Secure Element OS Update via MNO Profile Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing process for updating the operating system of secure elements like eUICC is complex, requiring close cooperation between secure element manufacturers and original equipment manufacturers, and lacks efficient mechanisms for delivering updates to devices without a FOTA platform.

Innovation Solution

The method involves generating a secure element OS update package in the format of a Trusted Connectivity Alliance (TCA) package, which is then provided to the secure element using mechanisms dedicated to MNO profile distribution, allowing the secure element to identify and execute the update.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a dedicated FOTA platform and OS update agent are implemented for secure element updates, then update capability is provided, but device complexity and integration requirements increase

Engineering Contradiction:
Improveupdate capabilityVSAvoidintegration requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the existing MNO profile distribution mechanism universal by enabling it to handle both MNO profile delivery and secure element OS updates through a single standardized interface, eliminating the need for separate FOTA platform infrastructure

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines the OS update delivery function with the existing MNO profile distribution mechanism, merging two separate functions into one unified process that uses the same transport and interface mechanisms

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If close cooperation and integration between EUM and OEM is required for OS updates, then update functionality is achieved, but ease of manufacture and deployment deteriorate

Engineering Contradiction:
Improveupdate functionalityVSAvoiddeployment process
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent enables the secure element to self-identify and self-execute OS updates by incorporating update indicators within the TCA package format, allowing the secure element to autonomously process updates without requiring external coordination between EUM and OEM systems

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The standardized TCA package format serves multiple purposes including both MNO profile delivery and OS update distribution, creating a universal mechanism that works across different manufacturers without requiring custom integration

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If specialized transport mechanisms and non-standard APDUs are used for OS updates, then update delivery is enabled, but device complexity and compatibility requirements increase

Engineering Contradiction:
Improveupdate deliveryVSAvoidtransport mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses the existing TCA package format, originally designed for MNO profile delivery, to also carry OS updates, thereby utilizing established standardized transport mechanisms instead of requiring new specialized protocols

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250199795A1Method and apparatus for updating a secure element operating system
Publication Date: 2025.06.19 IDEMIA FRANCE SAS
  • US20250199795A1 patent drawing
  • US20250199795A1 patent drawing
  • US20250199795A1 patent drawing

AI summary

The present invention concerns a method of updating a secure element operating system, OS, integrated in a device of an original equipment manufacturer, OEM, the secure element being manufactured by a secure element manufacturer, EUM, the method comprising: generating a secure element OS update; encapsulating the secure element OS update in a file; providing the file to the secure element; characterized in that: the file has the format of a Trusted Connectivity Alliance, TCA, package dedicated for mobile network operator, MNO, profile encapsulation; the file comprise indication indicating that it contains a secure element OS update; the file is provided to the secure element using mechanisms dedicated to MNO profile distribution; and that the method further comprises by the secure element: identifying the received file as a secure element OS update; and executing the secure element OS update.