Secure Element Startup via Status Message Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods fail to enable successful first-time startup of not fully personalized secure elements in mobile terminals, particularly integrated UICCs, due to rejection by the baseband processor and inability to download firmware images, and lack suitable methods for network binding with specific restrictions.

Innovation Solution

A method that initiates the first-time startup of a not fully personalized secure element by transmitting status messages to determine its state and initiate firmware downloads, and includes using a generic bootloader to load a start UICC with rules for selecting subscription data, ensuring network binding and secure operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a not fully personalized secure element with only a bootloader is used, then the device can be distributed with a generic bootloader allowing loading of iUICCs of various network operators, but the baseband processor rejects the secure element and prevents firmware image download

Engineering Contradiction:
Improvecompatibility with various network operatorsVSAvoidsuccessful startup and firmware download
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by having the secure element proactively transmit a status message during startup indicating it contains only a bootloader. This allows the baseband processor to anticipate the situation and prevent rejection before it occurs, enabling the firmware download process to proceed correctly.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by having the secure element communicate its state (containing only bootloader) to the baseband processor through a status message. This feedback loop allows the baseband processor to adjust its behavior accordingly, accepting the secure element and initiating the appropriate firmware download procedure rather than rejecting it.

Inventive Principle:
Principle #23Feedback

2Reliability

If a fully personalized UICC is used, then the mobile terminal can access services made available by mobile network operators, but it cannot be reconfigured or updated via subscription management services

Engineering Contradiction:
Improveservice access capabilityVSAvoidreconfigurability and update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by creating a transitional state between fully personalized and blank secure elements. The secure element can dynamically change its state from containing only a bootloader to containing a full firmware image, allowing it to be initially versatile (accepting multiple operators) and then become personalized (restricted to one operator) while still allowing future updates through the established communication protocol.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses preliminary action by establishing the communication protocol and status message mechanism before personalization occurs. This preliminary setup enables the secure element to be personalized later while maintaining the capability for future updates, as the communication channel is already in place.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the baseband processor strictly checks security conditions during startup, then security is maintained, but secure elements in transitional states are rejected and become inaccessible

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidaccessibility for subscription management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by differentiating the treatment of secure elements based on their specific state. Instead of applying a uniform rejection policy to all secure elements, the baseband processor checks the status message and applies different handling: accepting secure elements that indicate they contain only a bootloader, while maintaining security checks for others. This localized approach allows transitional secure elements to be accessed for subscription management.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11698994B2Method for a first start-up operation of a secure element which is not fully customized
Publication Date: 2023.07.11 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • US11698994B2 patent drawing

AI summary

A method is for a first-time startup of a not fully personalized secure element, which serves for the use of services of a mobile communication network, in a mobile terminal. In the method, the secure element is started and requested to transmit a status message. The secure element transmits a status message in which it is stated whether the secure element: S1) contains only a bootloader but as yet no firmware image for the secure element; S2) contains a firmware image for the secure element but is not yet fully personalized; or S3) is fully personalized. The secure element is accepted in the cases S1), S2) and S3) and rejected in other cases. In the case S1), a download for a firmware image of the secure element is initiated for a first-time startup.