eSIM Subscription Transfer Security via Signed Payloads

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current GSMA specification for device-to-device eSIM subscription transfers lacks security measures beyond client/server authentication and does not provide adequate gating events or notifications for safe transfer, particularly in scenarios where the same eSIM/ICCID is used for both source and target devices.

Innovation Solution

Incorporating a server nonce and eUICC-based security into the eSIM subscription transfer process, with the eUICC generating a signed payload using the source device's ICCID and optionally the target device's EID, and utilizing a secure processor subsystem for authorization to ensure secure transfer, along with user confirmation codes and hashes for added security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device-to-device eSIM subscription transfer is implemented without additional security measures, then the transfer process is simple and fast, but security vulnerabilities occur allowing replay attacks and unauthorized access

Engineering Contradiction:
Improvetransfer securityVSAvoidsecurity mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by requiring the source device to generate and transmit a signed payload containing a server nonce and source device information before the actual subscription transfer occurs. This preliminary authentication step ensures that only authorized transfers are processed, preventing replay attacks and unauthorized access while maintaining a relatively simple overall flow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism through the server nonce and signed payload structure. The server nonce acts as a mediator between the source and target devices, verifying authenticity without requiring direct trust between devices. This intermediary approach enhances security without significantly complicating the device-to-device transfer process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the same eSIM/ICCID is used for both source and target devices, then device reuse is efficient, but service conflicts and unauthorized access risks increase

Engineering Contradiction:
Improvedevice reuse capabilityVSAvoidservice conflict risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms through gating events and notifications that provide status information about the subscription transfer process. The target device receives feedback about the transfer state, and the system provides notifications about transfer completion or failures. This feedback loop prevents service conflicts by ensuring the source device is properly deactivated before the target device activates the subscription.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary action by requiring explicit user confirmation codes and hashes before the subscription transfer is finalized. This preliminary verification step ensures that the user intentionally initiates the transfer, preventing unauthorized access and service conflicts that might otherwise occur with eSIM reuse.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security measures including server nonce and signed payload are added, then replay attacks are prevented, but the transfer process becomes more complex

Engineering Contradiction:
Improveanti-replay securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by modifying the existing eSIM transfer parameters to include a server nonce and signed payload structure. These parameter changes enhance security against replay attacks while maintaining compatibility with existing eSIM infrastructure. The changes are made to the data structure rather than the fundamental transfer mechanism, minimizing added complexity.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If user confirmation codes and hashes are implemented, then unauthorized access is protected against, but user interaction requirements increase

Engineering Contradiction:
Improveunauthorized access protectionVSAvoiduser confirmation requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies self-service by having the system automatically generate and manage the confirmation codes and hashes without requiring manual user input for each security step. The user simply needs to initiate the transfer process, and the system handles the cryptographic operations and verification automatically, maintaining ease of operation while providing strong protection against unauthorized access.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20230171585A1Device-to-Device Secure Embedded Subscriber Identity Module Subscription Transfer
Publication Date: 2023.06.01 APPLE INC
  • US20230171585A1 patent drawing
  • US20230171585A1 patent drawing
  • US20230171585A1 patent drawing

AI summary

Systems and methods for facilitating transfer of an eSIM subscription from a source device to a target device. In one embodiment, a source device includes a transceiver and a processor system. The processor system includes an eUICC configured to store an eSIM associated with an eSIM subscription. The processor system is configured to transmit, via the transceiver and to an eSIM subscription manager server, a request for an eSIM subscription transfer activation code; receive, via the transceiver and at least partly in response to the request, a server nonce; generate a signed payload using the server nonce and source device information; transmit, via the transceiver and to the eSIM subscription manager server, the signed payload; receive, via the transceiver and in response to transmitting the signed payload, the eSIM subscription transfer activation code; and provide the eSIM subscription transfer activation code to the target device or a user thereof.