eUICC Public Certificate for Remote Subscription Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the remote subscription management of eUICCs, existing technologies face challenges in provisioning subscription manager servers with data for eUICCs, particularly in the consumer market where the manufacturing and operation of eUICCs are managed by different entities, and there is a need for end-users to choose their Mobile Network Operator (MNO) for connectivity, complicating the ecosystem setup.
Innovation Solution
A method allowing end-users to remotely manage eUICCs embedded in terminals by establishing a secure channel using a public certificate and cryptographic services, enabling the subscription manager server to decide if it can manage the eUICC without prior knowledge, and performing key establishment and subscription management requests securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the subscription manager server is provisioned with eUICC data in advance, then the server can manage eUICCs, but the complexity of ecosystem setup increases and pre-provisioning steps are required
Solution Approach 1:
The eUICC manufacturer performs preliminary actions by embedding a public certificate in the eUICC during manufacturing. This certificate contains information that enables the subscription manager server to verify eUICC authenticity without requiring pre-provisioning of eUICC data in the server, thus resolving the contradiction between ensuring management capability and reducing setup complexity
Solution Approach 2:
The invention extracts the verification capability from the subscription manager server by using public key infrastructure. Instead of provisioning server-side credentials for each eUICC, the system uses the eUICC's embedded public certificate for verification, eliminating the need for complex pre-provisioning while maintaining reliable subscription management
2Ease of manufacture
If the eUICC manufacturer manages the eUICC provisioning, then manufacturing is simplified, but the subscription manager server cannot independently manage eUICCs from different manufacturers
Solution Approach 1:
The public certificate embedded in the eUICC serves as a universal verification mechanism that works across multiple manufacturers and subscription manager servers. The certificate contains standardized information that any compliant server can verify, enabling the eUICC to be manufactured by different EUMs while maintaining compatibility with any subscription manager server in the ecosystem
Solution Approach 2:
The public certificate acts as an intermediary that bridges the eUICC and subscription manager server. It provides a standardized interface for verification that works regardless of which manufacturer produced the eUICC or which server manages it, thus resolving the contradiction between manufacturing simplicity and multi-manufacturer adaptability
3Reliability
If pre-provisioning of shared keys is required, then secure communication can be established, but the deployment process becomes more complex and time-consuming
Solution Approach 1:
The eUICC manufacturer performs preliminary action by embedding the public certificate in the eUICC during manufacturing. This eliminates the need for time-consuming pre-provisioning of shared keys in the subscription manager server, reducing deployment time while maintaining secure communication through cryptographic verification
Solution Approach 2:
The invention replaces the mechanical process of manually provisioning shared keys with an automated cryptographic verification system using public key infrastructure. This substitution eliminates the time-consuming manual configuration steps while ensuring secure communication through mathematical cryptography
Data Source
AI summary
Remote subscription management of an eUICC comprising a private key and a public certificate, the public certificate comprising information allowing a subscription manager server to decide if it can agree to manage the eUICC. The method includes: establishing a secure channel between the terminal and the subscription manager server by using the public certificate and dedicated cryptographic services of the eUICC; sending to the subscription manager server a subscription management request; verifying, based on the information in the public certificate in the subscription manager server, whether the eUICC is entitled to be managed by the subscription manager server and, if yes: performing a key establishment procedure between the subscription manager server and the eUICC by using the eUICC public certificate; establishing between the subscription manager server and the eUICC a secure channel with the established keys; and, executing by the subscription manager server the subscription management request on the eUICC.

