Secure Module Local Profile Management Activation Agent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure modules in electronic devices lack the ability to securely manage subscriber profiles locally, and there is a need to ensure the coexistence of local and remote management modes while maintaining security and operator control over configuration actions.

Innovation Solution

An electronic device with a secure module that includes a local manager and an activation agent to detect and authorize or prohibit local configuration requests, using secure radiofrequency transport protocols and interface notifications to manage local profile activation, deactivation, and deletion requests, ensuring secure local management and cooperation with remote servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If local profile configuration requests are allowed to be processed by the secure module, then user autonomy and local management capability are improved, but security risks and potential unauthorized modifications increase

Engineering Contradiction:
Improvelocal management capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The activation agent serves as an intermediary component between the local manager and the secure module. It intercepts local profile configuration requests, verifies their authenticity and authorization status, and only permits processing of validated requests. This mediator ensures that local management operations are securely controlled without compromising user autonomy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the secure module supports both local and remote management modes, then system versatility and adaptability are improved, but system complexity and management overhead increase

Engineering Contradiction:
Improvecoexistence of management modesVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The management system is segmented into distinct functional components: a local manager for local requests, a remote manager for remote requests, and an activation agent that coordinates between them. Each component has a specific responsibility, and the activation agent maintains state information about which management mode is currently active. This segmentation allows both local and remote modes to coexist without creating excessive system complexity.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the activation agent detects and authorizes local configuration requests, then security control is improved, but processing time and operational delays increase

Engineering Contradiction:
Improvesecurity controlVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The activation agent performs preliminary actions by pre-establishing authorization states and detecting the operational mode in advance of actual profile configuration requests. By determining whether local management is authorized before requests arrive, the system avoids time-consuming verification delays during actual configuration operations, while still maintaining security control.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3363178B1Electronic device comprising a secure module supporting a mode for the local management of the configuration of a subscriber profile
Publication Date: 2021.03.03 IDEMIA FRANCE SAS
  • EP3363178B1 patent drawingFigure 1
  • EP3363178B1 patent drawingFigure 2A
  • EP3363178B1 patent drawingFigure 2B

AI summary

The invention relates to the field of electronic devices comprising a secure module (14) for housing at least one subscriber profile (18) and an interface (13) allowing the local configuration of a profile. According to the invention, the secure module (14) also comprises an activation agent (16) comprising a means (161) for detection of a mode of local management of the profile (18) for authorising and/or prohibiting the processing of the local configuration requests (101) by a local manager (15) according to the result of the detection. The invention also applies to the detachable integrated circuit cards or secure elements soldered into the device communicating via a mobile telecommunication network.