Secure Element Profile Management for Verification Failures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing management of profiles in secure elements, such as eUICC cards, is not satisfactory as it does not effectively handle failures beyond loss of connection to the communication network, leading to unusability of the host device.

Innovation Solution

A method of managing profiles in a secure element that deactivates the active profile and activates a secondary profile upon detection of local verification failures, such as security or integrity issues, ensuring continuous connectivity by switching to a fall-back profile.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the existing profile management mechanism is used, then the secure element can handle connection loss to communication network, but it cannot handle other verification failures such as security or integrity issues

Engineering Contradiction:
Improveprofile management reliabilityVSAvoidfailure scenario coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its behavior based on the type of failure detected. When verification failures occur (security, integrity, or connection issues), the system automatically switches from the active profile to a fall-back profile, enabling it to handle multiple failure scenarios beyond just connection loss.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational parameter by switching between different profiles (active profile vs. fall-back profile) based on verification results. This parameter change allows the secure element to respond appropriately to different failure conditions by activating the suitable profile.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a fall-back mechanism is implemented for connection loss, then connectivity can be restored, but the system remains unusable when local verification failures occur

Engineering Contradiction:
Improveconnectivity restorationVSAvoiddevice usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The profile management system is segmented into distinct functional profiles: an active profile for normal operation and a fall-back profile for failure scenarios. This segmentation allows the system to maintain specialized handling for different failure types, ensuring both connectivity restoration and continued usability under various conditions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The fall-back profile is prepared in advance with the necessary configuration and credentials before any failure occurs. This preliminary action ensures that when verification failures happen (whether connection loss, security issues, or integrity problems), the system can immediately switch to a pre-configured fall-back profile without requiring complex real-time decision-making or additional user intervention.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the secure element switches to fall-back profile upon verification failure, then availability is restored, but the complexity of profile management increases

Engineering Contradiction:
Improvesecure element availabilityVSAvoidprofile management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure element performs self-service by automatically detecting verification failures and switching to the fall-back profile without requiring external intervention. This self-service capability maintains high availability while managing complexity internally within the secure element, preventing the complexity from propagating to the host device or user interface.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10715527B2Method of managing profiles in a secure element
Publication Date: 2020.07.14 IDEMIA FRANCE SAS
  • US10715527B2 patent drawing
  • US10715527B2 patent drawing
  • US10715527B2 patent drawing

AI summary

A method of managing profiles in a secure element where the secure element includes an active first profile associated with a first communication network and a second profile associated with a second communication network. The method includes deactivating the first profile and activating the second profile, where the deactivation and the activation are implemented following detection of a failure during a local verification pertaining to the first profile for the use of this the first profile. A local verification may be a verification in the secure element of the authorization of access of a user to the first profile, for example three failures of PIN or PUK code or of biometric authentication data, the local verification being performed in the secure element, and the failure being relative to a security failure of the first profile or to an operating failure of the first profile.