eUICC Binding Applet with Multi-Identifier Device Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device-eUICC binding solutions are susceptible to hacking and lack versatility, as they rely on single device identifiers, and cannot accommodate devices with varying security and performance capabilities, leading to potential malfunctions and unauthorized device-eUICC combinations.

Innovation Solution

An eUICC with a binding applet that utilizes multiple device identifiers, such as IMEI, IMEISV, ESN, and MEID, to generate a device fingerprint, ensuring secure binding by comparing received and pre-stored identification information, enhancing security without requiring additional infrastructure or complex cryptography.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If single device identifier (IMEI) is used for binding, then binding simplicity is maintained, but security is compromised and hacking susceptibility increases

Engineering Contradiction:
Improvebinding securityVSAvoidbinding mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The device identifier is segmented into multiple components (IMEI, IMEISV, ESN, MEID) rather than relying on a single identifier. Each identifier acts as a separate segment that contributes to the overall binding verification, making the system more secure while maintaining manageable complexity through modular verification

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Multiple device identifiers are combined to form a composite binding mechanism. The eUICC stores and verifies multiple identifier types simultaneously, creating a composite security layer that is more resistant to hacking attempts while the binding applet manages the complexity of handling multiple identifiers

Inventive Principle:
Principle #40Composite materials

2Reliability

If device-specific eUICC binding is enforced, then unauthorized combinations are prevented, but device versatility and adaptability are reduced

Engineering Contradiction:
Improveauthorized operation assuranceVSAvoiddevice-eUICC compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The binding between device identifier and eUICC is established in advance during device provisioning. The eUICC is pre-configured with the authorized device's identifiers, enabling automatic verification without restricting future legitimate uses. This preliminary binding ensures security while allowing the device to be used with authorized eUICCs

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The binding mechanism supports multiple identifier types (IMEI, IMEISV, ESN, MEID) to accommodate different device forms and generations. This multi-functional approach allows the same binding mechanism to work across diverse devices while maintaining authorized operation assurance through flexible identifier matching

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If eUICC is made compatible with multiple device types, then versatility is improved, but security capabilities are compromised due to varying device security levels

Engineering Contradiction:
Improvecross-device compatibilityVSAvoidsecurity capability assurance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The binding verification is performed locally within the eUICC through the binding applet, which checks device identifiers against stored authorized identifiers. This local verification ensures that each device-eUICC pair is independently validated according to its specific security requirements, maintaining security assurance while allowing compatibility across different device types with varying security capabilities

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4607980A1Device-euicc binding based on device identifier
Publication Date: 2025.08.27 GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
  • EP4607980A1 patent drawingFigure 1
  • EP4607980A1 patent drawingFigure 2
  • EP4607980A1 patent drawing

AI summary

An eUICC, - hosting, or constructed for hosting, at least one security domain profile, ISD-P, the ISD-P hosting, or constructed for hosting, at least one subscriber profile; - storing pre-stored identification information of a device; - hosting a device-eUICC binding applet constructed to, after each reset of the eUICC; --- receive identification information provided by the device; --- compare the received identification information to the pre-stored identification information; --- when the received identification information corresponds to the pre-stored identification information, allow further operation of the eUICC; andwhen the received identification information doesn't correspond to the pre-stored identification information, disable the eUICC; characterized by - the received, pre-stored and compared identification information comprising at least two or more device identifiers of the device.