UICC Secure Element Mutual Authentication for Wireless Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication devices lack secure communication protocols that effectively authenticate and encrypt data between devices, particularly due to the security disparities between the universal integrated circuit card (UICC) and the device processor, leading to vulnerabilities in data transmission.

Innovation Solution

A system and method utilizing a secure services platform with a secure element (UICC), a secure device processor, and a device processor, where mutual authentication and encryption keysets are used to establish a secure communication channel, ensuring secure communication between devices through a management server and secure application server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software applications are used on the device processor to provide security functions, then the device can perform authentication and encryption operations, but the security level remains vulnerable due to the processor's inherent insecurity

Engineering Contradiction:
Improvesecurity levelVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure element as an intermediary component between the device processor and the authentication/encryption operations. The secure element contains a secure processor that executes security-critical code and stores cryptographic keys, acting as a mediator that isolates the insecure device processor from direct access to security-sensitive resources. This resolves the contradiction by maintaining security functions while eliminating the vulnerability of running them on the insecure processor.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the device architecture into two distinct parts: an insecure device processor for general-purpose computing and a secure element with its own secure processor for security-critical operations. This segmentation allows the system to leverage the processing power of the device processor while isolating security functions in a protected environment, thereby improving reliability without exposing the entire system to processor vulnerabilities.

Inventive Principle:
Principle #1Segmentation

2Power

If the device processor stores and executes security applications, then processing capability is available, but the UICC remains relatively unsecure

Engineering Contradiction:
Improveprocessing capabilityVSAvoidsecurity assurance
Core Design Contradiction:
PowerVSReliability

Solution Approach 1:

The secure element acts as an intermediary that provides both secure storage and secure processing capabilities. It contains a secure processor that can execute authentication and encryption algorithms, while the device processor handles non-critical processing tasks. This intermediary architecture ensures that processing capability is maintained while security assurance is improved by isolating critical operations in the protected secure element environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies local quality by providing different processing capabilities to different parts of the system. The device processor offers high processing power for general tasks, while the secure element provides specialized secure processing for cryptographic operations. This localized specialization allows each component to operate at its optimal security and performance level, resolving the contradiction between processing capability and security assurance.

Inventive Principle:
Principle #3Local quality

3Reliability

If mutual authentication and encryption keysets are implemented between UICC and device processor, then end-to-end security is achieved, but system complexity increases

Engineering Contradiction:
Improveend-to-end securityVSAvoidauthentication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure element performs self-service by autonomously managing authentication and key generation operations. It contains the authentication management function that can independently authenticate the device processor and generate encryption keys without requiring external intervention. This self-service capability simplifies the overall system architecture by eliminating the need for complex external authentication protocols, thereby achieving end-to-end security while reducing system complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The secure element serves as an intermediary that simplifies authentication by centralizing security management functions. Instead of implementing complex mutual authentication between multiple components, the secure element acts as a single point of trust that can authenticate the device processor and establish encryption keys. This intermediary approach reduces protocol complexity while maintaining end-to-end security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11368844B2System and methods for UICC-based secure communication
Publication Date: 2022.06.21 AT&T INTELLECTUAL PROPERTY I L P
  • US11368844B2 patent drawing
  • US11368844B2 patent drawing
  • US11368844B2 patent drawing

AI summary

A system that incorporates the subject disclosure may include, for example, instructions which when executed cause a device processor to perform operations comprising sending a service request to a remote management server; receiving from the management server an authentication management function and an encryption key generator for execution by a secure element and an encryption engine for execution by a secure device processor, sending a request to establish a communication session with a remote device; and communicating with the remote device via a channel established using an application server. The secure element and the secure device processor authenticate each other using a mutual authentication keyset. The secure element, the secure device processor and the device processor each have a security level associated therewith; the security level associated with the secure device processor is intermediate between that of the secure element and that of the device processor. Other embodiments are disclosed.