eUICC Security Domain Segmentation for Operator Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Embedded UICC (eUICC) terminals are limited to a specific mobile network operator, making it difficult for users to change operators and increasing terminal production costs, as well as complicating the provision of value-added services due to their non-removable nature.
Innovation Solution
A smart card system with a first security domain sharing a key with a management server and multiple second security domains sharing keys with network operators, allowing for controlled activation and deactivation of security domains to facilitate changes in mobile network operators, using a Subscription Manager (SM) for remote provisioning and secure key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Volume of moving object
If eUICC is used to miniaturize terminals, then terminal size is reduced, but user ability to change mobile network operator is lost
Solution Approach 1:
The patent segments the UICC functionality into multiple security domains within the eUICC. Each security domain corresponds to a specific mobile network operator and can be independently activated or deactivated. This allows the terminal to maintain a single embedded eUICC for miniaturization while enabling multiple operator profiles to be stored and switched between, thus resolving the contradiction between reduced terminal size and operator changeability.
2Reliability
If ISD is used for card content management, then security is improved, but flexibility to change MNO is reduced
Solution Approach 1:
The patent introduces a dynamic control mechanism where the Issuer Security Domain (ISD) can selectively activate or deactivate specific security domains based on the desired mobile network operator. The ISD maintains security by controlling access to different operator-specific security domains, allowing the system to switch between operators dynamically while maintaining secure authentication. This resolves the contradiction by making the security system adaptable rather than static.
3Adaptability or versatility
If multiple security domains are added to support operator changes, then adaptability is improved, but device complexity increases
Solution Approach 1:
The patent creates a universal eUICC structure that can accommodate multiple security domains for different operators within a single chip. The ISD acts as a universal controller that manages all operator-specific security domains, providing a unified interface for authentication and key management. This multi-functional design allows the same eUICC to serve multiple operators without requiring separate physical cards, balancing adaptability with controlled complexity through standardized management protocols.
Data Source
AI summary
The present invention relates to modifying rights to a security domain for a smartcard, and more specifically, to a server for managing modification of rights to a security domain, a smartcard for modifying the rights to the security domain, a terminal which is loaded with the smartcard, and to a method for modifying the rights.


