Profile Installation in Secured Element Security Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for creating and activating new security domains in secure elements, such as eUICC, face challenges in loading profiles while maintaining isolation and secure communication protocols, as per GSMA recommendations, where the parent security domain cannot load new profiles into child domains and cannot decrypt secure transport protocols.

Innovation Solution

A method involving a target security domain and a privileged security domain that communicates using a secure transport protocol, where the target domain receives an encrypted profile installation script, transfers it to the privileged domain for decryption, and then executes the script to install the profile, ensuring compliance with GSMA standards and isolation requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If the target security domain directly decrypts and executes the profile installation script received via secure transport protocol, then the profile installation process is simplified, but the target security domain would need to possess decryption capabilities that compromise its isolation and security constraints

Engineering Contradiction:
Improveprofile installation processVSAvoidsecurity domain isolation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces a privileged security domain as an intermediary between the secure transport protocol and the target security domain. The privileged domain decrypts the secure transport protocol to obtain the encrypted script, then transfers it to the target domain which decrypts it using its own key. This mediator approach allows the target domain to remain isolated while still enabling profile installation through controlled interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the decryption process into two distinct stages performed by different security domains. First, the privileged security domain decrypts the secure transport protocol layer. Second, the target security domain decrypts the encrypted script using its private key. This segmentation maintains security domain isolation while enabling the profile installation workflow.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the parent security domain can load profiles into child domains, then profile management is simplified, but the isolation between security domains is compromised

Engineering Contradiction:
Improveprofile managementVSAvoidsecurity domain isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The privileged security domain acts as a mediator that enables the parent domain to indirectly load profiles into child domains without direct access. The parent domain sends the encrypted script to the privileged domain, which then facilitates the transfer and decryption process, maintaining child domain isolation while enabling profile management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the decryption capability from the target security domain and places it in the privileged security domain. This extraction allows the target domain to maintain its isolation while still receiving and executing encrypted scripts through the privileged domain's assistance.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If the target security domain possesses the ability to decrypt the secure transport protocol, then the profile installation process is more direct, but the security constraints and isolation requirements are violated

Engineering Contradiction:
Improveprofile installation efficiencyVSAvoidsecurity constraint compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The decryption process is segmented into two layers: the privileged security domain handles secure transport protocol decryption, while the target security domain handles the encrypted script decryption. This segmentation maintains security constraints by preventing the target domain from accessing the secure transport protocol directly, while still enabling efficient profile installation through the coordinated two-stage process.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2957086B1Method for creating a profile in a security domain of a secured element
Publication Date: 2017.04.05 OBERTHUR TECH SA
  • EP2957086B1 patent drawing
  • EP2957086B1 patent drawing
  • EP2957086B1 patent drawing

AI summary

The invention relates to a method for creating a profile (P) in a target security domain (ISD-P) of a secured element (10), which comprises: a step (E10) of receiving, by means of said target security domain (ISD-P) and according to a secured protocol that cannot be interpreted by said security domain, data (DSP) comprising a script for installing said profile (P), which is encrypted with a key (KMNO) of the target security domain (IDS-P); a step (E20) of transferring data to a privileged security domain (IDS-R) capable of interpreting the protocol; a step (E30) of decrypting said protocol by means of said privileged security domain in order to obtain said encrypted script; a step (E40) of sending the encrypted script to said target security domain; a step (E50) of decrypting said script encrypted with said key and of executing said script by means of the target security domain (IDS-P), in order to install said profile (P).