Secure eUICC Profile Management via TLS Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a lack of secure interaction methods between primary and companion terminals with embedded Universal Integrated Circuit Cards (eUICC), particularly for terminals with limited user interfaces and no cellular network access, which poses risks of unauthorized deletion, forgery, or modification of profiles.
Innovation Solution
The method involves a companion terminal indicating an HTTPS URL with security information to a primary terminal, allowing them to establish a TLS connection for secure data exchange, including operation instructions for the eUICC, using certificate authentication and pre-shared keys for mutual authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a companion terminal with limited UI and no cellular network access uses a primary terminal for profile operations, then the companion terminal can access network services, but security risks of unauthorized deletion, forgery, and modification of profiles arise
Solution Approach 1:
The patent introduces an HTTPS session as an intermediary secure communication channel between the primary terminal and companion terminal. This mediator ensures that profile operations are transmitted through an encrypted and authenticated pathway, preventing unauthorized access while maintaining the ability of the companion terminal to access network services through the primary terminal
Solution Approach 2:
The patent applies preliminary anti-action by establishing mutual authentication and encryption before any profile operations occur. The HTTPS session is set up in advance with certificate verification and key exchange, creating security measures that prevent potential unauthorized deletion, forgery, or modification of profiles before such threats can manifest
2Ease of operation
If a primary terminal directly performs operations on the eUICC profile without secure authentication, then operation simplicity is improved, but the risk of unauthorized access and profile manipulation increases
Solution Approach 1:
The HTTPS session acts as an intermediary layer between the primary terminal's simple operation interface and the eUICC profile. This mediator handles the complex security requirements including certificate authentication and encrypted transmission, allowing the primary terminal to maintain operational simplicity while the intermediary ensures protection against unauthorized access
Solution Approach 2:
The companion terminal performs self-service by autonomously establishing the HTTPS session and verifying the primary terminal's credentials. The companion terminal generates and manages its own certificates and encryption keys, enabling it to independently authenticate the primary terminal and protect its profile without requiring complex security management from the user
Data Source
AI summary
A method and an apparatus for secure interaction between terminals, where the method includes indicating or indirectly indicating, by a companion terminal with an embedded Universal Integrated Circuit Card (eUICC), a Hypertext Transfer Protocol (HTTP) over Secure Socket Layer (HTTPS) Uniform Resource Locator (URL) including security information to a primary terminal such that the primary terminal initiates establishment of a local Transport Layer Security (TLS) connection according to the HTTPS URL, receiving, by the companion terminal, an HTTP request from the primary terminal using the local TLS connection, completing establishment of an HTTPS session when the companion terminal determines that the HTTP request includes the security information, and receiving, by the companion terminal, an operation instruction for the eUICC from the primary terminal using the HTTPS session.


