Secure Chip eUICC Assignment Transfer via Subscription Manager Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current techniques for transferring service subscriptions from one mobile network operator to another lack an efficient mechanism for secure chip reassignment, particularly for embedded Universal Integrated Circuit Cards (eUICCs), which hinders seamless ownership transfer and network access provisioning without direct relationships between operators.
Innovation Solution
The method involves a subscription manager receiving a request for transfer, generating transfer permission data, and sending it to the secure chip, which then facilitates the reassignment to a new subscription manager by verifying digital signatures and certificates, enabling secure and trusted transfer of eUICC profiles between operators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If direct relationship or trust between different MNOs is required for service subscription transfer, then security and trustworthiness of the transfer process is improved, but the complexity of establishing relationships between operators increases and seamless transfer is hindered
Solution Approach 1:
The patent introduces a subscription manager as an intermediary entity that manages eUICC assignments between different MNOs. The subscription manager receives transfer requests, generates transfer permission data with digital signatures, and facilitates the reassignment process without requiring direct trust relationships between the involved operators. This mediator approach allows seamless subscription transfers while maintaining security through cryptographic verification.
2Ease of operation
If secure chip reassignment mechanism is implemented, then seamless ownership transfer and network access provisioning is enabled, but the complexity of the transfer process increases
Solution Approach 1:
The patent implements preliminary action by having the subscription manager generate transfer permission data with digital signatures before the actual eUICC reassignment occurs. The transfer permission data is prepared in advance with all necessary cryptographic elements (digital signature of current SM, identifier of new SM) so that the actual transfer process can proceed seamlessly without complex real-time negotiations or verifications between operators.
Solution Approach 2:
The patent uses digital signature copying where the current subscription manager's digital signature is embedded in the transfer permission data and verified by the new subscription manager. This cryptographic copying mechanism enables trust transfer without requiring direct relationships between operators, simplifying the overall transfer process while maintaining security.
3Reliability
If digital signature verification is performed during transfer, then security of the reassignment process is improved, but the processing time and complexity increase
Solution Approach 1:
The digital signature verification is performed as a preliminary action during the transfer permission data generation phase. The current subscription manager signs the transfer permission data in advance, and this pre-signed data is then efficiently verified by the new subscription manager without requiring complex real-time cryptographic negotiations, thus reducing processing time while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Techniques for use in transferring an assignment of a secure chip of a wireless device from a current subscription manager (SM) of a current mobile network operator (MNO) to a new SM of a new MNO are described. In one illustrative example, the current SM receives a request for transferring the assignment and produces transfer permission data in response. The transfer permission data includes an identifier of the secure chip, an identifier of the current SM, and a digital signature of the current SM. The current SM then sends to the secure chip a transfer permission message which includes the transfer permission data. The transfer permission data indicates a permission for the secure chip to transfer the assignment from the current SM to the new SM. Additional techniques are performed by the secure chip, and the new SM, as described.