Network Access Profile Distribution via Intermediary Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for obtaining a communication network access profile for a security module require numerous interactions with the operator's information system, making it cumbersome for users or pool managers to manage subscriptions, especially when dealing with multiple security modules or changes in operator subscriptions.

Innovation Solution

A method where a second user device with an existing access profile sends a message to a first user device to obtain an access profile for a first security module, using a contact address and datum to trigger a request to a server, which then downloads the access profile without needing an activation code or authentication, allowing direct command distribution without interacting with the subscription management system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the current method of obtaining access profile is used (connecting to operator portal, authenticating, searching subscription, requesting activation code), then the access profile can be obtained, but the process requires numerous interactions with the operator's information system making it cumbersome

Engineering Contradiction:
Improveease of obtaining access profileVSAvoidcomplexity of interaction with operator system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The invention extracts the essential elements needed for profile download (contact address and datum) from the complex operator portal interaction process. Instead of requiring users to navigate the entire operator information system, the second security module provides only the necessary extracted components to directly contact the profile download server, eliminating unnecessary intermediate steps and authentication requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The message sent from the second user device to the first user device acts as an intermediary carrier, transporting the contact address and datum without requiring the first user device to interact with the operator's subscription management system. This intermediary mechanism enables direct profile download while isolating the complex operator system interactions to a single initial authentication event.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the current method is used for multi-SIM offers, then multiple security modules can be managed, but users must repeatedly authenticate and interact with the portal making it time-consuming

Engineering Contradiction:
Improvespeed of managing multiple subscriptionsVSAvoidtime spent on repeated authentication
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The second security module performs preliminary action by storing the contact address and datum obtained during its initial authentication. This pre-stored information can be reused for subsequent profile downloads for additional security modules, eliminating the need for repeated authentication and portal interactions when managing multi-SIM offers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention enables copying of the essential access elements (contact address and datum) from one security module to another. Once these elements are obtained through authentication with one module, they can be copied and reused to trigger profile downloads for other security modules associated with the same subscription, dramatically reducing the time required to manage multiple SIMs.

Inventive Principle:
Principle #26Copying

3Ease of operation

If activation codes and authentication are required for each profile download, then security is maintained, but the process becomes cumbersome and requires contractual subscription numbers

Engineering Contradiction:
Improvesimplicity of profile download processVSAvoidsecurity of access profile distribution
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The message containing the contact address and datum serves as a secure intermediary that carries authentication evidence without requiring re-authentication. This intermediary mechanism maintains security by ensuring that only authorized devices (those that have previously authenticated and received valid credentials) can initiate profile downloads, while simplifying the user experience by eliminating repeated login requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11503474B2Technique for obtaining a network access profile
Publication Date: 2022.11.15 ORANGE SA
  • US11503474B2 patent drawing
  • US11503474B2 patent drawing

AI summary

Obtaining a communication network access profile for a first security module associated with a first user device. On receipt of a command for associating the first user device with a subscription with an operator including a second user device associated with a second security module, the second user device sends the first user device a message including a contact address of a server configured to provide by downloading an access profile and a datum allowing the server to interrogate a control server to obtain an order for downloading the access profile. This message triggers sending by the first security module a request for obtaining an access profile associated with the subscription, addressed to the contact address and having the datum. On obtaining an order, the access profile is downloaded into the first security module, a confirmation being sent by the first user device to the second user device.