Profile Transfer Between Secure Elements Using Cryptographic Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing UICC cards are proprietary and inflexible, making it difficult to manage authentication information and user data when switching between mobile network operators or devices, particularly in scenarios involving new terminal purchases or subscriptions/unsubscriptions, and there is a risk of illegitimate profile copying or duplication.
Innovation Solution
A method and system that utilizes embedded Secure Elements (eSEs) in mobile terminals, a profile provider, and profile managers to securely configure, transfer, and manage profiles, including encryption and signature-based authentication to prevent illegitimate copying, allowing seamless profile transfer between devices while updating authentication keys to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a proprietary UICC card is used for mobile network access, then authentication information can be stored securely, but flexibility to switch between network operators and devices is reduced
Solution Approach 1:
The UICC is divided into multiple independent profiles, each containing authentication information for different network operators. The profile manager can select and activate different profiles based on the user's needs, enabling flexible switching between operators while maintaining secure authentication through the same physical UICC card.
Solution Approach 2:
The UICC is designed to support multiple network operators and devices through a single card by storing multiple profiles. This multi-functional capability allows the same UICC to serve different purposes (different operators, different devices) without requiring separate physical cards for each scenario.
2Adaptability or versatility
If multiple profiles are stored in a UICC to enable operator switching, then adaptability improves, but risk of illegitimate profile copying or duplication increases
Solution Approach 1:
The system performs preliminary validation checks before allowing profile installation or activation. The profile manager verifies the authenticity and integrity of profiles through cryptographic validation, preventing illegitimate profiles from being copied or installed. This preemptive security measure blocks potential security breaches before they can occur.
Solution Approach 2:
The profile manager acts as an intermediary between profiles and the UICC system, controlling profile installation, activation, and switching. It enforces security policies and validation rules, mediating all profile operations to prevent unauthorized copying or duplication while enabling legitimate multi-operator functionality.
3Ease of operation
If profiles are transferred between devices, then ease of device change improves, but ensuring profile authenticity and preventing unauthorized access becomes more complex
Solution Approach 1:
Profiles are pre-configured with cryptographic authentication data and security parameters before being installed on the UICC. When transferring between devices, the profile manager automatically validates these pre-configured security elements, enabling seamless device changes while maintaining security without requiring complex real-time verification procedures.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure relates to a method and apparatus for setting profiles. In one embodiment, the profile setting method may include: receiving a profile transfer request that requests transfer of at least a portion of a first profile from a first secure element to a second secure element; sending a request message requesting at least a portion of the first profile to the first secure element; receiving at least a portion of the first profile from the first secure element; configuring a second profile using the received at least a portion of the first profile; sending the second profile to the second secure element; sending.