Secure eUICC Profile Management via TLS Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of secure interaction methods between primary and companion terminals with embedded Universal Integrated Circuit Cards (eUICC), particularly for terminals with limited user interfaces and no cellular network access, which poses risks of unauthorized deletion, forgery, or modification of profiles.

Innovation Solution

The method involves a companion terminal indicating an HTTPS URL with security information to a primary terminal, allowing them to establish a TLS connection for secure data exchange, including operation instructions for the eUICC, using certificate authentication and pre-shared keys for mutual authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a companion terminal with limited UI and no cellular network access uses a primary terminal for profile operations, then the companion terminal can access network services, but security risks of unauthorized deletion, forgery, and modification of profiles arise

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidprofile security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an HTTPS session as an intermediary secure communication channel between the primary terminal and companion terminal. This mediator ensures that profile operations are transmitted through an encrypted and authenticated pathway, preventing unauthorized access while maintaining the ability of the companion terminal to access network services through the primary terminal

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary anti-action by establishing mutual authentication and encryption before any profile operations occur. The HTTPS session is set up in advance with certificate verification and key exchange, creating security measures that prevent potential unauthorized deletion, forgery, or modification of profiles before such threats can manifest

Inventive Principle:
Principle #9Preliminary anti-action

2Ease of operation

If a primary terminal directly performs operations on the eUICC profile without secure authentication, then operation simplicity is improved, but the risk of unauthorized access and profile manipulation increases

Engineering Contradiction:
Improveoperation simplicityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The HTTPS session acts as an intermediary layer between the primary terminal's simple operation interface and the eUICC profile. This mediator handles the complex security requirements including certificate authentication and encrypted transmission, allowing the primary terminal to maintain operational simplicity while the intermediary ensures protection against unauthorized access

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The companion terminal performs self-service by autonomously establishing the HTTPS session and verifying the primary terminal's credentials. The companion terminal generates and manages its own certificates and encryption keys, enabling it to independently authenticate the primary terminal and protect its profile without requiring complex security management from the user

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12137094B2Method and apparatus for secure interaction between terminals
Publication Date: 2024.11.05 HUAWEI TECH CO LTD
  • US12137094B2 patent drawing
  • US12137094B2 patent drawing
  • US12137094B2 patent drawing

AI summary

A method and an apparatus for secure interaction between terminals, where the method includes indicating or indirectly indicating, by a companion terminal with an embedded Universal Integrated Circuit Card (eUICC), a Hypertext Transfer Protocol (HTTP) over Secure Socket Layer (HTTPS) Uniform Resource Locator (URL) including security information to a primary terminal such that the primary terminal initiates establishment of a local Transport Layer Security (TLS) connection according to the HTTPS URL, receiving, by the companion terminal, an HTTP request from the primary terminal using the local TLS connection, completing establishment of an HTTPS session when the companion terminal determines that the HTTP request includes the security information, and receiving, by the companion terminal, an operation instruction for the eUICC from the primary terminal using the HTTPS session.