Trusted Security Zone Mobile Device Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile communication devices that are rooted or manipulated unauthorizedly can deceive networks, leading to unauthorized service usage and asset migration, which results in financial losses for carriers and undermines network security.

Innovation Solution

A system and method that verifies the integrity and identity of mobile communication devices using an Open Mobile Alliance (OMA) Device Management (DM) payload and a trusted security zone, with a toggle key controlling provisioning, ensuring that only authorized devices are activated and provisioned, thereby preventing unauthorized access and maintaining security keys confidential to individual carriers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If device provisioning is enabled without verification, then ease of operation is improved, but network security deteriorates due to unauthorized access

Engineering Contradiction:
Improveease of device provisioningVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by performing integrity verification of the OMA DM payload and verification of device identification before allowing provisioning to occur. The verification application checks the toggle key state and compares security keys in advance, ensuring that only authorized devices can be provisioned. This preliminary verification prevents unauthorized provisioning while maintaining smooth operation for authorized devices.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security verification is implemented, then network security is improved, but device complexity increases due to additional verification applications and keys

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification application serves multiple functions within a single integrated component: it verifies the integrity of the OMA DM payload, verifies device identification, checks the toggle key state, and compares security keys. By consolidating these multiple verification functions into one application, the patent reduces overall device complexity while maintaining comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The trusted security zone acts as an intermediary that houses the verification application and secure storage of critical keys. This intermediary structure isolates security-critical operations from the main device functionality, allowing verification to occur without exposing sensitive data throughout the entire device. The toggle key serves as an intermediary mechanism that controls provisioning access based on verification results.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If toggle key control is implemented, then unauthorized provisioning is prevented, but ease of operation deteriorates due to additional control mechanisms

Engineering Contradiction:
Improveprevention of unauthorized provisioningVSAvoidease of device provisioning
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The verification application performs self-service by automatically checking the toggle key state and verifying device credentials without requiring user intervention. The system autonomously determines whether provisioning should be allowed based on the verification results, eliminating the need for users to manually configure security settings while maintaining strong protection against unauthorized access.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9226145B1Verification of mobile device integrity during activation
Publication Date: 2015.12.29 T MOBILE INNOVATIONS LLC
  • US9226145B1 patent drawing
  • US9226145B1 patent drawing
  • US9226145B1 patent drawing

AI summary

A mobile communication device. The mobile communication device comprises a verification application, when executed by a trusted security zone portion of the processor, examines an integrity of a preloaded open mobile alliance (OMA) device management (DM) payload, wherein a security key in the OMA DM payload is compared with a security key stored in the trusted security zone to determine the integrity of the OMA DM payload and to determine the state of a preloaded first operating system from a first network. The verification application further verifies the identification of the mobile communication device, transmits information comprising the security key in the trusted security zone to a server to verify network provisioning of the mobile communication device, and changes the toggle key based on the verification results, whereby asset migration between network carriers is achieved and unauthorized activities are avoided while security keys are kept confidential to individual carriers.