Dual-SIM Enterprise Profile Routing for Secure BYOD Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device management systems fail to provide adequate security and control over enterprise data transmission, especially for small to medium enterprises, as they often use the same wireless networks for both personal and enterprise usage, lacking control over network connections.

Innovation Solution

Implementing a dual-SIM configuration on mobile devices, where a first SIM is used for personal use and a second SIM is configured with enterprise-specific policies to route enterprise data through trusted cellular networks, ensuring secure and separate access to enterprise resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single SIM is used for both personal and enterprise usage, then device simplicity is maintained, but security and control over enterprise data transmission deteriorates

Engineering Contradiction:
ImproveSIM configurationVSAvoidenterprise data security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the single SIM functionality into two separate SIMs: a first SIM for personal usage and a second SIM for enterprise usage. This segmentation allows independent configuration and policy enforcement for enterprise data, improving security without requiring complete device redesign. The mobile device now has distinct communication channels for personal and enterprise traffic.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a dual-SIM configuration is implemented with separate policies, then enterprise data security is improved, but device complexity increases

Engineering Contradiction:
Improveenterprise data securityVSAvoidSIM configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal profile management system that handles both personal and enterprise SIM configurations through a common interface. The profile manager can store and apply multiple profiles (personal and enterprise) using the same underlying mechanisms, reducing the operational complexity despite the dual-SIM hardware. Users interact with a unified system rather than separate complex configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If enterprise data is routed through the same network as personal data, then network flexibility is maintained, but network control and security deteriorates

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidnetwork control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent applies different routing policies and network configurations to enterprise data versus personal data. Enterprise data routed through the second SIM can be subject to specific enterprise policies, trusted network lists, and security restrictions, while personal data maintains full user flexibility. This local differentiation of network quality and control achieves both security and adaptability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12477321B2Enterprise profile associated with a subscriber identity module (SIM)
Publication Date: 2025.11.18 BOOST SUBSCRIBERCO LLC
  • US12477321B2 patent drawing
  • US12477321B2 patent drawing
  • US12477321B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for associating an enterprise profile with a SIM. One of the methods includes obtaining a first profile corresponding to policies associated with usage of the mobile device to access enterprise resources, wherein a first SIM is configured in accordance with a second profile that is different from the first profile. The method includes configuring a second SIM in accordance with the first profile such that data through the second SIM is configured to be routed in accordance with the policies. The method includes routing data through the second SIM in accordance with the policies to access at least a portion of the enterprise resources, and routing data through the first SIM independent of the policies.