eUICC Identifier Allocation for Ephemeral Mobile Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems lack the ability to securely and dynamically assign identifiers to user equipment, making communications traceable and vulnerable to interception, which is addressed by the method of dynamically assigning ephemeral identifiers to user equipment using an embedded universal integrated circuit card (eUICC) to enhance security and anonymity.

Innovation Solution

A method for dynamically assigning identifiers, such as IMSI, to an eUICC in user equipment through an identifier management equipment connected to a mobile telephone network, creating a specific subscriber profile and implementing a strong authentication procedure to ensure secure and ephemeral communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static identifiers (e.g., IMSI) are assigned to user equipment, then network connectivity and identification are established, but communications become traceable and security is compromised

Engineering Contradiction:
Improvecommunication securityVSAvoididentifier management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic identifier assignment where the identifier management equipment assigns different identifiers (IMSI, IP address, IMEI) to user equipment based on service requirements and time conditions. This dynamic approach replaces static identifier assignment, enabling the system to adapt identifier allocation to specific communication scenarios, thereby enhancing security while maintaining manageable complexity through automated assignment protocols

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The identifier management equipment serves as an intermediary between the user equipment and the mobile telephone network. It dynamically assigns and manages identifiers, acting as a mediator that controls identifier distribution based on service requirements. This intermediary layer enables secure communication by managing identifier lifecycle without requiring complex changes to the underlying network infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dynamic identifier assignment is implemented, then communication security and anonymity are enhanced, but network protocol complexity and authentication overhead increase

Engineering Contradiction:
Improvecommunication anonymityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication and identifier assignment before actual communication begins. The identifier management equipment pre-assigns appropriate identifiers (such as temporary IMSI or virtual IP addresses) based on service requirements, and establishes authentication credentials in advance. This preliminary action ensures that when communication occurs, the complex authentication has already been completed, reducing real-time overhead while maintaining strong security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes identifier parameters dynamically based on communication context, service type, and security requirements. Different identifier types (IMSI, IP address, IMEI) are assigned or modified according to specific needs. This parameter change approach enables flexible security management where identifier characteristics can be adjusted without requiring complete re-authentication, balancing anonymity with procedural efficiency

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If temporary profiles are used for initial connection, then network access is enabled, but identifier traceability and security remain insufficient

Engineering Contradiction:
Improvenetwork access easeVSAvoididentifier security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments identifier assignment into multiple layers and types. Instead of using a single identifier for all communications, the system assigns different identifier types (IMSI, IP address, IMEI, temporary profiles) for different purposes and time periods. This segmentation allows the system to maintain ease of network access through simple initial profile assignment while enhancing security through multiple identifier layers that can be independently managed and rotated

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs temporary, short-lived identifier profiles for initial network access and specific communication sessions. These temporary profiles (such as temporary IMSI or session-based IP addresses) are assigned for limited durations and purposes, then discarded or rotated. This approach maintains ease of operation by providing simple initial access while improving security through the ephemeral nature of the identifiers, making traceability difficult without requiring complex long-term security infrastructure

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentEP4033794B1Method for dynamic allocation of identifiers to an embedded universal integrated circuit card (EUICC) of a user device and associated system
Publication Date: 2025.08.13 THALES SA
  • EP4033794B1 patent drawingFigure 1
  • EP4033794B1 patent drawingFigure 2
  • EP4033794B1 patent drawingFigure 3

AI summary

This method of assigning a subscription identifier (IMSI) to an embedded universal integrated circuit card - eUICC (4) residing in a user equipment - UE (1) consists of transmitting, from a management equipment (64), via a first telephone network (10) whose radio interface (11) is used by the UE to connect, a subscription identifier in a message exchanged in accordance with a standard protocol for attaching a terminal on the first telephone network, the management equipment being connected to an external roaming interface (70) of the first telephone network, the transmitted subscription identifier having been selected by the management equipment from a pool of previously defined subscription identifiers, the method further consisting of creating, by means of the management equipment, a specific subscriber profile for the eUICC and updating a subscriber service with the subscriber profile,the subscriber profile incorporating the subscription identifier assigned to the eUICC.