Method for connecting a connected object to a telecommunications network and associated device

The method for connecting a connected object with an embedded secure element (eUICC) addresses the challenge of configuring network access point identifiers by using a secure element manager and operator profile manager to update and activate profiles, ensuring efficient network connections.

FR3167031A1Pending Publication Date: 2026-04-03IDEMIA FRANCE SAS
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing solutions do not allow for the configuration of a network access point identifier for a connected object with an embedded secure element, particularly when the operator profile changes, due to limited memory resources and lack of standards support.

Method used

A method for connecting a connected object with an embedded secure element (eUICC) to a telecommunications network by receiving and activating a network access point identifier and operator profile, using a secure element manager and operator profile manager, and implementing commands like 'RUN AT COMMAND' and 'EnableProfile' to update and activate the network access.

Benefits of technology

Enables efficient configuration of network access point identifiers, allowing seamless connection to different telecommunications networks by updating and activating operator profiles, even with limited memory resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for connecting a connected object to a telecommunications network, and associated device. The invention relates to a method for connecting a connected object (IoT-D) to a telecommunications network, in which a secure element (eUICC) is embedded. The method comprises: reception, by the secure element (eUICC), of a network access point identifier (APN) previously issued by a secure element manager (eIM) of connected objects or by an operator profile manager (SM-DP+); activation, by the secure element (eUICC), of an operator profile (PR#2) associated with said operator, the operator profile (PR#2) being stored within the secure element (eUICC); and connection, by the connected object (IoT-D), to the operator's telecommunications network using said network access point identifier (APN). Figure for the abstract: Fig. 1.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for connecting a connected object to a telecommunications network and associated device. Technical field

[0001] The present invention belongs to the general field of telecommunications. More particularly, it relates to a method for connecting a connected object to a telecommunications network. It also relates to a connected object configured to implement such a method. Finally, it relates to a telecommunications system comprising a connected object, as well as a manager of secure elements of connected objects and / or a manager of operator profiles.

[0002] The invention is more particularly situated within the framework of a connected object in which is embedded a secure element of the eUICC type ("embedded Universal Integrated Circuit Card" according to the Anglo-Saxon terminology, or "embedded universal integrated circuit card"). Previous technique

[0003] As is known per se, eUICC-type secure elements are used to control access to a mobile telephone network and are embedded in electronic devices. By "embedded," it is understood that the secure element is not easily accessible or replaceable, or that it was not designed to be accessible or replaceable. A secure element embedded in an electronic device—and referred to hereafter as "eUICC"—may or may not be permanently attached to that electronic device, and is distinguished in particular from a conventional "SIM" card (e.g., "non-embedded") by the fact that it is configurable remotely ("Over-The-Air" in Anglo-Saxon terminology).

[0004] The GSMA (acronym for "GSM Association") acts as a standards body and has defined several rules and guidelines concerning eUICC-type secure elements when these are embedded in connected objects. These connected objects (sometimes also called "smart objects") are electronic devices characterized by their ability to interact with their immediate environment, generally through a microcontroller that controls a sensor and / or an actuator, as well as by their connectivity. These objects are connected to a communication network, such as the public Internet within the framework of the Internet of Things (IoT), and can thereby communicate with other systems to obtain and / or provide information.Thus, connected objects make it possible to capture and send back to the network the current value of information specific to their environment and / or their operation, and / or to receive from the network a . command whose execution can have an effect on this environment and / or its operation.

[0005] In order to be configured remotely without user intervention, an eUICC includes data necessary for establishing wireless communication, which is initiated, for example, during the first connection of the electronic device (e.g., the connected object) or in the event of a malfunction. This data is sometimes called a "provisioning profile." An eUICC also includes data relating to a subscription with a mobile phone operator, also called an "operator profile." An operator profile is specific to a mobile phone operator in that it only authorizes access to a particular infrastructure. For example, the operator profile may include information on the hardware and / or software components of the infrastructure to be contacted and cryptographic data..

[0006] In order to connect to a communication network, such as the Internet, a connected object must also have a network access point identifier (or "Access Point Name", APN, according to Anglo-Saxon terminology). This identifier typically allows an electronic device to connect to the Internet by identifying an interconnection gateway located between the mobile network and an IP network. This gateway is sometimes called "Gateway GPRS Support Node", GGSN in the context of 2G (second generation of mobile telephony technologies) or 3G (third generation), and "Packet Data Network Gateway", PGW, in the context of 4G (fourth generation) or 5G (fifth generation).

[0007] A network access point identifier is also operator-specific in that it only authorizes access to a particular infrastructure. Therefore, a change in operator profile typically results in a change of network access point identifier. However, the memory resources of connected objects are relatively limited and do not allow for the storage of a large number of network access point identifiers. Furthermore, the standards defined to date by the GSMA do not allow for the configuration of a network access point identifier for a specific operator profile, particularly when the operator profile changes.

[0008] There is therefore a need to improve existing solutions in terms of connecting a connected object to a telecommunications network. Description of the invention

[0009] The present invention aims to remedy all or part of the drawbacks of the prior art, in particular those described above, by proposing a solution that allows you to configure a network access point identifier for a connected object in which a secure element is embedded.

[0010] To this end, and according to a first aspect, the invention relates to a method of connecting a connected object containing an embedded secure element to a telecommunications network, the method comprising:

[0011] - a reception, by the secure element, of a network access point identifier previously issued by a secure connected object element manager or by an operator profile manager, the network access point identifier being associated with a telecommunications network operator;

[0012] - an activation, by the secure element, of an operator profile associated with the audit operator, the operator profile being stored within the secure element; and

[0013] - a connection, via the connected object, to the telecommunications network of the operator using said network access point identifier.

[0014] The secure element manager of connected objects corresponds for example to the "eSIM loT Remote Manager", elM, as defined in section 4.2.1 of the standard "SGP.31 eSIM loT Architecture and Requirements", Version 1.0, published on April 19, 2022 by the GSMA, and referred to as SGP.31 below.

[0015] The operator profile manager corresponds for example to the "Subscription Manager Data Preparation Plus", SM-DP+, as defined in the standard "SGP.22 RSP Technical Specification", Version 3.0, published on October 19, 2022 by the GSMA, and referred to as SGP.22 hereafter.

[0016] In general, it is considered that the steps of a process should not be interpreted as being linked to a notion of temporal succession.

[0017] In particular embodiments, the connection method may further comprise one or more of the following characteristics, taken individually or in all technically possible combinations.

[0018] In particular embodiments, the method further comprises, prior to activation,

[0019] - a reception, by the connected object and from the secure element, of said network access point identifier and a command, called the "first command", aimed at adding said identifier to a set of network access point identifier(s) usable by the connected object; and

[0020] - an addition, by the connected object, of said audit network access point identifier set of network access point identifier(s).

[0021] This first command corresponds for example to the "RUN AT COMMAND" command as defined in section 6.4.23 of the ETSI TS 102 223 standard, version V14.1.1, and published by ETSI in July 2018.

[0022] In particular embodiments, the connection method further includes a transmission of said network access point identifier, by the secure element manager of connected objects and to the secure element, via a connected object profile assistant.

[0023] In particular implementation modes, the connected object profile assistant is embedded within the secure element or the connected object.

[0024] In particular modes of implementation, the connected object profile assistant conforms to the object profile assistant, IPA (acronym for "loT Profile Assistant" according to Anglo-Saxon terminology, or loT profile assistant), as defined in section 4 of the SGP.31 standard.

[0025] In particular embodiments, the connected object profile assistant is embedded within the connected object, and the network access point identifier is transmitted, by the connected object profile assistant and to the secure element, using an "ES 10b" type interface.

[0026] This "ES 10b" interface, for example, conforms to the SGP.31 standard.

[0027] In particular modes of implementation, the network access point identifier is transmitted, by the secure element manager of connected objects and to the secure element, with a command, called "second command", interpretable by said secure element and aimed at transmitting said "first command" to the connected object.

[0028] Thus, the network access point identifier is for example transmitted as a parameter to a specific command (named "UpdateAPNList" in the rest of the description).

[0029] In particular modes of implementation, the network access point identifier is transmitted, by the secure element manager of connected objects and to the secure element, with a command, called "third command", to activate an operator profile of the secure element (eUICC), said third command comprising a parameter representing a request to update the set of network access point identifiers of the connected object.

[0030] This third command corresponds for example to the "EnableProfile" command as defined in the SGP.22 standard.

[0031] The parameter corresponds for example to a boolean indicator (named "UpdateList" in the rest of the description).

[0032] In particular modes of implementation, the network access point identifier and, where applicable, the second or third command, are transmitted in a data package.

[0033] This data package corresponds for example to the "elMPackage" package as defined by the "SGP.32 eSIM loT Technical Specification" standard, Version 1.0.1, published by the GSMA on July 4, 2023, and referred to as SGP.32 below.

[0034] In particular embodiments, the network access point identifier is transmitted by the operator profile manager as part of an operator profile loading onto the secure element of the connected object, and the reception further includes a reception of said operator profile.

[0035] In particular embodiments, the method further includes processing, by the secure element, said network access point identifier as metadata associated with said operator profile.

[0036] According to a second aspect, the invention relates to computer programs comprising instructions for implementing a connection method, when said programs are executed by a computer.

[0037] These programs may use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other desirable form.

[0038] According to a third aspect, the invention relates to a computer-readable recording medium on which computer programs according to the invention are recorded.

[0039] The information or recording medium can be any entity or device capable of storing programs. For example, the medium can include a storage means, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a hard disk drive.

[0040] On the other hand, the information or recording medium can be a transmissible medium such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means. The programs according to the invention can, in particular, be downloaded onto an Internet-type network.

[0041] Alternatively, the information or recording medium may be an integrated circuit in which the programs are incorporated, the circuit being adapted to execute or to be used in the execution of the process in question.

[0042] According to a fourth aspect, the invention relates to a connected object in which a secure element is embedded and comprising:

[0043] - a receiving module, within the secure element, for a point identifier network access previously issued by a secure connected object element manager or by an operator profile manager, the network access point identifier being associated with a telecommunications network operator;

[0044] - an activation module, within the secure element, for an associated operator profile operator audit, the operator profile being recorded within the secure element; and

[0045] - a connection module to the operator's telecommunications network using said network access point identifier.

[0046] According to a fifth aspect, the invention relates to a telecommunications system comprising a secure element manager for connected objects and a connected object according to the invention.

[0047] According to a sixth aspect, the invention relates to a telecommunications system comprising an operator profile manager and a connected object according to the invention. Brief description of the drawings

[0048] Other features and advantages of the present invention will become apparent from the description below, with reference to the accompanying drawings, which illustrate an example of an embodiment without being limiting in any way. In the figures:

[0049] [Fig-1] [Fig.1] is a schematic representation of a system of telecommunications, according to a first example of implementation;

[0050] [Fig.2] [Fig.2] is a schematic representation of a system of telecommunications, according to a second example of implementation;

[0051] [Fig.3] [Fig.3] represents modules embedded in a connected object, such as the connected object belonging to the telecommunications system of [Fig.1] or 2, according to an example of implementation of the invention;

[0052] [Fig.4] [Fig.4] schematically represents an example of architecture hardware of a connected object, such as the connected object belonging to the telecommunications system of [Fig.1] or 2;

[0053] [Fig.5] [Fig.5] represents, in the form of a flowchart, a first particular mode of implementation of a connection process;

[0054] [Fig.6] [Fig.6] represents, in the form of a flowchart, a second particular mode of implementation of a connection method; and,

[0055] [Fig.7] [Fig.7] represents, in flowchart form, a third mode specific implementation of a connection process. Description of the implementation methods

[0056] Fig. 1 is a schematic representation of a telecommunications system, according to a first example of implementation.

[0057] As illustrated in [Fig. 1], the SYS telecommunications system comprises a telecommunications operator OP connected to an SM-DP+ operator profile manager. In this way, the operator OP can, for example, transmit a request to the SM-DP+ manager to provide a specific operator profile. to a given secure element. The OP operator and the SM-DP+ operator profile manager are for example connected through an ES2+ interface, as defined by the SGP.21, SGP.22 or SGP.31 standard.

[0058] The SM-DP+ operator profile manager typically takes the form of a server and is responsible for preparing and storing operator profiles. It also plays a role in securing operator profiles and assigning each operator profile to the eUICC for which it is intended. Finally, the SM-DP+ also plays a role in remotely downloading profiles and associated data to the eUICCs for which it is responsible. The operator profile manager corresponds, for example, to the "Subscription Manager Data Preparation Plus", SM-DP+, as defined in standard SGP.22 or SGP.31.

[0059] The telecommunications system further includes an elM manager for secure elements of connected objects. This elM manager is configured to remotely manage the downloading of profiles and data associated with these profiles or to implement profile administration functions, such as those defined, for example, in the SGP.31 standard. An elM manager can be configured to manage a single connected object or a fleet of connected objects, and can be run on a server or a user terminal, such as a laptop or a smartphone.

[0060] Since connected objects typically have limited capabilities, whether in terms of power, memory, and / or processing, an elM manager can also serve as an intermediary between a connected object and an SM-DP+ manager. This intermediary communicates with the connected object using a lightweight communication protocol and with the SM-DP+ manager using a client / server communication protocol, such as HTTP (HyperText Transfer Protocol) or HTTPS (HTTP Secure), between the SM-DP+ manager and the elM manager. Using this elM manager advantageously allows for loading and managing eUICC profiles while ensuring end-to-end security between the eUICC and the SM-DP+ manager. As mentioned previously, the elM manager corresponds, for example, to the "eSIM IoT Remote Manager," elM, as defined by the SGP.31 standard.Furthermore, the elM manager of secure connected object elements and the SM-DP+ manager of operator profiles are, for example, connected through an ES9+ interface, as defined by the SGP.21 or SGP.22 standard.

[0061] The telecommunications system further includes a connected IoT-D object. This IoT-D object is connected to a communication network (not shown), such as, for example, the public Internet within the framework of the IoT or, for example, a radio-telecommunications network of the type, for example, GSM (acronym for "Global"). System for Mobile Communications (SMC), or global system for mobile communications, LTE (acronym for Long-Term Evolution), 5G, and can thereby communicate with other electronic systems or devices to obtain and / or provide information. Thus, this connected object can, for example, capture and transmit to the network the current value of information specific to its environment and / or operation, and / or receive a command from the network whose execution can have an effect on this environment and / or operation.

[0062] This connected loT-D object is used, for example, in one of the following fields:

[0063] - industry, sometimes referred to as "Industry 4.0". In this case, the connected loT- object D is, for example, configured to allow finer monitoring of different production stages, or is integrated into a predictive maintenance system;

[0064] - the smart city, for example in order to monitor and manage a system of traffic and transport;

[0065] - security, and the connected object loT-D corresponds, for example, to a camera or a connected presence sensors;

[0066] - health, and the connected object corresponds, for example, to a medical device connected to a fall detection device to combat loss of autonomy; and

[0067] - energy, and the connected object loT-D corresponds, for example, to a meter electrical communicating with an electrical network manager.

[0068] As illustrated in [Fig. 1], this loT-D connected object includes a secure eUICC element including an operating system (OS). This eUICC also includes an IPAe connected object profile assistant (acronym for "loT Profile Assistant eUICC" in Anglo-Saxon terminology, or loT eUICC profile assistant), which provides functionalities enabling the eUICC of the loT-D connected object to be provisioned by the SM-DP+ manager or via the elM manager. This connected object profile IPAe assistant is specifically configured to allow the downloading of operator profiles within the eUICC, the transfer of operator profile management commands - such as activation, deactivation or deletion of a profile - but also to allow the exchange of data (e.g., notifications) with the manager (elM) of secure connected object elements and / or with the manager (SM-DP+) of operator profiles.

[0069] As mentioned previously, the connected object profile assistant, for example, conforms to the object profile assistant, IPA, as defined in section 4 of the SGP.31 standard. Furthermore, the elM manager for secure connected objects and the connected object profile assistant are, for example, connected via an ESipa interface, as defined by the SGP.31 or SGP.32 standard. Moreover, the For example, the SM-DP+ operator profile manager and the connected object profile assistant are connected through an ES9+ interface, as defined by the SGP.21 or SGP.22 standard.

[0070] The eUICC also includes an ISD-R module (acronym for "Issuer Security Domain - Root") generally considered to represent, on the eUICC, an SM-SR server (acronym for "Subscription Manager Secure Routing"). This ISD-R module, for example, conforms to the "GlobalPlatform Technology Card Specification", Version 2.3.1, published in March 2018.

[0071] The eUICC further comprises a first ISD-P#1 (acronym for "Issuer Security Domain - Profile") operator profile container in which a first operator profile PR#1 is stored, and a second ISD-P#2 operator profile container in which a second operator profile PR#2 is stored. The ISD-P#1 and ISD-P#2 operator profile containers conform, for example, to the "GlobalPlatform Technology Card Specification", Version 2.3.1, published in March 2018. As discussed in more detail below with reference to [Fig. 5], only one of the two operator profiles is active, for example, operator profile PR#1.

[0072] It should be noted that considering two operator profiles is only one variant implementation of the invention. Generally speaking, there is no limitation on the number of operator profiles that can be considered, for example, more or less than two operator profiles.

[0073] Fig. 2 is a schematic representation of a telecommunications system, according to a second implementation example.

[0074] The SYS telecommunication system is based on the configuration already described above with reference to [Fig. 1]. Consequently, the elements mentioned in relation to [Fig. 1] are repeated here with identical numerical references.

[0075] This telecommunications system differs from that of [Fig. 1] only in that an IPAd (acronym for "LoT Profile Assistant device" in Anglo-Saxon terminology, or LoT Profile Assistant device) is no longer embedded in the eUICC, but in the LoT-D connected object. In this case, the IPAd connected object profile assistant is, for example, connected to the eUICC via an ES 10b interface, such as that defined, for example, by the SGP.22, SGP.31, and / or SGP.32 standards. The IPAe and IPAd assistants therefore have similar functionalities; only their respective locations differ: the IPAe is located in the eUICC, while the IPAd is located outside the eUICC but in the device hosting the eUICC, i.e., for the present invention, the LoT-D connected object.

[0076] Fig. 3 represents modules embedded in a connected object, such as the loT-D connected object belonging to the telecommunications system of Fig. 1 or 2, according to an example of implementation of the invention.

[0077] As illustrated in [Fig. 3], the loT-D connected object includes, in particular, an eUICC-compliant secure element including:

[0078] - a M0D_RX module for receiving a network access point identifier previously issued by an elM manager of secure connected object elements or by an SM-DP+ operator profile manager, the network access point APN identifier being associated with a telecommunications network operator;

[0079] - a M0D_ACT module for activating an operator profile PR#2 associated with audit operator, the operator profile PR#2 being registered within the secure eUICC element.

[0080] This connected object loT-D also includes a M0D_C0 module for connecting to the operator's telecommunications network using the network access point APN identifier.

[0081] Fig. 4 schematically represents an example of the hardware architecture of a connected object, such as the loT-D connected object belonging to the telecommunications system of Fig. 1 or 2.

[0082] As illustrated in [Fig. 4], the loT-D connected object has the hardware architecture of a computer. Thus, the loT-D connected object includes, in particular, a processor 1, RAM 2, ROM 3_D and non-volatile memory 4. It also has communication means 5. The hardware elements 1, 2, 3_D, 4 and 5 are interconnected, for example, by a communication bus allowing interconnection and communication between these different hardware elements.

[0083] The 3D read-only memory of the loT-D connected object constitutes a storage medium according to the invention, readable by the processor 1 and on which a computer program PROG_D according to the invention is stored, comprising instructions for executing steps of the connection process. The PROG_D program defines functional modules of the loT-D connected object, which rely on or control the hardware elements 1 to 5 of the loT-D connected object mentioned above. These functional modules are illustrated in [Fig. 3] by way of no limitation, and are described in more detail below with reference to different implementation methods.

[0084] In specific implementation modes, the communication means 5 enable the connected object IoT-D to exchange data with any equipment of the SYS communication system, including the secure connected object element manager (elM) and / or the operator profile manager (SM-DP+). To this end, the communication means 5 include a wired or wireless communication interface capable of implementing any suitable protocol known to those skilled in the art.

[0085] As illustrated in [Fig. 4], the loT-D connected object further comprises a secure eUICC-type element, which also includes a read-only memory 3_E and a non-volatile memory 6. For the sake of brevity, not all the hardware components of an eUICC, which are otherwise well known to those skilled in the art, have been detailed in this text. The eUICC's read-only memory 3_E constitutes a storage medium according to the invention, on which a computer program PROG_E according to the invention is stored, comprising instructions for executing steps in the connection process. The PROG_E program defines functional modules of the eUICC. These functional modules are illustrated in [Fig. 3] by way of no limitation, and are described in more detail below with reference to different implementation methods.

[0086] Figure 5 represents, in the form of a flowchart, a first particular mode of implementation of a connection method according to the invention.

[0087] As illustrated in [Fig. 5], the connection process includes a first step S10 of generating a data package. This step is implemented by the SM-DP+ operator profile manager and / or by the elM manager of secure elements of connected objects. This package corresponds, for example, to the "elMPackage" package as defined by the SGP.32 standard.

[0088] In this implementation mode, the elMPackage package includes an "Update APNLIst" command, referred to as the "second command", which takes as parameters an access point identifier APN#2 and a network identifier ID_NET#2. This second command aims to add said identifier APN#2 to a set of network access point identifier(s) usable by the connected object loT-D.

[0089] As previously mentioned with reference to [Fig. 1], the eUICC secure element comprises two operator profiles, PR#1 and PR#2, stored in a memory of this eUICC. The first profile, PR#1, corresponds in this example to the active profile and is associated with a network ID_NET#1, and the second profile, PR#2, is a deactivated operator profile and associated with the network ID_NET#2.

[0090] The package also includes a profile management command, referred to as the "third command" and corresponding in this example to an activation command for the second operator profile PR#2. This third command corresponds, for example, to the "EnableProfile" command as defined by the SGP.22 standard.

[0091] The connection method further includes a step S15 during which the elMPackage is transmitted by the elM manager of connected object secure elements to an IP Ad assistant, an IPAe of the connected object profile, and received by this assistant during a step S20. When this connected object profile assistant is embedded within the eUICC secure element, it is then referenced as IPAe, and when this connected object profile assistant is embedded within the connected object loT-D, it is then referenced as IP Ad. For the sake of brevity, the IPAe and IPAe connected object profile assistants have been grouped together in [Fig. 5]. Thus, the IPAe assistant is located in the eUICC and the IP Ad assistant is located, outside the eUICC, in the loT-D connected object.

[0092] Then, during an S25 step, this elMPackage is transmitted to the eUICC and received by the eUICC during an S30 step. In the specific case where the connected object profile IP Ad assistant is embedded within the loT-D connected object, the package is, for example, transmitted through the "ES 10b" interface as defined by the SGP.31 standard, and received by the ISD-R module. This S30 reception step is, for example, implemented by the eUICC's M0D_RX module.

[0093] The connection process further includes an S35 step during which the package is analyzed by the eUICC, for example by the ISD-R, or, in a variant, by the eUICC operating system. This S35 analysis step includes the detection, by the eUICC and in the received elMPackage, of a so-called "second command" "UpdateAPNList" for updating the set of network access point identifiers usable with the pair (APN#2, ID_NET#2). Following this detection, the eUICC generates a command, called the "first command," representing the detection of the second "UpdateAPNList" command. Then, during an S40 step, the eUICC transmits the "first command" to the loT-D connected object, which adds the identifier to a set of network access point identifiers usable by the connected object. This first command corresponds, for example, to the "RUN AT COMMAND" command as defined in section 6.4.23 of the ETSI TS 102 223 standard, version V14.1.1, and published by ETSI in July 2018. The "RUN AT COMMAND" command thus generated is formatted so as to be able to transmit the pair (APN#2, ID_NET#2) from the eUICC to the connected object, and to allow the update of the set of network access point identifier(s) of the loT-D connected object. .

[0094] This first command is received by the loT-D connected object during step S45. Then, during step S50, in response to receiving this first command, the connected object updates the set of usable network access point identifiers—for example, those stored in non-volatile memory 4. More precisely, during this step S50, the loT-D connected object adds the pair (APN#2, ID_NET#2) to this set. Then, during step S55, the loT-D connected object transmits a confirmation of the identifier set update to the eUICC, which is received by the eUICC during step S60. Following receipt of this update confirmation, the eUICC then activates the second PR#2 profile during step S65. This S65 step of profile activation is for example implemented by the M0D_ACT module of the eUICC.

[0095] The connection process further includes an S70 step for transmitting an ACK confirmation of the activation of the second PR#2 profile to the IPAd / IPAe assistant. This confirmation is transmitted, for example, via an "eUICCPackageResult" package, which is received by the assistant during an S75 step, before being retransmitted to the elM manager of secure connected object elements during an S80 step. This "eUICCPackageResult" package is then received by the elM manager during an S85 step.

[0096] Finally, the connection process includes an S90 step during which the connected object loT-D connects to the network ID_NET#2, using the network access point identifier APN#2. This S90 connection step is implemented, for example, by the M0D_C0 module of the connected object loT-D.

[0097] The invention has so far been described in the case where the update of the set of usable network access point identifiers takes place without errors. If the update of the set of usable network access point identifiers fails during step S50, the connected loT-D device transmits a confirmation of non-update of the identifier set to the eUICC, which is received by the eUICC during step S60. Following receipt of this confirmation of non-update, the eUICC does not activate the second PR#2 profile during step S65. In this particular case, a confirmation of non-activation of the PR#2 profile is transmitted, during step S70, to the IPAd / IPAe assistant, then to the elM manager of secure object elements during step S80.In this particular case, the loT-D object, at step S90, retains the previous connection state in which it was at the time of the update of the set of network access point identifier(s), for example "connected" to a network related to an eUICC PR#1 profile in the active or disconnected state.

[0098] The invention has been described so far in the case where the "elMPackage" package includes the "EnableProfile" command and the "UpdateAPNList" command, this "UpdateAPNList" command taking as parameters the access point identifier APN#2 as well as the network identifier ID_NET#2.

[0099] Alternatively, the "elMPackage" package includes the "EnableProfile" command, and this "EnableProfile" command takes as a parameter a boolean flag, e.g., "UpdateList", whose value represents a request to update the set of network access point identifiers of the connected object loT-D. In this case, the access point identifier APN#2 and the network identifier ID_NET#2 also correspond to parameters of the "EnableProfile" command.

[0100] The invention has also been described so far in the case where the "elMPackage" package includes both the "EnableProfile" command and the "UpdateAPNList" command. But the invention remains applicable in the case where these commands are transmitted by the elM manager through two separate "elMPackage" packages. In this case, the package containing the "UpdateAPNList" command is preferentially transmitted by the elM manager before the package containing the "EnableProfile" command. Preferably, the "EnableProfile" package is transmitted by the elM manager after it has received confirmation from the loT-D connected object that the network access point identifier set has been updated.

[0101] Fig. 6 represents, in the form of a flowchart, a second particular mode of implementation of a connection process.

[0102] As illustrated in [Fig. 6], the connection process includes a first step S100, implemented by the SM-DP+ operator profile manager and / or the elM secure device element manager, during which a secure connection is established between these two managers. Alternatively, the first step S100 is implemented by the SM-DP+ manager and the eUICC via the IPAd / IPAe wizard, without the involvement of the elM secure device element manager.

[0103] The connection method further includes an SI step 10 in which a mutual authentication procedure is implemented between the operator profile SM-DP+ manager, the eIoT secure element manager elM, the eIoT profile IPAd / IPAe assistant, and the eUICC secure element. In one variant, the eIoT secure element manager elM is not involved in the mutual authentication procedure of SI step 10, and only the operator profile SM-DP+ manager, the eIoT profile IPAd / IPAe assistant, and the eUICC secure element are. Then, in an SI step 15, the SM-DP+ manager transmits, to the eUICC secure element, an operator profile PR#2 and MD metadata associated with this PR#2 profile. This PR#2 profile is an operator profile associated with the ID_NET#2 network.In addition, this metadata includes the network identifier ID_NET#2 and a network access point identifier APN#2 allowing connection to the ID_NET#2 network. This data - e.g., the PR#2 profile and the associated MD metadata - is received by the eUICC secure element during an S120 step which is implemented, for example, by the M0D_RX module of this eUICC.

[0104] In response to receiving this data, the eUICC records this data in non-volatile memory 6 during an S125 step, and installs operator profile PR#2 during an S130 step.

[0105] The connection process further includes a step S135 during which the eUICC transmits, to the secure eM manager of connected objects, an ACK data representing a result of the installation of the operator profile PR#2. This ACK data is received by the secure eM manager of connected objects The ACK data is transmitted to the secure connected device during an S140 step. The ACK indicates whether the installation was successful and / or if any errors occurred. The eUICC secure element also transmits this ACK data to the SM-DP+ manager during an S145 step. The manager receives this ACK data during an S150 step and then forwards it to the operator (OP) during an S155 step. The operator then receives the ACK data again during an S160 step.

[0106] The connection process also includes an S165 step during which the eUICC secure element activates the operator profile PR#2 that it has just received. This S165 step of profile activation is implemented, for example, by the eUICC's M0D_ACT module and is initiated following the eUICC's receipt of an operator profile activation command, such as the "EnableProfile" command mentioned earlier. This procedure for receiving an activation command is similar to that described previously with reference to [Fig. 5] and is therefore not shown in [Fig. 6].

[0107] According to a particular implementation, the connection process further includes a transmission, to the elM manager of secure connected object elements, of an ACK confirmation of activation of this second PR#2 profile (not shown).

[0108] Finally, the connection process includes an S170 step during which the connected object loT-D connects to the network ID_NET#2, using the network access point identifier APN#2. This S170 connection step is implemented, for example, by the M0D_C0 module of the connected object loT-D.

[0109] Figure 7 represents, in flowchart form, a third particular mode of implementation of a connection process.

[0110] As illustrated in [Fig. 7], the connection process includes a first step S200, implemented by the SM-DP+ operator profile manager and / or the elM secure device element manager, during which a secure connection is established between these two managers. Alternatively, the first step S200 is implemented by the SM-DP+ manager and the eUICC via the IPAd / IPAe wizard, without the involvement of the elM secure device element manager.

[0111] The connection method further includes a step S205 during which a mutual authentication procedure is implemented between the SM-DP+ operator profile manager, the e-IoT secure element manager elM, the e-IoT profile IPAd / iPAe assistant, and the eUICC secure element. In an alternative, the e-IoT secure element manager elM is not involved in the mutual authentication procedure of step S205, and only The SM-DP+ operator profile manager, the IPAd / IPAe connected object profile assistant, and the eUICC secure element are.

[0112] The connection method further includes an S210 step in which an operator profile PR#2 and MD metadata associated with that PR#2 profile are transmitted, as part of a profile loading and installation procedure, by the SM-DP+ manager to an IP Ad assistant, an IPAe of the connected object profile, and received by that assistant in an S215 step. The PR#2 profile is an operator profile associated with the ID_NET#2 network. Furthermore, the metadata of the PR#2 profile includes a network identifier ID_NET#2 and a network access point identifier APN#2 enabling connection to the ID_NET#2 network. As mentioned previously, when the connected object profile assistant is embedded within the eUICC secure element, it is referenced as IPAe, and when this connected object profile assistant is embedded within the loT-D connected object, it is referenced as IPAd.

[0113] During an S220 step, the IPAd / IPAe wizard analyzes the MD metadata of the PR#2 operator profile and detects the APN ID_NET#2 and APN#2 configuration parameters. This detection can take place during the reception of the PR#2 profile by the IPAd / IPAe wizard, or when the IPAd / IPAe wizard has received the entire PR#2 profile and the loading of the PR#2 profile is complete.

[0114] During an S225 step, the IPAd / IPAe assistant transmits the PR#2 profile and MD metadata to the eUICC, which are received by the eUICC during the S230 step. In the specific case where the connected object profile IPA assistant is embedded within the loT-D connected object (IPAd assistant), the PR#2 profile and metadata are, for example, transmitted via the "ES 10b" interface as defined by the SGP.31 standard, and received by the ISD-R module. This S230 reception step is, for example, implemented by the eUICC's M0D_RX module.

[0115] Following the receipt of the PR#2 profile and associated metadata during step S230, the eUICC installs the PR#2 profile during a step S235.

[0116] The connection process further includes an S240 step during which the eUICC transmits, to the elM manager of secure connected objects, an "ACK_INSTPRO" data point representing an outcome of the PR#2 operator profile installation. This "ACK_INSTPRO" data point is received by the elM manager of secure connected objects during an S245 step. Thus, the ACK_INSTPRO data point indicates whether the profile installation proceeded as expected and / or whether errors were generated during this installation. The eUICC secure element also transmits, during an S250 step, this ACK_INSTPRO data point to the SM-DP+ manager. This ACK_INSTPRO data point is received by the SM-DP+ manager during an S255 step, which then retransmits to the OP operator during an S260 step. The ACK_INSTPRO data is then received by the operator during an S265 step.

[0117] The connection method further includes an S270 step in which the IPAd / IPAe assistant transmits a so-called "second command" or "UpdateAPNList" to the eUICC. This second command is received (and detected) by the eUICC during an S275 step, for example, by its ISD-R module. In the specific case where the connected object profile IPA assistant is embedded within the loT-D connected object (IPAd assistant), this second command is, for example, transmitted to the eUICC via the "ES 10b" interface as defined by the SGP.31 standard, and received by the ISD-R module. This "UpdateAPNList" command is formatted to contain at least the data pair (APN#2, ID_NET#2).

[0118] Following the reception and detection S275 of the second command, the eUICC generates, during a step S280, a command, called "first command", representative of the detection of the second "UpdateAPNList" command to update the set of identifier(s) of network access points usable with the pair (APN#2, ID_NET#2) upon its reception at step 275.

[0119] Then, during an S285 step, the eUICC transmits, to the loT-D connected object, this "first command" which aims to add said identifier to a set of network access point identifier(s) usable by the connected object. This first command corresponds, for example, to the "RUN AT COMMAND" command as defined in section 6.4.23 of the ETSI TS 102 223 standard, version V14.1.1, and published by ETSI in July 2018. The "RUN AT COMMAND" command thus generated is formatted so as to be able to transmit the pair (APN#2, ID_NET#2) from the eUICC to the connected object and to allow the update of the set of network access point identifier(s) of the loT-D connected object.

[0120] This first command is received by the loT-D connected object during an S290 step. Then, during an S295 step, in response to receiving this first command, the loT-D connected object updates the set of usable network access point identifiers—for example, those stored in non-volatile memory 4. More precisely, during this S295 step, the loT-D connected object adds the pair (APN#2, ID_NET#2) to this set.

[0121] Then, during an S300 step, the loT-D connected object transmits, to the eUICC, a "ACK_APNUPD" data representing a result of the update of the set of identifier(s), which is received by this eUICC during an S305 step. Thus, the ACK_APNUPD data indicates whether the installation took place as expected and / or whether errors were generated during this installation.

[0122] The connection method further includes an S310 step during which the eUICC transmits secure object elements to the elM manager The connected device receives the "ACK_APNUPD" data. This "ACK_APNUPD" data is received by the elM secure device manager during step S315. The eUICC secure device also transmits this "ACK_APNUPD" data to the SM-DP+ manager during step S320. This "ACK_APNUPD" data is received by the SM-DP+ manager during step S325, which then forwards it to the operator (OP) during step S330. The ACK data is then received by the operator during step S335.

[0123] The connection process also includes an S350 step during which the eUICC secure element activates the operator profile PR#2. This S350 profile activation step is implemented, for example, by the eUICC's M0D_ACT module and is initiated following the eUICC's S345 reception of an operator profile activation command, such as the "EnableProfile" command. This "EnableProfile" command is, for example, defined in the GSMA SGP.32 standard and transmitted by the eUICC's eM secure element manager to the eUICC via the IPAd / IPAe wizard during an S340 step.

[0124] According to a particular implementation, the connection process further includes an S355 transmission, by the eUICC and to the elM manager of secure connected objects, of an ACK_ACT confirmation of activation of this second PR#2 profile. This ACK_ACT confirmation is received by this elM manager during an S360 step.

[0125] Finally, the connection process includes an S365 step during which the connected object loT-D connects to the network ID_NET#2, using the network access point identifier APN#2. This S365 connection step is implemented, for example, by the M0D_C0 module of the connected object loT-D.

Claims

Demands

1. Method of connecting a connected object (LoT-D) in which a secure element (eUICC) is embedded to a telecommunications network, the method comprising: • a reception (S30, S120), by the secure element (eUICC), of a network access point identifier (APN) previously issued by a secure element manager (elM) of connected objects or by an operator profile manager (SM-DP+), the network access point identifier (APN) being associated with a telecommunications network operator; • an activation (S65, S165), by the secure element (eUICC), of an operator profile (PR#2) associated with said operator, the operator profile (PR#2) being recorded within the secure element (eUICC); and • a connection (S90, S170), by the connected object (LoT-D), to the operator's telecommunications network using said network access point identifier (APN).

2. Connection method according to claim 1, further comprising, prior to activation (S65), • a reception (S45), by the connected object (loT-D) and from the secure element (eUICC), of said network access point identifier (APN) and of a command, referred to as "first command", aimed at adding said identifier to a set of network access point identifier(s) usable by the connected object (loT-D); and • an addition (S50), by the connected object, of said network access point identifier (APN) to said set of network access point identifier(s).

3. Connection method according to claim 1 or 2, further comprising a transmission (S 15) of said network access point identifier (APN), by the secure element manager (elM) of connected objects and to the secure element (eUICC) via a connected object profile assistant (IPAd, IPAe).

4. Connection method according to claim 3, wherein the connected object profile assistant (IPAd, IPAe) is embedded within the secure element (eUICC) or the connected object (loT-D).

5. Connection method according to claim 3 or 4 in combination with claim 2, wherein said network access point identifier (APN) is transmitted (S 15), by the secure element manager (elM) of connected objects and to the secure element (eUICC), with a command, called "second command", interpretable by said secure element (eUICC) and intended to transmit said "first command" to the connected object (loT-D).

6. Connection method according to claim 3 or 4 in combination with claim 2, wherein said network access point identifier (APN) is transmitted (S 15), by the secure element manager (elM) of connected objects and to the secure element (eUICC), with a command, referred to as "third command", to activate an operator profile of the secure element (eUICC), said third command comprising a parameter representative of a request to update the set of network access point identifier(s) of the connected object (loT-D).

7. A connection method according to any one of claims 3 to 6, wherein the network access point identifier (APN) and, where applicable, the second or third command, are transmitted in a data packet.

8. Connection method according to claim 1, wherein the network access point identifier (APN) is transmitted by the operator profile manager (SM-DP+) as part of an operator profile (PR#2) load onto the secure element (eUICC) of the connected object (loT-D), and the reception (S 120) further includes a reception of said operator profile (PR#2).

9. Connection method according to claim 8, further comprising a processing (S 125), by the secure element (eUICC), of said network access point identifier (APN) as metadata associated with said operator profile (PR#2).

10. Computer programs (PROG_D, PROG_E) comprising instructions for implementing a connection method according to any one of claims 1 to 9, when said programs are executed by a computer.

11.

12.

13.

14. A computer-readable recording medium on which computer programs according to claim 10 are recorded. A connected object (IoT-D) in which a secure element (eUICC) is embedded and comprising: • a receiving module (M0D_RX), within the secure element (eUICC), of a network access point identifier (APN) previously issued by a secure element manager (elM) of connected objects or by an operator profile manager (SM-DP+), the network access point identifier (APN) being associated with a telecommunications network operator; • an activation module (M0D_ACT), within the secure element (eUICC), of an operator profile (PR#1, PR#2) associated with said operator, the operator profile (PR#1, PR#2) being registered within the secure element (eUICC); and, • a connection module (M0D_C0) to the operator's telecommunications network using said network access point identifier (APN). Telecommunications system comprising a secure element manager (elM) of connected objects and a connected object (loT-D) according to claim 12. Telecommunications system comprising an operator profile manager (SM-DP+) and a connected object (LoT-D) according to claim 12.

Citation Information

Patent Citations

  • A communication configuration method and apparatus for vehicle-mounted devices based on eSIM cards

    CN115484158B

  • UPDATING PROFILE IN AN EUICC CARD

    FR3143940A1