eUICC Security Credential Provisioning via Enterprise Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of embedded Universal Integrated Circuit Cards (eUICC) used in IoT devices, enterprises face issues with security key ownership and access, as the initial keys are typically provided by the SIM manufacturer or Mobile Network Operator, breaking the chain of trust and requiring dependence on external entities for security provisioning.
Innovation Solution
A system and method that allows enterprises to own and control security credential ownership by using the original security credentials to obtain new credentials from an Enterprise security provisioning service, enabling auto-provisioning of security keys directly to the eUICC, thus shifting the trusted domain to the Enterprise and obfuscating external communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the initial security keys are provided by the SIM manufacturer or Mobile Network Operator, then the eUICC can establish secure communications with external entities, but the enterprise loses control over the security credential ownership and must depend on external parties for security provisioning
Solution Approach 1:
The system enables enterprises to self-provision security credentials for their eUICCs without relying on external parties. The enterprise can directly issue and manage security keys through their own servers, making the security provisioning process autonomous and self-contained within the enterprise domain.
Solution Approach 2:
The patent introduces an intermediary mechanism where the enterprise acts as a trusted mediator between the eUICC and external entities. By using the enterprise's own security infrastructure as the intermediary, the system maintains secure communications while transferring control of credential ownership from external providers to the enterprise itself.
2Ease of manufacture
If enterprises use external parties for security provisioning, then the eUICC can obtain security credentials, but the chain of trust is broken and external communication paths must be maintained
Solution Approach 1:
The system extracts the security provisioning function from external parties and relocates it entirely within the enterprise domain. By taking out the credential issuance capability from external SIM manufacturers or MNOs and embedding it within the enterprise's own infrastructure, the patent eliminates the need to maintain external trust chains while preserving full provisioning functionality.
3Adaptability or versatility
If multiple profiles from different mobile providers are provisioned across multiple eUICC from different manufacturers, then global mobile networking interoperability is achieved, but security key ownership and access control become complex
Solution Approach 1:
Instead of having multiple external providers manage security keys across different eUICCs, the patent inverts the model by enabling each enterprise to be its own security provider. This reversal simplifies key management by consolidating control within the enterprise rather than distributing it across multiple external entities, while still supporting multi-profile and multi-device scenarios.
Data Source
AI summary
A system and method includes mobile device, a SIM associated with mobile device, an MNO computer, a computer associated with an owner of the mobile device, a first set of keys stored in the SIM for securely communicating with the MNO computer, and a second set of keys for securely communicating with the computer associated with the owner of the mobile device, to exchange application information. The SIM can be configured to determine when updated information related to the second set of keys is required, securely send a request to the MNO computer for updated information related to the second set of keys using the first set of keys, and responsively receive the updated information related to the second set of keys from the MNO computer, the updated information being provisioned by the computer associated with the owner of the mobile device. The mobile device is configured to utilize the updated information related to the second set of keys to establish data communication between an application running on the mobile device and the computer associated with the owner of the mobile device.


