Virtual SIM Authentication via Integrated Memory Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for communication endpoints with secure memory devices in networks lack robustness against counterfeit, tampering, and unauthorized access, as they rely on external processors for security computations and do not effectively verify the integrity and authenticity of data stored in memory devices.

Innovation Solution

Implementing a security server and memory devices with integrated security features, such as a cryptographic engine and access controller, that perform cryptographic computations locally within the memory device to secure communications, validate identity, and control access, eliminating the need for external processors and enhancing security by preventing data exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If external processors are used for security computations, then device complexity is reduced, but security reliability deteriorates due to vulnerability to counterfeit and tampering

Engineering Contradiction:
Improvesecurity computation architectureVSAvoidauthentication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent merges the security computation functions into the memory device itself by integrating a cryptographic engine and access controller within the memory device architecture. This eliminates the need for external processors to perform security computations, thereby improving security reliability while maintaining manageable device complexity through functional integration.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The memory device performs security computations autonomously using its integrated cryptographic engine. The device validates its own identity and secures its own data without requiring external processors, implementing self-service security that prevents counterfeit and tampering attacks while keeping the overall system architecture relatively simple.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If data is stored in memory devices accessible by host systems, then ease of operation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality control by introducing an access controller within the memory device that enforces different access policies for different data regions and different authorized users. The access controller verifies authentication credentials locally before allowing data access, maintaining ease of operation for authorized users while preventing unauthorized access through localized security enforcement at the memory device level.

Inventive Principle:
Principle #3Local quality

3Device complexity

If cryptographic keys are stored externally, then device complexity is reduced, but data integrity verification deteriorates

Engineering Contradiction:
Improvekey management architectureVSAvoiddata integrity verification
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent merges cryptographic key storage and management functions into the memory device architecture, integrating secure key storage, cryptographic operations, and data integrity verification within the same device. This integration ensures that cryptographic keys remain securely bound to the specific memory device, enabling precise data integrity verification while maintaining manageable complexity through unified design.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20240422547A1Virtual Subscriber Identification Module and Virtual Smart Card
Publication Date: 2024.12.19 MICRON TECHNOLOGY INC
  • US20240422547A1 patent drawing
  • US20240422547A1 patent drawing
  • US20240422547A1 patent drawing

AI summary

A system, method and apparatus to authenticate an endpoint having a secure memory device. For example, a card profile can be selected, configured, and/or stored into the secure memory device based on endpoint identity data representative of a component configuration of the endpoint, including the device identity representative of the memory device and other components. The card profile can be used by the endpoint to emulate a physical smart card and can be viewed a virtual smart card, such as a virtual subscriber identification module (SIM) card for accessing a cellular connection.