Portable Secure Element Server for Offline eSIM Profile Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Subscription Manager Functionalities for eSIM profiles require an online connection between devices and servers, which is not feasible for unattended Machine-to-Machine (M2M) scenarios, and lack security measures to protect mobile network operators' interests.

Innovation Solution

A method for managing eSIM profiles and data packages using Portable Secure Element servers that enable offline transfer and management without an internet connection, utilizing local data transport protocols like peer-to-peer communication, ensuring secure and decentralized data handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If online connection is required for eSIM profile transfer between servers, then security measures can be implemented through centralized server control, but device complexity and cost increase due to always-on connectivity requirements

Engineering Contradiction:
ImprovesecurityVSAvoidconnectivity requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the SM-DP+ server functionality from remote online servers and embeds it into portable secure element devices. This allows the profile transfer server to operate locally offline, eliminating the need for constant internet connectivity while maintaining security through the secure element's hardware-based protection. The server functionality is taken out of the centralized cloud infrastructure and placed directly in the portable device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The portable secure element device acts as an intermediary between the eUICC and the profile management system. It locally hosts the SM-DP+ server functionality, serving as a mediator that enables offline profile operations while maintaining the security architecture. This intermediary approach allows the system to function without direct online connectivity to remote servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If portable secure elements are used for offline profile transfer, then process complexity is reduced and user experience improves, but security measures to protect MNO interests must be implemented without online connection

Engineering Contradiction:
Improveprocess complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-provisioning the portable secure element with the SM-DP+ server functionality and security credentials during manufacturing or initial setup. This allows the device to autonomously perform secure profile operations offline without requiring real-time online validation, thereby simplifying the user experience while maintaining security through pre-configured cryptographic protections.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The portable secure element with embedded SM-DP+ server functionality provides self-service capabilities for profile management. It can independently download, store, and transfer eSIM profiles without requiring continuous online authentication or intervention from remote servers, reducing process complexity while maintaining security through local cryptographic verification and secure element protection.

Inventive Principle:
Principle #25Self-service

3Reliability

If centralized online server is used for profile management, then security control is maintained, but M2M unattended scenarios cannot operate without user action

Engineering Contradiction:
Improvesecurity controlVSAvoidM2M unattended operation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts the SM-DP+ server functionality from centralized online servers and embeds it into portable secure element devices. This enables M2M devices to autonomously perform profile operations offline without requiring user action or continuous online connectivity, while the secure element maintains security control through hardware-based cryptographic protections.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The portable secure element with embedded SM-DP+ enables self-service operations for M2M devices. The system can automatically download, manage, and transfer profiles without user intervention or online server communication, adapting to unattended M2M scenarios while maintaining security through local cryptographic verification and secure element protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11997495B2Transfer functionality between secure elements servers
Publication Date: 2024.05.28 GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
  • US11997495B2 patent drawing
  • US11997495B2 patent drawing

AI summary

It is provided a method for transferring and managing data packages between a first portable secure element, SE, server implemented in a portable device (100, 200) and a second portable SE server implemented in an embedded UICC, eUICC (120, 240), comprised in a user's device (110, 230) which is local to the portable device (100, 200), the first and second portable SE severs comprising Subscription Manager, SM, functionalities, the method comprises the first and the second portable SE servers establishing off-line communication using local data transport protocols in a secured mode, the first or the second portable SE server implementing first transfer functionalities (140) for performing secure transfer of the data packages and the first or the second portable SE server implementing second transfer functionalities (140) for performing end-to-end securing of the data packages after the secure transfer of the data packages.