Mobile Network Access Provisioning via Secure Payment Application
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for provisioning network access to mobile communication devices are inflexible, binding users to a single operator and lacking the ability for dynamic switching based on tariff, bandwidth, or network availability, with complex systems and increased storage and network load.
Innovation Solution
A method allowing users to select network operators on demand by using a mobile communication device with a secure payment application to request and pay for network access, download a network access application, and authenticate to the network, enabling flexible switching between different communication networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a SIM card with subscription identity information is used to bind a user to a specific network operator, then network security and operator control are improved, but user flexibility and the ability to dynamically switch between operators are worsened
Solution Approach 1:
The patent segments the authentication system into two parts: a secure element storing subscription credentials and a separate payment application enabling dynamic operator selection. This allows the SIM card to maintain security functions while adding flexibility through the payment application that can download credentials from different operators.
Solution Approach 2:
The patent introduces dynamic operator selection capability where users can switch between network operators based on current needs. The system transitions from static SIM-bound authentication to a dynamic model where the payment application can acquire credentials from multiple operators, enabling real-time flexibility while maintaining security through the secure element.
2Ease of manufacture
If preliminary subscription identity information is stored in a secure processing module for over-the-air activation, then device manufacturing and registration are simplified, but the system complexity increases due to multiple authentication servers and credential servers
Solution Approach 1:
The patent makes the secure element universal by enabling it to store credentials from multiple network operators, not just a single operator. The payment application acts as a multi-functional interface that can interact with different operators' credential servers, reducing the need for separate dedicated systems for each operator and simplifying the overall architecture.
Solution Approach 2:
The payment application serves as an intermediary between the user device and multiple network operators. It manages the complexity of interacting with different credential servers and authentication systems, providing a unified interface for the user while handling the complex backend communications with various operators through standardized protocols.
3Adaptability or versatility
If multiple authentication servers and credential servers are deployed for different network operators, then operator-specific authentication is enabled, but storage and network load on authentication servers increases
Solution Approach 1:
The patent extracts the credential storage function from the server infrastructure and places it in the user's secure element. Instead of servers storing all credentials for all operators, the system downloads only the necessary credentials to the device's secure element, significantly reducing server storage requirements and network load while maintaining the ability to access multiple operators.
Solution Approach 2:
The patent implements preliminary provisioning where the secure element is pre-configured with the capability to store operator credentials before the user actually needs them. The payment application can then quickly download and install specific operator credentials on-demand, avoiding the need for servers to maintain large databases of all possible operator credentials and reducing network traffic.
Data Source
Figure 1
Figure 2
AI summary
The invention refers to a method for provisioning of a network access for a mobile communication device (10) having at least one communication interface. A mobile communication device (10) comprising a secure payment application (15) in a secure environment (12) is provided. Network access from a network operator (20) with the mobile communication device (10) is requested. A payment to the network operator (20) for the requested network access using the secure payment application (15) is conducted. A network access application (16) from the network operator is downloaded and the network access application (16) in the secure environment of the mobile communication device (10) is stored wherein the network access application (16) is used for an authentication of the mobile communication device (10) to the mobile network (30).