eUICC Key Rotation for Remote Two-Factor Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rapid growth of machine-to-machine (M2M) applications has created challenges for traditional wireless networks, particularly in securely and efficiently distributing and managing network access credentials for embedded universal integrated circuit cards (eUICC) without physical intervention, as modules often operate in remote or sealed environments and may require frequent key changes to enhance security.

Innovation Solution

The system employs an embedded universal integrated circuit card (eUICC) that supports secure and efficient communication by allowing modules to remotely and automatically change network access credentials using cryptographic algorithms, ensuring control over key distribution and authentication, even when profiles are distributed outside the mobile network operator's control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional physical UICC cards are used for M2M devices, then initial network access authentication can be achieved, but key changes require physical intervention which is costly and impractical for remote or sealed devices

Engineering Contradiction:
Improvekey change operationVSAvoidphysical intervention requirement
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/physical system of UICC card manipulation with an electronic/software-based system. The eUICC embedded in the module allows key changes to be performed remotely through electronic communication, eliminating the need for physical card removal, replacement, or rewriting operations. This substitution resolves the contradiction by making key changes as easy as sending a data command while removing all physical complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The eUICC system enables the module to autonomously perform key changes without external physical intervention. The module can independently receive key change commands, process them through the eUICC, and update its network access credentials automatically. This self-service capability resolves the contradiction by making the device its own service provider for key management.

Inventive Principle:
Principle #25Self-service

2Reliability

If eUICC is embedded in sealed modules for remote M2M applications, then device security and protection are improved, but physical access for key management is lost

Engineering Contradiction:
Improvedevice securityVSAvoidkey distribution control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary key management system that acts as a mediator between the module operator and the eUICC. This intermediary receives key change requests, processes them securely, and delivers updated credentials to the module through electronic channels. This intermediary resolves the contradiction by maintaining security through controlled access while enabling operational flexibility through remote key distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system separates the security functions into distinct components: the eUICC securely stores cryptographic material, the module manages communication, and the intermediary handles key distribution logistics. This segmentation allows each component to specialize in its function, maintaining high security while enabling flexible key management operations without physical access.

Inventive Principle:
Principle #1Segmentation

3Reliability

If frequent key changes are implemented to enhance security, then authentication security is improved, but operational complexity and management overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The automated key change system allows modules to independently undergo frequent key rotations without human intervention. The module automatically receives key change commands, processes them through the eUICC, and updates its credentials. This self-service approach resolves the contradiction by making frequent key changes operationally simple while maintaining high security through automated enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where the module reports its current key status and receives directed key change commands based on security policies. This feedback loop enables automated key management systems to orchestrate frequent key changes across multiple modules efficiently, reducing overall management complexity while maintaining high security standards through systematic control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12490098B2Embedded universal integrated circuit card supporting two-factor authentication
Publication Date: 2025.12.02 NETWORK 1 TECH
  • US12490098B2 patent drawing
  • US12490098B2 patent drawing
  • US12490098B2 patent drawing

AI summary

A module with an embedded universal integrated circuit card (eUICC) can include a profile for the eUICC. The profile can include a first and second shared secret key K for authenticating with a wireless network. The first shared secret key K can be encrypted with a first key, and the second shared secret key K can be encrypted with a second key. The module can (i) receive the first key, (ii) decrypt the first shared secret key K with the first key, and (iii) subsequently authenticate with the wireless network using the plaintext first shared secret key K. The wireless network can authenticate the user of the module using a second factor. The module can then (i) receive the second key, (ii) decrypt the second shared secret key K, and (iii) authenticate with the wireless network using the second shared secret key K. The module can comprise a mobile phone.