eSIM Secure Profile Partitioning for Remote Multi-Operator Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SIM technologies lack flexibility in managing multiple mobile network operator profiles, especially for remote and hermetically sealed devices like IoT devices, and do not provide secure access control for different SIM profiles.
Innovation Solution
An embedded subscriber identification module (eSIM) with a secure memory and a physical memory manager that creates partitions for individual SIM profiles, uses public key infrastructure for authentication, and limits access to authorized mobile network operators, allowing remote provisioning and secure storage of multiple profiles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a traditional SIM card is used, then secure storage of subscriber information is achieved, but flexibility in managing multiple mobile network operator profiles is lost
Solution Approach 1:
The secure memory is divided into multiple independent partitions, each dedicated to storing a specific mobile network operator profile. This segmentation allows the system to manage multiple profiles simultaneously while maintaining the security isolation of traditional SIM cards, resolving the contradiction between profile management flexibility and secure storage.
Solution Approach 2:
The eSIM device integrates multiple SIM profile capabilities into a single physical unit, enabling it to function as multiple SIM cards simultaneously. This multi-functionality eliminates the need for physical SIM swapping while maintaining secure subscriber information storage, addressing both flexibility and security requirements.
2Adaptability or versatility
If multiple SIM profiles are stored in the same memory space, then flexibility is improved, but access control security is weakened
Solution Approach 1:
The memory is segmented into distinct partitions with enforced access boundaries. Each partition can only be accessed by its authorized mobile network operator through authenticated commands, preventing unauthorized cross-access while allowing multiple profiles to coexist in the same physical memory device.
Solution Approach 2:
Different security policies and access control mechanisms are applied to different memory partitions based on their specific requirements. Each partition has its own access authorization rules, enabling tailored security measures for each mobile network operator profile while maintaining overall system security.
3Ease of operation
If physical SIM cards are used for each mobile network operator, then access control is secure, but ease of operation for remote devices is reduced
Solution Approach 1:
The mechanical SIM card insertion and swapping operation is replaced by wireless electronic commands. Profile installation, activation, and switching are performed remotely through authenticated communication protocols, eliminating the need for physical device access while maintaining secure profile management.
Solution Approach 2:
The eSIM device autonomously handles profile installation and activation through remote commands without requiring physical intervention. The device can self-provision new profiles, activate dormant ones, and switch between operators remotely, greatly improving ease of operation for remote and sealed devices.
Data Source
AI summary
An example device includes a processor, and an embedded subscriber identification module (eSIM). The eSIM includes a secure memory, and a physical memory manager configured to receive a first request to load a first profile for accessing a first mobile network in the secure memory from a first mobile network operator, and responsive to authenticating the first request, create a first partition in the secure memory associated with the first mobile network operator, store in the first partition the first profile, and limit access to the first partition to the first mobile network operator.


