Secure Element Personalization via Data Generator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing process for personalizing secure elements in mobile terminals is inefficient, requiring a two-stage process where the operating system is loaded first, followed by profile data, which complicates production and lengthens delivery times, and lacks control for terminal manufacturers over the personalization process.

Innovation Solution

A method where a data generator receives requests for memory maps for multiple secure elements, obtains subscription data sets, generates memory maps including operating systems and subscription data, and bundles them for terminal manufacturers to personalize secure elements, allowing for pre-personalization and independent finishing processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the operating system is loaded first and then profile data is introduced into the secure element, then the secure element becomes operationally ready, but the production process is complicated and delivery time is lengthened

Engineering Contradiction:
Improveoperational readiness of secure elementVSAvoiddelivery time of terminals
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing the personalization of secure elements (loading operating system and profile data) before the secure elements are installed in terminals. The data generator creates personalized memory maps containing both the operating system and subscription data sets in advance, allowing terminal manufacturers to receive ready-to-use personalized secure elements without waiting for post-installation personalization, thus reducing delivery time while ensuring operational readiness

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If the terminal manufacturer personalizes the secure element themselves, then control over the personalization process is improved, but security control by the SE manufacturer is reduced

Engineering Contradiction:
Improvecontrol of terminal manufacturer over personalizationVSAvoidsecurity control of SE manufacturer
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a data generator as an intermediary between the SE manufacturer and the terminal manufacturer. The data generator receives requests from terminal manufacturers, obtains subscription data sets from subscription management servers, generates personalized memory maps, and delivers them to terminal manufacturers. This intermediary architecture allows terminal manufacturers to control the personalization process timing and content while the data generator maintains security controls through authenticated data delivery and encrypted transmissions

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If personalization is performed only after SE installation in terminal, then security control is maintained, but production efficiency is reduced

Engineering Contradiction:
Improvesecurity control during personalizationVSAvoidproduction efficiency of terminals
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables preliminary personalization of secure elements by the data generator before installation in terminals. Terminal manufacturers can receive multiple personalized memory maps in batch and install them efficiently. The security control is maintained through the data generator's authenticated delivery process and encrypted data transmission, while production efficiency improves because personalization no longer waits for post-installation timing

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the personalization process into distinct phases: (1) data generator obtains subscription data sets from subscription management servers, (2) data generator generates personalized memory maps containing operating system and profile data, (3) data generator delivers memory maps to terminal manufacturers, and (4) terminal manufacturers install personalized memory maps in secure elements. This segmentation allows parallel processing and batch operations, improving productivity while maintaining security controls at each stage

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240129743A1Method for personalizing a secure element
Publication Date: 2024.04.18 GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
  • US20240129743A1 patent drawing
  • US20240129743A1 patent drawing
  • US20240129743A1 patent drawing

AI summary

A method for personalizing a secure element, had the following steps: receiving, in a data generator, a request for a bundle of storage images for a plurality of secure elements; obtaining, in the data generator, at least one subscription data set for at least one securing element to be personalized of the plurality of secure elements; providing an operating system or a part of the operating system for the secure element to be personalized; generating, by means of the data generator, a storage image for each of the secure elements according to the received request; and bundling the generated storage image and providing the bundled storage image in the form of a storage image bundle by means of the data generator in order to complete the terminal, thereby introducing at least the storage image of the secure element to be personalized into the secure element.