Remote Identity Module Provisioning via Trusted Environment Brokerage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current manual or semi-automated procedures for provisioning identity modules in mobile devices are inefficient, non-scalable, and user-unfriendly, especially for machine-to-machine (M2M) and connected consumer electronics, and there is a need to select the appropriate Trusted Environment (TRE) for downloadable identity modules in devices with multiple TREs.

Innovation Solution

A method and apparatus for selecting a Trusted Environment from multiple available environments in a mobile device for provisioning a downloadable identity module, where the Registration Operator acts as a broker to choose the most favorable home operator and TRE, enabling flexible hardware configuration and decoupling access and service authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual or semi-automated provisioning procedures are used, then provisioning can be completed with existing systems, but the process is inefficient and non-scalable

Engineering Contradiction:
Improveprovisioning efficiencyVSAvoidautomation level
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system enables self-service provisioning where the mobile device automatically discovers available Trusted Environments and selects the appropriate one without manual intervention. The device autonomously communicates with the registration operator to complete the provisioning process, eliminating the need for manual configuration by sales personnel or partial automation via PoS systems.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If a mobile device has multiple Trusted Environments, then hardware configuration flexibility is improved, but the complexity of selecting the appropriate TRE increases

Engineering Contradiction:
Improvehardware configuration flexibilityVSAvoidTRE selection complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The registration operator acts as an intermediary between the mobile device and the multiple Trusted Environments. The device provides a list of available TREs to the registration operator, which then determines the most favorable TRE based on operator policies and requirements. This mediates the complexity by centralizing the selection logic in the network rather than the device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically selects the appropriate Trusted Environment based on real-time conditions and requirements. The selection is not fixed but adapts to the specific provisioning scenario, allowing the most suitable TRE to be chosen for each identity module download operation.

Inventive Principle:
Principle #15Dynamics

3Productivity

If remote provisioning is implemented, then scalability and user-friendliness are improved, but the need for TRE selection mechanisms in multi-TRE devices creates additional system complexity

Engineering Contradiction:
Improveprovisioning scalabilityVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The registration operator serves as a mediator that receives information about available TREs from the mobile device and determines the optimal selection. This intermediary approach enables remote provisioning to scale across multiple TREs without requiring complex device-side selection logic, as the registration operator centralizes the decision-making process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2656573B1Remote provisioning of a downloadable identity module into one of several trusted environments
Publication Date: 2020.06.03 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2656573B1 patent drawingFigure 1
  • EP2656573B1 patent drawingFigure 2
  • EP2656573B1 patent drawingFigure 3A~3C

AI summary

This invention relates to methods and apparatuses for implementing remote provisioning of a downloadable identity module into one of several Trusted Environments (7) available at a mobile device (1). A server (2) performs a selection of one of the Trusted Environments (7) available at the mobile device (1) for which at least one of one or more home operators (3) can provide downloadable identity modules, selects one of the one or more home operators (3) which can provide downloadable identity modules for the selected Trusted Environment, and manages the provisioning of a downloadable identity module to the mobile device (1).