eUICC Multi-Trust Circle Management via Security Domain Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional mobile devices with embedded Universal Integrated Circuit Cards (eUICCs) are limited to membership in a single trust circle, restricting their operating flexibility and user satisfaction, especially when users need to access services from different Mobile Network Operators (MNOs) or regions.
Innovation Solution
An eUICC method that allows a mobile device to operate as a member of multiple trust circles by receiving requests for eSIM management operations, identifying corresponding trust circles, and permitting access to those circles while ensuring only one trust circle is active at a time, using digital certificates associated with Certificate Authorities to establish and manage membership.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an eUICC is configured to store multiple digital certificates for multiple trust circles, then the operating flexibility and versatility of the mobile device is improved, but the device complexity and security management burden increases
Solution Approach 1:
The eUICC is divided into multiple security domains, with each security domain associated with a specific trust circle and storing only the digital certificates relevant to that trust circle. This segmentation allows the eUICC to manage multiple trust circles independently, reducing the complexity of managing all certificates simultaneously while maintaining the ability to access multiple trust circles as needed.
Solution Approach 2:
The eUICC dynamically activates only the security domain corresponding to the currently needed trust circle. Instead of maintaining all trust circle memberships actively at once, the system switches between security domains based on operational requirements, thereby reducing the active complexity while preserving versatility.
2Adaptability or versatility
If an eUICC stores digital certificates for multiple trust circles, then the ability to access different MNOs and regions is improved, but the security risk and potential for unauthorized access increases
Solution Approach 1:
By segmenting the eUICC into separate security domains, each domain's digital certificates are isolated and can only be used within their designated trust circle. This prevents cross-contamination of security contexts and reduces the risk that a compromise in one trust circle could affect others.
Solution Approach 2:
Each security domain is configured with specific digital certificates tailored to its associated trust circle, creating localized security contexts. This ensures that each trust circle has its own dedicated security credentials, enhancing security assurance by preventing unauthorized use of certificates across different trust circles.
3Reliability
If conventional approaches restrict eUICC to a single trust circle, then the security management and system reliability are maintained, but the operating flexibility and user satisfaction deteriorate
Solution Approach 1:
The eUICC is segmented into multiple independent security domains, each maintaining the security integrity of a single trust circle while collectively enabling multi-trust circle functionality. This segmentation preserves the simplicity and reliability of single-trust-circle security management within each domain while achieving multi-trust-circle operating flexibility at the eUICC level.
Solution Approach 2:
The eUICC is designed to perform multiple functions by supporting multiple security domains and trust circles, yet each individual security domain maintains the simple, reliable security model of conventional single-trust-circle systems. This multi-functionality achieves operating flexibility without sacrificing the proven security management approaches.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Representative embodiments set forth techniques for enabling a mobile device to be a member of various trust circles. According to some embodiments, an embedded Universal Integrated Circuit Card (eUICC) included in the mobile device can be configured to store, for each trust circle of which the eUICC is a member, at least one digital certificate associated with a Certificate Authority (CA) that serves as a root of the trust circle. In this manner, the at least one digital certificate for each trust circle enables the eUICC to participate as a member of the trust circle. According to some embodiments, the eUICC can be pre-configured to include digital certificates that establish membership to trust circles that the mobile device may encounter during operation. Moreover, the eUICC can also be updated to modify the different trust circles, which can further enable the functionality of the mobile device to evolve throughout its operation.