Virtual Terminal Security Domain for Recertification-Free eUICC Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing eUICC architectures either require cumbersome integration and recertification for LPAd/IPAd solutions or are vendor-specific and lack business agility for LPAe/IPAe solutions, failing to satisfy the needs of MNOs, OEMs, and EUMs.

Innovation Solution

Introduce a Virtual Terminal Security Domain (VTSD) within the eUICC, enabling standardized communication with GSMA eUICC functions via virtual APDU interfaces, allowing integration of an IPAe that maintains compatibility and security while avoiding recertification and vendor lock-in.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If LPA is integrated in the device (LPAd), then ease of operation and flexibility are improved, but device complexity increases and recertification is required

Engineering Contradiction:
ImproveflexibilityVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a Virtual Terminal Security Domain (VTSD) as an intermediary layer between the LPA and the eUICC functions. This VTSD acts as a mediator that enables the LPA to communicate with GSMA eUICC functions through virtual APDU interfaces, thereby providing the flexibility and control benefits of device-integrated LPA without directly increasing device complexity or triggering recertification requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If LPA is integrated in the eUICC (LPAe), then device complexity is reduced and recertification is avoided, but adaptability and business agility are limited due to vendor-specific implementations

Engineering Contradiction:
Improvedevice complexityVSAvoidbusiness agility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements a Virtual Terminal Security Domain (VTSD) that provides universal, standardized interfaces for communicating with eUICC functions. This VTSD enables the LPAe to interact with multiple operators and applications through standardized virtual APDU interfaces, thereby achieving multi-functionality and business agility without requiring vendor-specific customizations or increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If vendor-specific LPAe solutions are implemented, then ease of manufacture is improved, but adaptability and compatibility with multiple operators are reduced

Engineering Contradiction:
Improveease of manufactureVSAvoidcompatibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent creates a virtual copy of the terminal environment through the VTSD, which replicates standardized APDU interface behavior. This virtual copying allows the LPAe to maintain standardized, vendor-neutral communication protocols while being manufactured with ease, as the VTSD provides a consistent interface layer that works across different operators and applications without requiring vendor-specific hardware modifications.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP4589928A1Secure element comprising a virtual terminal security domain and corresponding terminal
Publication Date: 2025.07.23 THALES DIS FRANCE SA
  • EP4589928A1 patent drawingFigure 1
  • EP4589928A1 patent drawingFigure 2
  • EP4589928A1 patent drawingFigure 3

AI summary

The invention proposes a secure element 40 cooperating with a device 30, the secure element 40 comprising a GSMA elllCC function comprising an ECASD eUICC Controlling Authority Security Domain - 46 , an ISD-R Issuer Security Domain - Root - 43 and at least an ISD-P Issuer Security Domain - Profile - 44, the secure element 40 also comprising a Virtual Terminal Security Domain 42 having a direct access to the GSMA eUICC function via a virtual APDU interface, the Virtual Terminal Security Domain 42 interacting with the GSMA eUICC function with the same APDUs as the device 30.