eUICC Certificate Script Provisioning for Multi-PKI Activation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless devices face logistical challenges and increased costs due to the need to install multiple sets of certificate credentials for different public key infrastructures (PKIs) during manufacturing, which limits flexibility and complicates manufacturing flows.
Innovation Solution
Postpone the installation of certificate credentials to wireless devices by generating and storing secured scripts on an embedded Universal Integrated Circuit Card (eUICC) after manufacturing, allowing for installation, modification, and removal during device activation or remote electronic subscriber identity module (eSIM) provisioning, using OEM networked servers and local profile assistants for secure communication and management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If certificate credentials are installed during manufacturing for different PKIs, then wireless devices can access services in different geographic regions, but manufacturing costs increase and manufacturing flows become complicated
Solution Approach 1:
The patent applies preliminary action by pre-generating secured scripts during manufacturing that contain placeholder certificate credentials. These scripts are stored in the eUICC but not executed until post-manufacturing. This allows the manufacturing process to be simplified while still preparing the device for future credential installation in different geographic regions.
Solution Approach 2:
The patent extracts the certificate credential installation process from the manufacturing phase and separates it into a post-manufacturing step. By taking out the actual credential installation from the manufacturing flow and deferring it to device activation or later, the manufacturing process becomes simpler while the capability to access different regional services is preserved through later credential deployment.
2Adaptability or versatility
If multiple sets of certificate credentials are installed during manufacturing, then wireless devices support multiple public key infrastructures, but logistical challenges increase
Solution Approach 1:
The patent creates a universal solution by implementing a single secured script template that can serve multiple PKI requirements. Instead of installing different credential sets for different PKIs, the system uses one versatile script structure that can be configured at runtime to support any required PKI, thereby reducing logistical complexity while maintaining multi-PKI capability.
Solution Approach 2:
The patent applies parameter changes by transforming the static credential installation approach into a dynamic one. The secured scripts contain parameters that can be modified post-manufacturing to match different PKI requirements. This allows the same script infrastructure to adapt to various PKIs by changing credential parameters rather than requiring separate installation processes for each PKI.
3Reliability
If certificate credentials are installed during manufacturing, then security procedures can be performed, but flexibility in credential management is reduced
Solution Approach 1:
The patent introduces dynamics by making the credential installation process flexible and changeable after manufacturing. The secured scripts are designed to be executable at any point post-manufacturing, allowing credential management to adapt to changing security requirements, geographic deployments, or network conditions while maintaining the reliability of security procedures through the use of cryptographically secure script execution.
Data Source
AI summary
This application describes techniques for postponed certificate credential installation to wireless devices, including generation and storage of secured scripts to be used for subsequent certificate credential installation on an eUICC of a wireless device after manufacturing. Management of certificate credentials, including installation on, modification to, and removal from, an eUICC can occur post-manufacturing, such as during a device activation procedure or as part of remote electronic subscriber identity module (eSIM) provisioning to the eUICC of the wireless device. Updating certificate credentials on an eUICC can allow for wireless device operation in different geographic regions that use different public key infrastructures (PKIs) with distinct root certificate issuers. The secured scripts can be pre-generated by an eUICC manufacturer (EUM) for the particular eUICC and stored at an OEM networked server and later used to install the certificate credentials on the eUICC of the wireless device.


