Embedded SIM Locking via Trusted Service Manager Policy Tables
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional SIM Lock mechanisms are compromised, making it impractical to change telecommunications subscriptions for devices with embedded smartcards, as they are not easily accessible or swappable, and existing technologies do not allow for seamless switching between multiple network subscriptions.
Innovation Solution
A method and system that allow for logical swapping of telecommunications subscriptions on a physically unswappable smartcard, using personalization rules stored on the card or in a Trusted Service Manager's database, which can lock or bar the device to a specific subscription, enabling secure management and prevention of unauthorized changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional SIM Lock mechanisms are used to protect subsidized mobile devices, then device security against unauthorized SIM usage is improved, but the ability to change telecommunications subscriptions for devices with embedded smartcards deteriorates
Solution Approach 1:
The patent segments the SIM card functionality into two distinct components: a physically embedded secure element (SE) that cannot be removed or swapped, and a logical subscription profile that can be updated remotely. The secure element contains authentication credentials and immutable security functions, while the subscription data is stored in a separate, updatable area of the SIM card. This segmentation allows the secure element to maintain security while the subscription portion can be changed remotely without physical access.
Solution Approach 2:
The patent introduces a Trusted Service Manager (TSM) as an intermediary entity that mediates between the device operator and the remote subscription management system. The TSM securely stores personalization rules and controls the logical swap process, acting as a trusted broker that enables subscription changes while maintaining security constraints. This intermediary layer allows flexible subscription management without compromising the security enforced by the embedded secure element.
2Reliability
If SIM cards are embedded into devices for telematics applications, then device integration and reliability are improved, but ease of physical replacement and subscription change deteriorates
Solution Approach 1:
The patent replaces the mechanical SIM card replacement process with an electronic/remote subscription update mechanism. Instead of physically removing and inserting SIM cards, the system uses over-the-air (OTA) communication to remotely update subscription profiles in the SIM card's updatable memory area. This substitution eliminates the need for physical access to embedded SIM cards while maintaining the ability to change subscriptions, solving the contradiction between embedded integration and ease of change.
3Reliability
If personalization rules are enforced on embedded smartcards to prevent unauthorized changes, then security against theft and unauthorized use is improved, but flexibility in legitimate subscription changes deteriorates
Solution Approach 1:
The patent implements dynamic personalization rules that can change over time and based on conditions. The TSM stores multiple personalization rule sets and can activate different rules depending on the situation - such as allowing subscription changes during normal operation while blocking them during suspected theft scenarios. The system can dynamically adjust the strictness of personalization enforcement based on contextual factors, enabling both security and flexibility as needed.
Solution Approach 2:
The patent changes the parameters of the personalization system by introducing a hierarchy of personalization rules with different priority levels and conditions. Instead of a single static personalization state, the system uses multiple configurable parameters including rule priority, activation conditions, and time-based constraints. This allows the system to enforce strict personalization when needed while permitting flexible changes under appropriate conditions, resolving the contradiction between security and adaptability.
Data Source
Figure 1
Figure 2
AI summary
Where a smartcard is embedded or inaccessible within a cellular telecommunications device (i.e. an eUICC), locking the smartcard (or the subscription associated with the smartcard) to a particular MNO while allowing the MNO to be altered legitimately presents a challenge. A method is described using policy control tables stored in a trusted service manager registry and/or the smartcard's data store. By maintaining the policy control table, any MNO subscription may be downloaded / activated on the smartcard but the device will be prevented from accessing the desired MNO because that access would violate the lock rules.