UE Hardware Attestation Using Symmetric-Key Check Values
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication technologies lack a reliable method to determine the trustworthiness of user equipment (UE) devices, as end-to-end security verification is limited to network and SIM card interactions, failing to assess the hardware integrity of the UE.
Innovation Solution
Implement a trusted attestation method using symmetric keys to process random numbers and local attestation information, comparing check values and expected values to verify the trustworthiness of UE devices, involving network elements and terminals in a communication system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If end-to-end security verification is performed between network and SIM card, then authentication and authorization are achieved, but trustworthiness of UE hardware device cannot be determined
Solution Approach 1:
The verification process is segmented into two independent parts: SIM card authentication (existing) and hardware device attestation (new). The hardware device is segmented from the SIM card, allowing separate verification of hardware trustworthiness through attestation information while maintaining the existing SIM-based authentication framework.
2Reliability
If SIM card and network side use shared key for authentication, then user authentication is achieved, but hardware integrity verification is not performed
Solution Approach 1:
Attestation information acts as an intermediary that bridges the gap between existing SIM-based authentication and hardware integrity verification. The network element uses this intermediary to indirectly verify hardware trustworthiness without disrupting the established SIM card authentication mechanism.
3Reliability
If trusted attestation is implemented using symmetric keys and check values, then hardware trustworthiness can be determined, but verification complexity increases
Solution Approach 1:
The hardware device performs attestation information generation and check value computation in advance before network verification. This preliminary action prepares all necessary verification data locally, simplifying the network element's task to merely compare received check values against computed expected values, thereby reducing overall verification complexity.
Data Source
AI summary
A first network element receives first attestation information from a terminal. The first network element obtains a first trusted attestation result of the terminal based on the first attestation information and first expected information.


