Virtual SIM Authentication via Trusted Services Manager

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless systems require Subscriber Identity Modules (SIM) cards for authentication, leading to device bulkiness, increased costs, and complexities in SIM card management and distribution, limiting user access to wireless services without a SIM card.

Innovation Solution

A method and apparatus for wireless network authentication that allows network service providers to distribute Universal Subscriber Identity Module (USIM) credentials to a trusted services manager, which authenticates users and provides USIM credentials to user equipment for secure storage and use, eliminating the need for physical SIM cards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIM cards are used for wireless network authentication, then security and authentication reliability are improved, but device bulkiness and manufacturing cost increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddevice bulkiness
Core Design Contradiction:
ReliabilityVSWeight of moving object

Solution Approach 1:

The invention extracts the authentication functionality from the physical SIM card and implements it as a virtual SIM card using software-based authentication mechanisms. The authentication credentials are stored and managed in the device's memory or secure element rather than requiring a separate physical card, thereby eliminating the need for SIM card slots and reducing device bulkiness while maintaining authentication reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention creates a virtual copy of the SIM card functionality through software implementation. The virtual SIM card replicates all essential authentication functions of a physical SIM card including credential storage, authentication processing, and network registration, allowing the device to authenticate to wireless networks without requiring a physical SIM card present in the device

Inventive Principle:
Principle #26Copying

2Reliability

If SIM cards are used for wireless network authentication, then authentication security is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidSIM card management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention enables the device to autonomously manage authentication credentials through virtual SIM card implementation. The device can automatically provision, store, and utilize authentication credentials without requiring manual SIM card insertion, removal, or physical inventory management. The virtual SIM card system handles authentication security internally through software-based cryptographic operations, eliminating the need for complex physical SIM card management procedures

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The virtual SIM card implementation provides multi-functional capability by consolidating authentication, credential management, and network registration functions into a unified software-based system. This universal approach allows the same virtual SIM card mechanism to serve multiple purposes including authentication, encryption key management, and network selection, thereby reducing overall system complexity compared to separate physical SIM card management

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If physical SIM cards are distributed to users, then authentication capability is provided, but distribution and inventory management complexity increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidSIM card distribution complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The invention replaces the mechanical distribution system of physical SIM cards with an electronic delivery mechanism. Authentication credentials are transmitted digitally to devices through wireless communication or secure data transfer protocols, eliminating the need for physical manufacturing, packaging, shipping, and inventory tracking of SIM cards. The credential provisioning process is automated through network-based authentication servers that can remotely provision virtual SIM cards to authorized devices

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The virtual SIM card system allows for digital replication and distribution of authentication credentials without the constraints of physical card production. Multiple virtual SIM card instances can be created and distributed electronically to different devices, allowing flexible provisioning and revocation of authentication capabilities without the logistical overhead of physical card management

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9338649B2Wireless network authentication apparatus and methods
Publication Date: 2016.05.10 APPLE INC
  • US9338649B2 patent drawing
  • US9338649B2 patent drawing
  • US9338649B2 patent drawing

AI summary

Apparatus and methods for authenticating and granting a client device (e.g., cellular telephone) access to a network. In one embodiment, a network service provider such as a cellular telephone company may distribute user access (e.g., Universal Subscriber Identity Module or “USIM”) credentials to a service manager via a USIM vendor. The services manager may maintain a list of authorized users. A user at a client may authenticate to the services manager. Once authenticated, the services manager may provide the user with a set of USIM credentials. When the user desires to use wireless network services, the user equipment may establish a wireless link between the user equipment and the network service provider. During authentication operations, the user equipment may use the USIM credentials to authenticate to the network service provider. Following successful authentication, the network service provider may provide the user equipment with wireless services.