Virtual SIM Cloud Platform for Secure Data Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SIM cards have limited memory, security vulnerabilities, and lack user access control, making them inadequate for storing and protecting personal data and authentication information.

Innovation Solution

A virtual SIM platform is introduced, utilizing a computing cloud for storage and authentication, where a Terminal Trust Anchor (TTA) ensures secure provisioning and binding of the cloud SIM to the mobile device, providing enhanced memory and security through a Private Cloud Storage Service (PCSS) and Number Registration Service (NRS).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If conventional SIM cards are used to store user data and authentication information, then the SIM card provides basic identification and authentication functions, but the memory capacity is very limited (at most about 1 MB) and security protection is insufficient

Engineering Contradiction:
Improvestorage capacityVSAvoidsecurity protection
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent extracts the storage function from the SIM card by introducing a separate cloud storage service. User data is stored in a cloud database rather than on the SIM card itself, while the SIM card retains only essential authentication credentials. This separation allows the SIM card to maintain security while providing access to virtually unlimited storage capacity in the cloud.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a security module as an intermediary between the SIM card interface and user data. This security module implements additional authentication mechanisms and access control policies, acting as a mediator that verifies user identity before allowing access to stored data, thereby enhancing security beyond the basic PIN protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a SIM card stores personal information and contact details, then the information is accessible to the user, but the data is vulnerable to eavesdropping applications once the card interface is opened by successful PIN verification

Engineering Contradiction:
Improvedata accessibilityVSAvoideavesdropping vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements disposable or frequently rotating access tokens that are used for authentication and then discarded. Instead of relying on long-term static credentials stored on the SIM card, the system generates temporary access credentials that expire after use or after a short time period, making eavesdropped data useless for future unauthorized access.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent implements preliminary encryption of user data before it is stored or transmitted. Data is encrypted using keys stored securely in the SIM card or security module before leaving the device, so that even if data is intercepted during transmission or accessed from storage, it remains unreadable without the decryption keys.

Inventive Principle:
Principle #10Preliminary action

3Quantity of substance

If SIM card memory is limited to about 1 MB, then the SIM card structure remains simple and cost-effective, but the amount of user data and personal information that can be saved is severely restricted

Engineering Contradiction:
Improveuser data storageVSAvoidsystem architecture
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent transitions from two-dimensional local storage on the SIM card to three-dimensional distributed cloud storage. User data is stored across multiple servers in a cloud infrastructure, providing virtually unlimited storage capacity. The SIM card system is enhanced with communication interfaces and protocols to access this external storage dimension, enabling large-scale data storage without increasing SIM card physical complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Ease of operation

If the SIM card interface is opened by successful PIN verification, then the user can access their data, but anybody can also use the interface once the PIN is verified

Engineering Contradiction:
Improveuser accessVSAvoiduser access control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into multiple distinct stages with different security requirements. Instead of a single PIN verification that grants full access, the system implements hierarchical authentication where different levels of verification are required for different operations. The SIM card interface authentication is separated from data access authentication, allowing fine-grained control over what operations are permitted after login.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10349272B2Virtual SIM card cloud platform
Publication Date: 2019.07.09 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10349272B2 patent drawing
  • US10349272B2 patent drawing
  • US10349272B2 patent drawing

AI summary

A method of obtaining a virtual SIM for a mobile device comprises sending, to a TTA for authentication, a request for a virtual SIM for a mobile device associated with the TTA. The authenticated request is sent from the mobile device to an NRS application (or to a combined NRS/PCSS application). The mobile device subsequently receives information identifying a PCSS application (or a combined NRS/PCSS application) in a computing environment that provides a virtual SIM for the mobile device.