Key derivation for a module using an embedded universal integrated circuit card

Patent No. US10187206 (titled "Key derivation for a module using an embedded universal integrated circuit card") on Aug 18, 2017. The application was issued on Jan 22, 2019.

What is this patent about?

’206 is related to the field of secure machine-to-machine (M2M) communications and the remote management of network credentials. Specifically, it addresses the technical challenges of securely provisioning an embedded universal integrated circuit card (eUICC) with a profile containing network access credentials without relying on the physical distribution of SIM cards or the insecure electronic transmission of pre-shared secret keys.

The underlying idea behind ’206 is to leverage public key infrastructure (PKI) and elliptic curve cryptography to mutually derive a shared secret key between a module and a subscription manager. Instead of transmitting a sensitive network key over the air, the system uses an Elliptic Curve Diffie-Hellman (ECDH) exchange to establish a secure session key. This derived key is then used to encrypt the entire eUICC profile, ensuring that only the specific hardware module possessing the corresponding private key can access the network credentials.

The claims of ’206 focus on a method for a subscription manager to securely distribute a profile by utilizing a combination of asymmetric and symmetric cryptography. The process involves receiving a module's certificate from a provider, responding to a hardware challenge with an elliptic curve digital signature, and generating a temporary network key pair. The subscription manager then derives a shared secret using the module's public key and its own network private key, which serves as the encryption key for an AES-128 encrypted payload containing the network access credentials.

In practice, the module and the subscription manager system interact to verify each other's identities before any sensitive data is exchanged. The subscription manager uses its server private key to sign the challenge received from the module, providing authoritative proof of its identity. Once mutual trust is established, the ECDH protocol allows both parties to arrive at the same mutually derived shared key independently. This eliminates the risk of a 'man-in-the-middle' intercepting the raw network key K during the provisioning process.

This approach differs from prior methods that relied on pre-shared keys (PSKs) burned into physical SIM cards at the factory or encrypted files protected by static passwords. By using dynamic key derivation and hardware-specific certificates, the invention allows modules to be hermetically sealed and deployed globally while retaining the ability to securely switch between different mobile network operators. This provides a scalable architecture for the Internet of Things where physical access to devices is often impossible or cost-prohibitive.

How does this patent fit in bigger picture?

Technical Landscape

In the late 2010s when ’206 was filed, machine-to-machine (M2M) and Internet of Things (IoT) communications were typically implemented using wireless wide area networks that commonly relied on physical Subscriber Identity Module (SIM) cards for network authentication. At a time when hardware constraints made the manual replacement of these physical cards non-trivial—particularly for devices deployed in remote or hermetically sealed environments—the industry was transitioning toward virtualized connectivity management. System architectures during this era were beginning to incorporate embedded Universal Integrated Circuit Cards (eUICC) to allow for the electronic distribution of network profiles, yet these systems often faced engineering constraints regarding the secure transfer of pre-shared secret keys over potentially insecure or third-party communication channels.

Prosecution Position

The disclosed invention addresses the technical problem of securely updating network access credentials without the risks associated with transmitting pre-shared secret keys over a network. The architectural solution involves an integration of Public Key Infrastructure (PKI) algorithms directly within the module and the mobile network operator’s server to mutually derive a new secret shared network key. By utilizing a key derivation function that processes a module-generated private key and a network-provided token, the system enables a meaningful technical advancement where a second, unique authentication key is established without ever being transmitted in the clear or in an encrypted form. This capability enables periodic key rotation and enhanced security for M2M devices while maintaining full compatibility with legacy wireless authentication protocols, effectively overcoming the constraint of physical media dependency for credential management.

Claims

The patent contains a total of 13 claims, with claim 1 serving as the sole independent claim. This independent claim focuses on a method for the secure distribution of a wireless network profile from a subscription manager to a module, utilizing elliptic curve cryptography, digital signatures, and symmetric encryption to establish a mutually derived shared key for profile protection. The dependent claims serve to further specify technical parameters such as the use of specific elliptic curve standards, the timing of key generation and transmission, the inclusion of particular network access credentials like international mobile subscriber identities, and the hardware implementation within embedded universal integrated circuit cards.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Mutually derived shared key
(Claim 1)
The module can use a shared secret algorithm in order to derive a shared secret key without sending or receiving the shared secret key. A server could record the same component parameters, the same shared secret algorithm, and also receive the algorithm token from the module. The module and the server can then use the same shared secret key as a symmetric key for symmetric ciphering algorithms.A symmetric key generated independently by both the module and the subscription manager using Elliptic Curve Diffie-Hellman (ECDH) without the key itself being transmitted over the network.
Network access credentials
(Claim 1)
The profile can include data for appropriate network access credentials and also network parameters for connecting a module with a wireless network. Many open and remaining challenges for a eUICC pertain to securely and electronically transferring a new set of MNO network access credentials (such as an IMSI and network key K) to a module. The credentials in a eUICC are fully compatible with the legacy base of networks that use a pre-shared secret key K.The specific identity and security data, such as an IMSI and a pre-shared secret key K, used by a module to authenticate its subscription with a mobile network operator.
Network private key
(Claim 1)
The subscription manager system generates a network private key and a corresponding network public key using a key pair generation algorithm. The mutually derived shared key is based on the module public key and the network private key. This allows for the derivation of a shared secret key using public keys, private keys, and tokens.A temporary or session-based elliptic curve private key generated by the subscription manager to facilitate the derivation of a shared secret key with a specific module.
Profile
(Claim 1)
The profile can include data for (i) appropriate network access credentials and also (ii) network parameters for connecting a module with a wireless network associated with a mobile operator network. The profile for an eUICC can include the equivalent data that is recorded in a physical UICC, such that the eUICC operating with an activated eUICC profile can provide functionality to a module that is equivalent to a physical UICC. The module can receive eUICC profiles from an eUICC subscription manager.A set of data and parameters for an eUICC that includes network access credentials and network parameters required for a module to connect with and authenticate to a specific wireless network.
Subscription manager system
(Claim 1)
The module can receive eUICC profiles from an eUICC subscription manager. The module manufacturer, distributor, mobile network operator, and/or module provider could operate as an eUICC subscription manager. An eUICC subscription manager could also provide the initial module private key.A server-side entity, often operated by a module manufacturer, distributor, or mobile network operator, that manages and securely distributes eUICC profiles to modules.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-00667Jun 27, 2025Network-1 Technologies, Inc. v. SAMSUNG ELECTRONICS CO., LTD. et al

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US10187206

Application Number
US15680758A
Filing Date
Aug 18, 2017
Publication Date
Jan 22, 2019
External Links
Slate, USPTO , Google Patents