eUICC Profile Management via Direct MNO Server Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile network operators face a need to update profile content on embedded universal integrated circuit cards (eUICCs) without relying on over-the-air (OTA) platforms, which are costly and involve third-party service operations.
Innovation Solution
A provisioning server, such as a subscriber management data preparation (SMDP) server, is used to manage profile content on eUICCs, allowing mobile network operators (MNOs) to update profiles directly, with options for trusted and untrusted scenarios, including encryption with OTA keys for secure updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If OTA platforms are used for profile content updates, then security and established protocol support are improved, but operational costs and device complexity increase
Solution Approach 1:
The patent extracts the profile content update functionality from the OTA platform and implements it directly within the eUICC and LPA architecture. The eUICC hosts the profile and performs updates autonomously using the LPA to communicate with the MNO server, eliminating the intermediary OTA platform and reducing system complexity while maintaining security through existing eUICC cryptographic mechanisms.
Solution Approach 2:
The LPA acts as an intermediary between the MNO server and the eUICC for profile content updates. It manages the update process by receiving update information from the MNO server and coordinating with the eUICC to apply updates, thereby simplifying the architecture compared to OTA platforms while maintaining secure update delivery through established eUICC protocols.
2Reliability
If OTA platforms are used for profile content updates, then established protocols and security mechanisms are maintained, but operational costs and third-party service dependencies increase
Solution Approach 1:
The patent removes the OTA platform intermediary and enables direct profile content updates between the MNO server and eUICC. The eUICC autonomously manages updates through its integrated LPA, which communicates directly with the MNO server using standardized protocols, thereby eliminating third-party service dependencies and reducing operational costs while maintaining reliability through proven cryptographic mechanisms.
Solution Approach 2:
The eUICC performs self-service for profile content updates by hosting the LPA that autonomously manages the update process. The LPA receives update information from the MNO server and coordinates with the eUICC's profile management functions to apply updates without requiring external OTA platform intervention, thereby improving productivity and eliminating third-party dependencies.
3Productivity
If direct MNO server to eUICC updates are implemented, then operational costs and third-party dependencies are reduced, but trust relationship establishment and security verification complexity increase
Solution Approach 1:
The patent merges the trust verification functions directly into the eUICC-LPA-MNO server communication path. The LPA, hosted within the eUICC, performs authentication and security verification by directly communicating with the MNO server using established cryptographic protocols, eliminating the need for separate OTA platform trust mechanisms and simplifying the overall trust establishment process.
Solution Approach 2:
The eUICC's LPA performs self-service for trust verification by autonomously managing authentication with the MNO server. It handles security protocols, certificate verification, and encrypted communication directly with the MNO server, thereby enabling efficient direct updates without requiring complex external trust management infrastructure.
Data Source
AI summary
A mobile network operator (MNO) uses a provisioning server to update or install profile content in a profile or electronic subscriber identity module (eSIM). In an exemplary embodiment, the profile is present on a secure element such as an embedded universal integrated circuit card (eUICC) in a wireless device. One or more MNOs use the provisioning server to perform profile content management on profiles in the eUICC. In some embodiments, an MNO has a trust relationship with the provisioning server. In some other embodiments, the MNO does not have a trust relationship with the provisioning server and protects payload targeted for an MNO-associated profile using an over the air (OTA) key.


