IMEI STORAGE

DE502017017189D1Active Publication Date: 2026-01-22GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502017017189
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2016-04-19
Filing Date
2017-04-13
Publication Date
2026-01-22
Estimated Expiration
2037-04-13

AI Technical Summary

Technical Problem

Existing mobile devices face issues with IMEI manipulation and alteration, compromising network connectivity and security, as current protection mechanisms are not robust enough to prevent tampering.

Method used

A chipset with a secure processor and one-time programmable memory is used to store the IMEI, ensuring it is programmed during production and cannot be modified, with secure channels for updating and encryption to protect the IMEI from unauthorized changes.

Benefits of technology

The IMEI is safeguarded against manipulation, maintaining network integrity and security by ensuring the IMEI remains tamper-proof throughout the device's lifecycle.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

Field of invention

[0001] The invention relates to a chipset for a mobile communication-enabled terminal device with a terminal device serial number (IMEI) assigned to the terminal device and stored in the terminal device, and to a terminal device. State of the art

[0002] The world is connected via mobile networks, and this connectivity continues to advance. Mobile-enabled devices communicate via mobile networks. Classic examples of mobile-enabled devices include smartphones, mobile phones, and tablets. Mobile-enabled devices also include control devices (controllers, measuring devices, or combined control / measuring devices) for industrial facilities in commercial or private settings. Industrial facilities include, for example, production plants that have one or more control devices (end devices) capable of communicating with a background system and / or with each other via a mobile network. Other examples of industrial facilities include smart home devices such as heating systems or electrical appliances with end devices in the form of control devices.

[0003] The IMEI, short for International Mobile Equipment Identity, is a unique 15-digit serial number for each mobile device. This number allows every mobile device in the GSM or UMTS system and their successors to be uniquely identified worldwide. Dual-SIM phones have two IMEI numbers.

[0004] The IMEI of a mobile phone can be retrieved by entering *#06# in the phone number field, as standardized in the GSM system. This retrieval option is desirable. According to GSM regulations, an IMEI must be unique and protected against manipulation, such as forgery or alteration, by the user. This is specified in [1] ETSI TS 122 016, Chapter 2 "General", page 5: "The IMEI shall not be changed after the ME's final production process. It shall resist tampering, ie manipulation and change, by any means (eg physical, electrical and software)." However, in practice, it is shown that manipulation of the IMEI is possible for many mobile phones that have been on the market since 2002.

[0005] To use a mobile-enabled device, such as a smartphone or mobile phone, in a network operator's mobile network, the device contains a subscriber identity module with a subscription profile, or simply profile. The profile configures the device and its connection to the mobile network. It consists of a structured data set that enables the establishment, operation, and termination of the device's connection to the mobile network and includes, for example, a cryptographic authentication key (Ki) and an International Mobile Subscriber Identity (IMSI).

[0006] The device itself has a chipset with one or more end-device chips for operating the device's functions. Current (and older) smartphones, for example, typically have a chipset that includes at least three end-device chips: a transceiver IC, which handles the physical radio communication; a baseband processor (BB) (or equivalently, modem), which performs data transmission over radio communication at the protocol level; and an application processor (AP), on which the operating system and application software, such as apps, run. Additional end-device chips may include transceiver ICs for other radio channels, particularly for short-range radio channels such as NFC (near field communication) or Bluetooth.

[0007] The subscriber identification module can conventionally be integrated into carriers of different form factors, in particular plug-in and embedded carriers. Subscriber identification modules in plug-in (e.g., classic SIM card) and embedded (module designed for soldering into an end device) form factor carriers are located on a dedicated, separate chip or SoC (system-on-chip).

[0008] US 2006 / 0236111 Al ([2]) relates to a method for manufacturing an electronic device comprising a chipset with memory and a "special-purpose DSP". In this method, a combination of the electronic device's IMEI and a customer ID is written as a protectable identifier into an OTP area of ​​the electronic device's flash memory, enabling a loading module that loads software into the electronic device to uniquely identify the entity authorized to reprogram the electronic device, e.g., the device's authorized customer.

[0009] US Patent 2007 / 0050622 Al ([3]) provides techniques to prevent the replacement of an OTP component. The OTP component may be part of a wireless device. The wireless device is configured so that programming a new IMEI code into the OTP component is only permitted when the wireless device is in a secure mode. A challenge-response protocol is used to put the wireless device into this secure mode.

[0010] In US 2012 / 0011345 Al ([4]), processor hardware (e.g., eUICC) includes a microcode interpreter. If encrypted microcode is contained in a message from a service, the microcode can be passed to the microcode interpreter. Based on the decryption and execution of the microcode on the processor hardware, extended functionality can be implemented.

[0011] In WO 2014 / 134829 Al ([5]), methods and MultiSIM devices with integrated SIM functionality are provided. The method includes downloading at least one subscription from a secure application manager to a secure remote management element within user equipment. The method also includes determining whether or not an identity should be assigned with respect to the at least one subscription. Furthermore, the method includes informing the user equipment about the at least one subscription present at the time of identity assignment. This allows subscriptions and a pool of identities to be managed and remotely controlled efficiently and flexibly.

[0012] In US 2010 / 0180130 Al ([6]), an electronic device requires valid control keys to change the usage restriction setting. The device is provided with control keys, a secret key, and a signed software object containing a batch ID and a hash of the secret key. For each control key, the device generates a cryptographic footprint bound to the device and the secret key. A message authentication code (MAC) for each usage restriction setting is generated, along with the MAC bound to the device and a control key. To change a usage restriction, the device receives a control key, validates it against the stored footprint, modifies the usage restriction setting, and generates a new MAC for that usage restriction setting.The footprints of the control keys are bound to the secret key, but the device only retains a hash of the secret key.

[0013] CN 102 083 055 A ([7]) relates to an IMEI authentication procedure, an IMEI-protected mobile communication terminal, and an initialization device therein. The procedure comprises the following steps: capturing ciphertext authentication data from an OTP area of ​​a FLASH of the mobile communication terminal and capturing a decryption key stored in the FLASH; decrypting the ciphertext authentication data into plaintext authentication data using the decryption key according to a preset algorithm, wherein the plaintext authentication data includes at least one IMEI; and authenticating the plaintext authentication data and outputting the authentication result.The IMEI can be stored in the OTP region of the FLASH, effectively preventing any change to the IMEI; and the IMEI is tied to the unique identity of the mobile communication terminal, thus further enhancing the protection effect.

[0014] A more recent concept for the form factor of a subscriber identity module is the integrated subscriber identity module, which is integrated onto a terminal chip or SoC (System-on-Chip) of the terminal device, meaning it does not have its own separate chip. Integrated subscriber identity modules are designated with the suffix "integrated" or "i" and are referred to, for example, as integrated UICC, iUICC, iSIM, or iUSIM. Summary of the invention

[0015] The invention is based on the objective of specifying a chipset for a mobile communication-enabled terminal device in which the terminal device serial number IMEI assigned to the terminal device can be stored in a manner that is as tamper-proof as possible, and a corresponding terminal device.

[0016] The task is defined by the features of the independent patent claims. Advantageous embodiments of the invention are specified in the dependent claims.

[0017] The chipset according to claim 1 is intended for use with an end device as defined above, for example, a smartphone or mobile phone, or a control device in an industrial environment. The chipset comprises at least one secure processor in which a one-time programmable memory is integrated. At least one end device serial number – e.g., the IMEI – is stored in the chipset. The method is characterized in that information for protecting the end device serial number against manipulation is stored in the one-time programmable memory.

[0018] The solution according to claim 1 has the advantage that the one-time programmable memory is programmed once during the production of the chipset and cannot be modified later. This ensures that the information securing the device serial number remains as programmed during production and cannot be manipulated later. Consequently, the device serial number is protected against manipulation via this security information.

[0019] Therefore, according to claim 1, a chipset is created in which the terminal serial number is protected against manipulation.

[0020] A mobile communication-enabled terminal device according to the invention comprises a chipset according to the invention.

[0021] According to one embodiment of the invention, access to the information stored in the one-time programmable memory for securing the terminal serial number and / or to the terminal serial number is possible exclusively by the Secure Processor.

[0022] According to further embodiments of the invention, the chipset comprises at least one further processor, in particular an application processor and / or a baseband processor and / or one or more further processors, wherein access to the information stored in the one-time programmable memory for securing the terminal serial number and / or to the terminal serial number itself is not possible by the at least one further processor.

[0023] The Secure Processor typically offers a higher level of security compared to other processor cores in the chipset, such as a Baseband Processor, an Application Processor, or an Interface Processor (NFC, Bluetooth, WLAN, etc.). Therefore, it is preferable to grant security-critical access to the information used to secure the device serial number and / or the device serial number itself exclusively to the Secure Processor.

[0024] The chipset optionally includes, more precisely than a further processor, a baseband processor (BB) which is configured for the protocol layer of a mobile communication connection between the chipset and a server outside the chipset. In this embodiment of the invention, the secure processor and the baseband processor are configured to establish and operate a secure channel between the secure processor and the baseband processor, so that messages sent from the server to the chipset via the radio connection, in particular messages containing updated terminal serial numbers, can be extracted by the baseband processor and forwarded to the secure processor via the secure channel.The Secure Channel can also be used to securely transfer update data for subscription profiles for integrated subscriber identity modules of the chipset or update data for operating systems of the chipset between the Baseband Processor and the Secure Processor.

[0025] According to further embodiments of the invention, at least two or more terminal serial numbers of the terminal device are stored simultaneously in the chipset, wherein at least two or more terminal serial numbers are assigned to at least two different components of the chipset. These components can, in particular, be different processors of the chipset. Furthermore, different (integrated) subscriber identification modules, different subscription profiles, or different operating systems of the chipset can be provided as components. Thus, each different (integrated) subscriber identification module, each different subscription profile, or each different operating system has its own assigned terminal serial number (e.g., IMEI).

[0026] According to a first embodiment of the invention, designed to ensure tamper protection, the information stored in the one-time programmable memory includes the device serial number itself, or consists precisely of the device serial number itself. In this case, the device serial number can only be stored once, e.g., during the chipset production process, and is subsequently unchangeable, thus directly protecting it against tampering.

[0027] According to a second embodiment of the invention, designed to ensure tamper protection, the information stored in the one-time programmable memory does not directly include the device serial number, but rather a key used to secure the device serial number. The device serial number is stored in a separate memory, which need not be one-time programmable memory and, according to one embodiment, is even specifically rewritable. The key, and thus the security mechanism for the device serial number, is designed according to one of two variants. According to the first variant, the key is an encryption key for encrypting the device serial number. According to the second variant, the key is a backup key from which an encryption key for encrypting the device serial number can be derived.In both cases, the device serial number is encrypted with the encryption key. In the first case, the encryption key is stored directly in the OTP (One-Time Password). In the second case, the encryption key can only be derived from the backup key stored in the OTP. In the second version, and regardless of the key variant, the chipset also includes an encryption mechanism configured to encrypt the device serial number with the encryption key to create an encrypted device serial number and to store the encrypted device serial number in a dedicated memory location within the chipset.

[0028] According to embodiments of the invention, a non-volatile memory, which in some embodiments is specifically rewritable, is coupled or can be coupled to the Secure Processor, wherein the encryption device is set up to store the encrypted terminal serial number in the non-volatile memory.

[0029] In the second implementation variant, the device serial number is indirectly protected against manipulation by storing the information used to secure the device serial number only once, e.g., during the chipset production process, and then being unchangeable. In this second implementation variant, the device serial number itself is stored in non-volatile memory in a form secured by the security information, e.g., encrypted with the encryption key as an encrypted device serial number. In implementations where the secured (e.g., encrypted) device serial number is stored in rewritable non-volatile memory, an authorized entity with access to the security information can update the device serial number.The backup information in the one-time programmable memory (OTP) simultaneously ensures the protection of the terminal serial number against unauthorized manipulation.

[0030] According to one alternative, the non-volatile memory is designed as external memory of the chipset (external because it is not directly located on the chip area of ​​the Secure Processor) located outside the Secure Processor, but within the chipset itself, and is connected or connectable to the Secure Processor via a system bus of the chipset. According to another alternative, the non-volatile memory is designed as integrated internal memory located within the Secure Processor, integrated at the chip technology level on the chip area of ​​the Secure Processor.

[0031] Optionally, the chipset includes an integrated subscriber identity module iUICC in which a subscription profile is stored or implemented, or which is configured to store and implement a subscription profile.

[0032] A method according to the invention for updating the terminal serial number in a chipset according to the invention comprises the following steps: b) in the chipset, receiving an updated terminal serial number intended to replace the terminal serial number stored in the chipset, and supplying the updated terminal serial number to the Secure Processor; c) in the Secure Processor, in response to receiving the data from step b), obtaining the encryption key by: either reading the encryption key from the one-time programmable memory; or reading the backup key from the one-time programmable memory and subsequently deriving the encryption key from the backup key; d) encrypting the updated terminal serial number with the encryption key to create an encrypted updated terminal serial number; e) storing the encrypted updated terminal serial number in (rewritable) non-volatile memory.

[0033] The procedure optionally includes, prior to step b), step a) sending the updated terminal serial number from a server to the chipset, and receiving the sent updated terminal serial number by the chipset.

[0034] Optionally, the updated terminal serial number is sent to the chipset in an isolated terminal serial number update step or procedure, which has the sole or predominant purpose and content of updating the terminal serial number.

[0035] Alternatively, updating the terminal serial number can be integrated into an initial transfer or update of a subscription profile or operating system to the chipset. In this alternative approach, the chipset contains an integrated subscriber identification module in which at least one subscription profile is stored, or which is configured to store a subscription profile. The updated terminal serial number is then sent either a) as part of a transfer of a subscription profile or operating system to the chipset, or as part of a subscription or operating system update for a subscription profile already present in the chipset. This approach has the advantage that a subscription profile or operating system and the associated terminal serial number are automatically kept consistent.

[0036] According to embodiments of the method, the chipset comprises a baseband processor, and supplying the updated terminal serial number to the secure processor involves sending the updated terminal serial number from the baseband processor to the secure processor via the secure channel between the baseband processor and the secure processor. The secure processor has security resources for securely handling terminal serial numbers, whereas the baseband processor does not, or at least not necessarily. The baseband processor, on the other hand, provides the chipset with an interface to an OTA server, which holds an updated terminal serial number for the chipset. OTA (over-the-air) servers are configured in connection with cellular-enabled terminals that have a subscriber identification module (SIM) to communicate with the SIM over a cellular connection.The Secure Processor itself has no interface to OTA servers. The Secure Channel between the Baseband Processor and the Secure Processor enables an updated endpoint serial number received from the OTA server at the Baseband Processor to be securely forwarded within the chipset to the Secure Processor. Securing the communication from the OTA server to the Baseband Processor is not the subject of this application and can be achieved, for example, using known methods.

[0037] The procedure optionally includes the further step: f) rendering the stored terminal serial number unusable by deleting the stored encrypted terminal serial number, overwriting the encrypted terminal serial number with the updated encrypted terminal serial number or rendering it unusable by other means.

[0038] The procedure optionally includes, upon receipt of an updated terminal serial number, authentication and / or verification of a counter. Authentication is the authentication of the server to the chipset using one or more authentication keys stored in the one-time programmable memory. Verification is the verification of counter information received along with the updated terminal serial number against reference counter information stored in the one-time programmable memory. This ensures that the storage of the updated terminal serial number is only permitted if a certain number of terminal serial number updates, as defined by the reference counter information, has not yet been exceeded. Brief description of the drawings

[0039] The invention will now be explained in more detail using exemplary embodiments and with reference to the drawing, which shows: Fig. 1 shows a schematic representation of a chipset according to one embodiment of the invention. Detailed description of implementation examples

[0040] Fig. 1 Figure 1 shows, in schematic form, a chipset according to one embodiment of the invention. The chipset comprises the following components: a Secure Processor (SP), a Baseband Core Processor (BB) (a BB is sometimes also referred to as a modem), an Application Processor (AP) (with one or more, here multiple, processor cores, i.e., processor cores or CPUs), and a memory chip with a rewritable non-volatile memory (NVM) located outside the Secure Processor (SP) but within the chipset. The chipset is enclosed in a chipset package. The non-volatile memory (NVM) in this example is made of... Fig. 1The external storage ext NVM is provided within the chip package but located outside the Secure Processor SP (i.e., not internal, but directly on the Secure Processor SP chip), but can alternatively be located entirely outside the chip package. In another variant, which is described in Fig. 1 The non-volatile memory (NVM), shown with a dashed line, is an internal memory (int NVM) of the Secure Processor SP, which is permanently assigned to the Secure Processor SP and integrated into the Secure Processor SP chip, for example, at the level of the integrated semiconductor manufacturing technology. The components are in Fig. 1The Secure Processor SP and the Baseband Core Processor BB are coupled via a system bus. A Secure Channel (S-CH) is physically established between the Secure Processor SP and the Baseband Core Processor BB via this system bus, enabling secure data exchange between them. Data is exchanged between the Secure Processor SP and the Baseband Core Processor BB at the protocol level within the Secure Channel S-CH as APDU commands according to the widely used ISO 7816 standard. Alternatively, data can be exchanged in a format other than the ISO 7816 APDU format. The Secure Channel S-CH is established through authentication and key agreement and operated via subsequent encrypted data exchange.

[0041] The Secure Processor SP comprises an SP Core (i.e., a CPU), a one-time programmable memory (OTP) area, a read-only UICC ROM, a dedicated UICC RAM, a cryptographic unit (CRYPTO), a memory management unit (Mem Mgr), and an interface unit (I / O Unit). As mentioned, in addition to the one-time programmable memory (OTP), the Secure Processor SP chip area can also include a rewritable non-volatile memory (NVM), as indicated by the dashed lines. The memory management unit (Mem Mgr), the cryptographic unit (CRYPTO), and the interface unit (I / O Unit) work together to establish and operate the Secure Channel (S-CH) between the Secure Processor SP and the Baseband Core Processor (BB) using authentication and encryption. The Secure Processor SP includes an integrated subscriber identity module (iUICC).The read-only UICC ROM and the UICC RAM are specifically designated for integrated subscriber identification modules (iUICC) on the Secure Processor SP. The chipset also includes general-purpose RAM, shown here as external RAM (ext RAM), which is located outside the Secure Processor SP and is available to the other processor cores as main memory.

[0042] The one-time programmable memory (OTP) area stores keys for authentication and encryption for setting up and operating the Secure Channel S-CH. According to a first alternative of the invention, the terminal device serial number (IMEI) is also stored in the OTP area. In the case of multiple IMEIs, the multiple terminal device serial numbers (IMEI, IMEI', IMEI", ...) are stored. The terminal device serial number(s) (IMEI, IMEI', IMEI", ...) is / are stored in the OTP area either in plaintext or in encrypted form as enc(IMEI). According to a second alternative of the invention, the terminal device serial number(s) (IMEI, IMEI', IMEI", ...) is / are stored in the (external or internal) rewritable non-volatile memory (NVM) (ext NVM or int NVM), particularly in the case of ext NVM, necessarily in encrypted form as enc(IMEI), encrypted with an encryption key.In this second variant, the encryption key, or a backup key from which the encryption key can be derived, is stored in the one-time programmable memory (OTP area).

[0043] For the concept of an integrated iUICC and an eUICC, a mechanism is desirable that allows not only the profile data but also, if necessary, the entire operating system to be exchanged remotely, since the SIM card cannot simply be physically replaced. This mechanism is also known as eSIM management. Because subscriptions, operating systems, and network operators can theoretically change any number of times over the hardware (chipset) lifecycle, storing the IMEI for each subscription in rewritable non-volatile memory is preferable. Similarly, if sufficiently large rewritable non-volatile memory is provided, it is possible for multiple profiles or operating systems, or multiple iUICCs, to reside concurrently on the chipset.Therefore, to simplify the assignment of IMEI to profile / operating system, it is advantageous to manage the IMEI as part of the subscription update via the remote management system, together with the iUICC or eUICC profile / operating system (OS). This allows the IMEI to be transferred to the device either as an integral part of the subscription (e.g., in a dedicated elementary file within the UICC data structure) or as separate data within the same update process, in the event of an operating system or profile change, or when multiple subscriptions are active simultaneously (possibly from different network operators). This ensures that a dedicated IMEI is always assigned to the currently valid and active subscription. Cited state of the art

[0044] [1] ETSI TS 122 016, Digital cellular telecommunications system (Phase 2+); Universal Mobile Telecommunications System (UMTS); LTE; International Mobile Equipment Identities (IMEI); 3GPP TS 22.016 version 10.0.0 Release 10; [2] US 2006 / 0236111 A1; [3] US 2007 / 0050622 A1; [4] US 2012 / 0011345 A1; [5] WO 2014 / 134829 A1; [6] US 2010 / 0180130 A1; [7] CN 102 083 055 A.

Claims

1. Chipset for a terminal, the chipset comprising at least one secure processor in which a one-time programmable memory (OTP area) is integrated, wherein at least one terminal serial number of the terminal is stored in the chipset, wherein the chipset contains an integrated subscriber identity module in which a subscription profile is stored as a component of the chipset, or which is set up to store a subscription profile as a component of the chipset, and wherein information for protecting the terminal serial number against manipulation is stored in the one-time programmable memory (OTP area), and wherein an update of the terminal serial number is integrated into a transmission or an update of the subscription profile to the chipset.

2. Chipset according to claim 1, wherein access to the information stored in the one-time programmable memory (OTP area) for protecting the terminal serial number and / or to the terminal serial number is possible exclusively by the secure processor.

3. Chipset according to claim 2, which comprises at least one further processor, wherein access to the information stored in the one-time programmable memory (OTP area) for protecting the terminal serial number and / or to the terminal serial number is not possible by the at least one further processor.

4. Chipset according to claim 3, which comprises, as a further processor, a baseband processor (BB) which is set up for a radio link between the chipset and a server outside the chipset, and wherein the secure processor and the baseband processor (BB) are set up to set up and operate a secure channel (S-CH) between the secure processor and the baseband processor (BB), so that messages sent from the server to the chipset via the radio link can be received by the baseband processor (BB) and can be forwarded to the secure processor via the secure channel (S-CH).

5. Chipset according to any one of claims 1 to 4, wherein at least two or more terminal serial numbers, IMEI, IMEI', IMEI"..., of the terminal are stored simultaneously in the chipset, wherein at least two or more terminal serial numbers, IMEI, IMEI', IMEI"..., are assigned to at least two different components of the chipset.

6. Chipset according to any one of claims 1 to 5, wherein the information stored in the one-time programmable memory (OTP area) comprises the terminal serial number or consists of the terminal serial number.

7. Chipset according to any one of claims 1 to 6, wherein the information stored in the one-time programmable memory (OTP area) comprises a key which is designed: as an encryption key for encrypting the terminal serial number; or as a protection key from which an encryption key for encrypting the terminal serial number can be derived; and wherein the chipset further comprises an encryption device which is set up to encrypt the terminal serial number with the encryption key to form an encrypted terminal serial number and to store the encrypted terminal serial number in the chipset.

8. Chipset according to claim 7, wherein a non-volatile memory is coupled or can be coupled to the secure processor, and wherein the encryption device is set up to store the encrypted terminal serial number in the non-volatile memory.

9. Chipset according to claim 8, wherein the non-volatile memory is either designed as an external memory (ext NVM), arranged outside the secure processor, of the chipset and is coupled or can be coupled to the secure processor via a system bus of the chipset, or alternatively is designed as an internal memory (int NVM), arranged inside the secure processor and integrated on the chip of the secure processor SP at the chip level.

10. Method for updating the terminal serial number in a chipset according to any one of claims 7 to 9, comprising the steps: b) in the chipset, receiving an updated terminal serial number which is intended to replace the terminal serial number stored in the chipset, and supplying the updated terminal serial number to the secure processor c) in the secure processor, in response to the reception from step b), obtaining the encryption key by: - either reading the encryption key from the one-time programmable memory (OTP area); - or reading the backup key from the one-time programmable memory (OTP area) and subsequently deriving the encryption key from the backup key; d) encrypting the updated terminal serial number with the encryption key to form an encrypted updated terminal serial number; e) storing the encrypted updated terminal serial number in the non-volatile memory.

11. Method according to claim 10, further comprising, before step b), the step: a) sending the updated terminal serial number from a server to the chipset.

12. Method according to claim 11, wherein the chipset contains an integrated subscriber identity module in which at least one subscription profile is stored or implemented, or which is set up to store or implement a subscription profile, and wherein the a) sending of the updated terminal serial number, IMEI*, takes place as part of a transmission of a subscription profile or of an operating system to the chipset, or as part of a subscription update or operating system update for a subscription profile.

13. Method according to any one of claims 10 to 12, wherein the chipset is designed according to claim 4 and comprises a baseband processor (BB), and wherein the supplying of the updated terminal serial number to the secure processor comprises sending the updated terminal serial number from the baseband processor (BB) to the secure processor via the secure channel (S-CH) between the baseband processor (BB) and the secure processor .

14. Method according to any one of claims 10 to 13, further comprising the step: f) rendering the stored terminal serial number unusable by deleting the stored encrypted terminal serial number, overstoring the encrypted terminal serial number with the updated encrypted terminal serial number or rendering it unusable in some other way.

15. Method according to any one of claims 10 to 14, further comprising, on the occasion of the reception of an updated terminal serial number: - authenticating the server with respect to the chipset by means of one or more authentication keys stored in the one-time programmable memory (OTP area); or / and - verifying counter information received together with the updated terminal serial number with respect to reference counter information stored in the one-time programmable memory (OTP area), in order to cause the storage of the updated terminal serial number to be permitted only at most if a number of updates to the terminal serial number stipulated by the reference counter information has not yet been exceeded.

16. Mobile radio-enabled terminal, comprising a chipset according to one of the preceding chipset claims 1 to 9.