UICC Device Authorization Logic for Theft Deterrence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized use of Universal Integrated Circuit Cards (UICC) in wireless terminals poses a security risk, as they can be easily transferred between devices, leading to unintended usage and additional costs for service providers.

Innovation Solution

Implementing a mechanism within the UICC to restrict operation to specific devices by using logic embedded in its memory to verify attributes from the terminal, ensuring registration only occurs if the device meets predefined rules, thereby preventing unauthorized use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the UICC is made universally compatible with any wireless terminal, then ease of operation and adaptability are improved, but security and control over service usage deteriorate

Engineering Contradiction:
ImproveUICC compatibility with different terminalsVSAvoidSecurity control over service usage
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by implementing device-specific attributes and rules within the UICC that are tailored to each authorized terminal. The UICC contains device attributes (such as device ID, terminal type) and rule sets that are locally stored and evaluated, allowing the same UICC to adapt its behavior based on the specific terminal it is inserted into, rather than being universally compatible or strictly locked to one device

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent utilizes parameter changes by dynamically evaluating terminal attributes against stored rules and changing the operational state of the UICC accordingly. The system changes parameters such as network registration status, service access permissions, and operational mode based on whether the terminal attributes satisfy the predefined rules, allowing flexible control over UICC functionality

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the UICC is restricted to specific devices only, then security and service control are improved, but adaptability and ease of operation deteriorate

Engineering Contradiction:
ImproveSecurity control over service usageVSAvoidUICC compatibility with different terminals
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making the UICC's operational state changeable based on real-time evaluation of terminal attributes. Rather than being statically locked to one device, the UICC dynamically assesses whether the current terminal satisfies the authorized device rules and adjusts its functionality accordingly, enabling both security control and flexibility across multiple authorized terminals

Inventive Principle:
Principle #15Dynamics

3Reliability

If device verification rules are implemented in the UICC, then security against unauthorized use is improved, but device complexity and manufacturing difficulty increase

Engineering Contradiction:
ImproveSecurity against UICC theftVSAvoidUICC internal structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring the UICC with device attributes and rule sets during manufacturing or initial provisioning. The verification logic, terminal attributes, and authorization rules are established in advance within the UICC memory, allowing the card to perform security verification autonomously without requiring complex external validation systems, thus enhancing security while managing complexity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8639290B2UICC control over devices used to obtain service
Publication Date: 2014.01.28 AT&T INTELLECTUAL PROPERTY I L P
  • US8639290B2 patent drawing
  • US8639290B2 patent drawing
  • US8639290B2 patent drawing

AI summary

Devices and methods are disclosed by which a smart card or UICC that is removably insertable into a wireless terminal will only allow operation in either a specific terminal or a specific set of terminals. A mechanism to restrict the set of terminals that a UICC will operate with based upon logic embedded in a memory within the UICC. The UICC receives specific information from the wireless terminal when the terminal is turned on. If the information received satisfies a plurality of rules or conditions stored within the UICC, the UICC functions normally and the terminal may be registered with the network. If the UICC is inserted in an unsupported terminal, the UICC will refuse to function normally. This provides a deterrent against UICC theft.