Wireless Network Authentication Using Encrypted Biometrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional wireless networks face challenges in provisioning and managing subscriber identities, particularly with SIM cards, leading to operational complexity and difficulty in switching between carriers, and existing remote provisioning methods like eSIMs struggle with credential management.
Innovation Solution
Utilizing biometric information, such as fingerprints, to create a unique subscriber account and device ID, integrated with iSIM technology for secure authentication, which includes encrypting biometric data using homomorphic encryption for secure authentication and profile management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIM cards are used for subscriber identification, then network authentication is enabled, but device complexity and operational complexity increase due to provisioning and card swapping requirements
Solution Approach 1:
The patent extracts the SIM card functionality from the physical card and embeds it into the device's processor or system-on-chip (SoC). This eliminates the need for separate SIM card management while maintaining network authentication capabilities, thereby reducing provisioning complexity and operational complexity.
Solution Approach 2:
The patent combines the SIM card's subscriber identification and authentication functions with the device's existing processor or SoC. By merging these functions into a single integrated component, the system eliminates the need for separate SIM card provisioning and swapping operations, reducing overall device complexity while maintaining reliable network authentication.
2Reliability
If physical SIM cards are used, then carrier identification is established, but ease of operation deteriorates due to the need to swap cards when changing carriers
Solution Approach 1:
The patent implements dynamic carrier identification by storing multiple carrier profiles within the integrated SIM functionality. Users can switch between carriers through software-based profile selection rather than physical card swapping, making the system adaptable and easy to operate while maintaining reliable carrier identification.
Solution Approach 2:
The integrated SIM component is designed to support multiple carrier profiles and functions within a single device. This multi-functionality allows users to access services from different carriers without needing multiple physical SIM cards, significantly improving ease of operation while maintaining reliable carrier identification through the integrated authentication mechanism.
3Ease of operation
If eSIM remote provisioning is implemented, then SIM card swapping is eliminated, but credential management complexity increases
Solution Approach 1:
The patent implements self-service credential management where the integrated SIM component automatically handles profile installation, activation, and switching through remote provisioning. The system autonomously manages credential updates and carrier profile transitions without requiring complex manual intervention, thereby eliminating SIM card swapping while keeping credential management straightforward.
Solution Approach 2:
The patent introduces an intermediary provisioning server that mediates between the user and the integrated SIM component. This intermediary handles the complex credential management tasks including profile delivery, activation, and updates, simplifying the user experience while enabling robust remote provisioning functionality without increasing apparent device complexity.
4Reliability
If biometric information is encrypted and stored, then authentication security is enhanced, but device complexity increases due to encryption key management
Solution Approach 1:
The patent implements preliminary action by pre-generating and storing encryption keys within the integrated SIM component during device manufacturing or initial setup. These pre-configured keys are used to encrypt biometric information before storage, enhancing authentication security while eliminating the need for complex runtime key generation and management operations.
Solution Approach 2:
The patent combines the encryption key storage and biometric encryption functions within the integrated SIM component. By merging these security-critical functions into a single secure element, the system enhances authentication security through hardware-based protection while simplifying key management, as the integrated component handles all encryption operations autonomously without requiring external key management infrastructure.
Data Source
AI summary
During registration, a mobile communication device derives a first instance of biometric information from a user operating the mobile communication device. The communication device retrieves an encryption key assigned to the mobile communication device. Via application of the encryption key to the first instance of biometric information, the communication device produces first encrypted biometric information and forwards it to an authentication resource. The authentication resource stores the first encrypted biometric information for later authentication of the communication device. During subsequent authentication, the mobile communication device derives a second instance of biometric information from the user operating the mobile communication device. The communication device encrypts the second instance of biometric information with the encryption key and forwards it to the authentication resource. The authentication resource requires a substantial match of the second encrypted biometric information to the first encrypted biometric information to authenticate the communication device to use a wireless network.


