USIM Parameter Update Security via SIM OTA Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current techniques fail to securely update the routing indicator and other parameters in universal subscriber identity modules (USIM) of user equipment (UE) in 5G core networks, leading to wastage of computing and networking resources due to inefficient detection and correction of malicious activities.
Innovation Solution
A SIM over-the-air (OTA) device is introduced to securely update and manage USIM information by generating encrypted parameter update requests and responses, utilizing security features to verify authenticity and reduce resource utilization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current techniques are used to exchange SUPI/SUCI between UE and network, then communication can be established, but security is insufficient and computing/resources are wasted on detecting and correcting malicious activities
Solution Approach 1:
The patent applies preliminary action by pre-establishing security associations and configuring security parameters (such as encryption algorithms and keys) in the USIM card before the device is deployed. This preliminary security setup ensures that when communication occurs, the encryption and authentication mechanisms are already in place, preventing malicious activities rather than detecting and correcting them later, thus improving security while reducing wasted computing resources.
Solution Approach 2:
The patent introduces a security intermediary mechanism through the use of a concealed identifier (SUCI) as an intermediary between the actual subscription permanent identifier (SUPI) and the network. The SUCI acts as a secure intermediary that protects the true identity during initial communication, and the mapping between SUCI and SUPI is established through pre-configured security associations, thereby enhancing security without requiring extensive real-time computing resources for identity protection.
2Reliability
If routing indicator and parameters in USIM are not securely updated, then device complexity is low, but malicious activities go undetected and resources are wasted on correction
Solution Approach 1:
The patent applies self-service by enabling the USIM card to autonomously verify the authenticity of parameter updates using pre-configured security associations. When parameter updates are received, the USIM card independently verifies their authenticity using the established security credentials, without requiring complex external verification mechanisms. This self-verification capability enhances security while maintaining relatively simple device architecture.
Solution Approach 2:
The patent uses preliminary action by pre-configuring security associations and authentication credentials in the USIM card during manufacturing or initial provisioning. These preliminary security setups enable the USIM to independently verify parameter updates later, eliminating the need for complex real-time security management infrastructure and reducing device complexity while ensuring reliable security.
3Reliability
If extensive detection and correction mechanisms are implemented, then malicious activities can be identified, but computing and networking resources are excessively consumed
Solution Approach 1:
The patent converts the potential harm of unauthorized parameter modifications into a beneficial security feature by implementing authenticity verification mechanisms. Instead of trying to detect and correct malicious activities after they occur, the system is designed to prevent unauthorized changes from taking effect in the first place by verifying the authenticity of all parameter updates against pre-configured security associations. This preventive approach transforms what would be a detection-correction problem into a simple verification process, reducing resource consumption while maintaining reliable detection capability.
Data Source
AI summary
A device may receive, from a network device, a user equipment (UE) parameter update request notification indicating an update to a UE parameter of a universal subscriber identity module (USIM), and may generate an encrypted UE parameter update request. The device may cause the encrypted UE parameter update request to be provided to the USIM to cause the USIM to update the UE parameter and to generate an encrypted UE parameter update response. The device may receive, from the network device, the encrypted UE parameter update response, and may verify an authenticity of content of the encrypted UE parameter update response based on whether the encrypted UE parameter update response is signed by the USIM. The device may provide, to the network device, a result indicating whether the UE parameter is updated and whether the authenticity of the content of the encrypted UE parameter update response is verified.


