Remote security unlocking

By establishing a secure channel in telecommunications equipment to securely transmit module identification and verification information, the problem of network operators having difficulty controlling the operating modes of mobile devices is solved, and a secure and flexible operating mode management and verification process is achieved.

CN113785607BActive Publication Date: 2025-11-04TT SECURE PLATFORM LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080033346.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-11-22
Filing Date
2020-05-01
Publication Date
2025-11-04
Estimated Expiration
2040-05-01

AI Technical Summary

Technical Problem

In the current technology, network operators have difficulty effectively controlling the operating mode of mobile devices, and malicious parties often use technical workarounds to disable or circumvent the control of network operators.

Method used

By establishing a first secure channel between the modem and the application of the telecommunications equipment, and a second secure channel between the application and the remote server, the module identification information and verification information are securely transmitted, thereby enabling the validity verification of the subscriber identity module and ensuring the switching of the device between restricted or enhanced operating modes.

Benefits of technology

It enhances the security of the verification process, prevents malicious parties from bypassing verification, provides flexible device management and secure operation mode switching, supports complex verification methods and functions, and ensures the privacy and security of verification information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113785607B_ABST
    Figure CN113785607B_ABST
Patent Text Reader

Abstract

A method for securely changing an operating mode of a telecommunications device remotely, the method comprising: establishing a first secure channel between a modem of the telecommunications device and an application executing in an execution environment of the telecommunications device; establishing a second secure channel between the application and a remote server; enabling the modem in a restricted operating mode; generating, by the modem or the application, a request for verifying validity of a subscriber identity module of the telecommunications device; obtaining, by the modem, module identification information from the subscriber identity module; obtaining, by the application, verification information from the remote server using the second secure channel, sending the module identification information from the modem to the application using the first secure channel, verifying at the application whether the subscriber identity module is valid using the module identification information and the verification information, and sending the verification result from the application to the modem using the first secure channel, or obtaining, by the application, verification information from the remote server using the second secure channel, sending the verification information from the application to the modem using the first secure channel, and verifying at the modem whether the subscriber identity module is valid using the module identification information and the verification information, or sending the module identification information from the modem to the remote server, verifying at the remote server whether the subscriber identity module is valid using the module identification information and the verification information available at the server, sending the verification result from the remote server to the application using the second secure channel, and sending the verification result from the application to the modem using the first secure channel; in response to a positive verification of the subscriber identity module, transitioning the modem from the restricted operating mode to an enhanced operating mode.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross Reference to Related Applications

[0002] This application claims priority to UK Application GB1906276.9, filed 3 May 2019, entitled “Remote Secure Unlock”, and UK Application GB1917051.3, filed 22 November 2019, entitled “Multi-SIM Carrier-Lock”. The disclosures of both of these applications are incorporated herein by reference in their entirety.

[0003] TECHNICAL FIELD AND BACKGROUND

[0004] The present technology relates to the field of locking and unlocking mobile devices. More specifically, the described technology relates to various techniques by which a remote entity (e.g., a server operated by a mobile network operator) can control whether a mobile device is permitted to operate in an enhanced operation mode or is only permitted to operate in a limited operation mode.

[0005] In certain prior approaches, various techniques have been provided that allow a network operator to control the operation mode of a mobile device, for example, when a subsidized mobile device is provided to a user on the condition that the user maintains a network service subscription, such that if the user allows the subscription to lapse, the mobile device is only permitted to operate in a limited operation mode.

[0006] However, certain malicious parties have developed a number of technical workarounds to disable or circumvent the network operator’s control over the operation mode of a mobile device.

[0007] At least certain embodiments of the present disclosure address one or more of these problems as described above. SUMMARY

[0008] Particular aspects and embodiments are set forth in the appended claims.

[0009] From one perspective, a method for securely changing an operational mode of a telecommunication device remotely can be provided, the method comprising: establishing a first secure channel between a modem of the telecommunication device and an application executing in an execution environment of the telecommunication device; establishing a second secure channel between the application and a remote server; enabling the modem in a restricted operational mode; generating, by the modem or the application, a request for verifying validity of a subscriber identity module of the telecommunication device; obtaining, by the modem, module identification information from the subscriber identity module; obtaining, by the application, verification information from the remote server using the second secure channel, sending the module identification information from the modem to the application using the first secure channel, verifying at the application whether the subscriber identity module is valid using the module identification information and the verification information, and sending a result of the verification from the application to the modem using the first secure channel, or obtaining, by the application, verification information from the remote server using the second secure channel, sending the verification information from the application to the modem using the first secure channel, and verifying at the modem whether the subscriber identity module is valid using the module identification information and the verification information, or sending the module identification information from the modem to the remote server, verifying at the remote server whether the subscriber identity module is valid using the module identification information and verification information available at the server, sending a result of the verification from the remote server to the application using the second secure channel, and sending the result of the verification from the application to the modem using the first secure channel; in response to a positive verification of the subscriber identity module, transitioning the modem from the restricted operational mode to an enhanced operational mode.

[0010] As discussed further below, the above method encompasses three options for performing the verification of the subscriber identity module: A the verification is performed by the application; B the verification is performed by the modem; C the verification is performed by the remote server. Prior to the verification, the telecommunication device defaults to the restricted operational mode.

[0011] However, in each of A, B and C, the application needs to perform one or more steps to allow the successful performance of the verification. The method thus enhances the security of the verification process, as the verification process cannot be bypassed by deleting the application (e.g. by rooting the device), as if the application is deleted, the verification process will fail and thus the modem will remain in the restricted operational mode. The application thus acts as a master modem control point.

[0012] This requirement for the application to be present further enhances the security, as the application is able to support additional security measures and checks discussed in further examples below. Furthermore, the application (as software) can be directly updated Over-the-Air (OTA), e.g. in response to an inclusion security.

[0013] By allowing the verification information to be received from a remote server (option A or B), the verification information can be provided after, for example, power on of the device by an end user. This means that the verification information does not need to be provided at the time of manufacture, and the device can be produced as a single Stock Keeping Unit (SKU), i.e. there is no need for the mobile network operator to individually customise batches of devices during manufacture. From another perspective, the device can be customised as part of the first boot-up by, for example, an end user. As part of this first boot-up by an end user, the end user can be prompted to provide information provided by the mobile network operator.

[0014] The verification information can include information about the rules governing which subscriber identity modules the telecommunication device is allowed to operate with, and the conditions under which the device is to operate in conjunction with a particular subscriber identity module. In some examples, the verification information can include other information indicative of the operation of the telecommunication device, for example, geographical, time or functional limitations. In some examples, the telecommunication device can be shipped in a“locked” state in which the device will initially reject all subscriber identity modules until the verification information has been obtained. In some examples, the remote server in which the verification information is stored can be operated by the mobile network operator, in other examples, the remote server can be operated by the device manufacturer or a third party.

[0015] As mentioned above, there are three options that can perform the verification of the subscriber identity module, which have associated further effects and advantages.

[0016] By performing the verification at the application (option“A”), a complex verification method and functionality can be supported, examples of which will be discussed below. In some examples, the application can support a complex verification method and functionality because it is executed on a“full” application processor. By performing the verification at the application, the verification element (i.e. the application) can be directly replaced or updated, for example, in response to a security breach or to introduce new functionality. In some examples, where there are multiple subscriber identity modules with a corresponding plurality of (modem modules), performing the verification on the application provides a single central point of verification control.

[0017] By performing the verification at the modem (option“B”), the need to send the module identification information to any other element is avoided, thereby making the module identification information more difficult to intercept and / or copy, and thus enhancing security. Furthermore, option B allows the need to send the verification result to be avoided, thereby also making the verification result more difficult to intercept and / or copy, and thus enhancing security.

[0018] By performing the verification at the remote server (Option "C"), the verification information can be protected and hidden from the end user (device) and saved in a trusted environment. In addition, locating the verification mechanism at the remote server allows for dynamic adjustment of the verification mechanism and verification information. In other words, as long as the remote server is trusted, it is difficult for a malicious party to crack or compromise the verification mechanism and / or verification information. This approach avoids the need to send the verification information, making it difficult to intercept and / or copy the information. In some examples, where there are multiple subscriber identity modules with a corresponding plurality of (modem modules), performing the verification on the remote server provides a single centralized point of verification control.

[0019] In each of the above-listed options A, B, and C, when any of the module identification information, verification information, and verification result is sent between the modem and the application within the telecommunication device, they are sent using a first secure channel. This enhances security by protecting the information being sent from being intercepted, read, or modified.

[0020] Similarly, in each of the above-listed options A, B, and C, when any of the module identification information, verification information, and verification result is sent between the application and the remote server, they are sent using a second secure channel. This enhances security by protecting the information being sent from being intercepted, read, or modified.

[0021] In Option C, when the modem sends the module identification information to the remote server, this can be sent in a number of different ways. In some examples, the modem can first send the module identification information to the application through the first secure channel, and then the application sends the information to the remote server using the second secure channel. In other examples, there can be a third secure channel between the modem and the remote server. The security of the third secure channel can be based on a key pair embedded in the manufacturing device.

[0022] In some examples, the keys of the modem and the application are unique, such that a single compromised device does not compromise the security of an entire batch of devices that, for example, share the same keys with each other.

[0023] In some examples, restricted operating mode refers to a mode that imposes restrictions on the modem and / or the entire device. For example, in restricted operating mode, phone calls may be restricted to being blocked or limited to emergency calls; and / or text messaging may be blocked; and / or data connections may be blocked, bandwidth limited, and / or usage restricted; and / or restrictions may be imposed on other elements of the device in restricted operating mode, such as controlling / disabling Wi-Fi, controlling / disabling Bluetooth, and / or otherwise disabling the ability to execute certain applications. These restrictions may be applied continuously or only on certain days / times. In enhanced operating mode, one or more of these restrictions are removed.

[0024] In some examples, the application is a trusted application, and the execution environment is a trusted execution environment (TEE). This robustly protects the application's code from inspection or modification, ensuring the application's security. The TEE acts as a secure region within the processor where sensitive applications and processes execute. The TEE is isolated from the Rich Execution Environment (REE), in which a rich operating system, such as Android, iOS, Windows, or Linux, can run. Examples of embedded hardware technologies that can be used to support TEE implementations include... of AMD's secure processor and Intel's Trusted Execution Technology. It can be understood that trusted applications in a TEE can communicate with applications in a REE. For example, an application in the REE can act as a front-end user interface for a trusted application.

[0025] In some examples, when authentication is performed at the application or modem, the authentication information at the telecommunications device is periodically updated from a remote server. This allows changes to the authentication information to be periodically propagated to the device. These changes can then be processed by the device to enable the implementation of information represented by the authentication information (e.g., usage conditions). For example, in response to a user's arrears in monthly payments on a subsidized telecommunications device, or in the event of loss / theft of the telecommunications device, the authentication information can be changed at the request of the mobile network operator. The updated authentication information can modify / impose further restrictions on the use of the telecommunications device.

[0026] In some examples, the verification of the subscriber identity module is periodically rechecked, and wherein in response to a negative re-verification, the modem is transitioned from the enhanced mode of operation to the restricted mode of operation. In this way, the device periodically rechecks whether the subscriber identity module is still valid, and returns the modem to the restricted mode of operation in the event that the subscriber identity module is no longer valid. In some examples, the periodic check can be handled by setting a periodic interrupt for re-performing the verification process in the application, modem or server. The re-verification and propagation of the result can be handled in the same way as described in the methods above.

[0027] In some examples, the verification information specifies a first time period and a second time period, wherein during the first time period and until the end of the first time period, the telecommunication device is in a temporarily unlocked state in which the modem is able to transition to the enhanced mode of operation without the need to perform a verification step or in the event that the verification step is automatically passed, and wherein upon expiry of the second time period, the telecommunication device contacts the remote eligibility server to request an extension of the first time period. In this way, the device can have a "rolling" first time period which ensures that the device is generally kept in a temporarily locked state (e.g. temporarily in the enhanced mode of operation) whilst still retaining the ability to force the device into a locked state (e.g. the restricted mode of operation) through the second time period, which "forces" the device to periodically recheck whether it is still allowed to remain in the temporarily unlocked state from one perspective, as without such a check the device would have to perform the "normal" verification step to enter or remain in the enhanced mode of operation.

[0028] As discussed further in the detailed description, the second time period can be set to be shorter than the first time period to ensure that the first time period is extended before it expires. It will be appreciated that the remote eligibility server can be implemented as part of the remote server or as a separate server. In some examples, the extension of the first time period takes the form of updated verification information. For example, this approach can provide a technical implementation which allows a mobile network operator to comply with local legal requirements (that devices must be sold in an unlocked state) whilst still retaining the ability to control telecommunication devices when a user is in arrears with payments on their subsidised device.

[0029] In some examples, the verification information specifies a third time period, and after expiry of the third time period, the telecommunications device enters a permanently unlocked state in which the modem is able to transition to the enhanced operating mode without needing to perform the verification step or in which the verification step is automatically passed. In this way, the device can enter the permanently unlocked state at a predetermined time specified by the third time period (e.g. the device is always able to enter the enhanced operating state). This can save computational resources and bandwidth by avoiding further updates when they are no longer needed (e.g. when a contract relating to the subsidised device has ended).

[0030] In some examples, before obtaining the verification information, the modem transitions from the restricted operating mode to the enhanced operating mode for a fourth time period, and wherein if a positive verification is not made of the subscriber identity module before expiry of the fourth time period, after expiry of the fourth time period the modem transitions from the enhanced operating mode back to the restricted operating mode. In this way, in some examples, the fourth time period can allow the device time to temporarily access resources for the verification operation. For example, temporarily allowing the device to enter the enhanced operating mode can allow a data connection on the modem to be enabled, allowing the device to download (update) the verification information and / or contact a trusted time source.

[0031] In some examples, the determination that the first time period and / or the second time period and / or the third time period and / or the fourth time period has expired is performed by an application optionally using a trusted time source. In this way, using an application to determine whether a time period has expired can make it difficult to bypass the time period protection. Furthermore, by using a trusted time source, it can be more difficult to bypass the time period protection. The trusted time source can be a real time clock (RTC) which defines the actual time, rather than simply measuring a time period since the last call to the clock. By using an RTC, it can be further difficult to bypass the time period protection. In some examples, the trusted time source is a secure time server, for example the Trustonic Time of Check technology. In other examples, the trusted time source can be a dedicated piece of hardware included on the telecommunications device.

[0032] In some examples, when the subscriber identity module is detached from the modem, the modem transitions to the restricted operating mode. In this way, attempts to bypass the verification check by initially "presenting" a valid subscriber identity module to the device but subsequently swapping the valid subscriber identity module for an invalid subscriber identity module are addressed, as the device transitions back to the restricted operating mode and the new "invalid" subscriber identity module itself has to pass the verification check in order to run in the enhanced operating mode.

[0033] In some examples, when a subscriber identity module (VIM) is re-inserted into a telecommunications device, or when a second VIM is inserted, the re-inserted VIM or the inserted second VIM must be verified before the modem switches from restricted operating mode back to enhanced operating mode. This ensures that the verification process is re-executed whenever any VIM is re-inserted, thereby enhancing security. For example, this further allows for verification processes that restrict which VIMs can be used in combination. For instance, a mobile network operator subsidizing a device might want to ensure that the device operates in enhanced operating mode only if all VIMs used in the device originate from that mobile network operator. In other examples, a single VIM originating from a mobile network operator is sufficient for the device to operate in enhanced operating mode.

[0034] In some examples, the telecommunications equipment has multiple subscriber identity modules, and the method verifies the validity of all subscriber identity modules individually or jointly. This allows for the support of multiple network connections. As mentioned above, mobile network operators are free to verify the subscriber identity modules jointly or individually. In some examples, the verification information and / or associated conditions may differ for each subscriber identity module "slot." In some examples, the verification information and / or associated conditions may differ for each logical or physical subscriber identity module slot.

[0035] In some examples, one or more of the first and second secure channels are established using elliptic curve Diffie-Hellman, elliptic curve Diffie-Hellman temporary key exchange, or any other asymmetric key-sharing algorithm. This allows secure keys to be established without the need (e.g., at manufacturing time or as part of a retail supply chain) to pre-inject all keys.

[0036] In some examples, one or more of the first and second secure channels are established using keys injected into the modem and / or application during manufacturing. This allows keys to be established in a secure, trusted location, where they can be established undisturbed on the device. Furthermore, by establishing keys in a secure environment, a wider range of keys can be established because these keys do not need to be secure when shared over public / potentially interceptable connections.

[0037] In some examples, one or more of the first and second secure channels are established using keys generated by the modem and / or the application. This avoids the cost of key injection per device.

[0038] In some examples, the two entities at either end of the first secure channel and / or the two entities at the ends of the second secure channel each maintain a counter that is monotonically incremented as messages are exchanged, where the transmitted messages include a value derived from the sending entity's counter, and where the receiving end entity only accepts as valid messages values derived from the counter value that are higher than the receiving end's current counter value. In this way, security can be enhanced by providing replay protection. In other words, no replayed messages on either of the first or second secure channels would be considered valid, as the counter value contained in the replayed message would have too small a value.

[0039] In some examples, the second secure channel can communicate between the application and the remote server's secure endpoint through the modem. In some examples, the communication through the modem can be passed along the first secure channel between the application and the modem. In other examples, the communication through the modem can be passed along a communication channel different from the first secure channel between the application and the modem.

[0040] In some examples, the request is generated by the application, the application verifies the subscriber identity module, and the application transmits the verification result to the modem via the first secure channel. In this way, the request and the verification are performed by the same entity (i.e., the application), and thus the application retains full control.

[0041] In some examples, the request is generated by the modem, the application provides verification information to the modem over the first secure channel, and the modem verifies the subscriber identity module. In this way, the request and the verification are performed by the same entity (i.e., the modem), and thus the modem retains full control.

[0042] In some examples, the module identification information includes an International Mobile Subscriber Identity "IMSI", a Group Identifier "GID", or a Subscription Permanent Identifier "SUPI".

[0043] In some examples, when the telecommunication device receives the temporary module identification information, a copy of the temporary module identification information is stored on the subscriber identity module, and a temporary module identification information authenticator is generated based on the temporary module identification information and an identifier of the telecommunication device, the temporary module identification information authenticator being stored on a storage module of the telecommunication device, wherein when the telecommunication device subsequently initiates a network reconnection procedure and the temporary module identification information is identified as present on the subscriber identity module, the temporary module identification information from the subscriber identity module is verified according to the temporary module identification information authenticator and the identifier of the telecommunication device, wherein in response to a positive verification, the telecommunication device attempts to connect to the network using the temporary module identification information, and wherein in response to a negative verification, the telecommunication device attempts to connect to the network using the module identification information. In this way, attacks relying on "spoofing" the temporary module identification information can be resisted, since the temporary module identification information is effectively "bound" to the device by the temporary module identification information authenticator. Thus, it is not possible to transfer the temporary module identification information from a first device to a second device in a way that allows the second device to successfully connect to the telecommunication network without re- verifying the module identification information.

[0044] In some examples, the temporary module identification information comprises a Temporary Mobile Subscriber Identity "TMSI", or a Globally Unique Temporary UE Identity "GUTI". In some examples, the TMSI / GUTI can be one or more of a 5G-S-TMSI, a 5G-TMSI, a 5G-GUTI or an M-TMSI. It will be appreciated that in some examples, the temporary module identification information technique can be paired with the module identification information technique. For example, an IMSI and a TMSI can form a pair.

[0045] In some examples, in which the module identification information is stored in a cache of the telecommunication device after it has only been read once when the subscriber identity module is inserted or when the telecommunication device is started, in which when the modem reads the module identification information, the modem reads the module identification information from the cache, and in which when the telecommunication device performs a network connection procedure, the telecommunication device uses the cached module identification information to obtain the module identification information for use in the network connection procedure. In this way, attacks relying on different module identification information for the verification procedure and for the network connection can be addressed. One example of such an attack is known as "Turbo SIM", which works by using a physical device placed in the SIM card slot of the telecommunication device together with a SIM card, thereby manipulating data sent to the phone about the SIM card.

[0046] Viewed from one angle, a computer program for controlling a device to perform any of the above methods can be provided. In some examples, the computer program is stored on a storage medium.

[0047] Viewed from one aspect, there can be provided an apparatus comprising: processing circuitry for performing data processing; and data storage storing at least one computer program for controlling the processing circuitry to perform any of the above methods.

[0048] Other aspects will become apparent after consideration of the disclosure, particularly when taken in conjunction with the following drawings and detailed description. BRIEF DESCRIPTION OF DRAWINGS

[0049] Examples of the disclosure will now be described by way of example only with reference to the attached drawings, of which:

[0050] Figure 1 A system configured to operate in accordance with the teachings of the disclosure is schematically illustrated.

[0051] Figure 2A A method for remotely performing a secure change of operating mode of a telecommunications device in accordance with the teachings of the disclosure is schematically illustrated, in which a modem verifies the validity of a subscriber identity module.

[0052] Figure 2B A method for remotely performing a secure change of operating mode of a telecommunications device in accordance with the teachings of the disclosure is schematically illustrated, in which a modem verifies the validity of a subscriber identity module.

[0053] Figure 2C A method for remotely performing a secure change of operating mode of a telecommunications device in accordance with the teachings of the disclosure is schematically illustrated, in which a remote server verifies the validity of a subscriber identity module.

[0054] Figure 3 The interaction of a first time period, a second time period and a third time period in accordance with the teachings of the disclosure is schematically illustrated.

[0055] Figure 4 A method by which a telecommunications device can mitigate certain techniques to bypass security protections for verifying a subscriber identity module is schematically illustrated.

[0056] Figure 5 An example of an apparatus that can be used to implement the teachings of the disclosure is schematically illustrated.

[0057] While the disclosure is susceptible to various modifications and alternative forms, specific example methods are shown by way of example in the drawings and are described in detail herein. It should be understood however that the drawings and the detailed description thereto are not intended to limit the disclosure to the particular form disclosed but rather the disclosure covers all modifications, equivalents and alternatives falling within the spirit and scope of the claimed invention.

[0058] It will be appreciated that features of the above examples of the present disclosure can be used conveniently and interchangeably in any suitable combination. DETAILED DESCRIPTION

[0059] Figure 1 A schematic diagram of a system 100 configured to operate in accordance with the teachings of the present disclosure is shown. The diagram depicts a telecommunication device 110 and a remote server 140. In some examples, the telecommunication device 110 is a mobile phone, a tablet, a mobile hotspot, a laptop with integrated cellular connectivity, or any other device capable of connecting to a mobile telecommunication network. In some examples, the remote server 140 is a server operated by a mobile network operator or a device manufacturer. The telecommunication device 110 comprises a modem 120 and an application processing system 130.

[0060] The modem 120 comprises a processing circuit 122, a storage 124, and one or more subscriber identity module interfaces 126, 126B. It will be appreciated that there can be 1, 2, 3, 4, 5, 6, 7, 8, 9, or 10 subscriber identity module interfaces 126 in some examples. It will be appreciated that the processing circuit 122 can be any suitable processing circuit capable of performing the steps and functions described in this specification as being performed by the modem 120. It will be appreciated that the storage 124 can be any suitable storage capable of storing data and instructions processed by the processing circuit 122. The storage 124 can comprise both a main storage and a secondary storage, and can comprise read-only memory and / or read-write memory. In some examples, the modem 120 does not comprise a dedicated storage 124, but uses the storage 134 for both main storage and secondary storage. In other examples, the storage 124 comprises only main storage, and the modem 120 uses the storage 134 for secondary storage. In the case where the storage 124 comprises only main storage, the modem 120 can receive its firmware from the storage 134 during boot-up, and then mount a storage point from the storage 134 to act as its secondary storage.

[0061] Each of the subscriber identity module interfaces 126, 126B can include a subscriber identity module 128, 128B. It will be appreciated that from one perspective, the subscriber identity module(s) 128, 128B are not themselves part of the modem 120, and can be considered as separate, physically or logically removable elements. It will be appreciated that in some examples, the term subscriber identity module 128, 128B encompasses a range of physical and non-physical subscriber identity module technologies, such as SIM, eSIM, UICC, eUICC, USIM, iSIM, and TEE-SIM. The subscriber identity module(s) 128, 128B store module identification information 129, 129B, respectively. In some examples, the module identification information 129, 129B includes one or more of an International Mobile Subscriber Identity “IMSI,” a Group Identifier “GID,” and a Subscription Permanent Identifier “SUPI.”

[0062] The application processing system 130 includes processing circuitry 132 and storage 134. In some examples, the processing circuitry 132 is a “full” application processor capable of executing a rich operating system such as Android, iOS, Windows, or Linux. The processing circuitry includes applications 136 that perform the steps and functions described in this specification as being performed by the applications 136.

[0063] In some examples, the processing circuitry 132 is capable of supporting a trusted execution environment “TEE” 138 and a rich execution environment “REE” 139. The TEE 138 is isolated from the REE 139 in which a rich operating system such as Android, iOS, Windows, or Linux can be executed. Examples of processor technologies that can be used to support TEE 138 implementations include Arm’s TrustZone, AMD’s Secure Processor, and Intel’s Trusted Execution Technology. In the presence of the TEE 138, in some examples, the applications 136 can execute inside the TEE 138 for enhanced security. It will be appreciated that the storage 134 can be any suitable storage capable of storing data and instructions for processing by the processing circuitry 132. The storage 134 can include both main storage and secondary storage, and can include read-only memory and / or read-write memory.

[0064] A first secure channel 150 is established between the modem 120 and the application 136. The first secure channel 150 allows information to be securely communicated between the modem 120 and the application 136. In some examples, the first secure channel can be established using Elliptic Curve Diffie-Hellman, Elliptic Curve Diffie-Hellman ephemeral key exchange, or any other asymmetric key sharing algorithm. In some examples, the first secure channel is established using a key that is injected to the modem and / or application during manufacturing. Additionally or alternatively, the first secure channel is established using a key that is generated by the modem and / or application, and can be a symmetric key established secure channel.

[0065] The remote server 140 includes processing circuitry, which includes processing circuitry 142 and storage 144. It will be appreciated that the processing circuitry 142 can be any suitable processing circuitry capable of performing the steps and functions described in this specification as being performed by the remote server 140. It will be appreciated that the storage 144 can be any suitable storage capable of storing data and instructions processed by the processing circuitry 142. The storage 144 can include both main memory and secondary memory, and can include read-only memory and / or read-and-write memory. The storage 144 stores verification information 146. In some examples, the verification information 146 includes information specifying which subscriber identity modules 126 are valid for use with the telecommunication device 110. In some examples, the verification information 146 includes conditions regarding how the telecommunication device 110 is allowed to operate. In some examples, the remote server 140 includes a trusted time source.

[0066] A second secure channel 160 is established between the application 136 and the remote server 140. The second secure channel 160 allows information to be securely communicated between the application 136 and the remote server 140. In some examples, the second secure channel can be established using Elliptic Curve Diffie-Hellman, Elliptic Curve Diffie-Hellman ephemeral key exchange, or any other asymmetric key sharing algorithm. In some examples, the second secure channel is established using a key that is injected to the modem and / or application during manufacturing. Additionally or alternatively, the second secure channel is established using a key that is generated by the modem and / or application, and can be a symmetric key established secure channel.

[0067] In some examples, the two entities at the two ends of the first secure channel and / or the two entities at the ends of the second secure channel each maintain a counter that is monotonically incremented upon exchange of messages, wherein the transmitted messages include a value derived from the counter of the transmitting entity, and wherein the receiving end entity accepts as a valid message only if the value derived from the counter value is higher than the current counter value of the receiving end. In some examples, the counter is incremented by one each time, and the check for a "higher" counter value is accepted only when the counter is incremented by one.

[0068] Figure 2A 、 Figure 2B and Figure 2C Figures showing a schematic of methods 200A, 200B and 200C for securely changing the operating mode of a telecommunication device remotely, in accordance with the teachings of the present disclosure, in which various entities verify the validity of a subscriber identity module. It will be appreciated that the methods 200A, 200B and 200C can be implemented on the system 100 shown. It will be appreciated that steps S210 to S250 and S270 are common to each of the methods 200A, 200B and 200C, with steps S260A / S260B / S260C being performed between steps S250 and steps S270 in the methods 200A / 200B / 200C, respectively. Figure 1

[0069] Figure 2A Figure showing a schematic of a method 200A for securely changing the operating mode of a telecommunication device remotely, in accordance with the teachings of the present disclosure, in which an application verifies the validity of a subscriber identity module. The method comprises the following steps.

[0070] At step S210, a first secure channel is established between a modem of the telecommunication device and an application executing in an execution environment of the telecommunication device. The method then proceeds to step S220.

[0071] At step S220, a second secure channel is established between the application and a remote server. The method then proceeds to step S230.

[0072] At step S230, the modem is enabled in a restricted operating mode. The method then proceeds to step S240.

[0073] At step S240, a request for verifying the validity of a subscriber identity module of the telecommunication device is generated by the modem or the application. The method then proceeds to step S250.

[0074] ​At step S250, the modem obtains the module identification information from the subscriber identity module. In some examples, this obtaining is performed using a subscriber identity module interface. In method 200A, the method then proceeds to step S262A.

[0075] At step S262A, the application obtains the verification information from the remote server using the second secure channel. The method then proceeds to step S264A.

[0076] At step S264A, the modem sends the module identification information to the application using the first channel. The method then proceeds to step S266A.

[0077] At step S266A, the application uses the module identification information and the verification information to verify the validity of the subscriber identity module. The method then proceeds to step S268A.

[0078] At step S268A, the application sends the verification result to the modem using the first secure channel. The method then proceeds to step S270.

[0079] At step S270, in response to a positive verification result, the modem transitions from the restricted operating mode to the enhanced operating mode.

[0080] It will be appreciated that, Figure 2A The exact order of the steps depicted in FIG. 2 is merely by way of illustrative example, and these steps can be performed in any order, with the information used in the steps being available at the respective elements, and the first / second secure channels having been established where information is used. For example, in some examples: S210 can be performed at any time prior to S264A; S220 can be performed at any time prior to S262A; S230 can be performed at any time prior to S270; S240 can be performed at any time prior to step S266A; S250 can be performed at any time prior to S264A; S262A can be performed at any time after S220 and prior to S266A; S264A can be performed at any time after S250 and prior to S266A; S266A can be performed at any time after S262A, S264A, and prior to S268A; S268A can be performed at any time after S266A and prior to S270; and S270 can be performed at any time after S268A.

[0081] Figure 2BA schematic of a method 200B for remotely performing a secure change of operating mode of a telecommunication device is shown, in which the modem verifies the validity of the subscriber identity module, in accordance with the teachings of the present disclosure. The method performs steps S210 to S250 as described above, and then proceeds to step S262B.

[0082] At step S262B, the application obtains verification information from the remote server using the second secure channel. The method then proceeds to step S264B.

[0083] At step S264B, the application sends the verification information to the modem using the first secure channel. The method then proceeds to step S266B.

[0084] At step S266B, the modem verifies the validity of the subscriber identity module using the module identification information and the verification information. The method then proceeds to step S270, which has been described above.

[0085] It will be appreciated that, Figure 2B The exact order of the steps depicted in Figs. 2A, 2B and 2C is merely by way of illustrative example, and these steps can be performed in any order, with the information used in the steps being available at the respective elements, and where the information is used, the first / second secure channel having been established. For example, in some examples: S210 can be performed at any time before S264B; S220 can be performed at any time before S262B; S230 can be performed at any time before S270; S240 can be performed at any time before step S266B; S250 can be performed at any time before S266B; S262B can be performed at any time after S220 and before S264B; S264B can be performed at any time after S266B and S262B; S266B can be performed at any time after S250, before S264B and S270; and S270 can be performed at any time after S266B.

[0086] Figure 2C A schematic of a method 200C for remotely performing a secure change of operating mode of a telecommunication device is shown, in which the remote server verifies the validity of the subscriber identity module, in accordance with the teachings of the present disclosure. The method performs steps S210 to S250 as described above, and then proceeds to step S262C.

[0087] At step S262C, the modem sends the module identification information to the remote server. The method then proceeds to step S264C.

[0088] At step S264C, the remote server verifies the validity of the subscriber identity module using the module identification information and the authentication information. The method then proceeds to step S266C.

[0089] At step S266C, the remote server sends the verification result to the application using the second secure channel. The method then proceeds to step S268C.

[0090] At step S268C, the application sends the verification result to the modem using the first secure channel. The method then proceeds to step S270, which has already been described above.

[0091] It will be appreciated that, Figure 2C The exact order of the steps depicted in the figures is merely by way of illustrative example, and the steps can be performed in any order, with the information used in the steps being available at the respective elements, and the first / second secure channels having been established where the information is used. For example, in some examples: S210 can be performed at any time prior to S268C; S220 can be performed at any time prior to S266C; S230 can be performed at any time prior to S270; S240 can be performed at any time prior to step S264C; S250 can be performed at any time prior to S262C; S262C can be performed at any time prior to S264C and after S250; S264C can be performed at any time prior to S266C and after S262C; S266C can be performed at any time prior to S268C and after S264C; S268C can be performed at any time prior to S270 and after S266C; and S270 can be performed at any time after S268C.

[0092] In some examples, for methods 200A, 200B and 200C, if the subscriber identity module is subsequently detached from the modem, the modem transitions back to the restricted operating mode.

[0093] In some examples, for methods 200A, 200B and 200C, if the subscriber identity module is reinserted into the telecommunication device (e.g. after the subscriber identity module has been detached from the modem), or when a second subscriber identity module is inserted into the telecommunication device, the reinserted subscriber identity module or the inserted second subscriber identity module must be verified before the modem transitions from the restricted operating mode to the enhanced operating mode.

[0094] In some examples, for methods 200A, 200B and 200C, where the telecommunication device has multiple subscriber identity modules, the method verifies the validity of all of the subscriber identity modules individually or collectively.

[0095] In some examples, for the methods 200A, 200B, and 200C, the module identification information is stored in a cache of the telecommunication device after being read only once when the subscriber identity module is inserted or when the telecommunication device is powered on, where the modem reads the module identification information from the cache when the modem reads the module identification information, and where the telecommunication device uses the cached module identification information to obtain the module identification information for the network connection procedure when the telecommunication device performs the network connection procedure. In some examples, the cached module identification information is stored in the storage 124 of the modem 120, as shown in Figure 1 . In other examples, the cached module identification information is stored in the storage 134 of the application processing system 130, as shown in Figure 1 .

[0096] Figure 3 A schematic diagram showing the interaction of the first time period, the second time period, and the third time period is shown. This can be implemented on the system 100 shown in Figure 1 , and can be performed in conjunction with the methods 200A, 200B, and 200C.

[0097] It can be seen that, Figure 3 Three time periods are depicted. Time period 1 (first time period) corresponds to a “sliding” window in which the telecommunication device is in a temporarily unlocked state. Time period 2 (second time period) corresponds to a periodic check, in which, for example, the remote eligibility server requests an extension of time period 1, e.g., “allows” time period 1 to “slide.” This is depicted in Figure 3 , below the timeline, where multiple time periods 1 are shown at various “sliding” positions. In some examples, time period 1 is implemented by allowing the modem to transition to the enhanced operating mode without needing to perform a verification step or with the verification step automatically passing, for the duration of time period 1. In some examples, time period 1 can be set between one day and one month. In some examples, time period 2 can be set between twelve hours and two weeks.

[0098] In some examples, time period 1 is updated by receiving and processing updated verification information by the telecommunication device. In other examples, time period 1 is directly updated, e.g., by sending a security message to the application.

[0099] In some examples, the verification information at the telecommunication device is periodically updated from a remote server and / or a remote eligibility server. In some examples, the telecommunication device periodically rechecks the verification of the subscriber identity module, and where, in response to a negative re-verification, the modem transitions from the enhanced operating mode to the restricted operating mode.

[0100] It will be appreciated that there is a trade-off in setting the length of time period 1 and time period 2. For example, if time period 1 is set too short, the temporary unlock can expire unexpectedly before the telecommunication device successfully (re)contacts the remote eligibility server to extend the time period it can use. This can cause user dissatisfaction if this happens too frequently by temporarily rendering the device inoperable until the user can cause the device to connect to the remote eligibility server. For example, if time period 1 is set too long, the device can run in the enhanced operating mode for a longer period after it is no longer eligible due to, for example, the device being stolen or the user contract not being paid. For example, if time period 2 is set too short, the device will invoke the remote eligibility server too frequently to keep extending the expiration time of the temporary unlock of the device. This can unnecessarily consume bandwidth, processing time, and battery life. For example, if time period 2 is set too long, similar drawbacks to time period 1 can be encountered, in which the temporary unlock can expire unexpectedly before the telecommunication device successfully (re)contacts the remote eligibility server to extend the time period it can use. Again, this can cause user dissatisfaction if this happens too frequently by temporarily rendering the device inoperable (or into the limited operating mode) until the user can cause the device to connect to the remote eligibility server.

[0101] Time period 3 (third time period) corresponds to the total duration in the contract for which the subsidized device is eligible, after which the device will enter a permanently unlocked state. In some examples, time period 3 is implemented by the telecommunication device entering a permanently unlocked state after time period 3 expires, in which the modem is able to transition to the enhanced operating mode without needing to perform the verification step or in which the verification step is automatically passed. In some examples, time period 3 can be set between six months and three years.

[0102] In some examples, before obtaining the verification information, the modem transitions from the limited operating mode to the enhanced operating mode for a fourth time period (not shown). If no positive verification is made of the subscriber identity module before the fourth time period expires, the modem transitions from the enhanced operating mode back to the limited operating mode after the fourth time period expires.

[0103] In some examples, the determination that the first time period and / or the second time period and / or the third time period and / or the fourth time period has expired is performed by the application using a trusted time source. In some examples, the trusted time source can be a “real-time clock” (RTC), which defines the actual time, rather than merely measuring the time period since its last invocation. By using an RTC, it can be difficult to bypass the time period protection. In some examples, the trusted time source is a secure time server, for example, Trustonic’s Trusted Time Server. In other examples, the trusted time source can be a dedicated piece of hardware included on the telecommunication device.

[0104] Figure 4 A schematic illustration of a method by which a telecommunication device can mitigate against certain attacks that seek to bypass the security protections for verifying a subscriber identity module is shown. It will be appreciated that the method can be implemented on the system 100 shown, and can be performed in conjunction with the methods 200A, 200B and 200C, and the time periods described in relation to the methods 200A, 200B and 200C. Figure 1 The method comprises the following steps. Figure 3

[0105] At step S410, the telecommunication device receives temporary module identification information. In some examples, the telecommunication device receives the temporary module identification information from the network following a successful network connection request. The temporary module identification information can be provided by the mobile network operator to facilitate fast and secure network reconnection from the telecommunication device to the network in subsequent network connections. In some examples, the temporary module identification information comprises a Temporary Mobile Subscriber Identity “TMSI”, or a Globally Unique Temporary UE Identity “GUTI”. The method then proceeds to step S420.

[0106] At step S420, a copy of the temporary module identification information is stored on the subscriber identity module. The method then proceeds to step S430.

[0107] At step S430, a temporary module identification information authenticator is generated based on the temporary module identification information and an identifier of the telecommunication device. In some examples, the temporary module identification information authenticator can be generated using hashing and / or cryptographic techniques. The method then proceeds to step S440.

[0108] At step S440, the temporary module identification information authenticator is stored on a storage module of the telecommunication device. In some examples, the storage module corresponds to one or more of the storage 124 and / or the storage 134 as depicted in Figure 1 The method then proceeds to step S450.

[0109] ​At step S450, in response to the network reconnection procedure, it is verified whether the temporary module identification information exists. In some examples, the verification is performed by the telecommunication device, for example by the modem and / or the application. In other examples, the verification is performed by the remote server. The method then continues with step S460.

[0110] At step S460, the temporary module identification information from the subscriber identity module is verified from the temporary module identification information authenticator and the identifier of the telecommunication device. In some examples, the verification is performed by the telecommunication device, for example by the modem and / or the application. In other examples, the verification is performed by the remote server. The method then continues with step S470 in case of positive verification, or with step S480 in case of negative verification.

[0111] At step S470, in response to the positive verification, the telecommunication device attempts to connect to the network using the temporary module identification information.

[0112] At step S480, in response to the negative verification, the telecommunication device attempts to connect to the network using the module identification information.

[0113] It will be appreciated that in this way, attacks relying on “spoofing” the temporary module identification information can be resisted, since the temporary module identification information is effectively “bound” to the device by the temporary module identification information authenticator. Thus, the temporary module identification information cannot be transferred from a first device to a second device in a way that would allow the second device to successfully connect to the telecommunication network without re-verification of the module identification information.

[0114] It will also be appreciated that, Figure 4 The exact order of the steps depicted in Figs. 4 and 5 is merely illustrative examples, and these steps can be performed in any order, with the information used in the steps being available at the respective elements. For example, step S420 can be performed after steps S430 and S440.

[0115] Figure 5 An example of an electronic device 500 is schematically illustrated, which can be used to implement the telecommunication device 110 and / or the remote server 140 depicted in Figs. 1 and 2, and with respect to Figs. 3 and 4. Figure 1 An example of an electronic device 500 is schematically illustrated, which can be used to implement the telecommunication device 110 and / or the remote server 140 depicted in Figs. 1 and 2, and with respect to Figs. 3 and 4. Figures 2A-4Any of the methods discussed. The device has processing circuitry 510 for performing data processing in response to program instructions, and data storage 520 for storing data and instructions that are processed by the processing circuitry 510. In some examples, the processing circuitry 510 can correspond to processing circuitry that is operable to implement a TEE and a REE. In some examples, the processing circuitry 510 includes one or more caches for caching recent data or instructions. The data storage 520 can have a secure area 530 that is protected by a hardware mechanism (e.g., using a memory protection unit or a security mechanism that provides a TEE) or a software mechanism (e.g., encryption) such that data stored in the secure area 530 is inaccessible to software that is not executing in a trusted environment. The device 500 can have a communication interface 560 for communicating with external devices. For example, the communication interface 560 can use any other range of different communication protocols, e.g., cellular, Ethernet, The device can have one or more sensors 550 for sensing certain external conditions, e.g., temperature, pressure, proximity of nearby users, etc. The particular sensors 550 provided can depend on the purpose of the device. For example, the sensors 550 can include sensors that facilitate biometric authentication, e.g., a fingerprint sensor and a facial recognition camera system. It will be appreciated that, Figure 5 These are merely examples of possible hardware that can be provided in a device, and other components can also be provided. For example, some devices that are intended to have user interaction can be equipped with one or more user input / output devices 540 for receiving input from or outputting information to a user.

[0116] The methods discussed above can be performed under the control of computer programs executed on the device. Thus, the computer programs can include instructions for controlling the device to perform any of the methods described above. The programs can be stored on storage media. The storage media can be non-transitory recording media or transitory signal media.

[0117] In this application, the word "configured" is used to mean that an element of an apparatus has a configuration able to perform the defined operation. In this context, a "configuration" means an arrangement or manner of interconnection of hardware or software. For example, a device can have dedicated hardware which provides the defined operation, or a processor or other processing device can be programmed to perform the function. "Configured" does not imply that the apparatus element needs to be changed in any way in order to provide the defined operation.

[0118] While the illustrative teachings of the disclosure have been described in detail herein with reference to the accompanying drawings, it is to be understood that the teachings of the disclosure are not limited to those precise teachings and that various changes and modifications can be effected therein by one of ordinary skill in the art without departing from the scope and spirit of the disclosure as defined by the appended claims.

Claims

1. A method for remotely performing a secure change of the operating mode of a telecommunications device, the method comprising the telecommunications device performing the following operations: A first secure channel is established between the modem of the telecommunications equipment and the application running in the execution environment of the telecommunications equipment; Establish a second secure channel between the application and the remote server; Enable the modem in restricted operating mode; The modem or the application generates a request to verify the validity of the subscriber identity module of the telecommunications device; The modem obtains module identification information from the subscriber identity module; The application uses the second secure channel to obtain verification information from the remote server, uses the first secure channel to send the module identification information from the modem to the application, and uses the module identification information and the verification information to verify whether the subscriber identity module is valid. The application then uses the first secure channel to send the verification result from the application to the modem. The application obtains verification information from the remote server using the second secure channel, sends the verification information from the application to the modem using the first secure channel, and verifies the validity of the subscriber identity module using the module identification information and the verification information at the modem. The verification information specifies a first time period and a second time period. During the first time period and until the end of the first time period, the telecommunications equipment is in a temporarily unlocked state. In this temporarily unlocked state, the modem can switch to an enhanced operating mode if the verification step is automatically passed. In response to positive verification of the subscriber identity module, the modem is switched from the restricted operating mode to an enhanced operating mode, wherein the method further includes: The following steps are used to periodically re-verify the subscriber identity module: At the end of each of the second time periods, the remote server is contacted to request an extension of the first time period in the verification information. The remote server determines whether the first time period is eligible for extension. In response to each eligibility request to the remote server for extending the first time period, updated verification information is received from the remote server, and the updated verification information is processed to obtain an updated first time period for performing a re-check. In response to a negative verification check, the modem is switched from the enhanced operating mode to the restricted operating mode.

2. The method according to claim 1, wherein, The application is a trusted application, and the execution environment is a trusted execution environment.

3. The method according to claim 1 or claim 2, wherein, When authentication is performed at the application or the modem, the authentication information at the telecommunications device is periodically updated from the remote server.

4. The method according to claim 1 or claim 2, wherein, The verification information specifies a third time period, and after the third time period expires, the telecommunications equipment enters a permanently unlocked state. In this permanently unlocked state, the modem can switch to the enhanced operating mode without performing a verification step or if the verification step passes automatically.

5. The method according to claim 4, wherein, Before obtaining the verification information, the modem switches from the restricted operation mode to the enhanced operation mode during a fourth time period, and If the subscriber identity module is not positively verified before the expiration of the fourth time period, the modem will switch back from the enhanced operation mode to the restricted operation mode after the expiration of the fourth time period.

6. The method according to claim 5, wherein, The determination that the first time period and / or the second time period and / or the third time period and / or the fourth time period has expired is performed by the application using a trusted time source.

7. The method according to claim 1 or claim 2, wherein, When the subscriber identity module is separated from the modem, the modem switches to a restricted operating mode.

8. The method according to claim 1 or claim 2, wherein, When the subscriber identity module is reinserted into the telecommunications equipment, or when a second subscriber identity module is reinserted into the telecommunications equipment, the reinserted subscriber identity module or the second inserted subscriber identity module must be verified before the modem switches back from the restricted operating mode to the enhanced operating mode.

9. The method according to claim 1 or claim 2, wherein, The telecommunications equipment has multiple subscriber identity modules, and the method verifies the validity of all subscriber identity modules individually or collectively.

10. The method according to claim 1 or claim 2, wherein, One or more of the first and second secure channels are established using elliptic curve Diffie-Hellman, elliptic curve Diffie-Hellman temporary key exchange, or any other asymmetric key sharing algorithm.

11. The method according to claim 1 or claim 2, wherein, One or more of the first and second secure channels are established using a key injected into the modem and / or application during manufacturing.

12. The method according to claim 1 or claim 2, wherein, One or more of the first secure channel and the second secure channel are established using a key generated by the modem and / or the application.

13. The method according to claim 1 or claim 2, wherein, Each of the two entities at both ends of the first secure channel and / or the two entities at the end of the second secure channel maintains a counter that monotonically increments during message exchange. The message being sent includes a value derived from a counter of the sending entity, and The receiving entity accepts a message as valid only if the value derived from the counter value is higher than the current counter value of the receiving entity.

14. The method according to claim 1 or claim 2, wherein, The request is generated by the application, which verifies the subscriber identity module and transmits the verification result to the modem via the first secure channel.

15. The method according to claim 1 or claim 2, wherein, The request is generated by the modem, the application provides the verification information to the modem through the first secure channel, and the modem verifies the subscriber identity module.

16. The method according to claim 1 or claim 2, wherein, The module identification information includes the International Mobile Subscriber Identity (IMSI), the Group Identifier (GID), or the Subscription Permanent Identifier (SUPI).

17. The method according to claim 1 or claim 2, wherein, When the telecommunications equipment receives temporary module identification information, it stores a copy of the temporary module identification information on the subscriber identity module, and generates a temporary module identification information authentication character based on the temporary module identification information and the identifier of the telecommunications equipment. The temporary module identification information authentication character is stored in the storage module of the telecommunications equipment. Specifically, when the telecommunications equipment subsequently initiates a network reconnection process and the temporary module identification information is identified as existing on the subscriber identity module, the temporary module identification information from the subscriber identity module is verified based on the temporary module identification information authentication code and the identifier of the telecommunications equipment. In response to positive verification, the telecommunications equipment attempts to connect to the network using the temporary module identification information, and In response to a negative verification, the telecommunications equipment attempts to connect to the network using the module identification information.

18. The method according to claim 17, wherein, The temporary module identification information includes a temporary mobile subscriber identity "TMSI" or a globally unique temporary UE identity "GUTI".

19. The method according to claim 1 or claim 2, wherein, The module identification information is read only once, either when the subscriber identity module is inserted or when the telecommunications equipment is started, and then stored in the cache of the telecommunications equipment. Specifically, when the modem reads the module identification information, the modem reads the module identification information from the cache, and When the telecommunications equipment performs a network connection process, it uses cached module identification information to obtain the module identification information for use in the network connection process.

20. A computer program product for controlling a device to perform the method according to any one of claims 1 to 19.

21. A computer-readable medium storing a computer program product according to claim 20.

22. An apparatus comprising: Processing circuitry, used to perform data processing; as well as A data storage device storing at least one computer program for controlling the processing circuitry to execute the method according to any one of claims 1 to 19.

Citation Information

Patent Citations

  • Subscriber identity module unlocking service portal

    US20080090614A1

  • Secure remote user device unlock

    US20170085546A1