IMEI STORAGE
Patent Information
- Application Number
- DE502017016960
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2016-04-19
- Filing Date
- 2017-04-13
- Publication Date
- 2025-07-31
- Estimated Expiration
- 2037-04-13
AI Technical Summary
Existing mobile devices face issues with IMEI manipulation, as they can be altered or forged, compromising network security and user legitimacy.
A chipset with a secure processor and one-time programmable memory is used to store the IMEI, ensuring it cannot be modified post-production, and access is restricted to this processor alone, with optional encryption for added security.
The IMEI is protected against manipulation, maintaining network integrity and user legitimacy by ensuring the IMEI remains unchanged and secure.
Description
Field of the invention
[0001] The invention relates to a chipset for a mobile radio-capable terminal device with a terminal serial number IMEI assigned to the terminal device and stored in the terminal device, and to a terminal device. State of the art
[0002] The world is mobile, and mobile networking is advancing. Mobile devices communicate via mobile networks. Classic mobile devices include mobile devices such as smartphones, cell phones, and mobile tablets. Mobile devices also include control devices (control units or measuring devices or combined control / measuring devices) for industrial facilities in commercial or private environments. Industrial facilities include, for example, production plants that have one or more control devices (end devices) that can communicate with a background system and / or with each other via a mobile network. Other industrial facilities include smart home facilities, such as heating systems or power consumers with end devices in the form of control devices.
[0003] The IMEI, or International Mobile Station Equipment Identity, is a unique 15-digit serial number that uniquely identifies every mobile device in the GSM or UMTS system and successors worldwide. Dual-SIM phones have two IMEI numbers.
[0004] The IMEI of a mobile phone can be retrieved by entering *#06#, which is standardized in the GSM system, in the phone number input field. This query option is desirable. GSM requires that an IMEI be unique and protected from manipulation, such as forgery or alteration, by the user. [1] ETSI TS 122 016, Chapter 2 "General", page 5, stipulates: "The IMEI shall not be changed after the ME's final production process. It shall resist tampering, ie manipulation and change, by any means (eg physical, electrical and software ) ." However, practice shows that it is possible to manipulate the IMEI on many mobile phones that have been on the market since 2002.
[0005] To use a mobile radio-enabled device, such as a smartphone or mobile phone, in a network operator's mobile network, the device contains a subscriber identity module with a subscription profile, or profile for short. The profile manages the configuration of the device and its connection in the mobile network. The profile is formed by a structured data set that enables the establishment, operation, and termination of a connection of the device in the mobile network and includes, for example, a cryptographic authentication key (Ki) and an International Mobile Subscriber Identity (IMSI).
[0006] The terminal device itself has a chipset with one or more terminal chips for operating the terminal's functions. Current (and older) smartphones, for example, typically have a chipset that includes at least three terminal chips: a transceiver IC that carries out the physical radio communication, a baseband processor BB (or equivalently modem) that performs functions for data transmission via radio communication at the protocol level, and an application processor AP on which the operating system and application software, e.g., applications (e.g., apps), are executed. Transceiver ICs for other radio channels, in particular short-range radio channels such as NFC (near field communication) or Bluetooth, can be provided as additional terminal chips.
[0007] The subscriber identity module can traditionally be integrated into carriers of various form factors, particularly plug-in and embedded carriers. Subscriber identity modules in plug-in (e.g., a traditional SIM card) and embedded (a module designed to be soldered into a terminal device) form factors are arranged on a dedicated, separate chip or SoC (System-on-Chip).
[0008] US 2006 / 0236111 A1 ([2]) relates to a method for manufacturing an electronic device comprising a chipset with memory and a special-purpose DSP. A combination of the electronic device's IMEI and customer ID is written as a protectable identifier into an OTP area of a flash memory of the electronic device, thereby enabling a loading module that loads software into the electronic device to uniquely determine the entity authorized to reprogram the electronic device, e.g., the authorized customer of the device.
[0009] US 2007 / 0050622 A1 ([3]) provides techniques to prevent the replacement of an OTP component. The OTP component may be part of a wireless device. The wireless device is configured so that programming a new IMEI code into the OTP component is only permitted when the wireless device is in a secure mode. A challenge-response protocol is used to place the wireless device into this secure mode.
[0010] In US 2012 / 0011345 A1 ([4]), processor hardware (e.g., eUICC) contains a microcode interpreter. If encrypted microcode is included in a service message, the microcode can be passed to the microcode interpreter. Extended functionality can be realized based on the decryption and execution of the microcode on the processor hardware.
[0011] WO 2014 / 134829 A1 ([5]) provides methods and multi-SIM devices with integrated SIM functionality. The method comprises downloading at least one subscription from a secure application manager to a secure element with remote maintenance functionality within a user device. The method also comprises determining whether or not to assign an identity with respect to the at least one subscription. The method further comprises informing the user device of the at least one subscription present upon assignment of the identity. This allows subscriptions and a pool of identities to be managed and remotely controlled efficiently and flexibly.
[0012] In US 2010 / 0180130 A1 ([6]), an electronic device requires valid control keys to change the usage restriction setting. The device is provided with control keys, a secret key, and a signed software object with a batch ID and a hash of the secret key. For each control key, the device generates a cryptographic footprint bound to the device and the secret key. A message authentication code (MAC) for each usage restriction setting is generated, along with the MAC bound to the device and a control key. To change a usage restriction, the device receives a control key, validates it against the stored footprint, changes the usage restriction settings, and generates a new usage restriction MAC setting.The footprints of the control keys are bound to the secret key, but the device only retains a hash of the secret key.
[0013] CN 102 083 055 A ([7]) relates to an IMEI authentication method, an IMEI protection mobile communication terminal, and an initialization device thereof. The method comprises the following steps: acquiring ciphertext authentication data from an OTP area of a FLASH of the mobile communication terminal and acquiring a decryption key stored in the FLASH; decrypting the ciphertext authentication data into plaintext authentication data according to a preset algorithm using the decryption key, wherein the plaintext authentication data includes at least an IMEI; and authenticating the plaintext authentication data and outputting the authentication result.The IMEI can be stored in the OTP region of the FLASH, which effectively prevents the IMEI from being changed; and the IMEI is linked to the unique identity of the mobile communication terminal, which better enhances the protection effect.
[0014] EP 2 829 978 A1 ([8]) describes a method for recognizing mobile terminals and a mobile terminal. The method comprises reading a first International Mobile Equipment Identity (IMEI) stored in a flash; comparing the first IMEI with a backup IMEI stored in a one-time programmable data (OTP) area that must not be changed; and deactivating the mobile terminal if the first IMEI and the backup IMEI are inconsistent. In the present invention, the IMEI plaintext is directly saved in the OTP region of the mobile terminal, and the value of the IMEI stored in the flash and the value of the backup IMEI are dynamically compared to conveniently recognize the legitimacy of the IMEI of the mobile terminal, effectively protect the IMEI number of the mobile terminal from arbitrary changes, and ensure the legitimate interests of users and operators.
[0015] A newer concept for the form factor of a subscriber identity module is integrated subscriber identity modules, which are integrated into a terminal chip or SoC (System-on-Chip) of the terminal device, meaning they do not have their own chip. Integrated subscriber identity modules are designated with the suffix "integrated" or "i" and are referred to as integrated UICC, iUICC, iSIM, or iUSIM, for example. Summary of the invention
[0016] The invention is based on the object of specifying a chipset for a mobile radio-capable terminal in which the terminal serial number IMEI assigned to the terminal can be stored in a manner as secure against manipulation as possible, and a corresponding terminal.
[0017] The problem is solved by the features of the independent patent claims. Advantageous embodiments of the invention are specified in the dependent claims.
[0018] The chipset according to the invention, as defined above, is intended for a terminal device, for example, a smartphone or mobile phone or a control device in an industrial environment. The chipset comprises at least one secure processor, into which a one-time programmable memory is integrated. At least one terminal serial number—e.g., the IMEI—of the terminal device is stored in the chipset. The method is characterized in that information for protecting the terminal serial number against manipulation is stored in the one-time programmable memory.
[0019] The solution according to claim 1 has the advantage that the one-time programmable memory is programmed once during chipset production and cannot be modified later. This ensures that the information used to secure the terminal serial number remains as programmed during production and cannot be manipulated later. Consequently, the terminal serial number is protected against manipulation via the security information.
[0020] Therefore, according to claim 1, a chipset is provided in which the terminal serial number is protected against manipulation.
[0021] A mobile radio-capable terminal according to the invention comprises a chipset according to the invention.
[0022] According to one embodiment of the invention, access to the information stored in the one-time programmable memory for securing the terminal serial number and / or to the terminal serial number is possible exclusively by the Secure Processor.
[0023] According to further embodiments of the invention, the chipset comprises at least one further processor, in particular an application processor and / or a baseband processor and / or one or more further processors, wherein access to the information stored in the one-time programmable memory for securing the terminal serial number and / or to the terminal serial number itself is not possible by the at least one further processor.
[0024] Compared to other processor cores in the chipset, such as a baseband processor, an application processor, or an interface processor (NFC, Bluetooth, WLAN, etc.), the secure processor generally has a higher security level. Therefore, it is preferable to grant security-critical access to the information used to secure the device serial number and / or the device serial number itself exclusively to the secure processor.
[0025] The chipset optionally comprises, more precisely, as a further processor, a baseband processor (BB), which is configured for the protocol layer of a mobile radio connection between the chipset and a server external to the chipset. In this embodiment of the invention, the secure processor and the baseband processor are configured to establish and operate a secure channel between the secure processor and the baseband processor, so that messages sent from the server to the chipset via the radio connection, in particular messages comprising updated terminal serial numbers, can be retrieved by the baseband processor and forwarded to the secure processor via the secure channel.The Secure Channel can also be used to securely transmit update data for subscription profiles for integrated subscriber identity modules of the chipset or update data for operating systems of the chipset between the baseband processor and the secure processor.
[0026] According to further embodiments of the invention, at least two or more terminal serial numbers of the terminal are stored simultaneously in the chipset, wherein at least two or more terminal serial numbers are assigned to at least two different components of the chipset. Different processors of the chipset can be provided as components, in particular. Furthermore, different (integrated) subscriber identity modules or different subscription profiles or different operating systems of the chipset can be provided as components. Thus, each different (integrated) subscriber identity module or each different subscription profile or each different operating system has its own assigned terminal serial number (e.g., IMEI).
[0027] According to a first embodiment of the invention to ensure security against manipulation, the information stored in the one-time programmable memory comprises the terminal device serial number itself, or it consists precisely of the terminal device serial number itself. In this case, the terminal device serial number can only be stored once, e.g., in the production process of the chipset, and can no longer be changed thereafter and is thus directly protected against manipulation.
[0028] According to a second embodiment of the invention to ensure security against tampering, the information stored in the one-time programmable memory does not directly comprise the terminal device serial number, but rather a key with which the terminal device serial number is secured. The terminal device serial number is stored in another memory, which need not be a one-time programmable memory and, according to one embodiment, is even deliberately a rewritable memory. The key, and thus the security of the terminal device serial number, is in turn designed according to one of two variants. According to a first variant, the key is an encryption key for encrypting the terminal device serial number. According to a second variant, the key is a security key from which an encryption key for encrypting the terminal device serial number can be derived.In both cases, the device serial number is encrypted with the encryption key. In the first case, the encryption key is stored directly in the OTP.
[0029] In the second case, the encryption key can only be derived from the security key stored in the OTP. In the second embodiment, regardless of the key variant, the chipset further comprises an encryption device configured to encrypt the terminal device serial number with the encryption key to create an encrypted terminal device serial number and to store the encrypted terminal device serial number in the chipset in a memory provided for this purpose.
[0030] According to embodiments of the invention, a non-volatile memory, which according to some embodiments is specifically rewritable, is coupled or can be coupled to the secure processor, wherein the encryption device is configured to store the encrypted terminal serial number in the non-volatile memory.
[0031] In the second embodiment, the terminal device serial number is indirectly protected against manipulation by storing the information for securing the terminal device serial number only once, e.g., during the chipset production process, and then no longer being changeable. In the second embodiment, the terminal device serial number itself is stored in a non-volatile memory in a form secured by the security information, e.g., in an encrypted form using the encryption key as an encrypted terminal device serial number. In embodiments in which the secured (e.g., encrypted) terminal device serial number is stored in a non-volatile, rewritable memory, an authorized entity with access to the security information can update the terminal device serial number.The security information in the one-time programmable memory (OTP) simultaneously ensures that the device serial number is protected against unauthorized manipulation.
[0032] According to one alternative, the non-volatile memory is designed as external memory of the chipset (external, since it is not provided directly on the chip surface of the secure processor) located outside the secure processor, yet within the chipset, and is coupled or connectable to the secure processor via a system bus of the chipset. According to another alternative, the non-volatile memory is designed as integrated internal memory located within the secure processor, which is integrated at the chip technology level on the chip surface of the secure processor.
[0033] Optionally, the chipset contains an integrated subscriber identity module iUICC in which a subscription profile is stored or implemented, or which is configured to store and implement a subscription profile.
[0034] A method according to the invention for updating the terminal serial number in a chipset according to the invention comprises the steps: b) in the chipset, receiving an updated terminal serial number intended to replace the terminal serial number stored in the chipset and supplying the updated terminal serial number to the secure processor; c) in the secure processor, in response to receiving from step b), obtaining the encryption key by: either reading the encryption key from the one-time programmable memory; or reading the backup key from the one-time programmable memory and then deriving the encryption key from the backup key; d) encrypting the updated terminal serial number with the encryption key to form an encrypted updated terminal serial number; e) storing the encrypted updated terminal serial number in the (rewritable) non-volatile memory.
[0035] The method optionally further comprises, before step b), step a) sending the updated terminal serial number from a server to the chipset, and receiving the sent updated terminal serial number by the chipset.
[0036] Optionally, the updated terminal serial number is sent to the chipset in an isolated terminal serial number update step or process that has the exclusive or predominant purpose and content of updating the terminal serial number.
[0037] Alternatively, the updating of the terminal device serial number is integrated into an (initial) transmission or an update of a subscription profile or an operating system to the chipset. In this alternative approach, the chipset contains an integrated subscriber identity module in which at least one subscription profile is stored, or which is configured to store a subscription profile. In this case, a) the updated terminal device serial number is sent as part of a transfer of a subscription profile or an operating system to the chipset, or as part of a subscription update or operating system update for a subscription profile already present in the chipset. This approach has the advantage that a subscription profile or operating system and a terminal device serial number used in connection with it are automatically kept consistent.
[0038] According to embodiments of the method, the chipset comprises a baseband processor, and supplying the updated terminal serial number to the secure processor comprises sending the updated terminal serial number from the baseband processor to the secure processor via the secure channel between the baseband processor and the secure processor. The secure processor has security resources for securely handling terminal serial numbers, whereas the baseband processor does not, or at least not necessarily. The baseband processor, on the other hand, provides the chipset with an interface to an OTA server, which maintains an updated terminal serial number for the chipset. OTA (OTA = over the air) servers, in conjunction with mobile radio-capable terminals that have a subscriber identity module, are configured to communicate with the subscriber identity module via a mobile radio connection.The Secure Processor itself does not have an interface to OTA servers. The Secure Channel between the Baseband Processor and the Secure Processor enables an updated device serial number received at the Baseband Processor from the OTA server to be securely forwarded to the Secure Processor within the chipset. Securing communication from the OTA server to the Baseband Processor is not the subject of this application and can be achieved using known means, for example.
[0039] The method optionally further comprises the step: f) rendering the stored terminal serial number unusable by deleting the stored encrypted terminal serial number, overwriting the encrypted terminal serial number with the updated encrypted terminal serial number or otherwise rendering it unusable.
[0040] The method optionally further comprises, upon receipt of an updated terminal device serial number, authentication and / or verification of a counter. Authentication is an authentication of the server to the chipset using one or more authentication keys stored in the one-time programmable memory. Verification is a verification of counter information received together with the updated terminal device serial number against reference counter information stored in the one-time programmable memory, in order to ensure that the updated terminal device serial number is only permitted to be stored if a maximum number of terminal device serial number updates specified by the reference counter information has not yet been exceeded. Short description of the drawings
[0041] In the following, the invention is explained in more detail using exemplary embodiments and with reference to the drawing, in which: Fig. 1 shows a schematic representation of a chipset according to an embodiment of the invention. Detailed description of implementation examples
[0042] Fig. 1 shows, in a schematic representation, a chipset according to an embodiment of the invention. The chipset comprises the following components: a Secure Processor SP, a Baseband Core Processor BB (a BB is sometimes also referred to as a modem), an Application Processor AP (with one or more, here several, processor cores, i.e. processor cores or CPUs), a memory chip with a rewritable non-volatile memory NVM arranged outside the Secure Processor SP, but within the chipset. The chipset is housed in a chipset package. The non-volatile memory NVM is in the example made of Fig. 1as external memory ext NVM located within the chip package but outside the Secure Processor SP (i.e. not internal, located directly on the chip of the Secure Processor SP), but can alternatively be located completely outside the chip package. In a further variant, which is Fig. 1 As shown in dashed lines, the non-volatile memory NVM is an internal memory int NVM of the Secure Processor SP, which is permanently assigned to the Secure Processor SP and integrated into the chip of the Secure Processor SP, for example, at the level of the integrated semiconductor manufacturing technology. The components are in Fig. 1linked together via a system bus. Physically speaking, a Secure Channel S-CH is set up between the Secure Processor SP and the Baseband Core Processor BB via the system bus, via which the Secure Processor SP and the Baseband Core Processor BB can securely exchange data. The data is exchanged between the Secure Processor SP and the Baseband Core Processor BB in the Secure Channel S-CH at the protocol level as APDU commands in accordance with the currently widely used ISO 7816 standard. Alternatively, the data is exchanged in a format other than the ISO 7816 APDU format. The Secure Channel S-CH is set up through authentication and key agreement and operated through subsequent encrypted data exchange.
[0043] The Secure Processor SP comprises an SP Core (i.e. a CPU), a one-time programmable memory (OTP) area, a read-only memory (UICC) ROM, an exclusive main memory (UICC) RAM of the Secure Processor SP, a crypto unit (CRYPTO), a memory management (Mem Mgr), and an interface unit (I / O Unit). As mentioned, in addition to the write-once memory (OTP), a rewritable non-volatile memory (NVM) can be included on the chip area of the Secure Processor SP, as indicated by the dashed lines. The memory management (Mem Mgr), the crypto unit (CRYPTO), and the interface unit (I / O Unit) are configured to cooperate with one another to establish and operate the Secure Channel (S-CH) between the Secure Processor SP and the Baseband Core Processor BB using authentication and encryption. An integrated subscriber identity module (iUICC) is configured in the Secure Processor SP.The UICC ROM read-only memory and the UICC RAM are specifically designed for integrated subscriber identity modules (iUICC) on the Secure Processor SP. The chipset also has a general-purpose RAM, shown here as external RAM, which is located outside the Secure Processor SP and is available to the other processor cores as RAM.
[0044] The one-time programmable memory (OTP area) stores keys for authentication and encryption for setting up and operating the Secure Channel (S-CH). Furthermore, according to a first alternative of the invention, the terminal device serial number (IMEI) is stored in the one-time programmable memory (OTP area). In the case of multiple IMEIs, the multiple terminal device serial numbers (IMEI, IMEI', IMEI", ...) are stored. The terminal device serial number(s) (IMEI) is (are) stored either in plain text or in encrypted form as enc(IMEI) in the one-time programmable memory (OTP area). According to a second alternative of the invention, the terminal device serial number(s) (IMEI, IMEI', IMEI", ...) is (are) stored in the (external or internal) rewritable non-volatile memory (NVM) (ext NVM or int NVM), especially in the case of ext NVM, in encrypted form as enc(IMEI), encrypted with an encryption key.In this second variant, the encryption key, or a backup key from which the encryption key can be derived, is stored in the one-time programmable memory OTP area.
[0045] For the concept of an integrated iUICC and an eUICC, a mechanism is desirable that allows not only the profile data but also the entire operating system to be replaced remotely, since the SIM card cannot simply be physically replaced. This mechanism is also known as eSIM management. Since subscriptions, operating systems, and network operators can theoretically change as often as desired over the life cycle of the hardware (the chipset), storing the IMEI for the respective subscription in rewritable, non-volatile memory is preferable. Likewise, if a sufficiently large rewritable, non-volatile memory is provided, it is possible for multiple profiles or operating systems, or multiple iUICCs, to be located in parallel on the chipset.Therefore, to simplify the assignment between IMEI and profile / operating system, it is advantageous to manage the IMEI as part of the subscription update via the remote management system together with the profile / operating system of the iUICC or eUICC. This way, in the event of an operating system or profile change, or when applying different subscriptions active in parallel (possibly from different network operators), the IMEI can be transferred to the device either as an integral part of the subscription (e.g., in a dedicated elementary file in the UICC data structure) or as a separate data content, but in the same update process. This ensures that a dedicated IMEI is always assigned to the currently valid and executed subscription. Cited prior art
[0046] [1] ETSI TS 122 016, Digital cellular telecommunications system (Phase 2+); Universal Mobile Telecommunications System (UMTS); LTE; International Mobile Equipment Identities (IMEI); 3GPP TS 22.016 version 10.0.0 Release 10; [2] US 2006 / 0236111 A1; [3] US 2007 / 0050622 A1; [4] US 2012 / 0011345 A1; [5] WO 2014 / 134829 A1; [6] US 2010 / 0180130 A1; [7] CN 102 083 055 A; [8] EP 2 829 978 A1.
Claims
1. A chipset for a terminal (ME), the chipset comprising: - at least one secure processor (SP) into which a one-time programmable memory (OTP area) is integrated, - a modem (BB); - an application processor (AP); and - a memory chip with a rewritable non-volatile memory (NVM, ext NVM, int NVM), wherein the secure processor (SP) has a higher security level than the application processor (AP), wherein a secure channel (S-CH) is set up between the at least one secure processor (SP) and the modem (BB) via a system bus for secured transmission of data between the secure processor (SP) and the modem (BB), wherein at least one terminal serial number (IMEI) of the terminal (ME) is stored in the one-time programmable memory (OTP area) or in the memory chip (NVM, ext NVM, int NVM), wherein a key for setting up and operating the secure channel (S-CH) is stored in the one-time programmable memory (OTP area), and wherein access to information for securing the terminal serial number (IMEI) and / or the terminal serial number (IMEI) is exclusively granted to the secure processor (SP); wherein an encryption key for encrypting the terminal serial number (IMEI) or a securing key, from which an encryption key for encrypting the terminal serial number (IMEI) can be derived, is also stored in the one-time programmable memory (OTP area); and wherein the chipset further comprises an encryption device which is set up to encrypt the terminal serial number (IMEI) with the encryption key to form an encrypted terminal serial number (enc(IMEI)) and to store the encrypted terminal serial number (enc(IMEI)) in the rewritable, non-volatile memory (NVM, ext NVM, int NVM).
2. The chipset according to Claim 1, wherein the secure channel (S-CH) is set up by authentication and key agreement and is operated by subsequent encrypted exchange of the data.
3. The chipset according to one of the preceding claims, wherein the at least one secure processor (SP) furthermore comprises a memory management (MEMMGR), a crypto unit (CRYPTO) and an interface unit (I / O UNIT) which are set up in a cooperating manner to set up and operate the secure channel (S-CH).
4. The chipset according to one of the preceding claims, wherein the at least one secure processor (SP) furthermore comprises a read-only memory (UICC-ROM) and an exclusive working memory (UICC-RAM) which are provided for at least one integrated subscriber identity module (iUICC) set up in the secure processor (SP), wherein a subscription profile is stored in the integrated subscriber identity module (iUICC), or the integrated subscriber identity module (iUICC) is set up to store a subscription profile.
5. The chipset according to one of the preceding claims, wherein the modem is a baseband processor (BB) which is set up for a radio connection between the chipset and a server outside the chipset, wherein messages sent from the server to the chipset via the radio connection, in particular messages comprising updated terminal serial numbers (IMEI*), can be received by the baseband processor (BB) and can be forwarded to the secure processor (SP) via the secure channel (S-CH).
6. The chipset according to one of the preceding claims, wherein at least two or more terminal serial numbers (IMEI, IMEI', IMEI"...) of the terminal (ME) are stored simultaneously in the chipset.
7. The chipset according to one of Claims 1 to 6, wherein the rewritable non-volatile memory (ext NVM) is arranged outside the secure processor (SP) but within the chipset.
8. The chipset according to one of Claims 1 to 6, wherein the rewritable non-volatile memory (ext NVM) is arranged outside the chipset.
9. The chipset according to one of Claims 1 to 6, wherein the rewritable non-volatile memory (NVM) is an internal memory (int NVM) of the secure processor (SP) which is permanently assigned to the secure processor (SP) and is integrated into the chip of the secure processor (SP).
10. The chipset according to one of Claims 1 to 6, wherein the internal memory (int NVM) of the secure processor (SP) is integrated into the chip of the secure processor (SP) at the semiconductor level.
11. The chipset according to one of the preceding claims, wherein the data are transmitted between the secure processor (SP) and the modem (BB) as APDU commands.
12. Mobile radio-enabled terminal (ME) comprising a chipset according to one of the preceding chipset Claims 1 to 11.
13. Method for operating a chipset according to one of the preceding Claims 1 to 11 for managing the terminal serial number (IMEI) of the terminal (ME) together with the management of a profile or an operating system of a subscriber identity module integrated in the chipset, wherein the terminal serial number (IMEI) is managed as an integral part of the profile or as a separate data content in a common updating process.