • US9923716B2 patent drawing
  • US9923716B2 patent drawing
  • US9923716B2 patent drawing

AI summary

For personalizing a smart card (SC) coupled with a communication device (CD) of a user being a subscriber of a first telecommunication network (TN1) and wishing to become a subscriber of a second telecommunication network (TN2), a first international identity (IMSI_1) and a first authentication key (AK_1) being stored in the smart card (SC), the smart card receives a message (MesP) from an application server (AS) connected to the first telecommunication network and the second telecommunication network, the message (MesN) comprising a personalization command (ComP) and an admin code (ACas), after that the application server has received a request (Req) of subscription change comprising an identifier (1dMNO2) of the second telecommunication network (TN2) and has established a secured session with a personalization server (PS) of the second telecommunication network (TN2) identified by the identifier (1dMNO2), and interprets the personalization command (ComP) to establish a secure session with the personalization server (PS) via the application server (AS), if the admin code (ACas) is valid. The smart card negotiates with the personalization server to agree on an second authentication key, by exchanging messages containing values derived from random secrets, receives a message (Mes3) containing an second international identity (IMSI_2) from the personalization server (PS), and replaces the first international identity (IMSI_1) and the first authentication key (AK_1) by the second international identity and the second authentication key.