eSIM Credential Wrapping for Secure Device Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for secure mechanisms to transfer electronic SIMs (eSIMs) between wireless devices while ensuring the protection of sensitive credentials and maintaining tamper resistance, especially when users change devices or update their wireless devices.
Innovation Solution
The solution involves credential wrapping methods that allow for the secure transfer of eSIMs between devices through re-encryption using ephemeral keys and the formation of a new bound profile package (BPP), which includes re-wrapping eSIM data with new encryption keys, enabling secure installation on the target device without exposing sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If eSIM credentials are transferred between devices using traditional methods, then transfer simplicity is improved, but security and tamper resistance deteriorate
Solution Approach 1:
The system performs preliminary encryption of eSIM credentials with device-specific keys before transfer. The source device encrypts the eSIM data with the target device's public key in advance, so that when the transfer occurs, the credentials are already secured for the specific target device, preventing interception and unauthorized access during transit.
Solution Approach 2:
The patent introduces a provisioning server as an intermediary that facilitates secure eSIM transfer. The server acts as a trusted mediator that receives encrypted eSIM data from the source device, verifies the target device's credentials, and delivers the packaged credentials securely, eliminating the need for direct peer-to-peer transfer while maintaining security.
2Reliability
If eSIM data is re-encrypted with new keys for each transfer session, then security is improved, but processing complexity increases
Solution Approach 1:
The system performs preliminary encryption of eSIM credentials with device-specific keys before transfer. The source device encrypts the eSIM data with the target device's public key in advance, so that when the transfer occurs, the credentials are already secured for the specific target device, preventing interception and unauthorized access during transit.
Solution Approach 2:
The patent creates encrypted copies of the eSIM credentials tailored for each target device. Instead of transferring the original unencrypted eSIM data, the system generates device-specific encrypted copies that can only be decrypted by the intended target device, allowing secure distribution to multiple devices without compromising the master eSIM credentials.
3Reliability
If ephemeral keys are used for single-session transfer, then tamper resistance is improved, but key management complexity increases
Solution Approach 1:
Each device generates its own key pairs (public and private keys) autonomously. The source device obtains the target device's public key and uses it for encryption, while the target device independently manages its own private key for decryption. This self-service approach eliminates the need for a centralized key management system while ensuring that each device has full control over its cryptographic credentials.
Solution Approach 2:
The patent introduces a provisioning server as an intermediary that facilitates secure eSIM transfer. The server acts as a trusted mediator that receives encrypted eSIM data from the source device, verifies the target device's credentials, and delivers the packaged credentials securely, eliminating the need for direct peer-to-peer transfer while maintaining security.
4Reliability
If sensitive eSIM data is protected through re-encryption, then credential security is improved, but transfer time increases
Solution Approach 1:
The system performs preliminary encryption of eSIM credentials with device-specific keys before transfer. The source device encrypts the eSIM data with the target device's public key in advance, so that when the transfer occurs, the credentials are already secured for the specific target device, preventing interception and unauthorized access during transit.
Solution Approach 2:
The patent creates encrypted copies of the eSIM credentials tailored for each target device. Instead of transferring the original unencrypted eSIM data, the system generates device-specific encrypted copies that can only be decrypted by the intended target device, allowing secure distribution to multiple devices without compromising the master eSIM credentials.
Data Source
AI summary
Embodiments described herein relate to credential wrapping for secure transfer of electronic SIMs (eSIMs) between wireless devices. Transfer of an eSIM from a source device to a target device includes re-encryption of sensitive eSIM data, e.g., eSIM encryption keys, financial transaction credentials, transit authority credentials, and the like, using new encryption keys that include ephemeral elements applicable to a single, particular transfer session between the source device and the target device. The sensitive eSIM data encrypted with a symmetric key (Ks) is re-wrapped with a new header that includes a version of Ks encrypted with a new key encryption key (KEK) and information to derive KEK by the target device. The re-encrypted sensitive SIM data is formatted with additional eSIM data into a new bound profile package (BPP) to transfer the eSIM from the source device to the target device.


