eSIM Anonymity via Dynamic Hashed Identifiers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing subscriptions on eSIM cards in consumer mobile equipment raise privacy concerns as intermediate servers can track user subscriptions and correlate eSIM card identifiers with operators, compromising user anonymity.

Innovation Solution

A method that decorrelates the identification value from the physical eSIM card identifier, using a changing identification value based on date, ensuring anonymity and non-traceability by generating a set of anonymized identification values for the subscription data management server, which are calculated using a hash function and a prime number, making it difficult for the server to trace successive subscriptions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If an intermediate server stores correspondences between eSIM card identifier and operator management server address to enable subscription management, then subscription flexibility and ease of operation are improved, but user privacy and anonymity are compromised as the server can track subscriptions and correlate identifiers with operators

Engineering Contradiction:
Improvesubscription managementVSAvoiduser privacy
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces an intermediary component (the intermediate server) that mediates between the eSIM card and the operator management server. This intermediary stores the correspondence between eSIM identifiers and operator server addresses, enabling flexible subscription management while protecting user privacy by preventing direct correlation between the eSIM card and the operator server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the identifying information from the direct communication path between the eSIM card and the operator management server. By storing only the necessary correspondence data in the intermediate server and not the full identification details, the system enables subscription management functionality while removing the ability to track and correlate user identities across different operators.

Inventive Principle:
Principle #2Taking out (Extraction)

2Loss of information

If the identification value is decorrelated from the physical eSIM card identifier using a changing value based on date, then user anonymity and non-traceability are improved, but the complexity of the identification system increases

Engineering Contradiction:
Improveuser anonymityVSAvoididentification system
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies dynamics by making the identification value change over time rather than remaining static. The identification value is generated based on the eSIM card identifier combined with a date component, creating a dynamic identifier that evolves periodically. This temporal variation prevents traceability while maintaining a systematic approach to identification.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of the identification system by introducing a time-based parameter to the identification value. Instead of using a fixed identifier, the system uses a composite identifier that includes both the eSIM card identifier and a date parameter. This parameter change enables anonymity while maintaining structured identification through cryptographic hash functions.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If the intermediate server processes all subscription requests using the eSIM card identifier, then productivity and response time are improved, but security and privacy are reduced as the server can identify and trace the security module

Engineering Contradiction:
Improvesubscription processingVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent creates a copy of the identification mechanism by generating an identification value that represents the eSIM card identifier in an anonymized form. This copy maintains the functional capability of identifying the card for subscription processing purposes while eliminating the security risk associated with using the actual eSIM card identifier directly in the intermediate server.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3651408B1Method of anonymous identification of a security module
Publication Date: 2024.06.05 ORANGE SA
  • EP3651408B1 patent drawingFigure 1
  • EP3651408B1 patent drawingFigure 2
  • EP3651408B1 patent drawing

AI summary

The invention relates to a method for obtaining a download server address for a network access profile by a security module, said method, implemented by the security module, comprising: - providing a subscription data management server of an operator with a security module identifier (EID) on a date (ds) of subscription with said operator, - sending a request for the address from a subscription data management server of the operator to a second server, said request comprising a current anonymous identifier (IDc), calculated by the security module based on its identifier (EID) and a current date (dc), said second server being responsible for searching said current anonymous identifier in at least one set (S) of anonymized identification values, said set (S) being associated with an operator and comprising, for a given security module,a plurality of anonymized identification values, one of said anonymized identification values ​​being calculated based on the security module identifier and a date varying within a time range between an initial date (ds), representing the date of subscription to the operator, and a final date (df) representing the end of validity of the network access profile associated with the subscription.