Method and apparatus for transmitting embedded subscriber identity module user profile
By using NFC and optical technologies to transmit eSIM user profiles between mobile devices, and combining this with NFC encryption authentication, the security issues in the eSIM profile transmission process in existing technologies are resolved, enabling secure and reliable profile transmission and activation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NXP USA INC
- Filing Date
- 2024-12-23
- Publication Date
- 2026-06-23
AI Technical Summary
In existing technologies, eSIM user profiles are vulnerable to online hacking and theft during transmission between mobile devices, and the lack of encryption measures leads to legal obstacles and insufficient security.
Authentication between mobile devices is performed using Near Field Communication (NFC) technology, combined with optical technology to transmit profile identification information, generate authentication keys, and download user profiles to a profile server. NFC encryption authentication is also used to ensure security.
Security is enhanced during transmission, preventing remote theft and long-distance attacks, ensuring the secure transmission and activation of configuration files, and strengthening trust and security between mobile devices.
Smart Images

Figure CN122269246A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a method for transmitting an embedded user identity module (eSIM) user profile from a first mobile device to a second mobile device using near field communication (NFC) and a profile server. This disclosure also relates to a first mobile device, a second mobile device, and a computer program product.
[0002] Therefore, this disclosure relates to the technical field of mobile communications, and in particular to embedded subscriber identity modules (SIMs) or eSIMs. Background Technology
[0003] User information can be stored on the eSIM. If a user wants to switch mobile phones, they need to transfer their user information from their old phone to the new phone. According to existing technology, such as... Figure 1 As described, a common process involves the new phone scanning a quick-response QR code on the old phone, followed by the old phone generating a key and transferring it to the new phone. The new phone can then use this key to download a user profile from a profile server. Subsequently, the profile server deletes the user profile from the old phone, and the user profile is activated on the new phone.
[0004] One problem with the aforementioned processes in existing technologies is their potential for abuse by so-called online hacking or telecommunications fraud. Users may be attacked or deceived online, and user profiles may be stolen from a distance, creating legal obstacles for local (i.e., national) law enforcement agencies handling such cases because the attackers are not within their local jurisdiction. This is possible because QR codes can be copied and transmitted, or even remotely captured from a mobile device using so-called spyware. Furthermore, currently employed technologies typically lack any encryption, making them vulnerable to online theft. Summary of the Invention
[0005] Improved transfer of user profiles between mobile devices may be required. A method for transferring an embedded user identity module (eSIM) user profile from a first mobile device to a second mobile device using near-field communication (NFC) and a profile server. The first and second mobile devices, as well as a computer program product, are also provided.
[0006] According to one aspect of this disclosure, a method is described for transferring an embedded Subscriber Identity Module (eSIM) user profile from a first mobile device to a second mobile device using a profile server, the first and second mobile devices being within each other's Near Field Communication (NFC) range. The method includes performing transmission authentication on the first and second mobile devices using NFC technology. In response to successful transmission authentication, the method proceeds to transferring profile identification information from the first mobile device to the second mobile device using optical technology. Subsequently, the first mobile device generates an authentication key based on the user profile and transmits it to the second mobile device. The second mobile device then downloads the user profile from the profile server using the authentication key and the profile identification information, and the profile server deletes the user profile from the first mobile device.
[0007] According to another aspect of this disclosure, a first mobile device is described, comprising at least a memory, an NFC unit, a display, and a processor. The memory stores an embedded Subscriber Identity Module (eSIM) user profile. The processor is configured to perform transmission authentication with a second mobile device using the NFC unit, and in response to successful transmission authentication, displays profile identification information on the display. Subsequently, the first mobile device generates an authentication key based on the user profile and transmits it to the second mobile device. The processor also deletes the user profile in response to receiving a deletion instruction from a profile server.
[0008] According to another aspect of this disclosure, a second mobile device is described, which includes at least a memory, an NFC unit, a camera, and a processor. The memory may store an embedded Subscriber Identity Module (eSIM) user profile. The processor is configured to perform transmission authentication with the first mobile device using the NFC unit, and in response to successful transmission authentication, to capture profile identification information from the display of the first mobile device using the camera. The processor is further configured to receive an authentication key from the first mobile device and download a user profile from a profile server using the authentication key and the profile identification information.
[0009] Using NFC technology for authentication ensures that two mobile devices are in the same location. NFC technology is based on contactless connectivity. It operates at a frequency of 13.56 MHz and offers a data rate standard ranging from 106 kilobits per second to 848 kilobits per second. NFC range is typically indicated in centimeters, but in reality, NFC only works reliably within a distance of up to 10 cm, thus preventing long-range attacks.
[0010] In addition, NFC can be encrypted, which significantly enhances security.
[0011] In summary, this disclosure enables improved transmission of embedded user identity module eSIM user profiles from a first mobile device to a second mobile device by using NFC and a profile server.
[0012] The foregoing limitations and other aspects of this disclosure will become apparent from the examples of embodiments described below, and will be explained with reference to these examples. This disclosure will be described in more detail below with reference to examples of embodiments, but this disclosure is not limited to these examples.
[0013] Exemplary embodiments
[0014] According to an embodiment, the method may further include activating a user profile on a second mobile device. Therefore, the processor of the second mobile device may be additionally configured to activate the user profile. Thus, the user profile can be used on the second mobile device.
[0015] According to another embodiment, the method may further include performing activation authentication of the first mobile device and the second mobile device using NFC technology, and activating a user profile on the second mobile device in response to successful activation authentication. Therefore, the processor of the first mobile device may be further configured to perform activation authentication with the second mobile device using the NFC unit, and the processor of the second mobile device may be further configured to perform activation authentication with the first mobile device using the NFC unit and activate the user profile in response to successful activation authentication. This provides additional security, as even if the user profile is stolen, a fraudster cannot activate the user profile.
[0016] According to an embodiment, activation authentication and / or transmission authentication can be encrypted. Therefore, the processors of the first and second mobile devices can be additionally configured to perform activation authentication using encryption. Security is further enhanced by using encryption.
[0017] According to an embodiment, a computer program product includes instructions that, when executed by a computer, cause the computer to perform the methods described above. Attached Figure Description
[0018] Figure 1 The data flow is shown according to existing technology.
[0019] Figure 2 A data flow according to an exemplary embodiment of this disclosure is shown.
[0020] Figure 3 A flowchart illustrating a method according to an exemplary embodiment of the present disclosure is shown.
[0021] Figure 4A schematic configuration of a first mobile device and a second mobile device according to exemplary embodiments of the present disclosure is shown.
[0022] Figure 5 A schematic overview of the interaction between the first and second mobile devices and the configuration file server is shown. Detailed Implementation
[0023] First, based on Figure 4 A brief description of the device is provided. The first mobile device 1 includes a memory 2, in which an embedded Subscriber Identity Module (eSIM) user profile 3 is stored. The mobile device 1 also includes a Near Field Communication (NFC) unit 4, a display 5, and a processor 6. Figure 2 In this context, the first mobile device 1 is also known as the old mobile phone.
[0024] The second mobile device 11 includes at least a memory 12, a near-field communication (NFC) unit 14, a camera 15, and a processor 16, wherein the memory is used to store an embedded user identity module (eSIM) user profile 13. Figure 2 In this context, the second mobile device 11 is also known as the new mobile phone.
[0025] In this context, the term "memory," as referred to by reference numerals 2 and 12, may refer to an eSIM or an embedded universal integrated circuit card (eUICC) that can be used to store eSIM information, i.e., a user profile. The eSIM or eUICC may even have processing capabilities and therefore may also embody part of processors 6 and 16.
[0026] In this context, the terms "processor" or "multiple processors," referred to by reference numerals 6 and 16 for the first mobile device 1 and the second mobile device respectively, may refer to the central processing unit of the respective mobile device. Alternatively, they may refer to a group of circuits distributed throughout the components of the mobile device. Thus, some portions of the processor of the mobile device may be located in the NFC unit, some portions may be located in memory (e.g., eUICC), and so on. Processors 6 and 16 may even each be multiple processing circuits working together.
[0027] Processors 6 and 16 are configured to implement the relevant features of method 100, now combined with Figure 2 , 3 The method is described in section 5. Figure 2 , 3 As can be seen in 5, method 100 begins when the first mobile device 1 and the second mobile device 11 are within each other's near field communication (NFC) range.
[0028] First, in step 110, NFC technology is used to perform transmission authentication between the first mobile device and the second mobile device. This is achieved by using the processor 6 in the first mobile device 1 with NFC unit 4 and the processor 16 in the second mobile device 11 with NFC unit 14.
[0029] In response to the successful transmission authentication in step 110, the method proceeds to step 120, whereby the profile identification information is transmitted from the first mobile device to the second mobile device using optical technology. In the first mobile device 1, the processor 6 displays the profile identification information 7 on the display 5. The profile identification information 7 is optical information, which may be, for example, a barcode, a QR code, text or numbers or a combination of both, one or more colors, or even an image. The processor 16 of the second mobile device 11 uses a camera 15 to capture the profile identification information 7 displayed on the display 5 of the first mobile device 1. The information contained in the profile identification information 7 may be evaluated by the processor 16; for example, the barcode or QR code may be converted to plaintext, or the text or numbers may be processed using Optical Character Recognition (OCR). Figure 5 The symbol QR code is shown on the display 5 of the first mobile device 1. Figure 5 The arrow in step 120 indicates that the information of the configuration file identification information 7 is transmitted from the first mobile device 1 to the second mobile device 11.
[0030] Subsequently, method 100 proceeds to the generation of authentication key 8 by the first mobile device 1 based on user profile 3. Authentication key 8 may be generated by eSIM or eUICC based on instructions from processor 6. Subsequently, in step 140, authentication key 8 is transmitted from the first mobile device 1 to the second mobile device 11. Authentication key 8 may be transmitted by and from the NFC unit 4 of the first mobile device 1 to the NFC unit 14 of the second mobile device 11. Thus, processor 6 may instruct NFC unit 4 to transmit the authentication key. Alternatively, other technologies such as Bluetooth or Wi-Fi may be used to transmit authentication key 8 from the first mobile device 1 to the second mobile device 11. Processor 6 is configured to send authentication key 8 to the second mobile device 11, and processor 16 is configured to receive authentication key 8 from the first mobile device 1. As stated above, this includes instructing a transmission element such as NFC unit 4 to actually transmit authentication key 8. Figure 5 The authentication key 8 in the first mobile device 1 and the second mobile device 11 is shown. Figure 5 As can be seen, authentication key 8 is generated in the first mobile device 1 and transmitted to the second mobile device 11 in step 140. Subsequently, it also exists in the second mobile device 11, and authentication key 8 is then stored in memory 12 by processor 16 or NFC unit 14.
[0031] Subsequently, method 100 proceeds to the point where the second mobile device 11 downloads 150 user profiles 13 from the profile server 20 using authentication key 8 and profile identification information 7. Processor 16 is configured to download user profiles 13 from the profile server 20 using authentication key 8 and profile identification information 7. Figure 5 The arrow at step 150 indicates that the user profile 13 is downloaded from the profile server 20 to the second mobile device 11.
[0032] Method 100 may proceed to step 156, in which user profile 13 is activated on the second mobile device 11. This may be performed in response to the activation authentication of the first mobile device 1 and the second mobile device 11 using NFC technology in step 153, i.e., using NFC units 4 and 14. Since steps 153 and 156 are optional, they are... Figure 3 The middle is indicated by a dashed line.
[0033] To achieve this, the processor 6 of the first mobile device 1 may be configured to perform activation authentication with the second mobile device 11 using the NFC unit 4, and the processor 16 of the second mobile device 11 may be configured to perform activation authentication with the first mobile device 1 using the NFC unit 14. The processor 16 of the second mobile device 11 may also be configured to activate the user profile 13 in response to successful activation authentication.
[0034] Subsequently, method 100 proceeds to the deletion of user profile 3 on the first mobile device 1 by profile server 20. Processor 6 is configured to delete user profile 3 in response to receiving a deletion instruction from profile server 20. Figure 5 The arrow at step 160 indicates that the first mobile device 1 is instructed by the profile server 20 to delete the user profile 3, or in other words, the profile server 20 sends the instruction to delete the user profile 3 to the first mobile device 1.
[0035] As stated above, activation authentication can be encrypted, transmission authentication can be encrypted, or both authentications can be encrypted. Processors 6 and 16 can then be configured to perform one or more corresponding authentications in an encrypted manner.
[0036] It should be noted that the features of the methods described herein can be implemented in the apparatus described herein, and vice versa. Furthermore, combinations of features are possible for other corresponding categories of aspects.
[0037] In summary, transferring user profiles from an old phone to a new phone via an eSIM allows for the replacement of mobile devices. This enables phone swapping, such as moving a plastic SIM card from an old phone to a new one. Telecommunications fraud could use this process to remotely steal user profiles because the profile can be easily applied from one location and used in another, where the two locations may be geographically distant, such as thousands of kilometers apart.
[0038] The disclosed technology facilitates NFC authentication before transmitting a user profile, and optionally, facilitates another NFC authentication to activate the transmitted user profile for use after transmission. This ensures that both mobile phones are in the same location for profile transmission. As another improvement, a converged NFC+eSIM chipset can be used, where NFC technology can directly access the eSIM on the converged chipset, thereby preventing and avoiding online software attacks.
[0039] The disclosed technology overcomes the problems and shortcomings of existing technologies. Specifically, it can prevent online deception or attacks on customers, as well as fraudulent activities involving the theft of profiles from a distance to evade police checks. Furthermore, since NFC authentication only operates within a distance of up to 10cm, it can avoid or prevent long-distance attacks.
[0040] Furthermore, because NFC-to-eSIM authentication can be encrypted, the technology presented is more secure than alternative software solutions. Implementing the presented features on current hardware and software architectures is also easier.
[0041] The presented technology uses NFC to authenticate the initiation of profile transfers between devices, and can also use NFC to further authenticate profile activation, thereby preventing fraudsters from using stolen profiles.
[0042] According to one aspect of the present invention, a method is provided for transmitting an embedded user identity module (eSIM) user profile from a first mobile device to a second mobile device using a profile server, the first mobile device and the second mobile device being within each other's near field communication (NFC) range, the method comprising:
[0043] NFC technology is used to perform transmission authentication between the first mobile device and the second mobile device;
[0044] In response to successful transmission authentication:
[0045] Optical technology is used to transmit configuration file identification information from the first mobile device to the second mobile device;
[0046] The first mobile device generates an authentication key based on the user profile.
[0047] The authentication key is transmitted from the first mobile device to the second mobile device;
[0048] The second mobile device uses the authentication key and the configuration file identification information to download the user configuration file from the configuration file server; and
[0049] The user profile on the first mobile device is deleted by the profile server.
[0050] In one or more embodiments, the method further includes
[0051] Activate the user profile on the second mobile device.
[0052] In one or more embodiments, the method further includes
[0053] Activation authentication of the first mobile device and the second mobile device is performed using NFC technology; and
[0054] The user profile on the second mobile device is activated in response to successful activation authentication.
[0055] In one or more embodiments, the activation authentication is encrypted.
[0056] In one or more embodiments, the transmission authentication is encrypted.
[0057] According to another aspect of the present invention, a first mobile device is provided, comprising at least a memory, a near-field communication (NFC) unit, a display, and a processor, wherein the memory stores an embedded subscriber identity module (eSIM) user profile, and wherein the processor is configured to...
[0058] The NFC unit is used to perform transmission authentication with the second mobile device;
[0059] In response to successful transmission authentication:
[0060] The configuration file identification information is displayed on the display.
[0061] Generate an authentication key based on the user configuration file;
[0062] Transmit the authentication key to the second mobile device; and
[0063] The user profile is deleted in response to receiving a delete command from the profile server.
[0064] In one or more embodiments, the processor is further configured to use the NFC unit to perform activation authentication with the second mobile device.
[0065] In one or more embodiments, the processor is configured to use encryption to perform the activation authentication.
[0066] In one or more embodiments, the processor is configured to use encryption to perform the transmission authentication.
[0067] According to another aspect of the present invention, a second mobile device is provided, comprising at least a memory, a near-field communication (NFC) unit, a camera, and a processor, wherein the memory is used to store an embedded subscriber identity module (eSIM) user profile, and wherein the processor is configured to...
[0068] The NFC unit is used to perform transmission authentication with the first mobile device;
[0069] In response to successful transmission authentication:
[0070] The camera is used to capture profile identification information from the display of the first mobile device;
[0071] Receive authentication key from the first mobile device; and
[0072] The user profile is downloaded from the profile server using the authentication key and the profile identification information.
[0073] In one or more embodiments, the processor is further configured to activate the user profile.
[0074] In one or more embodiments, the processor is further configured to
[0075] Using the NFC unit to perform activation authentication with the first mobile device; and
[0076] The user profile is activated in response to successful activation authentication.
[0077] In one or more embodiments, the processor is configured to use encryption to perform the activation authentication.
[0078] In one or more embodiments, the processor is configured to use encryption to perform the transmission authentication.
[0079] According to another aspect of the present invention, a non-transitory computer-readable medium is provided, comprising a computer program including executable instructions that, when executed, perform or control a method for transmitting an embedded user identity module (eSIM) user profile from a first mobile device to a second mobile device using a profile server, the first mobile device and the second mobile device being within each other's near-field communication (NFC) range, the method comprising:
[0080] NFC technology is used to perform transmission authentication between the first mobile device and the second mobile device;
[0081] In response to successful transmission authentication:
[0082] Optical technology is used to transmit configuration file identification information from the first mobile device to the second mobile device;
[0083] The first mobile device generates an authentication key based on the user profile.
[0084] The authentication key is transmitted from the first mobile device to the second mobile device;
[0085] The second mobile device uses the authentication key and the configuration file identification information to download the user configuration file from the configuration file server; and
[0086] The user profile on the first mobile device is deleted by the profile server.
[0087] In one or more embodiments, the method further includes
[0088] Activate the user profile on the second mobile device.
[0089] In one or more embodiments, the method further includes
[0090] Activation authentication of the first mobile device and the second mobile device is performed using NFC technology; and
[0091] The user profile on the second mobile device is activated in response to successful activation authentication.
[0092] In one or more embodiments, the activation authentication is encrypted.
[0093] In one or more embodiments, the transmission authentication is encrypted.
[0094] According to another aspect of the present invention, a system for transmitting an embedded subscriber identity module (eSIM) user profile is provided, comprising:
[0095] According to any of the first mobile devices disclosed herein;
[0096] According to any of the second mobile devices disclosed herein; and
[0097] The configuration file server is configured as follows:
[0098] In response to receiving authentication key and profile identification information from the second mobile device, the user profile is provided to the second mobile device; and
[0099] The user profile on the first mobile device is deleted. These and other aspects of the invention will become apparent from the embodiments described below, and will be illustrated with reference to these embodiments.
[0100] Figure Labels
[0101] 1 First moving device
[0102] 2. Memory
[0103] 3. Embedded User Identity Module (eSIM) User Profile
[0104] 4 Near Field Communication (NFC) Unit
[0105] 5. Monitors
[0106] 6 processors
[0107] 7 Configuration file identification information
[0108] 8. Authentication Key
[0109] 11 Second mobile device
[0110] 12 Memory
[0111] 13 Embedded Subscriber Identity Module (eSIM) User Profile
[0112] 14 Near Field Communication (NFC) Unit
[0113] 15 cameras
[0114] 16 processors
[0115] 20 Configuration File Server
[0116] 100 Methods for transmitting eSIM user profiles
[0117] 110 Perform transmission authentication
[0118] 120 Transmit configuration file identification information
[0119] 130 Generate authentication key
[0120] 140 Transmit authentication key
[0121] 150 Download the user profile to the second mobile device
[0122] 153 Perform activation authentication
[0123] 156 Activate the user profile on the second mobile device
[0124] 160. Delete the user profile on the first mobile device.
Claims
1. A method for transmitting an embedded user identity module (eSIM) user profile from a first mobile device to a second mobile device using a profile server, characterized in that, The method includes the following: The first mobile device and the second mobile device are within each other's Near Field Communication (NFC) range. NFC technology is used to perform transmission authentication between the first mobile device and the second mobile device; In response to successful transmission authentication: Optical technology is used to transmit configuration file identification information from the first mobile device to the second mobile device; The first mobile device generates an authentication key based on the user profile. The authentication key is transmitted from the first mobile device to the second mobile device; The second mobile device uses the authentication key and the configuration file identification information to download the user configuration file from the configuration file server; and The user profile on the first mobile device is deleted by the profile server.
2. The method according to claim 1, characterized in that, Other than including Activate the user profile on the second mobile device.
3. The method according to claim 1, characterized in that, Other than including Activation authentication of the first mobile device and the second mobile device is performed using NFC technology; and The user profile on the second mobile device is activated in response to successful activation authentication.
4. The method according to claim 3, characterized in that, The activation authentication is encrypted.
5. The method according to claim 1, characterized in that, The transmission authentication is encrypted.
6. A first mobile device, characterized in that, It includes at least a memory, a near-field communication (NFC) unit, a display, and a processor. The memory stores an embedded user identity module (eSIM) user profile, and the processor is configured to... The NFC unit is used to perform transmission authentication with the second mobile device; In response to successful transmission authentication: The configuration file identification information is displayed on the display. Generate an authentication key based on the user configuration file; Transmit the authentication key to the second mobile device; as well as The user profile is deleted in response to receiving a delete command from the profile server.
7. The first mobile device according to claim 6, characterized in that, The processor is further configured to use the NFC unit to perform activation authentication with the second mobile device.
8. A second mobile device, characterized in that, It includes at least a memory, a near-field communication (NFC) unit, a camera, and a processor. The memory is used to store the embedded user identity module (eSIM) user profile, and the processor is configured to... The NFC unit is used to perform transmission authentication with the first mobile device; In response to successful transmission authentication: The camera is used to capture profile identification information from the display of the first mobile device; Receive the authentication key from the first mobile device; as well as The user profile is downloaded from the profile server using the authentication key and the profile identification information.
9. A non-transitory computer-readable medium, characterized in that, The computer program includes executable instructions that, when executed, perform or control a method for transmitting an embedded user identity module (eSIM) user profile from a first mobile device to a second mobile device using a profile server, the first mobile device and the second mobile device being within each other's near-field communication (NFC) range, the method comprising: NFC technology is used to perform transmission authentication between the first mobile device and the second mobile device; In response to successful transmission authentication: Optical technology is used to transmit configuration file identification information from the first mobile device to the second mobile device; The first mobile device generates an authentication key based on the user profile. The authentication key is transmitted from the first mobile device to the second mobile device; The second mobile device uses the authentication key and the configuration file identification information to download the user configuration file from the configuration file server; and The user profile on the first mobile device is deleted by the profile server.
10. A system for transmitting an embedded subscriber identity module (eSIM) user profile, characterized in that, include: The first mobile device according to claim 6; The second mobile device according to claim 8; and The configuration file server is configured as follows: In response to receiving authentication key and profile identification information from the second mobile device, the user profile is provided to the second mobile device; and Delete the user profile on the first mobile device.