Key derivation for a module using an embedded universal integrated circuit card
Inventors
Assignees
Interested in licensing this patent?
MTEC can help explore whether this patent might be available for licensing for your application.
Abstract
A module with an embedded universal integrated circuit card (eUICC) can include a received eUICC profile and a set of cryptographic algorithms. The received eUICC profile can include an initial shared secret key for authentication with a wireless network. The module can receive a key K network token and send a key K module token to the wireless network. The module can use the key K network token, a derived module private key, and a key derivation function to derive a secret shared network key K that supports communication with the wireless network. The wireless network can use the received key K module token, a network private key, and the key derivation function in order to derive the same secret shared network key K derived by the module. The module and the wireless network can subsequently use the mutually derived key K to communicate using traditional wireless network standards.
Core Innovation
A mobile device with an embedded universal integrated circuit card (eUICC) securely communicates with a wireless network by storing, in the eUICC, a first module private key, a corresponding first module public key, and a network public key. The mobile device receives, from a first server associated with the wireless network, an encrypted profile for the eUICC that includes cryptographic parameters, a module identity, and a key K. The mobile device generates a shared secret key using a first elliptic curve Diffie-Hellman (ECDH) key exchange with the first module private key and the network public key, and decrypts at least a portion of the encrypted profile using the shared secret key.
After decrypting the encrypted profile, the eUICC generates a second module public key and a corresponding second module private key. The mobile device sends, to a second server associated with the wireless network, the second module public key, and generates a symmetric key using a second ECDH key exchange with the second module private key and the cryptographic parameters. With the symmetric key, the mobile device generates module encrypted data that includes the module identity, and sends the module encrypted data to the second server.
The described approach integrates cryptographic-parameter sets identified via tokens and supports ECC-based public key cryptography using X.509 certificates and ECDSA/SHA-256, together with management of multiple module public/private key pairs over long device lifetimes. Separate eUICC profile receipt and activation is described as decrypting received eUICC profiles using initial module/private keys and ECDH-derived shared secrets, and deriving module key pairs and secret shared network keys for subsequent wireless authentication.
Claims Coverage
The independent claim content identifies one primary inventive workflow with three merged inventive features: eUICC key storage and encrypted-profile receipt, ECDH-based profile decryption, and second module key generation with symmetric-key encryption and transmission.
Ecdh-based shared secret to decrypt an encrypted eUICC profile
A mobile device with an embedded eUICC stores a first module private key, a corresponding first module public key, and a network public key, receives from a first server an encrypted profile comprising cryptographic parameters, a module identity, and a key K, generates a shared secret key using a first ECDH key exchange with the first module private key and the network public key, and decrypts at least a portion of the encrypted profile using the shared secret key.
Second module key generation and second-server module public-key submission
After decrypting the encrypted profile, the eUICC generates a second module public key and a corresponding second module private key, and sends the second module public key to a second server associated with the wireless network.
Symmetric key from second Ecdh and module-encrypted data including module identity
Using the second module private key and the cryptographic parameters, the mobile device generates a symmetric key using a second ECDH key exchange, generates module encrypted data using the symmetric key where the module encrypted data comprises the module identity, and sends the module encrypted data to the second server.
Overall, the independent claim covers a secure eUICC workflow that uses ECDH-derived shared secrets to decrypt an encrypted eUICC profile, produces a second module key pair for communication with a second server, and then derives a symmetric key via a second ECDH operation to encrypt and send module encrypted data containing the module identity.
Stated Advantages
Fewer packets.
Replay protection.
Avoiding distribution of key material, including avoiding distribution of key K through eUICC profiles.
The approach supports management of multiple module public/private key pairs over long device lifetimes.
Documented Applications
Secure communication between a mobile device with an embedded eUICC and one or more servers associated with a wireless network over IP, including switching between asymmetric and symmetric ciphering across message sequences.
Subsequent wireless authentication.
Interested in licensing this patent?