LPA Module Access Control for eUICC via OS API

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of a Local Profile Assistant (LPA) function into the Operating System (OS) of devices poses challenges such as the need for OS updates, restricted LPA functions, and complex system modifications for operators, especially during LPA upgrades, which limits adaptability and flexibility in managing eUICC profiles across different devices and operators.

Innovation Solution

An access control method where an LPA module on the application layer receives control instructions and invokes the OS API to manage eUICC operations, with the OS determining permission based on access control rules, allowing secure and flexible management of eUICC operations without requiring OS upgrades or system modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the LPA function is integrated into the OS, then the LPA can manage eUICC profiles, but the OS requires updates for LPA upgrades and system modifications become complex

Engineering Contradiction:
ImproveLPA adaptability to different devicesVSAvoidSystem modification complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent separates the LPA function from the OS by placing it in the application layer. The LPA is implemented as an independent application that communicates with the OS through standardized interfaces, allowing the LPA to be updated independently without requiring OS updates or complex system modifications.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the LPA function is integrated into the OS, then the LPA can access eUICC, but the operator needs to adapt LPAs for different terminal devices

Engineering Contradiction:
ImproveLPA access to eUICCVSAvoidLPA adaptability to different terminals
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal LPA implementation in the application layer that can operate across different terminal devices through standardized OS interfaces. The LPA uses common communication protocols and APIs that work across multiple device types, eliminating the need for device-specific LPA adaptations while maintaining ease of eUICC access.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If the LPA is upgraded, then the LPA function improves, but the subscriber needs to update the OS

Engineering Contradiction:
ImproveLPA function improvementVSAvoidOS update time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent segments the LPA into an independent application layer component separated from the OS. This allows the LPA to be upgraded independently as a standalone application without requiring OS updates, significantly reducing update time and allowing immediate deployment of LPA improvements.

Inventive Principle:
Principle #1Segmentation

4Ease of manufacture

If the LPA function is integrated into the OS, then the LPA can be implemented, but functions of the LPA are restricted

Engineering Contradiction:
ImproveLPA implementationVSAvoidLPA function flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements the LPA as a dynamic application layer component that can adapt its functionality based on runtime conditions and requirements. The LPA can dynamically load different modules, adjust its behavior, and extend its functions without being constrained by fixed OS integration, thereby increasing functional flexibility while maintaining ease of implementation through standardized interfaces.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3537329B1Access control method and system, electronic device, and computer storage medium
Publication Date: 2020.09.16 CHINA MOBILE COMM GRP CO LTD
  • EP3537329B1 patent drawingFigure 1
  • EP3537329B1 patent drawingFigure 2
  • EP3537329B1 patent drawingFigure 3

AI summary

Provided are an access control method and system, an electronic device, and a computer storage medium. The method comprises: a Local Profile Assistant (LPA) module located in an application layer of an electronic device receiving a control instruction (201), the control instruction being used to instruct that a control operation be performed on an embedded Universal Integrated Circuit Card (eUICC); in response to the control instruction, the LPA module invoking an Application Programming Interface (API) of an Operation System (OS) of the electronic device, to send corresponding information or command to the eUICC (202); when the API of the OS is invoked, the OS determining, based on an access control rule, whether the LPA module has permission to access the eUICC; and upon determining that the LPA module has permission to access the eUICC, sending the corresponding information or command to the eUICC (203), such that the eUICC performs an operation on the corresponding information or command.