Telecommunication Terminal Memory Segmentation for IMEI Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Old technology telecommunication devices lack effective protection against data access and fraudulent use, as their memory is easily accessible and the SIMLock mechanism is not secure due to widely known unlocking algorithms and accessible IMEI codes, allowing thieves to unlock and modify devices.
Innovation Solution
A process that decodes the operating memory using a pre-determined key, stored in secure memory, and calculates the decoding key using a unique hardware component or chip card information, ensuring only authorized access and preventing modification of lock flags or IMEI numbers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If memory is made freely accessible for read and write functions, then ease of operation is improved, but security against data access is worsened
Solution Approach 1:
The patent divides the memory into multiple segments: a first memory area that is freely accessible for normal operations, and a second memory area that is protected and requires authentication. This segmentation allows the system to maintain both ease of operation for common tasks and security for sensitive data by physically separating accessible and protected memory regions.
2Reliability
If SIMLock mechanism is implemented with known algorithms, then device locking capability is improved, but security against fraudulent use is worsened
Solution Approach 1:
The patent extracts the critical security element (IMEI code) from the freely accessible memory and stores it in the protected second memory area. By removing the IMEI code from public access and placing it in an authenticated memory section, the system maintains the locking capability while eliminating the vulnerability that allowed thieves to calculate unlock codes using easily accessible IMEI numbers.
Solution Approach 2:
The patent implements preliminary authentication checks before allowing access to the second memory area. The system requires verification of authentication data before permitting reading or writing of protected information, including the IMEI code. This preliminary action prevents fraudulent access by ensuring that only authorized users can access critical security elements before they can be misused.
3Ease of operation
If IMEI code is stored in accessible memory, then device identification functionality is improved, but security against code calculation is worsened
Solution Approach 1:
The patent extracts the IMEI code from the first freely accessible memory area and stores it in the second protected memory area. This extraction maintains the device identification functionality (as the IMEI is still stored and can be accessed by the system) while simultaneously improving security by placing the IMEI in an authenticated memory section that prevents unauthorized access and calculation of unlock codes.
4Reliability
If memory protection is implemented, then security against modification is improved, but ease of operation is worsened
Solution Approach 1:
The patent segments memory into two distinct areas with different access characteristics. The first memory area maintains full accessibility for normal operations, while the second memory area implements protection. This segmentation resolves the contradiction by ensuring that protection is applied only where necessary (sensitive data and IMEI code) while leaving the majority of memory freely accessible for ease of operation.
Solution Approach 2:
The system automatically manages memory access by implementing authentication mechanisms that transparently handle protected memory areas. Once authentication is established, the system can access protected areas without requiring continuous user intervention. This self-service approach maintains ease of operation while implementing comprehensive protection for critical data.
Data Source
AI summary
A method of protecting a telecommunication terminal having a chip-card-type personal component which is required for telecommunication network access. The terminal includes a processing unit, at least one operating memory element containing the information necessary to the operation of the terminal, i.e. a terminal operating program, and the data necessary to the program. The method involves: a) encrypting the contents of the operating memory element of the telecommunication terminal using a pre-determined key K which is necessary for decryption; and b) allowing the terminal to commence decryption once the terminal has been started with a start-up program that is saved in a secure memory element and once the key for decryption has been calculated by same.

