Patent No. US9319223 (titled "Key derivation for a module using an embedded universal integrated circuit card") on Nov 19, 2013. The application was issued on Apr 19, 2016.
’223 is related to the field of secure machine-to-machine (M2M) communications and the remote management of cellular credentials. Specifically, it addresses the technical challenges of securely provisioning and updating network access credentials, such as the shared secret key K, within an embedded universal integrated circuit card (eUICC) without requiring physical SIM card swaps or relying on insecure electronic distribution channels.
The underlying idea behind ’223 is to enable a wireless module to internally derive its own cryptographic keys and network credentials rather than receiving them in plaintext or simple encrypted files. By utilizing a key derivation function (KDF) and shared secret algorithms that incorporate unique hardware component parameters and dynamic tokens, the module and a subscription manager can mutually arrive at the same secret keys. This ensures that sensitive data like the network key K is never actually transmitted over the air, even in encrypted form, thereby eliminating a major point of vulnerability.
The claims of ’223 focus on a multi-stage derivation process where a module uses an eUICC to establish secure communication with a subscription manager. The process involves authenticating the manager using a network public key, receiving a token, and deriving a module-specific PKI key pair. These elements are then fed into a KDF to produce a first shared secret, which subsequently acts as a high-entropy input for a shared secret algorithm (utilizing a secure hash) to derive a second shared secret key. This final key is specifically used by the eUICC to decrypt a downloaded profile containing new network access credentials.
In practice, the invention allows a module to bootstrap its security using an initial, potentially low-security profile or a protected hardware identity to authenticate with a subscription manager. Once authenticated, the module generates a derived module private key and uses it to participate in a secure handshake. This handshake results in a mutually derived shared secret that is unique to that specific piece of hardware and the current session. The module then uses this secret to unlock a second, more permanent eUICC profile that contains the actual IMSI and key K needed for full cellular service.
This approach differs from prior solutions by moving the point of credential generation from the server to the device itself. Traditional eUICC provisioning relies on the server encrypting a pre-generated key K and sending it to the module, which leaves the key vulnerable to any compromise in the transport-layer encryption. By contrast, ’223 ensures the secret shared network key K is derived locally within the secure environment of the eUICC, maintaining full compatibility with legacy LTE and 3GPP infrastructure while significantly hardening the provisioning process against interception.
In the early 2010s when ’223 was filed, machine-to-machine (M2M) communications were increasingly leveraging wireless wide-area networks at a time when system architectures were typically implemented using physical Subscriber Identity Module (SIM) cards or Universal Integrated Circuit Cards (UICC). When systems commonly relied on these physical media to store pre-shared secret keys for network authentication, hardware constraints made the remote management or rotation of network credentials non-trivial. Engineering practices of this era required manual intervention to swap physical cards when changing network operators or updating security protocols, creating significant scalability and maintenance challenges for devices deployed in remote or hermetically sealed environments.
The disclosed invention represents a meaningful technical advancement by integrating an embedded Universal Integrated Circuit Card (eUICC) architecture that enables the secure, autonomous derivation of network access credentials. This architectural shift allows a module to generate its own public-private key pairs and derive a secret shared network key (Key K) locally using a key derivation function and cryptographic parameters received over-the-air. This capability enables the module to transition from an initial pre-shared key to a mutually derived second key without the electronic transmission of the secret key itself, thereby overcoming the technical constraint of relying on vulnerable communication channels for credential distribution. The technical effect achieved is a more resilient security model that supports periodic key rotation and seamless network migration without physical hardware replacement or the risks associated with third-party key handling.
The patent contains a total of 20 claims, with claims 1, 9, and 15 serving as the independent claims. These independent claims focus on methods for a module to manage embedded universal integrated circuit card (eUICC) profiles and secure data transmission, specifically through the derivation of shared secret keys using cryptographic parameters, tokens, and hash algorithms to decrypt profiles and authenticate with wireless networks. The dependent claims serve to further define these processes by specifying the use of particular encryption algorithms like elliptic curve cryptography, detailing the steps for network authentication using specific identity and key parameters, and outlining the integration of sensor measurements and digital signatures within the secure communication framework.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents