Method for configuring a user device, as well as the latter with a computer program, a computer-readable data carrier and an arrangement for its configuration
The method ensures secure and reliable interaction between user devices and secure elements by verifying authorized connections and refusing unauthorized commands, addressing the issue of unsecured communication in existing technologies.
Patent Information
- Application Number
- FR2025003188
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-28
- Filing Date
- 2025-03-27
- Publication Date
- 2025-10-03
AI Technical Summary
Existing methods do not adequately ensure secure and functionally reliable interaction between secure elements, such as eUICCs, and user devices, leading to potential unsecured and undetermined communications.
A method involving specification of a command data set for user devices, verification of a link between the device set and the secure element, and refusal of unauthorized commands to ensure a secure and functionally reliable interaction, using security keys and authorization conditions.
This approach prevents unsecured and undetermined communication by ensuring authorized connections, enhancing the secure and functional reliability between user devices and secure elements.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for configuring a user device, as well as the latter with a computer program, a computer-readable data carrier and an arrangement for its configuration Field of the invention
[0001] The present invention relates to the connection of embedded secure elements with sets of user devices. The embedded secure element may in particular be an embedded Universal Integrated Circuit Card (eUICC). In particular, the invention relates to a method for configuring a user device, for example a mobile user device intended to participate in a telecommunications network, comprising a set of devices on which a secure element, in particular an eUICC, is installed, a computer program, a computer-readable data carrier, a user device, in particular a mobile user device intended to participate in a communications network, and a configuration arrangement for configuring user devices. Background to the invention
[0002] Methods for handling embedded secure elements, such as eUICCs, as well as computer programs, computer-readable data carriers, user devices for participating in communication networks and communication networks are known from the prior art. For example, on eUICCs, for example on mobile user devices such as mobile phones, smartphones, tablets or the like, the user identification characteristics of the user devices are managed. On an eUICC, this generally takes the form of corresponding embedded subscriber identity modules (eSIMs). This procedure is necessary to meet the security requirements necessary for managing the identification elements.This requires a trusted party that can be provisioned on eUICCs and / or servers, such as eSIM download servers, from which eUICC datasets can be obtained or managed as trusted Subscription Manager Data Preparation platform (SM-DP+) while meeting the respective security requirements.
[0003] Secure elements generally have a system structure with an operating system so that they can interact with the sets of devices of the terminals on which they are implemented. The operating system can be used to access memory areas, usually non-volatile memory, of secure elements and to manipulate, manage, and query the information stored there, such as identification characteristics. For example, this is done using corresponding application protocol data elements (APDUs), which transmit one-way commands to the secure elements via a socket interface, which are then executed by them.
[0004] Document EP 4113342 A1 relates to a method, a data structure and an update agent for implementing a scheme for downloading an operating system image to a secure element. The update agent receives an installation package from an external device for installing an operating system on the secure element. The update agent requests control of the secure element and loads the operating system received with the installation package into the secure element, after which control of the secure element is transferred to the operating system.
[0005] Document EP 2862340 B1 relates to a mobile station having a terminal and a removable or permanently implemented security element operable in the terminal, a connection being established between the terminal and the security element and being verifiable by means of a secret key and the verification key. The terminal comprises a secure execution environment and the verification key is stored in the secure execution environment.
[0006] From document US 20200382957 A1, a method for establishing a secure connection between a secure element of a user device and a node in a network by means of token exchange and verification is known.
[0007] Originally, identity modules for mobile user devices were mechanically interchangeable as subscriber identity cards (SIM cards) or transferable from one user device to another, as long as the respective form factor of the SIM card allowed this. By integrating SIM cards as eSIMs on eUICCs, they can no longer be assigned to a user and / or a telecommunications service provider based on their external characteristics and can therefore be inserted into a specific intended user device so that they can develop their full range of functions. The aforementioned processes, computer programs, computer-readable data carriers, user devices and communication networks do not allow a satisfactory assignment between the secure element and the terminal.
[0008] The object of the present invention is to improve the interaction between secure elements and user devices. In particular, an object of the present invention is to ensure secure and functionally reliable interaction between elements secure elements and a user device. Furthermore, an object of the present invention is to enable special assignment of secure elements to certain intended user devices.
[0009] This task is solved by the subject matter of the independent claims. Exemplary embodiments result from the dependent claims and the following description. The features described herein with respect to the methods and the corresponding method steps can be implemented as device features or vice versa. The method sections of the description also apply analogously to computer programs, computer-readable data carriers, user devices for participating in communication networks and communication networks.In particular, the method steps and associated components mentioned can be implemented as functions of computer programs, computer-readable data carriers, user devices for participating in communication networks and communication networks and all functions of computer programs, computer-readable data carriers, user devices for participating in communication networks and communication networks can be implemented as method steps.
[0010] The invention relates to a method for configuring a user device, for example a mobile user device intended to participate in a telecommunications network, with a set of devices on which a secure element, in particular an eUICC, is installed, comprising the following steps: - specification of a command data set containing operating commands for the user device; - verification of a link between the set of devices and the secure element; and - refusal of at least one of the operating commands if the verification has shown that there is no authorized link.
[0011] A user device, in particular a mobile terminal intended to participate in a communication network, comprises a corresponding computer program stored thereon, a corresponding computer-readable data carrier and / or is configured to execute a corresponding method.
[0012] A computer program comprises commands which, when executed by a user device, cause the program to perform a corresponding method.
[0013] A computer-readable data carrier comprises a corresponding computer program stored thereon.
[0014] A configuration arrangement for configuring user devices comprises a corresponding computer program stored therein, a medium corresponding computer-readable data and / or is configured to perform a corresponding method.
[0015] A set of devices and / or a secure element may comprise a corresponding computer program stored thereon and / or a corresponding computer-readable data carrier and / or be configured to execute a corresponding method. The configuration arrangement may comprise at least one computing device, such as a computer, a server or the like, configured to interact with user devices, sets of devices and / or secure elements. The interaction may, for example, take place via a telecommunications network. A telecommunications network comprises at least one corresponding user device and / or a server on which a corresponding computer program is stored, a corresponding computer-readable data carrier or the server is configured to execute a corresponding method.
[0016] The method can therefore be implemented by a data processing device or using a computer, which can be implemented as a user device or a server. A computer program can comprise commands which, when the program is executed by a data processing device or a computer, cause the computer or the device to execute the method. A computer-readable storage medium, a computer-readable data carrier and / or a data carrier signal can store or transmit the computer program. A corresponding computer-readable data carrier can be in the form of a computer-readable medium and / or a data carrier signal.
[0017] At least one of the operating commands in the control data set may be designed to be interchangeable between the device set and the secure element. The binding may not be present or may not meet specified binding requirements. The device set may be bound to the secure element using a security key. Binding and / or authorization of the binding may be initiated from both the device set and the secure element.
[0018] The solution according to the invention has the advantage that by refusing at least one of the operating commands in the absence of an authorized connection between the set of devices and the secure element, a potentially unsecured and / or functionally undetermined communication between the set of devices and thus the user device on the one hand and the secure element on the other hand can be avoided. For example, this may involve a refused command, a user-specific and / or vendor-specific functionality that requires an appropriate authorized connection between the set of devices and the secure element. This makes it possible to improve the interaction between the secure elements and the user devices, in particular to make them secure and functionally reliable, and to assign secure elements to predetermined user devices.
[0019] The solution is not limited to eUICCs, but is generally suitable for so-called secure elements (SEs), herein referred to as integrated circuit cards, for example. Thus, secure elements include, in addition to eUICCs, conventional UICCs, integrated U1CCs (iUICCs) as well as all other types of integrated secure elements, such as integrated secure elements (iSE / eSE), smart cards, Subscriber Identity Modules (SIMs) and / or virtual SIMs (vSIMs). What all these secure elements have in common is that user data records or eUICC data records can be stored therein, for example in the form of telecommunications profiles or "profiles" for short, with the help of which users can authenticate themselves to communications networks, for example as subscribers to telecommunications networks.Secure elements are characterized by the fact that the information stored there, including profiles, is particularly protected against attacks by third parties and cannot be easily manipulated, either physically or by software.
[0020] According to one embodiment, it can be provided that a restricted operating mode is defined in which at least one of the operating commands of the control data set is defined as non-executable and / or executable. The restricted operating mode can be activated if there is no permitted link. This means that at least some functions, for example rudimentary functions, can be executed in the restricted operating mode. A function of the user device can be specified in the restricted operating mode depending on the respective requirements. This contributes to further improving the secure and functionally reliable interaction between the device sets and the secure elements.
[0021] According to one embodiment, it can be provided that the control data record comprises at least one control parameter with which the refusal and / or release of at least one of the operating commands can be specified. The control parameter can be used, for example, to define the restricted operating mode or the commands that cannot be executed and / or can be executed therein and to adapt them to the respective requirements. This contributes to further improving the secure and functionally reliable interaction between the device assemblies and the secure elements.
[0022] According to one embodiment, it may be provided that the connection is authorized depending on an authorization condition. For example, the connection may be designed to be technically feasible on the one hand and authorizable linked to a condition authorization on the other hand. This makes it possible to combine the verification of the link with an authorization check beyond its technical existence. Authorization can in turn be carried out according to specific requirements, for example in conjunction with a verification of security keys, (authenticity) certificates or similar. This also helps to further improve the secure and functionally reliable interaction between device sets and secure elements.
[0023] According to one embodiment, it may be provided that the linking is authorized after a predetermined number of uses of at least one operating command and / or at least one operating action of the user device, the set of devices and / or the secure element. The linking may have to be authorized after resetting the user device, the set of devices and / or the secure element to a predetermined state. For example, the authorization may be required after each reset, after n configured commands / operations (arbitrary or special commands / operations) and / or before configured commands (e.g., special use cases may be rejected with a special error code that signals re-authentication) and / or after a certain period of time.Such operating commands, operating actions and / or operating conditions can be used as and / or linked to authorization conditions. This allows a safe and functionally reliable interaction between the device assemblies and the secure elements to be flexibly adapted and controlled according to the respective requirements.
[0024] According to one embodiment, it can be provided that at least one of the specification, verification and rejection steps is designed to be activatable and / or deactivatable. In other words, the corresponding method steps can be implemented but do not necessarily have to be activated. This also makes it possible to flexibly adapt and control a secure and functionally reliable interaction between the device sets and the secure elements according to the respective requirements. Brief description of the figures
[0025] [Fig.l] [Fig.l] shows a schematic view of an embodiment of a configuration arrangement according to the invention with a user device and a server, which are designed to implement a method of configuring the user device.
[0026] [Fig.2] [Fig.2] shows a schematic view of another embodiment of a configuration arrangement according to the invention with a user device and a server, which are designed to implement a method of configuring the user device.
[0027] [Fig.3] [Fig.3] shows a schematic view of a flow diagram of steps enabling a link to be verified between a set of devices and a secure element of a user device as part of a method of configuring the user device according to the invention.
[0028] [Fig.4] [Fig.4] shows a schematic view of a flow diagram of steps enabling a link to be established between a set of devices and a secure element of a user device as part of a method of configuring the user device according to the invention.
[0029] [Fig.5] [Fig.5] shows a schematic view of a flow diagram of steps enabling authorization of a link between a set of devices and a secure element of a user device to be verified as part of a method of configuring the user device according to the invention.
[0030] Detailed Description of Exemplary Embodiments
[0031] The representations in the figures are schematic and not to scale. If the same reference signs are used in different figures of the following description of the figures, these designate identical or similar elements. However, identical or similar elements may also be designated by different reference signs.
[0032] [Fig. 1] shows a schematic view of a configuration system 1 according to the invention with a user device 2 and a computer device in the form of a server 3. The user device 2 and the server 3 can implement a method according to the invention using a computer program 4 on the basis of computer-readable instructions contained therein. The computer program 4 can be stored at least in sections on a computer-readable data carrier 5 and can define components of the configuration system 1 described here as well as associated parameters, identifiers, values, keys and / or steps S and can regulate their generation, use and / or manipulation. The computer-readable data carrier 5 can be in the form of a computer-readable medium 6 and / or a data carrier signal 7.In particular, the data carrier signal 7 can be designed such that it can be transferred between user devices 2 and / or the server 3 for respective execution thereon. Thus, the computer program 4 and thus a corresponding method for configuring the user device 2 can be executed on the user device and / or the server 3.
[0033] The user device 2 comprises a set of devices 8 and a secure element 9, for example in the form of an integrated circuit card or eUICC which can execute the computer program 4 and thus the corresponding method steps S, at least in sections. The set of devices can be designed as a communication module and / or a motherboard of the user device 2 or may comprise such a module or motherboard. The communication between the set of devices 8 and the secure element 9 is based on operating commands B, for example in the form of corresponding application protocol data elements (Application Protocol Data Unit - APDU), which transmit unidirectional commands to the secure elements via a connection interface, which are then executed by them. In addition, the operating commands B serve to control the functions C of the user device 2.
[0034] The operating commands B may be managed in the control data set D. The configuration arrangement 1, the user device 2, the server and / or the control data set D may also contain parameters P, such as error codes F, limit values G, markings K, execution variables T and / or counting variables Z, which may be linked to the operating commands B and / or to the functions C or to the actions M or to the possible restrictions N, which in turn may be based on and / or linked to the operating commands B. Such parameters P may be managed in the control data set D together with the operating commands B and / or separately therefrom and in a method according to the invention and its steps S.
[0035] In a first method step S1, the control data set D with the operating commands B and possibly the parameters P is specified for the user device 2. For this purpose, corresponding data can be provided by the server 3 of the device set 8 and / or the secure element 9 or implemented and / or queried thereon. In a second step S2, a connection W between the device set 8 and the secure element 9 can be initiated, for example after a first commissioning of the device set 8 and / or the secure element 9 or after activation of a corresponding function C. In the present example, the secure element 9 initiates the connection W by sending a connection request Q to the device set 8. In a third step S3, the connection request Q can be confirmed by a request confirmation R.In this example, device set 8 sends request confirmation R to secure element 9.
[0036] In a fourth step S4, a corresponding key exchange may be initiated by the initiation request I to encrypt the link W using a security key H. In this example, the secure element 9 sends the indexing request I to the set of devices 8. The key exchange may be confirmed in a fifth step S5 by means of an encryption confirmation J, which in the present example is sent by the set of devices 8 to the secure element 9.
[0037] In a sixth step S6, an authentication request U can be sent to authenticate the link W. In this example, the secure element 9 sends the authentication request U to the set of devices 8. In a seventh step S7, the authentication can be confirmed. In the present example, the set of devices 8 sends an authentication confirmation V to the secure element 9, for example using a corresponding certificate L.
[0038] In an eighth step S8, the linking process is completed. If the link is not fully configured correctly, at least one of the operation commands B may be disabled in a restricted operation mode X. If the link W has been successfully established, it is possible to switch to an unrestricted operation mode Y in which all or a desired range of the operation commands B of the operation data set D may be executed. If execution of a command B is generally permitted, a counting variable Z may be checked to see if it is greater than or less than a certain limit G for the number of permitted executions. For example, the counting variable Z or the corresponding counter may be reduced by one counting value each time the program is executed, and if the value of the counting variable Z has a value of 0 as a limit value G, the execution may be refused.If this is the case, a new counting variable Z should be reset by authorization. It is also possible to check, using a reliable time source, whether a runtime variable T exceeds a corresponding limit value G. If this is the case, a new lifetime variable T or a lifetime extension will have to be provided by authorization.
[0039] Furthermore, a configuration confirmation E may be generated for confirmation purposes, for example in a secure form by the secure element 9. The configuration confirmation E may be used to signal to the user device 2 and / or the server 3 that the configuration or handshake W has been successful. The user device 2 and / or the server 3 may then initiate the appropriate steps to complete the configuration process, for example by activating and / or deactivating all remaining operating commands B in the unrestricted operating mode Y, adjusting the counting variables Z, storing or recording configuration notes, for example by generating a blockchain, etc.
[0040] In other words, in the present example, the W-link can be initiated after a first start / boot of the user device 2 in the field. The secure element 9 can recognize that it has been configured for a W-link and now starts it in step S2 by sending a corresponding proactive command in the form of the Q-link request to the set of devices 8 in order to inform it of the connection W to be established. The device set 8 can signal with an "OK" in the form of the request confirmation R that the connection can be established. The secure element then sends another proactive command in the form of the initiation request I to initiate a key exchange according to the state of the art, for example according to Diffie-Hellman. With the response of the device set 8, a common security key H is shared by both components. In the next step, this shared security key H is used to verify a successful connection W. This can be achieved using a state-of-the-art cryptography function, for example an AES-CMAC. After successful authentication, the secure element 9 can be in the unrestricted operating mode Y, for example an "operational mode", i.e. all functions C and actions M are available as usual.
[0041] [Fig. 2] shows a schematic view of another embodiment of a configuration arrangement 1 according to the invention with the user device 2 and the server 3, which are designed to implement a method for configuring the user device 2. For the sake of brevity and efficiency, only the differences from the embodiment of the configuration arrangement 1 shown in [Fig. 1] will be described below. In the embodiment shown in [Fig. 2], in the second step S2, the device set 8 sends the link request Q. In the third step S3, the secure element 9 responds with the request confirmation R. In the fourth step S4, the device set 8 initiates the exchange of the security key H. In the fifth step S5, the secure element 9 sends the encryption confirmation J. In the sixth step S6, the device set 8 performs the authentication request U.In the seventh step, the secure element 9 sends the authentication confirmation V, for example using the certificate L, after which the binding process can be completed in the eighth step S8.
[0042] [Fig. 3] shows a schematic view of a flow diagram of steps S for verifying a connection W between the set of devices 8 and the secure element 9 of the user device 2 in the context of a method for configuring the user device 2 according to the invention. In a tenth step S10, a request can be initiated whether an operating command B, for example an APDU, is to be executed. In an eleventh step S11, it can be asked whether there is a restriction N concerning the execution of the operating command B. If the restriction N is present, a connection W can be made and / or queried in a twelfth step S12, for example by proceeding to step S2, as illustrated in FIGS. 1 and 2. If the connection W is correct or is not required, the operation up to 4 can be carried out in a step S13. The request can be terminated in step S14.In other words, at each new B operating command or at certain B operating commands or commands, it is possible to check . if a W link is configured and needed. If not, this command will continue to be used. If a link is configured and needed, a "pairing process" is performed.
[0043] [Fig. 4] shows a schematic view of a flow diagram of steps S for establishing the connection W between the set of devices 8 and the secure element 9 of the user device 9 in the context of a method for configuring the user device 2 according to the invention. Thus, in a twentieth step S20, a check can be launched to determine whether a specific operating command B, for example according to a corresponding restriction N, is a command aimed at executing the connection W. In a twenty-first step S21, it can be asked whether it is an operating command B relating to the execution of the connection W, for example the initiation request I, the encryption confirmation J, the connection request Q, the request confirmation R, the authentication request U and / or the authentication confirmation V.
[0044] If this is not the case, in a twenty-second step S22, similar to the eleventh step S11, it can be checked whether the operation command B is activated or subject to a restriction N. If there is no restriction N, the operation command B can be executed in a twenty-third step S23, similar to the thirteenth step S13. The check can then be completed in a twenty-fourth step S24. If a restriction N exists, an error with the corresponding error code F can be handled in a twenty-fifth step S25. For example, it is then possible to proceed to a twenty-sixth step S26 to perform the connection W, as in the twelfth step S12. Alternatively, if it is an operation command B concerning the execution of the link W, it is possible to go directly from the twenty-first step S21 to the execution of the link W, as illustrated in Figures 1 and 2.
[0045] In other words, it can first be checked whether the current command is a link command corresponding to the operation command B. If it is not, it is checked whether the command is allowed or prohibited according to the current configuration. If it is allowed, it is processed further. Otherwise, it will be rejected according to the configuration. If it is a link command, the link process is processed or executed as shown in Figures 1 and 2.
[0046] [Fig. 5] shows a schematic view of a flow diagram of steps S for verifying an authorization of the link W between the set of devices 8 and the secure element 9 of the user device 2 within the framework of a method for configuring the user device 2 according to the invention. In a thirtieth step S30, the check can be triggered, for example by a specific authorization condition A, an action M and / or a corresponding operating command B, such as the reinitialization of the user device 2, of the set of devices 8 and / or of the secure element 9 to a predetermined operating state. In a thirty-first step S31, it can be checked whether the authorization condition A, the action M and / or a corresponding operating command B are present.
[0047] If the authorization condition A, the action M and / or a corresponding operating command B are present, the authorization of the connection W can be checked in a thirty-second step S32, for example by means of a corresponding authorization request U, an authentication confirmation V and / or a certificate L. In the event of an authorization error, the error handling can be carried out in a thirty-third step S33 using a corresponding error code F, similar to step S25, for example by switching to the restricted operating mode X. If the authentication is successful, the check can be completed in a thirty-fourth step S34, for example by switching to the unrestricted operating mode Y.
[0048] If no authorization condition A, action M and / or corresponding operating command B is present, then in a thirty-fifth step S35 it can be checked whether the operating command B or a corresponding APDU requires or is authorized to authorize the link W, similarly to the twenty-second step S22. If the operating command B is authorized, it can be executed in a thirty-sixth step S36. If the operating command B is invalid, it is possible to proceed to error handling in the thirty-third step S33. If the operating command B is authorized, it can be executed in a thirty-sixth step S36. The check can then be completed again in the thirty-fourth step S34.
[0049] In other words, depending on the trigger, for example after a reset to a predetermined operating state, the authentication of the link W can be checked. First, it can be checked whether the current operating command B or the corresponding command is an authentication command. If so, the authentication is checked, for example via AES-CMAC. If successful, the command is accepted and the secure element 9 switches to unrestricted operating mode Y. Otherwise, all error codes F will be displayed accordingly. In restricted operating mode X, the secure element can then only authorize the operating commands B configured accordingly.If this is not an authentication command and no successful authentication has been performed to date, only B operation commands are allowed according to the configuration of restricted operation mode X.
[0050] The W binding itself may be specified and initiated in a factory as part of a secure personalization of the user device 2, the set of devices 8 and / or the secure element 9, as illustrated in Figures 1 and 2. Once a Once a W-link has been established, authentication can be performed at appropriate times. Depending on the configuration, this authentication can be unilateral or multilateral. In the case of unilateral authentication, for example, only the user device 2 or the set of devices 8 must authenticate to the secure element 9. In the case of multilateral authentications, the set of devices 8 and the secure element 9 must authenticate each other.
[0051] Possible times for authorizations can be specified in the user device 2, the device set 8 and / or the secure element 9. Possible times can be, for example: after each reset, after n configured commands / operations (arbitrary or special commands / operations) corresponding to a respective counting variable Z, before configured operating commands B or commands (e.g., special use cases can be rejected with a special error code F, which signals a new authentication after the expiration of the corresponding execution variable T, for example within certain times (the user device 2 sends an authentication request every x minutes / hours or the secure element 9 requests authentication of the user device 2 every x events / commands (counts)).An example of a possible D-order data set is shown in the following table: . Authentication Trigger / Operation Command B Type Number Reset Cold / Hot Reset Z APDU APDU Data Z Function C According to definition Z Execution Variable T
[0052] The restricted operating mode X can be implemented by a corresponding format of the control data set D. For example, for certain operating commands B, a kind of approved or prohibited list can be maintained as a synonym for the corresponding commands and / or functions C. For example, it is possible to determine which types of APDUs (including information such as the data bytes CLA, INS, PI and P2, the control data) or functions are allowed. For each entry, it is possible to note whether the corresponding operating command B is allowed or not. With the help of appropriate restrictions N and / or markings K, it is also possible to determine whether a distinction between allowed or prohibited operating commands B can be activated via a corresponding configuration parameter. For example, such a configuration parameter can be deactivated in the delivery state of the user device 2, the device set 8 and / or the secure element 9 and can be activated later, as shown in an abstract manner by the following tabular representations of example command data sets D, where wildcards or regular expressions such as "?" etc. can be allowed and supported: Operating command B Details Marking K APDU Command description Authorized / not authorized Function C Function description Authorized / not authorized Operating Command B Details Restriction N / Marking K Comment APDU INS=20 Allowed All APDUs with INS=20: allowed APDU INS=30 & Pl=30 & P2=40 Allowed All APDUs with INS=30 and Pl=30 and P2=40: allowed APDU CLA=8 & INS=40 Forbidden All APDUs with CLA starting with “8” and INS=40 are allowed APDU NS=A4 & Data=“AO00*” Allowed All APDUs with CL=A4 and data starting with “AO00*” are allowed Function C SGP ESlOc.GetProfi leslnfo Allowed A feature called “SGP ESlOc.GetProfi leslnfo” Function C SGP ESlOc.EnableProfile Forbidden A feature called “SGP ESlOc. EnableProfile » Feature C « Feature A* » Allowed All features starting with "Feature A" are allowed Feature C SE Link Enabled / Disabled SE Link is disabled / not required SE Link is enabled / required
[0053] In this way, the control data sets D can be personalized as individual and global data as part of a secure personalization in a manufacturing facility of the user devices 2, the device sets 8 and / or the secure elements 9. Alternatively or additionally, the control data sets D can be extended in list form, for example as part of a corresponding customization. Commands or changes can also be added or changed in the command data sets D during operation or later in the field. In general, a change may require the security keys H to be present in the secure element 9 for secure data exchange. This can be achieved, for example, via an OTA connection with a server 3 designed as an OTA server or via the user device 2, for example using so-called Global Platform commands.
[0054] It is possible to dissolve all bindings W and / or to initiate them again. This is possible, for example, in case of a factory reset when selling the user device 2 or the device set 8. First, the user device 2 and / or the device set 8 must successfully authenticate, for example via SGP or global platform mechanisms, mutual authentication, etc., and make a corresponding request. The secure element 9 can then delete the current binding W and generate a new security key H. This security key H can be exchanged with the user device 2 or the device set 8 via a secure transport path (e.g. global platform / Diffie-Hellmann). For example, after a successful exchange and verification of the data, this new binding W can then be used. This rebinding must be atomic. List of reference signs
[0055] 1 Configuration arrangement
[0056] 2 User device
[0057] 3 Server / computing device
[0058] 4 Computer program
[0059] 5 Computer-readable data carrier
[0060] 6 Computer-readable medium
[0061] 7 Data carrier signal
[0062] 8 Set of devices
[0063] 9 Secure Element / Integrated Circuit Card (eUICC)
[0064] A Condition of authorization
[0065] B Operating command
[0066] C Function
[0067] D Control Data Set
[0068] E Configuration confirmation
[0069] F Error Code
[0070] G Limit
[0071] H Security key
[0072] I Request for initiation
[0073] J Encryption Confirmation
[0074] K Marking
[0075] The Certificate
[0076] M Action
[0077] N Restriction
[0078] P Parameter
[0079] Q Link request
[0080] R Confirmation of request
[0081] S Step
[0082] T Execution Variable
[0083] U Authentication request
[0084] V Authentication Confirmation
[0085] W Liaison
[0086] X Restricted operating mode
[0087] Y Unrestricted operating mode
[0088] Z Count Variable
[0089] SI Command Specification
[0090] S2 Link Request
[0091] S3 Confirmation of the connection request
[0092] S4 Initiation of key exchange
[0093] S5 Confirmation of key exchange
[0094] S6 Authentication request
[0095] S7 Confirmation of authentication
[0096] S8 Completion of the binding process
[0097] S10 Start of request
[0098] S11 Request for restriction
[0099] S12 Implementation of the link
[0100] S13 Execution of operation command
[0101] S14 End of request
[0102] S20 Start of verification
[0103] S21 Verification of the link command
[0104] S22 Verification of the restriction
[0105] S23 Execution of the operation command
[0106] S24 End of verification
[0107] S25 Error Handling
[0108] S30 Trigger verification
[0109] S31 Verification of authorization command
[0110] S32 Authorization verification
[0111] S33 Error Handling
[0112] S34 End of verification
[0113] S35 Verification of admissibility
[0114] S36 Execution of the operation command
Claims
Claims
1. Method for configuring a user device (2), for example a mobile user device (2) intended to participate in a telecommunications network, with a device set (8) on which a secure element (9), in particular an eUICC, is installed, comprising the following steps: - specifying a control data set (D) with operating commands (B) for the user device (2); - verifying a connection (W) between the device set (8) and the secure element (9); and - refusing at least one of the operating commands (B) if the verification has shown that there is no authorized connection (W).
2. Method according to claim 1, characterized in that a restricted operating mode (X) is defined in which at least one of the operating commands (B) in the control data set (D) is defined as non-executable and / or executable.
3. Method according to claim 1 or 2, characterized in that the control data set (D) contains at least one control parameter (P) making it possible to specify the refusal and / or validation of at least one of the operating commands (B).
4. Method according to at least one of the preceding claims, characterized in that the connection (W) must be authorized depending on an authorization condition (A).
5. Method according to at least one of the preceding claims, characterized in that the connection (W) must be authorized after a predetermined number of uses of at least one operating command (B) and / or at least one operating action of the user device (2), the set of devices (8) and / or the secure element (9).
6. Method according to at least one of the preceding claims, characterized in that at least one of the specification, verification and rejection steps is designed to be activatable and / or deactivatable.
7. Computer program (4), characterized by commands which, when the program is executed by a user device (2), cause the execution of a method according to one of claims 1 to 6.
8. A computer-readable data carrier (5), characterized by a computer program (4) stored thereon according to claim 7.
9. User device (2), in particular a mobile terminal intended to participate in a communication network, characterized by a computer program (4) stored thereon according to claim 7, a computer-readable data carrier (2) according to claim 8 and / or characterized in that the user device () is configured to implement a method according to at least one of claims 1 to 6.
10. Configuration arrangement (1) for configuring user devices (2), characterized by a computer program (4) stored thereon according to claim 7, a computer-readable data carrier (5) according to claim 8 and / or characterized in that the configuration arrangement (1) is configured to implement a method according to at least one of claims 1 to 6.