Secure Element Subscription Management Interface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for providing secure elements, such as SIMs or eUICCs, in mobile terminals with subscription profiles are hindered by incompatibility issues between the subscription management interfaces and the proprietary formats used by mobile network operators and secure element manufacturers, particularly in M2M communication scenarios where secure provisioning over-the-air is necessary.

Innovation Solution

A method that involves providing a subscription management interface to the secure element, allowing it to process subscription data in the format defined by the target mobile network operator, while maintaining proprietary methods and formats, and enabling secure over-the-air reprogramming of the subscription profile.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the secure element manufacturer implements proprietary subscription management interfaces and formats, then security and manufacturing control are improved, but compatibility with mobile network operators' formats deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcompatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The subscription profile is segmented into two distinct parts: a subscription management interface (SMI) that handles format conversion and coordination, and subscription data in operator-defined format that contains the actual credentials. This segmentation allows the secure element to maintain proprietary security mechanisms while enabling compatibility with multiple network operators through the interface layer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The subscription management interface acts as an intermediary between the mobile network operator's proprietary format and the secure element's internal processing format. It receives subscription data in the operator's format, processes it through format conversion, and delivers it to the secure element without requiring the operator to know the secure element's proprietary formats, thus resolving the compatibility conflict.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual SIM replacement is required for switching mobile network operators, then security control is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidconvenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mechanical process of physically replacing SIM cards is replaced with an electronic/over-the-air provisioning system. The subscription profile can be downloaded and installed remotely through the subscription management interface, eliminating the need for manual SIM card handling while maintaining security through controlled authentication and encryption mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service operator switching where the mobile terminal can automatically download and install new subscription profiles from target network operators without requiring user intervention for physical SIM replacement. The subscription management interface handles the entire process automatically, from receiving the operator's format data to implementing it on the secure element.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If over-the-air provisioning is implemented for M2M devices, then ease of manufacture is improved, but security risks worsen

Engineering Contradiction:
Improveprovisioning capabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The subscription management interface is pre-configured in the secure element with authentication capabilities and format conversion functions before deployment. This preliminary setup ensures that over-the-air provisioning operations are performed through secure, pre-authenticated channels with built-in validation mechanisms, reducing security risks while maintaining ease of manufacture.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The subscription management interface serves as a secure intermediary that mediates all over-the-air communication between network operators and the secure element. It implements authentication, authorization, and format conversion in a controlled manner, preventing direct access to sensitive credentials and mitigating security risks associated with remote provisioning.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10492075B2Methods and devices for providing a secure element with a subscription profile
Publication Date: 2019.11.26 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • US10492075B2 patent drawing
  • US10492075B2 patent drawing

AI summary

A method for providing a secure element having a processor and a memory of a mobile terminal with a target subscription profile for communicating via a target mobile network comprises the steps of: providing as a first part of the target subscription profile a subscription management interface to the secure element; implementing the subscription management interface on the secure element; and providing as a second part of the target subscription profile subscription data in a format defined by the operator of the target mobile network to the secure element, wherein the subscription management interface allows the secure element to process the subscription data and to implement the target subscription profile thereon for allowing access to the target mobile network. A corresponding secure element, mobile terminal and subscription management backend system includes features associated with the method.