EP2113856A1

Secure storage of user data in UICC and Smart Card enabled devices

Abstract

A system for securing user data in Universal Integrated Circuit Card (referred to as UICC) and/or Smart Card enabled devices. The invention uses a UICC and/or Smart Card to function as a key repository for the UICC/Smart Card enabled device. The device can use encryption keys from the UICC/Smart Card to encrypt/decrypt data stored in the memory of the device, this data could be user data like e-mail, passwords, SMS messages etc.

EP2113856A1, drawing sheet 1
Sheet 1 of 4

Term

Projected expiry 29 April 2028.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

10 claims: 8 independent, 2 dependent

  1. 1
    A system for storing encrypted data, the system comprising:a) a UICC/Smart Card enabled mobile device with a memory for storing data;b) a UICC/Smart Card capable of hosting an application functioning as key repository;c) a key repository application and encryption keys residing within the UICC/Smart Card;d) a protocol for communicating data between the mobile device and the UICC/Smart Card.
  2. 3
    A UICC/Smart Card characterized by being capable of running a key repository function as an application storing encryption keys and/or certificates.
  3. 5
    A key repository functionality, residing within the UICC/Smart Card operating system that has a timing feature so that the password/PIN must be re-verified with defined intervals
  4. 6
    A key repository functionality residing within the UICC/Smart Card operating system that has a timing feature that can be configured by the user to an interval
  5. 7
    A key repository functionality residing within the UICC/Smart Card operating system that stores encryption keys and/or certificates securely so that they can only be retrieved from memory with the verification of password/PIN
  6. 8
    A key repository functionality residing within the UICC/Smart Card operating system that can be configured with a set of commands, these commands and configurations can also be altered via remote technologies.
  7. 9
    A method of encrypting data in a mobile device, the method comprising the following steps:a) providing a UICC/Smart Card personalized with a set of encryption key or certificates so as to act as a key repository;b) the mobile device authenticating a user to the key repository based on a password and/or PIN presented by the user;c) the UICC/Smart Card verifying the password/PIN;d) upon verifying the password/PIN the mobile device requesting an encryption key or certificate from the UICC/Smart Card;e) the UICC/Smart Card responding by sending a key with the required specifications to the mobile device;f) the mobile device encrypting, using the received key/certificate, the data;and g) storing the encrypted data.
  8. 10
    A method for decrypting data stored in a mobile device comprising the following steps:a) providing a UICC/Smart Card personalized with a set of encryption key or certificates so as to act as a key repository;b) the mobile device authenticating a user to the key repository based on a password and/or PIN presented by the user;c) the UICC/Smart Card verifying the password/PIN;d) upon verifying the password/PIN the mobile device requesting an encryption key or certificate from the UICC/Smart Card;e) the UICC/Smart Card responding by sending a key with the required specifications to the mobile device;f) the mobile device encrypting, using the received key/certificate, the data. Some related patents that have been found;these patents have some relation to the field of invention, but are only given for information purposes. US 2004/0206812 A1 US 7178724 B2 TW 588247B