eUICC Certificate Authentication for SIM-Less Cellular Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile wireless devices without SIM or eSIM credentials face challenges in accessing cellular wireless networks due to limited storage and processing capabilities, which hinder the execution of secure authentication protocols like EAP-TLS, and existing solutions complicate manufacturing and distribution.
Innovation Solution
The EAP-TLS procedure is divided between a secure element (eUICC) and processing circuitry (ME) of the UE, where the eUICC authenticates using its certificate and the ME verifies server certificates, leveraging platform-level security to meet cellular wireless network security requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EAP-TLS authentication procedure is executed on secure element (eUICC), then security requirements are met, but processing and storage capabilities are insufficient
Solution Approach 1:
The EAP-TLS authentication procedure is segmented into two parts: certificate verification and signing operations are performed on the secure element (eUICC), while the overall authentication state machine and message exchange are handled by the mobile equipment (ME). This segmentation allows the secure element to contribute its security capabilities without bearing the full processing burden.
Solution Approach 2:
The mobile equipment (ME) acts as an intermediary between the secure element (eUICC) and the network authentication server. The ME manages the authentication state machine, handles message routing, and coordinates between the eUICC's security functions and the network protocol requirements.
2Adaptability or versatility
If provisioning profiles are stored in eUICC, then access to MNO provisioning server is enabled, but storage space is occupied and device complexity increases
Solution Approach 1:
The provisioning profile data is extracted from the eUICC storage and replaced with a lightweight device identifier. The eUICC only stores its certificate and private key for authentication, while the actual provisioning profile information is obtained dynamically from the MNO provisioning server during the EAP-TLS authentication process.
Solution Approach 2:
The device identifier is pre-configured in the eUICC during manufacturing, enabling the device to initiate authentication with the MNO provisioning server without requiring pre-stored provisioning profiles. This preliminary configuration simplifies storage requirements while maintaining network access capability.
3Adaptability or versatility
If multiple profiles are stored in eUICC, then service customization is enabled, but activation complexity increases and connectivity may be severed
Solution Approach 1:
The system enables self-service profile management where the MNO provisioning server automatically provisions and configures service profiles based on the device identifier and authentication credentials. The server handles profile activation, modification, and deletion without requiring complex device-side profile management logic.
Data Source
AI summary
This application sets forth techniques for authenticating a mobile device with a cellular wireless network without electronic Subscriber Identity Module (eSIM) credentials by using an Extensible Authentication Protocol Transport Layer Security (EAP-TLS) procedure. The mobile device authenticates with an Authentication Server Function (AUSF) of the cellular wireless network using an embedded Universal Integrated Circuit Card (eUICC) certificate. Processing circuitry of the mobile wireless device external to the eUICC implements the EAP-TLS procedure and authenticates validity of the AUSF. In some embodiments, the eUICC provides key generation and storage for a session key for communication between the mobile device and the cellular wireless network. In some embodiments, a third-party managed Unified Data Management (UDM) broker authenticates the mobile device based on knowledge of the eUICC certificate and provides a session key to the cellular wireless network for subsequent communication with the mobile device, upon successful authentication of the mobile device.


