SM-SR Switching via Encrypted Credential Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of switching subscription manager-secure routing devices for embedded UICCs, the challenge lies in ensuring that the profile management credential of the target SM-SR cannot be learned by the source SM-SR during the switching process, while enabling secure communication and access to mobile networks.
Innovation Solution
The method involves acquiring a profile installer credential from the source SM-SR, generating a key pair, and using the second SM-SR to encrypt and send a provisioning profile to the eUICC, which then replaces the preset SM-SR, ensuring secure communication and access through the target SM-SR without revealing the target SM-SR's credential to the source SM-SR.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the source SM-SR transfers remote management right to the target SM-SR B, then the eUICC can access the mobile network of the target operator, but the profile management credential of the target SM-SR B may be learned by the source SM-SR A
Solution Approach 1:
The target SM-SR B performs preliminary actions by generating a new profile management credential and encrypting it with a public key before the actual switching occurs. The encrypted credential is transmitted to the eUICC in advance, ensuring that when switching happens, the source SM-SR A cannot intercept the plaintext credential.
Solution Approach 2:
The eUICC acts as an intermediary that receives and stores the encrypted profile management credential from the target SM-SR B. It then uses its private key to decrypt and activate the credential, serving as a secure mediator that prevents the source SM-SR A from learning the credential during the switching process.
Solution Approach 3:
The target SM-SR B creates a copy of the profile management credential and encrypts it before transmission. This allows the credential to be securely replicated and delivered to the eUICC without exposing the original plaintext credential to the source SM-SR A during the switching process.
2Reliability
If the eUICC deletes the first profile management credential and activates the second PP, then secure communication with the target SM-SR B is established, but the switching process complexity increases
Solution Approach 1:
The target SM-SR B performs preliminary actions by generating a new profile management credential and encrypting it with a public key before the actual switching occurs. The encrypted credential is transmitted to the eUICC in advance, ensuring that when switching happens, the source SM-SR A cannot intercept the plaintext credential.
Solution Approach 2:
The eUICC acts as an intermediary that receives and stores the encrypted profile management credential from the target SM-SR B. It then uses its private key to decrypt and activate the credential, serving as a secure mediator that prevents the source SM-SR A from learning the credential during the switching process.
Data Source
AI summary
The present invention provides a method and a device for switching a subscription manager-secure routing device. The method includes: acquiring, by a second SM-SR from a first SM-SR, a PIC corresponding to an eUICC; acquiring, by the second SM-SR from a second SM-DP, a second PP that is encrypted by using the PIC; generating, by the second SM-SR, a key pair including a public key and a private key; sending, by the second SM-SR, the second PP and the public key to the eUICC through the first SM-SR, so that the eUICC accesses the second SM-SR after deactivating a first PP and activating the second PP; and encrypting, by the second SM-SR, a second PMC by using the private key, and sending an encrypted second PMC to the eUICC, so that the eUICC accesses the mobile network through the second SM-SR.


