eSIM Secure Delivery via Wireless Network

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SIM card solutions are inflexible, requiring physical replacement for account changes and not allowing for secure management or modification of user accounts across different network carriers, leading to inefficiencies in access control and service usage.

Innovation Solution

The method involves establishing an authorized data session over a wireless network to deliver and assemble an electronic Subscriber Identity Module (eSIM) securely, enabling flexible management of access control clients and user accounts without the need for physical SIM card changes, using cryptographic key protocols and software updates to configure and activate new accounts on devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical SIM cards are used for access control, then security authentication is established, but flexibility for account changes and multi-carrier support deteriorates

Engineering Contradiction:
Improvesecurity authenticationVSAvoidflexibility for account changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The SIM functionality is segmented into two separate components: a secure authentication module (separated from the physical SIM card) and a flexible account management system. The authentication security is isolated in a dedicated security module that remains on the device, while account profiles can be independently downloaded and managed, allowing flexible switching between carriers without physical SIM changes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of requiring physical SIM cards for each carrier account, the system creates digital copies of account profiles that can be downloaded and stored electronically. These copied account credentials can be activated and deactivated software-based, providing the flexibility of multiple accounts without the constraints of physical card limitations.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If multiple physical SIM cards are provided for multi-account support, then account versatility is improved, but device complexity and space requirements worsen

Engineering Contradiction:
Improvemulti-account supportVSAvoidmultiple card receptacles
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal account management platform that can handle multiple carrier accounts through a single interface and storage system. Instead of requiring separate physical SIM card slots for each carrier, the device provides a unified system that can load and manage multiple account profiles electronically, making the device adaptable to different carriers without adding physical complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If SIM software is hardcoded to physical UICC media, then security is maintained, but ability to modify and manage accounts remotely deteriorates

Engineering Contradiction:
ImproveSIM securityVSAvoidremote account management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The account management functionality is extracted from the immutable physical SIM card and separated into a remotely updatable software component. The core authentication security remains anchored in the device's secure hardware, while the account profile management is taken out and placed in a flexible software layer that can be downloaded, updated, and managed remotely through wireless connections.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

An intermediary account management system is introduced between the user and the authentication security module. This intermediary layer handles the downloading, storage, and activation of account profiles, mediating between remote carrier systems and the device's security module, thereby enabling remote account management while preserving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10206106B2Methods and apparatus for delivering electronic identification components over a wireless network
Publication Date: 2019.02.12 APPLE INC
  • US10206106B2 patent drawing
  • US10206106B2 patent drawing
  • US10206106B2 patent drawing

AI summary

Methods and apparatus enabling programming of electronic identification information of a wireless apparatus. In one embodiment, a previously purchased or deployed wireless apparatus is activated by a cellular network. The wireless apparatus connects to the cellular network using an access module to download operating system components and/or access control client components. The described methods and apparatus enable updates, additions and replacement of various components including Electronic Subscriber Identity Module (eSIM) data, OS components. One exemplary implementation of the invention utilizes a trusted key exchange between the device and the cellular network to maintain security.