USIM Secure Channel for V2X Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of Internet of Vehicles (IoV), the existing methods for V2X terminal identity authentication and information security interaction expose session keys to physical attacks when transmitted outside a secure environment, compromising the security of provisioning.

Innovation Solution

A provisioning method and terminal device that establish a secure channel between a security module implementing USIM functions and a CA server, allowing for the secure transmission and storage of session keys and digital certificates within the secure environment, thereby preventing physical attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If session keys are transmitted between USIM and HSM for provisioning, then digital certificates can be obtained from CA server, but session keys are exposed outside secure environment and vulnerable to physical attacks

Engineering Contradiction:
Improveprovisioning securityVSAvoidphysical attack risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the key transmission path from the insecure external environment by having the USIM establish a direct secure channel with the CA server. The session key never leaves the secure environment of the USIM, and only public keys and certificate data are transmitted externally, effectively removing the vulnerability to physical attacks on transmitted session keys.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The CA server acts as a trusted intermediary that receives public keys from the USIM directly through a secure channel, issues digital certificates, and returns them to the USIM. This intermediary mechanism eliminates the need for intermediate key transmission through insecure channels, as the CA server handles all certificate operations directly with the USIM.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a secure channel is established between security module and CA server, then session keys remain protected from physical attacks, but the complexity of the provisioning process increases

Engineering Contradiction:
Improvesession key securityVSAvoidprovisioning process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The USIM card is designed to perform multiple functions: it serves as both the security module for storing session keys and as the communication entity for establishing secure channels with the CA server. The USIM's existing secure environment and cryptographic capabilities are leveraged to handle public key generation, secure transmission, and certificate storage, eliminating the need for separate dedicated hardware components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If session keys are transmitted outside secure environment, then provisioning can be completed, but the security of the session keys is compromised

Engineering Contradiction:
Improveprovisioning efficiencyVSAvoidsession key protection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The USIM generates and stores its public key before any communication with the CA server. This preliminary action allows the USIM to establish a secure channel using its pre-existing secure environment, ensuring that session keys are never transmitted externally. The public key is prepared in advance and can be securely transmitted without compromising session key security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4068716B1Initial configuration method and terminal device
Publication Date: 2025.05.14 CHINA MOBILE COMM GRP CO LTD
  • EP4068716B1 patent drawingFigure 1~3
  • EP4068716B1 patent drawingFigure 4~6
  • EP4068716B1 patent drawingFigure 7~9

AI summary

The present disclosure provides an initial configuration method and a terminal device. The initial configuration method is applied to the terminal device, including: the security module establishes a secure channel with the certificate authority CA server; obtianing the session key through the secure channel, and obtaining the digital certificate from the CA server; wherein, the security module is used to realize the function of the global user identification module (USIM).