eUICC Profile Management via Ephemeral Key Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional UICCs are manufactured for specific mobile communication operators, making it difficult to manage and install authentication information for various operators, especially when users switch or need to embed security modules in devices like M2M devices without user intervention.

Innovation Solution

A method and apparatus for remotely installing a profile on a UICC or eUICC using ephemeral asymmetric key pairs for secure authentication and encryption, allowing for flexible management of authentication information across different mobile communication operators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional UICCs are manufactured as dedicated cards for specific mobile communication operators, then authentication information for that operator is securely installed, but it becomes difficult to manage and install authentication information for various operators, especially when users switch operators or need to embed security modules in devices without user intervention

Engineering Contradiction:
ImproveAbility to install authentication information for various operatorsVSAvoidComplexity of managing and installing authentication information
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The UICC is designed with a profile manager that can handle multiple operator profiles and authentication mechanisms within a single card. The system supports downloading and installing profiles from different operators through standardized interfaces, making the UICC universally compatible across multiple operators without requiring dedicated manufacturing for each operator.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

A profile manager acts as an intermediary component within the UICC that handles the complexity of profile download, installation, and management. This intermediary layer provides standardized interfaces for terminal devices to interact with multiple operator profiles, shielding users from the underlying complexity while enabling versatile operator support.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If profile download and installation processes are implemented without pre-established secure channels, then flexibility and automation are improved, but security risks increase due to potential unauthorized access or tampering

Engineering Contradiction:
ImproveAbility to automatically download and install profiles without user interventionVSAvoidSecurity of profile download and installation
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

Secure channels and authentication mechanisms are established before the profile download process begins. The terminal and UICC perform mutual authentication and set up encrypted communication channels in advance, ensuring that subsequent automated profile downloads and installations occur over secure, authenticated connections that prevent unauthorized access or tampering.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The profile manager implements feedback mechanisms that monitor and verify the integrity of profile download and installation processes. Authentication status, encryption verification, and profile integrity checks provide continuous feedback to ensure security requirements are met throughout the automated process, allowing the system to detect and respond to potential security threats.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3281436B1Method and apparatus for downloading a profile in a wireless communication system
Publication Date: 2021.07.21 SAMSUNG ELECTRONICS CO LTD
  • EP3281436B1 patent drawingFigure 1
  • EP3281436B1 patent drawingFigure 2a
  • EP3281436B1 patent drawingFigure 2b

AI summary

The present disclosure relates to a pre-5th-Generation (5G) or 5G communication system to be provided for supporting higher data rates Beyond 4th-Generation (4G) communication system such as Long Term Evolution (LTE). A method for downloading profiles in a terminal in a wireless communication system include generating and storing an encryption key at a time point, loading the stored encryption key, when receiving profile download start information from a profile providing server, and downloading an encrypted profile for the electronic device from the profile providing server, via the loaded encryption key, and installing the encrypted profile in the electronic device.