eUICC Profile Installation via Pre-Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional UICCs are not suitable for miniaturization and are inadequate for M2M equipment, and provisioning profiles for a large number of terminals with internal security modules is challenging, especially when network synchronization is poor.
Innovation Solution
A method and device for installing eUICC profiles that involve encrypting profiles and password keys in advance, allowing for decentralized provisioning without network synchronization, using a network device with encryption and storage capabilities to transmit and install encrypted profiles and keys to eUICCs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If profiles are encrypted and transmitted in real-time for each terminal, then security is improved, but provisioning speed deteriorates when large numbers of terminals need profiles
Solution Approach 1:
The patent pre-generates and stores multiple encrypted profile versions with different encryption keys before provisioning. When a terminal requests a profile, the system can immediately provide a pre-prepared encrypted profile without requiring real-time encryption, thus maintaining security while dramatically improving provisioning speed for large numbers of terminals
Solution Approach 2:
The patent segments the profile data into multiple encrypted versions, each encrypted with a different key. This allows the system to provide different encrypted profile segments to different terminals based on their specific authentication credentials, maintaining individualized security while enabling batch provisioning operations
2Volume of moving object
If UICC is made smaller for miniaturization, then terminal size is reduced, but reliability deteriorates due to loss risk and slot space requirements
Solution Approach 1:
The patent merges the UICC functionality with the terminal's internal security module (eSIM). The authentication credentials and profile data are integrated into the terminal's embedded secure element, eliminating the need for a separate physical UICC card while maintaining authentication security through hardware-based security modules within the terminal itself
Solution Approach 2:
The patent creates virtual copies of UICC functionality through software-based eUICC implementations in the terminal's embedded security module. Multiple profile copies can be stored and activated in the eUICC, providing the same authentication security as physical UICCs without the physical form factor constraints
3Reliability
If profiles are provisioned without network synchronization, then provisioning reliability is improved in poor network conditions, but device complexity increases
Solution Approach 1:
The patent pre-generates and stores multiple encrypted profile versions with different encryption keys in the SM-DP+ server before network connectivity issues occur. This preliminary preparation allows terminals to receive and install profiles without requiring real-time network synchronization or complex local encryption capabilities, as the encryption work is already completed server-side
Solution Approach 2:
The patent introduces an intermediary SM-DP+ server that handles all encryption and profile preparation operations. This intermediary absorbs the complexity of encryption operations, allowing terminals to simply receive and install pre-encrypted profiles without implementing complex local encryption mechanisms
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to a method and a device for installing a profile of an embedded universal integrated circuit boards (eUICC) and, more particularly, to a method and a device for remotely installing mobile communication subscriber information (profile) substituting for a universal integrated circuit boards (UICC), on a security module. The present invention relate to a method and a device for installing a profile of an eUICC of a network device, the method comprising the steps of: acquiring at least one of or more profiles encrypted with a first password key and one or more first password keys encrypted with a second password key; and when profile installation for the eUICC starts, transmitting to, at least one eUICC, the one or more encrypted profiles and the one or more encrypted first password keys, wherein the first password key is re-encrypted by the first password key with a third password key and transmitted to the one or more eUICCs and the encrypted profiles are decrypted by the first password key and installed on the one or more eUICCs, respectively.