Dual SIM Architecture Isolating Service Domain for Theft Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing devices with embedded mobile broadband modules face challenges in ensuring access to Universal Integrated Circuit Cards (UICC) for service access, as UICC can be physically removed, leading to security risks and limitations in service availability, particularly for Machine-to-Machine (M2M) applications and data subscription penetration.
Innovation Solution
A device and method utilizing a dual SIM architecture, where a first SIM is associated with the end user for user domain services and a second SIM, isolated from the end user, is associated with a service provider for service domain services, using separate communication paths to ensure secure and efficient access to mobile broadband services without user intervention, enabling secure service provision and theft protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single removable UICC is used for both user services and service domain services, then ease of operation is improved, but security and service reliability deteriorate because the UICC can be physically removed
Solution Approach 1:
The patent divides the single UICC into two separate SIMs: a first SIM for user domain services that the end user can access, and a second SIM for service domain services that is isolated from the end user. This segmentation ensures that the service provider's SIM cannot be removed or tampered with by the user, while still allowing the user to operate their own SIM freely.
Solution Approach 2:
The service domain SIM is extracted as a separate, isolated entity from the user's control. The second SIM is specifically designed to be inaccessible to the end user, preventing removal or unauthorized access while maintaining its functionality for service domain operations such as monitoring and theft prevention.
2Device complexity
If a single SIM is used for all services, then device complexity is reduced, but adaptability and service versatility deteriorate
Solution Approach 1:
The patent segments service functionality into two distinct SIMs, each handling different service domains. This allows the device to support multiple service types (user services and service provider services) simultaneously, enhancing versatility while maintaining manageable complexity through clear functional separation.
Solution Approach 2:
The dual SIM architecture enables the device to perform multiple functions through two SIMs that can operate independently or in coordination. The first SIM handles user services while the second SIM handles service domain functions, allowing the device to adapt to different service requirements without increasing overall system complexity.
3Ease of operation
If the service domain SIM is accessible to the end user, then ease of operation is improved, but security and theft prevention capabilities deteriorate
Solution Approach 1:
The service domain SIM is extracted as a separate, isolated entity that is physically or logically inaccessible to the end user. This extraction ensures that security-critical functions such as monitoring and theft prevention cannot be compromised by user actions, while the user retains full access to their own SIM for normal operations.
Solution Approach 2:
The patent introduces an intermediary architecture where the service provider's SIM operates independently from user access. This intermediary SIM acts as a secure mediator that can monitor and control device usage without being accessible to or controllable by the end user, thereby preventing security risks while maintaining service functionality.
Data Source
AI summary
There is provided a device comprising a mobile broadband module comprising radio communication means. The device further comprises at least a first SIM for providing user domain services and at least a second SIM for providing service domain services. The second SIM is isolated from an end user of the device. According to an embodiment, the first SIM is associated with the end user of the device, wherein the end user may be associated with a first identity, and wherein the second SIM is associated with a service provider, the service provider being associated with a second identity. A method comprising: identifying which of the first and the second communication paths a command is issued from; and continuing with the command or discontinuing with the command in dependence on the identified path, such that the end user is not able to perform operation on to access the isolated second SIM.


