Virtual SIM Cloud Platform for Secure Data Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional SIM cards have limited memory, security vulnerabilities, and lack user access control, making them inadequate for storing and protecting personal data and authentication information.
Innovation Solution
A virtual SIM platform is introduced, utilizing a computing cloud for storage and authentication, where a Terminal Trust Anchor (TTA) ensures secure provisioning and binding of the cloud SIM to the mobile device, providing enhanced memory and security through a Private Cloud Storage Service (PCSS) and Number Registration Service (NRS).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If conventional SIM cards are used to store user data and authentication information, then the SIM card provides basic identification and authentication functions, but the memory capacity is very limited (at most about 1 MB) and security protection is insufficient
Solution Approach 1:
The patent extracts the storage function from the SIM card by introducing a separate cloud storage service. User data is stored in a cloud database rather than on the SIM card itself, while the SIM card retains only essential authentication credentials. This separation allows the SIM card to maintain security while providing access to virtually unlimited storage capacity in the cloud.
Solution Approach 2:
The patent introduces a security module as an intermediary between the SIM card interface and user data. This security module implements additional authentication mechanisms and access control policies, acting as a mediator that verifies user identity before allowing access to stored data, thereby enhancing security beyond the basic PIN protection.
2Ease of operation
If a SIM card stores personal information and contact details, then the information is accessible to the user, but the data is vulnerable to eavesdropping applications once the card interface is opened by successful PIN verification
Solution Approach 1:
The patent implements disposable or frequently rotating access tokens that are used for authentication and then discarded. Instead of relying on long-term static credentials stored on the SIM card, the system generates temporary access credentials that expire after use or after a short time period, making eavesdropped data useless for future unauthorized access.
Solution Approach 2:
The patent implements preliminary encryption of user data before it is stored or transmitted. Data is encrypted using keys stored securely in the SIM card or security module before leaving the device, so that even if data is intercepted during transmission or accessed from storage, it remains unreadable without the decryption keys.
3Quantity of substance
If SIM card memory is limited to about 1 MB, then the SIM card structure remains simple and cost-effective, but the amount of user data and personal information that can be saved is severely restricted
Solution Approach 1:
The patent transitions from two-dimensional local storage on the SIM card to three-dimensional distributed cloud storage. User data is stored across multiple servers in a cloud infrastructure, providing virtually unlimited storage capacity. The SIM card system is enhanced with communication interfaces and protocols to access this external storage dimension, enabling large-scale data storage without increasing SIM card physical complexity.
4Ease of operation
If the SIM card interface is opened by successful PIN verification, then the user can access their data, but anybody can also use the interface once the PIN is verified
Solution Approach 1:
The patent segments the authentication process into multiple distinct stages with different security requirements. Instead of a single PIN verification that grants full access, the system implements hierarchical authentication where different levels of verification are required for different operations. The SIM card interface authentication is separated from data access authentication, allowing fine-grained control over what operations are permitted after login.
Data Source
AI summary
A method of obtaining a virtual SIM for a mobile device comprises sending, to a TTA for authentication, a request for a virtual SIM for a mobile device associated with the TTA. The authenticated request is sent from the mobile device to an NRS application (or to a combined NRS/PCSS application). The mobile device subsequently receives information identifying a PCSS application (or a combined NRS/PCSS application) in a computing environment that provides a virtual SIM for the mobile device.


