Method for protecting a network access profile against cloning
Patent Information
- Application Number
- CN202180045819.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-06-29
- Filing Date
- 2021-06-16
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2041-06-16
AI Technical Summary
事实上,保护配置文件免遭克隆是对网络运营商来说至关重要的安全挑战
Smart Images

Figure CN115720713B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the general telecommunications field. More specifically, it relates to a method for protecting network access profiles from cloning. Background Technology
[0002] The present invention has particularly advantageous applications within the scope of onboard and therefore non-removable security modules increasingly used in public mobile devices such as mobile terminals or tablet computers. For example, when purchasing a new mobile device, the present invention allows users to transfer their access profile to the new device in a user-friendly manner, while providing operators with all the security guarantees required for their networks, particularly ensuring that no two identical access profiles are active in their networks simultaneously. "Active" means adapted for accessing an operator's network.
[0003] The onboard SIM card standard developed for GSMA, or the "eSIM" of the "eUICC" ("Embedded Universal Integrated Circuit Card") type, and the SSP ("Smart Security Platform") developed by ETSI, do not allow secure transfer of access profiles directly from a first mobile device to a second mobile device to an operator's network. A major obstacle to providing this mechanism is preventing profile cloning. In fact, protecting profiles from cloning is a critical security challenge for network operators.
[0004] However, this profile transfer mechanism can prove useful. In fact, subscribers frequently acquire new mobile devices. Therefore, it is natural to envision providing subscribers with a simple and user-friendly way to transfer their active network access profiles from one device to another without direct interaction with the operator, whether the transfer is end-to-end, through a proxy, or remotely via the internet or telephone, while ensuring the operator is protected from profile cloning, thus guaranteeing the security of their network. Summary of the Invention
[0005] One of the objectives of this invention is to overcome any shortcomings / deficiencies of the prior art and / or to provide improvements thereto.
[0006] To this end, the present invention proposes a method for protecting network access profiles from cloning. A first mobile device includes a security module called a "first security module," which includes the network access profile. A second mobile device is designed to receive the network access profile and includes a security module called a "second security module." The first and second security modules are respectively designed to establish logical communication channels with the first and second security modules. The method includes the following steps implemented by the first security module:
[0007] - Generate a secret key;
[0008] - The data packets associated with the network access profile are encrypted using the secret key, and the encrypted packets are sent to the second security module through the logical communication channel;
[0009] - Receive a reception confirmation from the second security module indicating that the encrypted data packet has been correctly received;
[0010] - Delete the data packet associated with the network access profile, and then send the secret key to the second security module through the logical communication channel.
[0011] The described method provides network operators with a guarantee that no two identical and active (in other words, adapted for network access) access profiles exist within their network. In fact, the method guarantees that when a network access profile is transferred from a first mobile device to a second mobile device, the transferred network access profile only becomes active from the moment the access profile is deleted from the first mobile device. This method provides operators with a solution to prevent the cloning of network access profiles. In fact, the network access profile and the secret key pair that allows it to be encrypted and / or decrypted always exist in at most a single security module. Therefore, at any given time, a clone of a decrypted access profile in one security module cannot coexist with the decrypted profile itself in another security module. Furthermore, it is impossible to successfully attack two mobile devices and two security modules to attempt to clone the network access profile by inducing a fault, such as a reset, in either terminal and its corresponding security element.
[0012] The security of this method involving the exchange of security modules relies on the security of the security modules themselves, rather than on the security of the mobile device. Therefore, when implementing the transfer method, the risk of attack is limited, and the security modules are designed to provide a high level of security.
[0013] Advantageously, the method includes the following steps implemented by the second security module:
[0014] - Receive encrypted data packets associated with the network access profile;
[0015] - Send confirmation of successful reception of the encrypted packet;
[0016] -Receive the secret key;
[0017] - Decrypt the encrypted data packets using the received secret key.
[0018] The steps described in this article correspond to those implemented by the second mobile device and its associated security module.
[0019] In one embodiment, the logical communication channel is a secure channel.
[0020] In this embodiment, the logical communication channel established between the security modules of the first and second mobile devices is a secure channel; in other words, this channel provides a set of security procedures based on proven cryptographic algorithms. When the secure logical communication channel is established, mutual authentication exists between the two security modules. This mutual authentication, based on public key certificates stored separately in each security module, ensures that each security module communicates with the real module. Furthermore, the channel established between the two security modules is encrypted. Therefore, a pirate, for example, who has control of one of the mobile devices and will see the data flowing through the channel, will be unable to interpret that data. For example, they will not be able to access the transmitted encryption key required to decrypt the encrypted transfer access profile. This security provides the operator with an additional guarantee: attackers cannot obtain the network access profile and therefore cannot clone it.
[0021] Finally, ensuring channel security provides protection against "man-in-the-middle" attacks, during which an attacker positioned between two devices (e.g., two security modules in this case) can eavesdrop on communication channels and collect sensitive information.
[0022] In one embodiment, the secret key is generated according to a method (“onboard key generation”) integrated into the first security module for generating keys in the security module.
[0023] In this embodiment, the encryption key is a random key generated using a method integrated into the security module. Operators prefer this key generation method because it provides the possibility of being integrated into the security module as an additional security guarantee.
[0024] In another embodiment, a secret key is generated by applying a key diversification algorithm stored in a first security module to a diversification key stored in a network access configuration file.
[0025] In this alternative embodiment, a diversity key is included in the network access profile and used within the security module to generate encryption keys.
[0026] In one embodiment, where the logical communication channel is secure, the method further includes the following steps implemented by a second security module:
[0027] - Check the integrity of the encrypted received network access data packets of the first security module; and
[0028] - Check the integrity of the received encryption key for the encryption of the first security module.
[0029] The present invention also relates to a security module, referred to as a first security module, included in a first mobile device, the first security module including a network access configuration file, and a second device including a security module, referred to as a second security module, wherein the first security module and the second security module are adapted to establish a logical communication channel, the security module comprising:
[0030] - A device for generating secret keys, which is designed to generate secret keys;
[0031] - A device for encryption and transmission, which is designed to encrypt data packets associated with a network access profile using the secret key and to transmit the encrypted packets to a second security module via a logical communication channel;
[0032] - A receiving device, which is designed to receive a reception acknowledgment from a second security module indicating that the encrypted data packet has been correctly received;
[0033] - Deletion device, which is designed to delete data packets associated with a network access profile; and
[0034] - A transmitting device, which is designed to transmit the secret key to a second security module via a logical communication channel.
[0035] In one embodiment, the security module further includes:
[0036] - A second receiving device, which is designed to receive encrypted data packets associated with a network access profile;
[0037] - A transmitting device, which is designed to send a reception acknowledgment indicating that the encrypted data packets have been correctly received;
[0038] - A third receiving device, designed to receive a secret key;
[0039] - A decryption device designed to decrypt encrypted data packets using a received secret key.
[0040] In this embodiment, the mobile device associated with the security module is designed to: on the one hand, initiate a transfer of a network access profile to the security module associated with another mobile device, and on the other hand, receive an access profile from another mobile device associated with the security module.
[0041] The present invention also relates to a program for a security module associated with a mobile device, the program including program code instructions that, when executed on the device associated with the module, are designed to control the execution of steps of the method described above for protecting network access profiles from cloning.
[0042] The present invention also relates to a data medium in which the aforementioned program is stored.
[0043] The present invention also relates to a mobile device that includes the security module described above. Attached Figure Description
[0044] Further features and advantages of the invention will be better understood from the specific embodiments and accompanying drawings, in which:
[0045] - Figure 1 The steps of a method for protecting a network access profile from cloning, according to one embodiment, are shown.
[0046] - Figure 2 This is an illustrative representation of a security module associated with a mobile device according to one embodiment, the security module being capable of implementing steps for a method of protecting a network access profile from cloning. Detailed Implementation
[0047] Now refer to Figure 1 The steps of a method for protecting a network access profile from cloning according to a first embodiment are described.
[0048] User (the user in) Figure 1 A first mobile device 10 (not shown) (e.g., a mobile terminal or tablet computer) is equipped with a security module 101, such as an onboard and therefore potentially non-removable module, like an eSIM ("embedded subscriber identity module") module of the eUICC ("embedded universal integrated circuit card") type. The security module 101 includes its specific public key certificate, wherein the public key is associated with a private key stored on the security module 101 by computation. The certificate conforms to, for example, the X.509v3 standard; the certificate is issued by a trusted authority and has been installed at the factory, for example, on the security module 101 along with the associated private key. The public key certificate may be specific to a cloning protection method. In another embodiment, the public key certificate is also designed to implement other trusted operations not described herein within the network. The security module 101 of the first mobile device also includes a user-to-operator (CIO) communication mechanism. Figure 1 (Not shown in the image) The network access profile associated with the service ordered. It is assumed that the user has already activated their network access profile; in other words, the profile is adapted for network access.
[0049] The second mobile device 11 includes an onboard security module 111. Like security module 101, security module 111 also includes its own public key certificate, wherein the public key is associated with a private key stored on security module 111 by computation.
[0050] For simplicity, the security module 101 of the first mobile terminal 10 can also be referred to as "first security module 101". Similarly, the security module 111 of the second mobile device 11 can also be referred to as "second security module 111".
[0051] First mobile device 10 and second mobile device 11 each include software applications 102 and 112, thereby providing profile management functionality for the mobile devices. The software applications include code instructions designed to implement steps of the methods described herein, and these steps are implemented by mobile devices 10 and 11. In one embodiment, the application is integrated into an "LPA" ("Local Profile Assistant") type profile or local manager profile, typically designed to request and obtain network access profiles from an operator's data server via a secure internet connection, and to control the installation and activation of the profile on a security module.
[0052] The first security module 101 and the second security module 111 each include software applications 103 and 113 that interface with applications 102 and 112 of the associated mobile devices 10 and 11. These applications include code instructions designed to implement steps of a method for protecting network access profiles from cloning, steps performed by security modules 101 and 111.
[0053] This document describes a method for protecting a network access profile from cloning in the context of transferring a network access profile from the security module 101 of a first mobile device 10 to the security module 111 of a second mobile device 11. In another embodiment not described, the method may be implemented when transferring a security profile from the first security module to the second security module of the same mobile device.
[0054] It is assumed that prior to the steps of the method described herein, a logical control channel has been established between the security module 101 of the first mobile device 10 and the security module 111 of the second mobile device 11 according to a known method.
[0055] In the embodiments described herein, the logical communication channel is secure. Therefore, the logical communication channel is authenticated and protected in terms of confidentiality and integrity. This secure channel is established according to known methods (e.g., based on the TLS (“Transport Layer Security”) protocol or the DTLS (“Datagram Transport Layer Security”) protocol). Establishing a secure logical communication channel involves mutual authentication between the two security modules 101 and 111. In this example, a secure communication logical channel is established using public key certificates included in security modules 101 and 111. It should be noted that the secure communication logical channel is established between the two security modules 101 and 111. Therefore, end-to-end data transfer security between the two security modules is guaranteed. The two security modules 101 and 111 have implemented TLS- or DTLS-specific mutual authentication on a message exchange basis according to the protocol used to establish the secure logical communication channel.
[0056] exist Figure 1 In another embodiment not shown, the logical communication channel established between the two security modules is insecure. For example, this embodiment can be implemented in a controlled environment (in other words, in a secure environment, such as one provided and managed by a network operator).
[0057] In the initial key generation step E01, the first security module 101 generates a secret key Kp intended for use by a secret key encryption algorithm to encrypt data. In the clone protection method, the secret key Kp is intended to encrypt data from the configuration file to be transferred, extracted from security module 101. This secret key is also intended to be subsequently used by the second security module 111 to decrypt the encrypted configuration file data.
[0058] In the first embodiment, the secret key Kp is generated based on a method for generating random keys integrated into the security module, known as "OBKG" (On-Board Key Generation). This method is appreciated by network operators because security is based solely on the security of the security module.
[0059] In another embodiment, when installed on security module 101, the diversification key stored in the network access configuration file is used as a parameter of the key diversification algorithm included in security module 101 to generate secret key Kp.
[0060] In the subsequent step E02 of preparing the configuration file data, the first security module 101 extracts data corresponding to the network access configuration file to be transferred and generates packets or "packets" of the data to be transferred corresponding to the access configuration file. Preparing the configuration file data involves formatting the data of the configuration file to obtain data packets designed to interoperate with other security modules.
[0061] In the subsequent encryption and transmission step E03, the security module 101 of the first mobile device 10 encrypts the data packet to be transferred by applying an encryption algorithm configured with the secret key Kp generated during step E01. The security module then sends the encrypted data packet to the security module 111 of the second mobile device 11. At the end of step E03, the security module 111 of the second mobile device 11 receives the encrypted data packet of the profile to be transferred. It should be noted that the security module 111 of the second mobile device 11 cannot decrypt the received encrypted data packet. In fact, this security module does not have the secret key Kp. At this stage, a single network access profile exists and may be active in the network: that is, the network access profile included in the security module 101 of the first mobile device 10.
[0062] In the embodiments described herein, where the logical communication channel established between the two security modules 101 and 102 is secure, the data of the configuration file to be transferred is protected both by encryption with the secret key Kp and by the encryption inherent in the secure communication channel. Furthermore, the data packets of the transferred configuration file benefit from the integrity checks inherent in the established secure communication channel.
[0063] In the subsequent integrity check step E04, the security module 111 of the second mobile device 11 performs an integrity check on the encrypted data packets. This integrity check aims to ensure that the received encrypted data packets are identical to the encrypted data packets sent by the security module 101 of the first mobile device 10 during step E03, and have not been altered during the transfer between the first security module 101 and the second security module 111. The integrity check is performed according to a known method for verifying an authentication code of the HMAC (Hash-Based Message Authentication Code) type specific to the security protocol used to establish a secure communication channel.
[0064] It should be noted that when the logical communication channel is insecure, integrity check step E04 is not performed.
[0065] In the embodiments described herein, if an integrity check is performed during step E04 and the check result is negative, indicating that the encrypted data packets of the received configuration file have been altered, the method stops. In this case, Figure 1 During the steps not shown, a message is displayed on the screen of the first mobile device 10 to draw the user's attention and notify them of the failure of the current program (e.g., transfer of access profile).
[0066] In the subsequent step E05 after sending the receipt confirmation, the second security module 111 sends the receipt confirmation of the encrypted data packet to the first security module 101, thereby confirming the correct reception of the packet.
[0067] In the embodiments described herein, if the logical communication channel is secure, an indicator confirming the result of the data integrity check performed in integrity check step E04 is received.
[0068] In step E06, which involves deleting the configuration file after receiving the confirmation of receipt, the first security module 101 deletes its previously stored network access configuration file.
[0069] It should be noted that at this stage, only a single data packet corresponding to the network access profile exists, namely, the data packet stored in the security module 111 of the second mobile device 11. However, the data packet is encrypted, and the second security module 111 does not have the secret key Kp used to decrypt the data packet. Therefore, at this stage, network access is not possible based on the service provisioning associated with the access profile, and the service proposal is temporarily unavailable.
[0070] In the subsequent step E07 of sending the secret key, the first security module 101 sends the secret key Kp to the second security module 101 via the previously established logical communication channel. At the end of step E07, the second security module 101 receives the secret key Kp.
[0071] In the embodiments described herein, when the logical communication channel between the two security modules 101 and 111 is secure, the secret key Kp is securely transmitted via encryption inherent in the secure logical channel. When the logical communication channel is insecure, the secret key Kp is transmitted to the second security module 111 in plaintext.
[0072] In the subsequent step E08, which checks the integrity of the secret key, the integrity of the received encrypted secret key Kp is verified. This integrity check is performed by the second security module 111 by verifying the HMAC authentication code inherent in the security assurance of the communication channel. If the integrity check result is negative, indicating that the transmitted encrypted secret key Kp has been altered during its transmission, the method stops. In this case, in Figure 1 During the steps not shown, a message is displayed on the screen of the second mobile device 11 to draw the user's attention and notify them of the failure of the current program (e.g., transfer of access profile).
[0073] It should be noted that this step should not be performed when the logical communication channel is insecure.
[0074] In step E09, the secret key Kp is decrypted. The secret key Kp is decrypted using data inherent in the secure communication logic channel. At the end of step E09, the second security module 111 possesses the secret key Kp.
[0075] It should be noted that this step should not be performed when the logical communication channel is insecure. In this case, the secret key Kp is not actually encrypted.
[0076] In step E10, which decrypts the encrypted data packets, the second security module 111 proceeds to decrypt the encrypted data packets of the configuration file received during step E03. For this purpose, the second security module uses a secret key Kp as a parameter for the encryption algorithm used to encrypt the configuration file data. At the end of step E10, the security module 111 of the second mobile device 11 has data related to the network access configuration file extracted from the security module 101 of the first mobile device 10 during step E02, which prepares the configuration file data.
[0077] Therefore, at the end of decryption step E10, only the security module 111 of the second mobile device 11 has the data packets corresponding to the network access profile.
[0078] In the subsequent step E11 of installing the configuration file, the second security module 111 installs and activates the network access configuration file. For example, Figure 1 The configuration file manager LPA (not shown) controls the installation and activation of configuration files on the second security module 111.
[0079] In step E12, which involves sending an optional confirmation of receipt, the security module 111 of the second mobile device 11 sends a message to the security module 101 of the first mobile device 11, notifying it of the correct installation and activation of the network access profile. This message is transmitted to the first mobile device 10 and / or the second mobile device 11 to notify the user that the transfer of the network access profile has been correctly performed within the context of the current application. This step is optional because the user can be notified of the correct installation and activation of the network access profile via the second mobile device 11.
[0080] It should be noted that if problems arise during the method used to securely transfer network access profiles, users may no longer have their network access profiles. In this case, the operator can be asked to proceed to the second mobile device 11 to install and activate their profiles. Under no circumstances is there a clone of the access profile, and the security of the network remains unquestionable.
[0081] As described above, the method for protecting access profiles from cloning can be easily integrated into other methods, such as methods for securely transferring access profiles from a first mobile device to a second mobile device. In this example, and during the previous steps (not shown), the two mobile devices 10 and 11 can be paired according to a known method, and then the two security modules 101 and 102 of the two mobile devices 10 and 11 can establish a secure communication logical channel in order to initiate the transfer of the network access profile from the first security module to the second security module as described above. Therefore, this method can be advantageously used by users themselves (in other words, without contacting the operator) to transfer their network access profiles to a security module they have recently acquired and included in the second device.
[0082] Now refer to Figure 2 Security module 101 describes the steps of implementing the method described above for protecting network access profiles from cloning.
[0083] For example, security module 101 is an embedded SIM card of type eUICC. It should be noted that security module 101 described herein is equally capable of initiating the transfer of its stored access profile and receiving such a profile. Therefore, security module 101 described herein equally implements the steps of the above-described method implemented by the first security module 101 and the steps implemented by the second security module 111.
[0084] Security module 101 includes:
[0085] - A processing unit or processor 101-1 or "CPU" ("Central Processing Unit") is designed to load instructions into memory and execute those instructions to perform operations;
[0086] A set of memories, including volatile memory 101-2 or "RAM" ("Random Access Memory") for executing code instructions, storing variables, etc.; and storage memory 101-3 of the "EEPROM" ("Electrically Erasable Programmable Read-Only Memory") type. Specifically, storage memory 101-3 is designed to store a software module including code instructions for implementing the steps of the method described above for protecting network access profiles from cloning, implemented by security module 101. Storage memory 101-3 is also designed to store the private key associated with the public key certificate and the network access profile in a secure area. Volatile memory 101-2 is also designed to store the secret key Kp generated during step E01. Security module 101 also includes an interface for communicating with mobile device 10. Figure 2 Not shown in the image.
[0087] Security module 101 also includes:
[0088] - Module 101-4 for establishing a logical communication channel is designed to establish a logical communication channel with a security module of a second mobile device intended to transfer a network access profile to it. In the embodiments described herein, the logical channel is secure, thus providing an authenticated channel protected in terms of confidentiality and integrity. In this embodiment, module 101-4 for establishing the logical communication channel integrates a software module (not shown) capable of implementing mutual authentication between security module 101 and the second security module 102, encrypting data transmitted through the channel, and performing integrity checks on data transmitted through the channel. Module 101-4 performs one of the preceding steps ( Figure 1 (not shown in the image);
[0089] - Module 101-5 for generating a secret key is designed to enable security module 101 to generate a secret key Kp intended for encrypting data packets associated with data in the configuration file to be transferred. Generation module 101-5 is designed to implement step E01 of the method described above for protecting the configuration file from cloning;
[0090] - Encryption and transmission module 101-6 is designed to encrypt data packets associated with a network access profile using the secret key, and to transmit the encrypted packets to a second security module via a logical communication channel. Encryption and transmission module 101-6 is designed to implement step E03 of the method for protecting the profile from cloning as described above;
[0091] - Receiver module 101-7 is designed to receive a reception acknowledgment from the second security module indicating successful reception of the encrypted data packet. Receiver module 101-7 is designed to implement step E05 of the method for protecting the configuration file from cloning as described above; and
[0092] - Deletion module 101-8 is designed to delete data packets associated with a network access profile. Deletion module 101-8 is designed to implement step E06 of the method for protecting the profile from cloning as described above;
[0093] - Sending module 101-9 is designed to send the secret key to the second security module via a logical communication channel. Sending module 101-9 is designed to implement step E07 of sending the secret key as described above in the method for protecting the configuration file from cloning.
[0094] The modules 101-4 for establishing a logical communication channel, 101-5 for generating a secret key, 101-6 for encryption and transmission, 101-7 for receiving, 101-8 for deleting, and 101-9 for sending are preferably software modules, which include software instructions for implementing the steps of the method described above for protecting network access profiles from cloning.
[0095] In one embodiment, when security module 101 acts as a second security module 102, security module 101 further includes:
[0096] - Module 101-10 for receiving encrypted data packets associated with a network access profile. Module 101-10 is designed to implement step E03 of the method for protecting a network access profile from cloning as described above, in which the step is implemented by a second security module;
[0097] - Module 101-11 for sending a receipt acknowledgment is designed to send a receipt acknowledgment indicating that the encrypted data packets have been correctly received. The sending module 101-11 is designed to implement step E05 of the method described above for protecting network access profiles from cloning.
[0098] - The second receiving module 101-12 is designed to receive a secret key. The second receiving module 101-12 is designed to implement step E07 of the method for protecting network access profiles from cloning as described above;
[0099] - Decryption module 101-13 is designed to decrypt encrypted data packets using the received secret key. Decryption module 101-13 is designed to implement step E10 of the method for protecting network access profiles from cloning as described above;
[0100] -Optionally, a module for sending a receipt confirmation ( Figure 2 (Not shown in the image). This module is designed to use the first security module 101 to verify: the correct reception of encrypted packets associated with the network access profile, the correct encryption of the encrypted packets, and the correct installation and activation of the profile obtained by decrypting the encrypted packets on the security module 101.
[0101] This invention also relates to:
[0102] - A program for a security module associated with a mobile device, the program including program code instructions that, when executed on the security module, are designed to control the execution of steps of the method described above for protecting a network access profile from cloning;
[0103] - A readable recording medium on which the above-mentioned program is stored.
[0104] The present invention also relates to a mobile device that includes the security module described above.
Claims
1. A method for protecting a network access profile from cloning, wherein a first mobile device includes a security module referred to as a "first security module," the first security module including the network access profile, and a second mobile device is configured to receive the network access profile, the second mobile device including a security module referred to as a "second security module," wherein... The first security module and the second security module are respectively designed to establish logical communication channels with the second security module and the first security module, respectively. The method includes the following steps implemented by the first security module: - Generate a secret key; - The data packets associated with the network access profile are encrypted using the secret key, and the encrypted packets are sent to the second security module via the logical communication channel; - Receive a reception confirmation from the second security module indicating that the encrypted data packet has been correctly received; - Upon receiving the confirmation from the second security module, the data packet associated with the network access profile stored in the first security module of the first mobile device is deleted, and then the secret key is sent to the second security module via the logical communication channel for decrypting the encrypted data packet associated with the network access profile.
2. The method for protecting network access configuration files from cloning as described in claim 1, comprising the following steps implemented by the second security module: - Receive the encrypted data packet associated with the network access profile; - Send a receipt confirmation acknowledging that the encrypted packet has been correctly received; - Receive the secret key to decrypt the encrypted data packet associated with the network access profile; - Decrypt the encrypted data packet using the received secret key.
3. The method for protecting network access configuration files from cloning as described in claim 1, wherein, This logical communication channel is a secure channel.
4. The method for protecting network access configuration files from cloning as described in claim 1, wherein, The secret key is generated according to the method for generating keys in the security module integrated in the first security module.
5. The method for protecting network access configuration files from cloning as described in claim 1, wherein, The secret key is generated by applying the key diversification algorithm stored in the first security module to the diversification key stored in the network access configuration file.
6. The method for protecting network access configuration files from cloning as described in claim 2, further comprising the following steps implemented by the second security module: - Check the integrity of the encrypted received data packets of the first security module; and - Check the integrity of the secret key received by the first security module.
7. A security module, referred to as a first security module, included in a first mobile device, the first security module including a network access configuration file; a second device including a security module, referred to as a second security module; the first security module and the second security module being adapted to establish a logical communication channel; the security module comprising: - A device for generating secret keys, which is designed to generate secret keys; - A device for encryption and transmission, which is designed to encrypt data packets associated with the network access profile using the secret key, and to transmit the encrypted packets to the second security module via the logical communication channel; - A receiving device, which is designed to receive from the second security module a reception acknowledgment indicating that the encrypted data packet has been correctly received; - A deletion device, which is designed to delete the data packet associated with the network access profile stored in the first security module of the first mobile device after receiving the confirmation from the second security module; as well as - A transmitting device, which is designed to then transmit the secret key to the second security module via the logical communication channel for decrypting the encrypted data packets associated with the network access profile.
8. The security module of claim 7, further comprising: - A second receiving device, which is designed to receive the encrypted data packets associated with the network access profile; - A transmitting device designed to send a reception acknowledgment indicating that the encrypted data packets have been correctly received; - A third receiving device, which is designed to receive the secret key for decrypting the encrypted data packets associated with the network access profile; - A decryption device designed to decrypt the encrypted data packet using a received secret key.
9. A non-transitory computer-readable data medium storing program code instructions that, when executed by a processor of a first security module included in a first mobile device, configure the first security module to control the execution of a method for protecting a network access profile from cloning, the first security module including the network access profile, a second mobile device configured to receive the network access profile, the second mobile device including a second security module, the first security module and the second security module being respectively configured to establish logical communication channels with the second security module and the first security module, the method comprising the following steps implemented by the first security module: - Generate a secret key; - The data packets associated with the network access profile are encrypted using the secret key, and the encrypted packets are sent to the second security module via the logical communication channel; - Receive a reception confirmation from the second security module indicating that the encrypted data packet has been correctly received; - Upon receiving the confirmation from the second security module, the data packet associated with the network access profile stored in the first security module of the first mobile device is deleted, and then the secret key is sent to the second security module via the logical communication channel for decrypting the encrypted data packet associated with the network access profile.
10. A mobile device comprising the security module as claimed in claim 7 or claim 8.
Citation Information
Patent Citations
Method for transferring profile and electronic device supporting the same
US20160241537A1