Patent No. US10187206 (titled "Key derivation for a module using an embedded universal integrated circuit card") on Aug 18, 2017. The application was issued on Jan 22, 2019.
’206 is related to the field of secure machine-to-machine (M2M) communications and the remote management of network credentials. Specifically, it addresses the technical challenges of securely provisioning an embedded universal integrated circuit card (eUICC) with a profile containing network access credentials without relying on the physical distribution of SIM cards or the insecure electronic transmission of pre-shared secret keys.
The underlying idea behind ’206 is to leverage public key infrastructure (PKI) and elliptic curve cryptography to mutually derive a shared secret key between a module and a subscription manager. Instead of transmitting a sensitive network key over the air, the system uses an Elliptic Curve Diffie-Hellman (ECDH) exchange to establish a secure session key. This derived key is then used to encrypt the entire eUICC profile, ensuring that only the specific hardware module possessing the corresponding private key can access the network credentials.
The claims of ’206 focus on a method for a subscription manager to securely distribute a profile by utilizing a combination of asymmetric and symmetric cryptography. The process involves receiving a module's certificate from a provider, responding to a hardware challenge with an elliptic curve digital signature, and generating a temporary network key pair. The subscription manager then derives a shared secret using the module's public key and its own network private key, which serves as the encryption key for an AES-128 encrypted payload containing the network access credentials.
In practice, the module and the subscription manager system interact to verify each other's identities before any sensitive data is exchanged. The subscription manager uses its server private key to sign the challenge received from the module, providing authoritative proof of its identity. Once mutual trust is established, the ECDH protocol allows both parties to arrive at the same mutually derived shared key independently. This eliminates the risk of a 'man-in-the-middle' intercepting the raw network key K during the provisioning process.
This approach differs from prior methods that relied on pre-shared keys (PSKs) burned into physical SIM cards at the factory or encrypted files protected by static passwords. By using dynamic key derivation and hardware-specific certificates, the invention allows modules to be hermetically sealed and deployed globally while retaining the ability to securely switch between different mobile network operators. This provides a scalable architecture for the Internet of Things where physical access to devices is often impossible or cost-prohibitive.
In the late 2010s when ’206 was filed, machine-to-machine (M2M) and Internet of Things (IoT) communications were typically implemented using wireless wide area networks that commonly relied on physical Subscriber Identity Module (SIM) cards for network authentication. At a time when hardware constraints made the manual replacement of these physical cards non-trivial—particularly for devices deployed in remote or hermetically sealed environments—the industry was transitioning toward virtualized connectivity management. System architectures during this era were beginning to incorporate embedded Universal Integrated Circuit Cards (eUICC) to allow for the electronic distribution of network profiles, yet these systems often faced engineering constraints regarding the secure transfer of pre-shared secret keys over potentially insecure or third-party communication channels.
The disclosed invention addresses the technical problem of securely updating network access credentials without the risks associated with transmitting pre-shared secret keys over a network. The architectural solution involves an integration of Public Key Infrastructure (PKI) algorithms directly within the module and the mobile network operator’s server to mutually derive a new secret shared network key. By utilizing a key derivation function that processes a module-generated private key and a network-provided token, the system enables a meaningful technical advancement where a second, unique authentication key is established without ever being transmitted in the clear or in an encrypted form. This capability enables periodic key rotation and enhanced security for M2M devices while maintaining full compatibility with legacy wireless authentication protocols, effectively overcoming the constraint of physical media dependency for credential management.
The patent contains a total of 13 claims, with claim 1 serving as the sole independent claim. This independent claim focuses on a method for the secure distribution of a wireless network profile from a subscription manager to a module, utilizing elliptic curve cryptography, digital signatures, and symmetric encryption to establish a mutually derived shared key for profile protection. The dependent claims serve to further specify technical parameters such as the use of specific elliptic curve standards, the timing of key generation and transmission, the inclusion of particular network access credentials like international mobile subscriber identities, and the hardware implementation within embedded universal integrated circuit cards.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents