Network Access Profile Transfer with Source Deletion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing on-board security modules in mobile equipment, such as eSIM and SSP, do not allow secure transfer of network access profiles without risking cloning, which is a critical security challenge for network operators.
Innovation Solution
A method involving a first mobile equipment with a security module encrypts a network access profile using a secret key, transfers it through a secure logic communication channel to a second mobile equipment, and deletes the profile from the first equipment, ensuring only one active profile exists, using mutual authentication and encryption to prevent cloning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a network access profile is transferred from a first mobile equipment to a second mobile equipment using existing on-board security modules (eSIM, SSP), then the transfer can be performed without direct operator interaction, but the profile may be cloned and multiple identical profiles can remain active simultaneously, compromising network security
Solution Approach 1:
The first security module deletes the network access profile before transferring it to the second security module. This preliminary deletion action ensures that the profile cannot be cloned and remain active in both devices simultaneously, resolving the security vulnerability while maintaining convenient profile transfer
Solution Approach 2:
A secret key acts as an intermediary mechanism between the first and second security modules. The profile is encrypted with this secret key during transfer, and the key is transmitted securely through the logic communication channel, enabling secure profile migration without operator intervention while preventing cloning
2Reliability
If the network access profile is encrypted and transferred through a logic communication channel between security modules, then cloning is prevented, but the complexity of the transfer mechanism increases
Solution Approach 1:
The security modules perform the encryption, decryption, and profile deletion operations autonomously using the secret key and established logic communication channel. This self-service capability eliminates the need for operator intervention or complex external verification systems, achieving cloning protection without proportionally increasing system complexity
Data Source
AI summary
A method for protecting a network access profile against cloning. A first mobile equipment includes a first security module having the network access profile. A second mobile equipment is designed to receive the network access profile and includes a second security module. The first and second security modules are designed to establish a logic communication channel with each other. The method is implemented by the first security module and includes: generating a secret key; using the secret key to encrypt a data packet associated with the network access profile; sending the encrypted packet to the second security module through the logic communication channel; receiving, from the second security module, an acknowledgement of a correct receipt of the encrypted data packet; deleting the data packet associated with the network access profile; and then sending the secret key to the second security module through the logic communication channel.
