IP Library Granted Patent US 12,166,869
Granted Patent B2
US 12,166,869 · App. 18/229,907 · Granted Dec 10, 2024

Key derivation for a module using an embedded universal integrated circuit card

Inventor: John A. Nix (Evanston, IL)
Assignee: Network-1 Technologies, Inc.
H04L9/0861G06F21/33G06F21/35H04J11/00H04L9/006H04L9/0662H04L9/0816H04L9/0841H04L9/0844H04L9/085H04L9/088H04L9/0891H04L9/0894H04L9/14H04L9/30H04L9/3066H04L9/32H04L9/321H04L9/3239H04L9/3247H04L9/3249H04L9/3263H04L12/2854H04L63/0272H04L63/0435H04L63/0442H04L63/045H04L63/06H04L63/061H04L63/0807H04L63/123H04L63/166H04L67/04H04W4/70H04W8/082H04W12/02H04W12/03H04W12/04H04W12/041H04W12/06H04W40/005H04W52/0216H04W52/0235H04W52/0277H04W76/27H04W80/04G06F2221/2105G06F2221/2107G06F2221/2115H04L63/0464H04L2209/24H04L2209/56H04L2209/72H04L2209/80H04L2209/805H04W84/12H04W88/12Y02D30/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,166,869
App. No.
18/229,907
Granted
Dec 10, 2024
Kind
B2
Abstract

A module with an embedded universal integrated circuit card (eUICC) can include a received eUICC profile and a set of cryptographic algorithms. The received eUICC profile can include an initial shared secret key for authentication with a wireless network. The module can receive a key K network token and send a key K module token to the wireless network. The module can use the key K network token, a derived module private key, and a key derivation function to derive a secret shared network key K that supports communication with the wireless network. The wireless network can use the received key K module token, a network private key, and the key derivation function in order to derive the same secret shared network key K derived by the module. The module and the wireless network can subsequently use the mutually derived key K to communicate using traditional wireless network standards.

Claims (29)

1. A method for a mobile device with an embedded universal integrated circuit card (eUICC) to securely communicate with a wireless network, the method performed by the mobile device, the method comprising:

a) storing, in the eUICC, a first module private key, a corresponding first module public key, and a network public key;

b) receiving, from a first server associated with the wireless network, an encrypted profile for the eUICC comprising cryptographic parameters, a module identity, and a key K;

c) generating a shared secret key using a first elliptic curve Diffie-Hellman (ECDH) key exchange with the first module private key and the network public key;

d) decrypting, with the shared secret key, at least a portion of the encrypted profile for the eUICC;

e) generating, by the eUICC, a second module public key and a corresponding second module private key;

f) sending, to a second server associated with the wireless network, the second module public key;

g) generating a symmetric key using a second ECDH key exchange with the second module private key and the cryptographic parameters;

h) generating, with the symmetric key, module encrypted data, the module encrypted data comprising the module identity; and

i) sending, to the second server, the module encrypted data.

2. The method of claim 1 , wherein the module identity comprises an international mobile subscriber identity (IMSI).

3. The method of claim 1 , wherein the module identity comprises a permanent identifier for the mobile device.

4. The method of claim 1 , wherein the cryptographic parameters comprise an identifier for a set of cryptographic parameters.

5. The method of claim 1 , further comprising in step c) deriving the shared secret key using an American National Standards Institute (ANSI) standard X-9.63 key derivation function.

6. The method of claim 1 , further comprising in step g) deriving the symmetric key using an ANSI standard X-9.63 key derivation function.

7. The method of claim 1 , wherein the first server mutually derives the shared secret key using the first ECDH key exchange with the first module public key and a network private key corresponding to the network public key.

8. The method of claim 1 , further comprising in step e), generating, by the eUICC, the second module public key and the second module private key using a random number generator and input from a sensor.

9. The method of claim 1 , further comprising in step h) generating, with the symmetric key and an Advanced Encryption Standard (AES), the module encrypted data.

10. The method of claim 1 , wherein steps g) and h) occur before step f).

11. The method of claim 1 , wherein the network public key is associated with an eUICC subscription manager.

12. The method of claim 11 , wherein the eUICC subscription manager comprises the first server.

13. The method of claim 1 , further comprising: j) receiving, from the wireless network, a random number (RAND) and generating a response (RES) using the RAND and the key K.

14. The method of claim 1 , further comprising before step b), authenticating the first server by (i) receiving a server digital signature and (ii) verifying the server digital signature with a server public key.

15. The method of claim 1 , further comprising (i) in step a), storing a server name for the first server and a port number in a nonvolatile memory of the eUICC, and (ii) before step b) sending the first module public key to the first server.

16. The method of claim 1 , wherein the first server, the second server, and the wireless network are associated with a mobile network operator.

17. The method of claim 1 , wherein the eUICC comprises a processor, firmware, and protected memory.

18. The method of claim 1 , wherein the cryptographic parameters include a base point G for an elliptic curve.

19. The method of claim 1 , wherein the mobile device comprises a wireless device with a radio for communicating with a plurality of base stations for the wireless network.

20. The method of claim 1 , wherein the eUICC comprises a package soldered to a circuit board of the mobile device.

Assignments (4)
CHANGE OF ADDRESS Recorded Sep 10, 2025
From: NETWORK-1 TECHNOLOGIES, INC.
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 072827/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2023
From: M2M AND IOT TECHNOLOGIES, LLC
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 065466/0055 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2023
From: VOBAL TECHNOLOGIES, LLC
To: NIX, JOHN A.
Reel/Frame 065456/0427 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2023
From: NIX, JOHN
To: M2M AND IOT TECHNOLOGIES, LLC
Reel/Frame 065431/0719 →
Continuity (7)
Continuation 17304922 · Jun 28, 2021
Continuation 16879325 · May 20, 2020
Continuation 16201401 · Nov 27, 2018
Continuation 15680758 · Aug 18, 2017
Continuation 15130146 · Apr 15, 2016
Continuation 14084141 · Nov 19, 2013
Related Publication 20230379148A1 · Nov 23, 2023
Cited By (1)
US 12,683,772