Dynamic eSIM Trusted List Update via Policy Notification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for provisioning electronic SIMs (eSIMs) in secure elements (SEs) face inefficiencies in memory and network bandwidth usage, particularly when updating trusted name lists, which can become outdated and are not efficiently managed, especially when dealing with untrusted servers during the provisioning process.
Innovation Solution
The proposed solution involves updating the trusted name list in a UICC on an as-needed basis by including the common name of a third-party eSIM server in the trusted list after verifying its authenticity through a policy update notification, allowing secure communication and provisioning of the eSIM by coordinating operations between the host eSIM server, carrier server, and third-party eSIM server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the trusted name list is updated broadcast fashion with certificates and names of servers, then trust establishment is improved, but memory usage and network bandwidth consumption increase significantly
Solution Approach 1:
The patent extracts only the necessary trusted server names from the broadcast fashion provisioning, updating the trusted name list selectively rather than provisioning all certificates and names. This reduces memory usage while maintaining trust establishment for required servers.
Solution Approach 2:
The trusted name list is segmented and updated on an as-needed basis rather than as a complete broadcast provision. Each server name is added individually when required, optimizing memory usage while maintaining reliability.
2Reliability
If the trusted name list is updated broadcast fashion with certificates and names of servers, then trust establishment is improved, but network bandwidth consumption increases significantly
Solution Approach 1:
The patent extracts only the necessary trusted server names from the broadcast fashion provisioning, updating the trusted name list selectively rather than provisioning all certificates and names. This reduces network bandwidth consumption while maintaining trust establishment for required servers.
Solution Approach 2:
The trusted name list is updated periodically and on an as-needed basis rather than through continuous broadcast provisioning. This reduces network bandwidth consumption while maintaining trust establishment when required.
3Reliability
If the trusted name list is universally provisioned, then trust coverage is improved, but entries become out-of-date and require frequent updates
Solution Approach 1:
The trusted name list is made dynamic, updated on an as-needed basis rather than universally provisioned statically. This allows the list to adapt to current provisioning requirements, reducing the frequency of updates while maintaining adequate trust coverage.
Solution Approach 2:
The necessary trusted server names are added to the trusted name list in advance of provisioning operations, rather than waiting for updates. This preliminary action ensures trust coverage is established before needed, reducing update frequency.
Data Source
AI summary
Methods, devices, and servers for as-needed update of a trusted list are provided herein. An electronic subscriber identity module (eSIM) server receives a request for an eSIM of a particular type from a wireless device. The eSIM server evaluates the particular type and requests an eSIM of the particular type from a second eSIM server, which is not initially trusted by a secure element (SE) of the wireless device. The eSIM server sends a policy update to the wireless device. The wireless device passes the policy update to the SE, for example, a universal integrated circuit card (UICC). The UICC updates the trusted list with an identity of the second eSIM server. When the wireless device downloads a bound profile package (BPP) containing an eSIM from the second eSIM server, the UICC validates the BPP based on the updated trusted list. The eSIM is then installed on the UICC.


