Secure Element OTA Subscription Profile Assembly
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods do not efficiently allow for over-the-air reprogramming of secure elements like SIMs in mobile terminals, especially for M2M communications, as they require complete subscription profiles including credentials, applications, and operating system components, which is cumbersome and not supported by existing technologies.
Innovation Solution
A method and system that assemble and provide a subscription profile over-the-air to secure elements, comprising network-specific and hardware-specific portions, using a two-server architecture where one server handles network-specific components and the other handles hardware-specific components, with encryption and mutual authentication to ensure secure and compatible profile updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If complete subscription profiles including credentials, applications, and operating system components are provided over-the-air, then secure element reprogramming is enabled, but the process becomes cumbersome and complex
Solution Approach 1:
The subscription profile is divided into multiple components: network-specific portion (PLMN identity, authentication credentials) and hardware-specific portion (terminal identity, device parameters). These segments are provided through separate signaling procedures, reducing the complexity of providing the complete profile at once and enabling incremental updates.
Solution Approach 2:
The terminal determines hardware-specific information about itself before receiving the network-specific subscription profile. This preliminary action allows the terminal to be pre-configured with device identifiers and capabilities, so that when the network profile is provided over-the-air, the complete subscription profile can be assembled automatically without manual intervention.
2Reliability
If manual SIM replacement is required to switch between mobile network operators, then authentication security is maintained, but user convenience deteriorates
Solution Approach 1:
The mechanical process of physically replacing SIM cards is replaced with an electronic over-the-air provisioning system. The network-specific subscription profile is transmitted wirelessly to the terminal and written to the secure element through authenticated signaling, eliminating the need for manual SIM card handling while maintaining security through cryptographic authentication procedures.
3Adaptability or versatility
If subscription credentials are stored in surface mounted chips without pre-personalization, then M2M device flexibility is improved, but the ability to provide credentials beforehand is lost
Solution Approach 1:
The terminal device determines hardware-specific information (device identity, capabilities, parameters) during manufacturing or initial setup, before the actual network subscription profile is provided. This preliminary configuration enables the device to receive and process network credentials over-the-air without requiring pre-personalization of the secure element, facilitating flexible M2M device deployment.
Solution Approach 2:
The terminal autonomously determines its own hardware-specific information and assembles the complete subscription profile by combining received network-specific data with its own hardware characteristics. This self-service capability eliminates the need for manual credential provisioning during manufacturing, allowing M2M devices to be configured remotely and dynamically.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a method of providing a secure element (20) of a mobile terminal (12) with a subscription profile (SUB). The mobile terminal (12) is configured to communicate with a cellular communications network and the subscription profile (SUB) comprises a network specific portion related to the cellular communications network or a different cellular communications network as well as a hardware specific portion related to the hardware of the mobile terminal and/ or the secure element. The method comprises the steps of: assembling the subscription profile (SUB), wherein the network specific portion of the subscription profile is provided by a first server (42) and the hardware specific portion of the subscription profile is provided by a second server (44); and providing the subscription profile (SUB) over-the-air to the secure element (20). Moreover, the invention relates to a corresponding secure element (20), mobile terminal (12) and subscription management backend system.