Mobile Network Access Provisioning via Secure Payment Application

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for provisioning network access to mobile communication devices are inflexible, binding users to a single operator and lacking the ability for dynamic switching based on tariff, bandwidth, or network availability, with complex systems and increased storage and network load.

Innovation Solution

A method allowing users to select network operators on demand by using a mobile communication device with a secure payment application to request and pay for network access, download a network access application, and authenticate to the network, enabling flexible switching between different communication networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a SIM card with subscription identity information is used to bind a user to a specific network operator, then network security and operator control are improved, but user flexibility and the ability to dynamically switch between operators are worsened

Engineering Contradiction:
Improvenetwork securityVSAvoiduser flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication system into two parts: a secure element storing subscription credentials and a separate payment application enabling dynamic operator selection. This allows the SIM card to maintain security functions while adding flexibility through the payment application that can download credentials from different operators.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic operator selection capability where users can switch between network operators based on current needs. The system transitions from static SIM-bound authentication to a dynamic model where the payment application can acquire credentials from multiple operators, enabling real-time flexibility while maintaining security through the secure element.

Inventive Principle:
Principle #15Dynamics

2Ease of manufacture

If preliminary subscription identity information is stored in a secure processing module for over-the-air activation, then device manufacturing and registration are simplified, but the system complexity increases due to multiple authentication servers and credential servers

Engineering Contradiction:
Improvedevice manufacturingVSAvoidsystem complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent makes the secure element universal by enabling it to store credentials from multiple network operators, not just a single operator. The payment application acts as a multi-functional interface that can interact with different operators' credential servers, reducing the need for separate dedicated systems for each operator and simplifying the overall architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The payment application serves as an intermediary between the user device and multiple network operators. It manages the complexity of interacting with different credential servers and authentication systems, providing a unified interface for the user while handling the complex backend communications with various operators through standardized protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple authentication servers and credential servers are deployed for different network operators, then operator-specific authentication is enabled, but storage and network load on authentication servers increases

Engineering Contradiction:
Improveoperator selection capabilityVSAvoidserver storage and network load
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent extracts the credential storage function from the server infrastructure and places it in the user's secure element. Instead of servers storing all credentials for all operators, the system downloads only the necessary credentials to the device's secure element, significantly reducing server storage requirements and network load while maintaining the ability to access multiple operators.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary provisioning where the secure element is pre-configured with the capability to store operator credentials before the user actually needs them. The payment application can then quickly download and install specific operator credentials on-demand, avoiding the need for servers to maintain large databases of all possible operator credentials and reducing network traffic.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2437530B1Method for provisioning of a network access for a mobile communication device
Publication Date: 2019.01.30 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP2437530B1 patent drawingFigure 1
  • EP2437530B1 patent drawingFigure 2

AI summary

The invention refers to a method for provisioning of a network access for a mobile communication device (10) having at least one communication interface. A mobile communication device (10) comprising a secure payment application (15) in a secure environment (12) is provided. Network access from a network operator (20) with the mobile communication device (10) is requested. A payment to the network operator (20) for the requested network access using the secure payment application (15) is conducted. A network access application (16) from the network operator is downloaded and the network access application (16) in the secure environment of the mobile communication device (10) is stored wherein the network access application (16) is used for an authentication of the mobile communication device (10) to the mobile network (30).