eUICC Authentication Key Encapsulation for Secure Provider Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Embedded UICC (eUICC) in terminals, such as M2M communication devices, cannot be easily replaced, making it difficult to change mobile communication providers without compromising security, as existing methods for providing provider information lack defined interfaces and security measures.

Innovation Solution

A method and device for securely providing mobile communication provider information to an eUICC by encapsulating authentication-key information within an authentication processing module, which is stored in the eUICC, using a server-generated encapsulation module transmitted via a secure over-the-air communication scheme, ensuring high security and preventing exposure of the authentication key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Strength

If eUICC is integrated with terminal during manufacture, then durability and resistance to damage are improved, but ability to change mobile communication provider is worsened

Engineering Contradiction:
ImprovedurabilityVSAvoidability to change provider
Core Design Contradiction:
StrengthVSAdaptability or versatility

Solution Approach 1:

The authentication key is segmented from the eUICC structure and stored separately in an authentication processing module within the terminal, allowing the key to be updated independently of the eUICC hardware. This enables provider changes while maintaining the integrated eUICC structure for durability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An authentication processing module acts as an intermediary between the eUICC and the authentication key. This module stores the key securely and manages authentication operations, allowing key updates without physical eUICC replacement while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication key is provided independently to eUICC, then ease of provider change is improved, but security is worsened

Engineering Contradiction:
Improveease of provider changeVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication key is nested within the authentication processing module rather than being stored independently or directly in the eUICC. This nested structure provides secure containment while enabling remote updates through the module's interface capabilities.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The physical mechanical system of removing and replacing eUICC cards is replaced with an electronic/software-based system where the authentication key is remotely provisioned to the authentication processing module. This substitution maintains security while enabling easy provider changes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Device complexity

If existing UICC provision method is directly applied to eUICC, then implementation simplicity is improved, but security is worsened due to lack of defined interface

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The authentication processing module serves as an intermediary that implements a defined interface between the terminal and eUICC for key provisioning. This interface enables secure, controlled key updates while maintaining implementation simplicity through standardized communication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10462667B2Method of providing mobile communication provider information and device for performing the same
Publication Date: 2019.10.29 SAMSUNG ELECTRONICS CO LTD
  • US10462667B2 patent drawing
  • US10462667B2 patent drawing
  • US10462667B2 patent drawing

AI summary

A method for providing mobile communication provider information and a device for performing the same are disclosed. A terminal having an eUICC receives data, in which mobile communication provider information is capsulized and included, and stores the received data in the eUICC. Therefore, the mobile communication provider information can be transferred by applying the highest security scheme, and duplication of the eUICC due to the exposure of an authentication key by external hacking attacks can be prevented.