SIM Credential Geofencing for Enterprise Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for provisioning geofencing information to user equipment (UE) in enterprise networks are cumbersome, requiring custom enterprise identifiers and manual association of credentials, which complicates the distribution of access rights across multiple networks.

Innovation Solution

A system where a SIM Provisioning Vendor provides credentials to UEs through an SM-DP+ and a Network Vendor Server, using an OTA Update Platform to manage and distribute geofencing information, allowing UEs to access enterprise networks without pre-association of enterprise-specific information, and enabling secure storage and updates of geofencing data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If custom enterprise identifiers are assigned to each enterprise network and manually associated with SIM credentials, then geofencing information can be provisioned to UEs, but the process becomes cumbersome and complex for distribution across multiple networks

Engineering Contradiction:
Improvegeofencing information provisioningVSAvoidcredential distribution process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by enabling a single SIM credential to be associated with multiple enterprise networks through a multi-network profile. The SIM card can store multiple enterprise identifiers (PLMNs) and their corresponding geofencing information, allowing one credential to serve multiple functions across different enterprise networks. This eliminates the need for separate SIM credentials for each enterprise network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements the nested doll principle by embedding multiple enterprise network profiles within a single SIM credential structure. Each enterprise network's identifier and geofencing information are nested within the SIM's storage, allowing hierarchical organization where multiple enterprise profiles are contained within one credential container. This nested structure simplifies distribution while maintaining individual network identities.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If each enterprise network is customized before pushing credentials to UEs, then proper authorization can be established, but administrative burden increases significantly

Engineering Contradiction:
ImproveauthorizationVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-configuring multiple enterprise network profiles and their associated geofencing information into the SIM credential during SIM provisioning, before the UE actually needs to access any enterprise network. This advance preparation eliminates the need for per-network customization at the time of credential deployment, as all necessary authorization data is already embedded in the SIM.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing the SIM card to autonomously manage multiple enterprise network profiles and select the appropriate geofencing information based on which enterprise network the UE is currently attempting to access. The SIM automatically provides the correct enterprise identifier and authorization data without requiring manual intervention for each network.

Inventive Principle:
Principle #25Self-service

3Reliability

If SIM profiles are established with enterprise identifiers, then geofencing information can be pushed to UEs, but the process requires multiple steps and server interactions

Engineering Contradiction:
Improvegeofencing information distributionVSAvoidprovisioning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the establishment of SIM profiles with enterprise identifiers and the provisioning of geofencing information into a single integrated process. By combining these previously separate steps into one unified SIM provisioning operation, the system eliminates multiple server interactions and accelerates the overall deployment time while maintaining the reliability of geofencing information distribution.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20240015505A1Enterprise Policies and Geofencing Information Provisioning
Publication Date: 2024.01.11 CELONA INC
  • US20240015505A1 patent drawing
  • US20240015505A1 patent drawing

AI summary

A system in which a plurality of UEs (User Equipment), each of which have access to one or more enterprise networks can be provided with credentials to access those enterprise network to which they have been granted access and in which system each such UE is provided with geofencing information for those enterprise networks to which a UE has been granted access (i.e., has been assigned credentials). The UE uses the geofencing information to determine whether to look for enterprise network transceivers (e.g., access points, eNBs or gNBs) though which the UE can gain wireless access to the enterprise network.