eUICC Key Indexing for Factory Profile Re-Injection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in efficiently installing and managing multiple profiles on embedded universal integrated circuit cards (eUICCs) in a factory environment, particularly due to the limitations of using a single one-time encryption key, which prevents re-injection and release of profiles in eSIM terminals.
Innovation Solution
A method and device for provisioning profiles in a wireless communication system that involves acquiring encryption key information for multiple eUICCs, transmitting this information to a profile server, receiving bound profile packages, and installing them on terminals, while supporting non-real-time connections and enabling profile changes, re-injections, and releases in a factory setting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single one-time encryption key is used for profile provisioning, then initial profile installation can be completed, but re-injection and release of profiles become impossible
Solution Approach 1:
The patent segments the encryption key system into multiple components: a first encryption key for initial profile provisioning and a second encryption key for subsequent profile operations. This segmentation allows different keys to serve different functions, enabling both initial installation and subsequent re-injection/release operations without compromising security.
Solution Approach 2:
The patent introduces dynamic key management where the system transitions from a static one-time key to a dynamic multi-key system. The second encryption key is generated and stored in the eUICC after initial provisioning, enabling flexible future operations. This dynamic approach allows the system to adapt to different operational phases while maintaining security.
2Ease of operation
If profiles are pre-installed in factory environment, then network access is immediate upon purchase, but profile management and changes become difficult
Solution Approach 1:
The patent performs preliminary profile installation in the factory environment using the first encryption key, ensuring that terminals have network access capability immediately upon purchase. This preliminary action satisfies the requirement for immediate network access while the multi-key system prepares the ground for future flexibility.
Solution Approach 2:
The patent introduces an intermediary key management mechanism where the second encryption key acts as a mediator between the eUICC and profile server for subsequent operations. This intermediary system simplifies profile management by providing a secure, standardized interface for profile changes, releases, and re-injections without requiring complex manual interventions.
3Adaptability or versatility
If multiple encryption keys are stored for multiple eUICCs, then profile re-injection and release become possible, but key management complexity increases
Solution Approach 1:
The patent creates a universal key management system where the second encryption key serves multiple functions: enabling profile re-injection, facilitating profile release, and supporting subsequent profile provisioning operations. This multi-functional key reduces the need for separate keys for each operation, thereby managing complexity while maintaining versatility.
Solution Approach 2:
The patent changes the parameter of encryption key state from a single static key to a multi-state key system. The first key is used in an initial provisioning state, then the system transitions to a second key for operational states. This parameter change allows flexible profile management while keeping the key management process structured and manageable through defined state transitions.
Data Source
AI summary
The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. The present disclosure discloses a method for provisioning a large number of profiles to terminals in a terminal manufacturing factory environment, wherein the method obtains key information and index information for profile installation, transmits a request for a profile for factory injection, including an index ID, to a profile server, receives a bound profile package (BPP) and profile installation key information including index information from the profile server, transmits the received BPP and profile installation key information to a terminal, and selects an encryption key with reference to the index ID in the eUICC of the terminal to decrypt the BPP.


