Wireless Terminal Network Locking via Segmented Certificate Signing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing network-locking methods for wireless terminals pose security risks and increased costs due to the need for a softdog during outfield testing, as testers often carry or email this sensitive key, which can be lost or mishandled.

Innovation Solution

The method divides network-locking operations into front-end and back-end parts, where the front-end module generates a locking certificate and the back-end module digitally signs it, eliminating the need for a softdog at the testing site by transferring the signed certificate back to the front-end for wireless terminal locking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If outfield testers carry or email the softdog to the front end for network-locking testing, then network-locking function testing can be performed, but security risk increases due to potential loss or improper storage of the softdog

Engineering Contradiction:
Improvenetwork-locking function testingVSAvoidnetwork-locking security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the network-locking function into two independent modules: a front-end network-locking module that generates locking certificates and performs locking operations, and a back-end network-locking module that digitally signs the locking certificates using the softdog. This segmentation allows the softdog to remain securely stored at the back end while enabling outfield testing at the front end.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A locking certificate serves as an intermediary between the softdog and the wireless terminal. The back-end module signs the certificate generated by the front-end module, and this signed certificate is then used for locking operations. This intermediary mechanism eliminates the need to transport the softdog itself while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the softdog is transported to the front end for outfield testing, then network-locking testing can be performed, but cost increases due to secure transport and storage requirements

Engineering Contradiction:
Improvenetwork-locking testing capabilityVSAvoidcost
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

By segmenting the network-locking function into front-end and back-end modules with distinct responsibilities, the system eliminates the need to physically transport the softdog. The front-end module handles certificate generation and locking operations, while the back-end module securely maintains the softdog for signing, thereby reducing transport and storage costs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of transporting the original softdog, the system creates a digital copy in the form of a locking certificate that can be securely transmitted. The back-end module signs this certificate, creating a verified copy that can be used for locking operations without requiring the physical softdog to be present at the front end.

Inventive Principle:
Principle #26Copying

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach reduces costs and significantly minimizes security risks associated with the handling and storage of softdogs during outfield testing by eliminating the need for physical transport of the softdog, enhancing the security and efficiency of network-locking operations.

Implementation Method 1

the back-end network-locking module is configured to digitally sign the locking certificate

Methodology Applied
Scientific EffectDigital signature:

Data Source

PatentEP3086583B1Wireless terminal network locking method and system
Publication Date: 2019.11.06 ZTE CORP
  • EP3086583B1 patent drawingFigure 1~2
  • EP3086583B1 patent drawingFigure 3
  • EP3086583B1 patent drawingFigure 4

AI summary

The present disclosure provides a network locking method for a wireless terminal, comprising: a front-end network-locking module sends a locking certificate generation request to a wireless terminal, and the wireless terminal generates a locking certificate according to the locking certificate generation request; a back-end network-locking module signs the locking certificate to generate a signed locking certificate; the front-end network-locking module performs communication interaction with the wireless terminal to send the signed locking certificate to the wireless terminal, for the wireless terminal to perform locking operations.