eSIM Credentials for 5G Network Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Low-cost IoT communication devices face challenges in establishing network connectivity without a pre-installed SIM profile, as they require additional hardware and complexity, and existing eSIM solutions necessitate changes to the eUICC and provisioning server for non-public networks.

Innovation Solution

The method leverages the 5G Subscription Concealed Identifier (SUCI) and EAP framework to tunnel consumer eSIM common mutual authentication between the subscription manager and eUICC, allowing network connectivity using eSIM credentials without altering existing interfaces, enabling continued profile download and avoiding additional authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an additional radio is introduced to provide non-cellular connectivity for downloading SIM profiles, then connectivity capability is improved, but device complexity and cost increase

Engineering Contradiction:
Improveconnectivity capabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The eUICC credentials are made multi-functional by enabling them to serve both as authentication credentials for network access and as credentials for profile download authentication. The EAP-TLS authentication method uses the same eUICC certificate and private key that are used for securing profile downloads, eliminating the need for separate authentication mechanisms or additional hardware radios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The communication device performs self-authentication using its eUICC credentials through the EAP-TLS framework. The device autonomously establishes secure connections for both network access and profile downloads without requiring additional authentication infrastructure or separate credential storage, reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If EAP-TLS and other EAP methods leveraging SM-DP+ credentials are used for network access authentication, then authentication security is improved, but changes to provisioning server and eUICC are required

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The eUICC credentials are designed to be universally applicable for multiple purposes: network access authentication via EAP-TLS and profile download authentication. The same certificate authority (CA) credentials stored in the eUICC are used for both functions, eliminating the need for separate authentication systems or additional changes to existing eUICC and provisioning server architectures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The EAP-TLS framework acts as an intermediary that bridges network access authentication and existing eUICC credential systems. By leveraging the existing eUICC credential structure and adding EAP-TLS as the authentication mechanism, the solution maintains compatibility with current eUICC implementations while enabling secure network access without requiring changes to the eUICC or provisioning server.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a bootstrap profile with global roaming agreements is pre-installed, then initial connectivity is ensured, but device cost and manufacturing complexity increase

Engineering Contradiction:
Improveinitial connectivityVSAvoidmanufacturing simplicity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The communication device autonomously performs network access authentication and profile downloads using its eUICC credentials without requiring pre-installation of bootstrap profiles. The device self-configures by authenticating to the network and automatically downloading appropriate profiles, eliminating the need for manufacturing complexity associated with pre-installing multiple regional profiles.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The eUICC credentials (certificate and private key) are pre-provisioned in the device during manufacturing, enabling immediate authentication capability. This preliminary provisioning of cryptographic credentials allows the device to independently establish network connectivity and download profiles without requiring pre-installed operational profiles or complex manufacturing processes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250106625A1Establishment of network connection for a communication device
Publication Date: 2025.03.27 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250106625A1 patent drawing
  • US20250106625A1 patent drawing
  • US20250106625A1 patent drawing

AI summary

There is provided mechanisms where a 5G SUCI and EAP framework is leveraged to tunnel the consumer eSIM common mutual authentication, eSIM credentials provided in a communication device can be leveraged during network access authentication such that network connectivity can be obtained for the communication device. This is achieved without making any changes to existing SM and eUICC interfaces. The embodiments also allow continued profde download, leveraging an already established session with the SM. This enables further common mutual authentication to be avoided.