Secure Element Configuration Over Encrypted Non-SMS Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Over-The-Air (OTA)-based methods for managing and updating Universal Integrated Circuit Cards (UICCs) or embedded UICCs (eUICCs) are expensive and require network coverage, limiting their effectiveness.
Innovation Solution
A method involving a secure element manager that uses a first interface for SMS communication and a second interface for a non-SMS communication channel secured with encryption keys to transmit configuration data, allowing data transmission even without cellular coverage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If OTA-based methods are used to manage and update UICCs or eUICCs, then configuration data can be transmitted securely, but the method requires network coverage and incurs expensive implementation costs
Solution Approach 1:
The patent introduces a host device as an intermediary between the OTA server and the secure element. The host device receives configuration data via SMS from the OTA server and then forwards it to the secure element through a secure interface. This intermediary approach allows the secure element to be configured even when not directly connected to the cellular network, as the host device can act as a relay using alternative communication channels like Wi-Fi.
Solution Approach 2:
The patent segments the configuration transmission process into two distinct parts: (1) receiving configuration data via SMS through the host device, and (2) forwarding the data to the secure element through a secure interface. This segmentation allows each component to operate independently - the SMS channel for initial receipt and the secure interface for final delivery - thereby eliminating the requirement for continuous network coverage at the secure element.
2Reliability
If traditional OTA methods are used, then configuration data can be transmitted to secure elements, but the infrastructure costs are expensive
Solution Approach 1:
The host device performs self-service by automatically receiving configuration data via SMS and forwarding it to the secure element without requiring additional infrastructure. The device utilizes existing SMS capabilities and secure interfaces already present in the system, eliminating the need for expensive dedicated OTA infrastructure while maintaining secure configuration transmission.
3Adaptability or versatility
If configuration data is transmitted via SMS channel, then it can reach the host device without network coverage, but the data must be secured using encryption keys
Solution Approach 1:
The encryption keys are pre-configured in both the host device and the secure element before the configuration transmission takes place. This preliminary setup eliminates the need for complex real-time key management during the actual configuration process. The host device can immediately encrypt the received SMS data using the pre-stored key and forward it to the secure element, simplifying the overall process despite the added security requirement.
Data Source
AI summary
A method for transmitting configuration data for a secure element is provided. The configuration data is generated in a secure element manager and the method comprises, securing the configuration data using a set of Over-The-Air, OTA, keys associated with the secure element, and transmitting the configuration data using a second interface to a second server for transmitting the configuration data over a non-SMS communications channel A communications network corresponding to the method is also provided. A method of receiving configuration data for a secure element at a host device is also provided. The method comprises receiving the configuration data using a data function for receiving configuration data over a non-SMS communications channel, processing the configuration data using a SIM application toolkit, and forwarding the processed configuration data to the secure element. A host device according to the method is also provided.


