eSIM Profile Installation via Dual-Token Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current eSIM card technologies lack effective mechanisms for joint control and compliance verification between operators and manufacturers, particularly in M2M specifications, regarding profile management and rule enforcement, which hinders compliance with commercial agreements and regulations.

Innovation Solution

A method involving the use of tokens signed by operators and third parties, such as manufacturers, to authenticate and install policy rules in eSIM cards, ensuring joint authorization and control over profile actions, including deactivation and activation, without direct involvement of terminal or SIM card manufacturers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the operator alone controls the installation of policy rules in eSIM cards, then the operator can manage profile lifecycle effectively, but manufacturers cannot verify compliance with commercial agreements or local regulations

Engineering Contradiction:
Improvecompliance verificationVSAvoidcontrol mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a manufacturer verification token as an intermediary mechanism that enables manufacturers to verify compliance without directly controlling rule installation. The token acts as a mediator between the operator's rule installation process and the manufacturer's compliance verification needs, allowing both parties to maintain their respective control while ensuring agreement compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the eSIM card is made non-removable and soldered, then security is improved, but the ability to replace or remove SIM cards by users is lost

Engineering Contradiction:
ImprovesecurityVSAvoidSIM card replacement
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic control over eSIM profile installation and activation through verified tokens. While the physical eSIM card remains non-removable for security, the system dynamically allows or prevents profile installations based on verified manufacturer tokens, providing adaptability within security constraints.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If multiple operator profiles are stored in a single eSIM card, then user flexibility is improved, but control over profile actions becomes more complex

Engineering Contradiction:
Improvemulti-operator supportVSAvoidprofile management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the control mechanism for each operator profile by associating specific verified manufacturer tokens with individual profiles. This allows multiple operator profiles to coexist in a single eSIM card, with each profile's installation and modification controlled by its own verification mechanism, simplifying management despite multi-operator support.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3456073B1Method and apparatus for policy control functions installation under the control of two entities in an embedded sim card
Publication Date: 2025.01.15 ORANGE SA
  • EP3456073B1 patent drawingFigure 1~2

AI summary

The invention relates to a method for setting up an execution rule of an operating environment for a communication terminal (UE) in a mobile network of an operator (Op1), said environment (P1) being referred to as the operator profile, the operator profile being stored in a subscriber module embedded in the terminal, and the method comprising the following steps carried out by the subscriber module: obtaining (U4) a first token (tokOp1) signed by the operator and comprising information relative to the identification of the rule; obtaining (U3) a second token (tokDM) signed by a third party other than the operator and comprising a first means for verifying the authenticity of the first token; verifying (U5) the authenticity of the first token by means of the first verification means; verifying (U5) the authenticity of the second token by means of a second verification means; and setting up (U6) the rule in the subscriber module if the authenticity of the first and second tokens is verified.