eUICC Certificate Script Provisioning for Multi-PKI Activation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless devices face logistical challenges and increased costs due to the need to install multiple sets of certificate credentials for different public key infrastructures (PKIs) during manufacturing, which limits flexibility and complicates manufacturing flows.

Innovation Solution

Postpone the installation of certificate credentials to wireless devices by generating and storing secured scripts on an embedded Universal Integrated Circuit Card (eUICC) after manufacturing, allowing for installation, modification, and removal during device activation or remote electronic subscriber identity module (eSIM) provisioning, using OEM networked servers and local profile assistants for secure communication and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If certificate credentials are installed during manufacturing for different PKIs, then wireless devices can access services in different geographic regions, but manufacturing costs increase and manufacturing flows become complicated

Engineering Contradiction:
Improveaccess to services in different geographic regionsVSAvoidmanufacturing flows
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent applies preliminary action by pre-generating secured scripts during manufacturing that contain placeholder certificate credentials. These scripts are stored in the eUICC but not executed until post-manufacturing. This allows the manufacturing process to be simplified while still preparing the device for future credential installation in different geographic regions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the certificate credential installation process from the manufacturing phase and separates it into a post-manufacturing step. By taking out the actual credential installation from the manufacturing flow and deferring it to device activation or later, the manufacturing process becomes simpler while the capability to access different regional services is preserved through later credential deployment.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If multiple sets of certificate credentials are installed during manufacturing, then wireless devices support multiple public key infrastructures, but logistical challenges increase

Engineering Contradiction:
Improvesupport for multiple public key infrastructuresVSAvoidlogistical challenges
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal solution by implementing a single secured script template that can serve multiple PKI requirements. Instead of installing different credential sets for different PKIs, the system uses one versatile script structure that can be configured at runtime to support any required PKI, thereby reducing logistical complexity while maintaining multi-PKI capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies parameter changes by transforming the static credential installation approach into a dynamic one. The secured scripts contain parameters that can be modified post-manufacturing to match different PKI requirements. This allows the same script infrastructure to adapt to various PKIs by changing credential parameters rather than requiring separate installation processes for each PKI.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If certificate credentials are installed during manufacturing, then security procedures can be performed, but flexibility in credential management is reduced

Engineering Contradiction:
Improvesecurity proceduresVSAvoidflexibility in credential management
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamics by making the credential installation process flexible and changeable after manufacturing. The secured scripts are designed to be executable at any point post-manufacturing, allowing credential management to adapt to changing security requirements, geographic deployments, or network conditions while maintaining the reliability of security procedures through the use of cryptographically secure script execution.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12610238B2Postponed certificate credential installation to wireless devices
Publication Date: 2026.04.21 APPLE INC
  • US12610238B2 patent drawing
  • US12610238B2 patent drawing
  • US12610238B2 patent drawing

AI summary

This application describes techniques for postponed certificate credential installation to wireless devices, including generation and storage of secured scripts to be used for subsequent certificate credential installation on an eUICC of a wireless device after manufacturing. Management of certificate credentials, including installation on, modification to, and removal from, an eUICC can occur post-manufacturing, such as during a device activation procedure or as part of remote electronic subscriber identity module (eSIM) provisioning to the eUICC of the wireless device. Updating certificate credentials on an eUICC can allow for wireless device operation in different geographic regions that use different public key infrastructures (PKIs) with distinct root certificate issuers. The secured scripts can be pre-generated by an eUICC manufacturer (EUM) for the particular eUICC and stored at an OEM networked server and later used to install the certificate credentials on the eUICC of the wireless device.