eUICC Profile Diversification for Secure OTA Credential Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for configuring and updating secure elements in user devices, such as eUICCs, fail to ensure future-proof functional safety, security, and flexibility due to limitations in deployability, availability, and data integrity, particularly when standards change during the device's lifecycle.

Innovation Solution

A method involving a diversification program dataset and configuration program to manage diversified data, allowing secure elements to be updated and personalized over-the-air, ensuring compatibility with evolving standards and specifications without requiring physical replacement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If eSE is soldered into user devices to prevent physical removal, then security and reliability are improved, but ability to update or replace eSE is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidupdate capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The eSE is divided into multiple secure storage areas: a first secure storage area for storing diversified data and a second secure storage area for storing updated data. This segmentation allows the system to maintain security while enabling updates by switching between storage areas without physically replacing the eSE.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by storing updated data in the second secure storage area before actually using it. The updated data is prepared and validated in advance, allowing seamless switching to the updated eSE content without disrupting the ongoing operation of the user device.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If firmware updates are implemented to keep eSE up to date, then adaptability to new standards is improved, but system complexity is worsened

Engineering Contradiction:
Improvestandard complianceVSAvoidupdate mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary mechanism using a controller that manages the switching between the first secure storage area (original eSE content) and the second secure storage area (updated eSE content). This intermediary simplifies the update process by handling the coordination between storage areas and the user device's operational state.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If diversified data is stored in secure elements, then personalization and security are improved, but data management complexity is worsened

Engineering Contradiction:
ImprovepersonalizationVSAvoiddata management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The secure storage is segmented into distinct areas: the first secure storage area for diversified data and the second secure storage area for updated data. This segmentation simplifies data management by clearly separating different types of data and their respective handling procedures, making it easier to manage personalization while maintaining security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4708943A1Method, configuration program, diversification program dataset, computer-readable data carrier as well as server device for configuring a user device
Publication Date: 2026.03.11 GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
  • EP4708943A1 patent drawingFigure 1
  • EP4708943A1 patent drawingFigure 2~3
  • EP4708943A1 patent drawing

AI summary

A method, as well as a corresponding configuration program (10), a diversification program dataset (J), a computer-readable data carrier (11, 12, 13), a user device (3), and a server device (4) are provided, wherein for configuring the user device (5), the method comprises the steps of providing a secure element (6) of the user device (5), such as an eUICC, with at least one user profile (P) containing diversified data (L) for personalizing the secure element (6); and providing a diversification program dataset (J) configured to manage at least parts of diversified data (L) to securely alter at least one security credential (H) as a part of a basic data subset (B) of the profile dataset (P).