Subscription Administration via Secure Server Tunnel
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for administering subscriptions on mobile communication terminals, such as eUICC cards, require numerous interactions with operator information systems, making it cumbersome for users and fleet managers to manage subscriptions without authentication and requiring knowledge of contractual subscription numbers.
Innovation Solution
A method that allows users or fleet managers to administer subscriptions directly from a mobile terminal by obtaining an access profile with a contact address of a server configured for subscription management data, enabling requests for administrative actions to be sent through a secure tunnel, eliminating the need for external authentication and subscription number entry.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users log in to operator portal and authenticate to administer subscriptions, then subscription management can be performed, but the process becomes complex and requires multiple interactions with operator information systems
Solution Approach 1:
The patent extracts the authentication and identification functionality from the operator's information system and places it directly in the user device. The device autonomously generates cryptographic proofs and identifies subscriptions using local credentials, eliminating the need to interact with the operator's authentication system for basic identification tasks.
Solution Approach 2:
The user device performs self-identification and subscription selection without requiring operator system involvement. The device uses locally stored credentials to cryptographically prove its identity and autonomously identify valid subscriptions, making the system self-sufficient for identification tasks.
2Ease of operation
If users enter subscription contract numbers to access operator portals, then specific subscriptions can be managed, but the process requires user knowledge and manual input
Solution Approach 1:
The device pre-stores multiple credentials and subscription identifiers locally before needing them. When administration is required, the device immediately uses these pre-stored elements to cryptographically identify subscriptions without requiring users to recall or input contract numbers.
Solution Approach 2:
The patent replaces manual mechanical input (typing contract numbers) with cryptographic automated identification. The device uses cryptographic proofs and digital signatures to automatically identify and select subscriptions based on locally stored credentials, eliminating the need for manual data entry.
3Adaptability or versatility
If multiple credentials are stored in the security module, then flexible subscription access is enabled, but the risk of unauthorized use increases
Solution Approach 1:
The patent applies different security characteristics to different credentials based on their intended use. Each credential is associated with specific usage rights and scopes, allowing the system to flexibly access multiple subscriptions while maintaining appropriate security controls for each credential type.
Solution Approach 2:
The device obtains authorization feedback from the operator's system after presenting cryptographic proofs. The operator system validates the credentials and provides authorization decisions, ensuring that even though multiple credentials are stored, only authorized ones can successfully access subscriptions.
Data Source
Figure 1~4
Figure 2a~2b
AI summary
The invention concerns a technique for administrating a subscription with an operator. This subscription allows access to a communication network for a security module (20) associated with a user device (10). A contact address of a server (30) configured for preparing subscription management data is obtained from a network access profile installed in the security module. The security module sends a request for execution of an administration task relating to this subscription. The request is addressed to the contact address of the server and comprises a datum allowing the server to forward the request to a control server (40). Once the administrative task is executed, the user device receives a confirmation of the execution of this administration task from the control server.