eUICC Key Decryption for Remote Two-Factor Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenges of securely and efficiently managing network access credentials for machine-to-machine (M2M) devices using embedded universal integrated circuit cards (eUICC) include the need for secure distribution of pre-shared secret keys without physical intervention, ensuring compatibility with legacy networks, and maintaining control over key changes to enhance security.
Innovation Solution
The system employs an eUICC that supports secure decryption and derivation of keys under the control of the mobile network operator, allowing remote and automatic changes in network access credentials using cryptographic algorithms and key derivation, with encryption and decryption processes managed by the MNO.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical UICC cards are used for M2M devices, then network access credentials can be securely stored, but manual intervention is required for key distribution and key changes
Solution Approach 1:
The patent replaces the mechanical/physical UICC card system with an embedded eUICC system that uses electronic key derivation and cryptographic algorithms. The eUICC is embedded in the M2M device during manufacturing, eliminating the need for physical card insertion and manual key distribution. Key changes are performed remotely through automated cryptographic processes rather than physical intervention.
Solution Approach 2:
The eUICC system performs self-service by automatically deriving network access keys using cryptographic algorithms stored in the embedded card. The device can autonomously authenticate with the network and perform key changes without requiring manual intervention, as the eUICC handles key derivation and security operations internally.
2Reliability
If manual UICC replacement is used for key changes, then security control is maintained, but costs and time are increased
Solution Approach 1:
The eUICC is pre-configured with cryptographic algorithms and security parameters during device manufacturing. Network access keys are derived in advance using these pre-configured elements, allowing rapid key changes without manual UICC replacement. The preliminary setup enables subsequent automated key management operations.
Solution Approach 2:
The patent replaces the manual mechanical process of UICC card removal and insertion with an electronic key derivation system. The eUICC uses cryptographic algorithms to generate and update network access keys electronically, allowing remote and instantaneous key changes while maintaining security control through the embedded security module.
3Productivity
If eUICC with automated key derivation is used, then operational efficiency is improved, but device complexity increases
Solution Approach 1:
The patent merges the security functions, key storage, and key derivation capabilities into a single integrated eUICC module embedded in the M2M device. This consolidation improves operational efficiency by providing automated key management while containing the complexity within the embedded card rather than distributing it across the entire device system.
Solution Approach 2:
The eUICC acts as an intermediary security module that handles complex cryptographic operations internally. The main device system interacts with the eUICC through simplified interfaces, allowing the device to benefit from automated key derivation and security operations without the full complexity of the cryptographic system being exposed at the device level.
Data Source
AI summary
A module with an embedded universal integrated circuit card (eUICC) can include a profile for the eUICC. The profile can include a first and second shared secret key K for authenticating with a wireless network. The first shared secret key K can be encrypted with a first key, and the second shared secret key K can be encrypted with a second key. The module can (i) receive the first key, (ii) decrypt the first shared secret key K with the first key, and (iii) subsequently authenticate with the wireless network using the plaintext first shared secret key K. The wireless network can authenticate the user of the module using a second factor. The module can then (i) receive the second key, (ii) decrypt the second shared secret key K, and (iii) authenticate with the wireless network using the second shared secret key K. The module can comprise a mobile phone.


