Derived eSIM Profile Generation for Temporary Subscription Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing remote provisioning process for eUICC technology faces challenges in efficiently managing short-term profiles, leading to resource exhaustion and overhead, particularly when users need to temporarily share active subscriptions across multiple devices, due to finite available profiles and computationally intensive security processes.

Innovation Solution

A method where a user equipment acts as an onboarding device to generate a derived profile for a target device by using a key derivation function based on existing credentials, allowing temporary subscription sharing without exhausting available profiles and reducing computational resources by directly provisioning the derived profile onto the target device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the existing remote provisioning process is used for short-term profiles, then subscription sharing is enabled, but resource exhaustion and computational overhead occur

Engineering Contradiction:
Improvesubscription sharing capabilityVSAvoidavailable profiles
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The solution segments the profile provisioning process into two distinct paths: long-term profiles are provisioned through the traditional RSP platform, while short-term profiles are generated locally using key derivation functions. This segmentation allows the system to handle different profile types differently, preventing resource exhaustion in the RSP platform while maintaining subscription sharing capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a copying mechanism where short-term profile credentials are derived by applying a key derivation function to the long-term profile credentials. Instead of creating entirely new profiles, the system generates cryptographic copies (derived credentials) that inherit security properties from the parent profile, enabling unlimited short-term profile generation without consuming additional RSP resources.

Inventive Principle:
Principle #26Copying

2Reliability

If traditional RSP platform processes are used for each profile provisioning, then security is maintained, but communication overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security setup by establishing a secure key derivation function during the initial long-term profile provisioning. This preliminary action creates a cryptographic template that can be rapidly replicated for short-term profiles without requiring repeated communication with the RSP platform, thus maintaining security while reducing provisioning time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The endpoint device is empowered to self-generate short-term profile credentials using the key derivation function and stored long-term credentials. This self-service capability eliminates the need for time-consuming RSP platform communication for each short-term profile, while the derived credentials maintain cryptographic security equivalent to RSP-provisioned profiles.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11805409B2System and method for deriving a profile for a target endpoint device
Publication Date: 2023.10.31 VERIZON PATENT & LICENSING INC
  • US11805409B2 patent drawing
  • US11805409B2 patent drawing
  • US11805409B2 patent drawing

AI summary

A device may obtain, from a pool of subscription identifiers allocated for sharing, a subscription identifier for a target device to be onboarded onto a wireless network. The device may generate a derived subscriber identification module (SIM) profile that includes the subscription identifier and a derived set of credentials. The derived set of credentials may be based on an existing set of credentials associated with the device. The device may cause the derived SIM profile to be provided to the target device to enable the target device to obtain access to the wireless network.