eUICC Profile Installation via Pre-Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional UICCs are not suitable for miniaturization and are inadequate for M2M equipment, and provisioning profiles for a large number of terminals with internal security modules is challenging, especially when network synchronization is poor.

Innovation Solution

A method and device for installing eUICC profiles that involve encrypting profiles and password keys in advance, allowing for decentralized provisioning without network synchronization, using a network device with encryption and storage capabilities to transmit and install encrypted profiles and keys to eUICCs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If profiles are encrypted and transmitted in real-time for each terminal, then security is improved, but provisioning speed deteriorates when large numbers of terminals need profiles

Engineering Contradiction:
Improveprofile encryption securityVSAvoidprofile provisioning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent pre-generates and stores multiple encrypted profile versions with different encryption keys before provisioning. When a terminal requests a profile, the system can immediately provide a pre-prepared encrypted profile without requiring real-time encryption, thus maintaining security while dramatically improving provisioning speed for large numbers of terminals

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the profile data into multiple encrypted versions, each encrypted with a different key. This allows the system to provide different encrypted profile segments to different terminals based on their specific authentication credentials, maintaining individualized security while enabling batch provisioning operations

Inventive Principle:
Principle #1Segmentation

2Volume of moving object

If UICC is made smaller for miniaturization, then terminal size is reduced, but reliability deteriorates due to loss risk and slot space requirements

Engineering Contradiction:
ImproveUICC sizeVSAvoidauthentication security
Core Design Contradiction:
Volume of moving objectVSReliability

Solution Approach 1:

The patent merges the UICC functionality with the terminal's internal security module (eSIM). The authentication credentials and profile data are integrated into the terminal's embedded secure element, eliminating the need for a separate physical UICC card while maintaining authentication security through hardware-based security modules within the terminal itself

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates virtual copies of UICC functionality through software-based eUICC implementations in the terminal's embedded security module. Multiple profile copies can be stored and activated in the eUICC, providing the same authentication security as physical UICCs without the physical form factor constraints

Inventive Principle:
Principle #26Copying

3Reliability

If profiles are provisioned without network synchronization, then provisioning reliability is improved in poor network conditions, but device complexity increases

Engineering Contradiction:
Improveprofile provisioning reliabilityVSAvoidlocal encryption capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent pre-generates and stores multiple encrypted profile versions with different encryption keys in the SM-DP+ server before network connectivity issues occur. This preliminary preparation allows terminals to receive and install profiles without requiring real-time network synchronization or complex local encryption capabilities, as the encryption work is already completed server-side

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary SM-DP+ server that handles all encryption and profile preparation operations. This intermediary absorbs the complexity of encryption operations, allowing terminals to simply receive and install pre-encrypted profiles without implementing complex local encryption mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3171622B1Method and device for installing profile of euicc
Publication Date: 2021.01.06 SAMSUNG ELECTRONICS CO LTD
  • EP3171622B1 patent drawingFigure 1
  • EP3171622B1 patent drawingFigure 2
  • EP3171622B1 patent drawingFigure 3

AI summary

The present invention relates to a method and a device for installing a profile of an embedded universal integrated circuit boards (eUICC) and, more particularly, to a method and a device for remotely installing mobile communication subscriber information (profile) substituting for a universal integrated circuit boards (UICC), on a security module. The present invention relate to a method and a device for installing a profile of an eUICC of a network device, the method comprising the steps of: acquiring at least one of or more profiles encrypted with a first password key and one or more first password keys encrypted with a second password key; and when profile installation for the eUICC starts, transmitting to, at least one eUICC, the one or more encrypted profiles and the one or more encrypted first password keys, wherein the first password key is re-encrypted by the first password key with a third password key and transmitted to the one or more eUICCs and the encrypted profiles are decrypted by the first password key and installed on the one or more eUICCs, respectively.