EP3547643B1

Methods and apparatus for establishing a secure communication channel

Abstract

This record has no abstract on file.

EP3547643B1, drawing sheet 1
Sheet 1 of 7

Term

8.8 yearsleft in the term

Expires 1 July 2035.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

15 claims: 3 independent, 12 dependent

  1. 1
    A wireless device (106) comprising:one or more antennas;an embedded Universal Integrated Circuit Card (120, 320), eUICC, communicatively coupled to the one or more antennas, the eUICC comprising a processor and a memory communicatively coupled to the processor and storing instructions that, when executed by the processor, cause the eUICC to perform operations comprising: providing, to a server via the wireless device, a request to establish a secure connection with the server, wherein the server is associated with a long-term server public key, PK server , provided by the server to the wireless device, and a long-term server private key, SK server , providing to the server via the wireless device: i) a signature produced using a long-term eUICC public key, PK eUICC , and ii) PK eUICC , authenticating (460) the server using PK server , generating (514), subsequent to the authenticating, an ephemeral eUICC public key, ePK eUICC , and an ephemeral eUICC private key, eSK eUICC , providing (518), to the server via the wireless device, a signed ePK eUICC that is signed (516) using a long-term eUICC private key, SK eUICC , receiving, from the server via the wireless device, an ephemeral server public key, ePK server , that is signed using using SK server , generating (520) a shared symmetric key using eSK eUICC and ePK server , and establishing (475) the secure connection with the server using the shared symmetric key.
  2. 9
    A method performed by an embedded Universal Integrated Circuit Card (120, 320), eUICC, of a wireless device (106), the method comprising:by the eUICC: providing, to a server via the wireless device, a request to establish a secure connection with the server, wherein the server is associated with a long-term server public key, PK server , provided by the server to the wireless device, and a long-term server private key, SK server , providing to the server via the wireless device: i) a signature produced using a long-term eUICC public key, PK eUICC , and ii) PK eUICC , authenticating (460) the server using PK server , generating (514), subsequent to the authenticating, an ephemeral eUICC public key, ePK eUICC , and an ephemeral eUICC private key, eSK eUICC , providing (518), to the server via the wireless device, a signed ePK eUICC that is signed (516) using a long-term eUICC private key, SK eUICC , receiving, from the server via the wireless device, an ephemeral server public key, ePK server , that is signed using using SK server , generating (520) a shared symmetric key using eSK eUICC and ePK server , and establishing (475) the secure connection with the server using the shared symmetric key.
  3. 14
    A non-transitory computer-readable medium storing instructions that, when executed by a processor of an embedded Universal Integrated Circuit Card, eUICC (120, 320), of a wireless device (106), cause the eUICC to perform operations comprising:providing, to a server via the wireless device, a request to establish a secure connection with the server, wherein the server is associated with a long-term server public key, PK server , provided by the server to the wireless device, and a long-term server private key, SK server , providing to the server via the wireless device: i) a signature produced using a long-term eUICC public key, PK eUICC , and ii) PK eUICC , authenticating (460) the server using PK server , generating (514), subsequent to the authenticating, an ephemeral eUICC public key, ePK eUICC , and an ephemeral eUICC private key, eSK eUICC , providing (518), to the server via the wireless device, a signed ePK eUICC that is signed (516) using a long-term eUCC private key, SK eUICC , receiving, from the server via the wireless device, an ephemeral server public key, ePK server , that is signed using SK server , generating (520) a shared symmetric key using eSK eUICC and ePK server , and establishing (475) the secure connection with the server using the shared symmetric key.