MNO-Specific 5G Encryption Key Storage in eSIM Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP standards and 5G specifications require varying encryption methods for subscriber identifier information across different mobile network operators (MNOs), making it challenging for user devices to comply with diverse encryption requirements for seamless 5G telecommunication services, especially with the transition to embedded UICCs (eUICCs) and IoT devices with limited resources.

Innovation Solution

The distribution of MNO-specific 5G functionality information allows user devices to store encryption keys and algorithms in either eSIM profiles or a trusted environment, enabling them to adapt to different encryption requirements from multiple MNOs, with the option to use third-party messaging services for network-agnostic updates, particularly beneficial for IoT devices with limited resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single default encryption policy is used in the user device, then the device complexity is reduced and ease of operation is improved, but the adaptability to different MNO encryption requirements deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidadaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The encryption policy is segmented into multiple MNO-specific profiles, each containing encryption settings tailored to specific mobile network operators. The system divides the monolithic encryption configuration into discrete, manageable segments that can be selectively applied based on which MNO the device is connecting to, thus maintaining ease of operation while achieving adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption policy transitions from a static single-default approach to a dynamic multi-profile system. The device automatically selects and applies the appropriate encryption profile based on real-time detection of the connected MNO, making the system adaptable to different encryption requirements while maintaining simple operation for the user.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If multiple MNO-specific encryption profiles are stored in the user device, then the adaptability to different MNO requirements is improved, but the device complexity and memory requirements increase

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Multiple encryption profiles are segmented into distinct MNO-specific configurations, each self-contained with its own encryption algorithms and parameters. This segmentation allows the system to manage complexity by treating each profile as an independent unit rather than managing a single complex multi-MNO configuration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption module is designed with universal functionality to handle multiple MNO profiles through a unified interface. The same underlying encryption infrastructure supports all different MNO requirements, reducing overall system complexity despite supporting multiple profiles through a single multi-functional component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If multiple MNO-specific encryption profiles are stored in the user device, then the adaptability to different MNO requirements is improved, but the memory resources required increase

Engineering Contradiction:
ImproveadaptabilityVSAvoidmemory resources
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

Different parts of the encryption configuration are optimized for their specific purposes. Each MNO profile contains only the encryption parameters and algorithms specific to that operator, avoiding redundant storage of identical encryption data across all profiles. This local optimization reduces overall memory consumption while maintaining full adaptability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Multiple MNO-specific encryption profiles are merged into a single unified data structure within the device. Rather than storing separate independent configuration files for each MNO, the system combines all profiles into one organized repository, reducing redundant metadata and improving memory efficiency while maintaining the ability to access any individual profile.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11277738B2MNO-specific 5G functionality delivery with eSIM stored encryption keys in user device
Publication Date: 2022.03.15 T MOBILE US INC
  • US11277738B2 patent drawing
  • US11277738B2 patent drawing
  • US11277738B2 patent drawing

AI summary

Mobile network operator (MNO)-specific 5G functionality information may be distributed by an MNO to a user device. A request from a mobile network operator (MNO) to provide MNO-specific 5G functionality information of the MNO to a user device may be received. In turn, a messaging service may be directed to deliver the MNO-specific 5G functionality information to the user device for storage in an MNO-specific memory area allocated for the MNO in a trusted environment of the user device. The MNO-specific 5G functionality information may instruct the user device to use an encryption key stored in the trusted environment or an Embedded Subscriber Identity Module (eSIM) of the user device to encrypt or decrypt subscriber identifier information of the user device. The encrypted subscriber identifier information is used for 5G communications exchanged between the user device and a core network of a wireless carrier network operated by the MNO.