Key derivation for a module using an embedded universal integrated circuit card

Inventors

Nix, John A.

Assignees

Network 1 Technologies IncM2M and IoT Technologies LLC

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-11736283-B2

Patent

Publication Date

2023-08-22

Expiration Date


Abstract

A module with an embedded universal integrated circuit card (eUICC) can include a received eUICC profile and a set of cryptographic algorithms. The received eUICC profile can include an initial shared secret key for authentication with a wireless network. The module can receive a key K network token and send a key K module token to the wireless network. The module can use the key K network token, a derived module private key, and a key derivation function to derive a secret shared network key K that supports communication with the wireless network. The wireless network can use the received key K module token, a network private key, and the key derivation function in order to derive the same secret shared network key K derived by the module. The module and the wireless network can subsequently use the mutually derived key K to communicate using traditional wireless network standards.

Core Innovation

The invention supports an embedded Universal Integrated Circuit Card (eUICC) on a mobile device together with cryptographic parameter sets and a server-based authentication and key establishment flow. The mobile device records a mobile device public key and mobile device private key, a pre-shared secret key, cryptographic parameters, and a mobile device identity, then generates a message authentication code (MAC) using the pre-shared secret key for authentication with a first set of servers.

The mobile device receives server encrypted data from the first set of servers, where the server encrypted data includes a set of cryptographic parameters, and decrypts the server encrypted data using the pre-shared secret key. The mobile device stores a network public key associated with a second set of servers and a network private key, and uses Elliptical Curve Diffie Hellman to generate a mutually derived shared key based on the mobile device private key, the network public key, and the set of cryptographic parameters.

The second set of servers derive the mutually derived shared key based on the mobile device public key associated with the mobile device private key, the network private key associated with the network public key, and the set of cryptographic parameters. After the mutually derived shared key is generated, the mobile device receives an encrypted profile for the eUICC and decrypts the encrypted profile using the mutually derived shared key to store network access credentials. The description also states dynamic eUICC profile activation and rekeying, including updated cryptographic parameters and a new key generation instruction after waking from sleep.

Claims Coverage

The provided independent claim is clm-00001. It covers a mobile-device/eUICC cryptographic workflow with MAC-based authentication using a pre-shared secret key, server encrypted cryptographic parameter exchange, ECDH-based mutually derived shared key generation with a second server set, and decryption of an encrypted eUICC profile to store network access credentials.

Two-set server authenticated eUICC key establishment and profile decryption

The mobile device records device key material, a pre-shared secret key, cryptographic parameters, and a mobile device identity, generates a MAC using the pre-shared secret key for authentication with a first set of servers, receives server encrypted data including a set of cryptographic parameters and decrypts it, stores a network public key associated with a second set of servers and a network private key, receives from the second set of servers an encrypted profile for the eUICC, and decrypts the encrypted profile using a mutually derived shared key to store network access credentials.

ECDH mutually derived shared key from recorded keys and cryptographic parameters

The mobile device generates a mutually derived shared key using Elliptical Curve Diffie Hellman in which the mutually derived shared key is derived by the mobile device based on the mobile device private key, the network public key, and the set of the cryptographic parameters, and is derived by the second set of servers based on the mobile device public key associated with the mobile device private key, the network private key associated with the network public key, and the set of cryptographic parameters.

MAC authentication with pre-shared secret key and server cryptographic parameter exchange

The mobile device generates a message authentication code (MAC) using the pre-shared secret key for authentication with a first set of servers, receives server encrypted data from the first set of servers wherein the server encrypted data includes a set of the cryptographic parameters, and decrypts the server encrypted data using the pre-shared secret key.

Encrypted eUICC profile decryption to store network access credentials

The mobile device receives from the second set of servers an encrypted profile for the eUICC and decrypts the encrypted profile using the mutually derived shared key in order to store network access credentials.

Independent claim clm-00001 centers on an eUICC-enabled mobile device that performs MAC-based authentication with a first set of servers, exchanges and decrypts cryptographic parameters, then performs ECDH-based mutually derived shared key establishment with a second set of servers. The mutually derived shared key is then used to decrypt an encrypted eUICC profile so that network access credentials are stored.

Stated Advantages

Secure communications for obtaining network access credentials without physical UICC swapping, by replacing physical/electronic key distribution with key establishment and authentication using the embedded eUICC and derived shared keys.

Module-private-key confidentiality benefits.

Documented Applications

Obtaining network access credentials by decrypting an encrypted profile for an eUICC using a mutually derived shared key established with server sets.

Enables later LTE/LTE-A authentication using an eUICC-based derived shared secret network key while avoiding distribution of the derived key in the eUICC profile.

Supports dynamic eUICC profile activation and rekeying, including updating cryptographic parameters and generating new key material after waking from sleep.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.