Security Module Network Configuration Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for managing subscription profiles in mobile communication networks are cumbersome, especially for M2M devices, as they require pre-personalization and are not easily switchable between networks, leading to difficulties in international use and inefficient memory usage.
Innovation Solution
A security module with multiple, isolated subscription profiles for different mobile communication networks, where the system configuration includes proprietary data for network-specific operations, allowing for over-the-air profile updates and selection based on user or automatic priority lists, ensuring secure and efficient network switching.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple subscription profiles are stored in the security module for different mobile communication networks, then adaptability to different networks is improved, but memory space consumption increases
Solution Approach 1:
The system configuration data is segmented into network-specific portions that are stored separately from subscription data. Each mobile communication network has its own isolated system configuration in the security module, allowing selective storage and activation of configurations based on which networks are needed, thereby optimizing memory usage while maintaining adaptability.
Solution Approach 2:
The system configuration is made dynamic and adjustable rather than fixed. The security module can selectively activate or deactivate specific system configurations for different networks based on current needs, allowing the memory allocation to be flexible rather than statically reserved for all possible networks.
2Reliability
If system configuration data with proprietary characteristics is stored in the security module, then reliability of network-specific operations is improved, but ease of operation deteriorates due to restricted access
Solution Approach 1:
A controlled interface or intermediary mechanism is introduced between the user and the protected system configuration data. This intermediary allows users to perform necessary operations (such as selecting networks or updating profiles) while automatically managing access to the proprietary configuration data, thus maintaining security without significantly complicating user operations.
Solution Approach 2:
The security module autonomously manages the system configuration data, automatically protecting and managing access to proprietary network-specific configurations without requiring direct user intervention. This self-service approach maintains reliability by preventing unauthorized access while keeping operations simple for users.
3Ease of operation
If subscription profiles are pre-personalized at manufacture, then ease of operation is improved for immediate use, but adaptability to different networks deteriorates
Solution Approach 1:
The security module is pre-configured with the capability and structure to store multiple system configurations for different networks, and can be pre-loaded with at least one subscription profile. This preliminary preparation enables immediate use while maintaining the flexibility to add, remove, or switch between different network configurations as needed.
Solution Approach 2:
The security module is designed with universal capability to support multiple mobile communication networks through its structured storage of system configurations. By incorporating a framework that can accommodate different network-specific configurations, the module achieves multi-functionality, serving both immediate operational needs and future adaptability to various networks.
Data Source
AI summary
A method is provided for operating a security module of a mobile terminal, and a security module. The security module is developed to communicate over one of a plurality of mobile communication networks. The security module comprises different system configurations for different mobile communication networks of the plurality of mobile communication networks. The security module receives subscription data for logging into one mobile communication network of the plurality of mobile communication networks, analyzes the subscription data, and identifies the mobile communication network out of the plurality of mobile communication networks. Subsequently, the security module selects a system configuration in accordance with the mobile communication network, identified in the preceding step, of the plurality of mobile communication networks. The security module is operated with the selected system configuration in the identified mobile communication network.


