eUICC Secure Channel via Ephemeral Session Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for provisioning embedded Subscriber Identity Modules (eSIMs) using symmetric keys are vulnerable to security flaws, particularly due to the need for storing and managing symmetric keys across multiple entities, which increases exposure and computational complexity, and poses risks for forward security.

Innovation Solution

Establishing ephemeral, session-based symmetric keys using Public Key Infrastructure (PKI) information for secure communication channels between off-card entities and eUICCs, with options for perfect or half forward security, allowing for authentication and secure data transmission without relying on pre-established symmetric keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If symmetric keys are stored and managed across multiple entities for eSIM provisioning, then secure communication can be established, but security exposure and computational complexity increase

Engineering Contradiction:
Improvesecure communicationVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the symmetric key management from the provisioning entity and replaces it with asymmetric key pairs stored on the eUICC. The eUICC generates and retains control of its own private key, while the provisioning entity only stores public keys. This extraction eliminates the need for the provisioning entity to store sensitive symmetric keys, reducing security exposure and management complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces asymmetric cryptography as an intermediary mechanism between the eUICC and provisioning entity. Instead of directly sharing symmetric keys, the system uses public key infrastructure to establish secure communication channels. The asymmetric key pair acts as a mediator that enables secure key exchange and authentication without requiring the provisioning entity to store sensitive symmetric keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If symmetric keys are shared between provisioning entity and eUICC, then encryption and decryption can be performed, but vulnerability to interception and exploitation increases

Engineering Contradiction:
Improveencryption capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent applies asymmetry by replacing symmetric key pairs with asymmetric key pairs. The eUICC holds a private key that never leaves the device, while the provisioning entity only stores the corresponding public key. This asymmetric structure enables encryption and decryption capabilities while eliminating the security vulnerability of sharing secret keys between multiple entities. The private key remains exclusively on the eUICC, preventing interception and exploitation.

Inventive Principle:
Principle #4Asymmetry

3Ease of operation

If long-term symmetric keys are used for secure communication, then authentication is simplified, but forward security is compromised

Engineering Contradiction:
Improveauthentication simplicityVSAvoidforward security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces dynamic ephemeral key pairs that are generated for each provisioning session. Instead of using static long-term symmetric keys, the system creates temporary asymmetric key pairs that exist only for the duration of each communication session. This dynamic approach maintains authentication simplicity through automated key generation while providing forward security, as compromise of one session's ephemeral keys does not affect other sessions or long-term credentials.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3547643B1Methods and apparatus for establishing a secure communication channel
Publication Date: 2020.11.18 APPLE INC
  • EP3547643B1 patent drawingFigure 1
  • EP3547643B1 patent drawingFigure 2
  • EP3547643B1 patent drawingFigure 3

AI summary

A method for establishing a secure communication channel between an off-card entity and an electronic Universal Integrated Circuit Card (eUICC) is provided. The method involves establishing symmetric keys that are ephemeral in scope. Specifically, an off-card entity, and each eUICC in a set of eUICCs managed by the off-card entity, possess long-term Public Key Infrastructure (PKI) information. When a secure communication channel is to be established between the off-card entity and an eUICC, the eUICC and the off-card entity can authenticate one another in accordance with the respectively-possessed PKI information (e.g., verifying public keys). After authentication, the off-card entity and the eUICC establish a shared session-based symmetric key for implementing the secure communication channel. Specifically, the shared session-based symmetric key is generated according to whether perfect or half forward security is desired. Once the shared session-based symmetric key is established, the off-card entity and the eUICC can securely communicate information.