eUICC Profile Management Authorization via Local Credential Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing authorization methods for embedded universal integrated circuit cards (eUICCs) are inefficient, requiring frequent communication with authorization servers and serial number reporting, leading to low efficiency in managing profile management functions.
Innovation Solution
An eUICC manager generates and encrypts authorization information using eUICC management credentials, which includes identifiers or credentials for authorized devices, allowing the eUICC to update and store correspondences for direct acceptance or rejection of profile management functions without continuous authorization requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authorization information is stored in an authorization server and device serial number is reported each time after startup, then authorization can be obtained, but efficiency of the authorization manner is low
Solution Approach 1:
The eUICC manager generates and provides authorization information to the eUICC in advance before the eUICC needs to perform profile management operations. This preliminary authorization enables the eUICC to directly accept or reject profile management requests without needing to contact the authorization server each time, thereby improving authorization efficiency while maintaining reliability
Solution Approach 2:
The authorization information from the authorization server is copied into the eUICC's memory. This copy allows the eUICC to independently verify authorization without repeatedly querying the original authorization server, thus resolving the contradiction between maintaining authorization validity and improving operational efficiency
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A method for authorizing management for an embedded universal integrated circuit card includes: generating, by an eUICC manager, authorization information (S101); encrypting the authorization information by using eUICC management credential (S102); and sending the encrypted authorization information to an eUICC (S103), where the authorization information includes an identifier of at least one first device; or the authorization information includes at least one authorization credential. The authorization information is configured in the eUICC, and therefore, when a subsequently authorized first device manages a profile in the eUICC, the eUICC may directly accept or reject, according to a stored correspondence between a profile management function and an authorized first device, to be managed, without obtaining authorization information each time.