Secure Element Subscription Management Interface
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for providing secure elements, such as SIMs or eUICCs, in mobile terminals with subscription profiles are hindered by incompatibility issues between the subscription management interfaces and the proprietary formats used by mobile network operators and secure element manufacturers, particularly in M2M communication scenarios where secure provisioning over-the-air is necessary.
Innovation Solution
A method that involves providing a subscription management interface to the secure element, allowing it to process subscription data in the format defined by the target mobile network operator, while maintaining proprietary methods and formats, and enabling secure over-the-air reprogramming of the subscription profile.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the secure element manufacturer implements proprietary subscription management interfaces and formats, then security and manufacturing control are improved, but compatibility with mobile network operators' formats deteriorates
Solution Approach 1:
The subscription profile is segmented into two distinct parts: a subscription management interface (SMI) that handles format conversion and coordination, and subscription data in operator-defined format that contains the actual credentials. This segmentation allows the secure element to maintain proprietary security mechanisms while enabling compatibility with multiple network operators through the interface layer.
Solution Approach 2:
The subscription management interface acts as an intermediary between the mobile network operator's proprietary format and the secure element's internal processing format. It receives subscription data in the operator's format, processes it through format conversion, and delivers it to the secure element without requiring the operator to know the secure element's proprietary formats, thus resolving the compatibility conflict.
2Reliability
If manual SIM replacement is required for switching mobile network operators, then security control is improved, but ease of operation deteriorates
Solution Approach 1:
The mechanical process of physically replacing SIM cards is replaced with an electronic/over-the-air provisioning system. The subscription profile can be downloaded and installed remotely through the subscription management interface, eliminating the need for manual SIM card handling while maintaining security through controlled authentication and encryption mechanisms.
Solution Approach 2:
The system enables self-service operator switching where the mobile terminal can automatically download and install new subscription profiles from target network operators without requiring user intervention for physical SIM replacement. The subscription management interface handles the entire process automatically, from receiving the operator's format data to implementing it on the secure element.
3Ease of manufacture
If over-the-air provisioning is implemented for M2M devices, then ease of manufacture is improved, but security risks worsen
Solution Approach 1:
The subscription management interface is pre-configured in the secure element with authentication capabilities and format conversion functions before deployment. This preliminary setup ensures that over-the-air provisioning operations are performed through secure, pre-authenticated channels with built-in validation mechanisms, reducing security risks while maintaining ease of manufacture.
Solution Approach 2:
The subscription management interface serves as a secure intermediary that mediates all over-the-air communication between network operators and the secure element. It implements authentication, authorization, and format conversion in a controlled manner, preventing direct access to sensitive credentials and mitigating security risks associated with remote provisioning.
Data Source
AI summary
A method for providing a secure element having a processor and a memory of a mobile terminal with a target subscription profile for communicating via a target mobile network comprises the steps of: providing as a first part of the target subscription profile a subscription management interface to the secure element; implementing the subscription management interface on the secure element; and providing as a second part of the target subscription profile subscription data in a format defined by the operator of the target mobile network to the secure element, wherein the subscription management interface allows the secure element to process the subscription data and to implement the target subscription profile thereon for allowing access to the target mobile network. A corresponding secure element, mobile terminal and subscription management backend system includes features associated with the method.

