Method for setting up a user device, as well as the same, together with a computer program, a computer-readable data carrier and a device for setting it up
The method improves secure element interactions in user devices by authorizing and managing links with device assemblies using a command data set, ensuring secure and reliable communication through restricted operating modes and authentication, addressing the association challenges in existing technologies.
Patent Information
- Application Number
- DE102024108995
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-03-28
- Publication Date
- 2025-08-14
- Estimated Expiration
- 2044-03-28
AI Technical Summary
Existing methods fail to ensure a secure and functionally reliable interaction between embedded secure elements, such as eUICCs, and user devices, particularly in mobile user devices, due to the inability to satisfactorily associate these elements with specific user devices based on their external features.
A method and system for setting up user devices with secure elements, involving a command data set to check and authorize the link between the device assembly and the secure element, allowing only authorized interactions and enabling a restricted operating mode if the link is not authorized, using security keys and authentication protocols.
This approach enhances the security and reliability of interactions between device assemblies and secure elements by preventing unsafe or uncertain communications, ensuring secure and functional reliability by authorizing and managing the link according to predefined conditions.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Field of the invention
[0001] The present invention relates to linking embedded secure elements with device assemblies of user devices. The embedded secure element can, in particular, be an embedded universal integrated circuit card (eUICC). In particular, the invention relates to a method for setting up a user device, for example a mobile user device for participation in a telecommunications network, comprising a device assembly on which a secure element, in particular an eUICC, is installed, a computer program, a computer-readable data carrier, a user device, in particular a mobile user device for participation in a communications network, and a device arrangement for setting up user devices. Background of the invention
[0002] Methods for handling embedded secure elements, such as eUICCs, as well as computer programs, computer-readable data carriers, user devices for participation in communication networks, and communication networks are known from the state of the art. For example, on eUICCs, for example on mobile user devices such as mobile phones, smartphones, tablets, or similar, identification features of users of the user devices are managed. On an eUICC, this usually takes place in the form of corresponding embedded Subscriber Identity Modules (eSIM). This procedure is necessary to meet the security requirements for managing the identification features. This requires a trusted party, which can be provided on eUICCs and / or servers, such aseSIM download servers, from which eUICC data sets can be obtained or managed as trusted subscription manager data preparation platforms (SM-DP+) in compliance with the respective security requirements.
[0003] Secure elements typically have a system structure with an operating system so they can interact with the device modules of the end devices on which they are implemented. The operating system can access memory areas, usually non-volatile memory, of secure elements, and handle, manage, and query information stored there, such as identification features. For example, this is done using data elements of corresponding application protocols (Application Protocol Data Units - APDUs), which transmit unidirectional commands to secure elements via a connection interface, which are then executed by them.
[0004] EP 4 113 342 A1 relates to a method, a data structure, and an update agent for implementing a scheme for downloading an operating system image to a secure element. The update agent receives an installation package from an external device for installing an operating system on the secure element. The update agent requests control of the secure element and loads the operating system received with the installation package into the secure element, whereupon control of the secure element is transferred to the operating system.
[0005] EP 2 862 340 B1 relates to a mobile station comprising a terminal device and a removable or permanently implemented security element operable in the terminal device. A binding is established between the terminal device and the security element and is verifiable using a secret key and the verification key. The terminal device comprises a secure runtime environment, and the verification key is stored in the secure runtime environment.
[0006] From US 2020 / 0 382 957 A1 a method is known for establishing a secure connection between a secure element of a user device and a node in a network by means of exchanging and verifying tokens.
[0007] Originally, identity modules for mobile user devices, known as subscriber identity cards (SIM cards), were mechanically interchangeable or transferable from one user device to another, as long as the respective form factor of the SIM card allowed. By embedding SIM cards as eSIMs on eUICCs, these cards can no longer be assigned to a user and / or a telecommunications service provider based on their external characteristics and can therefore no longer be inserted into a specific, designated user device to enable their full functionality. The aforementioned processes, computer programs, computer-readable data storage devices, user devices, and communication networks do not allow for a satisfactory assignment between the secure element and the terminal device. Description
[0008] The object of the present invention is to improve the interaction between secure elements and user devices. In particular, the object of the present invention is to ensure a secure and functionally reliable interaction between secure elements and user devices. Furthermore, the object of the present invention is to enable a specific assignment of secure elements to specific intended user devices.
[0009] This object is achieved by the subject matter of the independent claims. Exemplary embodiments emerge from the dependent claims and the following description. Features described herein with reference to methods, as well as corresponding method steps, can be implemented as device features, or vice versa. Sections of the description related to the method also apply analogously to computer programs, computer-readable data carriers, user devices for participating in communication networks, and communication networks.In particular, method steps and related components mentioned can be implemented as functions of the computer programs, computer-readable data carriers, user devices for participation in communication networks and communication networks and any functions of the computer programs, computer-readable data carriers, user devices for participation in communication networks and communication networks can be implemented as method steps.
[0010] A method is described for setting up a user device, for example a mobile user device for participation in a telecommunications network, with a device assembly on which a secure element, in particular an eUICC, is installed, comprising the following steps: - Specifying a command data set containing operating commands for the user device; - Verifying a link between the device assembly and the safe element; and - Refuse at least one of the operating commands if the verification shows that no authorized link exists.
[0011] A user device, in particular a mobile terminal for participation in a communication network, comprises a corresponding computer program stored thereon, a corresponding computer-readable data carrier and / or is configured to execute a corresponding method.
[0012] A computer program comprises instructions which, when executed by a user device, cause the program to perform a corresponding procedure.
[0013] A computer-readable data carrier includes a corresponding computer program stored thereon.
[0014] A device arrangement for setting up user devices comprises a corresponding computer program stored therein, a corresponding computer-readable data carrier and / or is configured to carry out a corresponding method.
[0015] A device assembly and / or a secure element can comprise a corresponding computer program stored thereon and / or a corresponding computer-readable data carrier and / or be configured to execute a corresponding method. The device arrangement can comprise at least one computing device, such as a computer, server, or the like, which is configured to interact with user devices, device assemblies and / or secure elements. The interaction can take place, for example, via a telecommunications network. A telecommunications network comprises at least one corresponding user device and / or a server with a corresponding computer program stored thereon, a corresponding computer-readable data carrier, or the server is configured to execute a corresponding method.
[0016] The method can accordingly be carried out by a data processing device or with the aid of a computer, which can be implemented as a user device or server. A computer program can comprise instructions that, when executed by a data processing device or a computer, cause the computer to carry out the method. A computer-readable storage medium, a computer-readable data carrier, and / or a data carrier signal can store or transmit the computer program. A corresponding computer-readable data carrier can be present as a computer-readable medium and / or data carrier signal.
[0017] At least one of the operating commands of the command data set can be designed to be interchangeable between the device module and the secure element. The link can either be nonexistent or not meet specified link requirements. The device module can be linked to the secure element using a security key. The link and / or authorization of the link can be initiated from both the device module and the secure element.
[0018] The solution according to the invention has the advantage that, by denying at least one of the operating commands in the absence of an authorized link between the device module and the secure element, potentially insecure and / or functionally indeterminate communication between the device module, and thus the user device, on the one hand, and the secure element, on the other hand, can be avoided. For example, a denied command may relate to user- and / or provider-specific functions that require a properly authorized link between the device module and the secure element. This helps to improve the interaction between secure elements and user devices, in particular to design them in a secure and functionally reliable manner, and to assign secure elements to predetermined user devices.
[0019] The solution is not limited to eUICCs, but is generally suitable for so-called secure elements (SEs), which are referred to herein, for example, as integrated circuit cards. As such, secure elements include, in addition to eUICCs, for example, classic UICCs, integrated UICCs (iUICCs) and all integrated secure elements of other types, such as integrated secure elements (iSE / eSE), smart cards, subscriber identity modules, subscriber identity modules (SIMs) and / or virtual SIMs (vSIMs). What all such secure elements have in common is that user data records or eUICC data records can be stored on them, for example as telecommunications profiles or "profiles" for short, with the help of which users can authenticate themselves to communication networks, for example as subscribers in telecommunications networks.The secure elements are characterized by the fact that information stored on them, especially profiles, is particularly protected against attacks by third parties and is neither physically nor software-wise easily manipulated.
[0020] According to one embodiment, a restricted operating mode can be defined in which at least one of the operating commands in the command data set is set as non-executable and / or executable. The restricted operating mode can be activated if no authorized link exists. Thus, at least certain, for example, rudimentary, functions can be executed in the restricted operating mode. A function of the user device can be specified in the restricted operating mode according to specific requirements. This helps to further improve secure and functionally reliable interaction between device modules and secure elements.
[0021] According to one embodiment, the command data set can contain at least one command parameter with which the denial and / or approval of at least one of the operating commands can be specified. The command parameter can be used, for example, to define the restricted operating mode or the commands that can and / or cannot be executed therein and to adapt them according to the respective requirements. This helps to further improve safe and functionally reliable interaction between device modules and safe elements.
[0022] According to one embodiment, it can be provided that the link is to be authorized depending on an authorization condition. For example, the link can be technically producible on the one hand and authorized on the other hand, linked to an authorization condition. This makes it possible to link the verification of the link with a verification of the authorization beyond its technical existence. The authorization, in turn, can be carried out according to respective requirements, for example, combined with a verification of security keys, (authenticity) certificates, or the like. This also helps to further improve secure and functionally reliable interaction between device assemblies and secure elements.
[0023] According to one embodiment, it can be provided that the link is to be authorized after a predetermined number of uses of at least one operating command and / or at least one operating action of the user device, the device module, and / or the secure element. The link can be authorized after a reset of the user device, the device module, and / or the secure element to a predetermined state. For example, authorization can be required after each reset, after n-configured commands / operations (arbitrary or specific commands / operations), and / or before configured commands (e.g., special use cases can be rejected with a special error code that signals reauthentication), and / or after a certain time period.Such operating commands, operating actions, and / or operating conditions can be used as authorization conditions and / or linked to them. This helps to flexibly adapt and control a safe and functionally reliable interaction between device assemblies and safe elements according to specific requirements.
[0024] According to one embodiment, at least one of the steps of specifying, checking, and denying can be configured to be activatable and / or deactivatable. In other words, corresponding method steps can be implemented, but do not have to be activated. This further helps to flexibly adapt and control a secure and functionally reliable interaction between device assemblies and secure elements according to specific requirements. Short description of the characters Fig.1 shows a schematic view of an embodiment of a device arrangement according to the invention with a user device and a server, which are designed to carry out a method for setting up the user device. Fig. 2 shows a schematic view of a further embodiment of a device arrangement according to the invention with a user device and a server, which are designed to carry out a method for setting up the user device. Fig. 3 shows a schematic view of a flow chart of steps for checking a link between a device assembly and a secure element of a user device within the framework of a method according to the invention for setting up the user device. Fig.4 shows a schematic view of a flow chart of steps for establishing a link between a device assembly and a secure element of a user device within the framework of a method according to the invention for setting up the user device. Fig. 5 shows a schematic view of a flow chart of steps for checking an authorization of a link between a device module and a secure element of a user device in the context of a method according to the invention for setting up the user device. Detailed description of exemplary embodiments
[0025] The representations in the figures are schematic and not to scale. Where the same reference symbols are used in different figures in the following description, they refer to identical or similar elements. Identical or similar elements may also be designated by different reference symbols.
[0026] Fig.1 shows a schematic view of a device system 1 according to the invention, comprising a user device 2 and a computing device in the form of a server 3. The user device 2 and the server 3 can carry out a method according to the invention with the aid of a computer program 4 based on computer-readable instructions contained therein. The computer program 4 can be stored at least in sections on a computer-readable data carrier 5 and can define components of the device system 1 described therein, as well as associated parameters, identifiers, value keys, and / or steps S, and can regulate their generation, use, and / or handling. The computer-readable data carrier 5 can be present as a computer-readable medium 6 and / or data carrier signal 7. In particular, the data carrier signal 7 can be designed to be transferable between user devices 2 and / or the server 3 for respective execution thereon.Thus, the computer program 4 and thus a corresponding method for setting up the user device 2 can be executed on the user device and / or the server 3.
[0027] The user device 2 comprises a device assembly 8 and a secure element 9, for example in the form of an integrated circuit card or eUICC, which can execute the computer program 4 and thus corresponding method steps S at least in part. The device assembly can be configured as a communications module and / or motherboard of the user device 2 or can comprise such a module or motherboard. Communication between the device assembly 8 and the secure element 9 is based on operating commands B, for example in the form of data elements of corresponding application protocols (Application Protocol Data Unit - APDU), which transmit unidirectional commands to secure elements via a connection interface, which are then executed by them. Furthermore, the operating commands B serve to control functions C of the user device 2.
[0028] The operating commands B can be managed in the command data set D. The device arrangement 1, the user device 2, the server and / or the command data set D can also contain parameters P, such as error codes F, limit values G, labels K, runtime variables T and / or count variables Z, which can be linked to the operating commands B and / or functions C or actions M or possible restrictions N, which in turn can be based on and / or related to the operating commands B. Such parameters P can be managed in the command data set D together with the operating commands B and / or separately therefrom and can be used in a method according to the invention and its steps S.
[0029] In a first method step S1, the command data record D, together with the operating commands B and possibly any parameters P, is specified for the user device 2. For this purpose, corresponding data can be provided by the server 3 to the device module 8 and / or the secure element 9, or implemented and / or queried thereon. In a second step S2, a link W between the device module 8 and the secure element 9 can be initiated, for example, after an initial commissioning of the device module 8 and / or the secure element 9 or after activation of a corresponding function C. In the present example, the secure element 9 initiates the link W by sending a link request Q to the device module 8. In a third step S3, the link request Q can be confirmed with a request confirmation R. In the present example, the device module 8 sends the request confirmation R to the secure element 9.
[0030] In a fourth step S4, a corresponding key exchange can be initiated via initiation request I to encrypt the link W using a security key H. In the present example, the secure element 9 sends the indexing request I to the device module 8. The key exchange can be confirmed in a fifth step S5 via encryption confirmation J, which in the present example is sent from the device module 8 to the secure element 9.
[0031] In a sixth step S6, an authentication request U can be sent to authenticate the link W. In the present example, the secure element 9 sends the authentication request U to the device module 8. In a seventh step S7, the authentication can be confirmed. In the present example, the device module 8 sends an authentication confirmation V to the secure element 9, for example, using a corresponding certificate L.
[0032] In an eighth step S8, the linking process is completed. If the linking is not completely configured correctly, at least one of the operating commands B may be deactivated in a restricted operating mode X. If the link W has been successfully configured, a switch to an unrestricted operating mode Y is possible, in which all or a desired range of the operating commands B from the operating data set D can be executed.
[0033] If the execution of an instruction B is generally permitted, then a counting variable Z can be checked to determine whether it exceeds or falls below a certain limit G for the number of permitted executions. For example, the counting variable Z or corresponding counter can be reduced by one count with each execution, and if the value of the counting variable Z is 0 as the limit G, execution can be denied. If this is the case, a new counting variable Z would have to be reset by authorization. It can also be checked using a reliable time source whether a runtime variable T exceeds a corresponding limit G. If this is the case, a new lifetime variable T or lifetime extension would have to be provided by authorization.
[0034] Additionally, a setup confirmation E can be generated for confirmation purposes, for example, in a secured form by the secure element 9. The setup confirmation E can be used to signal to the user device 2 and / or the server 3 that the setup or establishment of the link W was successful. The user device 2 and / or the server 3 can then initiate appropriate steps to complete the setup process, for example, by activating and / or deactivating any remaining operating commands B in the unrestricted operating mode Y, adjusting count variables Z, storing or logging setup notes, for example, by generating a blockchain, etc.
[0035] In other words, in the present example, the link W can be initiated after a first boot / startup of the user device 2 in the field. The secure element 9 can recognize that it has been configured for a link W and now starts this in step S2 by sending a corresponding proactive command in the form of the link request Q to the device module 8 in order to inform it of the link W to be carried out. The device module 8 can signal that the link can be carried out with an "OK" in the form of the request confirmation R. The secure element then sends another proactive command in the form of the initiation request I in order to start a key exchange according to the state of the art, e.g. according to Diffie-Hellman. With the response from the device module 8, a common security key H is shared by both components.In the next step, this shared security key H is used to verify a successful link W. This can be done using a state-of-the-art cryptography function, e.g., an AES-CMAC. After successful authentication, the secure element 9 can be in unrestricted operating mode Y, for example, a so-called "operational mode," meaning all functions C and actions M are available as usual.
[0036] Fig. Figure 2 shows a schematic view of a further embodiment of a device arrangement 1 according to the invention with the user device 2 and the server 3, which are designed to carry out a method for setting up the user device 2. For the sake of brevity and efficiency, only the differences to the device shown in Fig. 1 illustrated embodiment of the device arrangement 1. Thus, in Fig.2, in the second step S2 the device assembly 8 sends the linking request Q. In the third step S3 the secure element 9 responds with the request confirmation R. In the fourth step S4 the device assembly 8 initiates the exchange of the security key H. In the fifth step S5 the secure element 9 sends the encryption confirmation J. In the sixth step S6 the device assembly 8 makes the authentication request U. In the seventh step the secure element 9 sends the authentication confirmation V, for example using the certificate L, after which the linking process can be completed in the eighth step S8.
[0037] Fig.3 shows a schematic view of a flow chart of steps S for checking a link W between the device module 8 and the secure element 9 of the user device 2 within the framework of an inventive method for setting up the user device 2. In a tenth step S10, a query can be started if an operating command B, for example an APDU, is to be executed. In an eleventh step S11, a query can be made as to whether a restriction N exists with regard to the execution of the operating command B. If the restriction N exists, a link W can be carried out and / or queried in a twelfth step S12, for example by going to step S2, as in Fig. 1 and Fig.2. If the link W is present correctly or is not required, the operation described in step S13 can be executed. The query can be terminated in step S14. In other words, with each new operating command B or with specific operating commands B or commands, it is possible to check whether a link W is configured and required. If not, the process continues with this command. If a link is configured and required, so-called "pairing processing" is performed.
[0038] Fig.4 shows a schematic view of a flow chart of steps S for establishing the link W between the device assembly 8 and the secure element 9 of the user device 9 within the framework of an inventive method for setting up the user device 2. Thus, in a twentieth step S20, a check can be started as to whether a specific operating command B, for example according to a corresponding restriction N, is a command for executing the link W. In a twenty-first step S21, it can be queried whether it is an operating error B relating to the execution of the link W, for example the initiation request I, the encryption confirmation J, link request Q, the request confirmation R, the authentication request U, and / or the authentication confirmation V.
[0039] If this is not the case, a twenty-second step S22, similar to the eleventh step S11, can be used to check whether the operating command B is enabled or subject to a restriction N. If no restriction N exists, the operating command B can be executed in a twenty-third step S23, similar to the thirteenth step S13. The check can then be terminated in a twenty-fourth step S24. If a restriction N exists, an error with the corresponding error code F can be handled in a twenty-fifth step S25. For example, the execution of the link W can then be proceeded to in a twenty-sixth step S26, similar to the twelfth step S12. Alternatively, if the operating command B concerns the execution of the link W, the execution of the link W can be proceeded directly from the twenty-first step S21, as in Fig. 1 and Fig. 2 shown.
[0040] In other words, it can first be checked whether the current command is a linking command according to the operating command B. If not, the current configuration is used to check whether the command is permitted or prohibited. If it is permitted, it is processed further. Otherwise, it is rejected according to the configuration. If it is a linking command, the linking process is processed or executed as in Fig. 1 and Fig. 2 shown.
[0041] Fig.5 shows a schematic view of a flowchart of steps S for checking an authorization of the link W between the device assembly 8 and the secure element 9 of the user device 2 within the framework of an inventive method for setting up the user device 2. In a thirtieth step S30, the check can be triggered, for example, by a specific authorization condition A, action M, and / or a corresponding operating command B, such as resetting the user device 2, the device assembly 8, and / or the secure element 9 to a predetermined operating state. In a thirty-first step S31, it can be checked whether the authorization condition A, action M, and / or a corresponding operating command B are present.
[0042] If the authorization condition A, action M and / or a corresponding operating command B are present, the authorization of the link W can be checked in a thirty-second step S32, for example by means of a corresponding authorization request U, authentication confirmation V and / or certificate L. In the event of an authorization error, error handling can be carried out in a thirty-third step S33 using a corresponding error code F, similar to step S25, for example by switching to the restricted operating mode X. If the authentication is successful, the check can be terminated in a thirty-fourth step S34, for example by switching to the unrestricted operating mode Y.
[0043] If no authorization condition A, action M, and / or a corresponding operating command B is present, then a thirty-fifth step S35 can be checked to determine whether the operating command B or a corresponding APDU requires authorization of the link W or is permitted, similar to the twenty-second step S22. If the operating command B is permitted, it can be executed in a thirty-sixth step S36. If the operating command B is not permitted, error handling can be continued in the thirty-third step S33. If the operating command B is permitted, it can be executed in a thirty-sixth step S36. The check can then be terminated again in the thirty-fourth step S34.
[0044] In other words, depending on the trigger, for example again after a reset to a predetermined operating state, the authentication of the link W can be checked. First, it can then be checked whether the current operating command B or the corresponding command is an authentication command. If so, the authentication is checked, e.g. using AES-CMAC. If successful, the command is accepted and the secure element 9 goes into unrestricted operating mode Y. Otherwise, any error codes F are displayed accordingly. In restricted operating mode X, the secure element can then only allow operating commands B that are configured accordingly. If it is not an authentication command and no successful authentication has been carried out to date, only operating commands B according to the configuration of restricted operating mode X are permitted.
[0045] The link W itself can be specified and initiated in a factory as part of a secure personalization of the user device 2, the device assembly 8 and / or the secure element 9, as in Fig. 1 and Fig. 2. Once a link W has been established, authentication can be performed at the appropriate time. Depending on the configuration, this authentication can be one-way or multi-way. For one-way authentication, for example, only the user device 2 or the device module 8 needs to authenticate itself with the secure element 9. For multi-way authentication, the device module 8 and the secure element 9 must each authenticate each other.
[0046] Possible times for authorizations can be specified in the user device 2, the device module 8, and / or the secure element 9. Possible times can be, for example: after each reset, after n configured commands / operations (arbitrary or special commands / operations) corresponding to a respective counting variable Z, before configured operating commands B or commands (for example, special use cases can be rejected with a special error code F, which signals a new authentication after the expiration of the corresponding runtime variable T), for example, within certain times (user device 2 sends an authentication request every x minutes / hours, or the secure element 9 requests authentication of the user device 2 every x events / commands (counts)). An example of a possible command data set D is shown in the following table: Authentication trigger / operation command B type Number Reset Cold / Warm Reset Z APDU APDU data Z Function C Depending on the definition Z Runtime variable T
[0047] The restricted operating mode X can be implemented using a corresponding format of the command data record D. Thus, a type of permitted or prohibited list can be maintained for certain operating commands B as a synonym for corresponding commands and / or functions C. For example, it is possible to determine which types of APDUs (including information such as CLA, INS, PI, and P2 data bytes, command data) or functions are permitted. For each entry, it can be noted whether the corresponding operating command B is permitted or not. Using appropriate restrictions N and / or markings K, it can also be noted whether a distinction between permitted and prohibited operating commands B can be activated via a corresponding configuration setting.For example, such a configuration setting can be deactivated in the delivery state of the user device 2, the device module 8 and / or the secure element 9 and can be activated later, as is abstractly shown in the following tabular representations of exemplary command data sets D, where wildcards or regular expressions such as '?'' etc. can be permitted and supported:. Operational Order B Details Marking K APDU Command description Allowed / not allowed Function C Functional description Allowed / not allowed Operating OrderB Details Restriction N / Label K comment APDU INS=20 Allowed All APDUs withINS=20: allowed APDU INS=30 & Pl=30 &P2=40 Allowed All APDUs withINS=30 and Pl=30 andP2=40: allowed APDU CLA=8 & INS=40 Forbidden All APDUs with CLAstarting with '8' andINS=40 allowed APDU NS=A4 & Data=“AO00 *” Allowed All APDUs withCL=A4 and data startingwith "A0 00 *" allowed Function C SGPESlOc.GetProfileslnfo Allowed A functionality called“SGPESlOc.GetProfileslnfo" Function C SGPESlOc.EnableProfile Forbidden A functionality called“SGPESlOc.EnableProfile" Function C "function A*" Allowed All functionalities starting with "functionA" are allowed Function C SE Binding Enabled / disabled SE Binding is deactivated / not requiredSE Binding is activated / required
[0048] In this way, command data records D can be personalized with individual and global data as part of a secure personalization in a manufacturing facility of the user devices 2, device assemblies 8 and / or secure elements 9. Alternatively or additionally, the command data records D can be expanded list by list, for example as part of a corresponding personalization. Commands or changes can also be added or modified to the command data records D during operation or later in the field. In general, a change may require that security keys H are present in the secure element 9 for secure data exchange. This can be done, for example, via an OTA connection with a server 3 configured as an OTA server or via the user device 2, for example by means of so-called Global Platform Commands.
[0049] It is possible to dissolve any links W and / or to initiate them again. This is possible, for example, in the event of a factory reset when selling the user device 2 or the device assembly 8. First, the user device 2 and / or the device assembly 8 must successfully authenticate, e.g. via SGP or Global Platform mechanisms, Mutual Authentication, etc., and request a corresponding request. The secure element 9 can then remove the current link W and generate a new security key H. This security key H can be exchanged with the user device 2 or the device assembly 8 via a secure transport path (e.g. Global Platform / Diffie-Hellman). For example, after a successful exchange and verification of the data, this new link W can then be used. This rebinding of this kind must be atomic. List of reference symbols 1 Furnishing arrangement 2 user devices 3 Server / Computing Equipment 4 Computer program 5 computer-readable data carriers 6 computer-readable medium 7 Data carrier signal 8 Device assembly 9 secure element / integrated circuit card (eUICC) A Authorization condition B Operating command C function D Command data set E Confirmation of establishment F Error code G limit H Security key I Initiation request J Encryption confirmation K marking L Certificate M Action N Restriction P parameters Q Link request R Request confirmation S step T runtime variable U Authentication request V Authentication confirmation W link X restricted operating mode Y unrestricted operating mode Z counting variable S1 Default Commands S2 request link S3 Confirmation Link Request S4 Initiation key exchange S5 Confirmation key exchange S6 Request Authentication S7 Confirmation Authentication S8 Completion of linking process S10 start query S11 query restriction S12 Implementation Link S13 Execution of operating command S14 End query S20 start review S21 Check link command S22 Review restriction S23 Execution of operating command S24 End Review S25 Error handling S30 triggering test S31 Authorization command check S32 Authorization Check S33 Error handling S34 End of test S35 Review of admissibility S36 Execution of operating command
Claims
[1] Method for setting up a user device (2), for example a mobile user device (2) for participation in a telecommunications network, with a device assembly (8) on which a secure element (9), in particular an eUICC, is installed, comprising the following steps: - specifying a command data set (D) with operating commands (B) for the user device (2); - checking a link (W) between the device assembly (8) and the safe element (9); and - Refusal of at least one of the operating commands (B) if the check has shown that no authorized link (W) is present. [2] Method according to claim 1, characterized by that a restricted operating mode (X) is defined in which at least one of the operating commands (B) in the command data set (D) is set as non-executable and / or executable. [3] Method according to claim 1 or 2, characterized bythat the command data set (D) contains at least one command parameter (P) with which the refusal and / or release of at least one of the operating commands (B) can be specified. [4] Method according to at least one of the above claims, characterized by that the link (W) is to be authorized depending on an authorization condition (A). [5] Method according to at least one of the above claims, characterized by that the link (W) is to be authorized after a predetermined number of uses of at least one operating command (B) and / or at least one operating action of the user device (2), the device module (8) and / or the secure element (9). [6] Method according to at least one of the above claims, characterized by that at least one of the steps of specifying, checking and refusing is designed to be activatable and / or deactivatable. [7] Computer program (4), characterized by Instructions which, when the program is executed by a user device (2), cause a method according to one of claims 1 to 6 to be carried out. [8] Computer-readable data carrier (5), characterized by a computer program (4) according to claim 7 stored thereon. [9] User device (2), in particular a mobile terminal for participation in a communication network, characterized by a computer program (4) stored thereon according to claim 7, a computer-readable data carrier (2) according to claim 8 and / or in that the user device (2) is set up to carry out a method according to at least one of claims 1 to 6. [10] Setup arrangement (1) for setting up user devices (2), characterized bya computer program (4) stored therein according to claim 7, a computer-readable data carrier (5) according to claim 8 and / or in that the device arrangement (1) is designed to carry out a method according to at least one of claims 1 to 6.
Citation Information
Patent Citations
Device and method for authenticating transport layer security communications
US20200382957A1