UICC Initialization with Encrypted OS and Authenticated Personalization Lock

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing UICC initialization and personalization processes are vulnerable to abusive spreading of operating systems to unauthorized UICCs, as semiconductor vendors or OEMs may share OS and decryption keys with third parties without permission, allowing fraudulent personalization.

Innovation Solution

Incorporating an OS-owner specific lock-key into the OS image, and using a Hardware Security Module (HSM) to securely store the unlock-key, ensuring that the command dispatcher can only be unlocked by authorized personalization stations through authentication procedures, preventing unauthorized UICC personalization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the command dispatcher is kept unlocked to allow personalization commands to be processed, then personalization can be performed, but unauthorized OS loading and abusive spreading of operating systems can occur

Engineering Contradiction:
Improvepersonalization capabilityVSAvoidsecurity against fraudulent OS loading
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by locking the command dispatcher before personalization begins. The lock is prepared in advance and only unlocked temporarily when needed for authentication. This ensures that even if unauthorized persons gain access to the UICC, the command dispatcher remains protected unless proper authentication occurs, thus preventing abusive spreading of operating systems while allowing legitimate personalization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements preliminary anti-action by introducing an authentication mechanism that verifies the identity of the personalization station before unlocking the command dispatcher. This pre-verification step prevents unauthorized operations by blocking access until proper credentials are presented, thereby countering potential fraudulent OS loading attempts before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If the command dispatcher is locked to prevent unauthorized access, then security against fraudulent personalization is improved, but legitimate personalization operations cannot be performed

Engineering Contradiction:
Improvesecurity against unauthorized personalizationVSAvoidpersonalization execution
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies dynamics by making the command dispatcher's state changeable - it transitions from a locked state to an unlocked state temporarily during authenticated personalization operations, then returns to locked state. This dynamic behavior allows the system to maintain security by default while enabling legitimate operations when needed, resolving the contradiction between security and operational capability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an authentication mechanism as an intermediary between the locked command dispatcher and personalization operations. This intermediary verifies the identity of the personalization station and controls the unlocking process, ensuring that only authorized operations can access the command dispatcher while maintaining security against unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If OS and decryption keys are shared with third-party production sites for UICC initialization, then mass production capability is improved, but abusive spreading of operating systems to non-authorized UICCs occurs

Engineering Contradiction:
Improvemass production capabilityVSAvoidfraudulent OS distribution
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the critical security function from the third-party production environment by implementing authentication and locking mechanisms within the UICC itself. The command dispatcher is locked and requires authentication, meaning that even if OS images are present at third-party sites, they cannot be loaded onto unauthorized UICCs without proper credentials. This extraction of security control from the production environment prevents abusive spreading while maintaining mass production capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4075264B1Initialization and personalization of a uicc
Publication Date: 2025.08.13 GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
  • EP4075264B1 patent drawingFigure 1
  • EP4075264B1 patent drawingFigure 2
  • EP4075264B1 patent drawingFigure 3

AI summary

A method for initialization of a UICC, comprising the steps: (a) providing a UICC comprising a UICC-specific decryption key; (b) loading an encrypted OS image comprising an operating system into the UICC; (c) in the UICC, decrypting the encrypted OS image with the UICC-specific decryption key and installing the operating system in the UICC; (d) providing a command dispatcher to the UICC, the command dispatcher constructed to receive personalization commands from a personalization station to process the received personalization commands and to thereby personalize the UICC; characterized by (e) providing a lock-key to the UICC; (f) after installing the operating system in the UICC, locking the command dispatcher to enter a locked state in which the command dispatcher is unable to receive and/or to process personalization commands.