Subscriber Identity Locking via Server Password

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing subscriber identity modules (SIMs) do not effectively protect user information from unauthorized access, particularly if the SIM is lost or stolen, allowing potential identity theft and unauthorized use.

Innovation Solution

A method where a user device sends a request to a server to generate a password for the subscriber identity, which is then used to lock the SIM, and the password is stored in a database protected by a local password, preventing unauthorized access even if the device is lost or stolen.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a SIM card is made transferable between devices for convenience, then ease of operation is improved, but security and protection of user information deteriorates

Engineering Contradiction:
ImproveSIM transferabilityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the authentication process into multiple components: device identification, SIM identification, and password verification. This segmentation allows the SIM to be transferable while maintaining security through multi-factor authentication, as the SIM alone is insufficient without the correct password and device ID match.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The server acts as an intermediary between the user device and the network, mediating the authentication process. The server verifies the password, device ID, and SIM ID before granting network access, preventing unauthorized use even if the SIM is physically transferred to another device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If password protection is implemented for SIM cards, then security is improved, but device complexity and ease of operation worsen

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service authentication where the user independently manages their own password through the management software. The automatic password generation and verification processes reduce the need for complex manual security configurations, simplifying the user experience while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The password protection mechanism is integrated into the existing SIM card infrastructure and network authentication processes. The same authentication framework handles both traditional SIM authentication and the new password-protected authentication, avoiding the need for separate complex security systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If a SIM card is lost or stolen, then loss of information occurs, but the ability to prevent unauthorized access deteriorates

Engineering Contradiction:
Improveprivate information protectionVSAvoidunauthorized access prevention
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system applies preliminary anti-action by implementing password protection and device binding before any potential loss or theft occurs. The password is pre-configured and required for authentication, so even if the SIM is lost or stolen, the unauthorized user cannot access the network or extract information without the correct password and device ID.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The management software performs preliminary actions by automatically generating and securing the password, and by binding the SIM to the specific device ID before any security incident can occur. This preliminary setup ensures that the SIM becomes useless without the corresponding device and password combination.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11647017B2Subscriber identity management
Publication Date: 2023.05.09 CITRIX SYSTEMS INC
  • US11647017B2 patent drawing
  • US11647017B2 patent drawing
  • US11647017B2 patent drawing

AI summary

Methods and systems for management of subscriber identities associated with user devices are described herein. The user device may enroll the user device to a server and lock a subscriber identity associated with the device by setting a password on the subscriber identity. If a credential entered by a user is verified, the subscriber identity associated with the device may be unlocked. Alternatively, the user device may retrieve one or more identities associated with the user, the user device and/or the subscriber identity. A server may register the one or more identities with a database. If the user device sends a request to connect to the network, the server may verify the one or more identities retrieved by the user device to determine whether to grant access from the user device to the network.