eUICC Authentication for Human Intent Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Embedded Universal Integrated Circuit Cards (eUICCs) in mobile devices are vulnerable to unauthorized administrative operations, which can lead to hardware inoperability and malware attacks, especially since embedded eSIMs and firmware changes cannot be easily replaced.

Innovation Solution

Implementing user authentication and human intent verification mechanisms, including biometric sensors, secure input/output methods, and trusted execution environments, to ensure that only authorized users can perform administrative operations such as installing, modifying, or deleting eSIMs and firmware updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If eUICC is embedded directly into system boards to eliminate UICC-receiving bays and simplify design, then device complexity is reduced and space is freed up, but security vulnerability increases because embedded eUICCs cannot be easily replaced when firmware corruption or malware occurs

Engineering Contradiction:
Improvedevice design complexityVSAvoidsecurity reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system segments the authentication process into multiple independent components: biometric sensor for human verification, secure element for credential storage, and separate authentication logic. This segmentation allows each component to be optimized independently while maintaining overall security, resolving the contradiction between embedded design simplicity and security reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between the embedded eUICC and external threats. The biometric verification system acts as an intermediary layer that prevents unauthorized administrative operations without requiring physical access to or replacement of the embedded eUICC, thus maintaining security reliability while preserving the simplified embedded design.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If administrative functions for eSIM and eUICC firmware are enabled to provide new and enhanced services, then adaptability and functionality are improved, but security risk increases due to potential hardware inoperability and malware attacks

Engineering Contradiction:
Improveservice functionalityVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by implementing biometric verification before allowing any administrative operations on eSIM or eUICC firmware. This preemptive security measure prevents unauthorized modifications, malware installation, and firmware corruption before they can occur, enabling enhanced service functionality while counteracting security threats in advance.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements preliminary action by requiring user authentication and biometric verification before executing administrative functions. This ensures that only authorized users can perform operations that modify eSIM or eUICC firmware, allowing the system to provide new and enhanced services while preventing security risks through预先 verification.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If biometric verification and secure authentication mechanisms are implemented for administrative operations, then security reliability is improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs self-service by utilizing the device's own existing biometric sensors (fingerprint, facial recognition) and secure elements for authentication. Rather than introducing entirely new external security hardware, the device leverages its inherent capabilities to provide high-level security, thus improving authentication security without proportionally increasing device complexity.

Inventive Principle:
Principle #25Self-service

4Object-affected harmful factors

If multiple authentication layers are added to verify human intent for administrative operations, then harmful factors from automated attacks are reduced, but ease of operation decreases due to additional verification steps

Engineering Contradiction:
Improveautomated attack resistanceVSAvoidoperational convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent replaces traditional mechanical authentication methods (passwords, PINs) with biometric verification systems. This substitution provides stronger resistance to automated attacks while maintaining ease of operation, as biometric verification through fingerprint or facial recognition is more convenient and secure than manual password entry, reducing the impact of additional verification steps on user convenience.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10856148B2Methods and apparatus for user authentication and human intent verification in mobile devices
Publication Date: 2020.12.01 APPLE INC
  • US10856148B2 patent drawing
  • US10856148B2 patent drawing
  • US10856148B2 patent drawing

AI summary

Methods and apparatus for user authentication and human intent verification of administrative operations for eSIMs of an eUICC included in a mobile device are disclosed. Certain administrative operations, such as import, modification, and/or export, of an eSIM and/or for an eUICCs firmware can require user authentication and/or human intent verification before execution of the administrative operations are performed or completed by the mobile device. A user of the mobile device provides information to link an external user account to an eSIM upon (or subsequent to) installation on the eUICC. User credentials, such as a user name and password, and/or information generated therefrom, can be used to authenticate the user with an external server. In response to successful user authentication, the administrative operations are performed. Human intent verification can also be performed in conjunction with user authentication to prevent malware from interfering with eSIM and/or eUICC functions of the mobile device.