eUICC Authentication Algorithm Integration via Bound Profile Package
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Embedded Universal Integrated Circuit Cards (eUICCs) often lack the necessary authentication algorithm program, preventing successful network registration due to the absence of corresponding authentication algorithms, which is a critical issue in network access.
Innovation Solution
A method is introduced where the eUICC receives a bound profile package containing initial secure channel information, storage metadata, and an authentication algorithm program, which corresponds to target information such as firmware version, EID issuer identifier, or platform/operating system version, allowing the eUICC to add the authentication algorithm program, enabling identity validity verification and network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the eUICC uses a traditional profile download method, then the profile can be installed, but the eUICC cannot successfully register to the network due to lacking authentication algorithm program
Solution Approach 1:
The authentication algorithm program is packaged together with the profile in advance as a bound profile package. The LPA determines the target eUICC's authentication algorithm capability before downloading, and selects or generates the appropriate authentication algorithm program to bind with the profile, ensuring the eUICC has the necessary authentication capability before network registration.
Solution Approach 2:
The system changes the parameter of authentication algorithm capability by dynamically selecting or generating authentication algorithm programs that match the target eUICC's firmware version, EID issuer identifier, or platform version. This parameter adaptation enables the eUICC to successfully authenticate with the network.
2Reliability
If the eUICC lacks authentication algorithm program, then the device structure remains simple, but network access fails due to inability to verify identity
Solution Approach 1:
The LPA acts as an intermediary between the profile distribution system and the eUICC. It determines the target eUICC's authentication algorithm capability, selects or generates the appropriate authentication algorithm program, binds it with the profile, and downloads the combined package to the eUICC, thereby enabling identity verification without requiring the eUICC to have inherent authentication algorithm capabilities.
3Reliability
If the authentication algorithm program is added after profile download, then the profile installation is fast, but the authentication algorithm program may not match the eUICC version
Solution Approach 1:
The system performs preliminary determination of the target eUICC's authentication algorithm capability (firmware version, EID issuer identifier, platform version) before downloading the profile. The appropriate authentication algorithm program is selected or generated and bound with the profile in advance, ensuring both compatibility and efficient one-step installation without version mismatch issues.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present invention disclose a method for adding an authentication algorithm program, and a relevant device and system, where the method includes: receiving, by an SM-DP+ server, an authentication algorithm program sent by an MNO, where the authentication algorithm program corresponds to target information, and the target information is at least one of: firmware version information of an eUICC, an EID issuer identifier of the eUICC, platform/operating system version information of the eUICC, or capability information of the eUICC; and generating, by the SM-DP+ server, a bound profile package that includes the authentication algorithm program, and sending the bound profile package to the eUICC by using an LPA. As can be learned, the eUICC can add the authentication algorithm program into the eUICC in time by implementing the authentication algorithm program described in a first aspect.