eUICC Key Derivation for M2M Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing model of using physical UICC cards for machine-to-machine (M2M) communications is inefficient and costly, especially in remote locations, as it requires physical replacement for key changes and is not easily compatible with different wireless networks, posing security risks due to prolonged use of a single key.

Innovation Solution

The implementation of an embedded universal integrated circuit card (eUICC) that allows for secure and efficient derivation of keys using cryptographic algorithms, enabling remote and automatic changes in network access credentials without the need for physical UICC replacement, and supports Public Key Infrastructure (PKI) for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If physical UICC cards are used for M2M communications, then network access and key management are enabled, but physical replacement is required for key changes which is inefficient and costly especially in remote locations

Engineering Contradiction:
Improvekey change operationVSAvoidtime for physical replacement
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent replaces the mechanical physical UICC card system with an embedded eUICC that performs cryptographic key derivation computations internally. The eUICC uses cryptographic algorithms (SHA-256, HMAC) to derive new keys from existing keys and random challenges, eliminating the need for physical card replacement while maintaining security. This substitution of mechanical operations with cryptographic computations resolves the contradiction between ease of operation and time loss.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The embedded eUICC performs self-service by autonomously deriving new authentication keys using cryptographic algorithms when provided with a random challenge from the network. The device can update its own credentials without external physical intervention, automatically computing new keys and storing them locally. This self-service capability eliminates the need for manual physical replacement operations.

Inventive Principle:
Principle #25Self-service

2Reliability

If physical UICC cards are used, then initial key security is provided, but prolonged use of a single key poses security risks

Engineering Contradiction:
ImprovesecurityVSAvoidkey usage duration
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent implements dynamic key derivation where the eUICC continuously generates new authentication keys based on cryptographic computations using existing keys and random challenges from the network. This creates a dynamic key lifecycle where credentials automatically evolve over time, preventing the security risks associated with prolonged use of static keys while maintaining continuous authentication capability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes cryptographic parameters by deriving new keys with different values from existing keys through cryptographic algorithms. The eUICC modifies its authentication parameters dynamically by computing new keys that are functionally equivalent but cryptographically distinct, thereby refreshing security credentials without changing the physical device or its fundamental identity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If physical UICC replacement is required for key changes, then key updates are possible, but the process is costly and inefficient especially in remote locations

Engineering Contradiction:
Improvekey update capabilityVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent substitutes the expensive mechanical logistics of physical UICC card manufacturing, distribution, and replacement with embedded cryptographic operations. The eUICC performs key updates through software-based cryptographic computations using standard algorithms, eliminating the need for costly physical supply chain operations while maintaining secure key update capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system creates cryptographic copies of authentication credentials through key derivation rather than physical copying of UICC cards. The eUICC generates new keys that are cryptographic derivatives of existing keys, providing equivalent security functionality without the cost and complexity of physical card production and distribution logistics.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If physical UICC cards are used, then network access is enabled, but compatibility with different wireless networks is limited

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidmulti-network support
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal embedded eUICC that can derive and support multiple authentication keys for different wireless networks and technologies. The cryptographic architecture allows the single eUICC to generate network-specific credentials through key derivation, providing multi-network compatibility without requiring separate physical cards for each network type or technology standard.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250106013A1Key Derivation for a Module using an Embedded Universal Integrated Circuit Card
Publication Date: 2025.03.27 NETWORK 1 TECH
  • US20250106013A1 patent drawing
  • US20250106013A1 patent drawing
  • US20250106013A1 patent drawing

AI summary

A module with an embedded universal integrated circuit card (eUICC) can include a received eUICC profile and a set of cryptographic algorithms. The received eUICC profile can include an initial shared secret key for authentication with a wireless network. The module can receive a key K network token and send a key K module token to the wireless network. The module can use the key K network token, a derived module private key, and a key derivation function to derive a secret shared network key K that supports communication with the wireless network. The wireless network can use the received key K module token, a network private key, and the key derivation function in order to derive the same secret shared network key K derived by the module. The module and the wireless network can subsequently use the mutually derived key K to communicate using traditional wireless network standards.