eUICC Authentication Key Encapsulation for Secure Provider Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Embedded UICC (eUICC) in terminals, such as M2M communication devices, cannot be easily replaced, making it difficult to change mobile communication providers without compromising security, as existing methods for providing provider information lack defined interfaces and security measures.
Innovation Solution
A method and device for securely providing mobile communication provider information to an eUICC by encapsulating authentication-key information within an authentication processing module, which is stored in the eUICC, using a server-generated encapsulation module transmitted via a secure over-the-air communication scheme, ensuring high security and preventing exposure of the authentication key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Strength
If eUICC is integrated with terminal during manufacture, then durability and resistance to damage are improved, but ability to change mobile communication provider is worsened
Solution Approach 1:
The authentication key is segmented from the eUICC structure and stored separately in an authentication processing module within the terminal, allowing the key to be updated independently of the eUICC hardware. This enables provider changes while maintaining the integrated eUICC structure for durability.
Solution Approach 2:
An authentication processing module acts as an intermediary between the eUICC and the authentication key. This module stores the key securely and manages authentication operations, allowing key updates without physical eUICC replacement while maintaining security.
2Ease of operation
If authentication key is provided independently to eUICC, then ease of provider change is improved, but security is worsened
Solution Approach 1:
The authentication key is nested within the authentication processing module rather than being stored independently or directly in the eUICC. This nested structure provides secure containment while enabling remote updates through the module's interface capabilities.
Solution Approach 2:
The physical mechanical system of removing and replacing eUICC cards is replaced with an electronic/software-based system where the authentication key is remotely provisioned to the authentication processing module. This substitution maintains security while enabling easy provider changes.
3Device complexity
If existing UICC provision method is directly applied to eUICC, then implementation simplicity is improved, but security is worsened due to lack of defined interface
Solution Approach 1:
The authentication processing module serves as an intermediary that implements a defined interface between the terminal and eUICC for key provisioning. This interface enables secure, controlled key updates while maintaining implementation simplicity through standardized communication protocols.
Data Source
AI summary
A method for providing mobile communication provider information and a device for performing the same are disclosed. A terminal having an eUICC receives data, in which mobile communication provider information is capsulized and included, and stores the received data in the eUICC. Therefore, the mobile communication provider information can be transferred by applying the highest security scheme, and duplication of the eUICC due to the exposure of an authentication key by external hacking attacks can be prevented.


