Subscription Profiles for Security Element Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing subscription management systems for mobile terminals face complexity in initializing security elements for different subscriptions, as each subscription requires unique access to functionalities, making it difficult to standardize the initialization process and manage changes in subscription conditions.
Innovation Solution
The method involves generating and storing metadata within the security element to specify which functionalities a subscription profile can access, allowing for subscription-specific restriction of access to the security element's functionalities, enabling standardized initialization and flexible adjustment of access rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a security element is initialized with all functionalities available for any subscription, then all subscriptions can access required functionalities, but access control becomes complex and requires different initializations for different subscriptions
Solution Approach 1:
The patent segments the functionality access control by introducing subscription-specific profiles that divide and restrict access to specific functionalities within the security element. Each profile acts as an independent access control unit that can be individually configured and loaded, eliminating the need for complex different initializations for different subscription types.
Solution Approach 2:
The patent implements preliminary action by pre-configuring subscription profiles with specific access rights to functionalities before loading them into the security element. The subscription management system prepares and stores these profiles in advance, so that when a subscription is activated, the appropriate profile is already ready to enforce the correct access control without requiring complex real-time initialization decisions.
2Device complexity
If a security element is initialized specifically for a particular subscription, then access control is simplified, but the system cannot easily accommodate different subscription types and future subscriptions
Solution Approach 1:
The patent achieves universality by creating a standardized subscription profile structure that can accommodate multiple subscription types. The profile format is designed to be generic and adaptable, allowing the same security element to load and enforce different profiles for various subscription types (e.g., data-only, voice, SMS, full-service) without requiring re-initialization or hardware changes.
Solution Approach 2:
The patent implements dynamics by making the subscription profile system flexible and changeable. Profiles can be dynamically loaded, updated, or replaced based on the subscription type being activated. This allows the security element to adapt its functionality access control in real-time based on which subscription is currently active, rather than being fixed to a single initialization configuration.
3Adaptability or versatility
If all functionalities are made available to a subscription profile, then the subscription can access all services, but security risks increase and unnecessary functionalities remain accessible
Solution Approach 1:
The patent applies local quality by making access rights specific and localized to each subscription profile. Instead of providing blanket access to all functionalities, each profile is configured with precise access permissions for specific functionalities relevant to that subscription type. This ensures that only the necessary functionalities are accessible to each subscription, reducing security risks while maintaining service capability.
4Reliability
If access restrictions are implemented at the initialization level, then security is improved, but the process of loading different subscriptions becomes complex and time-consuming
Solution Approach 1:
The patent resolves this contradiction by performing access restriction configuration in advance during profile creation, rather than during subscription loading. The subscription management system pre-configures all access restrictions and security parameters when creating subscription profiles, storing them in a ready-to-load format. This eliminates the need for complex real-time initialization processes when loading subscriptions, as the security restrictions are already embedded in the profile data structure.
Data Source
Figure 1
AI summary
The invention relates to a method and to a system for subscription management in a security element for a mobile terminal. Here, each subscription is assigned a subscription profile. For a subscription profile, access to functionalities of the security element is restricted in a subscription profile-specific manner (S3).