UICC Session Control via IMEI Attribute Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration circuit card (UICC) cannot distinguish between communication sessions with a handset and external devices, leading to potential unauthorized access and security risks, as it cannot determine the origin of Application Protocol Data Units (APDUs), which may result in malicious applications accessing personal data or compromising UICC operability.
Innovation Solution
Implementing a method where the UICC retrieves and compares attributes such as International Mobile Equipment Identity (IMEI) and terminal profiles between the handset and external devices to differentiate communication sessions, limiting access rights and using a secret protocol for secure APDU communication, and returning invalid data for unauthorized PIN verification attempts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the UICC allows communication with external devices through the handset, then connectivity and functionality are improved, but security and unauthorized access risks increase
Solution Approach 1:
The handset acts as an intermediary between the UICC and external devices. The system distinguishes between APDUs originating from the handset versus external devices, allowing the handset to mediate and control access. This intermediary mechanism enables connectivity while maintaining security by verifying the source of each APDU before processing it.
Solution Approach 2:
The communication channel is segmented into two distinct types: APDUs from the handset and APDUs from external devices. The UICC processes these segments differently, applying appropriate access rights and security measures to each source, thereby enabling versatile connectivity while preventing unauthorized access.
2Ease of operation
If the UICC responds to all APDU requests without distinguishing sources, then operational simplicity is maintained, but security and data protection are compromised
Solution Approach 1:
Different quality levels of access are applied locally to different APDU sources. Handset-originated APDUs receive full access rights, while external device APDUs receive restricted access rights. This local differentiation maintains operational simplicity for trusted sources while enhancing security for external sources without complicating the overall system.
3Adaptability or versatility
If the UICC allows external applications to access personal data, then functionality and service capabilities are enhanced, but data protection and privacy are compromised
Solution Approach 1:
The system applies partial action by granting only specific, limited access rights to external devices rather than full access. External devices can access personal data only for specific purposes and under controlled conditions, preventing excessive action that would compromise data protection while still enabling necessary functionality.
Data Source
AI summary
A method may be for controlling communication between a UICC, a handset including the UICC, and an external device associated with an external application running outside the handset. The method may include switching on the UICC by the handset, executing a first initialization procedure by the handset to establish a first communication session between the handset and the UICC, establishing a second communication session between the UICC and the external device, and executing a second initialization procedure between the external device and the UICC. The method may include retrieving an attribute of the handset by the UICC after completing the first initialization procedure, retrieving an attribute of the external device via the handset by the UICC after the completing the second initialization procedure, and comparing the attribute of the handset with the attribute of the external device to distinguish the second communication session from the first communication session.


