Profile Transfer Between Secure Elements Using Cryptographic Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing UICC cards are proprietary and inflexible, making it difficult to manage authentication information and user data when switching between mobile network operators or devices, particularly in scenarios involving new terminal purchases or subscriptions/unsubscriptions, and there is a risk of illegitimate profile copying or duplication.

Innovation Solution

A method and system that utilizes embedded Secure Elements (eSEs) in mobile terminals, a profile provider, and profile managers to securely configure, transfer, and manage profiles, including encryption and signature-based authentication to prevent illegitimate copying, allowing seamless profile transfer between devices while updating authentication keys to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a proprietary UICC card is used for mobile network access, then authentication information can be stored securely, but flexibility to switch between network operators and devices is reduced

Engineering Contradiction:
Improveauthentication securityVSAvoidflexibility to switch operators/devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The UICC is divided into multiple independent profiles, each containing authentication information for different network operators. The profile manager can select and activate different profiles based on the user's needs, enabling flexible switching between operators while maintaining secure authentication through the same physical UICC card.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The UICC is designed to support multiple network operators and devices through a single card by storing multiple profiles. This multi-functional capability allows the same UICC to serve different purposes (different operators, different devices) without requiring separate physical cards for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple profiles are stored in a UICC to enable operator switching, then adaptability improves, but risk of illegitimate profile copying or duplication increases

Engineering Contradiction:
Improveoperator switching capabilityVSAvoidprofile copying risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary validation checks before allowing profile installation or activation. The profile manager verifies the authenticity and integrity of profiles through cryptographic validation, preventing illegitimate profiles from being copied or installed. This preemptive security measure blocks potential security breaches before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The profile manager acts as an intermediary between profiles and the UICC system, controlling profile installation, activation, and switching. It enforces security policies and validation rules, mediating all profile operations to prevent unauthorized copying or duplication while enabling legitimate multi-operator functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If profiles are transferred between devices, then ease of device change improves, but ensuring profile authenticity and preventing unauthorized access becomes more complex

Engineering Contradiction:
Improvedevice change simplicityVSAvoidprofile transfer security management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

Profiles are pre-configured with cryptographic authentication data and security parameters before being installed on the UICC. When transferring between devices, the profile manager automatically validates these pre-configured security elements, enabling seamless device changes while maintaining security without requiring complex real-time verification procedures.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3005092B1Method and apparatus for setting profile
Publication Date: 2024.12.04 SAMSUNG ELECTRONICS CO LTD
  • EP3005092B1 patent drawingFigure 1
  • EP3005092B1 patent drawingFigure 2
  • EP3005092B1 patent drawingFigure 3

AI summary

The present disclosure relates to a method and apparatus for setting profiles. In one embodiment, the profile setting method may include: receiving a profile transfer request that requests transfer of at least a portion of a first profile from a first secure element to a second secure element; sending a request message requesting at least a portion of the first profile to the first secure element; receiving at least a portion of the first profile from the first secure element; configuring a second profile using the received at least a portion of the first profile; sending the second profile to the second secure element; sending.