Delegated Subscription Credential Management for Enterprise Mobility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing credentials for communications devices lack flexibility and control for enterprises, as they rely on mobile network operators for provisioning, activation, and deactivation of subscription credentials, limiting the ability to enforce policies across multiple devices and subscriptions.

Innovation Solution

The delegation of control from mobile network operators to enterprises allows for direct or indirect management of subscription credentials and policies, enabling enterprises to determine when and where credentials are provisioned, activated, and removed, and associate them with specific devices and policies, using Universal Integrated Circuit Cards (UICC) or embedded UICC (eUICC) technologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprises rely on mobile network operators for provisioning and management of subscription credentials, then service provider control and security are maintained, but enterprise flexibility and control over credential provisioning, activation, and policy enforcement are limited

Engineering Contradiction:
Improveenterprise control flexibilityVSAvoidmanagement system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an enterprise server as an intermediary between mobile network operators and communications devices. This intermediary enables enterprises to control credential provisioning, activation, and policy enforcement without directly managing the complex interactions with mobile network operators, thus improving enterprise flexibility while maintaining security through the established operator interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If mobile network operators directly manage credential provisioning for all devices, then security and service control are maintained, but enterprise-specific policy enforcement and customized management are hindered

Engineering Contradiction:
Improveenterprise management easeVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the credential management process into distinct functions: the enterprise server handles policy determination, device identification, and provisioning decisions, while the mobile network operator handles secure credential delivery and activation. This segmentation allows enterprises to easily manage their specific requirements while the operator maintains security controls.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If enterprises directly manage subscription credentials without delegation, then full control and policy enforcement are achieved, but operational overhead and complexity increase

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidprovisioning efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system enables self-service provisioning where the enterprise server automatically determines which devices receive credentials based on predefined policies, without requiring manual intervention from enterprise administrators. The system autonomously handles device identification, policy evaluation, and credential provisioning requests to the operator, improving productivity while maintaining full policy enforcement capability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10362485B2Delegated profile and policy management
Publication Date: 2019.07.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10362485B2 patent drawing
  • US10362485B2 patent drawing
  • US10362485B2 patent drawing

AI summary

Identities of mobile communications devices and subscription credentials are maintained by an enterprise server. The subscription credentials are operative to enable access to subscription services of a mobile network operator. Control of the subscription credentials is delegated from the mobile network operator to the enterprise server. The enterprise server determines which of the mobile communications devices are to be provisioned by the subscription credentials. Policies for use of the subscription credentials by the determined mobile communications devices are identified. The subscription credentials and policies are applied to the mobile communications devices.