eUICC Profile Installation via Remote Network Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing universal integrated circuit cards (UICC) are not suitable for smaller form factors and machine-to-machine devices, as they require a dedicated terminal for each mobile network operator, limiting flexibility and compatibility, especially when changing network operators or using different IT systems.
Innovation Solution
A method and apparatus for remotely installing and managing UICC profiles in a terminal using a network server, allowing the terminal to download authentication information and profiles without changing the mobile network operator's IT system interface, enabling flexible management of multiple network operators and profiles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a removable UICC card is used, then network access authentication information can be stored and users can change terminals, but the terminal requires a dedicated slot and cannot support smaller form factors
Solution Approach 1:
The UICC functionality is merged with the terminal's existing secure element (such as a payment card chip), eliminating the need for a separate removable card and its associated slot. This integration allows the terminal to maintain network authentication capabilities while reducing overall device volume and removing the physical slot requirement.
2Ease of manufacture
If a dedicated UICC card is manufactured for each mobile network operator, then authentication information is pre-configured, but the terminal cannot flexibly switch between different network operators
Solution Approach 1:
The system transitions from a static, pre-configured UICC card to a dynamic architecture where the terminal's secure element can be remotely provisioned with authentication information for different network operators. This allows the terminal to adaptively switch between operators by downloading appropriate credentials via OTA technology, maintaining ease of manufacture while achieving operational flexibility.
3Reliability
If an embedded security module is installed during manufacturing, then the module cannot be detached, but the terminal lacks network access authentication information unless dedicated to a specific operator
Solution Approach 1:
The terminal is manufactured with an embedded secure element that is initially empty or contains placeholder credentials. Before deployment, the appropriate network authentication information is downloaded and installed into the secure element via OTA technology. This preliminary provisioning action ensures the module is both securely embedded and properly configured for the intended network operator.
4Ease of operation
If a removable UICC card is used, then profile management can be performed, but machine-to-machine devices cannot be supported in various installation environments
Solution Approach 1:
The UICC functionality is merged into the terminal's embedded secure element, enabling profile management capabilities to be maintained while removing the requirement for a removable card. This integration makes the solution suitable for M2M devices where removable cards are impractical, as the embedded module can be securely installed in various installation environments while retaining OTA profile management functionality.
Data Source
AI summary
A method and an apparatus for installing a profile in a terminal including a universal integrated circuit card (UICC) corresponding to a smart card security module, which is inserted into a mobile communication terminal and then used are provided. More particularly, a method and an apparatus for remotely installing or removing mobile communication subscriber information in/from a profile of a terminal are provided. The terminal can remotely download the profile from a network server (subscription manager data preparation (SM-DP) or subscription manager secure routing (SM-SR)) without any change in a mobile network operator information technology (IT) system interface rather than downloading the profile of the terminal by the network server.


