UICC Session Control via IMEI Attribute Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration circuit card (UICC) cannot distinguish between communication sessions with a handset and external devices, leading to potential unauthorized access and security risks, as it cannot determine the origin of Application Protocol Data Units (APDUs), which may result in malicious applications accessing personal data or compromising UICC operability.

Innovation Solution

Implementing a method where the UICC retrieves and compares attributes such as International Mobile Equipment Identity (IMEI) and terminal profiles between the handset and external devices to differentiate communication sessions, limiting access rights and using a secret protocol for secure APDU communication, and returning invalid data for unauthorized PIN verification attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the UICC allows communication with external devices through the handset, then connectivity and functionality are improved, but security and unauthorized access risks increase

Engineering Contradiction:
ImproveconnectivityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The handset acts as an intermediary between the UICC and external devices. The system distinguishes between APDUs originating from the handset versus external devices, allowing the handset to mediate and control access. This intermediary mechanism enables connectivity while maintaining security by verifying the source of each APDU before processing it.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The communication channel is segmented into two distinct types: APDUs from the handset and APDUs from external devices. The UICC processes these segments differently, applying appropriate access rights and security measures to each source, thereby enabling versatile connectivity while preventing unauthorized access.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the UICC responds to all APDU requests without distinguishing sources, then operational simplicity is maintained, but security and data protection are compromised

Engineering Contradiction:
Improveoperational simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Different quality levels of access are applied locally to different APDU sources. Handset-originated APDUs receive full access rights, while external device APDUs receive restricted access rights. This local differentiation maintains operational simplicity for trusted sources while enhancing security for external sources without complicating the overall system.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If the UICC allows external applications to access personal data, then functionality and service capabilities are enhanced, but data protection and privacy are compromised

Engineering Contradiction:
ImprovefunctionalityVSAvoiddata protection
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies partial action by granting only specific, limited access rights to external devices rather than full access. External devices can access personal data only for specific purposes and under controlled conditions, preventing excessive action that would compromise data protection while still enabling necessary functionality.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9143922B2Method and system for controlling communication between an UICC and an external application
Publication Date: 2015.09.22 STMICROELECTRONICS INT NV
  • US9143922B2 patent drawing
  • US9143922B2 patent drawing
  • US9143922B2 patent drawing

AI summary

A method may be for controlling communication between a UICC, a handset including the UICC, and an external device associated with an external application running outside the handset. The method may include switching on the UICC by the handset, executing a first initialization procedure by the handset to establish a first communication session between the handset and the UICC, establishing a second communication session between the UICC and the external device, and executing a second initialization procedure between the external device and the UICC. The method may include retrieving an attribute of the handset by the UICC after completing the first initialization procedure, retrieving an attribute of the external device via the handset by the UICC after the completing the second initialization procedure, and comparing the attribute of the handset with the attribute of the external device to distinguish the second communication session from the first communication session.