Procedure for setting up a user device, setup program, computer-readable media, user device and setup arrangement therefor

The method for deriving registration information using element and location identifiers addresses the challenge of timely and secure provisioning of secure elements, ensuring rapid connectivity and improved operability and security in user devices.

DE102024121784A1Pending Publication Date: 2026-02-05GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
DE102024121784
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-31
Publication Date
2026-02-05

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method, setup program (10), computer-readable data carrier (11), user device (5), and a setup arrangement (1) for setting up a user device (5), for example, a mobile user device (5) for participation in a telecommunications network, are proposed, comprising a secure element (6), in particular an eUICC, configured to manage at least one profile data record (P) for secure operation of the user device (5), and comprising the following steps: providing an element identifier (I) for identifying the secure element (6); providing a location identifier (W) for a home location register (R) of a telecommunications network; and deriving at least one login information (H) for logging the user device (5) from the element identifier (I) and the location identifier (W) and / or a local operator key (E) associated with the location identifier (W).
Need to check novelty before this filing date? Find Prior Art

Description

Field of the InventionThe present disclosure relates to the field of providing data to secure elements, such as embedded universal integrated circuit cards (eUICCs), that include user profiles for authorizing use of user devices, e.g., network devices in the form of cellular phones or the like. In particular, the invention relates to a method for setting up a user device, for example a mobile user device, for participation in a telecommunication network, having a secure element, in particular an eUICC, which is designed to manage at least one profile data record for secure operation of the user device, a setting-up program, a computer-readable data carrier, a user device, in particular a mobile terminal device, for participation in a communication network, and a setting-up arrangement for setting up user devices.BACKGROUND OF THE INVENTIONMethods for handling embedded secure elements such as eUICCs, as well as computer programs, computer readable media, user devices for participation in communication networks, and communication networks are known in the art. For example, on eUICCs, for example on mobile user devices, such as mobile telephones, smartphones, tablets, or the like, respective identification features of users of the user devices are managed. On an eUICC, this is generally done in the form of corresponding embedded subscriber identity modules (eNB). This procedure is necessary in order to meet the security requirements necessary for managing the identification features. This requires a trusted party (eUICC) that can be provided to eUICCs and / or servers, such as eSIM download servers, from which eUICC data records can be obtained or managed as Subscription Manager Data Preparation platform (SM-DP+) while satisfying respective security requirements.Secure elements typically have a system structure with an operating system to interact with device assemblies of terminals on which they are implemented. Storage areas, usually non-volatile memories, of secure elements can be accessed via the operating system and information stored therein, such as identification features, can be handled, managed and queried. For example, this is done with the aid of data elements of corresponding application protocols (application protocol data unit, APDU), which transmit unidirectional commands via a connection interface to secure elements, which are then executed by them.DE 10 2021 001 850 A, for example, relates to a method for personalizing a secure element, comprising the following method steps: receiving, in a data producer, a request for a bundle of storage images for a plurality of secure elements, wherein each requested storage image of the received bundle relates to a secure element of the plurality of secure elements and wherein in each case one secure element of the plurality of secure elements is fixedly installed or is fixedly installed in a corresponding terminal of a plurality of terminals; obtaining, in the data producer, at least one subscription data record for at least one secure element to be personalized of the plurality of secure elements, wherein the subscription data record is obtained from a subscription management server; providing, by the data producer, an operating system or part of the operating system for the secure element to be personalized; generating, by the data producer, a memory image for each of the secure elements according to the received request, wherein the memory image of the secure element to be personalized comprises the provided operating system or the part of the operating system and additionally the obtained at least one subscription data record; and bundling the generated memory images and providing the bundled memory images as a memory image bundle from the data producer for completing the terminals, while introducing at least the memory image of the secure element to be personalized into the secure element for personalizing the secure element.US 10 277 587 B2 describes methods for instantiating multiple electronic subscriber identity modules (eNBs) on an electronic universal integrated circuit card (eUICC) using a large data blob (data blob) installed by the manufacturer. An eSIM packet including the data blob in encrypted form is securely installed in the eUICC in a manufacturing environment. A key encryption key (KEK) associated with the eNB packet is separately provided to the factory of an original device manufacturer (OEM) for wireless devices. The wireless device OEM factory provides the KEK to the eUICC within a particular wireless device. The eUICC uses the KEK to decrypt the eNB packet and provide the data blob. The eUICC may receive a request to instantiate a first eNB. The eUICC may instantiate the first eSIM using data from the data blob. A user can then access network services via the wireless device. Subsequently, a second eSIM can be instantiated by the eUICC using the data blob.EP 2 533 485 B1 relates to methods and apparatuses in a mobile communication system for the over-the-air management of mobile stations containing a secure identification element, preferably a subscriber identity module. Based on a standard challenge-response authentication method implemented in a mobile communication system, not to be used for the intended authentication purpose, but to provide a mobile station with subscription and / or instruction data. The standard challenge-response authentication method is modified in that the challenge is used as a carrier for subscription and / or instruction data. This query containing the subscription and / or instruction data is provided to the mobile station in response to a request from the mobile station to obtain access or connection to the mobile communication system, and includes a special mode indicator data element indicating to the mobile communication system that the mobile station requests subscription and / or instruction data, and is therefore appropriately forwarded to a data provisioning unit configured to provide subscription and / or instruction data.Methods and systems known in the art for providing and updating secure elements of user devices, including operating system updates, may not meet all of the needs relating to operability and availability, on the one hand, and functional security and backup, on the other hand. For example, it is desirable that both the operating system and the secure elements have the same origin and preferably the same level of development to ensure functional security and security. However, due to restrictions on operability and availability, it may not always be ensured that the operating system and the secure elements have the same origin and the corresponding versions or meet certain future requirements, particularly when a new specification or standard for the operation of the user devices is expected to be introduced during the lifetime of the user device and / or the respective secure element.This may limit the functionality, in particular a spectrum of (future) capabilities, of the user device, impair the functional safety and safety during operation of user devices or even result in the devices not being able to be configured correctly, wherein it is to be taken into account that not only the operating system but also the associated data structures may be affected by update methods. In order to update the functional spectrum of the user devices and their devices and to ensure a corresponding level of development, it is desirable to load both the operating system and the data structures onto the secure elements as soon as possible before delivery to a user. In this case, the data structures should simultaneously enable connectivity to be established with a network operator of a telecommunications network and thus enable connectivity as directly as possible after delivery, in order to be able to retrieve further data, such as control data for the user devices, via telecommunications networks, possibly also private networks. However, the network operator may not yet be known if the user device together with the secure element is to be delivered to a user or secure element is to be delivered to a manufacturer of user devices, for which the known prior art cannot yet offer a satisfactory solution.DESCRIPTION OF THE INVENTIONIt is therefore an object of the present invention to enable the timely provision of user devices and / or secure elements as possible shortly before their delivery to a user or manufacturer of user devices. In particular, it can be considered an object to provide a way to handle secure elements and their operating systems and data structures in such a way that a future-secure spectrum of functions, security and protection can be ensured without adversely affecting the operability, availability and / or data integrity, in particular the communication capability of the user devices or of their secure elements.This object is achieved by the subject matter of the independent claims. Exemplary embodiments are evident from the dependent claims and the following description. Features described herein with respect to methods, as well as corresponding method steps, may be implemented as device features, or vice versa. Sections of the description relating to the method therefore also apply analogously to computer programs, computer-readable data carriers, user devices for participation in communication networks and communication networks. In particular, method steps and components mentioned in connection therewith can be implemented as functions of the computer or device programs, computer-readable data carriers, user devices for participation in communication networks and communication networks, and any desired functions of the device or computer programs, computer-readable data carriers, user devices and device arrangements for setting up the user devices for participation in communication networks and communication networks can be implemented as method steps.Method for setting up a user device, for example a mobile user device, for participation in a telecommunication network, having a secure element, in particular an eUICC, which is designed to manage at least one profile data record for secure operation of the user device, comprising the following steps:providing an element identifier for identifying the secure element;providing a location identifier for a home location register of a telecommunications network; andderiving at least one registration information for registering the user device from the element identifier and the location identifier and / or a location operator key assigned to the location identifier.A device program comprising instructions which, when the device program is executed by a user device, cause the user device to execute a corresponding method.A computer readable medium having stored thereon a corresponding setup program according to claim.User device, in particular mobile terminal, for participation in a communication network, having a corresponding setup program according to a computer-readable data carrier and / or configured for executing a corresponding method.Device arrangement for setting up user devices, having a corresponding device program stored therein, a corresponding computer-readable data carrier and / or for executing a corresponding method.The method can thus be executed accordingly by a data processing device or with the aid of a computer, which can be implemented as a user device or server. A device or computer program can comprise instructions which, when the program is executed by a data processing device or a computer, cause the latter to execute the method. A computer-readable storage medium, a computer-readable data carrier and / or a data carrier signal can store or transmit the device or computer program. A corresponding computer-readable data carrier can be present as a computer-readable medium and / or data carrier signal.The element identifier may be a unique electronic identifier (eUICC Identifier - eID) for identifying the secure element. The location identifier can be a location-dependent identifier, in particular a country identifier, such as a mobile country code (MCC) and / or mobile network code (MNC). The local operator key may be associated with the local identifier.The setup or computer program can be provided as an application program for a user device and / or a server, for example for and / or as part of a home location register (HLR). The setup arrangement may comprise the computing or server device for setting up user devices. For example, the server device may comprise a home location register.The solution according to the invention has the advantage that the registration information for registering the user device or the secure element in a telecommunications network of a respective network operator can be generated or provided for the secure element after the location identifier or the location operator key has become known. The login information may be generated at a manufacturer and / or customer of user devices after the secure element has been delivered to the manufacturer or customer. The consumer can then deliver the user device relatively promptly after the log-in information is provided to users, who in turn immediately has connectivity to a telecommunication network with the user device or the secure element available, so that further data, such as control data, can be obtained via the telecommunication network.In this way, a provisioning and / or setup period between an allocation of the registration information and the delivery or connectivity capability of the user device and / or secure element can be kept as short as possible. All further data components on the secure element or for this and / or the user device, such as operating system and / or control data records, device firmware, or the like, can thus also be provided at a relatively late point in time and therefore with the highest possible update. This helps to improve and simplify operability, availability and / or data integrity, in particular communication capability of the user devices or of their secure elements.The solution is not limited to eUICCs, but is generally suitable for so-called secure elements (SEs) or tamper-resistant elements (TREs), which are referred to herein as an integrated circuit card, for example. As such, secure elements include, in addition to eUICCs, for example classic UICCs, integrated UICCs (iUICCs) and all integrated secure elements of a different type, such as, for example, integrated secure elements (iSE / eSE), smart cards, subscriber identity modules, subscriber identity modules (SIMs) and / or virtual SIM (vSIM). Common to all such secure elements is that user datasets or eUICC datasets can be stored thereon, for example as telecommunication profiles or "profiles" for short, with the aid of which users can authenticate themselves to communication networks, such as, for example, as subscribers in telecommunication networks. The secure elements are each distinguished in that the information stored thereon, i.e. in particular the profiles, is particularly protected against third party attacks and is not easily manipulatable either physically or by software.According to one embodiment, it can be provided that the at least one piece of login information comprises a profile identifier and / or a security key. The profile identifier may be a unique International Mobile Subscriber Identity (IMSI). The security key can be a unique security key and / or key for the exchange of data commands or data elements of the application protocol. Thus, the profile identifier and / or security key may be provided at a relatively late time, which helps to improve and simplify operability, availability and / or data integrity, in particular communication capability of the user devices or their secure elements.According to one embodiment, it can be provided that the element identifier and / or the local operator key are obtained or are obtained from a secure instance. The secure instance (trusted entity) can be an instance with corresponding security certification. This helps to ensure a required level of security in the provision of element identifiers and / or out of carrier keys.According to one embodiment, it can be provided that the local operator key is derived from a master key. The secure instance may derive the operator key or a series of operator keys from the master key or operator key. The keys may be managed by the secure entity in a hardware security module. For example, the local operator keys can be generated individually for a respective local identifier or network identifier. This further helps to ensure a required level of security and / or integrity in the provision of operator keys.According to one embodiment, it can be provided that it further comprises a step of recognizing a location of the secure element for the provision of the location identifier and / or the location operator key. For example, the secure element can itself recognize its location when it is switched on for the first time. Alternatively or additionally, a computing device such as a server for setting up the secure element or user device can recognize, assign or communicate the location to the secure element. This can additionally help to improve and simplify the operability, availability and / or data integrity, in particular the communication capability of the user devices or of their secure elements.According to one specific embodiment, it may be provided that an auxiliary profile data record and / or auxiliary identification data record stored therein is used or is used for position recognition of the safe element. The auxiliary profile data record can be a temporary user profile. The auxiliary identification data record can comprise a temporary profile identification of an auxiliary profile data record or can be provided as such, so that a network registration can take place on the basis thereof. The network registration can take place in the case of a respective network provided for this purpose, such as a private network and / or a telecommunication network. The private network can be a network of a consumer or manufacturer of secure elements and / or user devices. The telecommunication network can be a network of a respective network operator. These networks may have their own network identifier. After registration in such a network, the secure element or user device may perform setup steps for which network registration is required, such as location recognition. This can again help to improve and simplify operability, availability and / or data integrity, in particular communication capability of the user devices or of their secure elements.Brief Description of the FiguresExemplary embodiments of the invention are explained in more detail below with reference to schematic drawings.The following are shown: FIG. 1 shows a schematic view of an exemplary embodiment of a device arrangement according to the invention having at least one user device and at least one server device, which are designed to carry out a method for setting up the at least one user device. FIG. 2 shows a schematic view of a further exemplary embodiment of a device arrangement according to the invention having at least one user device and at least one server device, which are designed to carry out a method for setting up the at least one user device.DETAILED DESCRIPTION OF EXEMPLARY EMBODIMENTSThe representations in the figure are schematic and not to scale. If the same reference numerals are used in the following description of the figures in different figures, these usually denote the same or similar elements. Identical or similar elements can, however, also be denoted by different reference numerals.FIG. 1 shows a schematic representation of a device arrangement 1 comprising at least one computing device 2, for example in the form of a server device 3, which is controlled by a trusted entity T, which can contain a hardware security module 4 which is configured to store, manage and / or provide data records for configuring a further computing device 2. The further computing device 2 may be configured as a user device 5, which may be in the form of an Internet of Things (IoT) device, such as a multimedia device, a camera, a loudspeaker, a household appliance, a measuring device, an industrial plant, a vehicle, a vending machine or the like, which is to be associated with a machine entity, and / or as a smart card, identification card, transaction card, personal mobile device, such as a smart phone, a smart watch, etc., which is to be associated with a person entity. The server device 3 may be provided in the form of a server for Subscription Manager Data Preparation+(SM-DP+), for example.In the present example, the device arrangement 1 and the corresponding method comprise a data provision device A, which serves as or is operated by the trusted entity T and can provide registration information H, operating system datasets O and / or profile datasets P, a production device B, which can produce the secure elements 6, and a production device C, which can produce the user devices 5. The data device A, the manufacturing device B and / or the manufacturing device C can be functionally and / or spatially combined as desired or required. Data connections can be set up between the data device A, the production device B and / or production device C as communication connections F or radio connections F.The user devices 5 may be configured for a secure operation, transactions and / or communication, e.g. via a telecommunication network (not shown), by means of at least one profile data set P for a user, respectively user, stored in a corresponding secure element 6 or tamper-proof element (TRE), such as a UICC, eUICC, iUICC, SIM, eSIM, iSIM, SE, eSE or the like, which may be provided in the form of a computer chip. The profile datasets P are generated on the basis of corresponding personal datasets or user datasets U, which are contained in data files on the server device 3, in particular the hardware security module 4 of the trusted entity T. For storing and managing profile records P on the secure elements 6, an operating system record O is installed on the secure element 6, for example, in a secure storage location 7, such as an Issue Security Domain (ISD-R) root, provided on the secure element 6. The secure storage location 7 may have different storage areas.In a data provision phase X, operating system datasets O and / or profile datasets for the user devices 5 on the basis of respective personalization data or user data U can be stored in the data device A, for example, in the server device 2 of the secure instance T, in particular at its hardware security module 3. In the data provision phase X, these data can be kept up-to-date in order to make them available to the manufacturing facility B and / or the manufacturing facility C, if required, in a respective manufacturing phase Y and / or manufacturing phase Z for setting up the user devices 5 or their secure elements 6. Alternatively or additionally, the production phase Y and / or the production phase Z can be arranged in the data device A and / or combined therewith, as desired or as required.A management application 8 or home location register (HLR) may be provided, which may be configured to allow a network provider N, such as a mobile network operator (MNO), to communicate with the user device 5, in particular the secure element 6, using the user profile P stored therein, or to establish secure communication connections F, for example directly and / or via a communication interface (not shown) to the user device 5. The security evidence H may include any type of evidence defined, for example, by the GSMA or the like. The security keys K may comprise all types of cryptographic codes or key elements that may be suitable for interaction with the user devices 5, the secure elements 6, the server device 3 of the trusted entity T as issuers of a part of the operating system dataset O, the management application 8 of the network operator N and / or a component thereof.The authentication certificates L can be, for example, any type of electronic certificate that can be issued by the trusted entity T in order to authenticate the origin of the user devices 5, the secure elements 6, the secure storage location 7, the management application 8 and / or the operating system dataset O. For handling and / or transmitting the operating system dataset O, transmission lines (not shown) may be provided, which may comprise any type of wired and / or wireless transmission chains as communication links F and radio links, respectively, including the Internet (for over-the-air transmissions), as well as other physical and / or non-physical data carriers, which may be configured and secured as desired and as needed by the device arrangement 1 and its components. Further, operating system dataset O may include executable sub-datasets that define application processes and / or may be configured to access data objects. Installation and / or update processes can generally be executed with the aid of an installation dataset, for example a secure installation program, which can be output by the secure instance T. The installation data record can be provided as part of the operating system data record O.In each of the embodiments of the device arrangement 1 described here, in particular the computing devices 2 and the secure element 6 can be configured and configured to be able to execute a computer program in the form of a device program 10. The device program 10 can be stored on a computer-readable data carrier 11, which can be embodied as a computer-readable medium 12 and / or as a data carrier signal 13. When the device program 10 is executed, the security system 1 and its components communicate as indicated in the device program 10. Parameters which are assigned to and / or on which the safety system 1, its components and / or the steps S executed by it are based can be defined in the setup program 10 and / or by it.In a first step S 1, at least one local operator key E, which can be assigned to a location V of the management arrangement 8, can be derived from a master key D, such as a master operator key (master OP), for example, by the data provision device A in the data provision phase X. The location V may have a corresponding location identifier W, such as mobile country code (MCC) and / or mobile network code (MNC). A plurality or series of carrier keys E 1 to E n may be provided, each of which may be allocatable to a respective site V with a respective site identifier W.In a second step S 2, the operator key E can be made available to that manufacturing facility C which is located at the location V for which the operator key W is provided. Independently of this, possibly on the basis of user data U already present at this point in time, in a third step S 3 the registration information H can be provided by the data provision device A in the data provision phase X at least to such an extent that an element identifier I is available for secure elements 6 to be produced. This third step S 3 can be carried out before, after and / or in parallel with the first step S 1. In the present example, the rudimentary registration information H, for example the element identifier I, is made available to the production device B, wherein a corresponding data transmission can be carried out using the server devices 3 or hardware security modules 4 of the data provision device A and / or the production device B.In a fourth step S 4, the secure elements 6 can be provided with the rudimentary registration information H, such as the element identifier I, by the production device B in the production phase Y. In a fifth step S 5, the secure elements 6 provided in the rudimentary application formulas H can be made available to the manufacturing device C. In a sixth step S 6, the user devices 5 can be provided with the secure elements 6 in the manufacturing facility C in the manufacturing phase Z.In a seventh step S 7, the manufacturing device C can be provided with the user data U, operating system datasets O and / or profile datasets P, wherein a corresponding data transmission can be carried out using the server devices 3 or hardware security modules 4 of the data provision device A and / or the manufacturing device C. In an eighth step S 8, a profile identifier J and / or a security key K for a user profile P and / or operating system dataset O can be derived from the local operator key E and a respective element identifier I of the secure elements 6 available to the production stage Z or installed in a user device 5. For this purpose, a communication connection F to the management application 8 can be established.The derivation step can be carried out with the aid of an application program 14, which can be made available by the secure instance T of the production device C, for example in the context of the second step S 2. With the derivation of a profile identifier J and / or a security key K for a user profile P and / or operating system data record O, remaining registration information H can be produced or provided so that a complete registration data record G, for example OPc according to the GSM standard, can be made available as part of the now complete registration information H, of the respective profile data record P and / or operating data record O, which can serve for registration with the management device 8 by the user device 5. The authentication algorithm R can be, for example, a Milenage / TUAK Algo code, which can be stored in that memory area 7 and executed from there.In a ninth step S 9, the set of complete registration information H or a corresponding registration data record G can be provided. In a tenth step S 10, a respective operating system data record O and / or profile data record P can be combined or provided on the basis of the registration information H or the registration data record G. In an eleventh step S 11, operating system data record O and / or profile data record P or log-on information H and / or registration data record G can be loaded onto the secure element 6 provided in each case for this purpose. The corresponding data can be installed in the secure storage location 7 of the secure element 6. The user device 5 with the secure element 6 is now ready for use. Thus, all registration information H necessary for using a telecommunication network is present thereon as registration data set G, which can comprise in particular local operator key E, element identifier I, profile identifier J, security key K and / or certificate L.FIG. 2 shows a schematic view of an exemplary embodiment of a device arrangement 1 according to the invention having at least one user device 5 and at least one server device 3, which are designed to carry out a method for setting up the at least one user device 5. For the sake of efficiency and brevity, only the differences between the exemplary embodiment described in FIG. 1 and the exemplary embodiment described in FIG. 2 will be discussed below. Thus, according to the exemplary embodiment shown in FIG. 2, auxiliary profile datasets Q and / or auxiliary registration information M are provided T by the secure instance.The auxiliary profile datasets Q can already contain all registration information H or respective registration dataset G necessary for registration with a network operator N in the form of corresponding auxiliary registration information M. The auxiliary profile datasets Q can simulate profile datasets P. Accordingly, they can be based at least partially on fictitious or temporary user data U. As such, the auxiliary login information may be already provided to the manufacturing facility B in the third step S 3. This can load the auxiliary registration information M in the framework of the creation phase Y in the fourth step S 4 onto the secure elements 6 and make this together with the auxiliary registration information M available to the production device C in the fifth step S 5.In the manufacturing facility C, the tenth step S 10 can now be dispensed with as it were, either by loading auxiliary profile datasets Q prefabricated for the manufacturing phase Z onto the secure elements 6 in the eleventh step S 11 or by loading these already thereon, for example by installing them on the secure elements 6 by the manufacturing facility B in the manufacturing phase Y. In a twelfth step S 12, the secure elements S 12 can query their location V and / or a corresponding location identifier W via a communication link F and generate an actual location operator key E from this and / or interacting with the application program 14.In a thirteenth step S 13, the user devices 5 or their secure elements 6 can then replace the previously present auxiliary registration information M by an actual registration data record G provided according to user data U with corresponding complete or final registration information H. In this case, location recognition can therefore take place by registration with the network operator N. While this network operator N can be a public network operator, a private network operator can alternatively or additionally be used, in particular in the exemplary embodiment shown in FIG. 1.During the method described above, the secure storage location 7 or its storage areas can be used for the respective requirements in order to store data sets or data objects therein. Thus, in particular the registration information H, the operating system data record O, the profile data record P and / or associated authentication algorithms R can be stored in the secure storage location 7 in such a way that it is as invariable and / or captive as possible, for example by the secure storage location being at least partially embodied as a read-only memory (ROM). The respective server device 3 may provide any data components of the configuration system 1, including the operating system dataset O, possibly together with an installation program dataset, the respective diversified data, such as the security credentials H and / or the user profile P, associated with the user U, to the management application 8 and / or the secure element 6 of the user device 5, for example via the communication interface 9, for storing them for application by the network operator N and at the secure storage location 7 for application by the user U, respectivelyReference numerals denote reference numerals1 Device arrangement 2 Computing device 3 Server device / computing device 4 Hardware security module / HSM 5 User device / computing device 6 Secure element / eUICC 7 Secure storage location 8 Management application / home location register 9 Communication interface 10 Device computer program 11 Computer-readable data carrier 12 Computer-readable medium 13 Data carrier signal 14 Application program A Data provision device B Production device C Production device D Master key E Location operator key F Communication connection / radio connection G Registration data record H Registration information / security proof / reference I Element identifier J Profile identifier K Security key L M Certificate Auxiliary registration information N Network operator / mobile network provider O Operating system data record P Profile data record Q Auxiliary profile data record R Authentication algorithm s Step T Secure instance U User data / user data V Location W Location identifier X Data provision phase Y Production phase Z Production phase S 1 Derivation of location operator key S 2 Provision of location operator key S 3 Provision of rudimentary registration information S 4 Installation of registration information S 5 Provision of secure elements S 6 Production of user devices S 7 Provision of user data S 8 Derivation of remaining registration information S 9 Provision of registration and / or registration information S 10 Provision of data records S 11 Installation of data records S 12 Provisional registration S 13 Generation of registration informationReferences included in the specificationThis list of documents cited by the applicant has been produced in an automated manner and is only included for the better information of the reader. The list is not part of the German patent application or utility model application. The DPMA does not take any adhesion for any faults or omissions.Patent Literature citedDE 10 2021 001 850 A

[0004] U.S. Pat. No. 10,277,587 B2

[0005] EP 2 533 485 B1

[0006]

Claims

Method for setting up a user device (5), for example a mobile user device (5) for participation in a telecommunication network, having a secure element (6), in particular an eUICC, which is designed to manage at least one profile data record (P) for secure operation of the user device (5), comprising the following steps: - providing an element identifier (I) for identifying the secure element (6); - providing a location identifier (W) for a home location register (R) of a telecommunication network; and - deriving at least one registration information (H) for registering the user device (5) from the element identifier (I) and the location identifier (W) and / or a location operator key (E) assigned to the location identifier (W).Method according to claim 1, characterised in that the at least one registration information item comprises a profile identifier (J) and / or a security key (K).Method according to Claim 1 or 2, characterized in that the element identifier (I) and / or the local operator key (E) are obtained from a secure entity (T).Method according to at least one of the above-mentioned claims, characterized in that the local operator key (E) is derived from a master key (D).Method according to at least one of the above claims, characterized in that it further comprises a step of detecting a location (V) of the secure element (6) for the provision of the location identifier (W) and / or the operator key.Method according to at least one of the above-mentioned claims, characterized in that an auxiliary profile data set (Q) and / or auxiliary identification data set (M) stored therein is used or is used for location recognition of the secure element (6).Device program (10), characterized by instructions which, when the device program (10) is executed by a computing device (2), cause the computing device to execute a method according to one of Claims 1 to 6.Computer-readable data medium (11), characterized bya setup program (10) according to Claim 7 stored thereon.User device (5), in particular mobile terminal for participation in a communication network, characterized bya setup program (10) according to claim 7 stored thereon, a computer-readable data carrier (11) according to claim 8 and / or in that the user device (5) is configured to execute a method according to at least one of claims 1 to 6.Device arrangement (1) for setting up user devices (5), characterized bya device program (10) according to Claim 7 stored therein, a computer-readable data medium (11) according to Claim 8 and / or in that the device arrangement (1) is set up to carry out a method according to at least one of Claims 1 to 6.

Citation Information

Patent Citations

  • Provisioning and operating a participant identity module

    DE102018006378A1

  • Method for configuring supply profile of terminal e.g. mobile phone, by embedded universal integrated circuit card, involves obtaining and storing identifier of current supply profile compatible with current use region of terminal

    FR3002408A1

  • Profile Processing Method, Profile Processing Apparatus, User Terminal, and eUICC

    US20180255451A1

  • Improved method for provisioning a user equipment with a subscription profile of an end operator

    WO2024141553A1