Security Domain Management in eUICC Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for managing security domains in mobile communications systems, particularly for embedded universal integrated circuit cards (eUICC), lack the ability to dynamically add or remove configuration information and security domains based on the status of user-subscribed services, leading to inefficient service management.

Innovation Solution

A security domain management system and method that includes a communications terminal and server, capable of obtaining and processing management requests to create, manage, and delete security subdomains within a mobile network operator profile, using an issuer security domain profile identifier to store and update configuration information of services based on subscription status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security domain is created for each service in the eUICC, then service security requirements are met, but the complexity of managing security domains increases when services are added or removed

Engineering Contradiction:
Improveservice securityVSAvoidsecurity domain management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security domain is segmented into multiple components: the profile identifier, service configuration information, and security parameters are separated into distinct data structures. This allows individual services to be managed independently within the overall security domain, reducing management complexity while maintaining security integrity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security domain management system implements dynamic creation and deletion of service configurations based on real-time service status. When a service is subscribed, its configuration is automatically created; when a service ends, its configuration is automatically deleted. This dynamic approach adapts the security domain structure to current service requirements without manual intervention.

Inventive Principle:
Principle #15Dynamics

2Reliability

If manual management of security domains is implemented, then security control is precise, but the time and operational effort required for adding/removing service configurations increases

Engineering Contradiction:
Improvesecurity control precisionVSAvoidservice configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-establishes the framework for security domain management including the profile identifier structure and the automated triggers for service events. When services are subscribed or terminated, the pre-configured automated processes immediately execute the appropriate actions (creation or deletion of service configurations) without requiring manual security control steps, thus maintaining precision while reducing time loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms that automatically detect service status changes (subscription or termination) and trigger corresponding security domain updates. This closed-loop feedback system ensures that security configurations are always synchronized with actual service states, maintaining control precision while eliminating manual operational delays.

Inventive Principle:
Principle #23Feedback

3Loss of information

If the eUICC stores all service configuration information, then complete service data is available, but the storage space consumption increases with each additional service

Engineering Contradiction:
Improveservice configuration completenessVSAvoidstorage space
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The system extracts and stores only the essential service configuration information and security parameters in the eUICC security domain, rather than storing complete service data. Non-essential or redundant configuration data is excluded from storage, reducing the quantity of stored information while maintaining the completeness of critical service configuration data needed for secure operation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3171566B1Method, device and system for security domain management
Publication Date: 2019.10.09 HUAWEI TECH CO LTD
  • EP3171566B1 patent drawingFigure 1~3
  • EP3171566B1 patent drawingFigure 4~5
  • EP3171566B1 patent drawingFigure 6~7

AI summary

The present invention provides a security domain management method, apparatus, and system, which relate to the communications field, and can manage, according to a service status of a user-subscribed service, a security domain used for storing service configuration information. A specific solution is as follows: A communications terminal obtains a management request message sent by a server, where the management request message includes an issuer security domain profile identifier; and the communications terminal manages a security subdomain in a mobile network operator profile corresponding to the issuer security domain profile identifier, where the security subdomain is used to store configuration information of a first service. The present invention is used for security domain management.