eSIM Profile Transfer with User-Key Protection for Private Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing eSIM ecosystem lacks the ability to securely transfer confidential user data between eUICCs without exposing it to mobile network operators, as current security protocols allow decryption and access to such data by MNOs, and eUICCs lack resources to store encrypted profiles entirely before decryption.

Innovation Solution

Implementing an additional encryption layer using a user-specific key to encrypt and protect confidential user data during transfer between eUICCs, ensuring only the user can decrypt and access this data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If eSIM profile data is transferred using the current GSMA security protocol, then the profile can be decrypted and installed on the new device, but confidential user data becomes accessible to mobile network operators and compromises user privacy

Engineering Contradiction:
Improveprofile transfer reliabilityVSAvoiduser data security
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements nested encryption by placing user-specific encryption keys and confidential user data within the eSIM profile structure. The profile contains not only standard operational data but also a nested layer of user-specific cryptographic materials (public keys, encrypted private keys) that create a protected enclave for confidential data, ensuring that even if the outer profile layer is accessed, the inner confidential data remains protected by user-controlled keys.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent applies preliminary action by performing user-specific encryption of confidential data and generation of user-specific key pairs before the profile transfer occurs. The user's public key is embedded in the profile during creation, and confidential data is pre-encrypted with derived encryption keys before transfer. This ensures that security measures are already in place before the vulnerable transfer phase begins, preventing unauthorized access during transmission and installation.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If additional user-specific encryption layers are added to protect confidential data, then user privacy is enhanced, but the complexity of the encryption and decryption process increases

Engineering Contradiction:
Improveconfidential data protectionVSAvoidencryption process complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the user's device to autonomously perform cryptographic operations using embedded user-specific key pairs. The confidential data is encrypted on the user's device using keys that only the user controls, and the decryption capability is self-contained within the target device. This eliminates the need for external key management services or operator intervention, reducing system complexity while maintaining strong security through user-owned cryptographic credentials.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If the MNO profile storage server stores encrypted profiles without additional security layers, then profile installation is simplified, but the MNO can decrypt and read personalized confidential data

Engineering Contradiction:
Improveprofile installation easeVSAvoidoperator access to user data
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies asymmetry by implementing asymmetric (public-private key) cryptography where the user's public key is embedded in the profile for encryption purposes, but the corresponding private key remains exclusively controlled by the user and never stored on the MNO's server. This creates an asymmetric security architecture where the profile can be encrypted and stored using the public key, making it mathematically infeasible for the MNO to decrypt the data even though they control the storage infrastructure. The asymmetry between public key availability and private key secrecy protects user data while allowing simplified storage operations.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentEP4525359B1Method for transferring esim profile data
Publication Date: 2026.04.29 NXP BV
  • EP4525359B1 patent drawingFigure 1
  • EP4525359B1 patent drawingFigure 2
  • EP4525359B1 patent drawingFigure 3

AI summary

Method for transferring eSIM profile data (30) from a first wireless communication device (D1) having a first eUICC device (100) to a second wireless communication device (D2) having a second eUICC device (200), comprising the steps: a. providing encrypted eSIM profile data (30) together with encrypted confidential user data (CD 1... CDn) on the first eUICC device (100), the encrypted eSIM profile data (30) having been encrypted by means of profile encryption keys (30), wherein the encrypted confidential user data (CD 1... CDn) has been encrypted at least partially by means of a user key (UK); b. transferring the encrypted eSIM profile data (30) together with the encrypted confidential user data (CD 1... CDn) from the first eUICC device (100) to the second eUICC device (200); and c. decrypting and installing the encrypted eSIM profile data (30) on the second wireless communication device (D2), wherein the confidential user data (CD 1... CDn) are decrypted and installed on the second wireless communication device (D2) at least partially by means of the user key (UK).