Security Element Subscription Management via Primary Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for managing subscriptions on security elements like SIM cards in mobile radio networks are inefficient, particularly for M2M communication devices, where subscriptions cannot be easily provided during manufacturing and network operators lack visibility into other subscriptions on the security element.
Innovation Solution
Implementing a security element with multiple memory locations for storing primary and secondary subscriptions, where the primary subscription includes a set of rules determining which secondary subscriptions can be used, allowing for over-the-air reprogramming and specific network operator restrictions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a security element is implemented as a surface-mounted chip in M2M devices, then the device can be manufactured with integrated security, but it becomes impossible or very difficult to integrate a subscription during manufacturing
Solution Approach 1:
The security element is divided into separate functional components: the security element itself (embedded chip) and the subscription data (stored separately in memory locations). This allows the security element to be manufactured and integrated during device production, while subscription integration can be performed separately later through over-the-air updates without requiring physical access to the embedded chip.
2Ease of operation
If a network operator downloads a subscription to a security element, then the subscription can be activated, but the network operator has no way of recognizing or determining which other subscriptions are already on the security element
Solution Approach 1:
The system implements a feedback mechanism where the security element provides information about existing subscriptions to the network operator during the subscription download process. This allows the network operator to recognize and determine which other subscriptions are already present on the security element, enabling informed decisions about subscription management and conflict detection.
3Adaptability or versatility
If multiple subscriptions are stored on a security element, then flexibility for network switching is improved, but the complexity of managing and controlling subscription usage increases
Solution Approach 1:
The system establishes subscription usage rules and access control mechanisms in advance, during the subscription setup phase. The security element is pre-configured with rules that automatically control which subscriptions can be used and under what conditions, eliminating the need for complex real-time management decisions and reducing operational complexity.
4Productivity
If subscriptions are provided during manufacturing, then device deployment is faster, but it is not feasible for M2M devices where deployment location is uncertain
Solution Approach 1:
The system transitions from a static subscription model (fixed during manufacturing) to a dynamic model where subscriptions can be added, removed, or modified after device deployment. The security element maintains the capability to receive and process subscription updates at any time, allowing the subscription configuration to adapt to the actual deployment location and requirements of the M2M device.
Data Source
Figure 1
Figure 2
AI summary
A method for managing a multiplicity of subscriptions on a security element (14) of a mobile terminal (12) for registering with a particular mobile radio network (30, 40) and such a security element (14) are provided. In this case, the security element (14) has a multiplicity of storage locations for storing the multiplicity of subscriptions (18a-d), wherein the multiplicity of subscriptions comprises a primary subscription (18a) and at least one secondary subscription (18b-d). In this case, the primary subscription (18a) stores a set of rules determining whether the at least one secondary subscription (18b-d) can be used on the security element (14).