Embedded UICC Profile Management via Dynamic Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional removable UICC cards hinder the miniaturization of M2M terminals and restrict users from switching mobile network operators, as IMSI assignment is tied to specific operators during manufacturing, leading to inventory management issues and increased costs.

Innovation Solution

An embedded UICC (eUICC) manages profiles using dynamically generated public keys for secure provisioning and switching between mobile network operators, with a subscription manager divided into secure routing and data preparation roles for remote management and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a removable UICC card is used, then users can switch between different MNOs freely, but the terminal cannot be miniaturized

Engineering Contradiction:
ImproveMNO switching flexibilityVSAvoidterminal size
Core Design Contradiction:
Adaptability or versatilityVSVolume of moving object

Solution Approach 1:

The patent merges the UICC functionality directly into the terminal chip, eliminating the need for a separate removable card. The eUICC is embedded within the terminal's secure element, combining the terminal and subscription management into a single integrated unit, thereby enabling miniaturization while maintaining MNO switching capability through remote profile management.

Inventive Principle:
Principle #5Merging (Combining)

2Ease of manufacture

If IMSI is assigned during manufacturing for a specific MNO, then terminal production is simplified, but users cannot switch operators and inventory management becomes complex

Engineering Contradiction:
Improveterminal production simplicityVSAvoidoperator switching capability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic profile management where the IMSI and MNO assignment are not fixed during manufacturing but can be remotely changed. The eUICC stores multiple operator profiles that can be activated or deactivated remotely, allowing the terminal to adapt its MNO assignment dynamically without physical reconfiguration or inventory complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent pre-loads multiple operator profiles into the eUICC during manufacturing, but keeps them in an encrypted or inactive state. The actual active profile is selected and activated remotely based on user needs, combining the simplicity of pre-configured hardware with the flexibility of remote software-based MNO selection.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If profiles are provided to eUICC remotely, then MNO switching is enabled, but security risks increase from external access

Engineering Contradiction:
Improveremote profile management capabilityVSAvoidsecurity risks from external access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Subscription Manager (SM) as an intermediary between the MNO and the eUICC. The SM handles all remote profile management operations, authentication, and key exchange, acting as a trusted mediator that enables remote provisioning while maintaining security through controlled access and mutual authentication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements different security levels for different data within the eUICC. Critical data such as private keys and authentication vectors are protected with stronger encryption and access controls, while less sensitive profile data can be managed with lighter security measures, allowing secure remote management without exposing all data to equal security risks.

Inventive Principle:
Principle #3Local quality

4Device complexity

If a single SM handles all subscription management functions, then system complexity is reduced, but scalability and security are compromised

Engineering Contradiction:
Improvesubscription management system complexityVSAvoidsystem scalability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent divides the Subscription Manager into separate functional components: an SM-DS (Subscription Manager - Data Preparation) that handles profile generation and an SM-SR (Subscription Manager - Secure Routing) that handles authentication and key management. This segmentation allows each component to be optimized independently, improving scalability and security while maintaining manageable system complexity through clear functional separation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9414233B2Method for managing profile of Embedded UICC, and Embedded UICC, Embedded UICC-equipped terminal, provision method, and method for changing MNO using same
Publication Date: 2016.08.09 SAMSUNG ELECTRONICS CO LTD
  • US9414233B2 patent drawing
  • US9414233B2 patent drawing
  • US9414233B2 patent drawing

AI summary

The present invention provides a method wherein an MNO receives a secret key allocated to a corresponding embedded UICC (eUICC) through SM-SR (secure routing) in an environment where SM is divided and implemented as SM-SR and SM-DP (data preparation), that is, provided is a method wherein the MNO dynamically acquires the secret key (public key or the like) from the corresponding eUICC through the SM-SR and uses the acquired secret key. In addition, the present invention allows the eUICC to receive an encrypted profile from the MNO or the SM and decrypts the encrypted profile using profile access credential information (a secret key corresponding to an eUICC public key) stored in the eUICC to use the decrypted profile, thereby securely transmitting important data such as operation profiles, and blocking external entities such as a device or terminal from accessing the important data.