Network Access Profile Distribution via Intermediary Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for obtaining a communication network access profile for a security module require numerous interactions with the operator's information system, making it cumbersome for users or pool managers to manage subscriptions, especially when dealing with multiple security modules or changes in operator subscriptions.
Innovation Solution
A method where a second user device with an existing access profile sends a message to a first user device to obtain an access profile for a first security module, using a contact address and datum to trigger a request to a server, which then downloads the access profile without needing an activation code or authentication, allowing direct command distribution without interacting with the subscription management system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the current method of obtaining access profile is used (connecting to operator portal, authenticating, searching subscription, requesting activation code), then the access profile can be obtained, but the process requires numerous interactions with the operator's information system making it cumbersome
Solution Approach 1:
The invention extracts the essential elements needed for profile download (contact address and datum) from the complex operator portal interaction process. Instead of requiring users to navigate the entire operator information system, the second security module provides only the necessary extracted components to directly contact the profile download server, eliminating unnecessary intermediate steps and authentication requirements.
Solution Approach 2:
The message sent from the second user device to the first user device acts as an intermediary carrier, transporting the contact address and datum without requiring the first user device to interact with the operator's subscription management system. This intermediary mechanism enables direct profile download while isolating the complex operator system interactions to a single initial authentication event.
2Productivity
If the current method is used for multi-SIM offers, then multiple security modules can be managed, but users must repeatedly authenticate and interact with the portal making it time-consuming
Solution Approach 1:
The second security module performs preliminary action by storing the contact address and datum obtained during its initial authentication. This pre-stored information can be reused for subsequent profile downloads for additional security modules, eliminating the need for repeated authentication and portal interactions when managing multi-SIM offers.
Solution Approach 2:
The invention enables copying of the essential access elements (contact address and datum) from one security module to another. Once these elements are obtained through authentication with one module, they can be copied and reused to trigger profile downloads for other security modules associated with the same subscription, dramatically reducing the time required to manage multiple SIMs.
3Ease of operation
If activation codes and authentication are required for each profile download, then security is maintained, but the process becomes cumbersome and requires contractual subscription numbers
Solution Approach 1:
The message containing the contact address and datum serves as a secure intermediary that carries authentication evidence without requiring re-authentication. This intermediary mechanism maintains security by ensuring that only authorized devices (those that have previously authenticated and received valid credentials) can initiate profile downloads, while simplifying the user experience by eliminating repeated login requirements.
Data Source
AI summary
Obtaining a communication network access profile for a first security module associated with a first user device. On receipt of a command for associating the first user device with a subscription with an operator including a second user device associated with a second security module, the second user device sends the first user device a message including a contact address of a server configured to provide by downloading an access profile and a datum allowing the server to interrogate a control server to obtain an order for downloading the access profile. This message triggers sending by the first security module a request for obtaining an access profile associated with the subscription, addressed to the contact address and having the datum. On obtaining an order, the access profile is downloaded into the first security module, a confirmation being sent by the first user device to the second user device.

