Security Element Bootloader for Multi-OS Subscription Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security elements, such as SIM cards or eUICCs, often require different operating system variants to support subscription profiles from various mobile network operators, limiting their compatibility and functionality.

Innovation Solution

A method and security element design that allows switching between multiple subscription profiles with different operating systems by using a boot loader to load and execute alternative operating systems after restart, facilitated through messages or user inputs, enabling communication with multiple cellular networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple subscription profiles are provided on one security element, then the functionality and compatibility with different mobile network operators are improved, but the device complexity increases due to the need to support multiple operating system variants

Engineering Contradiction:
Improvecompatibility with different mobile network operatorsVSAvoidcomplexity of supporting multiple operating system variants
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security element dynamically switches between different operating system variants based on which subscription profile is active. The bootloader can load different OS variants into memory, allowing the same hardware to adapt its software environment to match the required network operator compatibility, thus resolving the contradiction between versatility and complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

A single security element is designed to perform multiple functions by supporting multiple operating system variants. The element can serve different mobile network operators using different OS versions, making one security element universal rather than requiring separate elements for each operator, thereby improving compatibility without proportionally increasing physical device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If subscription profiles from different mobile network operators are supported, then the adaptability to various networks is improved, but the ease of operation deteriorates due to the complexity of managing different operating system variants

Engineering Contradiction:
Improvesupport for different mobile network operatorsVSAvoidease of switching between operating system variants
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The security element automatically manages the switching between different operating system variants based on the active subscription profile. When a user selects or activates a different subscription profile, the system autonomously loads the appropriate OS variant through the bootloader without requiring manual intervention or complex user configuration, thus maintaining ease of operation while supporting multiple operators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The bootloader acts as an intermediary between the subscription profile selection and the operating system execution. It mediates the switching process by automatically loading the correct OS variant corresponding to the active profile, shielding the user from the complexity of direct OS management while enabling seamless operator switching.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the security element is permanently integrated into the mobile device, then the reliability is improved, but the ease of repair and replacement deteriorates

Engineering Contradiction:
Improvereliability of security elementVSAvoidease of replacement of security element
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The security element is designed as a separable module even when permanently integrated into the device architecture. This segmentation allows the security element to be replaced or upgraded independently from the main device, maintaining reliability during normal operation while enabling repair or replacement when needed, thus resolving the contradiction between reliability and ease of repair.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3257219B1Method for operating a security element
Publication Date: 2020.02.05 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP3257219B1 patent drawingFigure 1

AI summary

A method for operating a security element (14) of a mobile terminal (12) having a memory unit (17) is provided, said memory unit containing a 1st subscription profile (SP1) with a 1st operating system for the security element (14) and a 2nd subscription profile (SP2) with a 2nd operating system for the security element (14). In this case, the method comprises the following steps: operation of the security element (14) with the 1st operating system in order to be able to communicate with the 1st subscription profile (SP1) via a 1st mobile radio network (30); changeover from the 1st operating system to the 2nd operating system of the security element (14) by virtue of a bootloader (18) in the memory unit (17) loading and executing the 2nd operating system after the security element (14) is restarted; and operation of the security element (14) with the 2nd operating system in order to be able to communicate with the 2nd subscription profile (SP2) via a 2nd mobile radio network (40). Further, a corresponding security element (14) and a corresponding mobile terminal (12) are provided.