Profile Transfer Between Embedded Authentication Modules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Embedded universal integrated circuit cards (eUICC) in small-sized communication terminals cannot be physically removed or inserted, making it difficult to transfer user profiles between terminals.
Innovation Solution
A system and method that utilizes a management server and provider server to securely transfer profiles between embedded authentication modules in different terminals by encrypting and decrypting the profiles using shared credentials, allowing profile import and export without physical module replacement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a detachable UICC is used, then profile transfer between terminals is easy, but the terminal size becomes larger
Solution Approach 1:
The patent separates the authentication module (eUICC) from the profile data, allowing the profile to be independently transferred between terminals while the eUICC remains embedded. This segmentation enables profile portability without requiring a detachable physical card, thus maintaining small terminal size while achieving easy profile transfer.
Solution Approach 2:
The patent introduces a profile management server as an intermediary that facilitates secure profile transfer between terminals. The server acts as a mediator that receives profile data from one terminal, verifies authentication credentials, and delivers the profile to another terminal, enabling seamless profile transfer without physical module replacement.
2Volume of moving object
If an eUICC is embedded in the terminal, then the terminal size is reduced, but profile transfer between terminals becomes difficult
Solution Approach 1:
The patent extracts the profile data from the embedded eUICC and enables its independent transmission through communication interfaces. By separating the profile (software data) from the eUICC (hardware module), the system allows profile extraction and transfer to other terminals while the eUICC remains permanently embedded, thus maintaining small terminal size while achieving profile portability.
Solution Approach 2:
The patent creates a copy of the profile data that can be transmitted between terminals. Instead of physically moving the eUICC, the system generates a transmittable copy of the profile information, authenticates it using shared credentials, and delivers it to the target terminal, enabling profile duplication and transfer without physical module movement.
3Adaptability or versatility
If profile data is transmitted outside the authentication module, then profile transfer flexibility is improved, but security risks increase
Solution Approach 1:
The patent performs preliminary authentication using shared credentials before transmitting profile data. The system verifies the legitimacy of the requesting terminal and the integrity of the profile data in advance, establishing secure communication channels and applying encryption before data leaves the authentication module, thus preventing unauthorized access during transmission.
Solution Approach 2:
The patent changes the state of profile data from unencrypted to encrypted form during transmission. By applying cryptographic transformations and changing data parameters (encoding, encryption keys), the system maintains profile security while enabling flexible transmission between terminals, ensuring that even if data is intercepted, it remains protected.
Data Source
AI summary
A system for transferring a profile that is stored at an authentication module includes: a first terminal that includes a first authentication module and that operates based on a user profile that is stored at the first authentication module; a second terminal that includes a second authentication module and that requests the user profile by transmitting a first message including user identification information; and a management server that receives the first terminal and that acquires a profile that is stored at the first terminal based on user identification information and that transmits the acquired profile to the second terminal, wherein the first terminal exports the stored profile, and the second terminal installs a profile, having received from the management server at the second authentication module.


