eUICC Profile Retrieval Using Anonymous Identifiers for EID Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for obtaining network access profiles for eUICC security modules in communication devices expose sensitive physical identifiers, such as EID, to potential hacking and tracing, compromising user privacy without consent, and require direct communication between terminals.
Innovation Solution
A method involving computing an anonymous identifier (TEID) from the physical identifier (EID) and a random parameter, using a one-way function, to transmit this identifier to servers, allowing indirect communication between primary and secondary terminals, ensuring anonymity and privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the physical identifier EID is shared with the intermediate server for profile management, then the flexibility of subscription management is improved, but the privacy protection and security against hacking deteriorate
Solution Approach 1:
The patent introduces an intermediary mechanism where the primary terminal generates an anonymous identifier TEID based on the physical identifier EID and transmits it to the secondary terminal. This TEID acts as a mediator that allows the secondary terminal to communicate with the network without exposing the sensitive EID, thus resolving the contradiction between subscription management flexibility and privacy protection.
Solution Approach 2:
The patent creates a copy of the identifier system by introducing the anonymous identifier TEID as a derivative of EID. This copy maintains the functional equivalence for network communication while eliminating the security risks associated with exposing the original EID, allowing flexible subscription management without compromising privacy.
2Ease of operation
If the EID is transmitted and shared between multiple network entities, then the subscription management functionality is improved, but the risk of data exposure to hacking increases
Solution Approach 1:
The anonymous identifier TEID serves as an intermediary that enables subscription management functionality across multiple network entities without exposing the sensitive EID. The primary terminal generates TEID from EID and transmits it to the secondary terminal, which then uses TEID for all subsequent communications with network servers, eliminating direct exposure of EID to hacking risks.
Solution Approach 2:
The patent changes the identifier parameter from the physical identifier EID to the anonymous identifier TEID for network communications. This parameter transformation maintains the functionality of subscription management while changing the security characteristics, making the identifier resistant to hacking and tracing.
3Device complexity
If direct communication between primary and secondary terminals is used, then the profile loading process is simplified, but the compatibility requirements between different terminals increase
Solution Approach 1:
The patent introduces network servers (discovery server and data preparation server) as intermediaries between the primary and secondary terminals. The primary terminal communicates with the discovery server to obtain the secondary terminal's address, and the data preparation server handles profile loading. This intermediary architecture simplifies the communication process while reducing direct compatibility requirements between different terminal types.
Solution Approach 2:
The patent creates a universal communication framework where the anonymous identifier TEID and the server-based architecture serve multiple functions across different terminal types. The discovery server and data preparation server act as universal intermediaries that handle various subscription management operations, making the system adaptable to different terminal configurations without requiring direct terminal-specific compatibility.
Data Source
AI summary
A method for obtaining a command relating to a network access profile of an eUICC security module incorporated into a communication device and associated with a physical identifier. The communication terminal: obtains the physical identifier and an anonymous identifier of the security module is calculated from the physical identifier and a random parameter; transmits a request to obtain the command, via an “operator server”, to a “preparation server”, the request to obtain including the anonymous identifier of the security module; obtains the random parameter and calculates the anonymous identifier from the physical identifier of the security module and the random parameter; and sends, to a “discovery server”, a request to obtain information intended to obtain the command, this request to obtain information including the anonymous identifier, in order to obtain, in response, from the discovery server, an address of the preparation server.


