Key derivation for a module using an embedded universal integrated circuit card

Inventors

Nix, John A.

Assignees

Network 1 Technologies IncM2M and IoT Technologies LLC

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-11082218-B2

Patent

Publication Date

2021-08-03

Expiration Date


Abstract

A module with an embedded universal integrated circuit card (eUICC) can include a received eUICC profile and a set of cryptographic algorithms. The received eUICC profile can include an initial shared secret key for authentication with a wireless network. The module can receive a key K network token and send a key K module token to the wireless network. The module can use the key K network token, a derived module private key, and a key derivation function to derive a secret shared network key K that supports communication with the wireless network. The wireless network can use the received key K module token, a network private key, and the key derivation function in order to derive the same secret shared network key K derived by the module. The module and the wireless network can subsequently use the mutually derived key K to communicate using traditional wireless network standards.

Core Innovation

A module with an embedded Universal Integrated Circuit Card (eUICC) records, in memory, a module public key and a corresponding module private key, a pre-shared secret key, a set of cryptographic parameters, and a module identity. The module generates module encrypted data associated with a first set of servers using the pre-shared secret key, wherein the module encrypted data includes at least a portion of the set of cryptographic parameters.

The module stores a network public key associated with a second set of servers and a network private key. The module generates a mutually derived shared key using Elliptical Curve Diffie Hellman, based on at least the module private key and the network public key, such that the mutually derived shared key can be derived by the second set of servers based on at least the module public key and the network private key.

The module receives from the second set of servers an encrypted profile for the eUICC and decrypts the encrypted profile with the mutually derived shared key in order to store network access credentials. The recorded key material and cryptographic parameters enable encrypted profile handling tied to server sets via the pre-shared secret key and the Elliptical Curve Diffie Hellman mutually derived shared key.

Claims Coverage

The document contains one independent claim covering the eUICC-enabled module workflow for recording key material, generating server-associated encrypted data, deriving a shared key via Elliptical Curve Diffie Hellman using module and network keys, and decrypting an encrypted eUICC profile to store network access credentials.

Recording module keys, pre-shared secret, cryptographic parameters, and module identity

The module records in its memory a module public key and a corresponding module private key, a pre-shared secret key, a set of cryptographic parameters, and a module identity.

Generating server-associated encrypted data using pre-shared secret key

The module generates module encrypted data associated with a first set of servers using the pre-shared secret key, wherein the module encrypted data includes at least a portion of the set of cryptographic parameters.

Storing network public key associated with network private key and second server set

The module stores a network public key, wherein the network public key is associated with a second set of servers and a network private key.

Mutually derived shared key via Elliptical Curve Diffie Hellman from module private key and network public key

The module generates a mutually derived shared key using Elliptical Curve Diffie Hellman derived based on the module private key and the network public key, and wherein the mutually derived shared key can be derived by the second set of servers based on the module public key associated with the module private key and the network private key associated with the network public key.

Decrypting encrypted eUICC profile using the mutually derived shared key to store network access credentials

The module receives from the second set of servers an encrypted profile for the eUICC and decrypts the encrypted profile with the mutually derived shared key in order to store network access credentials.

The inventive coverage centers on key recording for an eUICC module, generating encrypted data for a first set of servers using a pre-shared secret key, storing a network public key for a second server set, deriving a mutually derived shared key via Elliptical Curve Diffie Hellman, and using that shared key to decrypt an encrypted eUICC profile to store network access credentials.

Stated Advantages

Documented Applications

No documented applications found

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.