OS Update Platform for Secure Element Patching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Consumer secure elements, such as eUICCs or iUICCs, cannot be patched with operating system updates without direct access to an SM-SR platform, which is not feasible due to differences in architecture and lack of management capabilities in existing SM-DP platforms.
Innovation Solution
A method using an OS update platform exposing the ES9+ interface, allowing the secure element to receive and execute OS update scripts via the LPA, which connects using the ES9+ SM-DP+ protocol, downloads, installs, and returns execution results, enabling OS updates without relying on an SM-SR platform.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an SM-SR platform is used to patch the operating system on the secure element, then the patching can be performed transparently, but the architecture becomes complex and requires direct access to the SM-SR platform which is not feasible for consumer secure elements
Solution Approach 1:
The patent introduces an intermediary component called the 'OS update platform' that mediates between the secure element and the existing SM-DP+ platform. This intermediary enables OS patching functionality without requiring direct access to an SM-SR platform, thus resolving the contradiction by maintaining transparent patching capability while simplifying the overall architecture through the use of a dedicated update platform that leverages existing infrastructure.
Solution Approach 2:
The patent segments the update process into distinct components: the OS update platform handles patch distribution, the LPA (Local Profile Assistant) manages local operations, and the secure element executes updates. This segmentation allows each component to have well-defined responsibilities, reducing architectural complexity while maintaining reliable transparent patching through coordinated interaction between segmented functions.
2Ease of manufacture
If existing SM-DP platforms are used for OS updates, then the infrastructure is already in place, but they lack the necessary management capabilities for OS patches in their scope
Solution Approach 1:
The patent makes the OS update platform universal by enabling it to perform multiple functions: it interacts with the existing SM-DP+ infrastructure for profile management, simultaneously handles OS patch distribution and installation, and provides transparent updates to the secure element. This multi-functionality resolves the contradiction by extending the capabilities of the existing infrastructure to include OS patch management while maintaining ease of manufacture through reuse of existing components.
Solution Approach 2:
The patent merges the OS update functionality with the existing SM-DP+ platform infrastructure by having the OS update platform leverage the same communication protocols, security mechanisms, and management frameworks. This merging approach allows the system to benefit from both the availability of existing infrastructure and the added capability for OS patch management, resolving the contradiction through integration rather than separate systems.
3Adaptability or versatility
If proprietary commands are used to patch the secure element OS, then the EUM can implement custom updates, but the EUM generally doesn't own the SM-SR/SM-DP platforms and cannot manage OS patches
Solution Approach 1:
The patent introduces the OS update platform as an intermediary that enables EUMs to implement custom OS updates without needing to own or operate SM-SR/SM-DP platforms. The update platform handles the complex interactions with the secure element using proprietary commands while maintaining communication through standard ES9+ interfaces, thus providing custom update capability while reducing the complexity requirement around platform ownership.
Solution Approach 2:
The patent enables self-service by allowing EUMs to deploy custom OS update scripts directly through the OS update platform without requiring their own SM-SR or SM-DP infrastructure. The platform autonomously handles the update distribution, installation, and verification processes, enabling EUMs to provide tailored update solutions while avoiding the complexity of maintaining dedicated platform infrastructure.
4Adaptability or versatility
If M2M secure elements use the architecture from WO2020/201313, then patching is possible, but the architecture is not applicable to consumer secure elements due to differences in architecture and access capabilities
Solution Approach 1:
The patent applies parameter changes by adapting the update mechanism to match the specific capabilities of consumer secure elements. Instead of using the M2M architecture with direct SM-SR access, the system changes the interaction parameters to use ES9+ interfaces, LPA-based communication, and OS update scripts that are compatible with consumer eUICC/iUICC architecture, thus achieving patching capability while ensuring architecture compatibility.
Solution Approach 2:
The patent uses the OS update platform and LPA as intermediaries to bridge the architectural differences between M2M and consumer secure elements. These intermediaries translate and adapt the update commands into formats compatible with consumer secure element capabilities, enabling patching functionality while maintaining architecture compatibility through the mediating layers that accommodate different technical specifications.
Data Source
Figure 1
AI summary
The invention concerns a method to update an OS (102) installed in a secure element (106) thanks to an OS update platform (104) exposing the same ES9+ interface as an SM- DP+, the secure element (106) being an eUICC or an iUICC cooperating with a terminal, the secure element and the terminal being comprised in a device, the method comprising: Loading an OS update script (102) in the OS update platform (104) of the secure element manufacturer (100); Triggering the LPA (105) of the terminal to connect to the OS update platform (104) by using the ES9+ SM-DP+ protocol; Downloading by the LPA (105) the OS update script (102) in an ISD-P (107) of the secure element (106) and installing the OS update script (102) in the ISD-P (107) of the secure element (106); After the installation of the OS update script (102) in the ISD-P (107), return by the secure element (106) an execution result to the OS update platform (104) through the LPA (105).