Managing a subscription profile
The method ensures user consent and compliance with contractual agreements by requiring input before administrative actions in subscriber identity modules, addressing the lack of autonomy in existing systems.
Patent Information
- Application Number
- DE102015012943
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2015-10-07
- Publication Date
- 2025-12-11
- Estimated Expiration
- 2035-10-07
AI Technical Summary
Existing subscription management systems in subscriber identity modules lack user autonomy and consent mechanisms, allowing unsolicited administrative actions that may violate contractual agreements.
A method requiring user input before performing administrative actions in the subscriber identity module, such as loading or modifying profiles, ensuring the user's consent and compliance with contractual obligations.
Ensures user autonomy and compliance with contractual agreements by requiring user input before administrative actions, preventing unnoticed profile changes and allowing review of pending actions.
Smart Images

Figure 00000005_0000 
Figure 00000005_0001 
Figure 00000005_0002
Abstract
Description
Field of invention
[0001] The invention relates to a method for managing a profile for a subscription (subscription profile) in a subscriber identity module. State of the art
[0002] Mobile devices are operated securely in wireless networks using participant identity modules, also known as secure elements. Mobile devices can include, in particular, mobile communication devices such as smartphones, as well as M2M devices.
[0003] As part of setting up a subscriber identity module, a subscription profile must be loaded into the module. Changes to the subscription profile (or simply profile) require the provision of a modified subscription profile. For plug-in SIM cards in mobile devices, the change can be made by replacing the SIM card. Alternatively, a new subscription profile is loaded into the subscriber identity module, which is particularly useful for permanently soldered subscriber identity modules (e.g., eUICC in mobile communications or permanently soldered M2M modules) that cannot be easily replaced. Managing subscriptions, especially by downloading subscription profiles and accompanying data into a subscriber identity module, is generally referred to as subscription management.
[0004] The technical specifications [1] 12FAST.13 - Embedded SIM Remote Provisioning Architecture 17 December 2013", GSMA, and [2] SGP02-Remote-Provisioning-Architecture-for-Embedded-UICC-Technical-Specification-v2.0, 13 October 2014, GSMA, describe the downloading and installation of a subscription profile into an eUICC. According to [1] 12FAST.13, a Subscription Management Data Preparation SM-SP and a Subscription Management Secure Router SM-SR are involved in loading a subscription profile into a subscriber identity module.
[0005] The Subscription Management Data Preparation (SM-SP) contains subscriber identity module-specific information and uses this information to generate a load package from the subscription profile, which is then loaded into the subscriber identity module. The SM-SP provides this load package to the Subscription Management Secure Router (SM-SR), which in turn loads the load package into the subscriber identity module. Within the subscriber identity module, the load package is unpacked, and the profile is implemented based on the unpacked package contents. Changes to profiles already existing in the subscriber identity module are made in a similar manner. The Subscription Management Secure Router (SM-SR) receives a load package containing the desired changes from the Subscription Management Data Preparation (SM-SP) and sends it to the subscriber identity module. Within the subscriber identity module, the load package is unpacked, and the profile changes are implemented based on the unpacked package contents.
[0006] The Subscription Management Data Preparation (SM-SP) (via the Subscription Management Secure Router SM-SR) can send load packages containing profiles to be loaded or changes to already implemented profiles to the subscriber identity module without the user's knowledge or consent. A mobile device owner or user may not want such unnoticed or unsolicited administrative actions, such as profile loading or profile changes, to occur in the subscriber identity module.
[0007] In particular, the Subscription Management Data Preparation (SM-SP) can be operated by an issuer of the Subscriber Identity Module (SIM). After the SIM is handed over to the subscriber or user, the subscriber or user enters into contractual usage agreements with parties other than the SIM issuer, such as a mobile network operator. Some of the administrative actions performed on the SIM by the issuer, without their knowledge or consent, could violate contractual usage agreements between the other party (e.g., the network operator) and the user or subscriber. With the existing profile management infrastructure, the user / subscriber has no means of independently ensuring and enforcing compliance with their contractual usage agreements.
[0008] Document [3] EP2835995A1 from the prior art discloses a method for switching between two subscriptions in a subscriber identity module by executing a script.
[0009] Document [4] US2013 / 0165073A1, a prior art document, discloses a method for activating a subscription in a subscriber identity module in response to receiving an authentication request in the subscriber identity module, additionally requiring the entry of a PIN by a user at a user interface.
[0010] Document [5] WO2012 / 076419A1 from the prior art discloses a method for transferring a SIM application from a first terminal to a second terminal, wherein the SIM application together with a code is exported from the first terminal to a remote location, from there it is imported back into the second terminal, wherein during the import into the second terminal it is required that a user enters an activation code which corresponds to the exported code.
[0011] Document [6] US7480907B1, a prior art document, discloses a method for updating the firmware in an electronic device, using a user interface to manage the generation, distribution and storage of update information.
[0012] Document [7] US8200761B1, a prior art document, discloses a method for managing emails or message data comprising executable and non-executable parts, wherein a user makes inputs via an interface. In particular, the user can make an input by clicking, which causes no further user input to be required for subsequent corresponding actions. Summary of the invention
[0013] The invention is based on the objective of creating a method for managing a profile for a subscription (subscription profile) in a subscriber identity module, which provides the holder or user of the subscriber identity module with more autonomy vis-à-vis a publisher of the subscriber identity module.
[0014] The problem is solved by a method according to claim 1. Advantageous embodiments of the invention are specified in the dependent claims.
[0015] The inventive method for managing a subscription profile in a subscriber identity module comprises the steps: a) sending an administrative message from a server to the subscriber identity module and c) performing an administrative action in the subscriber identity module corresponding to the administrative message. The method is characterized by the following step prior to step c): b) requesting and receiving user input from the subscriber identity module and performing step c) only upon successful completion of step b).
[0016] By requiring user input before the administrative action initiated by the administrative message is carried out in the participant identity module, it is ensured that the user has the opportunity to review pending administrative actions for conformity with their own expectations and contractual obligations. This prevents administrative actions from being carried out unnoticed against the user's will. The user is thus given the opportunity to express their wishes in the administrative action process.
[0017] Alternatively, user input can be provided as an authentication input, in particular a static access code such as a PIN (personal identification number) or a static password, or a one-time password or OTP (one time password).
[0018] Alternatively, user input is requested and received via an input / output interface, e.g. a touch pad or touch display, of a mobile device in which the participant identity module is operated.
[0019] Furthermore, as an administrative measure, loading an administrative message to load a profile into the participant identity module is planned, and / or implementing a profile in the participant identity module.
[0020] In other words, the user is given the opportunity to intervene and is prompted to provide input before a loading profile is loaded into the participant identity module. Alternatively or additionally, the user is given the opportunity to intervene and is prompted to provide input before an already loaded loading profile is implemented in the participant identity module. Depending on the specific case, the loading package is initially loaded into the participant identity module without hindrance, and only then is the user's consent obtained via their input. The user can then review the contents of the loading package and, depending on its contents, agree to or reject its implementation. In another case, the user's consent is obtained before a loading package is even loaded into the participant identity module. In this case, the user can already refuse to load the loading package.
[0021] Furthermore, as an alternative or additional administrative measure, loading an administrative message for modification and / or modifying a profile already implemented in the participant identity module is provided. In this case, the administrative message is optionally first loaded into the participant identity module. The user is then prompted to provide input. The user is then given the opportunity to review the content of the change and, depending on the content, either approve (consent) or reject (objection) it.
[0022] Alternatively, step a) is performed by sending the administrative message from a data processing server via a security router to the participant identity module.
[0023] Optionally, step c) comprises the following sub-steps: c1) Release of the administrative action by the participant identity module and c2) Execution of the administrative action. Release optionally occurs in response to the receipt of an affirmative input from the user, i.e., a declaration of consent, e.g., by entering "Confirm" via a corresponding menu on the touchscreen of the terminal device.
[0024] According to a feature of the invention, the user has the option to define exception criteria in order to have certain administrative measures carried out even without user input, even unnoticed in the background.
[0025] According to the characteristic, the procedure further includes the step preceding step b) of evaluating the administrative message for fulfillment of an exception criterion. If the administrative message fulfills the exception criterion, step b) is skipped and step c) is performed immediately. For example, the exception criterion is fulfilled by updates to the already implemented, active profile. The exception criterion is not fulfilled, for example, by administrative actions that concern a different profile than the active profile, or that originate from or concern a different network operator than the one that maintains the currently implemented, active profile.
[0026] Thus, according to claim 1, a method for managing a subscription profile in a subscriber identity module is created, which provides the holder or user of the subscriber identity module with more autonomy from a publisher of the subscriber identity module.
[0027] Alternatively, the exception criterion can be created based on user input received at an earlier time. In this earlier user input, the user defined and saved, for example, which administrative actions may be carried out even without user input. Brief description of the drawings
[0028] The invention will now be explained in more detail with reference to exemplary embodiments and the drawings, which show: Fig. 1. A diagram illustrating the loading of a load package for loading a profile from a data processing server via a security router into a participant identity module, according to the state of the art; Fig. 2 A diagram of loading a load package for loading a profile from a data processing server via a security router into a subscriber identity module, according to an embodiment of the invention. Detailed description of implementation examples
[0029] Fig. Figure 1 shows a diagram illustrating the state-of-the-art process of loading an administrative message in the form of a load packet M from a data processing server SM-DP into a subscriber identity module eUICC. The load packet M includes a load sequence PL for implementing a subscription profile P in the subscriber identity module eUICC. The data processing server SM-DP sends the load packet M to a security router SM-SR, which in turn sends the load packet M to the subscriber identity module eUICC. By processing the load sequence PL from the load packet M, the profile P is implemented in the subscriber identity module eUICC.
[0030] Fig.Figure 2 shows a diagram illustrating the loading of an administrative message in the form of a load packet M for loading a profile P from a data processing server SM-DP via a security router SM-SR into a subscriber identity module eUICC, according to an embodiment of the invention. (a) First, the data processing server SM-DP sends the load packet M to the subscriber identity module eUICC. Initially, the subscriber identity module eUICC either blocks (prevents) the acceptance or processing of the load packet M. (b) Instead, (b1) the subscriber identity module eUICC, via the terminal device ME in which the subscriber identity module eUICC is operated, prompts a user of the terminal device ME to enter information on the terminal device ME, e.g., a PIN (personal identification number) or a one-time password OTP (one-time password). (b2) The user enters the requested information, e.g., by entering the PIN or OTP. (b3) The input, e.g.,The PIN or OTP is forwarded to the eUICC subscriber identity module for verification. If verification is successful (c) (c1), the block on accepting or processing the load packet m is lifted. (c2) Consequently, the load packet M is loaded into the eUICC subscriber identity module and subsequently processed, or the loaded but blocked load packet M is processed. By processing the load packet M, the load sequence PL is executed and the profile P is implemented in the eUICC subscriber identity module. Cited state of the art [1] 12FAST.13 - Embedded SIM Remote Provisioning Architecture 17 December 2013, GSMA [2] SGP02- Remote-Provisioning - Architecture-for- Ern bedded- UICC-Technical-Specification-v2.0, 13 October 2014, GSMA [3] EP2835995A1 [4] US2013 / 0165073A1 [5] WO2012 / 076419A1 [6] US7480907B1 [7] US8200761B1
Claims
[1] Procedure for managing a profile (P) for a subscription in a subscriber identity module (eUICC), comprising the steps: a) Sending an administrative message (M) from a server (SM-DP) to the subscriber identity module (eUICC); c) Carry out an administrative action corresponding to the administrative message (M) in the Participant Identity Module (eUICC); characterized by the step preceding step c): b) Requesting and receiving user input (PIN, OTP) from the subscriber identity module (eUICC); and Performing step c) only upon successful completion of step b); where the administrative measure is to load an administrative message (M) to load a profile (P) into the subscriber identity module and / or to implement a profile (P) in the subscriber identity module (eUICC); or / and as an administrative measure, loading an administrative message (M) to change and / or changing a profile (P) already implemented in the participant identity module (eUICC) is provided; The procedure further includes the step preceding step b) of evaluating the administrative notification (M) for fulfillment of an exception criterion, whereby if the administrative notification (M) fulfills the exception criterion, step b) is skipped and step c) is carried out immediately. [2] Method according to claim 1, wherein the user input is an authentication input, in particular a static access code (PIN) or a one-time password (OTP). [3] Method according to claim 1 or 2, wherein the user input (PIN; OTP) is requested and received via an input / output interface (TP) of a mobile terminal (ME) in which the subscriber identity module is operated. [4] Method according to any one of claims 1 to 3, wherein step a) is performed as sending the management message (M) from a data preparation server (SM-DP) via a security router (SM-SR) to the subscriber identity module (eUICC). [5] Method according to any one of claims 1 to 4, wherein step c) comprises the following sub-steps: c1) Release of the administrative action by the Participant Identity Module (eUICC); c2) Implementation of the administrative measure. [6] Method according to any one of claims 1 to 5, wherein the exception criterion has been created on the basis of user input received at an earlier time.
Citation Information
Patent Citations
Methods and devices for performing a mobile network switch
EP2835995A1
Method and apparatus for emulating a plurality of subscriptions
US20130165073A1
Mobile services network for update of firmware / software in mobile handsets
US7480907B1
Method and apparatus for improving security in a data processing system
US8200761B1
Method for transmitting a SIM application of a first terminal to a second terminal
WO2012076419A1