eUICC Credential Management for Two-Factor Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenges of securely and efficiently distributing and managing network access credentials for machine-to-machine (M2M) devices using embedded universal integrated circuit cards (eUICC) in wireless networks, particularly in scenarios where physical UICC replacement is costly or impractical, and the security of electronically transferred keys is compromised.

Innovation Solution

A system and method for securely and efficiently managing network access credentials using an eUICC, where credentials are transferred and decrypted under the control of the mobile network operator (MNO), allowing for automatic key changes without physical intervention, through a combination of symmetric and asymmetric encryption and key derivation algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical UICC replacement is used to change network access credentials, then security is maintained through physical control, but cost and practicality deteriorate due to manual intervention requirements

Engineering Contradiction:
ImprovesecurityVSAvoidcost and practicality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical system of physical UICC card replacement with an electronic key management system. The eUICC securely stores credentials while the mobile device can electronically receive and install new credentials through authenticated connections, eliminating the need for physical card swapping while maintaining security through cryptographic protection of the credential transfer process

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a credential distribution system as an intermediary between the network operator and the mobile device. This intermediary securely manages the electronic transfer of credentials, enabling automatic key changes without physical intervention while maintaining security through controlled distribution channels

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If electronic key transfer is used to change credentials, then ease of operation improves through automatic updates, but security deteriorates due to compromised transfer channels

Engineering Contradiction:
Improveautomatic updatesVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary authentication and encryption setup before the actual credential transfer occurs. The mobile device and distribution system establish secure channels in advance, authenticate each other, and prepare encrypted transmission paths, ensuring that when credentials are electronically transferred, their security is already protected by pre-established cryptographic measures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transforms the security parameters of the transfer channel by dynamically changing encryption keys and authentication credentials during the transfer process. This ensures that even if the transfer channel is compromised, the credentials remain protected through parameter changes that occur throughout the electronic transfer

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If eUICC is used to store credentials, then ease of operation improves by eliminating physical replacement, but device complexity increases due to embedded security requirements

Engineering Contradiction:
Improveeliminating physical replacementVSAvoidembedded security requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the UICC functionality directly into the mobile device's hardware, creating an embedded UICC (eUICC) that combines secure element functionality with the device's existing security infrastructure. This integration eliminates the need for separate physical card management while consolidating security functions into a unified embedded system

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The eUICC is designed with multi-functionality, serving both as a secure credential storage element and as an integrated part of the device's authentication system. This universal design allows the same embedded component to handle multiple security functions, reducing overall system complexity despite the advanced capabilities required

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12477341B2Embedded universal integrated circuit card supporting two-factor authentication
Publication Date: 2025.11.18 NETWORK 1 TECH
  • US12477341B2 patent drawing
  • US12477341B2 patent drawing
  • US12477341B2 patent drawing

AI summary

A module with an embedded universal integrated circuit card (eUICC) can include a profile for the eUICC. The profile can include a first and second shared secret key K for authenticating with a wireless network. The first shared secret key K can be encrypted with a first key, and the second shared secret key K can be encrypted with a second key. The module can (i) receive the first key, (ii) decrypt the first shared secret key K with the first key, and (iii) subsequently authenticate with the wireless network using the plaintext first shared secret key K. The wireless network can authenticate the user of the module using a second factor. The module can then (i) receive the second key, (ii) decrypt the second shared secret key K, and (iii) authenticate with the wireless network using the second shared secret key K. The module can comprise a mobile phone.