Trusted Execution Environment Initialization via SIM Operator Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Trusted Execution Environment (TEE) key management schemes require pre-binding to a specific operator, limiting their use in open markets and preventing seamless operator changes, which adversely affects user experience.
Innovation Solution
A TEE initialization method that utilizes a Subscriber Identity Module (SIM) card to acquire an operator identifier, match it with a list of operator identifiers and public keys, authenticate the Trusted Service Management (TSM) platform, and download a management key, allowing the TEE to operate without pre-designated operator binding.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If keys are stored in the TEE and bound to a specific operator during production, then security management is simplified, but the mobile terminal cannot be used in open markets and operator changes are prevented
Solution Approach 1:
The patent applies preliminary action by pre-writing multiple operator identifiers and their corresponding public keys into the TEE during terminal production, rather than binding to a single operator. This allows the TEE to later authenticate with any operator in the list, resolving the contradiction between security simplification and operator flexibility.
Solution Approach 2:
The TEE is designed with universal functionality by storing multiple operator identifiers and public keys, enabling it to work with any operator from a predefined list. This multi-functionality approach allows the same TEE to serve multiple operators without reconfiguration, achieving both security and adaptability.
2Ease of manufacture
If the TEE is bound to a particular operator in advance, then key management is simplified, but user experience deteriorates when operator changes are needed
Solution Approach 1:
The patent implements dynamics by making the operator binding flexible rather than fixed. The TEE dynamically selects and authenticates with operators from a predefined list based on the SIM card's operator identifier, allowing operator changes without terminal reconfiguration while maintaining simplified key management through pre-configured public keys.
Solution Approach 2:
The patent introduces the SIM card as an intermediary that carries the operator identifier, which the TEE uses to select the appropriate public key from its stored list. This intermediary mechanism simplifies key management by automating the selection process while enabling seamless operator changes.
3Adaptability or versatility
If multiple operator identifiers and public keys are stored in the TEE, then operator flexibility is improved, but device complexity increases
Solution Approach 1:
The TEE performs self-service by automatically selecting the appropriate public key from its stored list based on the operator identifier obtained from the SIM card. This self-service mechanism eliminates the need for manual configuration or complex key management interfaces, reducing perceived device complexity while maintaining high operator flexibility.
Solution Approach 2:
The system uses feedback from the SIM card's operator identifier to automatically select the corresponding public key from the TEE's stored list. This feedback mechanism ensures the correct key is used without user intervention, managing the complexity of multiple keys through automated key selection based on operator identification.
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
The present disclosure provides a TEE initialization method. An operator identifier acquired from an SIM card is compared with operator identifiers in a list or a table of correspondence between the operator identifiers and public keys preset in a TEE of a mobile terminal, so as to acquire a public key and authenticate a TSM platform with the public key. After the TSM platform has been authenticated successfully, loading processing on the TEE is completed, and a management key of the TEE is downloaded from the TSM platform. According to the present disclosure, it is able to initialize the TEE of the mobile terminal without designating an operator, thereby to improve the openness of the mobile terminal as well as the user experience.