eUICC Trust Relationship via Cryptographic Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in forming trust relationships between entities in an eSIM environment, particularly between a Mobile Network Operator (MNO), a Subscription Manager (SM), an embedded Universal Integrated Circuit Card (eUICC), and a terminal, where existing solutions lack a technical mechanism for establishing and maintaining secure, reliable connections.

Innovation Solution

A method is proposed that involves generating and exchanging verification information based on shared trust information to authenticate entities, ensuring secure communication and trust establishment between the eUICC, SM-SR, SM-DP, and MNO, utilizing cryptographic techniques like hash functions and electronic signatures to verify the authenticity of entities within the eSIM system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Volume of moving object

If an embedded UICC is used to miniaturize terminals, then terminal size is reduced, but the ability to switch mobile network operators is limited

Engineering Contradiction:
Improveterminal sizeVSAvoidability to switch mobile network operators
Core Design Contradiction:
Volume of moving objectVSAdaptability or versatility

Solution Approach 1:

The eUICC incorporates dynamic profile download capability that allows the card to be reconfigured remotely via OTA (Over-The-Air) technology. The profile management entity can download different operator profiles to the eUICC, enabling the terminal to switch between mobile network operators without physical card replacement, thus resolving the contradiction between miniaturization and operator switching flexibility

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention uses digital copying of operator profiles instead of physical SIM cards. Multiple operator profiles are stored in encrypted form within the eUICC, and the system can activate different profiles by downloading and decrypting them remotely. This digital profile copying mechanism enables operator switching while maintaining the embedded card structure

Inventive Principle:
Principle #26Copying

2Reliability

If trust relationships are established using cryptographic verification, then security is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity of trust relationshipsVSAvoidcomplexity of verification mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary cryptographic key pair generation and trust relationship establishment during the eUICC provisioning phase before the terminal is activated. The profile management entity and eUICC exchange cryptographic keys and establish trust anchors in advance, so that when the terminal operates, the verification processes are already configured and can proceed with simpler operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces a profile management entity as an intermediary that handles complex cryptographic operations. This intermediary manages the generation, distribution, and verification of cryptographic keys between the eUICC and network operators, shielding the terminal from direct complexity while maintaining security through standardized verification protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10462668B2Method for forming a trust relationship, and embedded UICC therefor
Publication Date: 2019.10.29 SAMSUNG ELECTRONICS CO LTD
  • US10462668B2 patent drawing
  • US10462668B2 patent drawing
  • US10462668B2 patent drawing

AI summary

The present invention relates to a method for forming a trust relationship among an MNO, an SM, and an eUICC in a communication system in which the SM is defined as an entity for managing the eUICC, as well as to an embedded UICC therefor.