eSIM Pre-Encryption for Scalable Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional approaches for securely preparing and provisioning electronic Subscriber Identity Modules (eSIMs) to embedded Universal Integrated Circuit Cards (eUICCs) face scalability issues, particularly when concurrently provisioning millions of eSIMs, as real-time encryption is required, and existing methods restrict pre-encryption to a single eSIM per target eUICC, limiting flexibility in mobile network operator selection.
Innovation Solution
Pre-encrypting eSIMs with a randomly-generated symmetric key that is later decrypted using a target eUICC's specific ephemeral public key, and utilizing Profile Issuer Security Domains (ISD-Ps), ephemeral public key copies, or Message Authentication Codes (MACs) to enable multiple eSIMs to be pre-encrypted for a target eUICC, allowing secure decryption and installation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If real-time encryption of eSIMs is performed during provisioning sessions, then security is maintained, but system scalability deteriorates due to processing overhead
Solution Approach 1:
The patent applies preliminary action by pre-generating encryption keys and preparing eSIM profiles before the actual provisioning session. The key derivation is performed in advance using the eUICC's identification data, and eSIM profiles are encrypted with symmetric keys beforehand. This eliminates the need for real-time key derivation during provisioning sessions, significantly reducing processing overhead and improving system scalability while maintaining security.
2Device complexity
If only a single eSIM is pre-encrypted per target eUICC, then decryption complexity is reduced, but flexibility in mobile network operator selection is limited
Solution Approach 1:
The patent applies segmentation by dividing the eUICC into multiple Profile Issuer Security Domains (ISD-Ps), where each ISD-P can store a separate ephemeral key pair. This allows multiple eSIM profiles to be pre-encrypted with different symmetric keys, each associated with a different mobile network operator. The eUICC can then select and decrypt the appropriate eSIM profile based on the desired operator, significantly enhancing flexibility while managing complexity through structured organization.
Solution Approach 2:
The patent changes the parameter of key storage capacity from a single ephemeral key pair to multiple ephemeral key pairs, one for each ISD-P. This parameter change enables the eUICC to handle multiple pre-encrypted eSIM profiles corresponding to different mobile network operators. The systematic organization of multiple key pairs across different ISD-Ps allows the system to manage increased complexity while providing enhanced adaptability and operator selection flexibility.
Data Source
AI summary
Methods for provisioning electronic Subscriber Identity Modules (eSIMs) to electronic Universal Integrated Circuit Cards (eUICCs) are provided. One method involves a provisioning server configured to encrypt the eSIM with a symmetric key (Ke). The provisioning server, upon identifying a target eUICC, encrypts the symmetric key with a key encryption key (KEK) derived based at least in part on a private key associated with the provisioning server and a public key associated with the target eUICC. The provisioning server generates an eSIM package including the encrypted eSIM, the encrypted symmetric key, a public key corresponding to the private key associated with the provisioning server, as well as additional information that enables the target eUICC to, upon receipt of the eSIM package, identify a private key that corresponds to the public key associated with the target eUICC and used to derive the KEK.


