Key derivation for a module using an embedded universal integrated circuit card

Patent No. US9319223 (titled "Key derivation for a module using an embedded universal integrated circuit card") on Nov 19, 2013. The application was issued on Apr 19, 2016.

What is this patent about?

’223 is related to the field of secure machine-to-machine (M2M) communications and the remote management of cellular credentials. Specifically, it addresses the technical challenges of securely provisioning and updating network access credentials, such as the shared secret key K, within an embedded universal integrated circuit card (eUICC) without requiring physical SIM card swaps or relying on insecure electronic distribution channels.

The underlying idea behind ’223 is to enable a wireless module to internally derive its own cryptographic keys and network credentials rather than receiving them in plaintext or simple encrypted files. By utilizing a key derivation function (KDF) and shared secret algorithms that incorporate unique hardware component parameters and dynamic tokens, the module and a subscription manager can mutually arrive at the same secret keys. This ensures that sensitive data like the network key K is never actually transmitted over the air, even in encrypted form, thereby eliminating a major point of vulnerability.

The claims of ’223 focus on a multi-stage derivation process where a module uses an eUICC to establish secure communication with a subscription manager. The process involves authenticating the manager using a network public key, receiving a token, and deriving a module-specific PKI key pair. These elements are then fed into a KDF to produce a first shared secret, which subsequently acts as a high-entropy input for a shared secret algorithm (utilizing a secure hash) to derive a second shared secret key. This final key is specifically used by the eUICC to decrypt a downloaded profile containing new network access credentials.

In practice, the invention allows a module to bootstrap its security using an initial, potentially low-security profile or a protected hardware identity to authenticate with a subscription manager. Once authenticated, the module generates a derived module private key and uses it to participate in a secure handshake. This handshake results in a mutually derived shared secret that is unique to that specific piece of hardware and the current session. The module then uses this secret to unlock a second, more permanent eUICC profile that contains the actual IMSI and key K needed for full cellular service.

This approach differs from prior solutions by moving the point of credential generation from the server to the device itself. Traditional eUICC provisioning relies on the server encrypting a pre-generated key K and sending it to the module, which leaves the key vulnerable to any compromise in the transport-layer encryption. By contrast, ’223 ensures the secret shared network key K is derived locally within the secure environment of the eUICC, maintaining full compatibility with legacy LTE and 3GPP infrastructure while significantly hardening the provisioning process against interception.

How does this patent fit in bigger picture?

Technical Landscape

In the early 2010s when ’223 was filed, machine-to-machine (M2M) communications were increasingly leveraging wireless wide-area networks at a time when system architectures were typically implemented using physical Subscriber Identity Module (SIM) cards or Universal Integrated Circuit Cards (UICC). When systems commonly relied on these physical media to store pre-shared secret keys for network authentication, hardware constraints made the remote management or rotation of network credentials non-trivial. Engineering practices of this era required manual intervention to swap physical cards when changing network operators or updating security protocols, creating significant scalability and maintenance challenges for devices deployed in remote or hermetically sealed environments.

Prosecution Position

The disclosed invention represents a meaningful technical advancement by integrating an embedded Universal Integrated Circuit Card (eUICC) architecture that enables the secure, autonomous derivation of network access credentials. This architectural shift allows a module to generate its own public-private key pairs and derive a secret shared network key (Key K) locally using a key derivation function and cryptographic parameters received over-the-air. This capability enables the module to transition from an initial pre-shared key to a mutually derived second key without the electronic transmission of the secret key itself, thereby overcoming the technical constraint of relying on vulnerable communication channels for credential distribution. The technical effect achieved is a more resilient security model that supports periodic key rotation and seamless network migration without physical hardware replacement or the risks associated with third-party key handling.

Claims

The patent contains a total of 20 claims, with claims 1, 9, and 15 serving as the independent claims. These independent claims focus on methods for a module to manage embedded universal integrated circuit card (eUICC) profiles and secure data transmission, specifically through the derivation of shared secret keys using cryptographic parameters, tokens, and hash algorithms to decrypt profiles and authenticate with wireless networks. The dependent claims serve to further define these processes by specifying the use of particular encryption algorithms like elliptic curve cryptography, detailing the steps for network authentication using specific identity and key parameters, and outlining the integration of sensor measurements and digital signatures within the secure communication framework.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Embedded universal integrated circuit card (eUICC)
(Claim 1, Claim 9, Claim 15)
With an eUICC, the operation of an UICC can be essentially “virtualized”, such that the data and algorithms within a UICC can be processed in software and distributed through electronic media. The profile for an eUICC can include the equivalent data that is recorded in a physical UICC, such that the eUICC operating with an activated eUICC profile can provide functionality to a module that is equivalent to a physical UICC. This allows a module to change network access credentials without requiring a physical replacement of a UICC or equivalent physical media.A virtualized or software-based version of a subscriber identity module (SIM) that allows for the electronic distribution and management of network access credentials and profiles without requiring physical replacement of the hardware.
EUICC profile
(Claim 1, Claim 9, Claim 15)
The profile can include data for (i) appropriate network access credentials and also (ii) network parameters for connecting a module with a wireless network associated with a mobile operator network. The profile for an eUICC can include the equivalent data that is recorded in a physical UICC. The module can receive a eUICC profile for an eUICC in the module, where the eUICC profile includes a network module identity and a first key K.A digital file or set of data containing network access credentials (such as IMSI and key K) and network parameters required for a module to connect to a specific mobile network operator.
EUICC subscription manager
(Claim 1, Claim 9, Claim 15)
The module can receive eUICC profiles from an eUICC subscription manager. The module can use the module identity to identify the module with the eUICC subscription manager and also an initial private key to authenticate and/or cipher data. The module manufacturer, distributor, mobile network operator, and/or module provider could operate as an eUICC subscription manager.A server-side entity or system responsible for providing, authenticating, and managing eUICC profiles and cryptographic parameters for modules over a network.
Key K
(Claim 9)
The pre-shared secret key K is also known as key K in 4G LTE and related networks and key Ki in 3G networks. It serves as the foundation for authentication and ciphering of data for a mobile phone or user equipment. The module can use the eUICC, the network module identity, and the first key K to authenticate with the wireless network.A pre-shared secret key used as the foundation for authentication and ciphering of data between a module and a wireless network, equivalent to the key K in 4G LTE or Ki in 3G networks.
Shared secret algorithm
(Claim 1, Claim 9, Claim 15)
The module can use a shared secret algorithm in order to derive a shared secret key without sending or receiving the shared secret key. A set of component parameters and an algorithm token can also be input into the shared secret algorithm. The server can derive the same shared secret key as the module by recording the same component parameters and receiving the algorithm token.A cryptographic process, often utilizing a secure hash algorithm and component parameters, used by both the module and a server to mutually derive identical secret keys without transmitting the keys themselves.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-00667Jun 27, 2025Network-1 Technologies, Inc. v. SAMSUNG ELECTRONICS CO., LTD. et al

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US9319223

Application Number
US14084141A
Filing Date
Nov 19, 2013
Publication Date
Apr 19, 2016
External Links
Slate, USPTO , Google Patents