eSIM Recovery via Cloud Verification and eUICC Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Recovery of an electronic subscriber identity module (eSIM) from an embedded Universal Integrated Circuit Card (eUICC) of a mobile wireless device is challenging due to the need for direct interaction with Mobile Network Operators (MNOs) when cellular connectivity is lost, and there is a lack of secure and efficient mechanisms for eSIM recovery.
Innovation Solution
The solution involves uploading eSIM subscription information to a cloud network services server and storing a portion locally before deletion, requiring secure user authentication, cross verification, and authorization from an MNO provisioning server to reinstall the eSIM on the eUICC, using multi-factor authentication and cryptographic methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If eSIM deletion requires direct interaction with MNO, then service security is improved, but user convenience deteriorates when cellular connectivity is lost
Solution Approach 1:
The patent introduces a cloud network service as an intermediary between the user device and MNO. When cellular connectivity is unavailable, the cloud service mediates the eSIM recovery process by receiving authentication credentials from the device, verifying them, and coordinating with the MNO provisioning server. This eliminates the need for direct real-time cellular connection between device and MNO, resolving the contradiction between security (maintained through verified authentication) and convenience (restored through cloud-mediated async communication).
Solution Approach 2:
The system performs preliminary actions by pre-configuring the cloud network service with device identifiers and authentication credentials before connectivity is lost. When eSIM deletion or recovery is needed, the device can communicate these pre-configured credentials to the cloud service, which has already prepared the necessary verification mechanisms. This preliminary setup enables recovery operations without requiring immediate MNO interaction, balancing security requirements with operational convenience.
2Reliability
If eSIM information is stored only on eUICC, then security is improved, but recovery efficiency deteriorates after deletion
Solution Approach 1:
The patent implements a copying mechanism where eSIM information is replicated between the eUICC (secure storage) and a cloud network service (accessible storage). The cloud service maintains a copy of the eSIM profile data, including authentication credentials and service information. When recovery is needed, the cloud service can quickly provision the eSIM without requiring complex retrieval from secure eUICC storage, thereby improving recovery efficiency while the eUICC copy maintains security through its hardware-based protection.
Solution Approach 2:
The eSIM information is segmented into different storage locations with different security and access characteristics: sensitive authentication credentials remain in the secure eUICC, while service profile data is copied to the cloud for efficient access. This segmentation allows the system to balance security (protected credentials in eUICC) with recovery efficiency (accessible profile data in cloud), resolving the contradiction between these two requirements.
3Ease of operation
If cloud storage of eSIM data is implemented, then recovery convenience is improved, but security risks increase
Solution Approach 1:
The patent applies local quality by implementing different security measures for different data components stored in the cloud. Sensitive authentication credentials are encrypted with device-specific keys before cloud transmission, while less sensitive service profile information is stored in plaintext for efficient access. This differentiated security approach enables recovery convenience through cloud accessibility while mitigating security risks through targeted protection of only the most sensitive data elements.
Solution Approach 2:
The system performs preliminary security actions by encrypting eSIM data with device-specific cryptographic keys before uploading to the cloud. This pre-encryption ensures that even if cloud storage is compromised, the data remains protected. The cloud service stores only encrypted credentials and uses them only for verification purposes without decrypting them, thereby enabling recovery convenience through cloud accessibility while maintaining security through cryptographic protection.
Data Source
AI summary
The described embodiments set forth techniques for recovering one or more electronic subscriber identity modules (eSIMs) previously deleted from an embedded universal integrated circuit card (eUICC) of a mobile wireless device. Prior to deletion of an eSIM, the mobile wireless device uploads first eSIM subscription information to a cloud network services server and stores second eSIM subscription information in a secure memory of the eUICC. The mobile wireless device can subsequently download the first eSIM subscription information to verify matching to the second eSIM subscription information stored in the eUICC before displaying an option for recovering the eSIM. The mobile wireless device sends to a mobile network operator (MNO) provisioning server an eSIM recovery request notification that includes at least a portion of the first eSIM subscription information, and the MNO provisioning server provides an eSIM recovery response message indicating approval and a network address to download the eSIM.


