Terminal with an assistance module for managing telecommunications profiles stored in the terminal and management method
Patent Information
- Application Number
- EP2023840885
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-12-21
- Filing Date
- 2023-12-20
- Publication Date
- 2025-10-29
AI Technical Summary
Existing solutions for managing telecommunications profiles in LoT devices, such as those standardized by GSMA, face challenges due to limited hardware and lack of user interfaces, making it difficult to implement secure and flexible profile management.
A terminal with two assistance modules, one embedded in the identification module and the other in the terminal itself, allowing for flexible adaptation and secure profile management by switching between operating modes based on the type of profile action, enabling efficient loading and changing of telecommunications profiles.
This solution provides a secure and flexible method for managing telecommunications profiles in LoT devices, optimizing performance and security by leveraging the strengths of both implementations while minimizing complexity and resource requirements.
Smart Images

Figure 1.1
Abstract
Description
[0001] Terminal device with an assistance module for managing telecommunications profiles and management procedures stored in the terminal device
[0002] The invention relates to the management of telecommunication profiles in terminal devices that can be controlled via a data network and have restricted network access or a restricted user interface.
[0003] The GSMA (GSM Association) has already standardized architectures for the remote provisioning of eSIM profiles for end-user devices and for M2M devices. The former requires the configuration of a Local Profile Assistant (LPA) on the user device, which controls the profile lifecycle on the device. The loading of an eSIM profile is initiated by the user. The standard for M2M devices is based on the use of SMS messages and requires the integration of the involved entities. Both known solutions cannot be transferred to IoT devices, or only with disadvantages. IoT devices generally have limited hardware and no dedicated user interface.
[0004] DE 102021127364 A1 discloses an implementation for securely connecting an IoT device to a wireless network, wherein the IoT device communicates with an authentication server via an access point to obtain access data for the network.
[0005] US 20220295281 A1 describes a system for reconfiguring an embedded identification module in a terminal device, wherein identification profiles can be provided to the terminal device from a server via a remote management unit ("remote IoT manager").
[0006] The new GSMA standard SGP.31 "eSIM IoT Architecture and Requirements," version 1.0, released on April 19, 2022, describes an architecture for the remote management of telecommunications profiles specifically for IoT devices. The new standard is based on the GSMA standard SGP.21 for user terminals and adopts key elements from it, including the concept of a profile provisioning entity (SM-DP+). New to the existing architecture are a remote management unit connected to the IoT device and the profile provisioning entity (SM-DP+), as well as an assistance module that can be implemented in two variants. In a first variant, the assistance module is part of the IoT device; in a second variant, it is embodied in the identification module embedded in the IoT terminal. Using profile management actions, the architecture enables the loading and modification of profiles stored in the embedded identification module.Regardless of the implementation, downloading a telecommunications profile always occurs between the support module and the profile provisioning instance.
[0007] Both implementations have advantages and disadvantages. An assistance module is more complex to implement in the IoT end device than in the embedded identification module and is less secure, but it is more powerful and flexible than the latter.
[0008] The object of the invention is to provide a terminal that combines the advantages of both implementations. This object is achieved by a terminal and a method having the features of the independent claims.
[0009] The terminal device according to the invention is characterized in that it comprises a first assistance module configured in the embedded identification module and a second assistance module configured in the terminal device itself, whereby only one of the two assistance modules is active at any one time. The activity of the first or second assistance module defines two operating modes.
[0010] The division into two assistance modules has the advantage that the first assistance module can be flexibly adapted to a given situation. If the remote management unit only supports profile status actions, the implementation of the first assistance module in the embedded identification module can be very streamlined. Since profile status actions require only small amounts of data, the performance requirements of the first assistance module are minimal when implemented in the embedded identification module.
[0011] An embedded identification module equipped with a corresponding first assistance module can be easily set up by downloading it onto a terminal device.
[0012] An embodiment of the invention is described in more detail below with reference to the drawing.
[0013] They show:
[0014] Fig. 1 shows an architecture for setting up and managing a telecommunications profile stored in an embedded identification module in an IoT terminal,
[0015] Fig. 2 shows a flow of a profile status action,
[0016] Fig. 3 loading a profile from a profile provisioning instance into an embedded
[0017] Identification module.
[0018] Description
[0019] Fig. 1 shows an architecture for setting up and managing a telecommunications profile stored in an embedded identification module in an IoT terminal. It includes a profile provisioning instance 10 (Subscription Manager Data Preparation, abbreviated to SM-DP+), a remote management unit 20 (eSIM IoT remote Manager, abbreviated to elM), a mediation server 30 (Subscription Manager Discovery Server, abbreviated to SM-DS), a network operator 40, and a terminal 50, as described, for example, in the GSMA standard SGP.31-V1.0.
[0020] The terminal 50 contains a profile support module 60 formed from two components 52, 72, as well as an embedded identification module 70. The embedded identification module 70 contains a primary domain 74 (ISD-R) of an issuer and at least one profile domain 76 (ISD-P), as also known from the GSMA standard SGP.31-V1.0. Each profile domain 76 (ISD-P) contains a security area 78 (MNO-SD) of a network operator 40. At least one telecommunications profile 80, hereinafter also referred to as a profile, is stored in the security area 78 (MNO-SD). The components of the architecture shown in Fig. 1 each provide one or more interfaces by means of which they are connected to one another via data connections and / or data networks, as explained in more detail below.
[0021] The Profile Provisioning Instance 10 (SM-DP+) has the function of making profile packages containing telecommunication profiles 80 available for download in a secure manner.
[0022] The function of the remote management unit 20 (elM) is to set up and manage profiles 80 stored in the embedded identification module 70 (eUlCC). For this purpose, the remote management unit 20 (elM) uses command data sets to control the loading of profiles 80 into the embedded identification module 70 (eUlCC) as well as the modification of the states of stored profiles 80. Command data sets include profile management operations, which can specifically refer to loading operations (profile download) and profile state management operations (PSMO). Optionally, the remote management unit 20 (elM) can be configured to convert profile packages during loading processes in order to convert them into a protocol required for using an interface, for example, a narrowband protocol.
[0023] The task of the mediation server 30 (SM-DS) is to provide the addresses of profile provisioning instances 10 (SM-DP+) in response to discovery requests from the connected components 20, 50.
[0024] For example, network operator 40 is a mobile network operator.
[0025] The terminal device 50 can, for example, be a component in a consumer product, such as a car or a camera, or part of a sensor unit. It generally does not have a user interface. The terminal device 50 can, in particular, be an IoT terminal device.
[0026] The profile support module 60 communicates with the profile provisioning instance 10 (SM-DP+), the remote management unit 20 (eLM) and the embedded identification module 70 (eUlCC) and enables the loading of profiles 80 into the embedded identification module 70 (eUlCC) as well as the changing of the states of loaded profiles 80.
[0027] The embedded identification module 70 is designed, for example, as an eUlCC, ie in the form of a hardware and software-secured HW element that is installed in a terminal device 50.
[0028] The architecture and its components comply with the GSMA standard SGP.31-V1.0 and associated standards.
[0029] Deviating from the architecture according to the GSMA standard SGP.31-V1.0, in the inventive architecture shown in Fig. 1, the profile support module 60 consists of two components: a first assistance module 72 (IPAe) and a second assistance module 52 (IPAd). The first assistance module 72 (IPAe) is embodied in the embedded identification module 70 (eUICC). The second assistance module 52 (IPAd) is implemented as part of the terminal 50.
[0030] Components 10, 20, 30, 40, 50, 52, 70, 72 each provide one or more interfaces by means of which they are connected to one another via conventional data connections and / or data networks. Profile provisioning instance 10 (SM-DP+) provides interfaces 100 (ES8+), 110 (ES9+'), 120 (ES9+), 130 (ES12), 140 (ES2+) to remote management unit 20 (elM), mediation server 30 (SM-DS), second assistance module 52 (IPAd), and network operator 40. Profile provisioning instance 10 (SM-DP+) communicates with second assistance module 52 (IPAd) via the protocols and interfaces defined in the GSMA standard SGP.22. This allows, in particular, a profile provisioning instance 10 (SM-DP+) according to the GSSMA standard SGP.22 to be used to implement the architecture, without the need to implement a special communication channel for communication with the second assistance module 52 (IPAd).
[0031] The first assistance module 72 (IPAe) provides an external interface 150 (ES8+) to the remote management unit 20 and an external interface 160 (Eil) to the mediation server 30 (SM-DS). Furthermore, within the embedded identification module 70, it has an interface 200 to the profile domain 76 (ISD-P).
[0032] The second assistance module 52 (IPAd) is connected within the terminal 50 via internal interfaces 220, 230 to the embedded identification module 70 (eUlCC) and further has an external side interface 170 (ESipa) to the remote management unit 20 (elM).
[0033] The second assistance module 52 (IPAd) is configured to exchange data with the profile provisioning instance 10 (SM-DP+) in order to load a new profile 80 into the embedded identification module 70 (eUlCC). Communication between the second hardware assistance module 52 (IPAd) and the profile provisioning instance 10 (SM-DP+) takes place using a second protocol, preferably the protocol defined in SGP.22.
[0034] The second assistance module 52 (IPAd) can request and receive activation codes from the remote management unit 20 (elM) via the side interface 170 (ESipa).
[0035] The security area of the network operator 78 (MNO-SD) in the embedded identification module 70 (eUlCC) further has an external interface 240 (ES6) to the network operator 40 via the terminal device 50.
[0036] Via the interface 140 (ES2+) between network operator 40 and profile provisioning instance 10 (SM-DP+), network operator 40 controls administrative functions according to the GSMA standard SGP.21 and orders profiles 80 for embedded identification modules 70 (eUlCC).
[0037] Via the interface 240 (ES6) between network operator 40 and embedded identification module 70 (eUlCC), network operator 40 manages profile contents using OTA services.
[0038] A secure end-to-end connection for managing the profile domain 76 (ISD-P) and the profiles stored therein during download and installation is provided via the logical interface 100, 150 (ES8+), which exists between the first assistance module 72 IPAe and the profile provisioning instance 10 (SM-DP+) and between the second assistance module 52 IPAd and the profile provisioning instance 10 (SM-DP+).
[0039] A secure transmission of profile packages, for example in the form of Bound Profile Packages, takes place via interface 120 (ES9+) between profile provisioning instance 10 (SM-DP+) and second assistance module 52 (IPAd). Via interface 110 (ES9+ 1 The secure transmission of profile packages takes place between profile provisioning instance 10 (SM-DP+) and remote management unit 20 (elM). The remote management unit 20 (elM) acts on behalf of the first assistance module 72 (IPAe).
[0040] Via interface 220 (ESlOa) between second assistance module 52 (LPAd) and embedded identification module 70 (eUlCC), the second assistance module 52 (IPAd) receives configured addresses for the mediation server 30 (SM-DS) and, optionally, for the profile provisioning instance 10 (SM-DP+). Via interface 220 (ESlOa), the second assistance module 52 (IPAd) transmits profile packages (Bound Profile Packages) to the embedded identification module 70 (eUlCC).
[0041] Via the interface 160 (ES11) between the mediation server 30 (SM-DS) and the first assistance module 72 (IPAe), the first assistance module 72 (IPAe) can retrieve event data records for the embedded identification module 70 (eUlCC).
[0042] Via interface 180 (ESU 1 During the communication between the remote management unit 20 (eLM) and the mediation server 30 (SM-DS), the remote management unit 20 (eLM) retrieves event records for the respective embedded identification module 70 (eULCC). The remote management unit 20 (eLM) can act on behalf of the first assistance module 72 (IPAe).
[0043] Through the interface 130 (ES12) between Profile Provisioning Instance 10 (SM-DP+) and Mediation Server 30 (SM-DS), Profile Provisioning Instance 10 creates or removes event registrations on Mediation Server 30 (SM-DS).
[0044] The logical interface 210 (ESpsmo) allows secure end-to-end communication between the remote management unit 20 (elM) and the embedded identification module 70 (eUlCC) and is used to transmit profile management actions (PSMO).
[0045] The remote management unit 20 (eLM) communicates with the first assistance module 72 (IPAe) via the logical interface 190 (ESipa). The embedded identification module 70 (eUlCC) is adapted to support the interface 190. The interface 190 enables a secure end-to-end connection between the remote management unit 20 (eLM) and the embedded identification module 70 (eUlCC).
[0046] The remote management unit 20 (eLM) controls profile management actions via interface 190. The remote management unit 20 (eLM) constantly communicates with the first assistance module 72 (IPAe) in the embedded identification module 70 (eUICC). The remote management unit 20 (eLM) can trigger the loading of a profile 80 via interface 190. Profile status actions (PSMO) are also performed via interface 190.
[0047] A profile is loaded by providing a profile 80 in the profile provisioning instance 10 (SM-DP+) and transferring it via the architecture to the network operator's security area 78 (MNO-SD).
[0048] Changing a profile 80 loaded into an embedded identification module (eUICC) is performed using profile status actions (PSMO). Profile status actions can include, in particular, activating a profile, deactivating a profile, deleting a profile, listing profile information, outputting profile metadata, or updating a profile. The two assistance modules 52, 72 (IPAd, IPAe) are operated such that only the first assistance module 72 or the second assistance module 52 is active at the same time. If the first assistance module 72 (IPAe) is active and the second assistance module 52 (IPAd) is deactivated, this forms a first operating mode. If the second assistance module 52 (IPAd) is activated and the first assistance module 72 (IPAe) is deactivated, this forms a second operating mode. Which assistance module is activated and which operating mode is set depends on the type of profile management action to be performed.
[0049] The first assistance module 72 (IPAe) is activated when it receives a profile management action from the remote management unit 20 (elM). Profile management actions include loading profiles and modifying profiles via a profile status action.
[0050] If a profile management action is a profile status action that concerns a change in the state (PSMO) of a telecommunications profile 80 stored in the embedded identification module (eUlCC), the first assistance module 72 (IPAe) causes its execution by the embedded identification module 70 (eUlCC).
[0051] After execution of a profile status action, the first assistance module 72 (IPAe) sends a feedback about the execution to the remote management unit 20 (elM), wherein the feedback is sent by means of a first protocol, preferably by means of an ESPSMO protocol, e.g. an MQ.TT or lightweight M2M protocol.
[0052] If a profile management action sent to the first assistance module 72 (IPAe) concerns the loading of a new profile 80, the first assistance module 72 (IPAe) transfers the execution of the profile management action to the second assistance module 52 (IPAd). The first assistance module 72 (IPAe) deactivates itself and activates the second assistance module 52 (IPAd).
[0053] The second assistance module 52 (IPAd) is activated when a profile management action involves loading a new profile (Profile Download). It then triggers the execution of this profile management action.
[0054] The second assistance module 52 (IPAd) is expediently activated at least until a first telecommunication profile 80 has been loaded into the embedded identification module (eUlCC).
[0055] The first assistance module 72 (IPAe) is expediently activated as soon as a telecommunication profile 80 has been loaded into the embedded identification module 70 (eUlCC) via the second assistance module 52 (IPAd).
[0056] The activation of the first or second assistance module 52 (IPAd) is expediently carried out on the basis of a command from the remote management unit 20 (elM).
[0057] Profile management actions are carried out effectively through the interaction of the assistance modules 52, 72 or by setting the first or second operating mode.
[0058] A profile management action can be a profile status action with which the state of a profile 80 stored in the embedded identification module 70 (eUlCC) is changed. For example, an activated profile 80 is deactivated and another activated, or a deactivated profile 80 is deleted. Profile status actions are expediently triggered via the remote management unit 20 (eUM). The sequence of a profile status action is shown in Fig. 2. To implement a change intended by a profile status action (PSMO), the remote management unit 20 establishes a secure connection to the first assistance module 72 (IPAe) via the interface 190 (ESipa) and a secure connection to the embedded identification element 70 (eUlCC) via the interface 210 (ESpsmo).
[0059] Via the secure connection 190, the remote management unit 20 (elM) sends a command data record with a profile management action to the first assistance module 72 (IPAe), step 1000. The terminal device 50 is in the first operating mode, the first assistance module 72 (IPAe) is activated, the second assistance module 52 (IPAd) is deactivated.
[0060] The first assistance module 72 (IPAe) checks the command data record to determine whether the profile management action is a profile status action or involves loading a profile 80. If the profile management action is a profile status action, for example, in the form of a PSMO message, the first assistance module 72 (IPAe) executes it (step 1010) and initiates the corresponding change to the addressed profile. For example, switching from a first profile to a second profile can be performed.
[0061] A profile management action can also be the loading of a profile 80 into the embedded identification element 70. Fig. 3 illustrates the signal flow when loading a profile 80 from the profile provisioning instance 10 (SM-DP+) into the embedded identification module 70 (eUlCC). The initial setup of a profile 80 on an embedded identification module 70 (eUlCC) or the loading of a new profile 80 is preferably performed via the second assistance module 52 (IPAd) in the second operating mode.
[0062] In a first embodiment variant 01, the loading of a profile 80 is initialized by the remote management unit 20 via the interface 150 (E8+) via the first assistance module 72 (IPAe). The remote management unit 20 (elM) sends a command data record with a loading message to the first assistance module 72 (IPAe), step 1100. The first assistance module 72 (IPAe) activates the second assistance module (IPAd) 52 using an activation message, step 1110, and deactivates itself. The second assistance module 52 (IPAd) contacts the remote management unit 20 (elM) via the side interface 170 and requests an activation code, step 1120. The remote management unit 20 (elM) sends the activation code, step 1130.
[0063] From the activation code, the second assistance module 52 (IPAd) determines the responsible profile provisioning instance 10 (SM-DP+) and establishes a secure connection to it via interface 120 (S9+). The second assistance module 52 (IPAd) presents the activation code to the profile provisioning instance (SM-DP+), step 1400. After performing mutual authentication with the embedded identification module 70 (eUlCC), the profile provisioning instance 10 (SM-DP+) provides a profile package to the second assistance module 52 (IPAd), step 1410. The second assistance module 52 (IPAd) loads the profile package into the embedded identification module 70 (eUlCC), step 1420. The profile 80 contained in the profile package is installed by the embedded identification module 70 (eUlCC).
[0064] In one embodiment of Figure 1, the remote management unit 20 (elM) initiates the loading of a profile 80 by connecting the mediation server 30 (SM-DS). For this purpose, a secure connection is established between the remote management unit 20 and the first assistance module 52 (IPAe) via the interface 190 (ESipa). The second assistance module 52 (IPAd) is deactivated, so that the first operating mode is set. After mutual authentication using information received from the embedded identification module 70 (eUlCC), the first assistance module 72 (IPAe) initiates the establishment of a secure connection to a mediation server 30 (SM-DS) via the interface 160 (Eil) in order to retrieve an event data record from the latter. Using the event data record, the first assistance module 72 (IPAe) identifies the responsible profile provisioning instance 10 (SM-DP+) and communicates it to the second assistance module 72 (IPAd).To do so, it sets the second operating mode by deactivating itself and activating the second assistance module 52 (IPAd). The second assistance module 52 (IPAd) then loads a profile into the embedded identification module 70 (eUlCC) as described.
[0065] In a modification of the embodiment, the remote management unit 20 (elM) accepts the request for the event data record and forwards it to the first assistance module 52 (IPAe).
[0066] In a second embodiment O2, the loading process is initiated by the remote management unit 20 (elM) using an activation code provided to the remote management unit 20. The remote management unit 20 (elM) sends a message containing the activation code to the first assistance module 72 (IPAe) via the interface 210 (EPpsmo), step 1200. The first assistance module 72 recognizes the message as a request to load a profile. It activates the second assistance module 52 using an activation message containing the activation code, step 1210. The terminal device 50 is then in the second operating mode.
[0067] The second assistance module 52 (IPAd) uses the activation code to determine the responsible profile provisioning instance 10 (SM-DP+) and establishes a secure connection to it via interface 120 (S9+). The second assistance module 52 (IPAd) presents the activation code to the profile provisioning instance (SM-DP+), step 1400. After performing mutual authentication with the embedded identification module 70 (eUlCC), the profile provisioning instance 10 (SM-DP+) provides a profile package to the second assistance module 52 (IPAd), step 1410. The second assistance module 52 (IPAd) loads the profile package into the embedded identification module 70 (eUlCC), step 1420. The profile 80 contained in the profile package is installed by the embedded identification module 70 (eUlCC).
[0068] Remote Management Unit 20 (elM) and Profile Provisioning Instance 10 (SM-DP+) are informed about the successful profile setup.
[0069] In a modification of the implementation variant, a profile provisioning instance 10 (SM-DP+) is preset and the determination from an activation code is omitted.
[0070] In one embodiment of O2, the charging process is initiated by the remote management unit 20 (elM) using an activation code provided to the remote management unit 20. Charging takes place in the first operating mode, i.e., the first assistance module 72 (IPAe) is activated, the second assistance module 52 (IPAd) is deactivated. The remote management unit 20 (elM) establishes a secure connection to the first assistance module 72 (IPAe) via the interface 190 (ESipa), determines the profile provision unit 10 (SM-DP+) from the activation code, and also establishes a secure connection to it via the interface 100 (ES8+). The profile provision unit 10 (SM-DP+) then performs mutual authentication with the embedded identification module 70 (eUlCC) via the then consistently secure connection. The profile provisioning unit 10 (SM-DP+) then provides a profile package and transmits it to the remote management unit 20 (elM).This sets the second operating mode and passes the profile package via the second assistance module 52 (IPAd) to the embedded identification module 70 (eUlCC), which installs the profile 80 and further notifies the management unit 20 (elM) and profile provisioning instance 10 (SM-DP+).
[0071] In a third embodiment variant 03, the second assistance module 52 (IPAd) triggers the loading process by determining that a condition for loading a profile 80 is met, step 1300. The second assistance module 52 (IPAd) contacts the remote management unit 20 (elM) via the side interface 170 and requests an activation code, step 1310. The remote management unit 20 (elM) sends the activation code via the side interface 170, step 1320.
[0072] From the activation code, the second assistance module 52 (IPAd) determines the responsible profile provisioning instance 10 (SM-DP+) and establishes a secure connection to it via interface 120 (S9+). The second assistance module 52 (IPAd) presents the activation code to the profile provisioning instance (SM-DP+), step 1400. After performing mutual authentication with the embedded identification module 70 (eUlCC), the profile provisioning instance 10 provides a profile package to the second assistance module 52 (IPAd), step 1410. The second assistance module 52 (IPAd) loads the profile package into the embedded identification module 70 (eUlCC), step 1420. The profile 80 contained in the profile package is installed by the embedded identification module 70 (eUlCC).
[0073] Remote Management Unit 20 (elM) and Profile Provisioning Instance 10 (SM-DP+) are informed about the successful profile setup.
[0074] In a suitable further development of the solution, an application is executed within the terminal device 50 or in the embedded identification module 70 (eUlCC), which controls the status of profiles 80 stored in the embedded identification module 70 (eUlCC). Such an application can, for example, be an application that detects the current location of a terminal device 50 and sets a profile 80 appropriate to the location. If suitable conditions are met, the application sends a message to the first assistance module 72 (IPAe), which then in turn causes the profile status to change.
[0075] In a further development of the described solution, the remote management unit 20 (eIM) is configured to provide a repair profile that is loaded into an embedded identification module 70 (eUICC) as needed. The repair profile is loaded as described above.
[0076] In another further development, it is provided that in principle only a first assistance module 72 (IPAe) is available in the terminal 50 and the second assistance module 52 (IPAd) is only set up when a need to load a profile 80 arises for the first time.
[0077] While maintaining the basic idea of providing a first assistance module 72 and a second assistance module 52 for executing profile management actions, one of which is embodied in the embedded identification module 70 and the other in the terminal 50, wherein the first assistance module 72 executes a profile management action if it is a profile status action and the second assistance module 52 executes a profile management action if it involves loading a profile, the described solution allows for a number of modifications that are not explained in detail for reasons of clarity. For example, a profile management action can be triggered based on other possible event occurrences. For example, additional measures for securing communications can be provided, or possibly fewer.
Claims
Patent claims 1. A terminal device with an embedded identification module (70) which is configured to carry out profile management actions by means of which a telecommunications profile (80) stored in the embedded identification module (70) can be changed or a new telecommunications profile (80) can be loaded, • wherein the embedded identification module (70) comprises a first assistance module (72) providing a first interface (150) to a remote management unit (20), • and the terminal (50) has a second assistance module (52) which is connected to the embedded identification module (70) and provides a second interface (120) to a profile provision instance (10), • wherein at the same time either the first assistance module (72) or the second assistance module (52) is active, • wherein the terminal (50) receives command data sets containing profile management actions from the remote management unit (20), • wherein the first assistance module (72) is active and causes the execution of a profile management action if the profile management action concerns a change in the state of a telecommunications profile (80) stored in the embedded identification module (70), • and wherein the second assistance module (52) is active and causes the execution of a profile management action when it concerns the loading of a new profile.
2. Terminal according to claim 1, characterized in that the command data sets with profile management actions are transmitted via the interface (150) and are received in the first assistance module (72).
3. Terminal according to claim 1 or 2, characterized in that the second assistance module (52) is configured to conduct a data exchange with the profile provision instance (10) in order to load a new profile (80) into the embedded identification module (70).
4. Terminal according to one of the preceding claims, characterized in that the first assistance module (72) transfers the execution of a profile management action to the second assistance module (52) if the profile management action concerns the loading of a telecommunications profile (80).
5. Terminal according to one of the preceding claims, characterized in that the first assistance module (72) sends a feedback about the execution to the remote management unit (20) after execution of a profile management action.
6. Terminal according to one of the preceding claims, characterized in that the second assistance module (52) has a side interface (170) to the remote management unit (20) which enables the remote management unit (20) to request an activation code.
7. Terminal according to one of the preceding claims, characterized in that the communication between the first assistance module (72) and the remote management unit (20) takes place by means of a first protocol.
8. Terminal according to one of the preceding claims, characterized in that the communication between the second assistance module (52) and the profile provision instance (10) takes place by means of a second protocol.
9. Terminal according to one of the preceding claims, characterized in that the second assistance module (52) is activated until a first telecommunication profile (80) has been loaded into the embedded identification module (70).
10. Terminal according to one of the preceding claims, characterized in that the first assistance module (72) is activated as soon as a telecommunications profile (80) has been loaded into the embedded identification module (70) via the second assistance module (52).
11. Terminal according to one of the preceding claims, characterized in that the activation of the first assistance module (72) or the second assistance module (52) occurs due to a command from the remote management unit (20).
12. A method for managing a telecommunications profile in an embedded identification module (70) of a terminal (50) using profile management actions, comprising the following steps: • Setting up a first assistance module (72) in the identification module (70), wherein the first assistance module (72) provides an interface (150) to a remote management unit (20), • Setting up a second assistance module (52) in the terminal (50), wherein the second assistance module (52) is connected to the identification module (70) and provides an interface (120) to a profile provision instance (10), • Setting up a first operating mode in which the first assistance module (72) is activated and the second assistance module (52) is deactivated, • Setting up a second operating mode in which the second assistance module (52) is activated and the first assistance module (72) is deactivated, • Transmitting a command data record containing a profile management action from the remote management unit (20) to the terminal (50), • Executing the profile management action by the first assistance module (72) in the first operating mode if the profile management action concerns a change in the state of a telecommunications profile (80) stored in the embedded identification module (70), • Setting the second operating mode and executing the profile management action by the second assistance module (52) if the profile management action concerns the loading of a new profile (80).
13. The method according to claim 12, characterized in that command data records containing a profile management action are received in the first assistance module (72) and a profile management action is transferred to the second assistance module (52) and the second operating mode is set if the profile management action concerns the loading of a new telecommunications profile (80).
14. Method according to claim 12 or 13, characterized in that the command data sets are formed in the remote management unit (20) on the basis of requests received via a user interface.