eUICC Dynamic Authentication Algorithm Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile devices are limited in their ability to dynamically support different authentication algorithms when interacting with Mobile Network Operators (MNOs), as traditional SIM cards are not easily modifiable, leading to impractical widespread replacement requirements for new algorithms.
Innovation Solution
The implementation of an embedded Universal Integrated Circuit Card (eUICC) within mobile devices, which manages and executes various authentication algorithms by receiving selections, querying for identifiers and parameters, and providing these to establish secure connections with MNOs, allowing for dynamic support of different authentication methods through eSIMs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional SIM cards are used with fixed authentication algorithms, then manufacturing simplicity is maintained, but authentication algorithm flexibility deteriorates
Solution Approach 1:
The patent implements dynamic authentication algorithm selection by allowing the mobile device to query the eSIM for an identifier corresponding to an authentication algorithm and then dynamically select and execute the appropriate algorithm. This transforms the static SIM card into a dynamic system that can adapt to different authentication methods without physical replacement.
Solution Approach 2:
The patent adds a software/digital dimension to the traditional hardware-based SIM card system. By embedding the SIM directly into the device (eUICC) and using downloadable eSIM profiles with algorithm identifiers, the system moves from physical card replacement to digital configuration, adding flexibility without increasing physical complexity.
2Reliability
If new authentication algorithms are deployed through replacement SIM cards, then authentication security is improved, but deployment time and cost increase
Solution Approach 1:
The patent implements preliminary action by pre-configuring multiple authentication algorithm profiles within the eSIM before deployment. When a new authentication algorithm needs to be deployed, the device can query for and switch to a pre-prepared profile containing the new algorithm identifier and parameters, eliminating the need for physical SIM replacement and enabling rapid security updates.
Solution Approach 2:
The patent uses copying by creating digital copies of authentication profiles (eSIMs) that can be downloaded and installed electronically. Instead of physically replacing SIM cards, the system copies authentication algorithm definitions and parameters to the device's embedded secure element, enabling rapid deployment of new algorithms without manufacturing or physical distribution delays.
3Adaptability or versatility
If eSIMs with multiple authentication algorithms are implemented, then authentication flexibility is improved, but device complexity increases
Solution Approach 1:
The patent introduces an intermediary mechanism - a selection module that queries the eSIM for an identifier corresponding to an authentication algorithm and automatically selects the appropriate algorithm based on the identifier. This intermediary layer manages the complexity of multiple algorithms by providing a simple query-select-execute interface, shielding users from the underlying complexity while maintaining flexibility.
Solution Approach 2:
The patent implements self-service by enabling the mobile device to automatically query the eSIM for authentication algorithm identifiers and parameters, then autonomously select and execute the appropriate algorithm without user intervention. The system self-manages the complexity of multiple authentication methods through automated querying, selection, and execution processes.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Disclosed herein are different techniques for enabling a mobile device to dynamically support different authentication algorithms. A first technique involves configuring an eUICC included in the mobile device to implement various authentication algorithms that are utilized by MNOs (e.g., MNOs with which the mobile device can interact). Specifically, this technique involves the eUICC storing executable code for each of the various authentication algorithms. According to this technique, the eUICC is configured to manage at least one eSIM, where the eSIM includes (i) an identifier that corresponds to one of the various authentication algorithms implemented by the eUICC, and (ii) authentication parameters that are compatible with the authentication algorithm. A second technique involves configuring the eUICC to interface with an eSIM to extract (i) executable code for an authentication algorithm used by an MNO that corresponds to the eSIM, and (ii) authentication parameters that are compatible with the authentication algorithm.