Download your production subscription profile

The proposed method securely downloads and installs operating subscription profiles by authenticating the eSIM server and ensuring authorized access to the SM-DP+ entity, addressing security concerns and enabling automated profile handling for communication devices.

JP2025514594AActive Publication Date: 2025-05-09TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024552297
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-12
Filing Date
2022-09-22
Publication Date
2025-05-09
Estimated Expiration
2042-09-22

AI Technical Summary

Technical Problem

Existing methods for downloading and installing operating subscription profiles in communication devices lack robust security measures, particularly for IoT devices, which can lead to unauthorized subscription profile downloads and malware threats.

Method used

The method involves obtaining download information for the operating subscription profile from an eSIM server during initial cellular connectivity, authenticating the eSIM server, and then downloading and installing the profile from an SM-DP+ entity, ensuring secure authentication and authorization.

Benefits of technology

This approach enhances security by ensuring that only authorized subscription profiles are downloaded and installed, reducing the risk of malware and unauthorized access, while also enabling automated and secure handling of subscription profiles for multiple devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025514594000001_ABST
    Figure 2025514594000001_ABST
Patent Text Reader

Abstract

A method for downloading and installing an operational subscription profile performed by a subscriber module (1200) in a communication device (180), the method including: obtaining (S102) download information for the operational subscription profile from an eSIM server (1400) over an initial cellular connectivity connection for the communication device, the subscriber module authenticating the eSIM server with the subscription data during a cellular network access authentication for establishing the initial cellular connectivity connection; downloading (S104) the operational subscription profile from an extended subscription manager data preparation entity (150) according to the download information, the operational subscription profile being downloaded over the initial cellular connectivity connection for the communication device; and installing the operational subscription profile in the subscriber module. Communication devices, eSIM servers, subscription modules, computer programs, computer program products, and further methods are also disclosed.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The invention presented herein relates to a method, a subscriber module, a communication device, a computer program and a computer program product for downloading and installing an operational subscription profile. The invention further relates to a method, an embedded subscriber identity module (eSIM) server, a computer program and a computer program product for enabling the downloading and installation of an operational subscription profile to a subscriber module. [Background technology]

[0002] The Global System for Mobile communication Alliance (GSMA) is standardizing how to provide subscribers with a third generation partnership project (3GPP) subscription profile, often referred to as a Subscriber Identity Module (SIM) subscription profile, referred to herein as a subscription profile. Such a subscription profile can be remotely downloaded via the Internet to the physical hardware in the communication device, known as an embedded UICC / embedded universal integrated circuit card (eUICC), integrated UICC / universal integrated circuit card (uUICC), or integrated embedded UICC / universal integrated circuit card (ieUICC). The Remote SIM Provisioning Protocol (RSP) is followed to remotely communicate the subscription profile from a provisioning server (an enhanced Subscription Manager Data Preparation (SM-DP+) server, henceforth referred to as an SM-DP+ entity for short) to the communication device. Remote SIM provisioning for consumer devices is described in the documents "SGP.21 - RSP Architecture Specification v2.4" and "SGP.22 - RSP Technical Specification v2.4".

[0003] The communication device downloads the subscription profile from the SM-DP+ entity. The Mobile Network Operator (MNO) orders the subscription profile from the SM-DP+ entity, which prepares the subscription profile and makes it available for download to the communication device. During the subscription profile ordering phase, the MNO also performs the necessary network provisioning actions. In particular, the communication device needs to be installed at manufacturing time with an appropriate SIM subscription profile that works in the location where the communication device is located so that the communication device has initial cellular-based connectivity when it boots up for the first time. Such a SIM subscription profile is hereafter referred to as the bootstrap subscription profile or the provisioning subscription profile. It is often not known where a specific communication device will end up at the time of manufacturing the eUICC / module / device. For this reason, an MNO provisioning subscription profile with global roaming agreements is desirable.

[0004] Generally speaking, an eSIM service for Internet of Things (IoT) type communication devices is available where knowledge of pre-negotiated MNO agreements, IoT device information, etc. based on the geographic location of the IoT device are used as inputs to a localization procedure to determine the appropriate MNO, provisioning server, and subscription profile to be used for the specific IoT device, and a download of the operational subscription profile is then triggered. Such an eSIM service should be provided by an eSIM server, triggered for example when the IoT device boots up for the first time.

[0005] Since IoT devices typically have no user interface, they should not be able to establish user consent for operations on subscription profiles. In a possible provisioning technique for IoT devices, the IoT device is configured to accept subscription profile download trigger operations and subscription profile management operations (such as subscription profile activation, deactivation and deletion) sent to the IoT device from an authoritative (remote) server (hereafter referred to as management entity) on an established secure communication channel without requiring user confirmation via any local or remote user interface. This allows automated subscription profile handling for a fleet of, for example hundreds or thousands of IoT devices. The management entity may be referred to as eSIM IoT Remote Manager (eIM). According to the document "SGP.31 - eSIM IoT Architecture and Requirements v1.0" published by GSMA, the intention is that the IoT eSIM variant can utilize the existing SM-DP+ and Subscription Manager Discovery Service (SM-DS) infrastructure based directly on the eSIM consumer variant. Thus, the IoT eSIM variant supports the same three ways as in the eSIM consumer variant to provide information to the communication device that a subscription profile is pending for download (summarised below). For secure subscription profile management in an IoT device, a secure communication must be established between the IoT device and the management entity, relying on key material available in the IoT device and the management entity. For example, a pre-shared key may be used, or a private-public key pair and certificates for the two entities are used.In the GSMA eSIM IoT architecture (SGP.31), a secure communication channel between the IoT device and the device management server acting as a management entity can be leveraged to protect the download of subscription profiles and the triggering of subscription profile management operations. Establishing key material at both parties is out of the scope of the solution proposed by GSM. Setting up the key material may for example rely on a bootstrapping process of the IoT device. The GSMA eSIM IoT architecture for low-power IoT devices deals with memory and / or power constrained IoT devices as well as IoT devices connected over low-power wide-area (LPWA) networks. Such devices typically cannot support Hypertext Transfer Protocol Secure (HTTPS) communication with the SM-DP+ entity as required by SGP.22. For those devices, the download of subscription profiles (and handling of notifications) is done via the management entity to the SM-DP+ entity, leveraging the secure communication between the IoT device and the management entity, which handles the HTTPS communication with the SM-DP+ entity.

[0006] Three options are currently defined for providing information to a communications device that a subscription profile is pending for download, hereinafter referred to as Option 1, Option 2 and Option 3.

[0007] Option 1: During the subscription profile ordering phase, the MNO either receives an Activation Code (AC) from the SM-DP+ (over the ES2+ interface) or generates the AC from data received from the SM-DP+. The MNO then distributes the AC to the customer, for example in the form of a Quick Response (QR) code that is readable by the communication device and can be used by the communication device to contact the SM-DP+ device. When the customer triggers the download of the subscription profile by providing the AC to the communication device, the communication device can connect to the appropriate SM-DP+ and download the subscription profile based on the information from the AC.

[0008] Option 2: The communications device is configured with or at least has access to a default SM-DP+ address that defines the SM-DP+ to be used for downloading the subscription profile. For example, upon first power-up during commissioning of the communications device, or based on some other defined trigger, the communications device connects to the default SM-DP+ to download the subscription profile.

[0009] Option 3: During the subscription profile ordering phase, the MNO requests the SM-DP+ to register with a discovery service (such as SM-DS) information about available subscription profiles for a particular communication device. An event is then generated in the SM-DS for the particular communication device, instructing the communication device to connect to the SM-DP+ and download the subscription profile. The communication device is configured to contact the SM-DS to check for pending subscription profile download events, for example at first power-up during commissioning of the communication device. Depending on the successful download of the event from the SM-DS, the communication device connects to the SM-DP+ given by the event and downloads the subscription profile. The GSMA currently defines a root SM-DS that is common for all communication devices. However, there may be secondary SM-DS servers and vendor-specific discovery services, and thus multiple SM-DS servers.

[0010] According to options 2 and 3, the MNO provides the eUICC identifier (EID) of the communication device, and the subscription profile package prepared for download is bound to the EID in the SM-DP+. According to option 1, it is not necessary for the MNO (or the SM-DP+) to know the EID at the time of ordering the subscription profile. In option 1, the communication device receives a matching ID (MID) via the AC, which the communication device presents to the SM-DP+ during the subscription profile download in order to identify the exact subscription profile package prepared.

[0011] In the GSMA eSIM IoT architecture as specified in the aforementioned document "SGP.31 - eSIM IoT Architecture and Requirements v1.0", in addition to the secure channel between the communication device and the management entity, an additional layer of protection is added between the management entity and the subscriber module to protect against potential malware residing in the communication device. According to the architecture, the management entity must sign all commands / operations to the subscriber module related to subscription profile state management operations with its private key, and the subscriber module must verify the signature with the public key of the management entity securely configured in the subscriber before accepting subscription profile state management operations (PSMOs) such as subscription profile enable, subscription profile disable, and subscription profile delete. This is to ensure that malware cannot (download, install, and) enable a rogue subscription profile for the subscriber module, or disable or delete an already installed subscription profile, resulting in loss of connectivity or the need to reinstall the subscription profile. The signed PSMO protects management operations, data that uniquely identifies the subscription profile (eg, an ICCID, which is an Integrated Circuit Card ID), and data for replay protection (eg, a counter or random).

[0012] The configuration of the management entity's public key to the subscriber module may be performed at different stages, such as during production of the subscriber module, during production of the communication device, and in the field when the communication device is switched into service. Currently, subscription profile state management is only possible if the management entity's public key has been configured for the subscriber module. In addition, automatic activation of the subscriber profile is possible without a signed PSMO, if the subscription profile is downloaded from a predefined SM-DP+ entity (as per option 2) or from a SM-DP+ entity obtained via the SM-DS entity (as per option 3).

[0013] Although the GSMA eSIM IoT architecture prevents malware in a communications device from changing the state of a subscription profile, it does not prevent the malware from attempting to download and install new subscription profiles. Furthermore, the above architecture does not prevent a person who knows the EID of a particular communications device from ordering an undesirable subscription profile for that particular communications device and preparing it for download via an SM-DP+ entity, which information is obtained via the same SM-DS entity that the communications device uses to check, for example, which subscription profiles to download. Summary of the Invention

[0014] An object of the embodiments herein is to solve at least one of the above problems and / or to enable improved security in handling operational subscription profiles.

[0015] According to a first aspect, a method for downloading and installing an operational subscription profile is presented. The method is performed by a subscriber module. The subscriber module is provided to a communication device. The subscriber module is provided with subscription data for use in establishing an initial cellular connectivity. The method includes obtaining download information for the operational subscription profile from an eSIM server over an initial cellular connectivity connection for the communication device. The download information is used by the subscriber module in determining that downloading of a subscription profile is authorized for the subscriber module. The subscriber module authenticates the eSIM server with the subscription data during a cellular network access authentication for establishing the initial cellular connectivity connection. The method includes downloading the operational subscription profile from a SM-DP+ entity according to the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device. The method includes installing the operational subscription profile in the subscriber module.

[0016] According to a second aspect, a subscriber module for downloading and installing an operational subscription profile is presented. The subscriber module is provided to a communication device. The subscriber module is provided with subscription data for use in establishing an initial cellular connectivity. The subscriber module comprises a processing circuit. The processing circuit is configured to cause the subscriber module to obtain, from an eSIM server, download information for the operational subscription profile over an initial cellular connectivity connection for the communication device. The download information is used by the subscriber module in determining that downloading of a subscription profile is authorized for the subscriber module. The subscriber module authenticates the eSIM server with the subscription data during a cellular network access authentication for establishing the initial cellular connectivity connection. The processing circuit is configured to cause the subscriber module to download, from a SM-DP+ entity, the operational subscription profile according to the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device. The processing circuitry is configured to cause the subscriber module to install the operational subscription profile in the subscriber module.

[0017] According to a third aspect, a subscriber module for downloading and installing an operational subscription profile is presented. The subscriber module is provided to a communication device. The subscriber module is provided with subscription data for use in establishing an initial cellular connectivity. The subscriber module comprises an acquisition module configured to acquire download information for the operational subscription profile from an eSIM server over an initial cellular connectivity connection for the communication device. The download information is used by the subscriber module in determining that downloading of a subscription profile is authorized for the subscriber module. The subscriber module authenticates the eSIM server with the subscription data during a cellular network access authentication for establishing the initial cellular connectivity connection. The subscriber module comprises a download module configured to download the operational subscription profile from a SM-DP+ entity according to the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device. The subscriber module comprises an installation module configured to install the operational subscription profile into the subscriber module.

[0018] According to a fourth aspect, a computer program for downloading and installing an operational subscription profile is presented. The subscriber module is provided to a communication device. The subscriber module is provided with subscription data for use in establishing an initial cellular connectivity. The computer program includes computer program code that, when executed on a processing circuit of the subscriber module, causes the subscriber module to obtain download information for the operational subscription profile from an eSIM server over an initial cellular connectivity connection for the communication device. The download information is used by the subscriber module in determining that downloading of a subscription profile is authorized for the subscriber module. During cellular network access authentication to establish the initial cellular connectivity connection, the subscriber module authenticates the eSIM server with the subscription data. The computer program includes computer program code that, when executed on a processing circuit of the subscriber module, causes the subscriber module to download the operational subscription profile from an SM-DP+ entity in accordance with the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device. The computer program includes computer program code that, when executed on processing circuitry of the subscriber module, causes the subscriber module to install the operational subscription profile in the subscriber module.

[0019] According to a fifth aspect, a method for enabling download and installation of an operational subscription profile to a subscriber module is provided. The method is performed by an eSIM server. The method includes obtaining a trigger for downloading the subscription profile to the subscriber module. The method includes providing to the subscriber module, on an initial cellular connectivity connection for a communication device on which the subscriber module is provided, download information for the operational subscription profile. The download information is identified for the subscriber module to determine that the subscriber module is authorized to download a subscription profile for the subscriber module. The eSIM server provides authentication data to the subscriber module for the subscriber module to authenticate the eSIM server during a cellular network access authentication for establishing the initial cellular connectivity connection.

[0020] According to a sixth aspect, an eSIM server for enabling download and installation of an operational subscription profile to a subscriber module is presented. The eSIM server comprises a processing circuit. The processing circuit is configured to cause the eSIM server to obtain a trigger for downloading the operational subscription profile to the subscriber module. The processing circuit is configured to cause the eSIM server to provide download information for the operational subscription profile to the subscriber module on an initial cellular connectivity connection for a communication device on which the subscriber module is provided. The download information is identified for the subscriber module to determine that the subscriber module is authorized to download a subscription profile for the subscriber module. The eSIM server provides authentication data to the subscriber module for the subscriber module to authenticate the eSIM server during a cellular network access authentication for establishing the initial cellular connectivity connection.

[0021] According to a seventh aspect, an eSIM server is presented for enabling download and installation of an operational subscription profile to a subscriber module. The eSIM server comprises an acquisition module configured to acquire a trigger for downloading the operational subscription profile to the subscriber module. The eSIM server comprises a provisioning module configured to provide, to the subscriber module, download information for the operational subscription profile on an initial cellular connectivity connection for a communication device on which the subscriber module is provided. The download information is identified for the subscriber module to determine that the subscriber module is authorized to download a subscription profile for the subscriber module. The eSIM server provides the subscriber module with authentication data for the subscriber module to authenticate the eSIM server during a cellular network access authentication for establishing the initial cellular connectivity connection.

[0022] According to an eighth aspect, a computer program for enabling download and installation of an operational subscription profile to a subscriber module is provided. The computer program includes computer program code, which, when executed on a processing circuit of an eSIM server, causes the eSIM server to obtain a trigger for downloading the operational subscription profile to the subscriber module. The computer program code, when executed on a processing circuit of an eSIM server, causes the eSIM server to provide, to the subscriber module, download information for the operational subscription profile on an initial cellular connectivity connection for a communication device on which the subscriber module is provided. The download information is identified for the subscriber module to determine that the subscriber module is authorized to download a subscription profile for the subscriber module. The eSIM server provides the subscriber module with authentication data for the subscriber module to authenticate the eSIM server during a cellular network access authentication for establishing the initial cellular connectivity connection.

[0023] According to a ninth aspect, there is provided a computer program product including a computer program according to at least one of the fourth and eighth aspects and a computer-readable storage medium having the computer program stored thereon. The computer-readable storage medium may be a non-transitory computer-readable storage medium.

[0024] A tenth aspect relates to a communications device including a subscriber module according to the second or third aspect.

[0025] Advantageously, these aspects provide a secure procedure for downloading and installing subscription profiles onto communication devices, avoiding the problems mentioned above.

[0026] Advantageously, these aspects mitigate the downloading and installation of fraudulent subscription profiles to subscriber modules of communication devices.

[0027] Advantageously, these aspects allow for automated handling of downloaded information without the involvement of the device owner or user, thereby allowing for automated provision of an operational subscription profile.

[0028] Advantageously, these aspects allow for automated ex post / subsequent configuration of information for use in the subscriber module in conjunction with the download of subscription profiles using Option 2 and Option 3 disclosed above. Such information includes SM-DP+ / SM-DS object identifiers (OIDs) and addresses.

[0029] Other objects, features and advantages of the included embodiments will become apparent from the following detailed disclosure, from the claims, and from the drawings.

[0030] In general, all terms used in the embodiments and claims should be interpreted according to their ordinary meaning in the art, unless expressly defined otherwise herein. All references to an element, apparatus, component, means, module, step, etc., should be openly interpreted as a reference to at least one instance of that element, apparatus, component, means, module, step, etc., unless expressly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless expressly stated otherwise. [Brief description of the drawings]

[0031] The inventive concept will now be described by way of example only, with reference to the accompanying drawings in which:

[0032] [Figure 1]1 is a schematic diagram illustrating a communication network according to an embodiment. [Diagram 2] 1 is a flowchart of a method according to an embodiment. [Diagram 3] 1 is a flowchart of a method according to an embodiment. [Figure 4] FIG. 2 is a sequence diagram according to an embodiment. [Diagram 5] FIG. 2 is a sequence diagram according to an embodiment. [Figure 6] FIG. 2 is a sequence diagram according to an embodiment. [Figure 7] FIG. 2 is a sequence diagram according to an embodiment. [Figure 8] FIG. 2 is a sequence diagram according to an embodiment. [Figure 9] FIG. 2 is a sequence diagram according to an embodiment. [Figure 10] FIG. 2 is a sequence diagram according to an embodiment. [Figure 11] FIG. 2 is a sequence diagram according to an embodiment. [Figure 12] FIG. 2 is a schematic diagram illustrating functional units of a subscriber module according to an embodiment. [Figure 13] FIG. 2 is a schematic diagram illustrating functional modules of a subscriber module according to one embodiment. [Figure 14] FIG. 2 is a schematic diagram illustrating functional units of an eSIM server according to an embodiment. [Figure 15] FIG. 2 is a schematic diagram illustrating a functional module group of an eSIM server according to an embodiment. [Figure 16] 1 illustrates an example of a computer program product including computer readable means according to one embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0033] The inventive concept will now be more fully described with reference to the accompanying drawings, in which certain embodiments of the inventive concept are depicted. The inventive concept may, however, be embodied in many different forms and should not be construed as being limited to the embodiments set forth herein, but rather, the embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the inventive concept to those skilled in the art. Throughout the description, like numbers refer to like elements. Any steps or features indicated with dashed lines should be considered optional.

[0034] The phrase that a data item or piece of information is obtained by a first device should be interpreted as the data item or piece of information being retrieved, fetched, received, or otherwise made available to the first device. For example, the data item or piece of information may be either pushed to the first device from the second device or pulled by the first device from the second device. Furthermore, in order for the first device to obtain the data item or piece of information, the first device may be configured to perform a series of operations, possibly including interactions with the second device. Such operations or interactions may involve message exchanges including any of a request message for the data item or piece of information, a response message including the data item or piece of information, and an acknowledgement message for the data item or piece of information. If the data item or piece of information is not explicitly or implicitly requested by the first device, the request message may be omitted.

[0035] The phrase "a data item or piece of information is provided by a first device to a second device" should be interpreted as the data item or piece of information being sent or otherwise made available by the first device to the second device. For example, the data item or piece of information may be either pushed from the first device to the second device or pulled from the second device by the second device. Furthermore, in order for the first device to provide the data item or piece of information to the second device, the first device and the second device may be configured to perform a series of operations for mutual interaction. Such operations or interactions may involve message exchanges including any of a request message for the data item or piece of information, a response message including the data item or piece of information, and an acknowledgement message for the data item or piece of information. If the data item or piece of information is not explicitly or implicitly requested by the second device, the request message may be omitted.

[0036] FIG. 1 is a schematic diagram illustrating a communication network 100 in which the embodiments presented herein can be applied.

[0037] The communication device 180 is a device to which an operational subscription profile is downloaded. The communication device 180 may be a mobile phone, a laptop, a computer tablet, or a user equipment (UE). Alternatively, it may be an IoT device. The communication device 180 comprises a subscriber module 1200 (illustrated as eUICC in the figure) such as an iUICC, eUICC or ieUICC, supporting remote provisioning of subscription profiles according to the GSMA consumer variant, including signed subscription profile state management operations according to the GSMA eSIM IoT architecture (as specified in the aforementioned document "SGP.31 - eSIM IoT Architecture and Requirements v1.0"). The communication device 180 supports secure subscription profile download, installation and activation, utilizing an authorization secret or using download and installation data. The subscriber module 1200 holds certificates for secure interaction with both a provisioning server (such as the SM-DP+ entity 150) and a discovery server (such as the SM-DS entity 160). The certificate includes an Elliptic Curve (EC) private key and the subscriber module 1200 certificate containing the corresponding public key. The subscriber module 1200 certificate also contains an identifier for the subscriber module 1200, such as an EID. The subscriber module 1200 is provided with a first profile in the form of a provisioning subscription profile at the time of manufacturing, personalization, or module / device manufacture. The provisioning subscription profile provides initial cellular connectivity that allows for the download of an operational subscription profile. Alternatively, if the subscriber module 1200 does not have a subscription profile installed, the operating system (OS) of the subscriber module 1200 may act as the provisioning subscription profile in establishing the initial cellular connectivity.The communications device 180 may be manufactured by an original equipment manufacturer (OEM) and the subscriber module 120 may be manufactured by an eUICC manufacturer (UEM), both represented by the manufacturer entity 130.

[0038] Management of subscription profiles on the subscriber module 1200 (e.g., enabling, disabling, and deleting subscription profiles) is handled remotely by the management entity 210, which may also handle device and data management for the communication device 180. When the communication device 180 first boots up, the information for connecting to the management entity 210 may not yet be configured. Such information may be obtained by the communication device 180, for example, via an operational subscription profile or via an application layer bootstrapping procedure.

[0039] The communication device 180 comprises a cellular modem configured to connect to a mobile network based on an active subscription profile. At the first power-up of the communication device 180, the provisioning subscription profile is the active subscription profile and provides the initial cellular connectivity. The initial cellular connectivity is established with a first mobile network (MNO1 120). Then, with remote SIM provisioning of the eSIM, the subscriber module 1200 can be provided with a second profile in the form of an operational subscription profile from a second mobile network (MNO2 200). It is noted here that MNO1 120 and MNO2 200 may be one and the same network or different networks in other embodiments. The terms MNO1, MNO2, and MNO3 may be used interchangeably in the following description for mobile network operators and their respective mobile networks in some examples. After the operational subscription profile is activated, the operational subscription profile is used to provide network connectivity for the communication device 180. In other words, the operational subscription profile is intended for long term use (than the provisioning subscription profile) for connectivity services for the communication device 180. The operational subscription profile, in one embodiment, includes MNO data and applications targeted for provision of services by the MNO. The operational subscription profile, in that embodiment, supports subscriptions to the MNO and enables connectivity to the mobile network, typically MNO2 200 in the above example. The operational subscription profile may also include one or more applications for non-communication services.The provisioning subscription profile, in one embodiment, contains a combination of MNO data and applications for the purpose of enabling connectivity to MNO1 120 for the sole purpose of providing an operational subscription profile to the subscriber module 1200. The provisioning subscription profile thus contains information / applications not present in the operational subscription profile, such as how to download the operational subscription profile.

[0040] The communication device 180 typically includes an IoT Subscription Profile Assistant (IPA) 170, as part of the modem, to assist in downloading subscription profiles and managing subscription profile operations. The IPA 170 interacts with a provisioning server for handling subscription profile downloads and notifications, and with a management entity for subscription profile management operations. The IPA 170 may be configured to interact with a discovery service to check for pending subscription profile download events. If the communication device 180 is network, energy and / or memory constrained, the interaction with the SM-DP+ entity 150 and the SM-DS entity 160 may be via the management entity 210.

[0041] The eSIM server 1400 serves as a home mobile network when the communication device 180 connects to a first mobile network (i.e., a visited / serving mobile network) during initial power-up to obtain initial cellular connectivity. The eSIM server 1400 provides a provisioning subscription profile that is installed during manufacturing or personalization of the subscriber module 1200. This may be a common subscription profile for all communication devices 180 that use the service. Alternatively, one individual subscription profile is used for each communication device 180. The provider of the eSIM server 1400 may be, for example, a mobile network operator, a communication service provider (CSP), a mobile virtual network operator (MVNO), or a mobile network vendor. The provider of the eSIM server 1400 may have an agreement with an MNO (shown in the figure as mobile network MNO3 110) to use a set of international mobile subscriber identities (IMSIs) for the eSIM server 1400 so that communication devices such as communication device 180 can be routed to the eSIM server 1400 during the establishment of initial cellular connectivity.

[0042] The MNO (or CSP) provides the cellular connectivity for the communication device and potentially also provides a localization server 140 for remote subscription profile download. If the provider of the eSIM server 1400 is an MVNO, it has roaming agreements with a set of MNOs (shown in the figure as mobile network MNO1 120) that assist in providing the initial cellular connectivity for the communication device 180 using the eSIM server 1400.

[0043] An enterprise, IoT service provider, device owner, or end user using eSIM server 1400 orders a subscription profile for their communication device 180 from an MNO (shown in the figure as mobile network MNO2 200). The MNO interacts with a provisioning server to prepare an operational subscription profile for remote download. Upon successful download and activation of the operational subscription profile to the communication device 180, the MNO provides cellular connectivity to the communication device 180. Note that MNO2 200 may be one of the operators MNO1 120 that provides the initial cellular connectivity.

[0044] The SM-DP+ entity 150 handles the download of subscription profiles to IoT devices according to the GSMA eSIM consumer variant. The SM-DP+ entity 150 is either operated by the MNO (shown in the figure as mobile network MNO2 200) that provides the operational subscription profile to be downloaded, or by a third party trusted by the MNO. The SM-DP+ entity 150 is attested and has acquired certificates that allow it to be part of the eSIM ecosystem. The SM-DP+ certificates for authentication and for downloading subscription profiles contain the SM-DP+ OID, which is used to ensure that communication takes place with the intended SM-DP+ entity 150.

[0045] The SM-DS entity 160 provides discovery services for use by communication devices 180 in accordance with the aforementioned documents "SGP.21 - RSP Architecture Specification v2.4" and "SGP.22 - RSP Technical Specification v2.4". The GSMA currently defines a root SM-DS for the eSIM ecosystem, although there may be auxiliary SM-DS entities and vendor-specific SM-DS entities. The SM-DS entity 160 is certified and has one or more acquired certificates that allow it to be part of the eSIM ecosystem. The SM-DS certificate for authentication contains the SM-DS OID, which is used to ensure that communication takes place with the intended SM-DS entity 160.

[0046] As part of the initial cellular connectivity provision, the localization server 140 may determine the appropriate MNO / MNO device to provide an operational subscription profile for the particular communication device 180. This is referred to as the localization process and may be more or less complicated depending on the scenario at hand. For example, based on the geographic location of the communication device 180, knowledge of pre-negotiated agreements with the MNO, or information on the communication device 180, the appropriate MNO, provisioning server, and operational subscription profile to be used is determined. Such localization may be offered as a service by the provider of the localization server 140 to the enterprise or to the communication service provider 190.

[0047] There can be different approaches on how the localization server 140 is provided and connected to the eSIM server 1400. In a first option, the localization server 140 manages the connectivity for a set of MNOs and handles the interaction of the provisioning server on behalf of the MNOs (even the provisioning server may be provided by the provider of the localization server 140), also updates / controls the Home Subscriber Server (HSS) etc. (such as the Unified Data Management (UDM) in the 5G Core Network (5GC) of the MNO). In a second option, the localization server 140 simply performs the localization based on input data and the interaction with the MNOs is handled by the enterprise itself. Other options are also possible. The eSIM server 1400 may be tightly connected to the localization server 140 (or part of it), for example in the first option, or may not have a relationship and just use the localization application programming interface (API) to trigger the localization and receive information about the operational subscription profile to be selected. Such interactions may also be via businesses.

[0048] The management entity 210 manages one or more subscription profiles on the subscriber module 1200 of the communication device 180. The management entity 210 may also assist in the interaction of downloading subscription profiles between the communication device 180 and the SM-DS entity 160. The management entity 210 supports signed subscription profile state management operations (PSMOs) using a private key of the management entity 210, such as an EC private key, and its corresponding public key, such as an EC public key, is configured into each subscriber module 1200 managed by the management entity 210. The management entity 210 is configured with a list of subscriber 1200 identifiers (such as EIDs) of the communication devices 180 or subscriber modules 1200 managed by the management entity 210. The device owner / end user / enterprise / service provider or other actor may interact with the management entity 210 to configure it with management operations. Such information may include, for example, the ICCID of the subscription profile of the particular subscriber module 1200 for which a particular subscription profile management operation is to be performed, or may include an activation code (AC) along with information from which a particular communication device 180 is to download the subscription profile.

[0049] The embodiments disclosed herein relate to techniques for downloading and installing an operational subscription profile to a subscriber module 1200. To obtain such techniques, a computer program product is provided that includes a subscriber module 1200, a method to be performed by the subscriber module 1200, and code, for example in the form of a computer program, which when executed on processing circuitry of the subscriber module 1200 causes the subscriber module 1200 to perform the method. To obtain such techniques, a computer program product is provided that includes an eSIM server 1400, a method to be performed by the eSIM server 1400, and code, for example in the form of a computer program, which when executed on processing circuitry of the eSIM server 1400 causes the eSIM server 1400 to perform the method.

[0050] Reference is now made to Figure 2, which illustrates a method for downloading and installing an operational subscription profile performed by a subscriber module 1200 according to one embodiment. The subscriber module 1200 is provided to a communication device 180. The subscriber module 1200 is provided with subscription data for use in establishing initial cellular connectivity.

[0051] S102: The subscriber module 1200 obtains download information for an operational subscription profile from the eSIM server 1400. The download information is obtained over an initial cellular connectivity connection for the communication device 180. The download information is used by the subscriber module 1200 in determining that download of a subscription profile is authorized for the subscriber module 1200. The subscriber module 1200 authenticates the eSIM server 1400 with the subscription data during cellular network access authentication to establish the initial cellular connectivity connection.

[0052] S104: The subscriber module 1200 downloads an operational subscription profile according to the download information from the SM-DP+ entity 150. The operational subscription profile is downloaded upon an initial cellular connectivity connection for the communication device 180.

[0053] S106: The subscriber module 1200 installs the operational subscription profile in the subscriber module 1200.

[0054] Embodiments relating to further details of the download and installation of operational subscription profiles performed by the subscriber module 1200 will now be disclosed.

[0055] In some embodiments, after S106, the operational subscription profile is activated upon download and installation (and storage). Thus, in some embodiments, the subscriber module 1200 is configured to perform (optional) step S108.

[0056] S108: The subscriber module 1200 activates the operational subscription profile in the subscriber module 1200 in response to the installation of the operational subscription profile.

[0057] Network access authentication will rely on a secret shared between the eSIM server 1400 and a provisioning profile (accessed by the subscriber module 1200). The shared secret may be a pre-configured part of the provisioning profile or may be derived from data included in the provisioning profile. Thus, in some embodiments, authentication of the eSIM server 1400 is performed using a secret shared with the eSIM server 1400 that is contained in or derivable from the subscription data. In some examples, the subscription data is contained in a provisioning subscription profile installed in the subscriber module 1200. In some examples, the subscription data is contained as part of the operating system of the subscriber module 1200. If no subscription profile is installed in the subscriber module 1200, the subscriber module 1200 uses the subscription data to behave to the communication device 180 as if a provisioning profile exists in the subscriber module 1200. In some examples, a secret shared with the eSIM server 1400 to protect the transfer of download information from the eSIM server 1400 to the subscriber module 1200 over an initial cellular connectivity connection for the communication device 180 is contained in or derivable from the subscription data. In some examples, the secret shared with the eSIM server 1400 is derivable from the subscription data based on the private key of the subscriber module 1200's private-public key pair and the public key of the eSIM server 1400's private-public key pair. The public key of the eSIM server 1400's private-public key pair is part of the subscription data.

[0058] In some examples, the download information is securely transferred from the eSIM server 1400 to the subscriber module 1200 using SIM over-the-air (OTA) procedures. The operational subscription profile could be downloaded from a default SM-DP+ entity 150 or from a SM-DP+ entity 150 provided by the SM-DS entity 160. If the SM-DS entity 160 is used, the SM-DP+ information from which the operational subscription profile is downloaded is first obtained securely from the SM-DS. An authorization secret is used to ensure that the subscriber module 1200 is authorized to download the operational subscription profile. Thus, in some examples, the download information specifies an authorization secret used by the subscriber module 1200 to determine that the download of the operational subscription profile from the SM-DP+ entity 150 is authorized and / or to determine that the download of the SM-DP+ information from the SM-DS is authorized, which identifies the SM-DP+ entity 150 from which the operational subscription profile is downloaded. The determination that the download is authorized is then based on the subscriber module 1200 obtaining proof of knowledge of the SM-DP+ / SM-DS authorization secret obtained during profile download preparation for the operational subscription profile.

[0059] In some examples, the download of the operational subscription profile is secured by utilizing SM-DS or SM-DP+ information (such as addresses and OIDs) in the subscriber module 1200. The SM-DS or SM-DP+ information is used by the subscriber module 1200 to verify information obtained from the SM-DP+ and, if used, from the SM-DS during the download of the operational subscription profile to determine that the profile is authorized. The SM-DS or SM-DP+ information is selected by the communication device 180 using unsigned download and install data that points to the SM-DS or SM-DP+ information. Thus, in some examples, the download information identifies the OIDs of the SM-DP+ entity 150 and / or the SM-DS entity 160 that the subscriber module 1200 uses to download and install the operational subscription profile. In some examples, the SM-DP+ entity from which the operational subscription profile is downloaded is given by the OID identified in the download information if the OID is that of the SM-DP+ entity 150, or by the event record received by the subscriber module 1200 from the SM-DS entity 160 if the OID identified in the download information is that of the SM-DS entity 160. The SM-DS entity 160 is then given by the OID identified in the download information.

[0060] An Authentication and Key Agreement (AKA) protocol, such as that enabled through UMTS-AKA, IMS-AKA, 5G AKA, or Extensible Authentication Protocol-AKA', could be utilized to securely transfer the download information while operating between the subscriber module 1200 and the eSIM server 1400 to authenticate the communication device 180 and obtain initial cellular connectivity. Thus, in some examples, the download information is obtained as part of performing a network access authentication using the AKA protocol when establishing the initial cellular connectivity connection.

[0061] Reference is now made to FIG. 3, which illustrates a method performed by the eSIM server 1400 for enabling download and installation of an operational subscription profile to the subscriber module 1200 according to one embodiment.

[0062] S202: The eSIM server receives a trigger for downloading an operational subscription profile to the subscriber module 1200.

[0063] S206: The eSIM server 1400 provides, to the subscriber module 1200, download information for an operational subscription profile on an initial cellular connectivity connection for the communication device 180 to which the subscriber module 1200 is provided. The download information is identified to determine that the subscriber module 1200 is authorized to download a subscription profile for the subscriber module 1200. The eSIM server 1400 provides authentication data to the subscriber module 1200 for the subscriber module 1200 to authenticate the eSIM server 1400 during cellular network access authentication to establish the initial cellular connectivity connection.

[0064] Embodiments relating to further details enabling the download and installation of operational subscription profiles to the subscriber module 1200 performed by the eSIM server 1400 will now be disclosed.

[0065] The trigger obtained in S202 may be in the form of a network access authentication being triggered at the eSIM server 1400. This in turn is triggered by a subscription identifier, such as an IMSI or a network access identifier (NAI), being provided / received from the subscriber module 1200 via the communication device 180 and the serving network to the eSIM server 1400.

[0066] In some aspects, the download information is generated or determined by the eSIM service in preparation for the profile download. Thus, in some embodiments, the eSIM server 1400 is configured to perform the (optional) step S204.

[0067] S204: The eSIM server 1400 determines download information during profile download preparation for the operational subscription profile.

[0068] It should be noted that step S204 may occur either after step S202 (as in FIG. 3) or before step S202, i.e., after or before the trigger is obtained in S202.

[0069] As disclosed above, in some examples, authentication data provided by the eSIM server 1400 to the subscriber module 1200 is derived using a secret (hence the shared secret) shared with the subscriber module 1200. As disclosed above, in some examples, transfer of download information from the eSIM server 1400 to the subscriber module 1200 over an initial cellular connectivity connection for the communication device 180 is secured using the secret shared with the subscriber module 1200. As disclosed above, in some examples, the secret shared with the subscriber module 1200 is based on the public key of the private-public key pair of the subscriber module 1200 and the private key of the private-public key pair of the eSIM server 1400. As disclosed above, in some examples, download information is securely transferred from the eSIM server 1400 to the subscriber module 1200 using a SIM OTA procedure.

[0070] As disclosed above, in some examples, the download information identifies an authorization secret for use by the subscriber module 1200 to determine that download of an operational subscription profile from the SM-DP+ entity 150 is authorized and / or to determine that download of SM-DP+ information from the SM-DS is authorized that identifies the SM-DP+ entity 150 from which the operational subscription profile is to be downloaded. The determination that the download is authorized is based on the subscriber module 1200 obtaining assurance of SM-DP+ / SM-DS knowledge of the authorization secret obtained during profile download preparation for the operational subscription profile.

[0071] As disclosed above, in some examples, the download information identifies the OID of the SM-DP+ entity 150 and / or the SM-DS entity 160 from which the subscriber module 1200 downloads and installs the operational subscription profile. As disclosed above, in some examples, the SM-DP+ entity from which the operational subscription profile is downloaded is provided by the OID identified by the download information if the OID is that of the SM-DP+ entity 150, or is provided by the event record received by the subscriber module 1200 from the SM-DS entity 160 if the OID identified by the download information is that of the SM-DS entity 160. The SM-DS entity 160 is provided by the OID identified by the download information.

[0072] As disclosed above, in some examples, the download information is provided as part of performing network access authentication using the AKA protocol when establishing an initial cellular connectivity connection, hi some examples, the download information is provided in an authentication vector.

[0073] In the following examples, the subscriber module 1200 will be represented by an eUICC for non-limiting and illustrative purposes, however, the following examples are also applicable to other types of subscriber modules 1200 already mentioned in this disclosure.

[0074] In the following examples, the communication device 180 will be represented by an IoT device for non-limiting and illustrative purposes. However, the following examples are also applicable to other kinds of communication devices 180 already mentioned in this disclosure. When the communication device is in the form of an IoT device, it may be a device for use in one or more application domains, including but not limited to home, urban, wearable technology, augmented reality, industrial applications, and healthcare. By way of example, an IoT device for a home, office, building, or infrastructure may be a baking scale, a coffee machine, a grill, a refrigerator, a freezer, a microwave, an oven, a toaster, a water faucet, a water heater, a hot water heater, a sauna, a vacuum cleaner, a washing machine, a dryer, a dishwasher, a door, a window, a curtain, a blind, furniture, a light bulb, an electric fan, an air conditioner, a cooler, an air purifier, a humidifier, a speaker, a television, a laptop, a personal computer, a game console, a remote controller, a vent, an iron, a steamer, a pressure cooker, a stove, an electric stove, a hair dryer, a hair styler, a mirror, a printer, a scanner, a copier, a projector, a hologram projector, a 3D printer, a drill, a hand dryer, an alarm clock, a clock, a security camera, a smoke detector, a fire alarm, a connected doorbell, an electronic door lock, a lawn mower, a thermostat, a plug, an irrigation control device, a water leak sensor, a humidity sensor, a motion detector, a weather station, an electricity meter, a water meter, and a gas meter.

[0075] By way of further example, an IoT device for use in a city, urban, or suburban area may be a connected street light, a connected traffic light, a traffic camera, a connected road sign, an air control / monitor, a sound level detector, a traffic congestion monitoring device, a traffic control device, an automatic toll payment device, a parking payment device, a parking lot usage monitoring sensor, a traffic management device, a digital kiosk, a trash can, an air quality monitoring sensor, a bridge condition monitoring sensor, a fire hydrant, a manhole sensor, a tarmac sensor, a fountain sensor, a connected closed circuit television, a scooter, a hoverboard, a ticket machine, a turnstile, a subway rail, a subway station device, a passenger information panel, an in-car camera, and other connected devices on a public transportation vehicle.

[0076] As a further example, the communicating IoT device may be a wearable device or an augmented reality related device, which may be an augmented reality (AR), virtual reality (VR), merged reality (MR), or mixed reality (MR) related device. Examples of such IoT devices may be a smart band, an activity tracker, a haptic glove, a haptic suit, a smart watch, clothing, glasses, a head mounted display, an ear pod, an activity monitor, a fitness monitor, a heart rate monitor, a finger ring, a key tracker, a blood glucose meter, and a pressure meter.

[0077] As a further example, the IoT device may be an industrial application device, which may be an industrial unmanned aerial vehicle, an intelligent industrial robot, a vehicle assembly robot, and an automated guided vehicle.

[0078] As a further example, the IoT device may be a transportation vehicle, which may be a bicycle, a motorbike, a scooter, a moped, an autorickshaw, rail transport, a train, a tram, a bus, a car, a truck, an airplane, a boat, a ship, skis, a snowboard, a snowmobile, a hoverboard, a skateboard, roller skates, a cargo vehicle, a drone, a robot, a stratospheric aircraft, an airplane, a helicopter, and a hovercraft.

[0079] As a further example, the IoT device may be a health or fitness device, which may be a surgical robot, an implantable medical device, a non-invasive medical device, and a stationary medical device, which may be an in-vitro diagnostic device, a radiology device, an imaging device, and an x-ray device.

[0080] A general aspect of the secure download of an operational subscription profile using download information obtained by an eUICC leveraging an eSIM server will now be disclosed with reference to the sequence diagram of FIG.

[0081] Referring to Figure 4, a procedure is described for an IoT device to obtain initial cellular connectivity and for the IoT device to download an initial operational subscription profile. The download information required for secure download (e.g., in the presence of malware) of the operational subscription profile is determined or generated during the subscription profile download preparation phase and provided to the eUICC with the aid of an eSIM server, which is part of providing initial cellular connectivity to the IoT device.

[0082] It is assumed (step 0) that the eSIM server database is populated with the EIDs for each IoT device that uses that eSIM server. The eUICC of each IoT device is configured with a provisioning subscription profile from the eSIM server. That subscription profile is the eUICC's current active subscription profile. The IoT device wakes up (e.g., for the first time) and leverages the eUICC's provisioning subscription profile to connect to MNO1, perform network access authentication, and obtain initial cellular connectivity (step 1a). Typically, roaming is used and the eSIM server acts as the home operator and handles the network access authentication. MNO1 determines the eSIM server based on the IMSI provided by the IoT device (or MNO3, if the eSIM server has an agreement with MNO3 to use a specific IMSI range).

[0083] The network access authentication performed as part of step 1a relies on a shared secret shared between the eSIM server and the provisioning subscription profile. In order to select the correct shared secret and trigger localization in step 2, the eSIM server determines the EID of the eUICC in step 1b. This may be done based on the received IMSI, for example if a mapping between IMSI and EID is maintained in the eSIM server, or the EID may be transferred from the eUICC to the eSIM server during the network access authentication (step 1b is done in combination with step 1a).

[0084] In order to prepare for downloading the operational subscription profile suitable for the IoT device, the eSIM server requests (in step 2) a localization to be performed by the localization server. The EID of the eUICC of the IoT device and optionally also the MCC (+MNC) of MNO1 (country / territory where the IoT device is located) are provided for use in the localization. The eSIM server does not necessarily interact directly with the entity performing the localization as shown here. The localization mechanism is performed in step 3, where the MNO that should provide the operational subscription profile is determined, denoted MNO2 in the figure. The operational subscription profile from MNO2 is either pre-prepared for download (in step 4a), for example for all of the IoT devices in the fleet, or the localization server interacts directly with the SM-DP+ (step 4b) to prepare the subscription profile for download. If SM-DS is used, an event is registered with the SM-DS.

[0085] Once an operational subscription profile has been determined and prepared for download, the download information required for secure download of the subscription profile is securely provided from the localization server to the eSIM server (step 5) and then to the eUICC (step 1c). Depending on the method used to securely transfer the download information, the transfer either occurs as part of obtaining the initial cellular connectivity (combined with step 1a) or after the initial cellular connectivity has been obtained, leveraging that connectivity for the transfer of the download information. In the first case, steps 2-5 are performed while the establishment of the initial cellular connectivity is in progress, while in the other case, they are typically performed after the initial cellular connectivity has already been established.

[0086] After receiving the download information, the eUICC stores the download information together with the help eUICC OS command in the ISD-R security domain for use during the download of the operational subscription profile (step 6). In step 7, the modem, with the help of the eUICC and the obtained download information, securely downloads the operational subscription profile from the SM-DP+ given by the information in the IoT device and / or eUICC. If SM-DS is used, the SM-DP+ from which the subscription profile is to be downloaded is first obtained securely from the SM-DS. Upon successful download, the subscription profile is installed and automatically activated. The provisioning subscription profile then uses a refresh command (step 8), which triggers the modem to detach from the current network and discard all cached information related to that network. The modem then attaches to the MNO2 network and gains connectivity using the newly installed and activated operational subscription profile (step 9).

[0087] An example will now be described with reference to the sequence diagram of Fig. 5, where the download of the first operational subscription profile is protected using an authorization secret. The authorization secret is generated during preparation of the subscription profile download by the localization server and provided to the eUICC with the help of the eSIM server, using a SIM OTA procedure.

[0088] Step 0: The eSIM Server's database is populated with the EIDs for each IoT device that uses the eSIM Server for the bootstrap connectivity service. The eUICC of each IoT device that uses the service is configured with a provisioning subscription profile from the eSIM Server. That subscription profile is the eUICC's currently active subscription profile. The eUICC is provisioned with a default SM-DP+ address and / or SM-DS address.

[0089] Step 1: The IoT device leverages the provisioning subscription profile on the eUICC to connect to MNO1 and perform network access authentication to obtain initial cellular connectivity. Roaming may be used and the eSIM server acts as the home operator and handles the network access authentication. MNO1 determines the eSIM server based on the IMSI provided by the IoT device (or MNO3 if the eSIM server has an agreement with MNO3 to use a specific IMSI range). The network access authentication relies on a shared secret shared between the eSIM server and the provisioning subscription profile. The shared secret may be pre-configured as part of the provisioning subscription profile or may be derived by the subscription module (and eSIM server) based on the eUICC private-public key pair and the eSIM server private-public key pair, with the eSIM server public key as part of the provisioning subscription profile. In the latter case, the provisioning subscription profile is configured / contained with the public key of the eSIM server, and the eSIM server's database contains the public key (e.g., the eSIM server's database contains an eUICC certificate that contains the public key of the eUICC) and the EID of each IoT device that uses the eSIM server. As known in the art, an eUICC certificate is a certificate issued by the EUM for a specific eUICC. To select the correct key and trigger the localization in step 2, the eSIM server determines the EID of the eUICC. This may be done based on the IMSI, e.g., a mapping between IMSI and EID is kept in the eSIM server. If the IMSI is selected randomly from the IMSI range, the EID may be transferred from the eUICC to the eSIM server during AKA authentication, as described in more detail below. In another example, the EID is encoded into the IMSI.For example, in the case of 5G, the EID may be transmitted as part of or together with the SUbscription Concealed Identifier (SUCI) (in encrypted form).

[0090] Step 2: The eSIM server requests to perform localization. The EID of the IoT device's eUICC and optionally also the Mobile Country Code (MCC) of MNO1 (the country / region where the IoT device is located) are provided as input. The eSIM server does not necessarily interact directly with the entity performing the localization as shown here.

[0091] Step 3: A localization mechanism is executed to determine the MNO that should provide the operational subscription profile, which is denoted as MNO2 in the figure.

[0092] Step 4: The operational subscription profile from the MNO selected in step 4 needs to be prepared for download. An authorization secret for use in preparing the operational subscription profile for download is randomly generated by the localization server.

[0093] Step 5: The localization server interacts with the SM-DP+ directly or via the MNO / CSP to prepare the subscription profile for download. The authorization secret is provided to the SM-DP+ along with the EID. If SM-DS is used, an event is registered with the SM-DS, including the authorization secret, the EID, and SM-DP+ information such as address and matching ID. The SM-DS here is the same as the one configured in the eUICC, if SM-DS is not used, the SM-DP+ here is the same as the default SM-DP+ configured in the IoT device.

[0094] Step 6: The localization server provides the authorization secret to the eSIM server.

[0095] Step 7: The eSIM Server provides an authorization secret to the Provisioning Subscription Profile of the eUICC using the SIM OTA procedure. The shared secret between the eSIM Server and the Provisioning Subscription Profile used to secure the SIM OTA procedure may be pre-configured as part of the Provisioning Subscription Profile or may be derived by the Provisioning Subscription Profile (and the eSIM Server) based on the eUICC private-public key and the eSIM Server private-public key pair.

[0096] Step 8: The eUICC stores the authorization secret together with the help eUICC OS command in the ISD-R security domain for use during the download of the operational subscription profile.

[0097] Step 9: The modem determines that the eUICC is ready for downloading the subscription profile.

[0098] Step 10: The modem downloads the subscription profile from the default SM-DP+ with the assistance of the eUICC, where the eUICC has determined using the authorization secret that the download is permitted as described above. If the SM-DS is used, the SM-DP+ from which the subscription profile is to be downloaded is first securely obtained from the SM-DS, where the eUICC has determined using the authorization secret that the download of the SM-DP+ information obtained from the SM-DS is permitted. Upon successful verification, the subscription profile is installed and automatically activated.

[0099] Step 11: The eUICC uses a Refresh command, which triggers the modem to detach from the current network and discard all cached information related to that network.

[0100] Step 12: The modem attaches to the MNO2 network using the newly installed and activated operational subscription profile and gains connectivity.

[0101] In step 0, the SM-DP+ and / or SM-DS addresses may be configured in the IoT device, e.g. in the modem, during manufacture of the device (or modem module) instead of being configured in the eUICC during manufacture or personalization of the eUICC. This allows for later configuration of the SM-DP+ / SM-DS to be used during the download of the first subscription profile. It is also possible to provide the SM-DP+ / SM-DS address to be used in step 7 together with the authorization secret.

[0102] As a variant of this example, the IoT device may belong to a group of IoT devices for which a set of subscription profiles is already prepared for download when the IoT device first connects. This is then illustrated in the sequence diagram of Figure 6, where an authorization secret is used.

[0103] The steps in the sequence diagram of FIG. 6 are identical to the steps in the sequence diagram of FIG. 5, except for the following points.

[0104] Step 1: The localization server generates authorization secrets for a group of IoT devices and stores them in a database.

[0105] Step 2: This step is the same as step 5 in the sequence diagram of FIG.

[0106] Step 3: See Step 1 in the sequence diagram in Figure 5.

[0107] Step 4: The eSIM server requests the authorization secret for the EID obtained in step 3 from the localization server.

[0108] Step 5: The localization server retrieves the authorization secret for the particular EID from its database.

[0109] Now, with reference to the sequence diagram of Fig. 7, an example will be described in which the initial operational subscription profile download is protected by utilizing SM-DP+ / SM-DS information in the eUICC during the operational subscription profile download to verify information obtained from the SM-DP+ and, if used, SM-DS to determine that the operational subscription profile download is authorized as previously described. The SM-DP+ / SM-DS information is selected by the communication device using unsigned download and installation data in the device pointing to the SM-DS or SM-DP+ information in the eUICC. The SM-DS / SM-DP+ information defines the download information and is determined during the subscription profile download preparation by the localization server and is provided to the eUICC with the aid of the eSIM server using a SIM OTA procedure. In the case where SM-DP+ information is provided, it may also include a matching ID.

[0110] The steps in the sequence diagram of FIG. 7 are identical to the steps in the sequence diagram of FIG. 5, except for the following:

[0111] Step 0: The eSIM Server's database is populated with the EIDs for each IoT device that uses that eSIM Server. The eUICC of each IoT device that uses the service is configured with a provisioning subscription profile from the eSIM Server provider. That subscription profile is the eUICC's currently active subscription profile.

[0112] Step 4: Step 4 in the sequence diagram of FIG. 5 is not performed in the sequence diagram of FIG.

[0113] Step 6: SM-DP+ or SM-DS information is returned from the localization server to the eSIM server. The information consists of the SM-DP+ / SM-DS OID and possibly its address. In the case where SM-DP+ information is provided, it may also contain a matching ID that identifies the subscription profile for download in the SM-DP+. Alternatively, the ICCID may be used to uniquely identify the subscription profile.

[0114] Step 7: The eSIM Server provides the SM-DP+ / SM-DS information to the Provisioning Subscription Profile of the eUICC using the SIM OTA procedure. The shared secret between the eSIM Server and the Provisioning Subscription Profile used to secure the SIM OTA procedure may be pre-configured as part of the Provisioning Subscription Profile or may be derived by the Provisioning Subscription Profile (and the eSIM Server) based on the eUICC private-public key and the eSIM Server private-public key pair.

[0115] Step 8: The eUICC stores its SM-DP+ / SM-DS information together with the help eUICC OS command into the ISD-R security domain for use during the download of the operational subscription profile.

[0116] Step 10: The modem downloads the subscription profile from the SM-DP+ with the help of the eUICC, which verifies the information obtained from the SM-DP+ / SM-DS during the download of the operational subscription profile with the SM-DP+ / SM-DS information in the eUICC. If the SM-DS is used, the SM-DP+ from which the subscription profile is to be downloaded is first obtained securely from the SM-DS. To prevent the download, installation and activation of an unauthorized subscription profile, the information obtained from the SM-DP+ and from the IoT device is verified by the eUICC with the SM-DP+ information. For example, the OID, address and matching identifier of the SM-DP+ provided to the eUICC are checked against the information obtained in step 7. If the match is successful, the subscription profile is downloaded, installed and activated automatically.

[0117] The derivation of Figure 6, where the IoT device belongs to a pool of IoT devices for which a set of operational subscription profiles is already prepared for download when the IoT device first connects, is also applicable when the download of the subscription profiles is protected using SM-DP+ / SM-DS information stored in the eUICC and used to verify information obtained from the SM-DP+ / SM-DS during the download of the operational subscription profiles, where the SM-DP+ / SM-DS information is obtained by the eUICC via a SIM OTA procedure.

[0118] Now, with reference to the sequence diagram of Fig. 8, an example will be described in which the initial operational subscription profile download is protected by using an authorization secret to determine that the download of the operational subscription profile is permitted, as previously explained, which authorization secret is generated by the localization server during preparation of the subscription profile download and provided to the eUICC with the help of the eSIM server. In this example, the authorization secret is communicated as part of the execution of the AKA protocol.

[0119] The transfer of the authorization secret to the eUICC is performed as part of the establishment of initial cellular connectivity for the IoT device.

[0120] Step 0: See step 0 in the sequence diagram in Figure 5.

[0121] Step 1: When an IoT device first wakes up and attaches to a network, the device's modem reads the IMSI from the eUICC.

[0122] Step 2: The provisioning subscription profile of the eUICC provides the IMSI to the modem. The provisioning subscription profile is unique per IoT device and may be configured with a unique IMSI, which is returned. Alternatively, a provisioning subscription profile that is common to a large set of IoT devices is used. The subscription profile may contain one or more IMSI ranges, from which the provisioning subscription profile randomly selects the IMSI to use. In yet another alternative, the provisioning subscription profile uses an IMSI range (pre-configured in the provisioning subscription profile) where the MCC+MNC digits and possibly a few more digits are fixed, and the remaining IMSI digits are derived from the EID of the eUICC. For example, the remaining digits are assigned as a truncated SHA-256 hash of the EID. The EID is obtained by the subscription profile using the OS functions of the eUICC.

[0123] Step 3: The modem scans for available networks to attach to. Using the MCC+MNC from the IMSI, the modem analyzes the available networks and determines MNO1 as the suitable one. The modem then requests to attach to the selected network.

[0124] Step 4: An identity request is provided by the network.

[0125] Step 5: The modem responds by providing the IMSI.

[0126] Step 6: MNO1 analyzes the IMSI to determine the home mobile network.

[0127] Step 7: A roaming request is made to the home network, which can be any eSIM server acting as an MVNO or another mobile network operator MNO3, whose IMSI range the IMSI belongs to is served by the eSIM server, and which controls the HSS or a similar entity.

[0128] Step 8: The eSIM server determines the EID of the eUICC of the IoT device. In one proposal, this is done based on the received IMSI, with a pre-configured mapping between IMSI and EID and the EID stored in a database of the eSIM server. For example, such a database can be used if a unique IMSI is used per provisioning subscription profile, or if the provisioning subscription profile encodes the EID to the IMSI. In the case of encoding the EID to the IMSI, there may be multiple EIDs that are encoded to the same IMSI, which results in multiple valid entries in the database. How often such collisions occur depends on the size of the IMSI range and the number of IoT devices currently using the service. In case of a collision, the full EID value has to be provided from the provisioning subscription profile to the eSIM server. This can be done via the AKA protocol, which is further explained below. Also, if in step 2 the IMSI is selected randomly from the IMSI range by the provisioning subscription profile, the EID is transferred to and from the eSIM server via the AKA protocol.

[0129] Step 9: See step 2 in the sequence diagram in Figure 5.

[0130] Step 10: See step 3 in the sequence diagram in Figure 5.

[0131] Step 11: See step 4 in the sequence diagram in Figure 5.

[0132] Step 12: See step 5 in the sequence diagram in Figure 5.

[0133] Step 13: See step 6 in the sequence diagram of Figure 5.

[0134] Step 14: Network access authentication is performed according to the AKA procedure using the AV based on the cellular technology used (with small modifications depending on the generation of the 3GPP cellular network). The provisioning subscription profile of the eUICC and the HSS of the eSIM server use a modified behavior according to the following description, however, the behavior is transparent to the visited network (MNO1) and the data and message formats follow the cellular standard used. As part of the network access authentication, the provisioning subscription profile of the eUICC obtains an authorization secret.

[0135] Step 14: See step 8 in the sequence diagram of FIG.

[0136] Step 15: See step 9 in the sequence diagram of FIG.

[0137] Step 16: See step 10 in the sequence diagram of FIG.

[0138] Step 17: See step 11 in the sequence diagram of FIG.

[0139] Step 18: See step 12 in the sequence diagram of FIG.

[0140] Next, an example of the transfer of the authorization secret from the eSIM server to the provisioning protocol using the AKA protocol will be disclosed with reference to the sequence diagram of Fig. 9. This example is based on step 14 of Fig. 8.

[0141] The authorization secret is transferred as part of the authentication vector prepared by the sSIM server. During the transfer, the authorization secret is both encrypted and integrity protected. The key used for encryption and integrity protection is derived from a secret shared between the provisioning subscription profile and the eSIM server. Preferably, the shared secret is an ECDH shared secret derived from an eUICC private-public key pair for use with the eSIM and a private-public key pair of the eSIM server. The eSIM server's HSS stores the eSIM server's private key and obtains the eUICC public key needed to calculate the shared secret from the eUICC certificate stored in its database, which corresponds to the EID determined in step 8 of Fig. 8. The eUICC stores the eSIM server's public key and uses eUICC OS functions to derive the shared secret, using the eUICC private key and the stored eSIM server public key. Alternatively, the provisioning subscription profile can hold a global secret from which the eUICC specific shared secret can be derived using the EID.

[0142] To make the encryption and MAC keys session dependent, they are derived from a shared secret (ECDH or derived from a global secret) and a seed. As a seed, a random value or a challenge communicated as RAND as part of the authentication vector can be used. The RAND is concatenated with a string, e.g. "NAA", used to allow separate keys to be derived for different purposes (see below). For example, the ANSI-16.63-KDF algorithm could be used for the key derivation. The encryption and MAC algorithms used for encryption and integrity protection of the IMSI can be, for example, the AES and HMAC-SHA-256 algorithms, respectively. The MAC algorithm could alternatively be the Milenage f1 function, in which case the IMSI and flags are substituted for the SQN and AMF given as input. The following substeps of step 14 are performed, in which first the authentication vector is generated and then the AKA protocol is performed.

[0143] Step 14a: The eSIM server's HSS generates a random value RAND for use in authentication.

[0144] Step 14b: The eSIM server derives the encryption keys K_enc and K_mac using RAND and a shared secret (ECDH or derived from a global secret) as described above. In addition, temporary values ​​for Ki and OPc, denoted Ki_tmp and OPc_tmp, are derived (using the same key derivation method) for use in network access authentication. In other words, the shared secret is derived using the public key of the eUICC and the private key of the eSIM bootstrap connectivity service.

[0145] Step 14c: The authorization secret is encrypted using K_enc and integrity protected by computing a MAC on the encrypted data using K_mac. The concatenation of the encrypted data and the MAC forms the AUTN value of the authentication vector. AUTN=(encrypted data|MAC).

[0146] Step 14d: Using RAND, Ki_tmp and OPc_tmp as inputs, the values ​​of XRES, CK and IK are calculated according to the normal network access authentication algorithm.

[0147] Step 14e: The authentication vector (RAND, AUTN, XRES, CK, IK) is communicated from the eSIM server to the visited mobile network (i.e., MNO1).

[0148] Step 14f: The visited network sends the RAND and AUTN as an authentication challenge to the modem of the IoT device.

[0149] Step 14g: The modem invokes an authentication command on the eUICC and RAND and AUTN are provided.

[0150] Step 14h: The eUICC derives the shared secret according to above and derives K_enc, K_mac, Ki_tmp and OPc_tmp according to the above description.

[0151] Step 14i: The eUICC extracts the MAC from the AUTN and verifies the MAC using K_mac. If the MAC verification is successful, the encrypted data in the AUTN is extracted and de-encrypted to obtain the authorization secret.

[0152] Step 14j: The eUICC uses RAND, Ki_tmp and OPc_tmp as input to calculate RES, CK and IK according to the normal network access authentication algorithm.

[0153] Step 14k: RES, CK and IK are provided in response to the authenticate command.

[0154] Step 14l: The modem returns the RES to the visited network as a response to the authentication challenge.

[0155] Step 14m: The visited network verifies that RES is equal to XRES, and if so, the authentication is successful.

[0156] The size of the authorization secret is variable and may be, for example, 64 bits. The size of the AUTN parameter may be 128 bits. The encryption may be performed, for example, using the AES encryption algorithm as follows: first, the encrypted data is obtained by encrypting a string (for example, "AUTN") with K_enc, then the result is truncated to the size of the data to be encrypted (for example, 64 bits), and then an exclusive-or or operation (XOR) is applied between the truncated result and the data to be encrypted. Assuming a final size of 64 bits, this can be expressed in pseudocode as follows: E(secret for authorization)=(secret for authorization) XOR E("AUTN")_trunc

[0157] The MAC portion of the AUTN may be represented as 64 bits, for example based on HMAC-SHA-256 with K_mac and truncated to 64 bits. As an example, a full 128-bit AUTN would then look like a 64-bit encrypted authorization secret followed by a 64-bit MAC.

[0158] If a larger authorization secret is used, e.g. 128 bits, the first half may be sent in the first AUTN, the provisioning subscription profile will signal a synchronization error even if it successfully receives the first part, and a new authentication will be performed with a new authentication vector (with a new RAND) in which the second half of the authorization secret is transferred to the provisioning subscription profile. This principle can be developed to accommodate even larger authorization secrets.

[0159] An example where an IMSI is randomly selected according to a provisioning subscription profile and the EID is transferred to the eSIM server via the AKA protocol will now be described with reference to the sequence diagram in Fig. 10. Step 8 of Fig. 8 for this specific case is detailed in Fig. 10.

[0160] Step 8a: The eSIM server's HSS generates a random value RAND for use in the AKA protocol.

[0161] Step 8b: The eSIM server derives an encryption key K_enc using the RAND and the global secret shared with the provisioning subscription profile. In addition, temporary values ​​for Ki (subscriber key) and OPc (key derived with Ki and the operator code as input), denoted Ki_tmp and OPc_tmp, are derived (using the same key derivation method) for use in network access authentication.

[0162] Step 8c: Using RAND, Ki_tmp and OPc_tmp as input, the authentication token (AUTN), expected response (XRES), cipher key (CK) and integrity key (IK) values ​​are calculated according to the normal network access authentication algorithm.

[0163] Step 8d: The authentication vector (RAND,AUTN,XRES,CK,IK) is communicated from the eSIM server to the visited mobile network (MNO1).

[0164] Step 8e: The visited network sends the RAND and AUTN as an authentication challenge to the modem of the IoT device.

[0165] Step 8f: The modem invokes an authentication command on the eUICC and RAND and AUTN are provided.

[0166] Step 8g: The provisioning subscription profile uses the RAND and the shared secret to derive K_enc, Ki_tmp, and OPc_tmp.

[0167] Step 8h: The provisioning subscription profile verifies the AUTN using RAND, Ki_tmp and OPc_tmp.

[0168] Step 8i: If the verification is successful, the EID is encrypted using K_enc and the encrypted data is formatted into an AUTS message.

[0169] Step 8j: The provisioning subscription profile enables synchronization error signaling by the eUICC and provides an AUTS in response to the request in step 8f.

[0170] Step 8k: The modem responds with a sync error to the visitor network and provides an AUTS.

[0171] Step 8i: The visitor network responds with a synchronization error to the eSIM server and provides AUTS.

[0172] Step 8m: The eSIM server de-encrypts the encrypted part of the AUTS with the K_enc derived in step 8b to obtain the EID.

[0173] In other words, AUTS is used here to transfer / obtain EIDs and does not indicate a true synchronization error, even though step 8i above mentions that a synchronization error is signaled.

[0174] The EID may be represented by a 32-digit number. One possibility for encoding the EID is to group three numbers together and encode them as a number between 0 and 999, represented by 10 bits. A 32-digit EID may then be represented by 110 numbers, but since the last two digits of the EID are check digits, a 30-digit number (100 bits) is sufficient. The size of the AUTS parameter may be 112 bits. The encryption may be performed, for example, using the AES encryption algorithm as follows: first, the encrypted data is obtained by encrypting a string (for example, "AUTS" for the EID) with K_enc, the result is truncated to the size of the data to be encrypted, and then an XOR operation is performed between the truncated result and the data to be encrypted. Assuming a final size of 100 bits, this can be expressed in pseudocode as follows: E(EID)=EID XOR E("AUTS")_trunc

[0175] As an example, a complete 112-bit AUTS could consist of a 100-bit encrypted EID followed by 12 random bits.

[0176] The shared secret used to derive K_enc may be a static, global secret between the provisioning subscription profile and the eSIM server. Even if RAND is used to be session specific in the derivation of K_enc, it would still be desirable to use a session specific key to derive the shared secret. In the case of 5G cellular connectivity and SUCI usage, the eSIM server's private-public key pair and an ephemeral key pair generated by the eUICC for SUCI protection could be used to establish an ECDH shared secret from which K_enc can be derived.

[0177] Next, the IMSI collision aspect will be disclosed. The MAC verification in step 14i of Fig. 9 can fail for various reasons. One reason is that in the case where the EID is encoded into the IMSI, there is an IMSI collision, which should be very rare. For IMSI, a collision means that in the eSIM server's database there exists at least one EID with the same IMSI as the one determined for the eUICC in step 8 of Fig. 8, and the eSIM server's HSS selected the wrong entry in the database (i.e. the wrong EID). This results in an incorrect shared secret being derived and the MAC verification fails. In this case, the provisioning subscription profile needs to send its own EID to the eSIM server. Another reason for a MAC failure is that there was some change in the value of AUTN during the transfer. The provisioning server cannot distinguish between these two cases and therefore the EID will always be provided in case of a MAC failure.

[0178] The eSIM server will know that if there is an IMSI collision, the wrong EID may be selected. In case of an IMSI collision, there is more than one entry in the eSIM server database that matches the IMSI in step 8 of FIG. 8. A localization procedure may help in selecting the right EID (the right entry). A localization rule may be that a given EID range belongs to IoT devices from a certain company for which a certain set of countries is valid for where IoT devices may be deployed based on a pre-negotiated MNO contract. As an example, suppose an IoT device connects through a visited network in a certain country and there are two possible EIDs inferred from the IMSI. However, according to the localization rule, only one of those EIDs is in the EID range from a company that is localizable for the MNO in the particular country in question, which means that that EID shall be selected.

[0179] Depending on the relationship between the eSIM server and the localization server, localization may be leveraged in the selection of the EID. Referring now to the sequence diagram of FIG. 10, where a collision occurs.

[0180] Step 8: There is more than one entry (ie more than one EID) in the database that matches the received IMSI.

[0181] Step 9: The entire list of possible EIDs is provided to the localization server in a localization request.

[0182] Step 10: The localization server performs localization to determine the MNO.

[0183] Step 11: The localization server selects from the list an appropriate EID for which to generate an authorization secret.

[0184] Steps 12a, 12b: An operational subscription profile is prepared for download for the selected EID (denoted as EID1).

[0185] Step 13: The authorization secret is provided from the localization server to the eSIM server.

[0186] Step 14: The eSIM server executes the AKA protocol (according to steps 14a to 14h in FIG. 8), in which the authorization secret is transferred to the provisioning subscription profile. A MAC failure occurs (step 14i in FIG. 9), and the EID is returned (in encrypted form) in an AUTS format message to the eSIM server (steps corresponding to steps 8i to 8m in FIG. 9 are performed). A re-localization is requested to the localization server. Steps 9 to 13 are repeated with a new EID (called EID2) received from the eUICC, and a new authorization secret is generated and returned to the eSIM server. Then, according to step 14 (as detailed in FIG. 8) and step 15, the authorization secret is communicated to the provisioning subscription profile and stored in the ISD-R. A new authentication vector is generated together with a new RAND.

[0187] The use of the SIM OTA procedure to securely transfer information to the eUICC allows more information to be provided than when using the AKA protocol. For example, in the example disclosed with reference to figures 5 and 6, the eUICC may not have a default SM-DP+ address. The address of the SM-DP+ (or of the SM-DS, if the corresponding option is used) can be provided to the eUICC using the SIM OTA procedure, together with the authorization secret.

[0188] The SM-DP+ / SM-DS OIDs typically have a size small enough for provisioning using the AKA protocol. For example, the SM-DS OIDs may be provided securely to the eUICC using the AKA protocol. As long as the SM-DS address is configured for use by the IPA, e.g., configured in the IoT device during device manufacturing, a secure subscription profile download can be performed, whereby the eUICC verifies the information obtained from the SM-DS during the operational subscription profile download with the SM-DS information in the eUICC. Similarly, the SM-DP+ OIDs may be provided to the eUICC over the AKA protocol, e.g., in combination with the ICCID. As long as the SM-DP+ address is configured for use by the IPA, a secure operational subscription profile download can be performed by verifying the information obtained from the SM-DP+ during the profile download.

[0189] As already mentioned above, the SIM OTA procedure has fewer constraints on the size of information that can be transferred from the eSIM server to the eUICC compared to using the AKA protocol. On the other hand, the SIM OTA procedure relies on the use of Short Message Service (SMS) messages or HTTPS as information bearers, which implies that the SIM OTA procedure may not be suitable for low-power IoT devices connected over LPWA networks such as narrowband (NB) IoT networks. The use of the AKA protocol for information transfer is possible for all IoT devices that support the required protocols. Furthermore, to address low-power IoT devices, in addition to HTTPS over Transmission Control Protocol (TCP), Constrained Application Protocol (CoAP) over Datagram Transport Layer Security (DTLS) over User Datagram Protocol (UDP) can be used, which allows the SIM OTA procedure to be used for low-power IoT devices as well.

[0190] Figure 12 shows a schematic of the components of a subscriber module 1200 according to one embodiment in terms of several functional units. The processing circuitry 1210 is provided using any combination of one or more suitable central processing units (CPUs), multiprocessors, microcontrollers, digital signal processors (DSPs), etc. capable of executing software instructions stored in a computer program product 1610a (as in Figure 16) in the form of, for example, a storage medium 1230. The processing circuitry 1210 may further be provided as at least one application specific integrated circuit (ASIC) or field programmable gate array (FPGA).

[0191] In particular, the processing circuitry 1210 is configured to cause the subscriber module 1200 to perform the set of operations or steps disclosed above. For example, the storage medium 1230 may store the set of operations, and the processing circuitry 1210 may be configured to read the set of operations from the storage medium 1230 and cause the subscriber module 1200 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus, the processing circuitry 1210 is adapted to thereby perform the method as disclosed herein.

[0192] The storage medium 1230 may also include persistent storage, which may be any one or combination of, for example, magnetic memory, optical memory, solid-state memory, or remotely mounted memory.

[0193] The subscriber module 1200 may further comprise a communication interface 1220 for communication with other entities, functions, nodes, and devices, such as in Figure 1. As such, the communication interface 1220 may comprise one or more transmitters and receivers, including analog and digital components.

[0194] Processing circuitry 1210 controls the overall operation of subscriber module 1200, such as by sending data and control signals to communication interface 1220 and storage medium 1230, receiving data and reports from communication interface 1220, and reading data and instructions from storage medium 1230. Other components and associated functionality of subscriber module 1200 have been omitted so as not to obscure the concepts presented herein.

[0195] FIG. 13 shows a schematic of the components of a subscriber module 1200 according to an embodiment in terms of several functional modules. The subscriber module 1200 of FIG. 13 includes a number of functional modules, such as an acquisition module 1210a configured to perform step S102, a download module 1210b configured to perform step S104, and an installation module 1210c configured to perform step S106. The subscriber module 1200 of FIG. 13 may further include a number of optional functional modules, such as an activation module 1210d configured to perform step S108. Generally speaking, each of the functional modules 1210a:1210d may be implemented in hardware or software. Preferably, one or more or all of the functional modules 1210a:1210d may be implemented by the processing circuitry 1210, possibly in cooperation with the communication interface 1220 and / or the storage medium 1230. The processing circuitry 1210 may thus be configured to retrieve instructions provided by the functional modules 1210a:1210d from the storage medium 1230 and execute those instructions to perform any of the steps of the subscriber module 1200 as disclosed herein.

[0196] Figure 14 shows a schematic of components of an eSIM server 1400 according to an embodiment in terms of several functional units. The processing circuitry 1410 is provided using any combination of one or more suitable central processing units (CPUs), multiprocessors, microcontrollers, digital signal processors (DSPs), etc. capable of executing software instructions stored in a computer program product 1610b (as in Figure 16), for example in the form of a storage medium 1430. The processing circuitry 1410 may further be provided as at least one application specific integrated circuit (ASIC) or field programmable gate array (FPGA).

[0197] Specifically, the processing circuitry 1410 is configured to cause the eSIM server 1400 to perform the set of operations or steps disclosed above. For example, the storage medium 1430 may store the set of operations, and the processing circuitry 1410 may be configured to read the set of operations from the storage medium 1430 and cause the eSIM server 1400 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus, the processing circuitry 1410 is adapted to thereby perform the method as disclosed herein.

[0198] The storage medium 1430 may also include persistent storage, which may be any one or combination of, for example, magnetic memory, optical memory, solid-state memory, or remotely mounted memory.

[0199] The eSIM server 1400 may further comprise a communication interface 1420 for communication with other entities, functions, nodes, and devices, such as those of Figure 1. As such, the communication interface 1420 may comprise one or more transmitters and receivers, including analog and digital components.

[0200] The processing circuit 1410 controls the overall operation of the eSIM server 1400, such as by sending data and control signals to the communication interface 1420 and the storage medium 1430, receiving data and reports from the communication interface 1420, and reading data and instructions from the storage medium 1430. Other components and associated functionality of the eSIM server 1400 have been omitted so as not to obscure the concepts presented herein.

[0201] FIG. 15 shows a schematic of components of an eSIM server 1400 according to an embodiment in terms of several functional modules. The eSIM server 1400 of FIG. 15 may further comprise a number of functional modules, such as an acquisition module 1410a configured to perform step S202 and a provision module 1410c configured to perform step S206. The eSIM server 1400 of FIG. 15 may further comprise a number of optional functional modules, such as a determination module 1410b configured to perform step S204. Generally speaking, each functional module 1410a:1410c may be implemented in hardware or software. Preferably, one or more or all of the functional modules 1410a:1410c may be implemented by a processing circuit 1410, possibly in cooperation with a communication interface 1420 and / or a storage medium 1430. The processing circuitry 1410 may thus be configured to retrieve instructions provided by the functional modules 1410a:1410c from the storage medium 1430 and execute those instructions to perform any steps of the eSIM server 1400 as disclosed herein.

[0202] 16 shows an example of a computer program product 1610a, 1610b including a computer readable means 1630. The computer readable means 1630 may store a computer program 1620a that can cause entities and devices, such as the processing circuit 1210 and the communication interface 1220 and storage medium 1230 operatively coupled thereto, to perform the method according to the embodiments described herein. The computer program 1620a and / or the computer program product 1610a may thus provide the means for performing any steps of the subscriber module 1200 as disclosed herein. The computer readable means 1630 may store a computer program 1620b that can cause entities and devices, such as the processing circuit 1410 and the communication interface 1420 and storage medium 1430 operatively coupled thereto, to perform the method according to the embodiments described herein. The computer program 1620a and / or computer program product 1610a may thus provide means for performing any of the steps of the eSIM server 1400 as disclosed herein.

[0203] In the example of Fig. 16, the computer program products 1610a, 1610b are shown as optical discs, such as compact discs (CDs), digital versatile discs (DVDs) or Blu-ray discs. The computer program products 1610a, 1610b may also be embodied as memory, such as random access memory (RAMs), read-only memory (ROMs), erasable programmable read-only memory (EPROMs) or electrically erasable programmable read-only memory (EEPROMs), more particularly as non-volatile storage media in the device, such as an external memory, such as a Universal Serial Bus (USB) memory or a flash memory, such as a CompactFlash memory. Thus, although the computer programs 1620a, 1620b are shown here diagrammatically as tracks on the depicted optical disc, the computer programs 1620a, 1620b can be stored in any manner suitable for the computer program products 1610a, 1610b.

[0204] The inventive concept has been described above primarily with reference to certain embodiments. However, as will be readily appreciated by those skilled in the art, other embodiments than those disclosed above are equally possible within the scope of the inventive concept as defined by the claims.

Claims

1. 1. A method for downloading and installing an operational subscription profile performed by a subscriber module (1200) provided to a communications device (180), the subscriber module being provided with subscription data for use in establishing initial cellular connectivity, the method comprising: obtaining (S102) download information for the operational subscription profile from an eSIM server (1400) on an initial cellular connectivity connection for the communication device (180), the download information being used by the subscriber module in determining whether download of a subscription profile is permitted for the subscriber module, and during cellular network access authentication to establish the initial cellular connectivity connection, the subscriber module authenticates the eSIM server with the subscription data; downloading (S104) the operational subscription profile according to the download information from an enhanced subscription manager data preparation (SM-DP+) entity (150), wherein the operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device (180); Installing the operational subscription profile in the subscriber module (1200) (S106); A method comprising:

2. 10. The method of claim 1, further comprising: activating the operational subscription profile in the subscriber module (1200) in response to installing the operational subscription profile (S108); A method comprising:

3. 2. The method of claim 1, wherein the authentication of the eSIM server (1400) is performed using a secret shared with the eSIM server that is contained in or derivable from the subscription data.

4. 4. The method of claim 3, wherein the subscription data is contained in a provisioning subscription profile that is installed in the subscriber module (1200).

5. 4. The method of claim 3, wherein the subscription data is contained as part of the subscriber module's operating system, and when a subscription profile is not installed in the subscriber module, the subscriber module (1200) uses the subscription data to behave as if a provisioning profile exists for the communication device (180).

6. 2. The method of claim 1, wherein a secret shared with the eSIM server (1400) to protect the transfer of the download information from the eSIM server to the subscriber module (1200) over the initial cellular connectivity connection for the communication device (180) is contained in or derivable from the subscription data.

7. 7. The method of claim 3 or 6, wherein the secret shared with the eSIM server (1400) is derivable from the subscription data based on a private key of a private-public key pair of the subscriber module (1200) and a public key of a private-public key pair of the eSIM server, the public key of the eSIM server's private-public key pair being part of the subscription data.

8. 2. The method of claim 1, wherein the download information is securely transferred from the eSIM server (1400) to the subscriber module (1200) using a SIM OTA procedure.

9. 2. The method of claim 1, wherein the download information identifies an authorization secret used by the subscriber module (1200) to determine that the download of the operational subscription profile from the SM-DP+ entity (150) is authorized for the subscriber module and / or to determine that the download of SM-DP+ information is authorized from a Subscription Manager Discovery Service (SM-DS) entity (160) that identifies the SM-DP+ entity from which the operational subscription profile will be downloaded, and determining that the download is authorized is based on the subscriber module obtaining assurance of the SM-DP+ / SM-DS knowledge of the authorization secret obtained during profile download preparation for the operational subscription profile.

10. 2. The method of claim 1, wherein the download information identifies object identifiers (OIDs) of the SM-DP+ entity (150) and / or SM-DS entity (160) for use by the subscriber module (1200) in downloading and installing the operational subscription profile.

11. 11. The method of claim 10, wherein the SM-DP+ entity from which the operational subscription profile is downloaded is given by the OID identified by the download information if the OID is that of the SM-DP+ entity, or is given by an event record received by the subscriber module (1200) from the SM-DS entity (160) if the OID identified by the download information is that of the SM-DS entity, and the SM-DS entity is given by the OID identified by the download information.

12. 2. The method of claim 1, wherein the download information is obtained as part of performing a network access authentication using an AKA protocol when establishing the initial cellular connectivity connection.

13. 1. A method for enabling download and installation of an operational subscription profile to a subscriber module, the method being performed by an eSIM server, the method comprising: Obtaining a trigger for downloading the operational subscription profile to the subscriber module (S202); providing (S206) to the subscriber module, download information for the operational subscription profile over an initial cellular connectivity connection for a communication device (180) on which the subscriber module is provided; Including, The method of claim 1, wherein the download information is identified to allow the subscriber module to determine that a subscription profile is authorized for the subscriber module, and during cellular network access authentication to establish the initial cellular connectivity connection, the eSIM server (1400) provides authentication data to the subscriber module (1200) for the subscriber module to authenticate the eSIM server.

14. 14. The method of claim 13, further comprising: determining the download information during profile download preparation for the operational subscription profile (S204); A method comprising:

15. 14. The method of claim 13, wherein the authentication data provided by the eSIM server to the subscriber module is derived using a secret shared with the subscriber module.

16. 14. The method of claim 13, wherein the transfer of the download information from the eSIM server (1400) to the subscriber module (1200) over the initial cellular connectivity connection for the communication device (180) is protected using a secret shared with the subscriber module.

17. 17. The method of claim 15 or 16, wherein the secret shared with the subscriber module is based on a public key of a private-public key pair of the subscriber module (1200) and a private key of a private-public key pair of the eSIM server (1400).

18. 14. The method of claim 13, wherein the download information is securely transferred from the eSIM server (1400) to the subscriber module (1200) using a SIM OTA procedure.

19. 14. The method of claim 13, wherein the download information specifies an authorization secret for use by the subscriber module (1200) to verify that the download of the operational subscription profile from an Extended Subscription Manager Data Preparation (SM-DP+) entity (150) is authorized for the subscriber module and / or to verify that the subscriber module is authorized to obtain SM-DP+ information from a Subscription Manager Discovery Service (SM-DS) entity (160) identifying the SM-DP+ entity from which the operational subscription profile is to be downloaded, the verification being based on the SM-DP+ entity and / or the SM-DS entity providing the subscriber module with assurance of knowledge of the authorization secret obtained during profile download preparation for the operational subscription profile.

20. 14. The method of claim 13, wherein the download information identifies object identifiers (OIDs) of SM-DP+ entities (150) and / or SM-DS entities (160) for use by the subscriber module (1200) in downloading and installing the operational subscription profile.

21. 21. The method of claim 20, wherein the SM-DP+ entity from which the operational subscription profile is downloaded is given by the OID identified by the download information if the OID is that of the SM-DP+ entity, or is given by an event record received by the subscriber module (1200) from the SM-DS entity (160) if the OID identified by the download information is that of the SM-DS entity, and the SM-DS entity is given by the OID identified by the download information.

22. 14. The method of claim 13, wherein the download information is provided as part of performing a network access authentication using an AKA protocol when establishing the initial cellular connectivity connection.

23. 23. The method of claim 22, wherein the download information is provided in an authentication vector.

24. A subscriber module (1200) for downloading and installing an operational subscription profile, the subscriber module being provided to a communications device (180), the subscriber module being provided with subscription data for use in establishing initial cellular connectivity, the subscriber module comprising a processing circuit (1210) that transmits to the subscriber module: obtaining, from an eSIM server (1400), download information for the operational subscription profile on an initial cellular connectivity connection for the communication device, the download information being used by the subscriber module in determining whether download of a subscription profile is permitted for the subscriber module, and during cellular network access authentication to establish the initial cellular connectivity connection, the subscriber module authenticates the eSIM server with the subscription data; downloading the operational subscription profile from an enhanced subscription manager data preparation (SM-DP+) entity (150) according to the download information, the operational subscription profile being downloaded over the initial cellular connectivity connection for the communication device (180); installing the operational subscription profile on the subscriber module; A subscriber module (1200) configured to:

25. A subscriber module (1200) for downloading and installing an operational subscription profile, the subscriber module being provided to a communications device (180), the subscriber module being provided with subscription data for use in establishing initial cellular connectivity, the subscriber module comprising: an acquisition module (1210a) configured to acquire download information for the operational subscription profile from an eSIM server (1400) upon an initial cellular connectivity connection for the communication device (180), the download information being used by the subscriber module in determining whether download of a subscription profile is permitted for the subscriber module, and during cellular network access authentication to establish the initial cellular connectivity connection, the subscriber module authenticates the eSIM server with the subscription data; a download module (1210b) configured to download the operational subscription profile from an enhanced subscription manager data preparation (SM-DP+) entity (150) according to the download information, the operational subscription profile being downloaded over the initial cellular connectivity connection for the communication device; an installation module (1210c) configured to install the operational subscription profile on the subscriber module; A subscriber module (1200) comprising:

26. A subscriber module (1200) according to claim 24 or 25, further configured to perform the method according to any one of claims 2 to 12.

27. 1. An eSIM server (1400) for enabling download and installation of an operational subscription profile to a subscriber module (1200), the eSIM server comprising a processing circuit (1410), the processing circuit providing to the eSIM server: Obtaining a trigger for downloading the operational subscription profile to the subscriber module; providing, to the subscriber module, download information for the operational subscription profile over an initial cellular connectivity connection for a communication device (180) on which the subscriber module is provided; configured to cause the download information is identified to the subscriber module to determine that the subscriber module is authorized to download a subscription profile, and during cellular network access authentication to establish the initial cellular connectivity connection, the eSIM server provides authentication data to the subscriber module for the subscriber module to authenticate the eSIM server. eSIM server (1400).

28. An eSIM server (1400) for enabling the download and installation of an operational subscription profile to a subscriber module (1200), said eSIM server comprising: an acquisition module (1410a) configured to acquire a trigger for downloading the operational subscription profile to the subscriber module; a provisioning module (1410c) configured to provide, to the subscriber module, download information for the operational subscription profile over an initial cellular connectivity connection for a communication device (180) on which the subscriber module is provided; Equipped with the download information is identified to the subscriber module to determine that the subscriber module is authorized to download a subscription profile, and during cellular network access authentication to establish the initial cellular connectivity connection, the eSIM server provides authentication data to the subscriber module for the subscriber module to authenticate the eSIM server. eSIM server (1400).

29. The eSIM server (1400) of claim 27 or 28, further configured to execute the method of any one of claims 14 to 23.

30. 16. A computer program (1620a) for downloading and installing an operational subscription profile, the computer program comprising computer code that, when executed on processing circuitry of a subscriber module (1200) provided to a communications device (180) and that is provided with subscription data for use in establishing initial cellular connectivity, causes the subscriber module to: obtaining, from an eSIM server (1400), download information for the operational subscription profile on an initial cellular connectivity connection for the communication device, the download information being used by the subscriber module in determining whether download of a subscription profile is permitted for the subscriber module, and during cellular network access authentication to establish the initial cellular connectivity connection, the subscriber module authenticates the eSIM server with the subscription data; downloading the operational subscription profile from an enhanced subscription manager data preparation (SM-DP+) entity (150) according to the download information, the operational subscription profile being downloaded over the initial cellular connectivity connection for the communication device; installing the operational subscription profile on the subscriber module; A computer program (1620a) for causing the computer to perform the above steps.

31. A computer program (1620b) for enabling download and installation of an operational subscription profile to a subscriber module (1200), the computer program comprising computer code that, when executed on processing circuitry of an eSIM server (1400), causes the eSIM server to: Obtaining a trigger for downloading the operational subscription profile to the subscriber module; providing, to the subscriber module, download information for the operational subscription profile over an initial cellular connectivity connection for a communication device (180) on which the subscriber module is provided; Let them do so, the download information is identified to the subscriber module to determine that the subscriber module is authorized to download a subscription profile, and during cellular network access authentication to establish the initial cellular connectivity connection, the eSIM server provides authentication data to the subscriber module for the subscriber module to authenticate the eSIM server. Computer program.

32. A computer program product (1610a, 1610b) comprising a computer program (1620a, 1620b) according to at least one of claims 30 and 31 and a computer readable storage medium having said computer program stored thereon.

33. A communication device (180) comprising a subscriber module (1200) according to any one of claims 24 to 26.

34. 34. The communication device (180) of claim 33, which is an IoT device.

Citation Information

Patent Citations

  • METHOD AND APPARATUS FOR MANAGING TERMINAL PROFILES IN A WIRELESS COMMUNICATION SYSTEM - Patent application

    JP2018512822A

  • SYSTEM AND METHOD FOR OPERATING A USER DEVICE WITH A PERSONALIZED IDENTITY MODULE PROFILE - Patent application

    JP2023530896A

  • Esim subscription management system

    US20190349743A1

  • Radio communication system, radio access network node, communication device, and core network node

    WO2014097517A1