Providing a profile package to a profile server for download to an eUICC

The method addresses the challenge of reusing profile numbers in eUICCs by releasing locked ICCIDs and generating new network access certificates, achieving flexible, efficient, and secure profile downloads.

JP2025516479AActive Publication Date: 2025-05-30GIESECKE PLUS DEFRIENT MOBILE SECURITY GERMANY GMBH
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024563204
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-25
Filing Date
2023-05-23
Publication Date
2025-05-30
Estimated Expiration
2043-05-23

AI Technical Summary

Technical Problem

Existing solutions for profile download in eUICCs face challenges in efficiently reusing profile numbers, leading to locked ICCIDs and increased costs due to the need for multiple IMSIs and ICCIDs.

Method used

A method that allows for the reuse of linked profile numbers by releasing them when certain criteria are met, generating a new network access certificate to ensure security and confidentiality, and including the profile package with the released ICCID for download to the eUICC.

Benefits of technology

This solution enables flexible and efficient reuse of profile numbers, reducing costs and maintaining security through the generation of new network access certificates, thereby ensuring secure and confidential profile downloads.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025516479000001_ABST
    Figure 2025516479000001_ABST
Patent Text Reader

Abstract

A method of providing a profile package for download from a profile server (SMDP+) to an eUICC, the method comprising releasing a link ICCID and generating a new network certificate for profile download.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Field of the Invention The present invention relates to providing a profile package to a profile server for downloading the profile package from the profile server to an eUICC, and a profile download method.

Background Art

[0002] Background and Prior Art of the Invention A mobile device accommodates at least one eUICC including one or more profiles that the mobile device can authenticate itself to a mobile network so that the mobile device can establish and execute a communication session (e.g., a voice call or data transmission) in the mobile network.

[0003] The document [1][SGP.22 V2.2.2] from the prior art, GSMA SGP.22 - SGP.22 RSP Technical Specification, Version 2.2.2, 05 June 2020 (2020 - 06 - 05) relates to remote SIM provisioning for downloading, installing, enabling, disabling, and deleting profiles on an embedded universal integrated circuit card (eUICC).

[0004] To establish and execute a communication session in a mobile network under a specific profile, the profile includes a set of identifiers such as IMSI and Ki. In addition to the identifiers, the profile includes an OTA key (OTA = Over-the-Air), also called a network certificate, which is used in conjunction with the communication between the eUICC and the OTA platform. The OTA platform is understood as an operator platform for the remote management of the eUICC and the content of the available operator profiles on the eUICC. Here, the operator is understood as a mobile network operator (MNO), or a mobile virtual network operator (MVNO), or generally a company that provides wireless cellular network services.

[0005] Reference [2][PP], SIM Alliance, eUICC Profile Package: Interoperable Format Technical Specification, Version 2.3, October 2019 defines the content and format of the elements of the profile package used to download the profile to the eUICC. The profile includes content in the form of profile elements (PE). Appendix A of [2] shows a template profile package indicating the essential elements of the profile package. According to [2] 9.2, the profile package includes the profile number "Integrated Circuit Card Identifier" (ICCID). According to [2] 9.5, the USIM profile package for GSM types 4G and below includes a basic file (EF) containing the International Mobile Subscriber Identity (IMSI) and a basic file (EF) containing keys, or in the case of an ISIM or CSIM profile package, includes a similar basic file (EF). The fifth generation (5G) profile includes a Subscriber Permanent Identifier (SUPI) containing the IMSI.

[0006] Considering the mobile networks of generations up to the fourth generation (4G), the document [1][SGP.22 V2.2.2] from the prior art, GSMA SGP.22 - SGP.22 RSP Technical Specification, Version 2.2.2, 05 June 2020 (2020 - 06 - 05) discloses a standard set of profile identifiers including or consisting of the authentication key Ki and the identifier International Mobile Subscriber Identity IMSI. In the fifth generation (5G) mobile network, the set of profile identifiers includes the SUPI as an analog element to the IMSI and is used to enter and execute communication sessions in the mobile network in a secret form such as the SUCI.

[0007] The document [1][SGP.22 V2.2.2], in particular, chapter 3.1.3 “Profile Download and Installation” relates to the process of downloading a profile from a profile server (SM - DP+ in [1]) to the eUICC.

[0008] Furthermore, the document [1][SGP.22 V2.2.2], in particular, chapter 3.1.1 “Profile Download Initiation” relates to the process of instructing a profile by a connectivity service provider CSP (referred to as the operator in [1], assumed to be a mobile network operator MNO) at a profile server (referred to as SM - DP+ in [1]).

[0009] Figure 2 of this specification represents Figure 9 from [1][SGP.22 V2.2.2], chapter 3.1.1 “Profile Download Initiation”. [1][SGP.22 V2.2.2], Figure 9, and the related text in chapter 3.1.1 describe the procedure for an operator to command a profile by the profile server SM-DP+. In step (1), the operator sends a profile download command to SM-DP+ via channel ES2+ by the command ES2+.DownloadProfile (EID, profile type or ICCID). The profile download command indicates the EID of the target eUICC (EID = identifier of the eUICC hardware), and the profile type or a different profile number ICCID. According to the description of step (1) in [1], 3.1.1.2, when an ICCID is given, SM-DP+ SHALL verify that this ICCID is available. When the operator commands a profile and gives a different ICCID in the profile download command, SM-DP+ notices that an ICCID has been assigned to a profile already downloaded to a certain eUICC. Next, SM-DP+ considers the ICCID unavailable and does not execute the profile download command without further measures. The measures to be taken are not further specified in the SGP.22 standard [1][SGP.22 V2.2.2].

[0010] At least a solution known in the country to release the ICCID of a profile already downloaded so as to form an available ICCID is to delete the profile from the download location in the eUICC and give a profile deletion notice from the eUICC to the SM-DP+. When receiving the profile deletion notice, the SM-DP+ releases the ICCID to be available, and a profile download command referring to the ICCID is approved (on the condition that there are no other restrictions), and the profile can be downloaded to the target eUICC indicated in the profile download command. The target eUICC can be the same or different eUICC compared to the eUICC that deleted the profile.

[0011] Another known solution to avoid the linked (locked) ICCID is to order a new profile that includes a new identifier IMSI and to which a new profile number ICCID is assigned. Each IMSI and ICCID of the profiles that are ready to be used in the mobile network needs to be registered in the home location register HLR of the MNO that houses the profiles. The MNO bills for each IMSI and ICCID registered in the HLR. Therefore, it becomes expensive to have a large number of IMSIs and ICCIDs registered in the MNO's HLR.

[0012] Even if some IMSI or ICCID or IMSI / ICCID pairs are no longer used, some IMSI or ICCID or IMSI / ICCID pairs in the field are linked (locked). For example, the user may stop using an old device (e.g., put the device away) that includes an eUICC housed in the device, and not take further measures regarding the device / eUICC, and in particular, may not delete any profiles from the eUICC. In this situation, the IMSI or ICCID or IMSI / ICCID pair of the profiles on the eUICC may continue to be linked (locked) indefinitely in the worst case.

[0013] In another use case, a profile user who owns several mobile devices may want to use a copy of the user's profile on several of the user's devices without having to delete the profile on any of the devices and without having to use several IMSIs and / or ICCIDs. However, currently, if the user wants to download the same profile a second time, the same profile certificate for network access is used, and the second profile download is only possible if the profile server receives a profile deletion notification for the profile that has already been downloaded. Summary of the Invention Problems to be Solved by the Invention

[0014] Object of the Invention An object of the present invention is to provide a flexible, efficient, and secure profile download solution that can use or reuse a link (lock) profile number (e.g., ICCID).

[0015] Summary of the Invention More specifically, the object of the present invention is achieved by a method having the following features described in claim 1. Embodiments of the present invention are presented in the dependent claims. Means for Solving the Problems

[0016] A method of providing a profile package for download from a profile server to an eUICC accommodated in a mobile device, the profile server a) receiving, from a connectivity service provider server, a profile download instruction including a profile type or a profile number; b) generating a profile package including a profile certificate and a profile number assigned in consideration of the received profile type or the received profile number; c) providing a generated profile package for download to the eUICC; A method comprising:

[0017] The method comprises: a1) identifying a received or assigned profile number as being linked to a profile already downloaded to the eUICC; a2) receiving, from a connectivity service provider server, a notification that the linked profile number is acceptable for release, the acceptability for release being to meet release criteria, where preferably the connectivity service provider server last verifies the release criteria and, as a result of the verification, notifies the profile server that the profile number is acceptable for release; a3) the profile server releasing the linked profile number; a4) the profile server generating a network access certificate to be used for downloading the generated profile package to the eUICC. Characterized in that.

[0018] By the method thus achieved, when the linked profile number meets the release criteria, the linked profile number can be reused for a new profile download. The linked profile number is the profile number occupied since downloading a profile to a certain eUICC using this profile number. Due to the generation of a (new) network certificate, the eUICC and the background infrastructure that used the same profile number in the past for downloading a profile to the eUICC cannot access the new profile download process. Thus, despite using the same profile number, due to the (new) generated network certificate, the confidentiality and security of the profile download are guaranteed. Optionally, the profile number is released on the fly, so the method is particularly flexible and efficient.

[0019] The release criteria can include one or more of the following: (1) The profile number has not been used in any authentication request received from a connectivity service provider server by any mobile device or eUICC for a predetermined period of time (the time can be, for example, one year as a non-limiting example). In this case, the release of the profile number implicitly means stopping the use of the profile number for the profile linked before the release. Therefore, the release exchanges the profile number from the old profile to the new profile and assigns the same number (e.g., one) of profiles to the profile number before and after the release of the profile number. (2) The profile number is intended to be used for two or more copies of the same profile that are intended to be kept available for parallel use on two or more different mobile devices and / or two or more different eUICCs. In this case, the released profile number can continue to be used for the profile to which the profile number was linked before the release. Therefore, the release of the profile number will add additional profiles to the same profile number.

[0020] The network access certificate can include one or more of - the OTA key, - the NAA parameter, - the AKA parameter for the authentication algorithm such as MILENAGE or TUAK or the one that can claim ownership. The network access certificate is designed to enable the secure and confidential profile download from the profile server to the eUICC via the network.

[0021] Preferably, the network access certificate is different from the network access certificate generated for the profile already downloaded to the eUICC.

[0022] The connectivity service provider is - a mobile network provider (e.g., MNO), - A mobile virtual network provider (e.g., MVNO) may be one or more of them.

[0023] Step a2) is a2-1) A sub-step of sending a download instruction response to the connectivity service provider server, which notifies the connectivity service provider server of the link profile number and requests the connectivity service provider server to release the link profile number; a2-2) A sub-step of receiving a confirmation instruction from the connectivity service provider server that it is acceptable for the link profile number to be released; a2-3) A sub-step of releasing the link profile number at the profile server may be included.

[0024] The profile already downloaded to the eUICC may include a profile identifier (e.g., IMSI), and the profile package in step b) may include the same profile identifier (e.g., IMSI) as the profile already downloaded to the eUICC. This embodiment of the present invention can also reuse the profile number (e.g., ICCID) and the profile identifier (e.g., IMSI), which is particularly useful when downloading the same profile to a further device of the same user. In other use cases, for example, when an expired profile number (ICCID) should be reused, the new profile identifier for use (e.g., IMSI) is usually different from the profile identifier for the previous use (e.g., IMSI).

[0025] The profile download instruction in step a) may further include the eUICC hardware identifier (e.g., EID) of the eUICC to which the profile package should be downloaded.

[0026] A method for downloading a profile to an eUICC is - The step of providing a profile package to a profile server by the above method; - The step of downloading the provided profile package from the profile server to the eUICC using the generated network access certificate; and

[0027] Preferably, the generated network access certificate has not been previously used for profile download.

[0028] The profile server according to the present invention is implemented to execute the above method.

[0029] Brief Description of the Drawings Now, embodiments of the present invention will be described with reference to the following attached drawings, and through the drawings, the same components will be referred to with the same reference numerals.

Brief Description of the Drawings

[0030]

Figure 1

Figure 2

Modes for Carrying Out the Invention

[0031] Detailed Description of the Invention Figure 1 shows a diagram showing profile commands and transmissions from a profile server SMDP+ to an eUICC housed in an esim device for releasing a link profile number ICCID according to an embodiment of the present invention.

[0032] The connectivity service provider server CSP sends a download instruction for the profile to the profile server SMDP+ over the channel ES2+. The download instruction includes the profile type of the eUICC for which the profile package should be downloaded, and optionally the eUICC hardware identifier EID.

[0033] The profile server SMDP+ checks the profile type and assigns a profile number ICCID that conforms to the profile type to the download instruction. Further, the profile server SMDP+ identifies that the assigned profile number ICCID is not free and is already linked to a profile resident in the eUICC.

[0034] The profile server SMDP+ sends a notification on the channel ES2+ to the connectivity service provider server CSP that the assigned profile number ICCID is linked to a profile resident in the eUICC.

[0035] The connectivity service provider server CSP checks the ICCID, determines that the ICCID is free for release according to the release criteria, and sends a notification on the channel ES2+ to the profile server SMDP+ that the assigned profile number ICCID is acceptable for release.

[0036] In response to receiving from the connectivity service provider server CSP a notification that the assigned profile number ICCID is acceptable for release, the profile server SMDP+ releases the profile number ICCID. Further, the profile server SMDP+ generates a network certificate. The generated network certificate is usually different from the network certificate generated when previously connecting to the downloaded profile and using the ICCID, for example, due to the use of random number generation during the generation of the network certificate. However, it is important to reuse the network certificate that already exists and was previously used for profile download, but a new network certificate is generated.

[0037] The profile server SMDP+ generates a profile certificate.

[0038] Authenticate between the profile server SMDP+ and the esim device via the channel ES9+. Notify the connectivity service provider via the channel ES2+.

[0039] The profile server SMDP+ generates a profile package. The profile package includes the ICCID, the profile structure, and the generated profile certificate. The profile server generates a combined profile package from the profile package.

[0040] SMDP+ uses the newly generated network certificate and downloads the combined profile package to the eUICC housed in the esim device via the channel ES8+.

[0041] Cited prior art documents [1] [SGP.22 V2.2.2] GSMA SGP.22 - SGP.22 RSP Technical Specification, Version 2.2.2, 05 June 2020 (2020-06-05) [2] [PP], SIM Alliance, eUICC Profile Package: Interoperable Format Technical Specification, Version 2.3, October 2019

Claims

1. A method of providing a profile package for download from a profile server (SMDP+) to an eUICC housed in a mobile device, the profile server (SMDP+) comprising: a) receiving, from a connectivity service provider server (CSP), a profile download instruction including a profile type or a profile number (ICCID); b) generating a profile package including a profile certificate and a profile number (ICCID) assigned in consideration of the received profile type or the received profile number (ICCID); c) providing the generated profile package for download to the eUICC comprising: a1) identifying the received or assigned profile number (ICCID) as being linked to a profile already downloaded to the eUICC; a2) receiving, from the connectivity service provider server (CSP), a notification that the linked profile number (ICCID) is acceptable for release, the acceptability for release being for meeting a release criterion; a3) releasing the linked profile number (ICCID); a4) generating a network access certificate to be used for downloading the generated profile package to the eUICC characterized by the method.

2. The release criterion is: - the profile number (ICCID) has not been used in any authentication request received by the connectivity service provider server (CSP) from any mobile device or eUICC for a predetermined period of time or more; - the profile number (ICCID) is to be used for two or more copies of the same profile that are to be kept available in parallel on two or more different mobile devices and / or two or more different eUICCs The method according to claim 1, comprising one or more of the above.

3. The network access certificate is: - an OTA key; - an NAA parameter; - an AKA parameter for MILEAGE or TUAK or an authentication algorithm capable of asserting ownership The method according to claim 1 or 2, comprising one or more of the above.

4. The method according to any one of claims 1 to 3, wherein the network access certificate is different from the network access certificate generated for the profile already downloaded to the eUICC.

5. The connectivity service provider is - a mobile network operator (MNO), - a mobile virtual network operator (MVNO) The method according to any one of claims 1 to 4, which is one or more of.

6. Step a2) is a2-1) Notify the connectivity service provider server (CSP) of the link profile number (ICCID), and send a download instruction response to the connectivity service provider server (CSP) requesting the connectivity service provider server (CSP) to release the link profile number (ICCID). A sub-step, a2-2) A sub-step of receiving a confirmation instruction from the connectivity service provider server (CSP) that it is acceptable for the link profile number (ICCID) to be released, a2-3) A sub-step of releasing the link profile number (ICCID) on the profile server (SMDP+). The method according to any one of claims 1 to 5, including.

7. The profile already downloaded to the eUICC includes a profile identifier (IMSI), and the profile package in step b) includes the same profile identifier (IMSI) as the profile already downloaded to the eUICC. The method according to any one of claims 1 to 6.

8. The profile download instruction in step a) further includes the eUICC hardware identifier (EID) of the eUICC to which the profile package should be downloaded. The method according to any one of claims 1 to 7.

9. A method for downloading a profile to an eUICC, - Providing a profile package to a profile server (SMDP+) by the method according to any one of claims 1 to 8, - Downloading the provided profile package from the profile server (SMDP+) to the eUICC using the generated network access certificate. A method including.

10. The generated network access certificate has not been used for profile download, in particular, has not been used for profile download before the download of claim 9, the method according to any one of claims 1 to 9.

11. A profile server (SMDP+) implemented to execute the method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Methods and entities for terminating subscriptions

    JP2019519174A

  • Method for establishing a bidirectional communication channel between a server and a secure element - Patents.com

    JP2020511097A

  • Information processing device, information processing program, and information processing method

    JP2021158551A

  • Method and apparatus for transmitting and receiving profile in communication system

    US20190020997A1

  • Methods and devices for resolving conflicts between identifiers for communication devices

    US20190215684A1