eSIM Anonymity via Dynamic Hashed Identifiers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for managing subscriptions on eSIM cards in consumer mobile equipment raise privacy concerns as intermediate servers can track user subscriptions and correlate eSIM card identifiers with operators, compromising user anonymity.
Innovation Solution
A method that decorrelates the identification value from the physical eSIM card identifier, using a changing identification value based on date, ensuring anonymity and non-traceability by generating a set of anonymized identification values for the subscription data management server, which are calculated using a hash function and a prime number, making it difficult for the server to trace successive subscriptions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If an intermediate server stores correspondences between eSIM card identifier and operator management server address to enable subscription management, then subscription flexibility and ease of operation are improved, but user privacy and anonymity are compromised as the server can track subscriptions and correlate identifiers with operators
Solution Approach 1:
The patent introduces an intermediary component (the intermediate server) that mediates between the eSIM card and the operator management server. This intermediary stores the correspondence between eSIM identifiers and operator server addresses, enabling flexible subscription management while protecting user privacy by preventing direct correlation between the eSIM card and the operator server.
Solution Approach 2:
The patent extracts the identifying information from the direct communication path between the eSIM card and the operator management server. By storing only the necessary correspondence data in the intermediate server and not the full identification details, the system enables subscription management functionality while removing the ability to track and correlate user identities across different operators.
2Loss of information
If the identification value is decorrelated from the physical eSIM card identifier using a changing value based on date, then user anonymity and non-traceability are improved, but the complexity of the identification system increases
Solution Approach 1:
The patent applies dynamics by making the identification value change over time rather than remaining static. The identification value is generated based on the eSIM card identifier combined with a date component, creating a dynamic identifier that evolves periodically. This temporal variation prevents traceability while maintaining a systematic approach to identification.
Solution Approach 2:
The patent changes the parameters of the identification system by introducing a time-based parameter to the identification value. Instead of using a fixed identifier, the system uses a composite identifier that includes both the eSIM card identifier and a date parameter. This parameter change enables anonymity while maintaining structured identification through cryptographic hash functions.
3Productivity
If the intermediate server processes all subscription requests using the eSIM card identifier, then productivity and response time are improved, but security and privacy are reduced as the server can identify and trace the security module
Solution Approach 1:
The patent creates a copy of the identification mechanism by generating an identification value that represents the eSIM card identifier in an anonymized form. This copy maintains the functional capability of identifying the card for subscription processing purposes while eliminating the security risk associated with using the actual eSIM card identifier directly in the intermediate server.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a method for obtaining a download server address for a network access profile by a security module, said method, implemented by the security module, comprising: - providing a subscription data management server of an operator with a security module identifier (EID) on a date (ds) of subscription with said operator, - sending a request for the address from a subscription data management server of the operator to a second server, said request comprising a current anonymous identifier (IDc), calculated by the security module based on its identifier (EID) and a current date (dc), said second server being responsible for searching said current anonymous identifier in at least one set (S) of anonymized identification values, said set (S) being associated with an operator and comprising, for a given security module,a plurality of anonymized identification values, one of said anonymized identification values being calculated based on the security module identifier and a date varying within a time range between an initial date (ds), representing the date of subscription to the operator, and a final date (df) representing the end of validity of the network access profile associated with the subscription.