UE Hardware Attestation Using Symmetric-Key Check Values

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication technologies lack a reliable method to determine the trustworthiness of user equipment (UE) devices, as end-to-end security verification is limited to network and SIM card interactions, failing to assess the hardware integrity of the UE.

Innovation Solution

Implement a trusted attestation method using symmetric keys to process random numbers and local attestation information, comparing check values and expected values to verify the trustworthiness of UE devices, involving network elements and terminals in a communication system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If end-to-end security verification is performed between network and SIM card, then authentication and authorization are achieved, but trustworthiness of UE hardware device cannot be determined

Engineering Contradiction:
Improvesecurity verificationVSAvoidhardware trust assessment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The verification process is segmented into two independent parts: SIM card authentication (existing) and hardware device attestation (new). The hardware device is segmented from the SIM card, allowing separate verification of hardware trustworthiness through attestation information while maintaining the existing SIM-based authentication framework.

Inventive Principle:
Principle #1Segmentation

2Reliability

If SIM card and network side use shared key for authentication, then user authentication is achieved, but hardware integrity verification is not performed

Engineering Contradiction:
ImproveauthenticationVSAvoidhardware integrity assessment
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

Attestation information acts as an intermediary that bridges the gap between existing SIM-based authentication and hardware integrity verification. The network element uses this intermediary to indirectly verify hardware trustworthiness without disrupting the established SIM card authentication mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If trusted attestation is implemented using symmetric keys and check values, then hardware trustworthiness can be determined, but verification complexity increases

Engineering Contradiction:
Improvetrustworthiness determinationVSAvoidverification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware device performs attestation information generation and check value computation in advance before network verification. This preliminary action prepares all necessary verification data locally, simplifying the network element's task to merely compare received check values against computed expected values, thereby reducing overall verification complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250365272A1Attestation Method and Related Device Thereof
Publication Date: 2025.11.27 HUAWEI TECH CO LTD
  • US20250365272A1 patent drawing
  • US20250365272A1 patent drawing
  • US20250365272A1 patent drawing

AI summary

A first network element receives first attestation information from a terminal. The first network element obtains a first trusted attestation result of the terminal based on the first attestation information and first expected information.