UICC-Based Secure Device Update Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Devices that rely on stored software/firmware face challenges in updating components in a timely and secure manner, as existing methods are often expensive and time-consuming.

Innovation Solution

The use of a Universal Integrated Circuit Card (UICC) facilitates secure, cost-effective, and timely device updates by providing a Trusted Execution Environment and partitioning security domains between telecommunications carriers and manufacturers, enabling secure software and firmware updates without proprietary communication requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional secure update methods are used, then security is maintained, but cost and time increase

Engineering Contradiction:
ImprovesecurityVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The UICC card is designed to perform multiple functions including secure element operations, authentication, and update verification. By making the UICC multi-functional, the system achieves secure updates without requiring separate dedicated hardware modules, thereby reducing both cost and time while maintaining security requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional secure update methods are used, then security is maintained, but cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges the security functions with the existing UICC card that is already present in the device for telecommunications purposes. By combining secure element operations, authentication, and update verification into the existing UICC infrastructure, the system eliminates the need for additional dedicated security hardware modules, thereby reducing manufacturing costs while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If existing update methods are used, then updates can be performed, but they are expensive and time-consuming

Engineering Contradiction:
Improveupdate efficiencyVSAvoidupdate time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring the UICC with necessary security credentials and update verification capabilities during device manufacturing or initial setup. This preliminary configuration enables rapid secure updates later without requiring time-consuming authentication setups or additional hardware initialization, thereby improving update efficiency and reducing update time

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11216267B2Facilitating use of a universal integrated circuit card (UICC) for secure device updates
Publication Date: 2022.01.04 AT&T INTELLECTUAL PROPERTY I L P
  • US11216267B2 patent drawing
  • US11216267B2 patent drawing
  • US11216267B2 patent drawing

AI summary

Apparatus, methods and systems facilitating communications via a mobile internet-enabled connection interface are provided. One apparatus is configured to perform various operations, including performing a first type of security function associated with determining whether an information package is authorized to be received and downloaded to a device other than the apparatus, wherein the information package is associated with updating a functionality of the device; and performing a second type of security function associated with identifying an authorized user of the apparatus.