Terminal device having auxiliary module for managing telecommunications profile stored in terminal device, and management method

By setting up two auxiliary modules in the terminal device, one in the embedded identification module and the other in the device itself, only one auxiliary module is activated within any time period, the problem of insufficient security and flexibility of telecommunications configuration file management in the Internet of Things devices is solved, and efficient and secure configuration file management is achieved.

CN120345274APending Publication Date: 2025-07-18GIESECKE & DEVRIENT EPAYMENTS GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202380086928.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-21
Filing Date
2023-12-20
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

Existing methods of end devices in managing telecommunications profiles cannot be effectively applied to IoT devices, especially due to their limited hardware and user interface, resulting in insufficient security and flexibility.

Method used

There are two auxiliary modules in the terminal device, one in the embedded recognition module and the other in the device itself, only one auxiliary module is activated within any time period, and flexible configuration file management operations are realized through different activation methods.

Benefits of technology

It realizes efficient and secure management of telecommunications profiles in IoT devices, with the advantages of embedded and auxiliary modules, and improves the flexibility and security of the device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120345274A_ABST
    Figure CN120345274A_ABST
Patent Text Reader

Abstract

The invention relates to a terminal (50) having an embedded identification module (70), which is designed to carry out a profile management operation, by means of which a telecommunications profile (80) stored in the embedded identification module (70) can be changed or a new telecommunications profile (80) can be loaded, the embedded identification module (70) has a first auxiliary module (72), which provides a first interface to the remote management unit (20), and a second auxiliary module (72), which is connected to the embedded identification module (70) and provides a second interface to the profile provision entity (10). At the same time, either the first auxiliary module (72) or the second auxiliary module (52) is in an active state. A terminal device (50) acquires a command data set containing a profile management operation from a remote management unit (20). When the profile management operation involves a change in the state of the telecommunications profile (80) stored in the embedded identification module (70), the first auxiliary module (72) is in an active state and causes the profile management operation to be performed. When the profile management operation involves the loading of the new profile (80), the second auxiliary module (52) is in an active state and causes the profile management operation to be performed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the management of a telecommunications profile in a terminal device that can be controlled via a data network, the terminal device having a limited network entry or a limited user interface. Background Art

[0002] The GSMA (GSM Association) has developed a standardized architecture for remotely providing eSIM profiles for end-user devices and M2M devices. For the former, a Local Profile Assistant (LPA) is set up on the user device, which controls the lifecycle of the profiles on the device. The loading of the eSIM profile is initiated by the user. The standard for M2M devices is based on the use of SMS messages and requires the integration of the entities involved. Neither of these two known solutions can be applied to Internet of Things (IoT) devices, or can only be applied to IoT devices with deficiencies. IoT devices usually only have limited hardware devices and do not have their own user interface.

[0003] DE 102021127364 A1 discloses an implementation method for securely connecting an IoT device to a wireless network, wherein the IoT device communicates with an authentication server via an access point to obtain access data for the network.

[0004] US 20220295281 A1 describes a system for reconfiguring an embedded identification module in a terminal device, wherein an identification profile can be provided to the terminal device by a server via a remote management unit (“remote IoT manager”).

[0005] The new GSMA standard SGP.31 “eSIM IoT Architecture and Requirements” (version 1.0, April 19, 2022) describes a remote management architecture for telecommunications profiles specifically for IoT devices. The new standard is based on the GSMA standard SGP.21 for user terminals and adopts key elements thereof, including the scheme of the profile provision entity (SM-DP+). A remote management unit associated with the IoT device and the profile provision entity (SM-DP+) and an auxiliary module that can be implemented in two variant schemes are newly introduced compared with the known architectures. In the first variant scheme, the support module is part of the IoT device; in the second variant scheme, the support module is formed in the identification module embedded in the IoT terminal device. This architecture enables the loading and changing of the profiles stored in the embedded identification module through profile management operations. The download of the telecommunications profile is always carried out between the support module and the profile provision entity regardless of the implementation method.

[0006] Both of these implementation methods have their own advantages and disadvantages. Compared with the embedded recognition module, the auxiliary module is more complex to implement in the Internet of Things terminal device and has lower security. However, its performance is stronger and more flexible than that of the embedded recognition module. Summary of the Invention

[0007] The technical problem to be solved by the present invention is to provide a terminal device that combines the advantages of these two implementation methods.

[0008] The above technical problem is solved by a terminal device and a method having the features of the independent claims.

[0009] The terminal device according to the present invention is characterized in that a first auxiliary module is provided in the embedded recognition module, and a second auxiliary module is provided in the terminal device itself, wherein only one of the two auxiliary modules is always activated. The activation of the first or second auxiliary module defines two operating modes.

[0010] The advantage of dividing into two auxiliary modules is that the first auxiliary module can be flexibly adapted to the given situation. When the remote management unit only assists in the profile status operation, the first auxiliary module in the embedded recognition module can be designed to be very simple. Since the profile status operation only requires a small amount of data, only a low performance requirement is needed for the first auxiliary module when implemented in the embedded recognition module.

[0011] The embedded recognition module equipped with the corresponding first auxiliary module can be set in a simple manner by being downloaded to the terminal device.

[0012] Embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Description of the Drawings

[0013] In the accompanying drawings:

[0014] Figure 1 shows an architecture for setting and managing a telecommunication profile in an embedded recognition module stored in an Internet of Things terminal device,

[0015] Figure 2 shows the process of the profile status operation,

[0016] Figure 3 shows loading a profile from a profile providing entity into the embedded recognition module. Detailed Embodiment

[0017] Figure 1Shows an architecture for setting and managing a telecommunication profile in an embedded identification module stored in an Internet of Things terminal device. The architecture includes a profile providing entity 10 (Subscription Manager Data Preparation, abbreviated as SM-DP+), a remote management unit 20 (eSIM Internet of Things Remote Manager, abbreviated as eIM), a switching server 30 (Subscription Manager Discovery Server, abbreviated as SM-DS), a network operator 40, and a terminal device 50 as described in GSMA standard SGP.31-v1.0.

[0018] In the terminal device 50, there is a profile support module 60 and an embedded identification module 70 composed of two components 52, 72. In the embedded identification module 70, there is constructed a home domain 74 (ISD-R) of the issuer and at least one profile domain 76 (ISD-P), which is also known from GSMA standard SGP.31-v1.0. In each profile domain 76 (ISD-P), there is a security area 78 (MNO-SD) of the network operator 40. At least one telecommunication profile 80, hereinafter also simply referred to as a profile, is stored in the security area 78 (MNO-SD). Figure 1 Each component of the shown architecture provides one or more interfaces, and the components are interconnected with each other via data connections and / or data networks by means of these interfaces, as described in detail below.

[0019] The profile providing entity 10 (SM-DP+) has the function of securely providing a profile package containing the telecommunication profile 80 for download.

[0020] The function of the remote management unit 20 (eIM) is to set and manage the profile 80 stored in the embedded identification module 70 (eUICC). For this purpose, the remote management unit 20 (eIM) controls the loading of the profile 80 into the embedded identification module 70 (eUICC) by means of a command data set, and controls the change of the state of the stored profile 80. The command data set contains profile management operations for this purpose, in particular a loading operation (profile download) and a profile state operation (Profile State Management Operation, abbreviated as PSMO). Optionally, the remote management unit 20 (eIM) can set up to convert the profile data packet in the context of the loading process in order to convert it into the protocol required for interface use, for example, into a narrowband protocol.

[0021] The task of the switching server 30 (SM-DS) is to provide the address of the profile providing entity 10 (SM-DP+) in response to a determination request from the connected components 20, 50.

[0022] The network operator 40 is, for example, a mobile network operator.

[0023] The terminal device 50 can be, for example, a component in daily-use products such as an automobile or a camera, or a component of a sensor unit. It usually does not have a user interface. The terminal device 50 can in particular be an Internet of Things terminal device.

[0024] The profile support module 60 communicates with the profile providing entity 10 (SM-DP+), the remote management unit 20 (eIM), and the embedded identification module 70 (eUICC), and is capable of loading the profile 80 into the embedded identification module 70 (eUICC) and changing the status of the loaded profile 80.

[0025] The embedded identification module 70 is designed, for example, as an eUICC, that is, a HW element protected both in terms of hardware and software and installed in the terminal device 50.

[0026] In this regard, the architecture and its components correspond to the GSMA standard SGP.31-v1.0 or related standards.

[0027] Differently from the architecture according to the GSMA standard SGP.31-v1.0, in Figure 1 the shown architecture according to the present invention, the profile support module 60 consists of two components, namely a first auxiliary module 72 (IPAe) and a second auxiliary module 52 (IPAd). The first auxiliary module 72 (IPAe) is constructed in the embedded identification module 70 (eUICC). The second auxiliary module 52 (IPAd) is designed as a component of the terminal device 50.

[0028] The components 10, 20, 30, 40, 50, 52, 70, 72 respectively provide one or more interfaces, and the components are interconnected with each other via the common data connection and / or data network by means of the interfaces.

[0029] The profile providing entity 10 (SM-DP+) provides interfaces 100 (ES8+), 110 (ES9+'), 120 (ES9+), 130 (ES12), and 140 (ES2+) to the remote management unit 20 (eIM), the switching server 30 (SM-DS), the second auxiliary module 52 (IPAd), and the network operator 40. The profile providing entity 10 (SM-DP+) communicates with the second auxiliary module 52 (IPAd) through the protocol and interface defined in the GSMA standard SGP.22. In this way, in particular, the profile providing entity 10 (SM-DP+) according to the GSSMA standard SGP.22 can be used to implement the architecture without implementing a special communication channel for communication with the second auxiliary module 52 (IPAd).

[0030] The first auxiliary module 72 (IPAe) provides an external interface 150 (ES8+) to the remote management unit 20 and an external interface 160 (E11) to the switching server 30 (SM-DS). The first auxiliary module also has an interface 200 to the profile domain 76 (ISD-P) within the embedded identification module 70.

[0031] The second auxiliary module 52 (IPAd) is connected within the terminal device 50 to the embedded identification module 70 (eUICC) via internal interfaces 220, 230 and has an external interface 170 (ESipa) to the remote management unit 20 (eIM).

[0032] The second auxiliary module 52 (IPAd) is arranged for data exchange with the profile providing entity 10 (SM-DP+) in order to load a new profile 80 into the embedded identification module 70 (eUICC). The communication between the second HW auxiliary module 52 (IPAd) and the profile providing entity 10 (SM-DP+) takes place via a second protocol, preferably via the protocol defined in SGP.22.

[0033] The second auxiliary module 52 (IPAd) can request and receive an activation code from the remote management device 20 (eIM) via the side interface 170 (ESipa).

[0034] The security area 78 (MNO-SD) of the network operator in the embedded identification module 70 (eUICC) also has an external interface 240 (ES6) to the network operator 40 via the terminal device 50.

[0035] Via the interface 140 (ES2+) between the network operator 40 and the profile providing entity 10 (SM-DP+), the network operator 40 controls the management functions according to the GSMA standard SGP.21 and reserves a profile 80 for the embedded identification module 70 (eUICC).

[0036] Via the interface 240 (ES6) between the network operator 40 and the embedded identification module 70 (eUICC), the network operator 40 manages the profile content by means of OTA services.

[0037] Via the logical interfaces 100, 150 (ES8+) existing between the first auxiliary module 72 IPAe and the profile providing entity 10 (SM-DP+) and between the second auxiliary module 52 IPAd and the profile providing entity 10 (SM-DP+), a secure end-to-end connection is provided for managing the profile domain 76 (ISD-P) and the profiles stored therein during the download and installation process.

[0038] The secure transmission of the profile package is achieved by configuring an interface 120 (ES9+) between an entity 10 (SM-DP+) and a second auxiliary module 52 (IPAd). The profile package is in the form of, for example, a bound profile package.

[0039] The secure transmission of the profile data packet is achieved by configuring an interface 110 (ES9+') between a profile providing entity 10 (SM-DP+) and a remote management unit 20 (eIM). The remote management unit 20 (eIM) processes on behalf of a first auxiliary module 72 (IPAe).

[0040] Through an interface 220 (ES10a) between a second auxiliary module 52 (LPAd) and an embedded identification module 70 (eUICC), the second auxiliary module 52 (IPAd) receives the addresses for configuring the exchange server 30 (SM-DS), and optionally the addresses for configuring the profile providing entity 10 (SM-DP+). The second auxiliary module 52 (IPAd) transmits the profile package (bound profile package) to the embedded identification module 70 (eUICC) through the interface 220 (ES10a).

[0041] The first auxiliary module 72 (IPAe) retrieves (invokes) the event data set of the embedded identification module 70 (eUICC) through an interface 160 (ES11) between the exchange server 30 (SM-DS) and the first auxiliary module 72 (IPAe).

[0042] The remote management unit 20 (eIM) retrieves the corresponding event data set of the embedded identification module 70 (eUICC) through an interface 180 (ES11') between the remote management unit 20 (eIM) and the exchange server 30 (SM-DS). The remote management unit 20 (eIM) is capable of processing on behalf of the first auxiliary module 72 (IPAe).

[0043] The profile providing entity 10 creates or removes an event registration on the exchange server 30 (SM-DS) through an interface 130 (ES12) between the profile providing entity 10 (SM-DP+) and the exchange server 30 (SM-DS).

[0044] The logical interface 210 (ESpsmo) enables secure end-to-end communication between the remote management unit 20 (eIM) and the embedded identification module 70 (eUICC), and is used to transmit profile management operations (PSMO).

[0045] The Remote Management Unit 20 (eIM) communicates with the first auxiliary module 72 (IPAe) via the logical interface 190 (ESipa). The Embedded Identification Module 70 (eUICC) is adapted to assist the interface 190. The interface 190 enables secure end-to-end communication between the Remote Management Unit 20 (eIM) and the Embedded Identification Module 70 (eUICC).

[0046] The Remote Management Unit 20 (eIM) controls the profile management operations via the interface 190. The Remote Management Unit 20 (eIM) always communicates with the first auxiliary module 72 (IPAe) in the Embedded Identification Module 70 (eUICC) here. The Remote Management Unit 20 (eIM) is able to trigger the loading of the profile 80 via the interface 190. The Profile Status Management Operation (PSMO) is also carried out via the interface 190.

[0047] The profile is loaded by providing the profile 80 in the profile providing entity 10 (SM-DP+) and transmitting it to the secure area 78 (MNO-SD) of the network operator via the architecture.

[0048] The profile 80 loaded into the Embedded Identification Module (eUICC) is changed by means of the Profile Status Management Operation (PSMO). The Profile Status Management Operation can in particular be activating a profile, deactivating a profile, deleting a profile, listing profile information, outputting profile metadata or updating a profile.

[0049] The two auxiliary modules 52, 72 (IPAd, IPAe) operate such that either the first auxiliary module 72 is active or the second auxiliary module 52 is active at the same time. If the first auxiliary module 72 (IPAe) is active and the second auxiliary module 52 (IPAd) is deactivated, the first operating mode is formed. If the second auxiliary module 52 (IPAe) is active and the first auxiliary module 72 (IPAd) is deactivated, the second operating mode is formed. Which auxiliary module is active and which operating mode is set depends on the type of profile management operation to be carried out.

[0050] When the first auxiliary module 72 (IPAe) receives a profile management operation from the Remote Management Unit 20 (eIM), the first auxiliary module is activated. The profile management operations are loading a profile and modifying a profile by means of the Profile Status Management Operation.

[0051] If the profile management operation is a profile status operation regarding a status change (PSMO) of a telecommunications profile 80 stored in an embedded identification module (eUICC), the first auxiliary module 72 (IPAe) causes the embedded identification module 70 (eUICC) to perform the profile management operation.

[0052] After performing the profile status operation, the first auxiliary module 72 (IPAe) sends feedback regarding the performance to the remote management unit 20 (eIM), wherein the sending of the feedback is implemented by means of a first protocol, preferably the ESPSMO protocol, for example, implemented by means of the MQTT or LightWeight M2M protocol.

[0053] If the profile management operation sent to the first auxiliary module 72 (IPAe) involves loading a new profile 80, the first auxiliary module 72 (IPAe) transfers the execution of the profile management operation to the second auxiliary module 52 (IPAd). The first auxiliary module 72 (IPAe) is deactivated, and the second auxiliary module 52 (IPAd) is activated.

[0054] If the profile management operation involves loading a new profile (profile download), the second auxiliary module 52 (IPAd) is activated. The second auxiliary module then causes the profile management operation to be performed.

[0055] Preferably, the second auxiliary module 52 (IPAd) remains in an active state at least until the first telecommunications profile 80 is loaded into the embedded identification module (eUICC).

[0056] Preferably, once the telecommunications profile 80 is loaded into the embedded identification module 70 (eUICC) by the second auxiliary module 52 (IPAd), the first auxiliary module 72 (IPAe) is activated.

[0057] The first or second auxiliary module 52 (IPAd) is preferably activated according to an instruction from the remote management unit 20 (eIM).

[0058] Through the coordinated action of the auxiliary modules 52 and 72, or by setting the first or second operating mode, the profile management operation can be effectively performed.

[0059] The profile management operation may be a profile status operation for changing the status of a profile 80 stored in the embedded identification module 70 (eUICC). For example, an activated profile 80 is deactivated, and another activated or deactivated profile 80 is deleted. The profile status operation can be appropriately triggered by the remote management unit 20 (eIM). The process of the profile status operation is as Figure 2 shown.

[0060] To implement the changes required for Profile Status Management Operations (PSMO), the Remote Management Unit 20 establishes a secure connection with the first auxiliary module 72 (IPAe) via interface 190 (ESipa) and a secure connection with the Embedded Identification Element 70 (eUICC) via interface 210 (ESpsmo).

[0061] Via the secure connection 190, the Remote Management Unit 20 (eIM) sends a command data set with profile management operations to the first auxiliary module 72 (IPAe), step 1000. The terminal device 50 is in the first operating mode, the first auxiliary module 72 (IPAe) is in the active state, and the second auxiliary module 52 (IPAd) is in the deactivated state.

[0062] The first auxiliary module 72 (IPAe) checks the command data set to check whether the profile management operation is a profile status operation or involves the loading of profile 80. If the profile management operation is a profile status operation in the form of, for example, a PSMO message, the first auxiliary module 72 (IPAe) executes the profile management operation, step 1010, and makes the corresponding changes to the addressed profile. For example, it can be switched from the first profile to the second profile.

[0063] In addition, the profile management operation can also be to load profile 80 into the Embedded Identification Element 70. Figure 3 The signal flow when loading profile 80 from the profile providing entity 10 (SM-DP+) into the Embedded Identification Module 70 (eUICC) is shown. The initial setting of profile 80 on the Embedded Identification Module 70 (eUICC) or the loading of a new profile 80 is preferably carried out via the second auxiliary module 52 (IPAd) in the second operating mode.

[0064] In the first variant design O1, the Remote Management Unit 20 initializes the loading of profile 80 via the first auxiliary module 72 (IPAe) through interface 150 (E8+). The Remote Management Unit 20 (eIM) sends a command data set with loading information to the first auxiliary module 72 (IPAe), step 1100. The first auxiliary module 72 (IPAe) activates the second auxiliary module (IPAd) 52 with activation information, step 1110, and deactivates itself. The second auxiliary module 52 (IPAd) contacts the Remote Management Unit 20 (eIM) via the side interface 170 and requests an activation code, step 1120. The Remote Management Unit 20 (eIM) sends the activation code, step 1130.

[0065] The second auxiliary module 52 (IPAd) determines the responsible profile providing entity 10 (SM-DP+) from the activation code and establishes a secure connection with it via the interface 120 (S9+). The activation code is provided by the second auxiliary module 52 (IPAd) of the profile providing entity (SM-DP+), step 1400. After mutual authentication with the embedded identification module 70 (eUICC), the profile providing entity 10 (SM-DP+) provides a profile package to the second auxiliary module 52 (IPAd), step 1410. The profile package loads the second auxiliary module 52 (IPAd) into the embedded identification module 70 (eUICC). The profile 80 contained in the profile package is installed by the embedded identification module 70 (eUICC).

[0066] In a variant design for O1, the remote management unit 20 (eIM) triggers the loading of the profile 80 when the switching server 30 (SM-DS) is turned on. For this purpose, a secure connection is established between the remote management unit 20 and the first auxiliary module 52 (IPAe) via the interface 190 (ESipa). The second auxiliary module 52 (IPAd) is deactivated, thus set to the first operating mode. After mutual authentication using the information obtained from the embedded identification module 70 (eUICC), the first auxiliary module 72 (IPAe) prompts the establishment of a secure connection with the switching server 30 (SM-DS) via the interface 160 (E11) in order to retrieve the event data set. The first auxiliary module 72 (IPAe) identifies the responsible profile providing entity 10 (SM-DP+) from the event data set and passes it on to the second auxiliary module 72 (IPAd). For this purpose, the first auxiliary module sets itself to the second operating mode by deactivating itself and activating the second auxiliary module 52 (IPAd). The second auxiliary module 52 (IPAd) then loads the profile into the embedded identification module 70 (eUICC) as described above.

[0067] In a variant of this variant design, the remote management unit 20 (eIM) accepts a request for the event data set and forwards the event data set to the first auxiliary module 52 (IPAe).

[0068] In the second variant design O2, the charging process is triggered by the remote management unit 20 (eIM) using the activation code provided to the remote management unit 20. The remote management unit 20 (eIM) sends information containing the activation code to the first auxiliary module 72 (IPAe) via the interface 210 (EPpsmo), step 1200. The first auxiliary module 72 identifies the information as a call-up instruction to load the profile. The first auxiliary module activates the second auxiliary module 52 using the activation information containing the activation code, step 1210. The terminal device 50 is then in the second operating mode.

[0069] The second auxiliary module 52 (IPAd) provides the configuration file providing entity 10 (SM-DP+) responsible for the activation code determination, and establishes a secure connection with it through the interface 120 (S9+). The activation code is provided by the second auxiliary module 52 (IPAd) of the configuration file providing entity (SM-DP+), step 1400. After mutual authentication with the embedded identification module 70 (eUICC), the configuration file providing entity 10 (SM-DP+) provides a configuration file package to the second auxiliary module 52 (IPAd), step 1410. The configuration file package loads the second auxiliary module 52 (IPAd) into the embedded identification module 70 (eUICC), step 1420. The configuration file 80 contained in the configuration file package is installed by the embedded identification module 70 (eUICC).

[0070] The remote management unit 20 (eIM) and the configuration file providing entity 10 (SM-DP+) are informed that the configuration file is successfully set up.

[0071] In a variant of this variant design, the configuration file providing entity 10 (SM-DP+) is preset, and the determination of the activation code is omitted.

[0072] In a variant design of O2, the charging process is triggered by the remote management unit 20 (eIM) with the help of the activation code provided to the remote management unit 20. Loading is performed in the first operating mode, that is, the first auxiliary module 72 (IPAe) is activated, and the second auxiliary module 52 (IPAd) is deactivated. The remote management unit 20 (eIM) establishes a secure connection with the first auxiliary module 72 (IPAe) through the interface 190 (ESipa), determines the configuration file providing unit 10 (SM-DP+) by the activation code, and also establishes a secure connection with the configuration file providing unit through the interface 100 (ES8+). The configuration file providing unit 10 (SM-DP+) performs mutual authentication with the embedded identification module 70 (eUICC) through a common secure connection. The configuration file providing unit 10 (SM-DP+) then provides a configuration file package and transmits it to the remote management unit 20 (eIM). The remote management unit sets the second operating mode, and transmits the configuration file package to the embedded identification module 70 (eUICC) through the second auxiliary module 52 (IPAd). The embedded identification module installs the configuration file 80 and notifies the management unit 20 (eIM) and the configuration file providing entity 10 (SM-DP+).

[0073] In the third variant design solution O3, the second auxiliary module 52 (IPAd) triggers the loading process by determining that the conditions of the loading profile 80 are met, step 1300. The second auxiliary module 52 (IPAd) contacts the remote management unit 20 (eIM) via the side interface 170 and requests an activation code, step 1310. The remote management unit 20 (eIM) sends the activation code via the side interface 170, step 1320.

[0074] The second auxiliary module 52 (IPAd) determines the responsible profile providing entity 10 (SM-DP+) from the activation code and establishes a secure connection with it via the interface 120 (S9+). The activation code is provided by the second auxiliary module 52 (IPAd) of the profile providing entity (SM-DP+), step 1400. After mutual verification with the embedded identification module 70 (eUICC), the profile providing entity 10 provides a profile package to the second auxiliary module 52 (IPAd), step 1410. The profile package loads the second auxiliary module 52 (IPAd) into the embedded identification module 70 (eUICC), step 1420. The profile 80 contained in the profile package is installed by the embedded identification module 70 (eUICC).

[0075] The remote management unit 20 (eIM) and the profile providing entity 10 (SM-DP+) are informed that the profile setting is successful.

[0076] In a suitable extended design of this solution, an application program is executed in the terminal device 50 or the embedded identification module 70 (eUICC), and this application program controls the status of the profile 80 stored in the embedded identification module 70 (eUICC). Such an application program can be, for example, an application program that identifies the current location of the terminal device 50 and sets the profile 80 that matches this location. Under suitable conditions, the application program sends information to the first auxiliary module 72 (IPAe), and this first auxiliary module then changes the profile status.

[0077] In the extended design of the said solution, the remote management unit 20 (eIM) is designed to provide a repair profile, and the repair profile is loaded into the embedded identification module 70 (eUICC) when needed. The loading of the repair profile is carried out as described above.

[0078] In another extended design, it is stipulated that in the terminal device 50, only the first auxiliary module 72 (IPAe) is provided in principle, and the second auxiliary module 52 (IPAd) is only set when the loading of the profile 80 is needed for the first time.

[0079] A first auxiliary module 72 and a second auxiliary module 52 are provided to perform profile management operations, one of the first auxiliary module and the second auxiliary module is formed in the embedded recognition module 70, and the other is formed in the terminal device 50. Wherein, in the case of an operation related to the profile status, the first auxiliary module 72 causes the profile management operation to be performed, and wherein, in the case where the profile management operation includes loading a profile, the second auxiliary module 52 causes the profile management operation to be performed. While maintaining this basic concept, the solution also has a series of variations, which are not elaborated in detail for the sake of brevity. Therefore, the profile management operation can be triggered according to other possible events. For example, additional measures can be set to ensure communication security, or fewer measures can be set when necessary.

Claims

1. A terminal device with an embedded recognition module (70), the embedded recognition module being arranged to perform profile management operations by means of which it is possible to change a telecommunication profile (80) stored in the embedded recognition module (70) or to load a new telecommunication profile (80). • Among them, The embedded recognition module (70) has a first auxiliary module (72), the first auxiliary module providing a first interface (150) to a remote management unit (20). • And the terminal device (50) has a second auxiliary module (52), the second auxiliary module being connected to the embedded recognition module (70) and providing a second interface (120) to a profile providing entity (10). • Wherein, at the same time, either the first auxiliary module (72) is in an active state or the second auxiliary module (52) is in an active state. • Wherein, the terminal device (50) obtains a command data set containing profile management operations from the remote management unit (20). • Wherein, when the profile management operation involves a change in the state of the telecommunication profile (80) stored in the embedded recognition module (70), the first auxiliary module (72) is in an active state and causes the profile management operation to be executed. • And wherein, when the profile management operation involves loading a new profile, the second auxiliary module (52) is in an active state and causes the profile management operation to be executed.

2. The terminal device according to claim 1, characterized in that The command data set with profile management operations is transmitted through the interface (150) and is received by the first auxiliary module (72).

3. The terminal device according to claim 1 or 2, characterized in that The second auxiliary module (52) is arranged to perform data exchange with the profile providing entity (10) in order to load a new profile (80) into the embedded recognition module (70).

4. The terminal device according to one of the preceding claims, characterized in that, When the profile management operation involves loading a telecommunication profile (80), the first auxiliary module (72) transfers the execution of the profile management operation to the second auxiliary module (52).

5. The terminal device according to one of the foregoing claims, characterized in that, After the profile management operation is executed, the first auxiliary module (72) sends feedback about the execution to the remote management unit (20).

6. The terminal device according to one of the foregoing claims, wherein The second auxiliary module (52) has a side interface (170) to the remote management unit (20), the side interface enabling a request for an activation code to be sent to the remote management unit (20).

7. The terminal device according to one of the foregoing claims, wherein, The communication between the first auxiliary module (72) and the remote management unit (20) is realized by means of a first protocol.

8. The terminal device according to one of the foregoing claims, characterized in that, The communication between the second auxiliary module (52) and the profile providing entity (10) is realized by means of a second protocol.

9. The terminal device according to one of the foregoing claims, characterized in that, The second auxiliary module (52) is in an active state until the first telecommunication profile (80) is loaded into the embedded recognition module (70).

10. The terminal device according to one of the preceding claims, characterized in that, Once the telecommunication profile (80) is loaded into the embedded recognition module (70) through the second auxiliary module (52), the first auxiliary module (72) is activated.

11. The terminal device according to one of the preceding claims, characterized in that The activation of the first auxiliary module (72) or the second auxiliary module (52) is carried out according to the instructions of the remote management unit (20).

12. A method for managing a telecommunication profile in an embedded identification module (70) of a terminal device (50) by means of a configuration file management operation, the method having the following steps: • A first auxiliary module (72) is provided in the recognition module (70), wherein, The first auxiliary module (72) provides an interface (150) to a remote management unit (20). • A second auxiliary module (52) is provided in the terminal device (50), wherein the second auxiliary module (52) is connected to the identification module (70) and provides an interface (120) to a profile providing entity (10). • A first operating mode is set in which the first auxiliary module (72) is active and the second auxiliary module (52) is deactivated. • A second operating mode is set in which the second auxiliary module (52) is active and the first auxiliary module (72) is deactivated. • A command data set containing a configuration file management operation is transmitted from the remote management unit (20) to the terminal device (50). • When the configuration file management operation involves a change in the state of a telecommunication profile (80) stored in the embedded identification module (70), the configuration file management operation is carried out in the first operating mode by the first auxiliary module (72). • When the configuration file management operation involves the loading of a new profile (80), the second operating mode is set and the configuration file management operation is carried out by the second auxiliary module (52).

13. The method according to claim 12, wherein The first auxiliary module (72) receives the command data set containing the configuration file management operation and, when the configuration file management operation involves the loading of a new telecommunication profile (80), the first auxiliary module transfers the configuration file management operation to the second auxiliary module (52) and sets it to the second operating mode.

14. The method according to claim 12 or 13, characterized in that, The command data set is formed in the remote management unit (20) according to a request input via a user interface.

Citation Information

Patent Citations

  • CONNECTING INTERNET OF THINGS (I0T) DEVICES TO A WIRELESS NETWORK

    DE102021127364A1

  • System, module, circuitry and method

    US20220295281A1