eSIM ID Mapping via Trusted Intermediary for Seamless Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems, such as those defined by the GSMA, restrict access to the embedded Universal Integrated Circuit Card (eUICC) ID, limiting seamless provisioning and service management for mobile devices, particularly for third-party enterprise customers of mobile network operators (MNOs), as they do not allow direct access or sharing of the eUICC ID with applications or services.
Innovation Solution
Mapping the International Mobile Equipment Identity (IMEI) to the eUICC ID and storing this mapping in secure, persistent storage on the mobile device, making it accessible via an API for service providers, enabling them to provision devices and manage subscriptions without relying on the Local Profile Assistant (LPA) and allowing for over-the-air (OTA) dynamic SIM profile updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If eUICC ID access is restricted according to GSMA standards, then security and credential protection are improved, but device provisioning efficiency and service management capability deteriorate
Solution Approach 1:
The patent introduces a trusted intermediary component (secure element or trusted execution environment) that mediates between applications and the eUICC ID. This intermediary securely stores and manages the eUICC ID, allowing controlled access to authorized applications while maintaining security. The intermediary acts as a gateway that enforces access policies without exposing the actual credential, thus resolving the contradiction between security and accessibility.
Solution Approach 2:
The system segments the eUICC ID access control into multiple layers: the actual eUICC ID remains protected in the secure element, while a separate trusted intermediary manages access rights and policies. This segmentation allows different applications to have different levels of access without compromising the core credential security, enabling efficient provisioning for authorized services while maintaining strong security boundaries.
2Reliability
If eUICC ID is not shared with third-party applications, then credential security is maintained, but seamless provisioning and automated service management cannot be achieved
Solution Approach 1:
The patent implements self-service provisioning mechanisms where the trusted intermediary automatically manages eUICC ID distribution and access control without requiring manual user intervention or direct exposure of credentials. The system autonomously handles service provisioning requests, matching applications with appropriate eUICC IDs based on pre-configured policies, thereby achieving seamless provisioning while maintaining security through automated, policy-driven access control.
Solution Approach 2:
The system performs preliminary actions by pre-configuring access policies and permissions for the trusted intermediary before actual service provisioning occurs. Application identities and access rights are established in advance, allowing rapid, seamless provisioning when services are needed without compromising security. This preliminary setup enables automated service management while maintaining strong credential protection.
3Adaptability or versatility
If direct eUICC ID access is provided to applications, then service management flexibility is improved, but security risks and unauthorized access increase
Solution Approach 1:
The patent applies local quality by providing different levels of eUICC ID access to different applications based on their specific needs and authorized permissions. The trusted intermediary implements fine-grained access control policies that grant appropriate access rights to specific applications while denying access to others, thereby achieving service management flexibility for authorized applications while maintaining security by restricting access for unauthorized ones.
Data Source
AI summary
Mobile communications devices are provisioned using unique device information. A request may be received by a device from an application executing on the device. The request may be for unique identification data for an embedded Universal Integrated Circuit Card (eUICC) installed on the device. In response to the request, the device may access the unique identification data from a persistent storage of the computing device. The unique identification data may be provided to the requesting application via an interface.


