Secure Element Profile Provisioning with Pre-Installed Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional remote provisioning methods for secure elements in energy-constrained devices, such as eUICC and iUICC, are energy-intensive and require complex key agreement steps, leading to increased manufacturing costs and reduced flexibility due to the need for managing multiple SKUs for different mobile network operators.
Innovation Solution
Utilizing pre-installed encryption keys in the secure element to encrypt and decrypt bound profile packages, eliminating the need for key agreement steps during provisioning, allowing for secure and efficient remote installation of connectivity profiles in multiple sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional remote provisioning methods are used for secure elements, then connectivity profiles can be provisioned remotely, but the process is energy-intensive and requires complex key agreement steps
Solution Approach 1:
The patent applies preliminary action by pre-installing encryption keys in the secure element before the provisioning process. The secure element contains pre-configured key storage with encryption keys that are ready before remote provisioning occurs, eliminating the need for time-consuming key agreement steps during actual profile provisioning. This preliminary key installation enables energy-efficient remote provisioning by avoiding complex key negotiation protocols.
2Ease of operation
If conventional remote provisioning methods are used for secure elements, then connectivity profiles can be provisioned remotely, but key agreement steps increase device complexity
Solution Approach 1:
The patent applies preliminary action by pre-installing encryption keys in the secure element before the provisioning process. The secure element contains pre-configured key storage with encryption keys that are ready before remote provisioning occurs, eliminating the need for time-consuming key negotiation steps during actual profile provisioning. This preliminary key installation simplifies the device architecture by removing complex key agreement protocols.
Solution Approach 2:
The patent extracts the key agreement functionality from the provisioning process by using pre-installed keys. Instead of performing key agreement during provisioning, the system extracts and uses pre-configured keys that are already stored in the secure element's key storage, thereby removing the complex key agreement steps from the provisioning workflow.
3Productivity
If pre-installed keys are used for provisioning, then key agreement steps are eliminated, but security may be compromised if keys are not properly managed
Solution Approach 1:
The patent applies preliminary action by pre-installing encryption keys in the secure element before the provisioning process. The secure element contains pre-configured key storage with encryption keys that are ready before remote provisioning occurs, eliminating the need for time-consuming key negotiation steps during actual profile provisioning. This preliminary key installation enables energy-efficient remote provisioning by avoiding complex key negotiation protocols.
Solution Approach 2:
The patent uses key storage as an intermediary component that securely holds pre-installed encryption keys. The key storage acts as a protected intermediary between the provisioning system and the connectivity profiles, managing key access and ensuring that pre-installed keys are only used for their intended purpose of decrypting and installing profiles without exposing the keys to unauthorized access.
4Adaptability or versatility
If multiple connectivity profiles are stored in secure element, then device flexibility increases, but storage requirements increase
Solution Approach 1:
The patent applies segmentation by organizing connectivity profiles into separate, discrete entries within the secure element's storage. Each connectivity profile is stored as an independent unit with its own associated keys and metadata, allowing the system to manage multiple profiles efficiently without requiring contiguous large storage spaces. This segmentation enables flexible profile management and selective activation.
Solution Approach 2:
The patent implements universality by designing the secure element's key storage and profile management system to handle multiple types of connectivity profiles from different network operators. The pre-installed key infrastructure and profile storage mechanism are designed to universally support various profile formats and network operators, allowing a single secure element to store and activate multiple connectivity profiles without requiring operator-specific hardware configurations.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A method is provided for provisioning a secure element with a given connectivity profile for mobile network communication. The method comprises: receiving, at the secure element, a bound profile package specifying the given connectivity profile, the bound profile package being encrypted using an encryption key specific to the secure element; decrypting the bound profile package using a pre-installed key pre-installed in key storage of the secure element prior to initiation of a connectivity profile provisioning process for provisioning the secure element with the given connectivity profile; and installing the given connectivity profile from the decrypted bound profile package on the secure element.