Wireless Network Authentication Using Encrypted Biometrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless networks face challenges in provisioning and managing subscriber identities, particularly with SIM cards, leading to operational complexity and difficulty in switching between carriers, and existing remote provisioning methods like eSIMs struggle with credential management.

Innovation Solution

Utilizing biometric information, such as fingerprints, to create a unique subscriber account and device ID, integrated with iSIM technology for secure authentication, which includes encrypting biometric data using homomorphic encryption for secure authentication and profile management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIM cards are used for subscriber identification, then network authentication is enabled, but device complexity and operational complexity increase due to provisioning and card swapping requirements

Engineering Contradiction:
Improvenetwork authenticationVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the SIM card functionality from the physical card and embeds it into the device's processor or system-on-chip (SoC). This eliminates the need for separate SIM card management while maintaining network authentication capabilities, thereby reducing provisioning complexity and operational complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent combines the SIM card's subscriber identification and authentication functions with the device's existing processor or SoC. By merging these functions into a single integrated component, the system eliminates the need for separate SIM card provisioning and swapping operations, reducing overall device complexity while maintaining reliable network authentication.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If physical SIM cards are used, then carrier identification is established, but ease of operation deteriorates due to the need to swap cards when changing carriers

Engineering Contradiction:
Improvecarrier identificationVSAvoidcarrier switching
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic carrier identification by storing multiple carrier profiles within the integrated SIM functionality. Users can switch between carriers through software-based profile selection rather than physical card swapping, making the system adaptable and easy to operate while maintaining reliable carrier identification.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The integrated SIM component is designed to support multiple carrier profiles and functions within a single device. This multi-functionality allows users to access services from different carriers without needing multiple physical SIM cards, significantly improving ease of operation while maintaining reliable carrier identification through the integrated authentication mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If eSIM remote provisioning is implemented, then SIM card swapping is eliminated, but credential management complexity increases

Engineering Contradiction:
ImproveSIM card swappingVSAvoidcredential management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service credential management where the integrated SIM component automatically handles profile installation, activation, and switching through remote provisioning. The system autonomously manages credential updates and carrier profile transitions without requiring complex manual intervention, thereby eliminating SIM card swapping while keeping credential management straightforward.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary provisioning server that mediates between the user and the integrated SIM component. This intermediary handles the complex credential management tasks including profile delivery, activation, and updates, simplifying the user experience while enabling robust remote provisioning functionality without increasing apparent device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If biometric information is encrypted and stored, then authentication security is enhanced, but device complexity increases due to encryption key management

Engineering Contradiction:
Improveauthentication securityVSAvoidencryption key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-generating and storing encryption keys within the integrated SIM component during device manufacturing or initial setup. These pre-configured keys are used to encrypt biometric information before storage, enhancing authentication security while eliminating the need for complex runtime key generation and management operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent combines the encryption key storage and biometric encryption functions within the integrated SIM component. By merging these security-critical functions into a single secure element, the system enhances authentication security through hardware-based protection while simplifying key management, as the integrated component handles all encryption operations autonomously without requiring external key management infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12587840B2Authentication management in a wireless network environment
Publication Date: 2026.03.24 CHARTER COMM OPERATING LLC
  • US12587840B2 patent drawing
  • US12587840B2 patent drawing
  • US12587840B2 patent drawing

AI summary

During registration, a mobile communication device derives a first instance of biometric information from a user operating the mobile communication device. The communication device retrieves an encryption key assigned to the mobile communication device. Via application of the encryption key to the first instance of biometric information, the communication device produces first encrypted biometric information and forwards it to an authentication resource. The authentication resource stores the first encrypted biometric information for later authentication of the communication device. During subsequent authentication, the mobile communication device derives a second instance of biometric information from the user operating the mobile communication device. The communication device encrypts the second instance of biometric information with the encryption key and forwards it to the authentication resource. The authentication resource requires a substantial match of the second encrypted biometric information to the first encrypted biometric information to authenticate the communication device to use a wireless network.