Improved method for provisioning a user equipment with a subscription profile of an end operator
Patent Information
- Application Number
- EP2023840741
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-12-28
- Filing Date
- 2023-12-27
- Publication Date
- 2025-11-05
AI Technical Summary
The existing method of provisioning user equipment with a subscription profile from a final operator is complex and costly, requiring multiple roaming agreements and the use of a bootstrap file, which is logistically challenging and not feasible for large-scale deployment of low-cost IoT devices.
A private mobile telephone network is deployed on a production site, managed by the manufacturer, which includes a server that assigns temporary identifiers to user equipment, allowing it to connect to the internet and download the subscription profile directly from the final operator's server, eliminating the need for an intermediate network and bootstrap file.
This solution simplifies the provisioning process, reduces costs, and enhances security management, enabling efficient initial connectivity for user equipment without the need for multiple roaming agreements or bootstrap files, making it suitable for large-scale IoT deployments.
Smart Images

Figure 1.1
Abstract
Description
[0001] TITLE: Improved method for provisioning user equipment with an end-operator subscription profile
[0002] The present invention relates to methods allowing the provisioning of user equipment with the subscription of a so-called “end” operator.
[0003] Equipment equipped with a radiocommunication interface must have a subscription with an end operator of a mobile telephone network in order to be able to connect to this mobile telephone network in order to then access, depending on the rights granted to it, the desired services.
[0004] To load this subscription, the equipment must, in an initial phase, connect to the Internet to access a profile server, in which the end operator will have previously deposited the subscription associated with the user of the equipment. Such a profile server is for example an SM-DP / SM-SR server ("Subscription Manager Data Preparation / Secure Routing" or "Surname Manager - Data Preparation / Secure Routing" in French) used in the world of the Internet of Things - loT ("Internet of Things") or its evolution an SM-DP+ server, as described in the specifications of the "GSMA" association SGP.21 and SGP.31.
[0005] However, for this initial phase, especially when it is not equipped with any other interface (WIFI is not available on IoT terminals), the equipment must use its air interface to access the internet. It must therefore use the services of an intermediate public radiocommunication network managed by an intermediary operator.
[0006] Currently, a bootstrap file is provided to the equipment to enable it to perform this initial connectivity with an intermediate public network.
[0007] This is what is taught, for example, by documents US 2021 / 314765 A1 and US 2020 / 236529 A1.
[0008] However, such a solution has several drawbacks.
[0009] It is therefore necessary to have roaming agreements between the final operator and the intermediary operator of the public network authorizing initial connectivity.
[0010] For equipment that may be used in different countries and / or anywhere within a country, it is then necessary to multiply roaming agreements to allow the user of the equipment to load and activate a subscription, at the time he has just taken possession of the equipment and wishes to fully initialize it. However, it is difficult to obtain such a variety of agreements. This is very expensive and remains difficult to operate.
[0011] Furthermore, having a roaming agreement is sometimes not enough, since the equipment may, at the time the user wishes to initialize it, be located in a white zone, i.e. an area not covered by the public network of the intermediary operator with which the final operator has this roaming agreement.
[0012] Furthermore, the boot file must be saved in the equipment before it is purchased by the end user. It is therefore up to the manufacturer to save the boot file in equipment intended for use with a subscription from a particular end operator.
[0013] The manufacturer is therefore dependent on the provider of this boot file. Since the boot file depends on the end operator (and possibly for an end operator on the various intermediary operators with which it has roaming agreements), this poses a significant logistical problem for the manufacturer, who must know which boot file to register in a batch of equipment intended for sale in a particular market.
[0014] All of this represents a complex management from an operational and security point of view and therefore an additional cost just to achieve this initial connectivity.
[0015] In particular, such an approach is not feasible in practice for the deployment of equipment in the context of the Internet of Things (IoT), where the aim is to disseminate a large number of low-cost devices in the environment with the capacity to connect to the Internet to exchange data.
[0016] Using a bootstrap file is therefore problematic.
[0017] There is therefore a need to simplify the process for provisioning equipment with a subscription from an end operator.
[0018] The purpose of the present invention is to meet this need.
[0019] For this purpose, the invention relates to a provisioning method, a system for implementing a provisioning method, a private mobile telephone network and a production line for user equipment according to the appended claims.
[0020] The invention finally relates to a computer program product comprising software instructions which, when executed by a computer, give said computer the possibility of operating in accordance with the preceding private mobile telephone network, the computer having hardware means adapted to constitute a base station of the private mobile telephone network and a wired or wireless connection to an IP network.
[0021] The invention and its advantages will be better understood upon reading the following detailed description of a particular embodiment, given solely as a non-limiting example, this description being made with reference to the appended drawings in which:
[0022] Figure 1 is a schematic representation of an installation integrating a system according to the invention allowing the implementation of the method according to the invention;
[0023] Figure 2 is a schematic representation in block form of a preferred embodiment of the method according to the invention;
[0024] Figure 3 is a timing diagram of the messages exchanged in the installation of Figure 1 for carrying out the main step of the process of Figure 3; and,
[0025] Figure 4 is a schematic representation of a production line equipped with the system according to the invention.
[0026] The present invention involves deploying a private network at a production site. This private network is managed by the manufacturer. This network includes, in particular, an HSS-type server initially free of any profile.
[0027] This private network is connected to the Internet via a wired connection or alternatively via a wireless connection, for example Wi-Fi.
[0028] This private network includes a server that automatically assigns temporary identifiers to equipment arriving at the end of the production line.
[0029] These temporary identifiers define a profile, which is saved in the HSS server.
[0030] The equipment itself is equipped with an eUlCC card, such as an eSIM (“embedded SIM”) card or the equivalent, such as an iSIM (“integrated SIM”) card, suitably programmed.
[0031] The eULCC card is initially blank, in the sense that it does not contain any connection profile via its air link. In particular, it does not contain an IMSI, which is the only identifier that should be added at a minimum if you wish to change your subscription.
[0032] Temporary credentials are stored on the eULCC card, which is then burned during this process.
[0033] Once the IMSI of the private network is provisioned in the eSIM card, the equipment can attach and identify itself to the private network, then connect to the internet and directly download the appropriate subscription from a profile server of the end operator. The system according to the invention is therefore a completely dynamic solution, which offers temporary initial connectivity to equipment at the end of the production line.
[0034] This eliminates the need for a boot file and the need to use an intermediate public network. This also drastically simplifies the associated logistics. All of this therefore contributes to reducing costs. In addition, it leaves security management to the manufacturer alone.
[0035] A preferred embodiment of the invention will be presented in relation to the figures.
[0036] Figure 1 represents an installation comprising a user equipment - UE ("User Equipment") 1, a private radiocommunication network 10, and the IP network 20 (i.e. a communication network implementing the internet protocol - IP ("Internet Protocol")).
[0037] The IP network 20 is for example a public network, such as the Internet network. It comprises a server 22 provisioned with information relating to a subscription to the mobile telephone network of an end operator on which the user equipment UE 1 is intended to operate. The server 22 is for example a server of the SM-DP type storing a profile associated with a subscription.
[0038] The network 10 is a private mobile telephony network of the 3G, 4G or 5G type or future as defined by the 3GPP (“3rd Generation Partnership Project”). In what follows, the case of a 4G type network will be taken more particularly as an example, but the person skilled in the art knows how to apply the teaching of the present description to the case of another type of mobile telephony infrastructure, in particular a 5G type infrastructure.
[0039] Network 10 provides a mobile telephone service in a limited geographical area (of the order of a few meters) covering, for example, the production line or the manufacturing plant of EU 1. We can speak of a micro radiocommunication system.
[0040] Network 10 is operated by the EU 1 manufacturer, which also operates the EU 1 manufacturing line.
[0041] The network 10 comprises a radio access network 11, or RAN ("Radio Access Network"), preferably incorporating a single access point 12, or eNB ("e-Node B" in 4G). An eNB allows a user equipment to connect by means of a wireless radio link to the network 10. For example, the UE1 is connected (or seeks to establish a connection) through the link 81 with the eNB 12 of the RAN 11.
[0042] The network 10 comprises a core network 15, or ePC (“evolved Packet Core” in 4G), comprising in particular: - a service gateway 14, or SGW (“Serving Gateway”), which takes care, at the data plane level, of routing “useful” flows (voice communications, application data traffic, etc.) between the RAN 11 and the ePC 15.
[0043] - an MME (“Mobile Management Entity”) server 16, which manages, at the control plane level, sessions (authentication, authorizations, etc.).
[0044] - a gateway 19, or PGW (“Packet Data Network Gateway”) responsible for exchanging “useful” flows with the internet network 20. The gateway 19 may comprise or consist of an Ethernet network card connected by a cable to the internet network 20 (link 86 in figure 1);
[0045] - a subscriber server, or HSS (“Home Subscriber Server”) 18, capable of offering a subscriber service. The HSS 18 includes a database of subscriber profiles, with their rights and characteristics. The HSS 1_ is initially empty;
[0046] - an identifier management module 64, which will be described in detail below.
[0047] In Figure 1, different connections have been represented:
[0048] - link 82 is a data flow link between the eNB 12 and the SGW 14,
[0049] - link 83 is a data flow link between SGW 14 and PGW 19.
[0050] - link 84 is a control flow link between the SGW 14 and the MME 16.
[0051] - link 85 is a control flow link between the eNB 12 and the MME 16.
[0052] - link 70 is a control flow link between the MME 16 and the HSS 18.
[0053] The UE 1 uses the network 10 to download a temporary profile, which will then allow it to connect to the Internet 20, in particular to an SMDP server 22 in order to download a definitive profile associated with a subscription to the mobile telephone network managed by a final operator.
[0054] The UE 1 comprises a calculation means, such as a processor 2, a storage means, such as a memory 3, an eUlCC card 4 and a radio module 5. These components are connected by a suitable data bus 6.
[0055] The memory 3 comprises the instructions of computer programs which, when executed by the processor 2, allow the implementation of certain functionalities. In particular, the memory 3 comprises the instructions of a program 31 allowing the implementation by the UE 1 of certain of the steps of the method according to the invention.
[0056] Radio module 5 is known as such. It stores two identifiers:
[0057] - the IMEl (“International Mobile Equipment Identity”), which is an identifier of the radio module 5 of the UE 1. This is information that is fixed; and,
[0058] - the IPadd, which is the IP address ("Internet Protocol") assigned to the UE 1 during the implementation of the method according to the invention. The user equipment UE 1 comprises an embedded universal integrated circuit card - eULCC ("Embedded Universal Integrated Circuit Card") 4. Before the implementation of the method, the eULCC card 4 is free of any profile.
[0059] Generally speaking, an eULCC card (like an eSIM card) is a SIM card ("Subscriber Identity Module") that has the ability to be reprogrammed remotely via the radio interface ("Over The Air" - OAT) programming by a machine on the network to which the UE connects, such as a SM-DP+ ("Subscription Manager - Data Preparation") server. Alternatively, an iSIM card is used. This is an eULCC card integrated into the equipment's processor.
[0060] In this way, a user can store several profiles on the UE he uses, each profile corresponding to subscriptions with different end operators and / or, for the same end operator, for different services (such as data exchange, long distance calls, etc.)
[0061] In the present method, the use of an eUlCC card is necessary because the main identifier that the present method allows to be dynamically assigned to the equipment is the IMSI identifier (“International Mobile Subscriber Identity”). However, a conventional SIM card (“subscriber identity / identification module”) stores an IMSI that cannot be modified.
[0062] The eUICC 4 comprises a calculation means, such as a processor 42, and a storage means, such as a memory 43.
[0063] The memory 43 comprises the instructions of computer programs which, when executed by the processor 42, allow the implementation of certain functionalities. In particular, the memory 43 comprises the instructions of a program 41 allowing the implementation by the eUICC 4 of certain of the steps of the method according to the invention.
[0064] Furthermore, memory 43 stores various information.
[0065] Before implementing the method according to the invention, the memory 43 comprises a set of pre-provisioned information, in particular:
[0066] - an EID (“eUICC ID”), which is an eUICC 4 identifier;
[0067] - an MK, which is a master key, shared with the dynamic identifier allocation service of module 64;
[0068] - MK1 and MK2, which are diversified keys characteristic of eUICC 4;
[0069] - a Cer, which is a certificate constituting a signature of the eUICC 4; and,
[0070] - an IPsmdp, which is the IP address of the SM-DP+ server to which the UE 1 seeks to connect to download a definitive profile. During or after the implementation of the method according to the invention, the memory 43 further comprises:
[0071] - an IMSI (“international mobile subscriber identity”), which is an identifier normally assigned by an operator to the SIM cards of EUs whose users have a subscription with that operator;
[0072] - a Ki (“Subscriber Authentication Key”) and an OPc (“derived operator code”), which are an example of a set of information allowing reciprocal authentication between a subscriber and an operator. Such a set of keys is called accreditations (“credentials”).
[0073] It should be noted that the method allows an IMSI, and possibly a Ki and an OPc, to be loaded onto the eUICC 4 and, in parallel, a profile corresponding to these attributes into the HSS 18.
[0074] Other information, identifiers, or parameters exist. They are not mentioned because they are not modified by this method. If some of them are used during the implementation of this method, they take a predefined value or a default value.
[0075] The identifier management module 64 is constituted by a computer for carrying out certain of the steps of the method according to the invention so as to provide a dynamic identifier allocation service and, once these identifiers have been allocated to a user device, a communications management service.
[0076] The identifier management equipment 64 is for example based on an architecture of the SDN (“Software Defined Network”) type. It then comprises a network control component 50 and a service orchestration application component, or orchestrator 60.
[0077] The network control component 50 includes, for example:
[0078] - an authorization and authentication module, called AAA module (“Authentication, Authorization, Accounting / Auditing”) 57, for implementing authentication mechanisms based on certificates, such as for example the EAP-TLS mechanism (“Extensible Authentication Protocol - Transport Layer Security”). This module is connected to the orchestrator 60 by a link 72, for example of the REST API type.
[0079] - a dynamic identifier allocation server, called “TIC” server 51, participating in the allocation and use of a temporary IMSI (t-IMSI) for user equipment. The TIC server 51 is connected to the orchestrator 60 by a link 72, for example of the REST API type. The TIC server 51 is connected, via the link 70, to the MME 16.
[0080] The TIC server 51 can be identified as an authentication center - AuC ("Authentication Center"). The TIC server 51 comprises for example an SP module 52 having the function of identifying UEs subscribed to the dynamic identifier allocation service and of implementing the transfer protocol of a temporary t-ISMI, as well as advantageously an SG module 53 having the function of simplifying the management of the keys and rights of the UEs subscribed to the service.
[0081] The service orchestration component 60 has the function of synchronizing the different services, in particular the allocation and management of temporary identifiers.
[0082] In a particularly advantageous variant, the network 10 does not include a separate HSS server 18. It is the module 64 which performs the functions of an HSS server. It should be noted that the functions of an HSS server are simplified insofar as there is no mobility management to be provided on the network 10, since this network advantageously only includes one eNB and one MME.
[0083] The orchestrator 60 manages the different modules of the network control component 50. The orchestrator 60 is connected to the different functionalities of the control plane. In the present embodiment, the orchestrator 60 is thus connected to the TIC server 51 (link 72), to the HSS server 18 (link 71), to the PGW gateway 19 (link 73 in FIG. 1, for example of the SGi Radius interface type). It is the orchestrator which synchronizes and ensures consistency when setting up the services.
[0084] In addition, the orchestrator 60 is connected to the HSS 18 by a link 71, for example of the REST API type.
[0085] The service orchestration component 60 maintains a database 65.
[0086] The database 65 contains the data necessary for the allocation of temporary identifiers to a subscriber to the service and, once a temporary identity has been allocated to a UE, the control of the communication between this UE and the recipient constituted by the SM-DP server 22.
[0087] In particular, database 65 includes:
[0088] - an EID_List, which is a list of the EIDs of the UEs subscribed to the service and the Cer certificates of each of these UEs;
[0089] - the master key MK of the dynamic identifier allocation service;
[0090] And, for each UE 1 actually using the network 10 at a given time, the database 65 further comprises:
[0091] - the EID of this EU;
[0092] - the current IMEl of this UE;
[0093] - the current IMSI of this EU;
[0094] - the MK1, MK2 diversified keys of this UE;
[0095] - the Ki and OPc credentials of this UE; and, - the IP address, IPadd, assigned to this UE.
[0096] Figure 2 represents the use case envisaged for the present invention, namely a manufacturing line, in this case of a motor vehicle, the last station of which consists of configuring the user equipment, in this case an on-board computer of the motor vehicle, manufactured along this line.
[0097] The production line 100 comprises a succession of stations leading to the production of a motor vehicle 90. For example, the production line 100 comprises a station 102 for assembling sheet metal for the production of the body, a station 104 for painting the body, a station 106 for assembling the chassis and the engine components, a station 108 for mounting the body on the chassis, a station 110 for installing equipment in the passenger compartment, and a step 112 for installing the on-board computer.
[0098] According to the invention, the production line 100 further comprises a station 120 for configuring the on-board computer, as user equipment 1, of each vehicle passing through this station 120.
[0099] The station 120 preferably comprises a computer 122 for deploying the private radiocommunication network 10 of FIG. 1. It comprises in particular an antenna 124, which is the antenna of the eNB 12 of the RAN 11 of the network 10. It is programmed to perform the functions of the ePC 15 of FIG. 1. The computer 122 is programmed to implement at least the minimum functionalities of a core network, as well as the functionalities allowing the implementation of the method according to the invention.
[0100] This antenna 12 makes it possible to define an elementary coverage area of the network 10, or cell 126, having a reduced geographical extension, but sufficient to allow vehicles moving along the production line, inside said cell, to have time to download a subscription profile.
[0101] The computer 122 is also connected to the Internet network (not shown in FIG. 2) by a wired connection 128. Alternatively, it is a wireless connection, for example Wi-Fi.
[0102] The user equipment 1 is switched on when the vehicle it equips enters the station 120 (i.e. inside the cell 126). The UE1 establishes a connection 81 with the eNB 12 (via the antenna 124). The implementation of the method according to the invention is carried out while the vehicle is moving through the cell 126. When it leaves the station 120, the on-board computer of the vehicle 90 is provisioned with a subscription profile of a final mobile telephone operator. In this way, when the vehicle 90 is sold, its new owner will be able to immediately connect to the mobile telephone network of this final operator so as to access without delay and easily the services provided by this final operator. Possibly, this first connection to the network of the final operator will consist of redefining the rights and services actually open to this new owner of the vehicle 90, i.e. loading another subscription profile.
[0103] If the case of a motor vehicle has been presented, the present method can be applied to any device intended to be able to connect to a mobile telephone network, such as for example a telephone, a tablet, a personal computer, smart devices for home automation, infrastructure security, medical telemetry, etc.
[0104] As shown in FIG. 3, the method 200 consists, in a step 205, of deploying the private local network 10 along a production line.
[0105] Before implementing the method according to the invention, the eU ICC of the UE 1 is blank, in the sense that it does not contain any profile allowing it to attach, via its air interface, to a mobile telephone network.
[0106] Additionally, HSS 18 server does not have any profiles related to EU 1. It is also blank or empty.
[0107] Then in a step 210, the method consists of moving the UE 1 along the production chain so that it enters the coverage area of the private network 10, namely the cell 126.
[0108] In a step 220, UE 1 is turned on.
[0109] Switching on the UE 1 initiates the implementation of the first phase of the method leading, in step 230, to the allocation of temporary identifiers to the UE 1.
[0110] Once the UE 1 has temporary identifiers, in a step 240, UE 1 connects to the internet network 20, via the network 10.
[0111] In a second phase of the method, which corresponds to step 250, the UE 1 connects to the server 22 to download a profile associated with a subscription previously prepared by the final operator.
[0112] Once UE 1 is provisioned with a subscription profile, UE 1 is powered off.
[0113] Thus, following the implementation of this process, once in the hands of its end user, UE 1 will be able to connect directly to the network, private or public, managed by the end operator or managed by an operator with which the end operator has a roaming agreement.
[0114] Referring to Figure 4, steps 230 and 240 of method 200 will be detailed.
[0115] The method 200 allows the dynamic allocation of an IMSI subscription identifier to the equipment UE 1, based on a mechanism for exchanging hidden data in the fields of the messages conventionally exchanged during the registration of user equipment with a mobile telephone network, such as the first network 10. This mechanism is for example described in the patent application EP 3 506 668.
[0116] More specifically, in Figure 4, after being powered on in step 220, step 230 consists of enrolling the UE 1 with the dynamic identifier assignment service in order to provide the UE 1 with a temporary profile.
[0117] UE 1 will first use a first IMSI, IMSI1, randomly generated to register with network 10. This IMSI will be identified by network 10 as belonging to its private network and the TIC server 51 will take advantage of this to recover the ElD of UE 1, and send it a temporary IMSI, t-IMSL
[0118] In detail:
[0119] Step 302: following the power-up of the UE1, the eUlCC card 4 does not detect any definitive IMSI in its memory 43 and then calculates, randomly, a first IMSI, IMS 11. For example, this first IMSI is calculated on the basis of the ElD.
[0120] Step 303: To enroll on network 10, UE 1 requests an IMSI from eULCC card 4.
[0121] Step 304: The eUlCC 4 card returns the IMS11, calculated in step 301.
[0122] Step 305: UE 1 seeking to connect to network 10, sends an attachment request to MME 16. This attachment request includes the IMSH.
[0123] Step 306: following receipt of the attachment request, the MME 16 notes that the IMSH is in a first predefined range of values (for example between 0 and 50). Consequently, the MME 16 sends a request to the TIC server 51.
[0124] Step 307: In response to this request, the TIC server 51 asks the eUlCC card 4 for its EID in order to identify it as one of the subscribers to the dynamic identifier allocation service. This request is hidden in a classic authentication request. More precisely:
[0125] Step 308: An authentication request is transmitted from the TIC server 51 to the MME 16.
[0126] Step 309: An authentication request is transmitted from the MME 16 to the UE 1.
[0127] Step 310: An authentication request is transmitted from UE 1 to eULCC card 4.
[0128] Step 31 1: following receipt of the authentication request, the eUlCC card 4 reads the ElD present in its memory 43 and, preferably, encrypts it using the master key MK associated with the dynamic identifier assignment service. The key MK is a private key, which is shared with the network 10 and previously provisioned on the UEs.
[0129] Step 312: The eULCC card 4 responds to the authentication request from the UE 1 by passing it the encrypted ElD. Step 313: The UE 1 responds to the authentication request from the MME 16 with a standard authentication failure message. This message includes the encrypted ElD.
[0130] Step 314: MME 16 transmits the authentication failure message to the TIC server 51.
[0131] Step 315: The TIC server 51 uses the master key MK from module 64 to decrypt the ElD from the eUICC 4.
[0132] The TIC server 51 verifies that the ElD is present in the EID_List list containing the EIDs of the subscribers to the service. If the received ElD is not in the list of EIDs, step 230 ends. On the other hand, if the received ElD is valid, the TIC server 51 selects a temporary IMSI, t-MSI, in a second range of values (for example between 1000 and 3000).
[0133] Alternatively, in the event that the manufacturer does not wish to provision its EIDs in the equipment 64, the use of an additional parameter will make it possible to identify a user equipment of the manufacturer, this parameter then having to be provisioned in its equipment and in the database 65 of the equipment 64, which is accessed by the TIC server 51.
[0134] The TIC 51 server calculates the credentials (Ki and OPc) associated with the selected t-IMSI, a random number RAND, as well as a temporary connectivity duration of X minutes.
[0135] The TIC server 51 of the equipment 64 encrypts the t-IMSI, the Ki, the OPc and the temporary connectivity duration using the master key MK and transmits to the eUlCC card 4 this encrypted information, as well as the random number RAND, and an encryption result XRES. This transmission is carried out by masking this information in a new authentication request addressed to the eUlCC card 4. More precisely:
[0136] Step 316: an authentication request is thus transmitted from the TIC server 51 to the MME 16.
[0137] Step 317: MME 16 retains the XRES and retransmits the authentication request to UE 1.
[0138] Step 318: The authentication request is retransmitted from UE 1 to eULCC card 4.
[0139] Step 319: The eUlCC 4 card calculates a result RES from the random number RAND and the encrypted information, in particular the t-IMSI.
[0140] Step 320: the eUlCC TAC 4 card responds to the authentication request from the UE 1 with a message integrating the RES result of the calculation from step 319.
[0141] Step 321: UE 1 responds to the authentication request from MME 16 with a message including the RES result.
[0142] Step 322: the MME compares the RES and the XRES. Step 323: these quantities being identical, the MME 16 retransmits the authentication response to the TIC server 51.
[0143] Step 324: In response, the TIC server 51 returns an authentication error message to the MME 16.
[0144] Step 325: MME 16 rejects UE 1's attachment request.
[0145] From the point of view of MME 16, i.e. network 10, there was therefore only an exchange of authentication messages leading to an authentication failure, while module 64 was able to recover the ElD of the eUlCC 4 card and the latter a temporary IMSI.
[0146] Step 326: the TIC 51 server calculates, from the t-IMSI just assigned to the eUlCC 4 card, the master key MK, and the random number RAND sent to the eUlCC 4 card, a Ki 1 and an OPc1.
[0147] The TIC server 51 transmits these accreditations (Ki 1 and an OPc1) to the orchestrator 60 so that it can provision, via the link 71, the HSS 18 with the temporary profile of this new subscriber, which is the eUlCC card 4 of the UE 1. The equipment 64 provides the HSS with the t-IMSI, the Ki1 and the OPd. It also indicates, preferably, the IT or telecommunications resources in order to meet the needs of this new subscriber.
[0148] Step 327: At the same time, the eUlCC 4 card stores the t-IMSI instead of e-IMSI1.
[0149] The eUICC 4 calculates the Ki 1 and OPc1 , with the t-IMSI, the master key MK and the random number RAND received from the TIC server 51 .
[0150] Finally, the eUlCC card 4 commands a restart of the radio module 5 in order to initiate an attachment to the network 10 but with the t-IMSI.
[0151] Advantageously, the eUlCC 4 card checks that this new connection will remain temporary and will not extend beyond the planned temporary connectivity duration of X minutes.
[0152] Step 328: The eUlCC 4 card refreshes the information from the radio module 5 of the UE 1 by indicating the t-IMSI.
[0153] Step 329: UE 1 seeking to connect to network 10, sends an attachment request to MME 16. This attachment request includes the t-IMSI.
[0154] Step 330: Following receipt of the attachment request, noting that the t-IMSI is in the second range of values, the MME 16 requests the HSS server 18 to authenticate the UE 1. This request includes the t-IMSI.
[0155] Step 331: The HSS server 18, now properly provisioned with the temporary profile of the UE 1, responds with an authentication request message with the RAND, XRES and AUTN parameters necessary for mutual authentication to be performed at the MME 16 level.
[0156] Step 332: Upon receipt of the authentication request message, the MME 16 stores some of these parameters, while retransmitting the others in an authentication message to the UE 1.
[0157] Step 333: the authentication message received by UE1 is retransmitted to the eUlCC card 4.
[0158] Step 334: after positive verification of the RAND / AUTN, the eUlCC 4 card calculates a RES.
[0159] Step 335: the eUlCC 4 card transmits the calculated RES to the UE 1.
[0160] Step 336: UE 1 retransmits the RES to MME 16.
[0161] Step 337: the MME compares the RES and the XRES, and, these two quantities being effectively identical, the MME 16 accepts the attachment of UE 1.
[0162] Step 338: Conventionally, once the attachment has been accepted, the MME 16 transmits to the HSS 18 location information of the UE 1 and the HSS 18 responds to the MME 16 with an acknowledgment message.
[0163] Step 240: UE 1 now being attached to network 10 with its temporary profile, UE 1 receives from network 10 an IP address, IPadd, so as to be able to connect to internet network 20, via network 10.
[0164] The UE 1 can then download (step 250) the subscription profile provided by the final operator by querying the SM-DP server 22 whose IP address, IPsmdp, it knows.
[0165] Once the profile is downloaded, the temporary connection between UE 1 and network 10 is released, for example when the connection time expires. The eUlCC 4 then automatically detaches from network 10. After this period, the t-IMSI and Ki 1 are deprovisioned from the HSS. The t-IMSI value can therefore be reused for another user equipment.
[0166] UE 1 is then switched off (step 260).
[0167] Many variations of the preferred embodiment described above are conceivable.
[0168] Once it has an Internet connection, the UE 1 can download any information from an end operator other than a subscription profile, such as an activation code. An activation code includes, for example, a profile server address and a matching identifier to retrieve the subscription of the user using the activation code. The user must therefore first acquire an activation code, then connect to a profile server and receive the corresponding subscriber profile. Filtering could not be implemented on the ElDs, so that the dynamic identifier assignment service is open to any equipment in the coverage area of the network 10. However, this presents a risk of crosstalk between two user equipment configuration stations in a factory whose coverage areas partially overlap.Filtering on the ElD therefore ensures that the desired user equipment is configured.
[0169] Similarly, one could do away with encryption with a shared key if one considers that this offers a sufficient level of security.
[0170] Similarly, one could limit oneself to transmitting a temporary IMSI (t-IMSI) without the credentials. However, it is preferable to calculate credentials in order to appropriately provision an HSS function, which ensures that a unique temporary profile is assigned to a unique user equipment.
[0171] The proposed solution goes beyond a simple test profile, such as a "Rhodes and Schwartz" profile, adapted to allow access to a private network. Indeed, such a test profile would not allow two parallel attachments of two different user devices, since they would share the same credentials. This would therefore not allow the configuration of several user devices simultaneously, which remains a basic need for an implementation on a production line.
[0172] Furthermore, when a new terminal seeks to register by indicating its EID to the equipment 64, the verification of this EID is that of a subscriber who can benefit from the service may include a control step carried out manually by an operator, via a human-machine interface connected to the equipment 64.
[0173] Instead of basing this verification on the ElD, it could be carried out on another identification parameter of the card, such as the Cer certificate or an identifier provisioned for this purpose in the terminal by the manufacturer.
[0174] The solution can also be implemented without an ICT server on the private network, using IMSIs / Kls pre-loaded in the eULCC cards of user equipment and in the HSS of the local network.
[0175] Instead of calculating a pair of credentials Ki 1 and OPc1 from a pair of credentials Ki and OPc1 on both sides, only the OPc could be exchanged between the network and the terminal, and the Ki derived by the terminal on the one hand and by the network on the other (using the OPc, the key MK and the number RAND).
[0176] The present invention makes it possible to locally and dynamically manage the subscription of a user equipment at its production site. Alternatively, the method can be implemented by a reseller of the user equipment. For example, a motor vehicle dealer or a mobile phone seller in a particular country, so that the user equipment concerned accesses subscription files adapted to this country and to the end operators managing networks offering coverage in said country.
[0177] Temporary means information with a limited validity over time (i.e. short lifespan), typically the time required for a user device to be enrolled on the private network and then download the entire subscription file.
[0178] The invention therefore simplifies the management of information provisioning in ellICC cards by provisioning a final profile in the factory. In order for the eU ICC to be able to hook onto the network in order to download this final profile while it is blank, it must first be burned with a hook profile, while pushing the hook profile onto a server of the HSS type.
[0179] Thus, no pre-registration is required at the user equipment level, nor at the TIC server level. HSS provisioning is dynamic via the TIC server. This allows ease of use for the manufacturer (or the entity deploying the private network), even though this is not their core business.
Claims
CLAIMS 1. Method for provisioning user equipment with final information from an end operator, the user equipment - UE (1) being provided with a card of the embedded universal integrated circuit type - eUlCC (4), initially blank, and a radio module (5), characterized in that the method consists of: - deploying (205) a private mobile telephone network (10), connected to an IP network (20), the IP network hosting a server (22) storing said final information; - dynamically assigning (230), by an identifier management equipment (64) of the private mobile telephone network (10), at least one temporary subscription identifier (t-IMSI) to the eUICC (4) residing in the EU (1); - connecting (240) the UE (1) to the IP network (20) via the private mobile telephone network (10) using said at least one temporary subscription identifier (t-IMSI); - downloading (250) said final information from the server (22); and, - disconnecting (260) the UE (1), the dynamic allocation, by an identifier management equipment (64) from the private mobile telephone network (10), of at least one subscription identifier (IMSI) to the eUICC (4) consisting of transmitting, by the identifier management equipment (64), through the private mobile telephone network (10) to which the UE (1) requests to attach by implementing a standard protocol for attaching a roaming terminal on a mobile telephone network, the temporary subscription identifier (t-IMSI) in a field of a message exchanged in accordance with said standard attachment protocol, the implementation of the standard attachment protocol ending with a rejection of the attachment request, and, a specific temporary profile for the eUICC (4) having been created by the identifier management equipment (64), to be transmitted to a subscriber profile server (18) of the private mobile telephone network (10), initially empty,said temporary profile integrating the temporary subscription identifier assigned to the eUICC (4)., 2. Method according to claim 1, wherein connecting the UE (1) to the IP network (20) via the private mobile telephone network (10) using said at least one temporary subscription identifier (t-IMSI) consists of transmitting, by the UE (1), a new request for attachment to the private mobile telephone network (10) by implementing the standard attachment protocol using the temporary subscription identifier.
3. Method according to claim 2, in which the new attachment request implements an authentication procedure between the eUICC (4) and the identifier management equipment (64).
4. Method according to any one of claims 1 to 3, in which the eUICC (4) and the identifier management equipment (64) exchange encryption parameters making it possible to calculate, on both sides, accreditations, said temporary profile integrating said accreditations.
5. Method according to any one of claims 1 to 4, in which the identifier management equipment (64) recognizes the eUICC (4) to which to provide a temporary subscription identifier from an eUICC identification parameter (EID) received from the eUICC and present in a list of eUICC identification parameters stored by the identifier management equipment (64).
6. Method according to any one of the preceding claims, in which the information to be downloaded is a subscription profile, the server being a profile server of the SM-DP type.
7. System for implementing the method of provisioning user equipment with final information from an end operator, according to any one of the preceding claims, comprising: - user equipment - UE (1), the UE (1) being provided with a card of the embedded universal integrated circuit type - eUlCC (4) and a radio module (5) for connection; - an IP network (20) hosting a server (22) storing said information; and, - a private mobile telephone network (10), the private mobile telephone network (10) comprising: - a wired or wireless connection to the IP network (20); - a subscriber profile server (18); - identifier management equipment (64), the identifier management equipment (64) being capable of: assigning to the eUICC (4) a temporary subscription identifier (t-IMSI); transmitting to the ellICC (4) the temporary subscription identifier; creating a temporary profile specific to the eUICC (1); and updating the subscriber profile server - HSS with said temporary profile, said temporary profile integrating the temporary subscription identifier assigned to the eUICC.
8. Private mobile telephone network (10) adapted to be integrated into a system according to claim 7.
9. Private mobile telephone network (10) according to claim 8, deployed from a computer integrating the different functionalities of a mobile telephone network and adapted to cover a limited geographical area.
10. Production line for user equipment - UE (1) comprising a station for configuring the manufactured UEs (1), said station integrating a private mobile telephone network (10) according to claim 8 or claim 9.
11. Computer program product comprising software instructions which, when executed by a computer, enable said computer to operate in accordance with the private mobile telephone network of claim 8 or claim 9, the computer having hardware means adapted to constitute a base station of the private mobile telephone network and a wired or wireless connection to an IP network