System and method for managing SIM card profiles for different embedded universal integrated circuit cards
By employing batch processing and encryption mechanisms, the efficiency and security issues of SIM card configuration file download during device manufacturing of embedded general-purpose integrated circuit cards have been resolved, achieving efficient and secure file transfer and continuous device production.
Patent Information
- Application Number
- CN202480014112.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-02-24
- Filing Date
- 2024-02-12
- Publication Date
- 2025-11-14
AI Technical Summary
In the prior art, embedded universal integrated circuit cards (eUICC) have difficulty efficiently downloading SIM card configuration files during device manufacturing, resulting in reduced data transmission rate and reliability. Furthermore, device manufacturers need to handle a large number of configuration file requests, which may lead to production stoppages.
By employing a batch processing method, the static portion of the SIM card configuration file is encrypted using a public cryptographic key, while the dynamic portion is encrypted using the associated cryptographic key of the embedded general-purpose integrated circuit card, forming a SIM card configuration file package. This reduces data transmission volume and ensures file security.
It improved the download efficiency of SIM card configuration files, reduced data transmission volume, ensured file security and integrity, and prevented equipment production from stalling.
Smart Images

Figure CN120958788A_ABST
Abstract
Description
Technical Field
[0001] The implementation and embodiments of the present invention relate to embedded general-purpose integrated circuit cards. Background Technology
[0002] A Universal Integrated Circuit Card (UICC) is a smart card (integrated circuit card) used in mobile terminals within GSM (Global System for Mobile Communications) and UMTS (Universal Mobile Telecommunications System) networks. A UICC can also be called a SIM card (SIM stands for Subscriber Identity Module).
[0003] Embedded Universal Integrated Circuit Cards (also known as “eUICCs”) are an evolution of classic universal integrated circuit cards. An embedded universal integrated circuit card is a programmable SIM card that is directly embedded in a device. Specifically, an embedded universal integrated circuit card is an electronic chip permanently attached to a device. Embedded universal integrated circuit cards can be embedded in a variety of devices. For example, they can be embedded in smartphones or objects such as sensors, particularly in the field of the Internet of Things (“IoT”).
[0004] Embedded general-purpose integrated circuit cards can simplify subscription and connection management with different cellular network service providers.
[0005] Specifically, embedded universal integrated circuit cards (“eUICCs”) are used to securely store one or more SIM card profiles. For example, embedded universal integrated circuit cards are specified in GSMA specifications, particularly SGP.01 and SGP.21.
[0006] A SIM card profile is a unique identifier and cryptographic key used by a cellular network service provider to uniquely identify and securely connect to a mobile network device. More specifically, a SIM card profile is a combination of file structure, data, and applications stored in an embedded general-purpose integrated circuit card. SIM card profiles are created by profile manufacturers according to specific purchase orders from cellular network service providers. For example, a SIM card profile may be a profile defined in the Trusted Connectivity Alliance's "eUICC ProfilePackage: Interoperable Format Technical Specification".
[0007] Subscribing to cellular network services requires downloading a SIM card profile to an embedded universal integrated circuit (EUC) card. It is important to provide a secure method for downloading the SIM card profile to the EUC card to protect the data included in the SIM card profile. Therefore, the SIM card profile is transmitted to the EUC card as a secure packet.
[0008] When embedded general-purpose integrated circuit cards (GPICS) are embedded in IoT devices, downloading SIM card profiles can be difficult when the devices are deployed in the field. In fact, connecting embedded GPICS cards to telecommunications networks without an initial subscription is challenging.
[0009] Furthermore, it is difficult to download the SIM card profile to the embedded general-purpose integrated circuit (GPIB) card in the manufacturing plant. In fact, this downloading implies that the embedded GPIB card manufacturer knows in advance which cellular network service provider's subscription the entity using the device embedded with that card will receive.
[0010] Therefore, during device manufacturing, it is sometimes more convenient to download the SIM card profile onto the device itself. Device manufacturers can receive the SIM card profile from the Data Preparation Subscription Manager's server (“SM-DP”, the consumer's “SM-DP+”, or another such server configured at the factory). This server is configured to receive the SIM card profile from the profile manufacturer and generate a secure package including the SIM card profile before delivering it to the device manufacturer.
[0011] A SIM card profile provided by the profile manufacturer is securely associated with a given embedded universal IC card (ECC) using that device manufacturer's technology. The device manufacturer receives the associated profile and downloads each profile to the intended ECC. The device manufacturer cannot access or manipulate the SIM card profile before delivering it to the ECC because the data in the SIM card profile is encrypted and can only be decrypted by the ECC.
[0012] Device manufacturers may need to provide a large number of SIM card profiles for the devices they produce. Therefore, SIM card profiles are typically delivered to device manufacturers in batches generated by profile manufacturers.
[0013] The reduced data transfer rate and reliability decrease the number of SIM card profiles that can be sent in the same batch. Furthermore, the SM-DP server can receive a large number of profile requests. If a device manufacturer does not receive all the SIM card profiles it needs, it may have to halt production of its devices.
[0014] Therefore, there is a need to provide a solution for downloading SIM card profiles in embedded universal integrated circuit cards, which allows for a reduction in the amount of data transferred between the profile manufacturer server and the embedded universal integrated circuit card. Summary of the Invention
[0015] Based on one aspect, a system is proposed, which includes:
[0016] - Embedded general-purpose integrated circuit card,
[0017] - At least one server is configured as follows:
[0018] • Generate SIM card profiles based on a given configuration (particularly a configuration defined by the cellular network service provider), each SIM card profile including at least one static portion common to the aforementioned SIM card profiles and at least one dynamic portion different between SIM card profiles, and
[0019] • A batch of SIM card profiles is generated, comprising at least one dynamic portion of each SIM card profile and at least one common static portion appearing only once, wherein the at least one static portion is encrypted using a common cryptographic key, and wherein the at least one dynamic portion of each SIM card profile is encrypted using a cryptographic key associated with that SIM card profile.
[0020] - Another server is configured as follows:
[0021] • Receive the above batches and generate a SIM card profile package for each SIM card profile in the above batches. Each SIM card profile package includes:
[0022] ○ At least one of the aforementioned static portions of the SIM card configuration file, encrypted using a public cryptographic key.
[0023] ○ The aforementioned public cryptographic key and at least one dynamic portion of the SIM card configuration file, wherein the public cryptographic key and the at least one dynamic portion are encrypted using their associated cryptographic key.
[0024] • Download the SIM card profile package to the embedded general-purpose integrated circuit card. Each embedded general-purpose integrated circuit card is configured to decrypt at least one static part using a public cryptographic key and at least one dynamic part using its associated cryptographic key to obtain the SIM card profile.
[0025] The at least one server configured to generate SIM card profile batches may include two servers, specifically a profile manufacturer's server and a data preparation subscription manager ("SM-DP") server. In this case, the profile manufacturer's server is configured to generate SIM card profiles and the aforementioned SIM card profile batches, and delivers the SIM card profile batches to the data preparation subscription manager's server via a secure channel between the two servers. The data preparation subscription manager's server is then configured to deliver the aforementioned SIM card profile batches to a server configured to generate SIM card profile packages, which are then downloaded to the embedded general-purpose integrated circuit card via the secure channel between the two servers.
[0026] Alternatively, only one server configured to generate SIM card profile batches can be used. This server is then configured to generate SIM card profiles and the aforementioned SIM card profile batches, and delivers these batches directly to a server configured to generate SIM card profile packages, which are then downloaded to the embedded general-purpose integrated circuit card via a secure channel between the two servers.
[0027] The server configured to generate SIM card profile packages to be downloaded onto the embedded general-purpose integrated circuit card can be a server of the device manufacturer. Each embedded general-purpose integrated circuit card can be embedded in a device manufactured by the aforementioned device manufacturer.
[0028] In a batch of SIM card profiles, at least one of the aforementioned static portions appears only once, rather than being repeated for each SIM card profile. This allows for a reduction in the amount of data transferred from the at least one server that generates the SIM card profiles to the server used to download the SIM card profile package onto the embedded general-purpose integrated circuit card.
[0029] Using a public cryptographic key allows for the protection of at least one static portion using a different key than the one associated with the cryptographic key used to encrypt the at least one dynamic portion. This allows a server downloading a SIM card profile package to an embedded general-purpose integrated circuit card to manipulate at least one encrypted static portion and at least one encrypted dynamic portion of the SIM card profile to generate the SIM card profile package. The server cannot alter or decrypt the SIM card profile while manipulating it because the SIM card profile is manipulated within an encrypted domain.
[0030] According to a particularly advantageous embodiment, for each SIM card profile, the aforementioned batch includes:
[0031] - The aforementioned public cryptographic key, encrypted with the aforementioned associated key associated with the SIM card profile, and
[0032] - The aforementioned associated password key that is linked to this SIM card profile.
[0033] Each SIM profile package also includes the aforementioned associated cryptographic key associated with the SIM profile, which is linked to the SIM profile package.
[0034] Advantageously, each associated cryptographic key associated with a SIM card profile is encrypted with a cryptographic key known to at least one of the aforementioned servers and to an embedded general-purpose integrated circuit card configured to download a SIM card profile package associated with that SIM card profile.
[0035] Preferably, the aforementioned cryptographic key, known to at least one of the servers and to the embedded general-purpose integrated circuit card, is calculated using the Diffie-Hellman algorithm.
[0036] Advantageously, the public cryptographic key is a random value.
[0037] Preferably, the associated cryptographic key is a random value.
[0038] According to a particularly advantageous embodiment, the batch further includes an identifier associated with at least one static portion and an identifier associated with at least one dynamic portion for each SIM card profile, and the other server is configured to assemble the at least one static portion and the at least one dynamic portion of the SIM card profile based on its identifiers to form the SIM card profile package.
[0039] Advantageously, each SIM card profile includes multiple static sections and multiple dynamic sections.
[0040] Preferably, at least one of the servers described above is configured to group all static portions of the SIM card profile into a single portion of the SIM card profile packet. This simplifies the encryption and decryption of both the static and dynamic portions. In particular, this allows avoiding the need to expand each static and dynamic portion to the input size of the cryptographic algorithm (e.g., 16 bytes for AES), thereby limiting the overhead required to execute the cryptographic algorithm.
[0041] According to a particularly advantageous embodiment, the batch further includes at least one integrity check value. This integrity check value can then be used to verify the integrity of the at least one static portion and to verify that the at least one static portion has not been mixed compared to the original expected order.
[0042] Preferably, the at least one integrity check value may be a hash value associated with the at least one static portion. As a variation, the at least one integrity check value may be a counter or unique identifier included in both the at least one static portion and the at least one dynamic portion.
[0043] On the other hand, a method for downloading SIM card configuration files to different embedded general-purpose integrated circuit cards is proposed, the method comprising:
[0044] - A SIM card profile is generated by at least one server based on a given configuration (particularly a configuration defined by the cellular network service provider). Each SIM card profile includes at least one static portion that is common to all SIM card profiles and at least one dynamic portion that differs between SIM card profiles.
[0045] - A batch of the aforementioned SIM card profiles is generated by at least one of the aforementioned servers, the batch including at least one dynamic portion of each SIM card profile and at least one aforementioned common static portion appearing only once, wherein the at least one static portion is encrypted using a public cryptographic key, and the at least one dynamic portion of each SIM card profile is encrypted using a cryptographic key associated with that SIM card profile.
[0046] - The above batches are received by another server.
[0047] - A SIM card profile package is generated by the other server for each SIM card profile in the above batch. Each SIM card profile package includes:
[0048] ○ At least one of the aforementioned static portions of the SIM card configuration file, which is encrypted using a public cryptographic key.
[0049] ○ The aforementioned public cryptographic key and at least one dynamic portion of the SIM card configuration file, wherein the public cryptographic key and the at least one dynamic portion are encrypted using their associated cryptographic key.
[0050] - Download the SIM card configuration file package from the other server mentioned above to the embedded general-purpose integrated circuit card.
[0051] - The at least one static part described above is decrypted using a public cryptographic key by each embedded general-purpose integrated circuit card, and the at least one dynamic part described above is decrypted using its associated cryptographic key to obtain the SIM card profile.
[0052] According to a particularly advantageous implementation, for each SIM card profile, the aforementioned batch includes:
[0053] - The aforementioned public cryptographic key, encrypted with the aforementioned associated key associated with the SIM card profile, and
[0054] - The aforementioned associated password key that is linked to this SIM card profile.
[0055] Each SIM profile package also includes the aforementioned associated cryptographic key associated with the SIM profile, which is linked to the SIM profile package.
[0056] Advantageously, each associated cryptographic key associated with a SIM card profile is encrypted with a cryptographic key known to at least one of the aforementioned servers and to an embedded general-purpose integrated circuit card configured to download a SIM card profile package associated with that SIM card profile.
[0057] Preferably, the aforementioned cryptographic key, known to at least one of the servers and to the embedded general-purpose integrated circuit card, is calculated using the Diffie-Hellman algorithm.
[0058] Advantageously, the public cryptographic key is a random value.
[0059] Preferably, the associated cryptographic key is a random value.
[0060] According to a particularly advantageous embodiment, the aforementioned batch also includes an identifier associated with at least one static portion and an identifier associated with at least one dynamic portion for each SIM card profile. The other server assembles the at least one static portion and the at least one dynamic portion of the SIM card profile based on its identifiers to form the aforementioned SIM card profile package.
[0061] Advantageously, each SIM card profile includes multiple static sections and multiple dynamic sections.
[0062] Preferably, generating the above batch includes grouping all the static portions of the SIM card profile into a portion of the SIM card profile package.
[0063] According to a particularly advantageous embodiment, the aforementioned batch also includes at least one integrity check value. Preferably, the at least one integrity check value is a hash value associated with the at least one static portion. Attached Figure Description
[0064] Other advantages and features of the invention will appear in the detailed description of the embodiments and implementations (in no way limiting) and the accompanying drawings, in which:
[0065]
Figure 1
[0066]
Figure 2
[0067]
Figure 3
[0068]
Figure 4
[0069]
Figure 5
[0070] 【 Figure 6 Various implementations and embodiments of the present invention are illustrated schematically. Detailed Implementation
[0071] Figure 1 The illustration shows an example of a system SYS used to manage SIM card configuration files.
[0072] The system SYS includes multiple embedded general-purpose integrated circuit cards, a configuration file manufacturer's server PM, a device manufacturer's server DM, and a data preparation subscription manager's server SM-DP.
[0073] An embedded universal integrated circuit card (eUICC) is an electronic chip used as a programmable SIM card.
[0074] An equipment manufacturer is an entity that produces equipment. For example, Figure 1 The illustration shows two devices, DVC1 and DVC2, manufactured by a device manufacturer. These devices can be configured for use in smartphones or objects such as sensors in the Internet of Things (IoT). Each device includes an embedded general-purpose integrated circuit card. Figure 1 In the process, devices DVC1 and DVC2 respectively include embedded general-purpose integrated circuit cards eUICC1 and eUICC2.
[0075] Each device's embedded universal integrated circuit card is configured to be associated with a given SIM card profile. The SIM card profile allows the embedded universal integrated circuit card to use the cellular network of a cellular network service provider.
[0076] The profile maker's server PM is configured to generate SIM card profiles based on subscriptions to cellular network service providers.
[0077] The configuration file manufacturer's server PM is configured to deliver SIM card configuration files intended for use by the device manufacturer DM in a single batch of BTCH1. For example, in Figure 1 In this context, batch BTCH1 includes two SIM card profiles, PRF#1 and PRF#2. However, such a batch can include more than two SIM card profiles. For example, the batch could include thousands of SIM card profiles.
[0078] Each SIM card profile in batch BTCH1 includes at least one static section and at least one dynamic section.
[0079] The static portion of each SIM card profile in a batch of BTCH1 is a common data portion across different SIM card profiles within the batch of BTCH1. If a SIM card profile in the same batch of BTCH1 includes multiple static portions, then the batch of BTCH1 includes an identifier for each static portion of the SIM card profile.
[0080] The dynamic portion of each SIM card profile in a batch of BTCH1 is a distinct data portion across different SIM card profiles within the same batch of BTCH1. If SIM card profiles within the same batch include multiple dynamic portions, the batch of BTCH1 includes an identifier for each dynamic portion of each SIM card profile. The identifier for a dynamic portion may be the same as the identifier for a static portion preceding that dynamic portion in the SIM card profile.
[0081] Each identifier serves as an integrity check value. Specifically, each identifier can be subsequently used to verify the integrity of at least one of the aforementioned static parts, and to verify that the at least one static part has not been mixed compared to the original expected order. The identifier can be a hash value of each static part.
[0082] The profile manufacturer server (PM) is configured to encrypt each static section and its identifier for each SIM card profile using a public key (PPKS). The PPKS can be calculated using any method. For example, the PPKS can be a random value.
[0083] The profile maker server PM is configured to generate batches BTCH1 so that only each static portion of a different SIM card profile that appears only once is included. Batch BTCH1 also includes each dynamic portion of each SIM card profile.
[0084] If each SIM card profile in a batch of BTCH1 includes multiple static sections, the static sections are arranged one after another in the batch of BTCH1.
[0085] If each SIM card profile in a batch of BTCH1 includes multiple dynamic sections, the dynamic sections are arranged one after another in the batch of BTCH1.
[0086] The dynamic part can be placed after the static part in the batch BTCH1.
[0087] The configuration file maker server PM is configured to deliver the generated batches of BTCH1 to the server SM-DP via a secure channel.
[0088] The server SM-DP is configured to receive batch BTCH1 generated by the profile manufacturer and generate batch BTCH2 of SIM card profiles and send them to the device manufacturer's server DM through a secure channel.
[0089] Specifically, batch BTCH2 is equivalent to batch BTCH1. Batch BTCH2 includes each static portion of a different SIM card profile and each dynamic portion of each SIM card profile, appearing only once. For each SIM card profile i, the server SM-DP is configured to encrypt each dynamic portion of that SIM card profile i, its identifier, and the associated cryptographic key PPKS using the associated cryptographic key PPK(i). As a variant, the profile manufacturer's server PM can also perform this encryption.
[0090] In particular, the cryptographic key PPK(i) can be a random value.
[0091] The batch BTCH2 therefore includes each cryptographic key PPK(i) (or preferably, includes a value, in particular a public key, which can be used by an embedded general-purpose integrated circuit card designed to receive the SIM card profile i to obtain the cryptographic key PPK(i)).
[0092] Each cryptographic key PPK(i) is encrypted using a cryptographic key called session key S-ENC(i), which is known only to the aforementioned server SM-DP and the embedded general-purpose integrated circuit card intended to receive SIM card profile i. Each session key S-ENC(i) can be computed using the Diffie-Hellman algorithm, specifically according to specification SGP.22 defined by the GSMA organization.
[0093] The device manufacturer's server DM is configured to assemble different parts of each SIM card profile.
[0094] Specifically, the device manufacturer's server DM is configured to assemble different parts of each SIM card profile based on the associated identifiers indicated in the batch BTCH2 delivered by the profile manufacturer's server, in order to generate a package for each SIM card profile. This package includes the SIM card profile associated with a given embedded general-purpose integrated circuit card. Figure 1 The image shows two SIM card configuration file packages, PRFP#1 and PRFP#2.
[0095] Specifically, the SIM card profile package includes a cryptographic key PPK(i) (or preferably, a value that can be used by an embedded general-purpose integrated circuit card intended to receive the SIM card profile i to obtain the cryptographic key PPK(i)), a cryptographic key PPKS, each static portion of the SIM card profile, and each dynamic portion of the SIM card profile. More specifically, the static and dynamic portions are arranged alternately in the package after the cryptographic keys PPK and PPKS. As a variation, the static and dynamic portions of the SIM card profile can be grouped.
[0096] The package may also include the aforementioned identifier for each static section, such as a hash value for the static section. This identifier can be used to verify the integrity of each static section when the embedded general-purpose integrated circuit card loads the SIM card profile.
[0097] The cryptographic key PPKS, each dynamic part, and the final hash value are encrypted using the cryptographic key PPK. Encrypting the cryptographic key PPKS with the cryptographic key PPK allows for the protection of the cryptographic key PPKS. Furthermore, each static part is encrypted using the cryptographic key PPKS.
[0098] Each SIM card profile package generated by the device manufacturer's server DM can be downloaded by the device manufacturer to its corresponding embedded general-purpose integrated circuit card integrated into a given device. For example, in Figure 1In the process, SIM card configuration file PRFP#1 is downloaded to embedded general-purpose integrated circuit card eUICC1, and SIM card configuration file PRFP#2 is downloaded to embedded general-purpose integrated circuit card eUICC2.
[0099] The embedded general-purpose integrated circuit card is configured to decrypt the cryptographic key PPKS using the cryptographic key PPK. The embedded general-purpose integrated circuit card is also configured to decrypt each static part using the cryptographic key PPKS and each dynamic part using the cryptographic key PPK.
[0100] An embedded general-purpose integrated circuit (GPIB) card can be configured to calculate the hash value of each static section of the SIM card profile and compare it with the hash value associated with it as indicated in the SIM card profile package. This allows the GPIB card to verify the integrity of the static section and to verify that each static section is in the correct position within the SIM card profile.
[0101] The embedded general-purpose integrated circuit card is also configured to assemble each decrypted static part with each dynamic static part to obtain a complete SIM card profile.
[0102] Figure 2 The diagram illustrates a method for managing SIM card configuration files to be downloaded to different embedded general-purpose integrated circuit cards. This method can be implemented using the system described previously.
[0103] The method includes step 20, wherein a profile manufacturer server receives a request from a cellular network service provider for generating a SIM card profile. This request is executed to allow the embedded general-purpose integrated circuit (EPS) cards to use the cellular network service provider's cellular network after they are embedded in various devices manufactured by the device manufacturer.
[0104] This request is received by the configuration file manufacturer server from the cellular network service provider server.
[0105] The method then includes step 21, where a profile manufacturer server generates a batch of SIM card profiles based on a received request. Each SIM card profile is generated according to a configuration defined by the cellular network service provider. Specifically, as previously described, the batch generated by the profile manufacturer includes different dynamic portions of the SIM card profiles, but the common static portions of the SIM card profiles appear only once.
[0106] The method then includes step 22, in which the profile manufacturer server delivers SIM card profile batches to the server SM-DP.
[0107] Next, the method includes: step 23, wherein the server SM-DP generates a batch BTCH2 of SIM card profiles as described above, and delivers the batch BTCH2 of SIM card profiles to the device manufacturer's server.
[0108] The method then includes step 24, in which the device manufacturer's server assembles the static and dynamic portions of a batch received from the profile manufacturer PM to form different SIM card profile packages intended for use with different embedded general-purpose integrated circuit cards embedded in devices manufactured by the device manufacturer.
[0109] Next, the method includes: step 25, wherein each SIM card profile package formed by the device manufacturer's server is downloaded to the associated embedded general-purpose integrated circuit card embedded in the device manufactured by the device manufacturer.
[0110] Figure 3 The illustration shows examples of two SIM card profiles, PRF#1 and PRF#2, generated by a profile manufacturer. Both the first SIM card profile, PRF#1, and the second SIM card profile, PRF#2, consist of three static parts: STAT#1, STAT#2, and STAT#3. Each static part, STAT#1, STAT#2, and STAT#3, with associated identifiers IDS#1, IDS#2, and IDS#3, is encrypted by the profile manufacturer's server, PM, using the cryptographic key PPKS.
[0111] The first SIM card profile PRF#1 also includes two dynamic sections, DYNA#1 and DYNA#12. The second SIM card profile PRF#2 also includes two dynamic sections, DYNA#21 and DYNA#22. For each SIM card profile PRF#1 and PRF#2, the server SM-DP encrypts the dynamic sections DYNA#11, DYNA#12, DYNA#21, and DYNA#22 using their identifiers IDD#11, IDD#12, IDD#21, and IDD#22, respectively, and the cryptographic key PPKS. This encryption is performed using the cryptographic key PPK#1 used for the first SIM card profile PRF#1 and the cryptographic key PPK#2 used for the second SIM card profile PRF#2. These encryptions allow the retrieval of the dynamic segments SEGD#1 and SEGD#2 associated with the SIM card profiles PRF#1 and PRF#2, respectively.
[0112] Figure 3The diagram also illustrates a batch BTCH2 generated by the server SM-DP based on two SIM card profiles, PRF#1 and PRF#2. Batch BTCH2 includes encrypted static segments SEGS#1, SEGS#2, and SEGS#3, appearing only once in each of the two SIM card profiles, PRF#1 and PRF#2. This batch also includes dynamic segments SEGD#1 and SEGD#2. Therefore, batch BTCH2 also includes a cryptographic key PPK#1 or PPK#2 for each dynamic segment SEGD#1 and SEGD#2 (or the values of cryptographic keys PPK#1 and PPK#2 can be obtained by an embedded general-purpose integrated circuit card). Cryptographic keys PPK#1 and PPK#2 are encrypted using session keys S-ENC#1 and S-ENC#2.
[0113] Figure 4 The illustration shows an example of a SIM card profile package PRFP#1 that can be generated by a device manufacturer's server. For example, this package is associated with a SIM card profile PRF#1. The SIM card profile package includes a cryptographic key PPK#1 (or preferably, a value that can be used by an embedded general-purpose integrated circuit card to obtain the cryptographic key PPK#1, transmitted in a batch delivered by a server SM-DP), a cryptographic key PPKS, static portions STAT#1, STAT#2, STAT#3, and hash values HSH#1, HSH#2, HSH#3 ultimately used for the static portions STAT#1, STAT#2, STAT#3, respectively. The SIM card profile package also includes dynamic portions DYNA#11 and DYNA#12.
[0114] The static portions STAT#1, STAT#2, and STAT#3 are encrypted by the server SM-DP using the cryptographic key PPKS. The cryptographic key PPK#1 is encrypted using the session key S-ENC#1. The cryptographic key PPKS, the final hash values HSH#1, HSH#2, and HSH#3, and the dynamic portions DYNA#11 and DYNA#12 are encrypted by the server SM-DP using the cryptographic key PPK#1 in the packet.
[0115] Figure 5 The illustration shows a first alternative to the SIM card profile package (PRFP) that can be generated by the device manufacturer's server. In this alternative package, all the static parts of the SIM card package are arranged in only one part of the package, STAP, and the dynamic parts are arranged in another part of the package, DYNAP.
[0116] This portion of the packet, the STAP, is encrypted using the cryptographic key PPKS. The packet also includes the hash value HHSP of the STAP portion. The dynamic portion, the cryptographic key PPKS, and the hash value are encrypted using the cryptographic key PPK. The cryptographic key PPK is encrypted using the session key S-ENC.
[0117] Figure 6 The diagram illustrates a second alternative to the SIM card profile package. The SIM card profile includes a cipher key PPK, cipher key PPKS, different static segments SEGST#1, SEGST#2, and SEGST#3, identifiers IDSG#1, IDSG#2, and IDSG#3 for each static segment SEGST#1, SEGST#2, and SEGST#3, and dynamic portions DYNA#1 and DYNA#2 of the SIM card profile. Each static segment includes the static portion of the SIM card profile and an identifier for that static portion.
[0118] A method can be implemented to update this SIM card profile package by modifying static segments SEGST#1, SEGST#2, and SEGST#3 through new static portions NSEGT#1, NSEGT#2, and NSEGT#3. In this method, only the new segments NSEGT#1, NSEGT#2, and NSEGT#3 (rather than a completely new SIM card profile package) are provided to the embedded general-purpose integrated circuit card. This allows for a reduction in the amount of data sent to the embedded general-purpose integrated circuit card to update the SIM card profile package.
Claims
1. A system comprising: - Embedded general-purpose integrated circuit cards (eUICC1, eUICC2), - At least one server (PM, SM-DP) is configured as follows: • Generate SIM card profiles (PRF#1, PRF#2) based on a given configuration. Each SIM card profile (PRF#1, PRF#2) includes at least one static portion that is common to all SIM card profiles and at least one dynamic portion that differs between the SIM card profiles (PRF#1, PRF#2). • Generate batches (BTCH2) of the SIM card profiles (PRF#1, PRF#2), each batch including at least one dynamic portion of each SIM card profile and at least one common static portion appearing only once, the at least one static portion being encrypted using a public cryptographic key (PPKS), and the at least one dynamic portion of each SIM card profile being encrypted using a cryptographic key (PPK#1, PPK#2) associated with the SIM card profile. - Another server (DM) is configured as follows: • Receive the batch (BTCH2) and generate SIM card profile packets (PRFP#1, PRFP#2) for each SIM card profile (PRF#1, PRF#2) in the batch (BTCH2), each SIM card profile packet (PRFP#1, PRFP#2) including: ○ At least one static portion of the SIM card configuration file encrypted using the public key (PPKS), The public key (PPKS) and the at least one dynamic portion of the SIM card configuration file are encrypted using their associated key (PPK#1, PPK#2). • The SIM card profile package (PRFP#1, PRFP#2) is downloaded to the embedded general-purpose integrated circuit card (eUICC1, eUICC2). Each embedded general-purpose integrated circuit card is configured to decrypt at least one static part using the public cryptographic key and at least one dynamic part using its associated cryptographic key to obtain the SIM card profile (PRF#1, PRF#2).
2. The system of claim 1, wherein for each SIM card profile (PRF#1, PRF#2), the batch comprises: - The public cryptographic key (PPKS) encrypted with the associated keys (PPK#1, PPK#2) associated with the SIM card profiles (PRF#1, PRF#2), and - The associated password keys (PPK#1, PPK#2) associated with the SIM card configuration file, Furthermore, each SIM card profile package (PRFP#1, PRFP#2) also includes the associated cryptographic key (PPK#1, PPK#2) associated with the SIM card profile (PRF#1, PRF#2), and the SIM card profile (PRF#1, PRF#2) is associated with the SIM card profile package (PRFP#1, PRFP#2).
3. The system of claim 2, wherein each associated cryptographic key (PPK#1, PPK#2) associated with a SIM card profile (PRF#1, PRF#2) is encrypted with a cryptographic key (S-ENC#1, S-ENC#2) known by the at least one server and known by the embedded general-purpose integrated circuit card, the embedded general-purpose integrated circuit card being configured to download the SIM card profile package (PRFP#1, PRFP#2) associated with the SIM card profile (PRF#1, PRF#2).
4. The system of claim 3, wherein the cryptographic keys (S-ENC#1, S-ENC#2) known by the at least one server and by the embedded general-purpose integrated circuit cards (eUICC1, eUICC2) are computed using the Diffie-Hellman algorithm.
5. The system according to any one of claims 1 to 4, wherein the public cryptographic key is a random value.
6. The system according to any one of claims 1 to 5, wherein the associated cryptographic key is a random value.
7. The system according to any one of claims 1 to 6, wherein the batch further comprises an identifier associated with the at least one static portion and an identifier associated with the at least one dynamic portion for each SIM card profile, and the other server is configured to assemble the at least one static portion and the at least one dynamic portion of the SIM card profile based on the identifier of the static portion and the identifier of the dynamic portion to form the SIM card profile package.
8. The system according to any one of claims 1 to 7, wherein each SIM card profile includes a plurality of static parts and a plurality of dynamic parts.
9. The system of claim 8, wherein the at least one server (PM, SM-DP) is configured to group all said static portions of the SIM card profile into a portion of the SIM card profile package.
10. The system according to any one of claims 1 to 9, wherein the batch further comprises at least one integrity check value.
11. The system of claim 10, wherein the at least one integrity check value is a hash value associated with the at least one static portion.
12. A method for downloading a SIM card configuration file to different embedded general-purpose integrated circuit cards (eUICC1, eUICC2), the method comprising: - A SIM card profile (PRF#1, PRF#2) is generated by at least one server (PM, SM-DP) according to a given configuration. Each SIM card profile includes at least one static portion that is common to all SIM card profiles (PRF#1, PRF#2) and at least one dynamic portion that differs between the SIM card profiles (PRF#1, PRF#2). - A batch (BTCH2) of the SIM card profiles (PRF#1, PRF#2) is generated by the at least one server (PM, SM-DP), the batch including at least one dynamic portion of each SIM card profile and at least one common static portion appearing only once, the at least one static portion being encrypted using a public cryptographic key (PPKS), and the at least one dynamic portion of each SIM card profile being encrypted using a cryptographic key (PPK#1, PPK#2) associated with the SIM card profile (PRF#1, PRF#2). - The batch (BTCH2) is received by another server (SM-DP). - The other server generates SIM card profile packets (PRFP#1, PRFP#2) for each SIM card profile (PRF#1, PRF#2) in the batch (BTCH2), each SIM card profile packet (PRFP#1, PRFP#2) including: ○ At least one static portion of the SIM card configuration file encrypted using the public key (PPKS), The public key (PPKS) and at least one dynamic portion of the SIM card configuration file are encrypted using their associated key (PPK#1, PPK#2). - Download the SIM card configuration file packages (PRFP#1, PRFP#2) from the other server (DM) to the embedded general-purpose integrated circuit card (eUICC1, eUICC2). -The SIM card profile (PRF#1, PRF#2) is obtained by decrypting at least one static part using the public cryptographic key and at least one dynamic part using its associated cryptographic key by each embedded general-purpose integrated circuit card (eUICC1, eUICC2).
13. The method of claim 12, wherein for each SIM card profile (PRF#1, PRF#2), the batch comprises: - The public cryptographic key (PPKS) encrypted with the associated keys (PPK#1, PPK#2) associated with the SIM card profiles (PRF#1, PRF#2), and - The associated password keys (PPK#1, PPK#2) associated with the SIM card configuration file, Furthermore, each SIM card profile package (PRFP#1, PRFP#2) also includes the associated cryptographic key (PPK#1, PPK#2) associated with the SIM card profile (PRF#1, PRF#2), and the SIM card profile (PRF#1, PRF#2) is associated with the SIM card profile package (PRFP#1, PRFP#2).
14. The method of claim 13, further comprising encrypting each associated cryptographic key (PPK#1, PPK#2) associated with a SIM card profile (PRF#1, PRF#2) with cryptographic keys (S-ENC#1, S-ENC#2) known to the at least one server and known to the embedded universal integrated circuit card (eUICC1, eUICC2), the embedded universal integrated circuit card (eUICC1, eUICC2) being configured to download the SIM card profile package (PRFP#1, PRFP#2) associated with the SIM card profile.
15. The system of claim 14, wherein the cryptographic keys (S-ENC#1, S-ENC#2) known by the at least one server and by the embedded general-purpose integrated circuit cards (eUICC1, eUICC2) are computed using the Diffie-Hellman algorithm.
16. The method according to any one of claims 12 to 15, wherein the public cryptographic key is a random value.
17. The method according to any one of claims 12 to 16, wherein the associated cryptographic key is a random value.
18. The method of any one of claims 12 to 17, wherein the batch further comprises an identifier associated with the at least one static portion and an identifier associated with the at least one dynamic portion for each SIM card profile, and wherein the other server (DM) assembles the at least one static portion and the at least one dynamic portion of the SIM card profile based on the identifier of the static portion and the identifier of the dynamic portion to form the SIM card profile package.
19. The method according to any one of claims 12 to 18, wherein each SIM card profile includes a plurality of static portions and a plurality of dynamic portions.
20. The method of claim 19, wherein generating the batch comprises grouping all of the static portions of the SIM card profile into a portion of the SIM card profile package.
21. The method according to any one of claims 12 to 20, wherein the batch further comprises at least one integrity check value.
22. The method of claim 21, wherein the at least one integrity check value is a hash value associated with the at least one static portion.