Secure Element Profile Provisioning with Pre-Installed Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional remote provisioning methods for secure elements in energy-constrained devices, such as eUICC and iUICC, are energy-intensive and require complex key agreement steps, leading to increased manufacturing costs and reduced flexibility due to the need for managing multiple SKUs for different mobile network operators.

Innovation Solution

Utilizing pre-installed encryption keys in the secure element to encrypt and decrypt bound profile packages, eliminating the need for key agreement steps during provisioning, allowing for secure and efficient remote installation of connectivity profiles in multiple sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional remote provisioning methods are used for secure elements, then connectivity profiles can be provisioned remotely, but the process is energy-intensive and requires complex key agreement steps

Engineering Contradiction:
Improveremote provisioning capabilityVSAvoidenergy consumption during provisioning
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by pre-installing encryption keys in the secure element before the provisioning process. The secure element contains pre-configured key storage with encryption keys that are ready before remote provisioning occurs, eliminating the need for time-consuming key agreement steps during actual profile provisioning. This preliminary key installation enables energy-efficient remote provisioning by avoiding complex key negotiation protocols.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If conventional remote provisioning methods are used for secure elements, then connectivity profiles can be provisioned remotely, but key agreement steps increase device complexity

Engineering Contradiction:
Improveremote provisioning capabilityVSAvoidkey agreement process complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-installing encryption keys in the secure element before the provisioning process. The secure element contains pre-configured key storage with encryption keys that are ready before remote provisioning occurs, eliminating the need for time-consuming key negotiation steps during actual profile provisioning. This preliminary key installation simplifies the device architecture by removing complex key agreement protocols.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the key agreement functionality from the provisioning process by using pre-installed keys. Instead of performing key agreement during provisioning, the system extracts and uses pre-configured keys that are already stored in the secure element's key storage, thereby removing the complex key agreement steps from the provisioning workflow.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If pre-installed keys are used for provisioning, then key agreement steps are eliminated, but security may be compromised if keys are not properly managed

Engineering Contradiction:
Improveprovisioning speedVSAvoidsecurity of pre-installed keys
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-installing encryption keys in the secure element before the provisioning process. The secure element contains pre-configured key storage with encryption keys that are ready before remote provisioning occurs, eliminating the need for time-consuming key negotiation steps during actual profile provisioning. This preliminary key installation enables energy-efficient remote provisioning by avoiding complex key negotiation protocols.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses key storage as an intermediary component that securely holds pre-installed encryption keys. The key storage acts as a protected intermediary between the provisioning system and the connectivity profiles, managing key access and ensuring that pre-installed keys are only used for their intended purpose of decrypting and installing profiles without exposing the keys to unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If multiple connectivity profiles are stored in secure element, then device flexibility increases, but storage requirements increase

Engineering Contradiction:
Improvemulti-profile support capabilityVSAvoidstorage capacity required
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent applies segmentation by organizing connectivity profiles into separate, discrete entries within the secure element's storage. Each connectivity profile is stored as an independent unit with its own associated keys and metadata, allowing the system to manage multiple profiles efficiently without requiring contiguous large storage spaces. This segmentation enables flexible profile management and selective activation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universality by designing the secure element's key storage and profile management system to handle multiple types of connectivity profiles from different network operators. The pre-installed key infrastructure and profile storage mechanism are designed to universally support various profile formats and network operators, allowing a single secure element to store and activate multiple connectivity profiles without requiring operator-specific hardware configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4601347A1Connectivity profile provisioning for secure element
Publication Date: 2025.08.13 KIGEN (UK) LIMITED
  • EP4601347A1 patent drawingFigure 1~2
  • EP4601347A1 patent drawingFigure 3
  • EP4601347A1 patent drawingFigure 4

AI summary

A method is provided for provisioning a secure element with a given connectivity profile for mobile network communication. The method comprises: receiving, at the secure element, a bound profile package specifying the given connectivity profile, the bound profile package being encrypted using an encryption key specific to the secure element; decrypting the bound profile package using a pre-installed key pre-installed in key storage of the secure element prior to initiation of a connectivity profile provisioning process for provisioning the secure element with the given connectivity profile; and installing the given connectivity profile from the decrypted bound profile package on the secure element.