UICC Security Domain Hierarchy for Multi-Provider Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security management systems for universal integrated circuit cards (UICC) face challenges in securely managing and configuring security domains, particularly in ensuring secure communication and data protection across various devices and networks, as they lack a standardized and efficient method for handling multiple service providers and third-party service managers.

Innovation Solution

The implementation of a security domain structure within the UICC based on Global Platform standards, which allows for the creation and management of operator-specific security domains, enabling secure communication by establishing a hierarchy that includes a link provider operator security domain above a mobile network operator trusted security domain, and allowing third-party service managers to perform card content management actions without authorization from the mobile network operator.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a standardized security domain structure is implemented, then security management efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity management efficiencyVSAvoidsecurity domain structure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The security domain structure is divided into distinct hierarchical levels: a first security domain for card management functions and a second security domain for telephony management functions. This segmentation allows each domain to be managed independently with appropriate security controls, improving overall management efficiency while maintaining clear structural boundaries that prevent confusion.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security domain structure is designed to support multiple service providers and third-party service managers within a unified framework. The structure can accommodate different operator configurations and service provider requirements while maintaining consistent security management principles, making it universally applicable across different network configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple service providers and third-party service managers are supported, then system adaptability is improved, but management complexity increases

Engineering Contradiction:
Improvesupport for multiple service providersVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Different security domains are created for different service providers and management functions. Each service provider can have their own security domain isolated from others, allowing independent configuration and management. This segmentation reduces the complexity of managing multiple providers by treating each as a separate, manageable unit.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A common security domain structure serves as an intermediary framework that mediates between different service providers and third-party service managers. This unified structure provides standardization and common security controls while allowing individual providers to maintain their specific configurations within the broader framework.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If secure communication and data protection are enhanced, then security reliability is improved, but system complexity increases

Engineering Contradiction:
Improvesecure communication reliabilityVSAvoidsecurity implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security controls are segmented and applied at different hierarchical levels within the security domain structure. Each domain has its own security controls tailored to its specific functions, which simplifies the overall security implementation by breaking down complex security requirements into manageable, domain-specific controls rather than requiring a monolithic security system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10476859B2Apparatus and method for managing security domains for a universal integrated circuit card
Publication Date: 2019.11.12 AT&T INTELLECTUAL PROPERTY I L P
  • US10476859B2 patent drawing
  • US10476859B2 patent drawing
  • US10476859B2 patent drawing

AI summary

A device that incorporates the subject disclosure may perform, for example, generating a security domain root structure for a universal integrated circuit card of an end user device, where the security domain root structure includes a hierarchy of a link provider operator security domain above a mobile network operator trusted security domain, where the link provider operator security domain enables transport management by a link provider operator, and where the mobile network operator trusted security domain enables card content management and subscription eligibility verification by a mobile network operator trusted service manager. Other embodiments are disclosed.