eUICC Key Derivation for M2M Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing model of using physical UICC cards for machine-to-machine (M2M) communications is inefficient and costly, especially in remote locations, as it requires physical replacement for key changes and is not easily compatible with different wireless networks, posing security risks due to prolonged use of a single key.
Innovation Solution
The implementation of an embedded universal integrated circuit card (eUICC) that allows for secure and efficient derivation of keys using cryptographic algorithms, enabling remote and automatic changes in network access credentials without the need for physical UICC replacement, and supports Public Key Infrastructure (PKI) for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If physical UICC cards are used for M2M communications, then network access and key management are enabled, but physical replacement is required for key changes which is inefficient and costly especially in remote locations
Solution Approach 1:
The patent replaces the mechanical physical UICC card system with an embedded eUICC that performs cryptographic key derivation computations internally. The eUICC uses cryptographic algorithms (SHA-256, HMAC) to derive new keys from existing keys and random challenges, eliminating the need for physical card replacement while maintaining security. This substitution of mechanical operations with cryptographic computations resolves the contradiction between ease of operation and time loss.
Solution Approach 2:
The embedded eUICC performs self-service by autonomously deriving new authentication keys using cryptographic algorithms when provided with a random challenge from the network. The device can update its own credentials without external physical intervention, automatically computing new keys and storing them locally. This self-service capability eliminates the need for manual physical replacement operations.
2Reliability
If physical UICC cards are used, then initial key security is provided, but prolonged use of a single key poses security risks
Solution Approach 1:
The patent implements dynamic key derivation where the eUICC continuously generates new authentication keys based on cryptographic computations using existing keys and random challenges from the network. This creates a dynamic key lifecycle where credentials automatically evolve over time, preventing the security risks associated with prolonged use of static keys while maintaining continuous authentication capability.
Solution Approach 2:
The system changes cryptographic parameters by deriving new keys with different values from existing keys through cryptographic algorithms. The eUICC modifies its authentication parameters dynamically by computing new keys that are functionally equivalent but cryptographically distinct, thereby refreshing security credentials without changing the physical device or its fundamental identity.
3Reliability
If physical UICC replacement is required for key changes, then key updates are possible, but the process is costly and inefficient especially in remote locations
Solution Approach 1:
The patent substitutes the expensive mechanical logistics of physical UICC card manufacturing, distribution, and replacement with embedded cryptographic operations. The eUICC performs key updates through software-based cryptographic computations using standard algorithms, eliminating the need for costly physical supply chain operations while maintaining secure key update capability.
Solution Approach 2:
The system creates cryptographic copies of authentication credentials through key derivation rather than physical copying of UICC cards. The eUICC generates new keys that are cryptographic derivatives of existing keys, providing equivalent security functionality without the cost and complexity of physical card production and distribution logistics.
4Adaptability or versatility
If physical UICC cards are used, then network access is enabled, but compatibility with different wireless networks is limited
Solution Approach 1:
The patent implements a universal embedded eUICC that can derive and support multiple authentication keys for different wireless networks and technologies. The cryptographic architecture allows the single eUICC to generate network-specific credentials through key derivation, providing multi-network compatibility without requiring separate physical cards for each network type or technology standard.
Data Source
AI summary
A module with an embedded universal integrated circuit card (eUICC) can include a received eUICC profile and a set of cryptographic algorithms. The received eUICC profile can include an initial shared secret key for authentication with a wireless network. The module can receive a key K network token and send a key K module token to the wireless network. The module can use the key K network token, a derived module private key, and a key derivation function to derive a secret shared network key K that supports communication with the wireless network. The wireless network can use the received key K module token, a network private key, and the key derivation function in order to derive the same secret shared network key K derived by the module. The module and the wireless network can subsequently use the mutually derived key K to communicate using traditional wireless network standards.


