Method for managing service profile of secure element
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-05-11
- Publication Date
- 2026-04-02
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the management of service profiles in a secure element of a host terminal.
Background Art
[0002] A secure element, SE, is a hardware component or platform (typically a chip or a chip card) with tamper resistance that is used in a host terminal (typically a mobile terminal) and can securely host applications and data in accordance with security rules and requirements set by a trusted authority.
[0003] One form factor of SE that is becoming more prevalent is the embedded secure element, eSE. This embedded secure element is generally soldered to the host terminal. One more recent form factor is the integrated secure element, iSE. Thus, the secure element forms an integral part of the main processor (e.g., as a secure core added to another core of the processor).
[0004] The secure element is programmed according to a desired application.
[0005] For example, eSE or iSE can form a secure element required for various applications or services based on NFC (Near Field Communication) communication implemented by a host mobile terminal. For example, in the NFC payment service, the user's confidential bank information is required, which is preferably stored in the eSE protected from any unwanted access. This also applies to public transportation services, where it is possible to identify the user at the entrance gate by the eSE.
[0006] Another example of a secure element is an embedded UICC (Universal Integrated Circuit Card), which provides subscriber qualification information for authenticating itself, in particular, on one or more mobile phone networks via various operators. For example, this is configured as a SIM (Subscriber Identification Module) card. Subsequently, reference is made to eUICC (abbreviation of embedded UICC) or iUICC (abbreviation of integrated UICC). The main specifications of the eUICC card are defined by the GSMA (Global System for Mobile Communications Association) group in the GSMA standard SGP.02v3.2 named "Remote Provisioning Architecture for Embedded UICC-Technical Specification-Version3.2" dated June 27, 2017.
[0007] The main advantage of these secure elements is to provide multiple services using the same secure element. Therefore, multiple service providers must load data and / or applications onto the same secure element so that users can access each service. These data and / or applications specific to a user's service provider form a service profile (hereinafter also simply referred to as a "profile"), which is stored within the secure element. In particular, a profile associated with a mobile operator (service provider) in the sense of the GSMA RSP technical specification version 2.2 dated September 1, 2017 (hereinafter GSMA SGP.22), containing information about the user and enabling them to access the mobile operator's mobile phone services, is known. A configuration associated with a public authority (service provider) in the sense of the Global Platform Card Specification standard (version 2.3 in October 2015), containing information about the user and enabling them to access the respective services of the said authority, is also known.
[0008] According to GSMA specifications, these profiles are managed by an entity called LPA (Local Profile Administration). LPA is within the operating system of the host terminal or the secure element of the host terminal, and forms an interface between the data secure element of a profile management operator (e.g., SM-DP+, Subscription Manager Data Preparation +, Subscription Management Server) on the communication network and that entity. Thereby, the user of the host terminal can, for example, install a new profile in the secure element or enable, disable, or delete a profile already installed in the secure element.
[0009] In recent years, with the development of the Internet of Things (IoT) representing hundreds of thousands or even millions of connected devices, including secure elements storing profiles associated with new services, it has become necessary to consider solutions for effective remote management of such profiles.
[0010] In particular, the system according to FIG. 1 has been proposed, and the function for remote management of service profiles is implemented by a device CLPA within the communication network outside the host terminal. i It is implemented by.
[0011] More precisely, FIG. 1 shows a host terminal 101 including a secure element 102, e.g., eUICC, and a communication agent 103. The host terminal 101 can be, for example, a mobile phone, a device incorporated in an automobile and remotely managed by the information system of the automobile manufacturer, or any other type of connected object. The secure element 102 typically stores one or more profiles. The communication agent 103 is within the operating system of the host terminal 101 or the secure element 102 of the host terminal 101, and as detailed below, between the secure element 102 and various external profile management devices CLPA. iForm an interface with 105a, 105b, and 105c.
[0012] The system of FIG. 1 also includes an SM-DP+ (Subscription Manager Data Preparation) server 104 of a mobile network, which stores or receives a plurality of profiles to be sent to the secure element 102. Various types of remote servers can be used. For example, the SM-DP+ server 104 can be used instead of two SM-DP and SM-SR servers.
[0013] The profiles stored on the secure element 102 are managed by a plurality of external profile management devices CLPA i 105a, 105b, 105c, which are remote devices (or servers) in the network rather than being within the host terminal 101. In this regard, the external profile management devices CLPA i 105a, 105b, 105c each implement a profile management function instead of the LPA entity defined in the GSMA specification SGP.22 v2.0 named "RSP Technical Specification-Version2.0" dated October 14, 2016, for the services associated with them.
[0014] The external profile management devices CLPA i Each of 105a, 105b, 105c is thus configured to communicate with the SM-DP+ server 104 on the one hand to obtain one or more commands (e.g., commands to install or delete profiles) regarding the management of the profiles of the secure element 102, and to communicate with the communication agent 103 of the host terminal 101 on the other hand to send the profile management commands thereto. The communication agent 103 is further configured to send the profile management commands to the secure element 102.
[0015] Such a system is described in detail in the French Patent Application No. 3111042.
[0016] However, considering that the number of services associated with the same secure element continues to increase, and thus the number of external profile management devices also further increases, such a system is not entirely satisfactory.
[0017] In fact, since the external profile management device communicates with the host terminal (either directly or via another management platform that manages the terminal), in order to securely access the secure element, the premise where the external profile management device is hosted needs to be authenticated by the certification authority. However, such authentication is prohibitively costly, and not all service providers necessarily desire to invest in it.
[0018] Furthermore, in this system, it is not possible to effectively manage the deployment of an external profile management device for a certain server (for example, an external profile management device that cannot be used anymore, or whose profile cannot be updated, or the external profile management device cannot be replaced, etc.). For example, for a given service, the migration to a new service provider involves changing the profile management device associated with this service. The secure element is not informed of this deployment and does not know the address of the new profile management device. Currently, no mechanism is provided to enable the switching of the external profile management device for an existing service. SUMMARY OF THE INVENTION
[0019] Therefore, it is necessary to improve the management of service profiles stored within the secure element.
[0020] A first aspect of the present invention relates to a method for managing service profiles of a secure element of a host terminal, which is implemented by a central centralized profile management device external to the host terminal. This method includes - Receiving, from a plurality of processing devices, profile data corresponding to the same service and intended for its secure element; - Storing in a memory the profile data among the received profile data, where each stored profile data is stored in association with the service; - Detecting an event that triggers an update of the service profile of the secure element for the service; - When the event is detected, transmitting to a host terminal the latest profile data among the stored profile data associated with the service; may be included.
[0021] "Profile data" is to be understood as meaning one or more data associated with a service profile for installing or updating a profile in a secure element. A "processing device" may be an external device or a server managed by a service provider and in which profile data associated with one or more services managed by the service provider is stored. Hereinafter, the processing device is also referred to as a "profile management device". An "event that triggers an update of the service profile" is to be understood as meaning any event that leads to searching for and transmitting the profile data among the profile data stored in the central centralized profile management device 206. For example, the central centralized profile management device may receive an inquiry request from a secure element ("pull mode") or may be configured to check whether profile data is available at a predetermined time and, if appropriate, transmit it to the secure element.
[0022] Advantageously, by the above method, it becomes possible to manage a case where a plurality of profile data corresponding to the same service are received from at least two different processing devices, which was impossible with the architecture of FIG. 1. Furthermore, since the central centralized management device exists as the only entity that becomes the communication partner of the host terminal, authentication problems can be eliminated.
[0023] In one or more embodiments, the transmitted profile data may be transmitted by the central centralized profile management device to the communication agent of the host terminal, and the communication agent is configured to transfer the profile data to the secure element.
[0024] In one or more embodiments, the central centralized profile management device may further receive other profile data intended for at least one other secure element, each profile data being received together with the identifier of the secure element for which it is intended, and each stored profile data is further stored in association with the identifier of the secure element for which it is intended, and the latest profile data among the stored profile data associated with the service is transmitted together with the identifier of the secure element for which it is intended.
[0025] In other words, the central centralized profile management device may be configured to manage the profiles of a plurality of secure elements that belong or do not belong to the same host terminal. In this case, each profile data received from the processing device may include the identifier of the secure element for which it is intended.
[0026] Furthermore, each stored profile data can be associated with respective version data, and the version data represents the reception time by the centralized profile management device or is the version number of the profile associated with the profile data. The transmitted profile data corresponds to the profile data having the latest version data among the stored profile data associated with the service.
[0027] In one or more embodiments, each profile data can be received together with respective service identification data, and the method - For each profile data received and stored in the memory, identify the corresponding service based on each service identification data received together with the profile data, and store the profile data in association with the identified corresponding service may further include.
[0028] For example, the service identification data among the received service identification data is - An identifier of the processing device from which the profile data was received, - The network address of the processing device from which the profile data was received, - An identifier of the service provider that manages the service associated with the received profile data, or - An identifier of the service associated with the received profile data can be.
[0029] Each profile data is thus received with information that enables it to identify the corresponding service. Therefore, when storing the profile data, it is possible to associate the data with the corresponding service.
[0030] In one or more embodiments, the method, for each received profile data associated with a service, - Identify a service provider associated with the profile data and store the profile data in association with the identified service provider. - When detecting the event, identify a current service provider associated with a secure element for the service based on a database. It further includes that the transmitted profile data is the latest profile data among the stored profile data associated with the service and the current service provider associated with the secure element for the service.
[0031] It should be understood that the "current service provider" means the provider of the service at the time when the trigger event is detected. In fact, the target service provider may have changed during the period from when at least some of the profile data is received until the trigger event is detected. In this case, the profile data transmitted to the terminal is stored in the central profile management device and is selected from among the profile data associated with the current provider of the service.
[0032] In one or more embodiments, the detection of an event that triggers an update of the service profile of a secure element - Receiving an inquiry request including identification information regarding the given service from a host terminal or a management platform for managing the host terminal may include.
[0033] Such an embodiment corresponds to the "pull" mode. The host terminal sends a request asking whether a new version of the profile associated with a given service is available for that service, and obtains it if possible. In the system of FIG. 1, when the network address of the processing device to which the inquiry request is sent changes, this request is either lost or sent to the wrong entity. In fact, nothing is provided to dynamically manage changes in network address or provider. In the present invention, this problem no longer occurs because all inquiry requests are sent to the same entity with a fixed network address.
[0034] The inquiry request may further include an identifier of the secure element.
[0035] In one or more embodiments, each of the plurality of processing devices may have its own first asymmetric key pair, each first asymmetric key pair including a private key and a public key, the public key being shared between the processing device and the central profile management device. Each received profile data may be signed with the private key of the issuing processing device. This method involves, for each received profile data, - the central profile management device checking the signature of the profile data based on the public key of the issuing processing device, - and storing the received profile data in the memory of the central profile management device only if the check is successful and may further include.
[0036] The issuing processing device is to be understood as meaning the processing device from which the profile data was then received. Such a check of the signature of the processing device can check that the profile data was actually issued by a legitimate and trustworthy entity and that they have not been tampered with between their transmission and reception. In some embodiments, the public key of the processing device can be broadcast to the central profile management device in a digital certificate.
[0037] Furthermore, the central profile management device may have a second asymmetric key pair, which includes the private key of the central profile management device and the public key of the central profile management device. The public key of the second asymmetric key pair is shared between the central profile management device and the secure element. For each stored profile data, the profile data can be signed using the private key of the central profile management device.
[0038] This signature can be added to the first signature described above. According to this embodiment, therefore, the profile data is signed twice, that is, first with the private key of the issuing processing device and second with the private key of the central profile management device. The public key of the second asymmetric key pair (and thus the public key of the central profile management) can be sent to the secure element in a second digital certificate. In this embodiment, the public key of the processing device must also be communicated to the secure element (for example, the certificate of each processing device can be sent from the central profile management device to the secure element, and this certificate can be signed using the private key of the central profile management device if necessary). Thereby, when the secure element receives the profile data, it can check that it has not been changed since it was sent by the processing device and can "trace" its path (issuing processing device - central profile management device - secure element).
[0039] Another aspect of the present invention relates to a central centralized profile management device for managing the communication profile of a secure element of a host terminal, which is a central centralized profile management device external to the host terminal. The central centralized profile management device is - receiving, from a plurality of processing devices, profile data corresponding to the same service and intended for the secure element thereof; - storing, in a memory, the profile data among the received profile data, each stored profile data being stored in association with the service; - detecting an event that triggers an update of the service profile of the secure element for the service; - transmitting, to the host terminal, the latest profile data among the stored profile data associated with the service upon detection of the event and may be configured to perform.
[0040] Another aspect of the present invention relates to a system including a host terminal having a secure element, a central centralized profile management device external to the host terminal, and a plurality of processing devices, the central centralized profile management device being - receiving, from a plurality of processing devices, profile data corresponding to the same service and intended for the secure element thereof; - storing, in a memory, the profile data among the received profile data, each stored profile data being stored in association with the service; - detecting an event that triggers an update of the service profile of the secure element for the service; - transmitting, to the host terminal, the latest profile data among the stored profile data associated with the service upon detection of the event and may be configured to perform.
[0041] The secure element may be configured to - receive profile data transmitted by a central profile management device, and - update a service profile based on the received profile data and may be configured to perform.
[0042] Furthermore, each of the plurality of processing devices may have its own first asymmetric key pair, each first asymmetric key pair including a private key and a public key, and the public key is shared between the processing device and the central profile management device. Each received profile data may be signed with the private key of the issuing processing device, and the central profile management device, for each received profile data, - checks the signature of the profile data based on the public key of the issuing processing device, and - stores the received profile data in memory only if the check is successful and may be further configured to perform.
[0043] In one or more embodiments, the central profile management device may have a second asymmetric key pair, the second asymmetric key pair including the private key of the central profile management device and the public key of the central profile management device, and the public key of the second asymmetric key pair is shared between the central profile management device and the secure element. For each stored profile data, the profile data may be signed (optionally in addition to the first signature) using the private key of the central profile management device before being transmitted to the host terminal.
[0044] The public key of each of the plurality of processing devices may be shared with the secure element, and the secure element - when receiving the signed profile data, checks the relevant signature using the public key of the processing device that issued the profile data and the public key of the central profile management device, and - Update the service profile based on the received profile data only if the check is successful and may be configured to perform.
[0045] Another aspect of the present invention relates to a computer program product that includes instructions for performing the above method when the program is executed by a processor.
[0046] Another aspect of the present invention relates to a non-transitory computer-readable medium that stores a program for causing a central centralized profile management device to perform the above method when executed by a processor of the central centralized profile management device.
[0047] At least some of the methods according to the present invention may be implemented by a computer. As a result, the present invention may take the form of an embodiment in the form of entirely hardware, an embodiment in the form of entirely software (including firmware, resident software, microcode, etc.), or an embodiment including software and hardware aspects, all of which may be referred to herein as "circuits", "modules" or "systems". The present invention may further take the form of a computer program product incorporated in any tangible expression medium having program code usable by a computer incorporated in a medium.
[0048] Considering that the present invention can be implemented in software, the present invention can be incorporated in the form of computer-readable code supplied to a programmable device on any suitable medium. Tangible or non-transitory media may include storage media such as hard drive readers, magnetic tape devices, or semiconductor memory devices. Transitory media may include signals, such as electrical, electronic, optical, acoustic, magnetic, or electromagnetic signals, such as microwave or RF (radio frequency) signals.
[0049] Other specific features and advantages of the present invention will become more clearly apparent from the following description, which is illustrated by the accompanying drawings showing some limited exemplary embodiments of the present invention.
Brief Description of the Drawings
[0050]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Modes for Carrying Out the Invention
[0051] The present invention proposes to improve the prior art architecture to incorporate an external profile management device (or server) that is configured to receive profile data from various service providers and retransmit it to a host terminal incorporating a secure element, where the profile data installs or updates profiles corresponding to various services of this secure element. In other words, the profile data is no longer directly transmitted from servers associated with various providers to the host terminal, but instead is transmitted to what is called a central centralized profile management device, which retransmits at least some of the profile data to the host terminal. As will be detailed later, such an architecture enables efficient management of situations where data corresponding to the same service is transmitted by multiple servers (e.g., with respect to a change in service provider). According to the proposed system, furthermore, the need for each provider to have a certificate for each premise where the service exists can be eliminated. In fact, since the data is transmitted from the central centralized profile management device, a certificate is only required for the premise hosting it.
[0052] FIG. 2 shows an example of a communication system including a central centralized profile management device according to one or more embodiments of the present invention.
[0053] The system shown in FIG. 2 includes a host terminal 201, which includes a secure element 202, such as an eUICC, and a communication agent (shown as DAG in FIG. 2) 203. The host terminal 201 can be, for example, a mobile phone, a device installed in a vehicle and remotely managed by the information system of the vehicle's manufacturer, or any other type of connected object. The secure element 202 typically stores one or more profiles (also referred to as "service profiles" or "subscriptions"). Each profile is associated with a given service provided by an operator called a "service provider". Each service provider is a profile management device (or server) DPA i205a, 205b, 205c (DPA stands for Remote Profile Administrator, although any other term may be used) may have, and profiles associated with this service are stored therein. For example, the profile management device DPA i 205a, 205b, 205c may store the latest version of the profile regarding the target service and, optionally, past versions of this profile (e.g., each available new version of the service profile is stored in the profile management device DPA in addition to or instead of the past versions i in 205a, 205b, 205c).
[0054] The communication agent 203 is within the operating system of the host terminal 201 or within the secure element 202 of the host terminal 201, and forms an interface between the secure element 202 and a central centralized profile management device (denoted as TS in FIG. 2) having functions to be detailed later. As an alternative, the host terminal may be managed by a remote management platform 204 (denoted as DMP for short of Device Management Platform) for managing the terminal. In this case, the communication agent 203 forms an interface between the secure element 202 and the remote management platform 204 for managing the terminal.
[0055] The system of FIG. 2 further includes a central centralized profile management device TS 206. This central centralized profile management device 206 is configured to receive data (referred to as "profile data") associated with the service profile prepared thereby from the external profile management device DPA i 205a, 205b, 205c. iThe profile data transmitted by 205a, 205b, 205c can be a complete profile (i.e., a dataset constituting the profile), for example, data for installing a new profile or updating a profile already installed in the secure element 202. For simplicity, the term "update" of a profile is used hereinafter to refer to both the installation of a new profile in the secure element 202 and the update of a profile already installed in the secure element 202.
[0056] For example, each external profile management device DPA i 205a, 205b, 205c may transmit profile data corresponding to one or more profiles for the services they perform to the central centralized profile management device 206.
[0057] In one or more embodiments, the profile data can be transmitted by the profile management device DPA i 205a, 205b, 205c to the central centralized profile management device 206 associated with the identifier of the secure element 202 they are intended for. In fact, only one secure element 202 is shown in FIG. 2, but the central centralized profile management device 206 can receive profile data for secure elements of multiple host terminals and / or multiple secure elements of the same host terminal. In this case, the central centralized profile management device 206 needs to know the service element for which the received profile data is intended.
[0058] Furthermore, in one or more embodiments, the profile data can be transmitted by the profile management device DPA i 205a, 205b, 205c to the central centralized profile management device 206 in association with service identification data. With this service identification data, the central centralized profile management device 206 can identify the service to which the received profile data corresponds. The service identification data is, for example, - The external profile management device DPA that is the source of the profile data i The identifiers of 205a, 205b, 205c, - The external profile management device DPA that is the source of the profile data i The network addresses (e.g., IP addresses) of 205a, 205b, 205c, - The external profile management device DPA that is the source of the profile data i The identifier of the service provider that manages 205a, 205b, 205c, or - The identifier of the service associated with the received profile data can be.
[0059] In the first three examples, the central centralized profile management device 206 may further have access to a table (e.g., stored in the memory of the central centralized profile management device 206) or a database that associates the identifier or address with the identifier of the service associated with the received profile data. The central centralized profile management device 206 can use this table to identify the service associated with the received data based on the received service identification data. Of course, other examples than those described above are also conceivable if the service associated with the received profile data can be identified by the service identification data.
[0060] The central centralized profile management device 206 is the profile management device DPA i When receiving profile data from 205a, 205b, 205c, it stores it in the memory in association with the service with which it is associated. In one or more embodiments, this association may be performed based on the service identifier.
[0061] For the same service, multiple profile data are from different profile management devices DPA iNote that it can be received from 205a, 205b, and 205c. Such a situation can occur, for example, when a user changes the service provider. For example, before the provider change, the first profile management device (e.g., DPA1205a) can send the first profile data associated with a given service, and after the provider change, the second profile management device (e.g., DPA2205b) can send the second profile data associated with the same service.
[0062] In one or more embodiments, each profile management device DPA i 205a, 205b, 205c has its own asymmetric key pair, and each pair is formed by a public key K CPA,pub,i and a private key K CPA,priv,i Each profile management device DPA i The public key K of 205a, 205b, 205c CPA,pub,i is shared with the central centralized profile management device 206 (i.e., the central centralized profile management device 206 knows the public key K of each profile management device DPA i 205a, 205b, 205c). In some embodiments, the public key K of the profile management device DPA CPA,pub,i 205a, 205b, 205c can be sent to the profile management device DPA i 205a, 205b, 205c in a digital certificate issued by a certification authority. The profile management device DPA CPA,pub,i 205a, 205b, 205c can then send the profile data signed with a signature generated using the private key K of the profile management device DPA i 205a, 205b, 205c to the central centralized profile management device 206. When the central centralized profile management device 206 receives the profile data, it checks the signature, which means that this data and the public key K of the profile management device DPA i 205a, 205b, 205c from which it received the profile data i The private key K of 205a, 205b, 205c CPA,priv,i The central centralized profile management device 206 can then send the profile data signed with a signature generated using the private key K of the profile management device DPA i 205a, 205b, 205c to the central centralized profile management device 206. When the central centralized profile management device 206 receives the profile data, it checks the signature, which means that this data and the public key K of the profile management device DPA CPA,pub,iBased on this, a signature is calculated, and then the two signatures are compared. If the two signatures match, this indicates that the profile data was actually sent from a "genuine" entity, and the data is stored in the memory of the centralized profile management device 206. If the two signatures do not match, the profile data is deleted and not stored in the memory of the centralized profile management device 206. This makes it possible to check the integrity and origin (traceability) of the received data.
[0063] Next, the centralized profile management device 206 may directly send one or more pieces of profile data stored in its memory to the communication agent 203 (for example, after a direct request from the agent 203 to the centralized profile management device 206), or, in a variant form, send it to the remote management platform 204 for managing the terminal (this remote management platform sends these to the communication agent 203). The communication agent 203 then transfers one or more pieces of profile data to the secure element 202, which can install or update one or more corresponding profiles. The profile data is associated with the service identification data so that the secure element can identify the profile to be updated (as described in detail above), and / or the profile data is sent from the profile management device DPA i 205a, 205b, 205c (this is particularly advantageous when the data is signed using the private key K of the source profile management device as described below, so that the secure element can check the signature using the public key K of the source profile management device) CPA,priv,i and can be sent. Alternatively or additionally, the profile data can be sent in association with the identifier of the secure element (this is particularly advantageous when the terminal includes a plurality of secure elements 202, so that the communication agent 203 sends this data to the secure element 202 including the profile involved in the update). CPA,pub,i
[0064] As described above, the central centralized profile management device 206 can store a plurality of respective profile management devices DPA i received from 205a, 205b, 205c. Therefore, the central centralized profile management device 206 may need to know which of the profile data associated with a given service should be sent to the communication agent 203 or the remote management platform 204 for managing the terminal. In one or more embodiments, the profile data transmitted for a given service is the latest profile data among the stored profile data associated with this service. For example, for each stored profile data, it is possible to record the reception date thereof by the central centralized profile management device 206 or any information representing this date, and the profile data to be transmitted is the one with the latest reception date (i.e., the profile data received last). As an alternative, each stored profile data may be recorded together with the version number of the corresponding profile, and the profile data to be transmitted corresponds to the latest version.
[0065] When the central centralized profile management device 206 manages profiles for a plurality of secure elements, the profile data may be further stored in association with the identifier of the service element for which the profile data is intended, and the profile data to be transmitted may be the latest profile among the stored profile data associated with the identifiers of this service and the secure element 202. As an alternative, the profile data may be transmitted together with the identifier of the provider of the associated service, and the central centralized profile management device 206 may have access to a table or database that associates the secure element with the list of service providers to which the user has subscribed. The profile data to be transmitted may be the latest profile data among the profile data stored for a given service and provided by the provider of this service associated with the secure element 202. According to another alternative, the memory of the central centralized profile management device 206 may be partitioned into memory areas according to service providers, and each memory area corresponds to a respective provider. When the secure element sends a request to search for an update of one of its profiles (the "pull" mode described in detail later), in response to this, it receives the profile data among the profile data stored in the memory area associated with the service provider to which the user of the host terminal 201 has subscribed. For this purpose, it is possible to use a pointer indicating the respective address of the memory area associated with the service provider to which the user of the host terminal 201 has subscribed.
[0066] In one or more embodiments, the central centralized profile management device 206 has an asymmetric key pair, and this pair is formed by the public key K TS,pub and the private key K TS,priv . The public key K TS,pub of the central centralized profile management device 206 is shared with the secure element 202. In some embodiments, the public key K TS,pubcan be sent in the digital certificate issued by the certification authority to the central centralized profile management device 206. The central centralized profile management device 206 then signs the profile data (which may have been pre-signed using the private keys K of the profile management devices DPA i 205a, 205b, 205c) with its private key K CPA,priv,i and can send the signed (optionally double-signed) data to the communication agent 203 of the management platform 204 for managing the terminal or the terminal 201. When the secure element 202 receives the profile data, it then checks the signature, i.e., it calculates the signature based on this data and the public key K of the central centralized profile management device 206 TS,priv and then compares the two signatures. If they match, the profile of the secure element is updated based on the received data. If they do not match, the profile is not updated and the received profile data is deleted. Further, if the data received by the secure element 202 is double-signed (i.e., the signature based on the private key K of the profile management devices DPA TS,pub 205a, 205b, 205c and the signature based on the private key K of the central centralized profile management device 206 i 205a, 205b, 205c), the secure element needs to also know the public key K of the profile management devices DPA CPA,priv,i 205a, 205b, 205c. In some embodiments, the public key K of the profile management devices DPA TS,priv 205a, 205, 205c can be sent by the central centralized profile management device 206 to the secure element 202 (either via the management platform 204 for managing the terminal or to the communication agent 203 of the terminal 201). Further, the public key K of the profile management devices DPA I 205a, 205b, 205c CPA,pub,i is also known. In some embodiments, the public key K of the profile management devices DPA i 205a, 205, 205c can be sent by the central centralized profile management device 206 to the secure element 202 (either via the management platform 204 for managing the terminal or to the communication agent 203 of the terminal 201). Further, the public key K of the profile management devices DPA CPA,pub,i 205a, 205b, 205c can be sent by the central centralized profile management device 206 to the secure element 202 (either via the management platform 204 for managing the terminal or to the communication agent 203 of the terminal 201). Further, the public key K of the profile management devices DPA i 205a, 205b, 205c CPA,pub,ican be sent in its digital certificate by the central centralized profile management device 206, which may, in some cases, use its private key K TS,priv to sign. If the data is doubly signed, the secure element 202 checks two signatures, namely one based on the public keys K i of the profile management devices DPA CPA,pub,i 205a, 205b, 205c of the issuer, and the other based on the public key K TS,pub of the central centralized profile management device 206. If both checks succeed, the profile of the secure element is updated based on the received data. If not, the profile is not updated and the received profile data is deleted. This double check makes it possible to check, first, that the profile data is from a "legitimate" entity and, second, that it has not been changed since it was sent to the external profile management devices DPA i 205a, 205b, 205c of the issuer.
[0067] Note that the external profile management devices DPA i 205a, 205b, 205c do not communicate directly with the host terminal 201 or the management platform 204 for managing the terminal. The profile is sent from the external profile management devices DPA i 205a, 205b, 205c to the central centralized profile management device 206, which transfers them to the host terminal 201. The host terminal 201 (or the remote management platform 204 for managing the terminal) thus receives the profile from only one entity, thereby solving the authentication problem as described above and facilitating the management of service provider changes.
[0068] In fact, the external profile management devices DPA iIt is no longer necessary to authenticate all premises where 205a, 205b, and 205c exist. It is only necessary to authenticate the premises where the central centralized profile management device 206 exists, because it is the only entity that sends data to the secure element 202.
[0069] Furthermore, according to some embodiments, the profile is obtained in "pull" mode, i.e., in response to a request from the secure element 202. In these embodiments, the secure element 202 sends an inquiry request via the communication agent 203 to check whether profile data (corresponding to a new profile or a new version of a certain profile) is available. In the system of FIG. 1, this request is sent to the external profile management device CLPA i of the service provider associated with the target profile, which is sent to 105a, 105b, and 105c. However, when the user changes the service provider or the service provider changes the external profile management device CLPA i 105a, 105b, and 105c, it may occur. In such a case, the inquiry request may not be sent to the correct external profile management device CLPA i 105a, 105b, and 105c. In fact, in the secure element 202, no mechanism is provided for dynamically managing changes in the service provider or the addresses of the servers of the service provider for a given service. In the system of FIG. 2, this problem does not occur because (as detailed with respect to FIGS. 4 and 5) the inquiry request is sent to the central centralized profile management device 206 whose network address is fixed. The provider is clearly changed for the terminal 201, and the inquiry request cannot be sent to the wrong entity.
[0070] FIG. 3 shows an example of a flowchart of a service profile management method according to one or more embodiments of the present invention. In the first step 301, the central centralized profile management device 206 receives profile data regarding a given service.
[0071] Optionally, this profile data is sent to the profile management device DPA from which the profile data was received i The private key K of 205a, 205b, 205c CPA,priv,i is used for signing. The signature is then checked using the public key K of the profile management device DPA from which the profile data was received i of 205a, 205b, 205c (step 302). If the check fails (step 302, arrow "K" in Figure 3), the data is deleted (step 303). If the check is successful (step 302, arrow "O" in Figure 3), the data is stored in the memory of the central profile management device 206, associated with the service in question (step 304). Unless an event is detected that triggers an update of the profile of the secure element associated with the service in question (step 305, arrow "N"), the central profile management device 206 continues to receive profile data regarding the service in question (step 301), optionally checks them (step 302), deletes them (step 303), or stores them in the memory (step 304). If an event is detected that triggers an update of the profile of the secure element associated with the service in question (step 305, arrow "Y"), the latest profile data of the stored profile data associated with the service in question is sent to the communication agent 203 or the remote management platform 204 for managing the terminal (step 307). Optionally, the profile data can be signed using the private key K of the central profile management device 206 before being sent in step 307, as described above CPA,pub,i TS,priv
[0072] An event that triggers an update to the profile of the secure element can be any event that causes the latest profile data to be sent by the central profile management device 206 to the communication agent 203 or the remote management platform 204 for managing the terminal. In some embodiments, this trigger event is when the central profile management device 206 receives an inquiry request (such an inquiry request particularly includes an identifier of the service in question) to check whether profile data associated with a given service, sent from the secure element 202 via the communication agent 203, is available. These embodiments correspond to the "pull mode", and several examples are shown in detail in FIGS. 4 and 5. As an alternative, this trigger event is the profile management device DPA i 205a, 205b, 205c from which the profile must be updated as soon as possible or upon receipt of data from the profile management device DPA i 205a, 205b, 205c. According to other alternatives, the trigger event corresponds to a predetermined timing (e.g., regular) at which the profile must be updated (e.g., every week or whenever the host terminal is restarted, etc.).
[0073] FIG. 4 shows the steps of a service profile management method according to one specific embodiment of the present invention.
[0074] This embodiment corresponds to the "pull" mode, in which the communication agent 203 of the host terminal 201 sends an inquiry request to the central profile management device 206 (optionally via the remote management platform 204 for managing the terminal), and in exchange is configured to search for profile data to update the profile of the secure element 202 of the host terminal 201. Further, in the embodiment of FIG. 4, it is assumed that the host terminal is managed by the remote management platform 204 for managing the terminal.
[0075] In step 401, the profile management device DPA i 205a, 205b, 205c send ( "push") the profile data to the central centralized profile management device 206 (denoted as TS in FIG. 4). As already detailed, this profile data can be signed. In this case, the signature of the profile data is checked (step 402) and can be stored in the memory of the central centralized profile management device 206 only if the check is successful. The profile data is stored in association with the corresponding service and version data (for example, the version number of the profile associated with the received profile data or the reception date of the profile data). Further, the profile data may optionally be signed a second time using the private key K of the central centralized profile management device 206 TS,priv (step 403). The signed / doubly signed profile data is then encapsulated in a packet (step 404) and stored in the central centralized profile management device 206. In one or more embodiments, the packet may further include service identification data and / or an identifier of the secure element for which it is intended. In optional step 405, the central centralized profile management device 206 sends a notification to the profile management devices DPA i 205a, 205b, 205c informing them of the result of the processing (steps 402-403) performed on the previously received profile data. In a sense, this approves the reception and storage of the received profile data.
[0076] Steps 401-405 can be repeated for a plurality of profile data received from various profile management devices DPA i 205a, 205b, 205c and various services. After several iterations of steps 401-405, the central centralized profile management device 206 may have a plurality of packets in the memory intended for the same secure element 202, at least two of which are associated with the same service and are from two different profile management devices DPAi It is emitted from 205a, 205b, and 205c.
[0077] In step 406, the communication agent 203 of the host terminal (denoted as TERM in FIG. 4) sends an inquiry request to the remote management platform 204 (denoted as DMP in FIG. 4) for managing the terminal, which is transferred to the central centralized profile management device 206 in step 407. According to these embodiments, the inquiry request may include an identifier of the secure element and / or an identifier of a service for which it is sought whether an update is available. The inquiry request may be sent, for example, periodically (e.g., weekly) or after the operation of the user of the host terminal 201.
[0078] In one or more embodiments, the inquiry request may be signed using the private key K of the secure element SE,priv and the private key K SE,priv is part of an asymmetric key pair (K SE,priv , K SE,pub ) formed with the public key K SE,priv , K SE,pub ) associated with the secure element 202. The public key K SE,pub of the secure element 202 may be shared with the central centralized profile management device 206. Upon receiving the inquiry request (step 407), the central centralized profile management device 206 uses the public key K SE,pubIt is possible to check the signature of the request in step 408. If the check ends in failure, this inquiry request is ignored. If the check is successful, the central centralized profile management device 206 transmits the latest profile data among the profile data associated with the target service stored in the central centralized profile management device 206 to the remote management platform 204 for managing the terminal (step 409). The target service can be identified, for example, based on the service identifier included in the inquiry request. As an alternative, the inquiry request does not include a service identifier, and in step 409, the central centralized profile management device 206 transmits the latest profile data associated with this service for each service for which it stores profile data. In other words, the central centralized profile management device 206 transmits a plurality of profile data, each of which is the latest profile data regarding a given service. In step 410, one or more profile data are transmitted from the remote management platform 204 for managing the terminal to the communication agent 203 of the terminal 201, which is then transferred to the secure element 202. The secure element can then update one or more profiles corresponding to the one or more received profile data, provided that one or more signatures associated with the one or more received profile data are valid.
[0079] FIG. 5 shows an alternative embodiment of the embodiment shown in FIG. 4. According to this embodiment, the host terminal is not managed by the remote management platform 204 for managing the terminal, and the communication agent 203 communicates directly with the central centralized profile management device 206.
[0080] Steps 401 to 405 and 408 are the same as those in FIG. 4. Steps 506 and 509 respectively correspond to steps 406 to 407 in FIG. 4 on one hand and 409 to 410 on the other hand. In other words, in step 506, the inquiry request is directly transmitted from the communication agent 203 of the host terminal 201 (denoted as TERM in FIG. 5) to the central centralized profile management device 206 (denoted as TS in FIG. 5), and in step 509, one or more profile data are directly transmitted from the central centralized profile management device 206 to the communication agent 203 of the host terminal 201. Similar to FIG. 4, one or more profile data received by the communication agent 203 are then transferred to the secure element 202. The secure element can then update one or more profiles corresponding to the one or more received profile data, provided that one or more signatures associated with the one or more received profile data are valid.
[0081] FIG. 6 shows an example of another central centralized profile management device for implementing a transaction according to one or more embodiments of the present invention.
[0082] In this embodiment, the device 600 includes a memory 605 (denoted as MEM in FIG. 6) for storing instructions for enabling the method to be implemented, received profile data, and temporary data for implementing various steps of the aforementioned method.
[0083] This device further includes a circuit 604 (denoted as PROC in FIG. 6). This circuit can be, for example, - a processor capable of interpreting instructions in the form of a computer program, - an electronic card in which the steps of the method of the present invention are described in silicon, or - an FPGA (Field Programmable Gate Array) chip, for example a programmable electronic chip such as a SOC (System on Chip) or other ASIC (Application Specific Integrated Circuit). It can be.
[0084] An SOC, that is, a system-on-chip, is an embedded system that integrates all components of an electronic system onto one chip. An ASIC is a dedicated electronic circuit that combines functions customized for a certain application into one. An ASIC is generally configured when these are manufactured and only simulation by the user is possible. A field-programmable gate array (FPGA) programmable logic circuit is an electronic circuit that can be reconfigured by the user.
[0085] Device 600 is a profile management device DPA i It includes at least one input interface 603 (denoted as INP in FIG. 6) for receiving profile data from 205a, 205b, 205c, and one output interface 606 (denoted as OUT in FIG. 6) for providing the profile data to the management platform 204 for managing the terminal or the communication agent 203 of the terminal 201. Finally, the central centralized device may include a screen 601 and a keyboard 602 to facilitate interaction with the user. Naturally, the keyboard is optional, especially with respect to a central centralized device in the form of, for example, a touch-screen tablet.
[0086] According to an embodiment, device 600 may include a processor operatively connected to a computer, a computer network, an electronic component or other devices including memory, and also, according to a selected embodiment, a data storage unit and other related hardware elements such as a media reader (not shown) for reading from and writing to a network interface and a removable storage medium. The removable storage medium can be, for example, a compact disc (CD), a digital video / versatile disc (DVD), a flash disk, a USB key, etc.
[0087] Depending on the embodiment, the memory, data storage unit, or removable storage medium contains instructions that, when executed by the control circuit 604, cause the control circuit 604 to execute or control the input interface 603, the output interface 606, and the data processing unit of the exemplary embodiments described herein for data storage and / or proposal within the memory 605.
[0088] The control circuit 604 can be a component that controls the units 603, 605, and 606 of the device 600.
[0089] Furthermore, the device 600 can take the form of software in the form of a program executable by a processor, or in the form of an application-specific integrated circuit (ASIC), a system-on-chip (SOC), etc., or in the form of a combination of hardware elements and software elements, for example, in the form of a software program intended to be loaded and executed on the aforementioned electronic components (e.g., FPGA, processor). The device 600 can also use a hybrid architecture, for example, an architecture based on CPU+FPGA, GPU (graphics processing unit), or MPPA (multi-purpose processor array).
[0090] Furthermore, the block diagram shown in FIG. 3 is one typical example of a program in which some instructions can be executed on the aforementioned centralized device. In this regard, FIG. 3 can correspond to a flowchart of the general algorithm of a computer program in the sense of the present invention.
[0091] Although the present invention has been described above with respect to specific embodiments, the present invention is not limited to these specific embodiments, and improvements within the scope of the present invention will be apparent to those skilled in the art.
[0092] By referring to the foregoing exemplary embodiments, which are provided only by way of example and do not limit the scope of the present invention, many other improvements and modifications will be apparent to those skilled in the art, and the scope is defined only by the appended claims. In particular, the various features of the various embodiments may be interchanged where appropriate.
Claims
1. A method for managing the service profile of a secure element of a host terminal, the method being performed by a centralized profile management device outside the host terminal, and Receiving profile data from multiple processing units that correspond to the same service and the secure element, The process involves storing the profile data from the received profile data into memory, wherein each stored profile data is stored in association with the service. Detecting an event that triggers an update of the service profile of the secure element for the said service, Upon detection of the aforementioned event, the latest profile data from among the stored profile data associated with the service is transmitted to the host terminal. A method that includes this.
2. The method according to claim 1, wherein the centralized profile management device further receives other profile data corresponding to at least one other secure element, each profile data being received together with the identifier of the secure element corresponding to the profile data, each stored profile data being further stored in association with the identifier of the secure element corresponding to the profile data, and the most recent profile data among the stored profile data associated with the service being transmitted together with the identifier of the secure element corresponding to the profile data.
3. The method according to claim 1, wherein each stored profile data is associated with a version data, the version data being the reception time by the centralized profile management device or the version number of the profile associated with the profile data, and the transmitted profile data corresponds to the profile data having the latest version data among the stored profile data associated with the service.
4. Each profile data is received along with its respective service identification data, and the method is as follows: For each profile data received and stored in memory, the corresponding service is identified based on the respective service identification data received along with the profile data, and the profile data is stored in association with the identified corresponding service. The method according to claim 1, further comprising:
5. The service identification data among the received service identification data is: The identifier of the processing device, where the profile data is received from the processing device. The network address of the processing device, where the associated profile data was received from the processing device. The identifier of the service provider that manages the service associated with the received profile data, or The method according to claim 4, wherein the identifier is a service identifier associated with the received profile data.
6. For each of the received profile data associated with the aforementioned service, Identifying the service provider associated with the profile data, and storing the profile data in association with the identified service provider. Upon detection of the aforementioned event, the current service provider associated with the secure element for the service is identified based on the database. It further includes, The method according to claim 1, wherein the transmitted profile data is the most recent profile data among the stored profile data associated with the service and the current service provider associated with the secure element for the service.
7. The detection of the event that triggers the update of the service profile of the secure element is Receiving an inquiry request containing identification information relating to a given service from the host terminal or a management platform for managing the host terminal. The method according to claim 1, including the method described in claim 1.
8. Each of the plurality of processing units has its own first asymmetric key pair, each of which includes a private key and a public key, the public key is shared between the processing unit and the centralized profile management device, each received profile data is signed with the private key of the issuing processing unit, and the method applies to each received profile data, The centralized profile management device checks the signature of the profile data based on the public key of the issuing processing device, Only if the above check is successful, the received profile data is stored in the memory of the centralized profile management device. The method according to claim 1, further comprising:
9. The method according to claim 1, wherein the centralized profile management device has a second asymmetric key pair, the second asymmetric key pair comprising a private key of the centralized profile management device and a public key of the centralized profile management device, the public key of the second asymmetric key pair is shared between the centralized profile management device and the secure element, and for each stored profile data, the profile data is signed using the private key of the centralized profile management device.
10. A centralized profile management device for managing the communication profile of a host terminal's secure element, located outside the host terminal, Receiving profile data intended for the secure element from multiple processing units that correspond to the same service, The process involves storing the profile data from the received profile data into memory, wherein each stored profile data is stored in association with the service. Detecting an event that triggers an update of the service profile of the secure element for the said service, Upon detection of the aforementioned event, the latest profile data from among the stored profile data associated with the service is transmitted to the host terminal. A centralized profile management device configured to perform the following actions.
11. A system comprising a host terminal having a secure element, a centralized profile management device external to the host terminal, and a plurality of processing devices, wherein the centralized profile management device is Receiving profile data from multiple processing units that correspond to the same service and the secure element, The process involves storing the profile data from the received profile data into memory, wherein each stored profile data is stored in association with the service. To detect an event that triggers an update of the service profile of the secure element for the said service, Upon detection of the aforementioned event, the latest profile data from the stored profile data associated with the service is transmitted to the host terminal. The secure element is configured to perform the following: Receiving the profile data transmitted by the centralized profile management device, Updating the service profile based on the received profile data and A system configured to perform the following actions.
12. Each of the plurality of processing units has its own first asymmetric key pair, each of which includes a private key and a public key, the public key is shared between the processing unit and the centralized profile management device, each received profile data is signed with the private key of the issuing processing unit, and the centralized profile management device, The signature of the profile data is checked based on the public key of the issuing processing device, Only if the above check is successful, the received profile data is saved to memory. The system according to claim 11, further configured to perform the following:
13. The system according to claim 11 or 12, wherein the centralized profile management device has a second asymmetric key pair, the second asymmetric key pair comprising a private key of the centralized profile management device and a public key of the centralized profile management device, the public key of the second asymmetric key pair being shared between the centralized profile management device and the secure element, and for each stored profile data, the profile data is signed using the private key of the centralized profile management device before being transmitted to the host terminal.
14. The public key of each of the plurality of processing units is shared with the secure element, and the secure element is Upon receiving the signed profile data, the public key of the processing device that issued the profile data and the public key of the centralized profile management device are used to check the associated signature. Only if the above check is successful, the service profile will be updated based on the received profile data. The system according to claim 12, configured to perform the following:
15. A computer program product comprising, when the program is executed by a processor, instructions for carrying out the method according to any one of claims 1 to 9.