Secure Link Mediates eUICC Profile Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Faulty connection data stored in secure electronic entities within terminals prevent remote processing and maintenance in telecommunications networks, especially when the entities are non-removable, such as eUICC, making it impossible to establish a secure connection for data exchange and authentication.

Innovation Solution

A method is proposed where a first terminal with a secure connection to a telecommunications network transmits encrypted data related to a second terminal's profile to an infrastructure server, allowing for secure processing and updating of connection data through a secure link between the terminals and the network, enabling the correction of faulty connection data stored in the second terminal's microcircuit card.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If connection data is stored in a non-removable secure electronic entity (eUICC), then security and integration are improved, but the ability to remotely update and maintain connection data is lost when anomalies occur

Engineering Contradiction:
Improveconnection securityVSAvoidremote anomaly handling
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

A first terminal acts as an intermediary device to transfer profile data from the faulty second terminal to a subscription manager. The first terminal establishes a secure connection with the network and uses its own functional profile to enable authentication and data transfer, allowing remote handling of anomalies in the eUICC without requiring physical access to the secure element.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The solution separates the authentication function from the profile storage function. The first terminal uses a functional profile for authentication while the second terminal's eUICC retains its stored profile data. This segmentation allows the authentication capability to be transferred to a different device that can communicate with the network, while the original secure element remains intact but unable to authenticate.

Inventive Principle:
Principle #1Segmentation

2Quantity of substance

If a single connection profile is stored in the secure electronic device, then cost is reduced, but the device cannot handle connection anomalies remotely

Engineering Contradiction:
Improvenumber of profiles storedVSAvoidanomaly processing capability
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The first terminal serves multiple functions: it acts as a communication bridge between the faulty second terminal and the subscription manager, provides authentication capabilities using its own profile, and enables the transfer and updating of profile data. This multi-functionality allows the system to handle anomalies remotely without requiring the second terminal to store multiple profiles locally.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If connection data is encrypted and stored securely, then data security is improved, but the data cannot be transmitted or updated when connection faults occur

Engineering Contradiction:
Improvedata securityVSAvoiddata transmission capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The first terminal serves as a secure intermediary that can communicate with both the second terminal and the subscription manager. It receives encrypted profile data from the second terminal, maintains secure communication channels, and transfers the data to the subscription manager for updating, all while preserving the encryption and security of the connection data throughout the transmission process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3175601B1Method for treating a faulty connection to a telecommunications network
Publication Date: 2022.08.31 IDEMIA FRANCE SAS
  • EP3175601B1 patent drawingFigure 1~3
  • EP3175601B1 patent drawingFigure 2

AI summary

The invention relates to a method for treating a faulty connection to a telecommunications network (N), comprising the following steps: - establishing a secure link (SL) between a first terminal (B), storing a first access profile (PB) for access to the telecommunications network (N), and a second terminal (A), storing a second access profile (PA) for access to the communication network (N) associated with the faulty connection; - communicating, from the second terminal (A) to the first terminal (B), via the secure link (SL), data relating to the second profile (PA); - transmitting, by the first terminal (B), using the first profile (PB), data relating to the second profile (PA) to an infrastructure server (SMB) of the telecommunications network (N).