IP Library Granted Patent US 10,084,768
Granted Patent B2
US 10,084,768 · App. 15/928,848 · Granted Sep 25, 2018

Embedded universal integrated circuit card supporting two-factor authentication

Inventor: John A. Nix (Evanston, IL)
Assignee: Network-1 Technologies, Inc.
H04L63/08H04B1/3816H04L9/0819H04L9/0869H04L9/3271H04L63/0428H04L63/0435H04L63/06H04L63/062H04L63/101H04W4/70H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,084,768
App. No.
15/928,848
Granted
Sep 25, 2018
Kind
B2
Abstract

A module with an embedded universal integrated circuit card (eUICC) can include a profile for the eUICC. The profile can include a first and second shared secret key K for authenticating with a wireless network. The first shared secret key K can be encrypted with a first key, and the second shared secret key K can be encrypted with a second key. The module can (i) receive the first key, (ii) decrypt the first shared secret key K with the first key, and (iii) subsequently authenticate with the wireless network using the plaintext first shared secret key K. The wireless network can authenticate the user of the module using a second factor. The module can then (i) receive the second key, (ii) decrypt the second shared secret key K, and (iii) authenticate with the wireless network using the second shared secret key K. The module can comprise a mobile phone.

Claims (27)

1. A method for a module comprising a network application and an embedded universal integrated circuit card to receive a profile for use with the embedded universal integrated circuit card, the method comprising:

(a) sending, from the module via the network application to a subscription manager system, a first message comprising:

(i) an identity for the embedded universal integrated circuit card;

(ii) a nonce; and

(iii) a first digital signature, generated using a first eUICC private key, wherein the first eUICC private key corresponds to a first eUICC public key;

(b) deriving a second eUICC private key and a corresponding second eUICC public key using a first random number generator and a first set of cryptographic algorithms;

(c) recording, by the module, a subscription manager public key which corresponds to a subscription manager private key;

(d) deriving, by the module, a profile key using a key exchange algorithm based on at least:

(i) the second eUICC private key, and

(ii) the recorded subscription manager public key,

wherein the profile key can also be derived at the subscription manager system based at least on:

(i) the second eUICC public key, and

(ii) the subscription manager private key;

(e) receiving, at the module by the network application, an encrypted profile comprising a ciphertext including a key K encrypted with a symmetric key;

(f) receiving at the module for use by the embedded universal integrated circuit card, the symmetric key;

(g) decrypting, by the embedded universal integrated circuit card, the ciphertext using the symmetric key;

(h) decrypting, by the embedded universal integrated circuit card, the encrypted profile using the profile key; and

(i) recording, by the embedded universal integrated circuit card, the decrypted profile for use in future communications.

2. The method of claim 1 , wherein the subscription manager public key is downloaded.

3. The method of claim 1 , wherein the subscription manager public key was recorded at the time of manufacture of the module.

4. The method of claim 1 , wherein the key exchange algorithm is a Diffie-Hellman key exchange.

5. The method of claim 1 , wherein the key exchange algorithm is an Elliptic Curve Diffie-Hellman key exchange.

6. The method of claim 1 , wherein the encrypted profile is encrypted in a manner so that intermediate nodes on an IP network would not be able to read data within the profile in an unencrypted form.

7. The method of claim 1 , wherein the encrypted profile is encrypted with an eUICC profile key.

8. The method of claim 1 , wherein after the step 1(a), the module is authenticated by the subscription manager system using at least the identity of the embedded universal integrated circuit card included in the first message.

9. The method of claim 1 , wherein after the step 1(a), the module is authenticated by the subscription manager system using at least the digital signature included in the first message.

10. The method of claim 1 , wherein the decrypted profile is recorded in a nonvolatile memory of the module.

Assignments (4)
CHANGE OF ADDRESS Recorded Sep 10, 2025
From: NETWORK-1 TECHNOLOGIES, INC.
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 072827/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2018
From: M2M AND IOT TECHNOLOGIES, LLC
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 046551/0630 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2018
From: VOBAL TECHNOLOGIES, LLC
To: JOHN A. NIX
Reel/Frame 046515/0799 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2018
From: NIX, JOHN
To: M2M AND IOT TECHNOLOGIES, LLC
Reel/Frame 046497/0428 →
Continuity (3)
Continuation 14751119 · Jun 25, 2015
Continuation 14099329 · Dec 6, 2013
Related Publication 20180212946A1 · Jul 26, 2018