eUICC Profile Management via Direct MNO Server Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile network operators face a need to update profile content on embedded universal integrated circuit cards (eUICCs) without relying on over-the-air (OTA) platforms, which are costly and involve third-party service operations.

Innovation Solution

A provisioning server, such as a subscriber management data preparation (SMDP) server, is used to manage profile content on eUICCs, allowing mobile network operators (MNOs) to update profiles directly, with options for trusted and untrusted scenarios, including encryption with OTA keys for secure updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If OTA platforms are used for profile content updates, then security and established protocol support are improved, but operational costs and device complexity increase

Engineering Contradiction:
Improveprofile update securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the profile content update functionality from the OTA platform and implements it directly within the eUICC and LPA architecture. The eUICC hosts the profile and performs updates autonomously using the LPA to communicate with the MNO server, eliminating the intermediary OTA platform and reducing system complexity while maintaining security through existing eUICC cryptographic mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The LPA acts as an intermediary between the MNO server and the eUICC for profile content updates. It manages the update process by receiving update information from the MNO server and coordinating with the eUICC to apply updates, thereby simplifying the architecture compared to OTA platforms while maintaining secure update delivery through established eUICC protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If OTA platforms are used for profile content updates, then established protocols and security mechanisms are maintained, but operational costs and third-party service dependencies increase

Engineering Contradiction:
Improveupdate mechanism reliabilityVSAvoidupdate efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent removes the OTA platform intermediary and enables direct profile content updates between the MNO server and eUICC. The eUICC autonomously manages updates through its integrated LPA, which communicates directly with the MNO server using standardized protocols, thereby eliminating third-party service dependencies and reducing operational costs while maintaining reliability through proven cryptographic mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The eUICC performs self-service for profile content updates by hosting the LPA that autonomously manages the update process. The LPA receives update information from the MNO server and coordinates with the eUICC's profile management functions to apply updates without requiring external OTA platform intervention, thereby improving productivity and eliminating third-party dependencies.

Inventive Principle:
Principle #25Self-service

3Productivity

If direct MNO server to eUICC updates are implemented, then operational costs and third-party dependencies are reduced, but trust relationship establishment and security verification complexity increase

Engineering Contradiction:
Improveupdate efficiencyVSAvoidtrust verification complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges the trust verification functions directly into the eUICC-LPA-MNO server communication path. The LPA, hosted within the eUICC, performs authentication and security verification by directly communicating with the MNO server using established cryptographic protocols, eliminating the need for separate OTA platform trust mechanisms and simplifying the overall trust establishment process.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The eUICC's LPA performs self-service for trust verification by autonomously managing authentication with the MNO server. It handles security protocols, certificate verification, and encrypted communication directly with the MNO server, thereby enabling efficient direct updates without requiring complex external trust management infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12021966B2Embedded universal integrated circuit card (eUICC) profile content management
Publication Date: 2024.06.25 APPLE INC
  • US12021966B2 patent drawing
  • US12021966B2 patent drawing
  • US12021966B2 patent drawing

AI summary

A mobile network operator (MNO) uses a provisioning server to update or install profile content in a profile or electronic subscriber identity module (eSIM). In an exemplary embodiment, the profile is present on a secure element such as an embedded universal integrated circuit card (eUICC) in a wireless device. One or more MNOs use the provisioning server to perform profile content management on profiles in the eUICC. In some embodiments, an MNO has a trust relationship with the provisioning server. In some other embodiments, the MNO does not have a trust relationship with the provisioning server and protects payload targeted for an MNO-associated profile using an over the air (OTA) key.