eUICC Profile Retrieval Using Anonymous Identifiers for EID Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for obtaining network access profiles for eUICC security modules in communication devices expose sensitive physical identifiers, such as EID, to potential hacking and tracing, compromising user privacy without consent, and require direct communication between terminals.

Innovation Solution

A method involving computing an anonymous identifier (TEID) from the physical identifier (EID) and a random parameter, using a one-way function, to transmit this identifier to servers, allowing indirect communication between primary and secondary terminals, ensuring anonymity and privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the physical identifier EID is shared with the intermediate server for profile management, then the flexibility of subscription management is improved, but the privacy protection and security against hacking deteriorate

Engineering Contradiction:
Improveflexibility of subscription managementVSAvoidprivacy protection and security against hacking
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary mechanism where the primary terminal generates an anonymous identifier TEID based on the physical identifier EID and transmits it to the secondary terminal. This TEID acts as a mediator that allows the secondary terminal to communicate with the network without exposing the sensitive EID, thus resolving the contradiction between subscription management flexibility and privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the identifier system by introducing the anonymous identifier TEID as a derivative of EID. This copy maintains the functional equivalence for network communication while eliminating the security risks associated with exposing the original EID, allowing flexible subscription management without compromising privacy.

Inventive Principle:
Principle #26Copying

2Ease of operation

If the EID is transmitted and shared between multiple network entities, then the subscription management functionality is improved, but the risk of data exposure to hacking increases

Engineering Contradiction:
Improvesubscription management functionalityVSAvoiddata exposure to hacking
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The anonymous identifier TEID serves as an intermediary that enables subscription management functionality across multiple network entities without exposing the sensitive EID. The primary terminal generates TEID from EID and transmits it to the secondary terminal, which then uses TEID for all subsequent communications with network servers, eliminating direct exposure of EID to hacking risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the identifier parameter from the physical identifier EID to the anonymous identifier TEID for network communications. This parameter transformation maintains the functionality of subscription management while changing the security characteristics, making the identifier resistant to hacking and tracing.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If direct communication between primary and secondary terminals is used, then the profile loading process is simplified, but the compatibility requirements between different terminals increase

Engineering Contradiction:
Improveprofile loading processVSAvoidterminal compatibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent introduces network servers (discovery server and data preparation server) as intermediaries between the primary and secondary terminals. The primary terminal communicates with the discovery server to obtain the secondary terminal's address, and the data preparation server handles profile loading. This intermediary architecture simplifies the communication process while reducing direct compatibility requirements between different terminal types.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal communication framework where the anonymous identifier TEID and the server-based architecture serve multiple functions across different terminal types. The discovery server and data preparation server act as universal intermediaries that handle various subscription management operations, making the system adaptable to different terminal configurations without requiring direct terminal-specific compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12507062B2Method for obtaining a command relating to a network access profile of an eUICC security module
Publication Date: 2025.12.23 ORANGE SA
  • US12507062B2 patent drawing
  • US12507062B2 patent drawing
  • US12507062B2 patent drawing

AI summary

A method for obtaining a command relating to a network access profile of an eUICC security module incorporated into a communication device and associated with a physical identifier. The communication terminal: obtains the physical identifier and an anonymous identifier of the security module is calculated from the physical identifier and a random parameter; transmits a request to obtain the command, via an “operator server”, to a “preparation server”, the request to obtain including the anonymous identifier of the security module; obtains the random parameter and calculates the anonymous identifier from the physical identifier of the security module and the random parameter; and sends, to a “discovery server”, a request to obtain information intended to obtain the command, this request to obtain information including the anonymous identifier, in order to obtain, in response, from the discovery server, an address of the preparation server.