Subscription Administration via Secure Server Tunnel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for administering subscriptions on mobile communication terminals, such as eUICC cards, require numerous interactions with operator information systems, making it cumbersome for users and fleet managers to manage subscriptions without authentication and requiring knowledge of contractual subscription numbers.

Innovation Solution

A method that allows users or fleet managers to administer subscriptions directly from a mobile terminal by obtaining an access profile with a contact address of a server configured for subscription management data, enabling requests for administrative actions to be sent through a secure tunnel, eliminating the need for external authentication and subscription number entry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users log in to operator portal and authenticate to administer subscriptions, then subscription management can be performed, but the process becomes complex and requires multiple interactions with operator information systems

Engineering Contradiction:
Improvesubscription administration processVSAvoidinteraction with operator information system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the authentication and identification functionality from the operator's information system and places it directly in the user device. The device autonomously generates cryptographic proofs and identifies subscriptions using local credentials, eliminating the need to interact with the operator's authentication system for basic identification tasks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The user device performs self-identification and subscription selection without requiring operator system involvement. The device uses locally stored credentials to cryptographically prove its identity and autonomously identify valid subscriptions, making the system self-sufficient for identification tasks.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If users enter subscription contract numbers to access operator portals, then specific subscriptions can be managed, but the process requires user knowledge and manual input

Engineering Contradiction:
Improvesubscription identificationVSAvoidauthentication and identification process
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The device pre-stores multiple credentials and subscription identifiers locally before needing them. When administration is required, the device immediately uses these pre-stored elements to cryptographically identify subscriptions without requiring users to recall or input contract numbers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual mechanical input (typing contract numbers) with cryptographic automated identification. The device uses cryptographic proofs and digital signatures to automatically identify and select subscriptions based on locally stored credentials, eliminating the need for manual data entry.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If multiple credentials are stored in the security module, then flexible subscription access is enabled, but the risk of unauthorized use increases

Engineering Contradiction:
Improvesubscription access flexibilityVSAvoidauthorization security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies different security characteristics to different credentials based on their intended use. Each credential is associated with specific usage rights and scopes, allowing the system to flexibly access multiple subscriptions while maintaining appropriate security controls for each credential type.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The device obtains authorization feedback from the operator's system after presenting cryptographic proofs. The operator system validates the credentials and provides authorization decisions, ensuring that even though multiple credentials are stored, only authorized ones can successfully access subscriptions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3580944B1Technique for administrating a subscription at an operator
Publication Date: 2021.12.15 ORANGE SA
  • EP3580944B1 patent drawingFigure 1~4
  • EP3580944B1 patent drawingFigure 2a~2b

AI summary

The invention concerns a technique for administrating a subscription with an operator. This subscription allows access to a communication network for a security module (20) associated with a user device (10). A contact address of a server (30) configured for preparing subscription management data is obtained from a network access profile installed in the security module. The security module sends a request for execution of an administration task relating to this subscription. The request is addressed to the contact address of the server and comprises a datum allowing the server to forward the request to a control server (40). Once the administrative task is executed, the user device receives a confirmation of the execution of this administration task from the control server.