eUICC Authentication Algorithm Integration via Bound Profile Package

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Embedded Universal Integrated Circuit Cards (eUICCs) often lack the necessary authentication algorithm program, preventing successful network registration due to the absence of corresponding authentication algorithms, which is a critical issue in network access.

Innovation Solution

A method is introduced where the eUICC receives a bound profile package containing initial secure channel information, storage metadata, and an authentication algorithm program, which corresponds to target information such as firmware version, EID issuer identifier, or platform/operating system version, allowing the eUICC to add the authentication algorithm program, enabling identity validity verification and network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the eUICC uses a traditional profile download method, then the profile can be installed, but the eUICC cannot successfully register to the network due to lacking authentication algorithm program

Engineering Contradiction:
Improvenetwork registration success rateVSAvoidauthentication algorithm compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication algorithm program is packaged together with the profile in advance as a bound profile package. The LPA determines the target eUICC's authentication algorithm capability before downloading, and selects or generates the appropriate authentication algorithm program to bind with the profile, ensuring the eUICC has the necessary authentication capability before network registration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the parameter of authentication algorithm capability by dynamically selecting or generating authentication algorithm programs that match the target eUICC's firmware version, EID issuer identifier, or platform version. This parameter adaptation enables the eUICC to successfully authenticate with the network.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the eUICC lacks authentication algorithm program, then the device structure remains simple, but network access fails due to inability to verify identity

Engineering Contradiction:
Improveidentity verification capabilityVSAvoidauthentication algorithm program
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The LPA acts as an intermediary between the profile distribution system and the eUICC. It determines the target eUICC's authentication algorithm capability, selects or generates the appropriate authentication algorithm program, binds it with the profile, and downloads the combined package to the eUICC, thereby enabling identity verification without requiring the eUICC to have inherent authentication algorithm capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the authentication algorithm program is added after profile download, then the profile installation is fast, but the authentication algorithm program may not match the eUICC version

Engineering Contradiction:
Improveauthentication algorithm compatibilityVSAvoidprofile installation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary determination of the target eUICC's authentication algorithm capability (firmware version, EID issuer identifier, platform version) before downloading the profile. The appropriate authentication algorithm program is selected or generated and bound with the profile in advance, ensuring both compatibility and efficient one-step installation without version mismatch issues.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3592014B1Method and device for adding authentication algorithm program
Publication Date: 2021.03.03 HUAWEI TECH CO LTD
  • EP3592014B1 patent drawingFigure 1
  • EP3592014B1 patent drawingFigure 2
  • EP3592014B1 patent drawingFigure 3

AI summary

Embodiments of the present invention disclose a method for adding an authentication algorithm program, and a relevant device and system, where the method includes: receiving, by an SM-DP+ server, an authentication algorithm program sent by an MNO, where the authentication algorithm program corresponds to target information, and the target information is at least one of: firmware version information of an eUICC, an EID issuer identifier of the eUICC, platform/operating system version information of the eUICC, or capability information of the eUICC; and generating, by the SM-DP+ server, a bound profile package that includes the authentication algorithm program, and sending the bound profile package to the eUICC by using an LPA. As can be learned, the eUICC can add the authentication algorithm program into the eUICC in time by implementing the authentication algorithm program described in a first aspect.