eSIM Type Parameter Protection via Segmented File Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Embedded Universal Integrated Circuit Cards (eUICCs) face challenges in maintaining security and robustness, particularly when Type parameters associated with electronic Subscriber Identity Modules (eSIMs) are erroneously updated by mobile network operators (MNOs, leading to confusion and degradation of user experience.

Innovation Solution

Implementing methods to protect eSIM Type parameters by modifying file access properties, establishing logical containers, and utilizing an Operating System (OS) registry to prevent unauthorized modifications, ensuring the integrity of Type parameters during over-the-air updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If MNOs are allowed to update eSIM Type parameters via OTA updates, then service flexibility and update capability are improved, but security and reliability deteriorate due to erroneous modifications

Engineering Contradiction:
Improveservice flexibilityVSAvoidparameter integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the eSIM file system into multiple directories with different access permissions. The Type parameter is stored in a protected directory that is segmented from the general updateable areas, allowing MNOs to update service parameters while preventing modification of critical Type parameters.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different directories within the eSIM file system are assigned different access permissions and security characteristics. The directory containing Type parameters has restricted write access, while other directories allow normal OTA updates, creating local quality differences in security and accessibility.

Inventive Principle:
Principle #3Local quality

2Reliability

If Type parameters are made read-only to prevent modification, then reliability is improved, but adaptability deteriorates as legitimate updates are blocked

Engineering Contradiction:
Improveparameter integrityVSAvoidupdate capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies different access permissions to different parts of the eSIM file system. Rather than making the entire eSIM read-only, only specific directories containing Type parameters have restricted write access, while other areas remain updateable, creating localized security measures.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The file system is segmented into protected and updateable zones. Type parameters reside in a protected segment that prevents erroneous modification, while service configuration parameters reside in updateable segments that allow legitimate OTA updates.

Inventive Principle:
Principle #1Segmentation

3Reliability

If file access permissions are restricted for Type parameters, then security is improved, but device complexity increases due to additional permission management

Engineering Contradiction:
ImprovesecurityVSAvoidpermission management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent establishes file access permissions for Type parameters during the initial eSIM provisioning process. By pre-configuring the protected directory structure and access rights before the eSIM is activated, the system avoids the need for complex runtime permission management while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9736678B2Tamper prevention for electronic subscriber identity module (eSIM) type parameters
Publication Date: 2017.08.15 APPLE INC
  • US9736678B2 patent drawing
  • US9736678B2 patent drawing
  • US9736678B2 patent drawing

AI summary

Disclosed herein are various techniques for preventing or at least partially securing parameters—e.g., Type parameters—of electronic Subscriber Identity Modules (eSIMs) stored within an embedded Universal Integrated Circuit Card (eUICC) from being inappropriately modified by mobile network operators (MNOs). One embodiment sets forth a technique that involves modifying file access properties of the Type parameters of eSIMs to make the Type parameters readable, but not updatable by the MNOs. Another embodiment sets forth a technique that involves implementing eSIM logical containers that separate the Type parameters from the eSIM data within the eUICC, such that the Type parameters are inaccessible to the MNOs. Yet another embodiment sets forth a technique that involves implementing an Operating System (OS)-based registry that is inaccessible to the MNOs and manages Type parameters for the eSIMs that are stored by the eUICC.