Trusted Execution Environment Initialization via SIM Operator Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Trusted Execution Environment (TEE) key management schemes require pre-binding to a specific operator, limiting their use in open markets and preventing seamless operator changes, which adversely affects user experience.

Innovation Solution

A TEE initialization method that utilizes a Subscriber Identity Module (SIM) card to acquire an operator identifier, match it with a list of operator identifiers and public keys, authenticate the Trusted Service Management (TSM) platform, and download a management key, allowing the TEE to operate without pre-designated operator binding.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If keys are stored in the TEE and bound to a specific operator during production, then security management is simplified, but the mobile terminal cannot be used in open markets and operator changes are prevented

Engineering Contradiction:
Improvesecurity managementVSAvoidoperator binding flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-writing multiple operator identifiers and their corresponding public keys into the TEE during terminal production, rather than binding to a single operator. This allows the TEE to later authenticate with any operator in the list, resolving the contradiction between security simplification and operator flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The TEE is designed with universal functionality by storing multiple operator identifiers and public keys, enabling it to work with any operator from a predefined list. This multi-functionality approach allows the same TEE to serve multiple operators without reconfiguration, achieving both security and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If the TEE is bound to a particular operator in advance, then key management is simplified, but user experience deteriorates when operator changes are needed

Engineering Contradiction:
Improvekey managementVSAvoidoperator change capability
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The patent implements dynamics by making the operator binding flexible rather than fixed. The TEE dynamically selects and authenticates with operators from a predefined list based on the SIM card's operator identifier, allowing operator changes without terminal reconfiguration while maintaining simplified key management through pre-configured public keys.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces the SIM card as an intermediary that carries the operator identifier, which the TEE uses to select the appropriate public key from its stored list. This intermediary mechanism simplifies key management by automating the selection process while enabling seamless operator changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple operator identifiers and public keys are stored in the TEE, then operator flexibility is improved, but device complexity increases

Engineering Contradiction:
Improveoperator selection flexibilityVSAvoidTEE configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The TEE performs self-service by automatically selecting the appropriate public key from its stored list based on the operator identifier obtained from the SIM card. This self-service mechanism eliminates the need for manual configuration or complex key management interfaces, reducing perceived device complexity while maintaining high operator flexibility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses feedback from the SIM card's operator identifier to automatically select the corresponding public key from the TEE's stored list. This feedback mechanism ensures the correct key is used without user intervention, managing the complexity of multiple keys through automated key selection based on operator identification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3089494B1Trusted execution environment initialization method and mobile terminal
Publication Date: 2019.07.24 CHINA MOBILE COMM GRP CO LTD
  • EP3089494B1 patent drawingFigure 1~2
  • EP3089494B1 patent drawingFigure 3
  • EP3089494B1 patent drawingFigure 4~5

AI summary

The present disclosure provides a TEE initialization method. An operator identifier acquired from an SIM card is compared with operator identifiers in a list or a table of correspondence between the operator identifiers and public keys preset in a TEE of a mobile terminal, so as to acquire a public key and authenticate a TSM platform with the public key. After the TSM platform has been authenticated successfully, loading processing on the TEE is completed, and a management key of the TEE is downloaded from the TSM platform. According to the present disclosure, it is able to initialize the TEE of the mobile terminal without designating an operator, thereby to improve the openness of the mobile terminal as well as the user experience.