eSIM Network Infrastructure for Secure Virtual SIM Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtualized SIM operation in wireless communication systems poses challenges for network operators and device manufacturers regarding secure distribution, uniqueness, and conservation of access control clients, as traditional SIM solutions are hardware-based and difficult to clone, whereas software-based solutions lack equivalent security and management capabilities.

Innovation Solution

A network infrastructure that enables secure electronic delivery and management of electronic Subscriber Identity Modules (eSIMs) to electronic Universal Integrated Circuit Cards (eUICCs), using a system with eSIM managers, eUICC managers, and depots to protect, track, and authorize access control clients, ensuring secure delivery and conservation through encryption and trusted relationships.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional hardware-based SIM solutions are used, then security and anti-cloning capabilities are maintained, but device size is increased and functionality is limited

Engineering Contradiction:
ImprovesecurityVSAvoiddevice size
Core Design Contradiction:
ReliabilityVSVolume of moving object

Solution Approach 1:

The patent creates a virtual copy of the SIM card functionality through software (eSIM) that replicates the security and authentication capabilities of hardware SIM cards. The eSIM application contains the same authentication algorithms, key management, and security protocols as traditional SIM cards, allowing it to function as a secure credential storage device without requiring physical hardware presence

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical hardware-based SIM card system with a software-based eSIM system. The physical SIM card (mechanical component) is substituted with an electronic application that runs on the device's existing secure elements or trusted execution environments, eliminating the need for a separate physical card while maintaining security functions

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If virtualized SIM operation is implemented, then device size is reduced and functionality is increased, but security and management capabilities deteriorate

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The eSIM application is nested within the device's existing secure hardware elements or trusted execution environments. The virtual SIM software leverages the security infrastructure already present in modern devices (secure elements, hardware security modules, or TEEs), embedding the eSIM functionality within these protected environments to inherit their security properties

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces an eSIM manager as an intermediary component that mediates between the eSIM application and the network infrastructure. This manager handles secure provisioning, authentication, and key management, acting as a trusted intermediary that ensures the security of the virtualized SIM operation while enabling flexible functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If software-based SIM solutions are used, then distribution flexibility is improved, but conservation and uniqueness control worsen

Engineering Contradiction:
Improvedistribution flexibilityVSAvoidconservation
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The eSIM applications are pre-configured with unique identifiers, authentication keys, and profile information before being distributed to devices. The eSIM manager performs preliminary provisioning and validation to ensure each eSIM is unique and properly configured, preventing duplication and ensuring conservation of authentication credentials

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The eSIM manager implements feedback mechanisms to track and monitor eSIM distribution, activation, and usage. This feedback system allows the network operator to maintain an accurate inventory of eSIMs, verify uniqueness, and control conservation by detecting and preventing unauthorized duplication or misuse of eSIM credentials

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9419970B2Electronic access client distribution apparatus and methods
Publication Date: 2016.08.16 APPLE INC
  • US9419970B2 patent drawing
  • US9419970B2 patent drawing
  • US9419970B2 patent drawing

AI summary

Apparatus and methods for distributing access control clients. In one exemplary embodiment, a network infrastructure is disclosed that enables delivery of electronic subscriber identity modules (eSIMs) to secure elements (e.g., electronic Universal Integrated Circuit Cards (eUICCs), etc.) The network architecture includes one or more of: (i) eSIM appliances, (ii) secure eSIM storages, (iii) eSIM managers, (iv) eUICC appliances, (v) eUICC managers, (vi) service provider consoles, (vii) account managers, (viii) Mobile Network Operator (MNO) systems, (ix) eUICCs that are local to one or more devices, and (x) depots. Moreover, each depot may include: (xi) eSIM inventory managers, (xii) system directory services, (xiii) communications managers, and/or (xiv) pending eSIM storages. Functions of the disclosed infrastructure can be flexibly partitioned and/or adapted such that individual parties can host portions of the infrastructure. Exemplary embodiments of the present invention can provide redundancy, thus ensuring maximal uptime for the overall network (or the portion thereof).