Constrained Smart Card Subscription Switching via Pre-Provisioned Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote SIM provisioning methods, such as RSP, are not suitable for IoT and NB-IoT devices due to limited bandwidth and battery capacity, making it difficult to securely switch subscriptions from one network operator to another.

Innovation Solution

Pre-provisioning smart cards with a batch of secret keys at a personalization factory, generating and transmitting necessary credentials over secure channels, and using OTA to switch subscriptions securely without changing the physical card.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If RSP is used for subscription switching, then subscription switching is enabled, but the device complexity and bandwidth requirements increase which are not suitable for constrained IoT devices

Engineering Contradiction:
Improvesubscription switching capabilityVSAvoidbandwidth and battery requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-provisioning smart cards with multiple secret keys and operator codes at the personalization factory before deployment. This allows IoT devices to switch subscriptions by simply selecting from pre-loaded credentials rather than performing complex over-the-air provisioning, thereby reducing bandwidth and battery requirements while maintaining subscription switching capability.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If physical smart card replacement is used for subscription switching, then subscription change is achieved, but the ease of operation decreases due to manual intervention requirements

Engineering Contradiction:
Improveoperator switchingVSAvoidmanual card replacement
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent applies copying by creating virtual copies of operator credentials (secret keys, operator codes, IMSIs) within the smart card's memory. Multiple operator subscriptions are stored as data copies rather than requiring physical card replacements, enabling automatic or semi-automatic subscription switching while maintaining security through cryptographic protection of the credential copies.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If multiple subscriptions are stored in smart cards, then subscription switching flexibility improves, but the security risks increase due to multiple secret keys

Engineering Contradiction:
Improvemulti-operator supportVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies segmentation by dividing the subscription management function into separate components: the smart card stores multiple encrypted credential sets, while the personalization factory and network operators maintain separate control over key generation and distribution. Each operator's credentials are independently encrypted and stored, allowing secure multi-operator support without creating a single point of vulnerability for all subscriptions.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12368587B2Method to provision a subscription in a constrained device
Publication Date: 2025.07.22 THALES DIS FRANCE SA
  • US12368587B2 patent drawing

AI summary

The disclosure proposes a method for switching from a first subscription of a first telecommunication network operator to a second subscription of a second telecommunication network operator on a plurality of smart cards, the method comprising, for each smart card pre-provisioning the smart card with a batch of secret keys at the level of a personalization factory; thanks to a first input file transmitted by the first telecommunication network operator to the personalization factory, generating at the personalization factory an output file comprising a first secret key selected in the batch, a corresponding first IMSI and a first ciphered operator code; transmitting the output file to the first telecommunication network operator; and transmitting OTA keys and the first IMSI to an OTA server of a service provider managing the smart card in order to attach the smart card to the first telecommunication network.