Dual-Profile Security Module for M2M Network Failover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current M2M equipment lacks reliability in maintaining network connectivity and data transmission during network failures, such as 'no service' or 'limited service' conditions, as it cannot switch to alternative networks without human intervention or significant equipment modifications.

Innovation Solution

A method utilizing a dual-profile security module that stores subscriber identification numbers for multiple networks, enabling automatic switchover between networks using roaming agreements, allowing M2M equipment to continue data transmission by switching between networks based on service availability, with timed delays to manage load and minimize roaming costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If M2M equipment uses a single network subscription, then equipment complexity is minimized, but reliability during network failures deteriorates

Engineering Contradiction:
Improvenetwork connectivity reliabilityVSAvoidsecurity module complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security module is designed to store and manage multiple subscriber profiles (IMSI, Ki, OpC) for different networks, enabling it to function as both a primary network access module and a fallback network access module. This multi-functionality allows the equipment to maintain connectivity across multiple networks without adding external devices, thus improving reliability while keeping the security module as the single point of management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If M2M equipment implements automatic network switchover, then service continuity is improved, but ease of operation deteriorates due to automatic roaming activation

Engineering Contradiction:
Improvedata transmission continuityVSAvoidroaming configuration simplicity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The security module pre-stores multiple subscriber profiles (including alternative IMSI, alternative Ki, and alternative OpC) before network failure occurs. When the primary network fails, the module automatically activates the pre-configured alternative profile without requiring real-time configuration or user intervention. This preliminary preparation ensures continuous data transmission while maintaining operational simplicity.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If M2M equipment stores multiple subscriber identifiers, then adaptability to network failures is improved, but loss of information increases due to security key management

Engineering Contradiction:
Improvenetwork failure adaptabilityVSAvoidsecurity key storage overhead
Core Design Contradiction:
Adaptability or versatilityVSLoss of substance

Solution Approach 1:

The patent combines multiple security elements (IMSI, Ki, OpC) that are normally stored separately in different locations into a single security module. The module stores the primary and alternative subscriber identifiers along with their associated security keys in an integrated manner, eliminating the need for multiple separate security modules or external authentication servers. This merging approach enables network failure adaptability while consolidating security key management in one secure location.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3005795B1Method for locating a device in a network
Publication Date: 2021.01.27 ORANGE SA
  • EP3005795B1 patent drawingFigure 1
  • EP3005795B1 patent drawingFigure 2
  • EP3005795B1 patent drawingFigure 3

AI summary

The invention concerns a method for locating a device (10) in a network, the device being located in a coverage area of a first network (A) of a first country, a security module (11) associated with the device memorising a first subscriber identification number (IMSIA) in the first network and at least a second subscriber identification number (IMSIB) in a second network (B) of a second country, the roaming of a subscriber of the second network being allowed in a third network (A') of the first country, said method comprising the following steps, implemented by the security module: - reception (E3) of an event associated with an update of an item of location data of the device in the first network, - detection (E4) of a lack of normal service in the first network, - switching (E5, E6, E7) from the first network to the second network, said switching triggering a locating of the device in the third network.