Smart Secure Platform Certificate Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless devices are limited in their ability to manage multiple security certificates, as they are typically dedicated to a single market segment and use a single security certificate for various functions, lacking flexibility to support different industry sectors with different certificate authorities.

Innovation Solution

The implementation of a smart secure platform (SSP) that can load different operating system bundles and certificates from various certificate authorities, allowing it to switch between security certificates and operational modes to support multiple industry sectors, such as telecommunications and payment processing, by using a combination of operating system code, applets, and metadata, and an embedded Universal Integrated Circuit Card (eUICC) that stores electronic Subscriber Identity Modules (eSIMs).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a wireless device uses a single security certificate for various functions, then the device structure is simple and ease of manufacture is improved, but the adaptability to support different industry sectors with different certificate authorities deteriorates

Engineering Contradiction:
Improvedevice structure simplicityVSAvoidsupport for different industry sectors
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The secure processing element is designed to perform multiple security functions across different industry sectors (telecommunications, payment processing, digital identification) by loading different operating system bundles and using different security certificates from various certificate authorities, making a single hardware component universally applicable to multiple markets

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If a wireless device is dedicated to a single market segment with a single security certificate, then the device complexity is reduced, but the versatility to support multiple operational modes deteriorates

Engineering Contradiction:
Improvecertificate management complexityVSAvoidoperational mode support
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The secure processing element transitions from static single-certificate operation to dynamic multi-certificate operation by loading different operating system bundles and security certificates based on the required operational mode or industry sector, allowing the device to adapt its security configuration dynamically

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If multiple security certificates are stored in the secure processing element, then the adaptability to support different industry sectors is improved, but the device complexity increases

Engineering Contradiction:
Improveindustry sector supportVSAvoidcertificate management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Multiple security certificates and corresponding operating system bundles are pre-loaded into the secure processing element during manufacturing or initial provisioning, so that when the device needs to support a specific industry sector, the appropriate certificates and software are already available without requiring complex real-time acquisition or generation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11290268B2Mode switching with multiple security certificates in a wireless device
Publication Date: 2022.03.29 APPLE INC
  • US11290268B2 patent drawing
  • US11290268B2 patent drawing
  • US11290268B2 patent drawing

AI summary

This application describes various embodiments to manage multiple security certificates in a wireless device, including switching between different security certificates to support different functions, including supporting connectivity for multiple industry sectors that use different certificate authorities, and/or supporting different operational modes that require different security certificates for performing administrative functions. The wireless device includes a smart secure platform (SSP) or an embedded Universal Integrated Circuit Card (eUICC) that stores multiple security certificates to use for different industry sectors and/or for different operational modes.