UIM OS Identifier and Cloud Authentication for Identity Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile terminals, the separation of information related to the communication circuit and sensitive data stored in the cloud is not effectively verified, leading to potential identity mismatch issues, especially when UIMs are arbitrarily replaced or shared among users, making it difficult to track improper processing, particularly for high-value or medical transactions.

Innovation Solution

The UIM application includes an OS identifier that verifies the operating system accessing the UIM, a determiner that compares authentication data stored locally with data on a cloud server, and a permitter that controls access based on identity matching, ensuring that only authorized users can perform secure processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the UIM is arbitrarily replaced or shared among users, then the ease of operation is improved, but the reliability of identity matching deteriorates

Engineering Contradiction:
Improveease of UIM replacementVSAvoidreliability of identity matching
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication by comparing authentication data stored in the UIM with authentication data stored in the cloud server before allowing access to sensitive data. This preliminary verification ensures that even if UIMs are replaced or shared, only authorized users can access their own sensitive data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where the result of authentication data comparison determines whether access to sensitive data is permitted. The cloud server verifies the authenticity of the UIM holder and provides feedback on whether the identity matching is successful, thereby controlling access based on verified identity.

Inventive Principle:
Principle #23Feedback

2Device complexity

If authentication data is stored only locally in the UIM, then the device complexity is reduced, but the reliability of identity verification deteriorates

Engineering Contradiction:
Improvecomplexity of authentication systemVSAvoidreliability of identity verification
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The cloud server acts as an intermediary that stores authentication data and performs verification. Instead of storing all authentication data locally in the UIM or requiring complex local verification systems, the cloud server serves as a centralized mediator that compares authentication data and verifies identity, simplifying the local device while maintaining high reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If the secure OS acquires sensitive data from a cloud server, then the manufacturing precision of security protocols is improved, but the loss of information increases due to network transmission

Engineering Contradiction:
Improveprecision of security protocol implementationVSAvoidinformation loss during transmission
Core Design Contradiction:
Manufacturing precisionVSLoss of information

Solution Approach 1:

The system extracts and compares only the necessary authentication data between the UIM and the cloud server, rather than transmitting or storing all sensitive data locally. This selective extraction minimizes information loss during transmission while maintaining the precision of security verification by focusing only on the essential authentication elements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9723483B2Mobile electronic device
Publication Date: 2017.08.01 KK TOSHIBA
  • US9723483B2 patent drawing
  • US9723483B2 patent drawing
  • US9723483B2 patent drawing

AI summary

A mobile electronic device according to an embodiment has an identifier, a determiner, and a permitter. The identifier identifies the operating system of a mobile terminal to which its own device is connected and determines whether the identified operating system is a prescribed operating system. If the identifier determines that the identified operating system is the prescribed operating system, the determiner performs processing to determine whether or not authentication data held in its own device and authentication data held in an authentication data holding device that can communicate via a network match. If the determiner determines that there is a match, the permitter permits data processing using processing data held in a processing data holding device that can communicate via the network.