Terminal Network Locking via IMSI and PLMN Hash Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network locking solutions for terminals are insecure due to simple SIM card verification methods that can be easily cheated by hackers using fake PLMN numbers or cracked unlocking codes, leading to low security.
Innovation Solution
A network locking method and apparatus that utilizes the International Mobile Subscriber Identity (IMSI) number on a SIM card to register with the network and verify the Public Land Mobile Network (PLMN) number, ensuring secure usage by comparing the network PLMN number with a pre-stored valid segment, and includes security verification through hashing and digital certificates to prevent tampering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a simple SIM card verification method is used (comparing PLMN number with pre-stored value), then the device complexity is reduced and ease of operation is improved, but the security and reliability of network locking deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-calculating and storing Hash values of valid PLMN numbers in the terminal before actual verification. When a SIM card is inserted, the terminal reads the PLMN number, calculates its Hash value, and compares it with the pre-stored Hash values. This preliminary preparation of Hash values enables fast and secure verification without requiring complex real-time computation during the verification process itself.
Solution Approach 2:
The patent replaces the simple mechanical comparison of PLMN numbers with a cryptographic Hash-based verification system. Instead of directly comparing plaintext PLMN numbers, the system transforms them into Hash values using cryptographic algorithms (MD5, SHA-1, or SHA-256). This substitution provides strong security guarantees while maintaining operational simplicity, as the Hash comparison process remains computationally efficient.
2Reliability
If an unlocking code verification method is used, then the network locking security is improved, but the ease of operation deteriorates and the system becomes more vulnerable to cracking
Solution Approach 1:
The patent replaces the vulnerable unlocking code mechanism with a cryptographic Hash-based verification system. Instead of storing and verifying plaintext unlocking codes that can be cracked, the system stores Hash values of PLMN numbers and uses cryptographic algorithms to verify SIM card authenticity. This substitution eliminates the security vulnerability of crackable unlocking codes while maintaining operational simplicity through automated Hash comparison.
Solution Approach 2:
The patent creates cryptographic copies (Hash values) of the original PLMN numbers and stores these copies in the terminal. These Hash copies serve as secure references for verification without exposing the original sensitive data. The system verifies SIM cards by comparing Hash copies rather than requiring users to manually input unlocking codes, thereby improving both security and ease of operation.
3Speed
If the terminal stores valid PLMN number segments in Flash memory, then the verification speed is improved, but the loss of information increases if the Flash is tampered with
Solution Approach 1:
The patent replaces the storage of plaintext PLMN number segments with storage of cryptographic Hash values. This substitution ensures that even if the Flash memory is tampered with, the integrity can be verified through Hash comparison. The terminal stores Hash values of valid PLMN numbers in Flash memory, enabling fast verification while protecting against information loss or corruption, as any tampering would result in Hash value mismatches.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present invention provide a network locking method and apparatus for a terminal. The method mainly includes: utilizing an IMSI number carried on a SIM card of the terminal to register the SIM card with a network, and obtaining a PLMN number of the network; comparing a PLMN number segment of the network with a valid PLMN number segment pre-stored on the terminal, and allowing or limiting, according to a comparison result, use of the SIM card by the terminal. According to the embodiments of the present invention, the SIM card is registered with the network by utilizing the IMSI number carried on the SIM card and a data card is verified in the terminal and network combined verification manner, which may avoid a situation that a hacker sets a fake PLMN in a manner of a card sticker and the like to cheat SIM card verification, and ensure security of network locking for the terminal.