Dynamic eSIM Trusted List Update via Policy Notification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for provisioning electronic SIMs (eSIMs) in secure elements (SEs) face inefficiencies in memory and network bandwidth usage, particularly when updating trusted name lists, which can become outdated and are not efficiently managed, especially when dealing with untrusted servers during the provisioning process.

Innovation Solution

The proposed solution involves updating the trusted name list in a UICC on an as-needed basis by including the common name of a third-party eSIM server in the trusted list after verifying its authenticity through a policy update notification, allowing secure communication and provisioning of the eSIM by coordinating operations between the host eSIM server, carrier server, and third-party eSIM server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the trusted name list is updated broadcast fashion with certificates and names of servers, then trust establishment is improved, but memory usage and network bandwidth consumption increase significantly

Engineering Contradiction:
Improvetrust establishmentVSAvoidmemory usage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the necessary trusted server names from the broadcast fashion provisioning, updating the trusted name list selectively rather than provisioning all certificates and names. This reduces memory usage while maintaining trust establishment for required servers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The trusted name list is segmented and updated on an as-needed basis rather than as a complete broadcast provision. Each server name is added individually when required, optimizing memory usage while maintaining reliability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the trusted name list is updated broadcast fashion with certificates and names of servers, then trust establishment is improved, but network bandwidth consumption increases significantly

Engineering Contradiction:
Improvetrust establishmentVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts only the necessary trusted server names from the broadcast fashion provisioning, updating the trusted name list selectively rather than provisioning all certificates and names. This reduces network bandwidth consumption while maintaining trust establishment for required servers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The trusted name list is updated periodically and on an as-needed basis rather than through continuous broadcast provisioning. This reduces network bandwidth consumption while maintaining trust establishment when required.

Inventive Principle:
Principle #19Periodic action

3Reliability

If the trusted name list is universally provisioned, then trust coverage is improved, but entries become out-of-date and require frequent updates

Engineering Contradiction:
Improvetrust coverageVSAvoidupdate frequency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The trusted name list is made dynamic, updated on an as-needed basis rather than universally provisioned statically. This allows the list to adapt to current provisioning requirements, reducing the frequency of updates while maintaining adequate trust coverage.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The necessary trusted server names are added to the trusted name list in advance of provisioning operations, rather than waiting for updates. This preliminary action ensures trust coverage is established before needed, reducing update frequency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10141966B2Update of a trusted name list
Publication Date: 2018.11.27 APPLE INC
  • US10141966B2 patent drawing
  • US10141966B2 patent drawing
  • US10141966B2 patent drawing

AI summary

Methods, devices, and servers for as-needed update of a trusted list are provided herein. An electronic subscriber identity module (eSIM) server receives a request for an eSIM of a particular type from a wireless device. The eSIM server evaluates the particular type and requests an eSIM of the particular type from a second eSIM server, which is not initially trusted by a secure element (SE) of the wireless device. The eSIM server sends a policy update to the wireless device. The wireless device passes the policy update to the SE, for example, a universal integrated circuit card (UICC). The UICC updates the trusted list with an identity of the second eSIM server. When the wireless device downloads a bound profile package (BPP) containing an eSIM from the second eSIM server, the UICC validates the BPP based on the updated trusted list. The eSIM is then installed on the UICC.