Portable Secure Element Server for Offline eSIM Profile Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current GSMA Subscription Manager Functionalities for eSIM profiles require an online connection between the user's device and the Subscription Management server, which is not feasible for unattended M2M devices, and lack secure offline management solutions for mobile operator profiles.
Innovation Solution
Implementing a Portable Secure Element (SE) server local to the eUICC receiver, enabling offline management of eSIM profiles and subscriptions using peer-to-peer protocols like NFC or Bluetooth, allowing secure downloading, installation, and management without an internet connection, and supporting GSMA specifications for both consumer and M2M use cases.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an online connection is used between the user's device and the Subscription Management server, then secure profile management can be achieved, but the system requires constant internet connectivity which is not feasible for unattended M2M devices
Solution Approach 1:
A portable secure element server acts as an intermediary between the eUICC receiver and the remote Subscription Management server. This local server enables offline profile management operations by caching profiles and authentication data locally, while still maintaining security through encrypted communication protocols when online connectivity is available.
Solution Approach 2:
The system segments the Subscription Management functionality into two parts: a remote server for initial profile distribution and a local portable secure element server for offline management. This segmentation allows the device to perform profile installation and management operations without requiring continuous online connectivity.
2Extent of automation
If a remote Subscription Management server is used, then centralized control can be maintained, but the system complexity and cost increase due to required online connectivity infrastructure
Solution Approach 1:
The portable secure element server serves as a local intermediary that implements Subscription Manager functionalities, reducing the need for complex online infrastructure. It handles profile installation, activation, and management locally, simplifying the overall system architecture while maintaining centralized control through periodic synchronization with the remote server.
3Adaptability or versatility
If offline profile management is implemented, then internet connection requirements are reduced, but security measures must be strengthened to protect mobile network operator interests
Solution Approach 1:
Security credentials, encryption keys, and authentication data are pre-loaded into the portable secure element server during manufacturing or initial provisioning. This preliminary action ensures that the offline server has the necessary security materials to protect profile management operations without requiring real-time connection to the home network.
Solution Approach 2:
The system uses disposable or replaceable secure element modules that can be securely provisioned offline. These modules contain embedded security credentials and can be replaced if compromised, providing a cost-effective security solution that doesn't require complex continuous verification infrastructure.
Data Source
Figure 1
Figure 2
AI summary
Method for managing eSIM profiles in a user's device (110, 230) comprising an embedded UICC, eUICC, the method performed by a portable secure element, SE, server implemented in a portable device (100, 200) local to the user's device (110, 230), the portable SE sever comprising Subscription Manager, SM, functionalities, the method comprises the portable SE server establishing off-line communication with the user's device (100) using local data transport protocols in a secured mode, the portable SE server implementing first SM functionalities (140) for performing secure downloading of the eSIM profiles in the user's device (110) and the portable SE server implementing second SM functionalities (160) for performing end-to-end securing of the eSIM profiles after installation in the eUICC of the user's device (110, 230).