Smart Card Remote Key Provisioning via Secure Multiparty Computation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices and connected objects with embedded UICC cards face challenges in changing telecommunication network operators without physical access to the cards, leading to costly or impossible reconfiguration, especially for devices like sensors and vehicles.

Innovation Solution

A method using secure multiparty computation protocols allows smart cards to establish a secure session with application servers to agree on and compute new authentication keys, enabling remote reconfiguration of credentials and operator changes without revealing or transmitting the old authentication key, ensuring secure and flexible operator switching.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If UICC cards are physically personalized and welded inside devices at manufacturing stage, then security and trust in stored secrets are strengthened, but reconfiguration for changing telecommunication network operators becomes impossible or too costly

Engineering Contradiction:
Improvesecurity and trust in stored secretsVSAvoidreconfiguration for changing operators
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static, immutable authentication key into a dynamic credential system. The smart card can now remotely update its authentication key through secure multiparty computation protocols, allowing the device to adapt to different telecommunication network operators while maintaining security. The credential becomes flexible and changeable without physical access or device opening.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces the mechanical/physical personalization process (requiring physical access to the smart card for key replacement) with a cryptographic/computational system. Secure multiparty computation protocols enable remote key agreement between the smart card, first application server, and second application server, eliminating the need for physical card access or replacement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual replacement of UICC card is required for operator changes, then security is maintained through physical control, but ease of operation and cost-effectiveness deteriorate

Engineering Contradiction:
Improvesecurity through physical controlVSAvoidease of operator switching
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The smart card performs self-updating of its authentication key through the secure multiparty computation protocol. The card autonomously negotiates with the application servers, computes the new key, and replaces its own credential without requiring external physical intervention or manual card replacement by the user or operator.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces cryptographic protocols as intermediaries between the smart card and application servers. The secure multiparty computation protocol acts as a mediator that enables secure key agreement and transmission without requiring physical card access, thus maintaining security while enabling easy remote operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If authentication key is transmitted over air interface, then remote provisioning becomes possible, but security is compromised due to potential interception

Engineering Contradiction:
Improveremote provisioning capabilityVSAvoidsecurity risk from air interface transmission
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent converts the potential security vulnerability of air interface transmission into a benefit by using secure multiparty computation protocols. These protocols are designed to be secure even over insecure channels, transforming the untrusted air interface into a safe communication medium for key provisioning. The computational security replaces physical security requirements.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentEP2712222B1Confidential provisioning of secret keys over the air
Publication Date: 2020.04.01 ALCATEL LUCENT SA
  • EP2712222B1 patent drawingFigure 1
  • EP2712222B1 patent drawingFigure 2

AI summary

For personalizing a smart card (SC) coupled with a communication device (CD) of a user being a subscriber of a first telecommunication network (TN1) and wishing to become a subscriber of a second telecommunication network (TN2), a first authentication key (AK_1) being stored in the smart card (SC) and in an first application server (AS1) included in the first telecommunication network, the smart card: establishes a secure session with a second application server (AS2) included in the second telecommunication network (TN2) via the first telecommunication network, negotiates with the first application server (AS1) and the second application server in order that the smart card (SC) and the second application server agree on an second authentication key (AK_2), by exchanging messages referring to shared values and shared functions by means of a secure multiparty computation protocol involving the smart card, the first application server and the second application server, and computing the second authentication key (AK_2) depending on at least a shared value and a shared function, replaces the first authentication key by the second authentication key.