eUICC Profile Administration via Role Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing M2M architecture for managing eUICCs is complex and not interoperable with B2C architectures, making it difficult for M2M service providers to modify administrative entities and manage access profiles remotely, especially in M2M use cases where secure links are limited to SM-SR servers.

Innovation Solution

A method and system that allow administrative entities to request and execute actions on access profiles by verifying certificates, enabling M2M service providers to define and modify administrative entities, and allowing the network operator to manage access profile downloads, thereby separating roles and enabling secure interactions between operators and M2M service providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the M2M architecture uses SM-SR entity as a checkpoint for all administrative actions, then security is maintained, but the complexity of the system increases and flexibility to modify administrative entities is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the administrative entity roles into two distinct types: SM-DP+ for profile download and installation, and SM-AP for profile administration actions. This segmentation eliminates the need for SM-SR to be a universal checkpoint, reducing system complexity while maintaining security through role-specific authentication mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic role assignment where administrative entities can be configured with specific permissions and roles. The system can dynamically determine which entity type (SM-DP+ or SM-AP) should handle specific administrative actions based on the request type, providing flexibility while maintaining security requirements.

Inventive Principle:
Principle #15Dynamics

2Reliability

If the M2M architecture requires SM-SR server for all profile administration, then access control is enforced, but the ability for M2M service providers to modify administrative entities is limited

Engineering Contradiction:
Improveaccess controlVSAvoidflexibility to modify administrative entities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal administrative framework where both SM-DP+ and SM-AP entities can perform administrative actions appropriate to their roles. M2M service providers can select and configure the appropriate entity type based on their needs, enabling flexibility while maintaining access control through the standardized certificate verification process.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the system uses certificate verification for administrative actions, then security is enhanced, but the processing time and complexity of action execution increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring administrative entities with their certificates and permissions before they need to perform actions. The security module stores and validates certificates in advance, so when administrative actions are requested, the verification process is streamlined and faster, reducing processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230016837A1Method for administering a profile for access to a communication network
Publication Date: 2023.01.19 ORANGE SA
  • US20230016837A1 patent drawing
  • US20230016837A1 patent drawing
  • US20230016837A1 patent drawing

AI summary

A method for administering a profile for access to a communication network by using a security module. The security module receives a request to perform an administrative action relating to an access profile originating from an administration entity. The request includes a certificate from the administration entity. The security module verifies that the certificate received is legitimate and that it carries information indicating that the entity is authorised to request the action and, if so, sends an authorisation to perform the action in conjunction with the administration entity. Otherwise, the security module rejects the request.