Method and corresponding server for sending data to a user device that collaborates with a secure element
The method addresses the challenge of securely transmitting data for 5G SUCI encryption and initial connection by using a standard protocol to send necessary data via AUSF/UDM, enhancing security and compatibility in 5G stand-alone networks.
Patent Information
- Application Number
- JP2024571352
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-06-21
- Filing Date
- 2023-06-20
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2043-06-20
AI Technical Summary
In a 5G stand-alone network, existing methods for establishing initial connections with non-removable secure elements like eUICC face challenges such as the inability to securely send necessary data for SUCI encryption, Ki calculation, and profile download instructions, leading to potential rejections by mobile network operators.
Utilizing a standard protocol to send additional data, such as SUCI encryption information, Ki, and activation codes, via a signaling message between the secure element and a server acting as AUSF/UDM, leveraging the 3GPP TS 33.501 V17.5.0 protocol for user equipment steering during registration.
Enhances security and compatibility by enabling secure transmission of essential data for 5G SUCI encryption and initial connection, reducing the need for storing secrets in the eUICC and improving overall network compatibility.
Smart Images

Figure 2025522344000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to telecommunications in a cellular network and, more specifically, to the transmission of data to a secure element, preferably a non-removable secure element such as an integrated UICC (iUICC) or an embedded UICC (eUICC).
Background Art
[0002] Secure elements can be embodied in various form factors such as smart cards, UICCs, embedded UICCs, or integrated UICCs.
[0003] Conventional smart card form factors are generally physically removable (from a card reader) and are, for example, in the form of a SIM card.
[0004] An embedded UICC is a non-removable secure element soldered onto an electronic board configured within such a terminal.
[0005] An integrated UICC is a non-removable secure element having the particularity of being combined within a system-on-chip (SoC).
[0006] The present invention proposes an enhanced initial mobile connection in a 5G network, particularly in a 5G stand-alone network.
[0007] From EP-3 358 867 A1 and EP-3 358 868 A1, which are incorporated herein by reference, a method for managing communication between a server and a user equipment is known. This method relates in particular to the establishment of a communication channel between a server and a user equipment that does not have complete telecommunications credentials.
[0008] In order to securely connect to a telecommunications network, a user device needs to be supplied with complete telecommunications credentials (profiles) including an IMSI / Ki pair, where the IMSI is a unique identifier of a telecommunications subscription and the Ki is a secret key uniquely assigned to the subscription by a mobile network operator.
[0009] The IMSI / Ki pair is typically stored within a tamper-resistant element (also called a secure element), which can be a SIM card, a Universal Integrated Circuit Card (UICC), an embedded secure element (e.g., eUICC), a software secure enclave within a System-on-Chip (SOC) or an integrated secure element (i.e., iUICC).
[0010] A tamper-resistant element is considered secure because it can control access to the data it contains and authorize or not authorize the use of this data by other machines or entities. A tamper-resistant element can also provide computing services based on cryptographic components (also known as cryptographic processors). Generally, a tamper-resistant element has limited computing resources and limited memory.
[0011] Due to the manufacturing process, a user device (and its tamper-resistant element) can be issued without an IMSI / Ki pair.
[0012] It is necessary to securely establish such a communication session between such a user device and a server, which is intended to enable the user device to obtain in particular an IMSI / Ki pair.
[0013] The above patent application describes a solution to this problem.
[0014] More precisely, the first one (EP-3 358 867 A1) describes a method of communication between a server and a user equipment through a set of command / response pairs. The user equipment uses the IMSI field of the Attach Request frame as defined by ETSI TS 124.008 to convey one of these commands to the server. The server uses the Authentication parameter RAND field or the Authentication parameter AUTN field of the Authentication Request frame as defined by ETSI TS 124.008 to convey the response corresponding to the received command. The server sends an Authentication Request frame in response to the Attach Request frame.
[0015] Figure 1 represents such a process completed by steps enabling the attachment of a user equipment to the network of an MNO (Mobile Network Operator).
[0016] In this figure, three entities are represented: the user equipment 10 collaborating with a secure element, the server 11 acting as an HLR / HSS, and the SM-DP+ 12 (Subscription Manager Data Preparation).
[0017] The workflow is as follows: In the first step (Step #1), the user equipment (or more precisely, the secure element) selects an ephemeral IMSI, which is called an e-IMSI and is configured within a certain range of e-IMSIs. The MCC / MNC (Mobile Country Code / Mobile Network Code) of the e-IMSI corresponds to the MCC / MNC of Server 11. The MSIN part of the e-IMSI preferably takes the EID of the eUICC as a law to avoid collisions between different devices that may use the same e-IMSI.
[0018] The EID (eUICC identifier) is included in the barcode printed on the box containing the user equipment and is scanned by the vendor of the user equipment. Thanks to the e-IMSI, the EID is sent to the ephemeral MNO (e-MNO) network 13 within the AUTS message (Attach Request frame). The e-MNO network 13 is usually a 3G, 4G, or 5G NSA network (NSA represents a non-standalone 4G network operating with a 5G radio part). The authentication algorithm can be, for example, Milenage. The e-MNO 13 network is connected to Server 11, and Server 11 returns a temporary IMSI (t-IMSI), an oPC key (operator key), and a PLMN (Private Land Mobile Network) list within the RAND or AUTN message. The t-IMSI is selected by Server 11 from the perspective of the EID, business rules (and the location of the user equipment 10).
[0019] In the second step (Step #2), the user equipment 10 connects to the network of the temporary MNO, t-MNO 14, which is connected to SM-DP+ 12, using the received t-IMSI. SM-DP+ 12 then downloads the complete profile to the secure element of the user equipment 10.
[0020] In the third step (Step #3), thanks to the profile downloaded during Step #2, the user equipment 10 can connect to the network of the operational MNO 15.
[0021] In Step 1, the eUICC attaches to the server 13 by means of the e-IMSI only for authentication purposes, i.e., to execute the Milenage algorithm. There is no phase such as location update, actual attachment to the server 11, data connection, possibility of sending SMS, or subscription at this stage.
[0022] Also during Step 1, the PLMN list sent depends on the location of the user equipment. This list is defined according to the roaming contract for using the preferred MNO.
[0023] In Step 2, the secure element executes an IMSI switch to replace the e-IMSI with the t-IMSI, and Refresh is executed to use the t-IMSI instead of the e-IMSI.
Prior Art Documents
Patent Documents
[0024]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0025] The problem with this solution is that within the scope of a 5G SA network (SA represents stand-alone access), during Step 1, it is desired to send more data to the eUICC, for example, as follows (non-exhaustive list):
[0026] - Enable 5G SUCI encryption: In a 5G SA network, for the initial connection in step 1, only unencrypted SUCI (null scheme) can be used. However, some MNPs may reject the use of unencrypted SUCI. One objective of the present invention is to enable the upload of data necessary for SUCI encryption (such as the home network public key);
[0027] - Send the Ki that will be used for the initial connection. Currently, Ki is calculated by using the secret within the eUICC and only OPc is sent. By sending Ki together with oPC, the need to store this secret in the eUICC is removed, and the overall security of the solution is improved.
[0028] - Send an "activation code" to the eUICC indicating to the SM-DP+ 12 where to download the profile.
Means for Solving the Problem
[0029] This problem is solved by using a standard protocol to send these auxiliary data from the server 11 to the eUICC.
[0030] More precisely, the present invention proposes a method for sending data to a user device that collaborates with a secure element. The method includes exchanging information in a signaling message between the secure element and a server acting as an AUSF / UDM to send a temporary IMSI to the secure element, and for sending data from the server to the secure element, "3rd Generation Partnership Project, Technical Specification Group Services and System Aspects, Security Architecture and Procedures for the 5G System (Release 17) (3 rdIt is intended to use the procedure for steering of user equipment within the VPLMN during registration as specified by 3GPP TS 33.501 V17.5.0 (2022-03) entitled "Generation Partnership Project, Technical Specification Group Services and System Aspects, Security architecture and procedures for 5G system (Release 17))".
[0031] Preferably, the data is: - Information enabling the calculation of a 5G SUCI, or - Ki that will be used for the initial connection, or - An "activation code" indicating to the SM-DP+ where to download the profile is.
[0032] The present invention also relates to a server acting as an AUSF / UDM, the server being configured to send a temporary IMSI to a user equipment that cooperates with a security element, the server also sending some data to the security element, and for sending data from the server to the security element, using the procedure for steering of user equipment within the VPLMN during registration as specified by 3GPP TS 33.501 V17.5.0 (2022-03) entitled "Generation Partnership Project, Technical Specification Group Services and System Aspects, Security architecture and procedures for 5G system (Release 17)".
[0033] The present invention will be better understood by reading the following description of the preferred method according to the present invention in relation to the figures showing the following.
Brief Description of the Drawings
[0034]
Figure 1
Figure 2
Figure 3
Embodiment for Carrying Out the Invention
[0035] Figure 1 is described from the perspective of the state of the art.
[0036] Figure 2 represents a preferred solution according to the present invention.
[0037] In Figure 2, the same entities as in Figure 1 are represented. The difference here is that the e-MNO network is a 5G SA network.
[0038] The first exchange in step 20 is the same as step 1 in Figure 1 (the allocation of t-IMSI to the eUICC configured within the user equipment 10 by the server 11). More precisely, the eUICC attaches to the network 13 using an ephemeral IMSI. The client 10 and the server 11 exchange data thanks to specific values of RAND, AUTN, and AUTS of the Milenage authentication algorithm. These steps are described in EP-3 358 867 A1 and EP-3 358 868 A1.
[0039] Here, since the protocol operates in 5G, the server 11 acts as an AUSF / UDM (AUSF / UDM corresponds to the HSS of a 4G network).
[0040] This corresponds to steps 1 and 2 of Figure 3, which represent the procedures for steering a UE within a VPLMN during registration, as defined by 3GPP TS 33.501 V17.5.0 (2022-03) entitled "Security Architecture and Procedures for 5G System (Release 17), 3rd Generation Partnership Project, Technical Specification Group Services and System Aspects". More precisely, this corresponds to Figure 6.14.2.1-1 of this technical specification.
[0041] However, at step 20 of Figure 2, server 11 encodes the additional data that will be sent to the eUICC.
[0042] This corresponds to steps 3 to 15 of Figure 3. In this Figure 3, the steering list is sent from server 11 to the eUICC within a secured packet. However, within the scope of the present invention, instead of sending the steering list, server 11 sends other data to the eUICC within this secured packet. These other data are, for example, as follows:
[0043] - Information enabling the calculation of a 5G SUCI (such as a key for SUCI encryption, e.g., a home network key): Without the present invention, only the non-encrypted SUCI (i.e., the SUPI) can be used for the initial connection. However, as already stated, some MNOS may reject the use of non-encrypted SUCI. According to the proposed solution, it is possible to upload the data necessary for SUCI encryption (such as the home network public key).
[0044] - Send the Ki that will be used for the initial connection. Currently, Ki is calculated by using a secret within the eUICC and only OPc is sent. By sending Ki together with oPC, the need to store this secret in the eUICC is removed, improving the overall security of the solution.
[0045] - Send the "Activation Code" indicating where to download the profile to SM-DP+ 12.
[0046] After sending this data to the eUICC, the eUICC is registered with the server 11 and the attachment is dropped.
[0047] Therefore, the attachment procedure depends on the 3GPP standard attachment flow, but uses specific semantics to exchange specific data of limited size.
[0048] Steps 21 and 22 are the same as steps 2 and 3 in Figure 1.
[0049] The present invention takes advantage of the benefits of the 5G attachment procedure defined in the aforementioned technical specifications, which include an optional roaming steering (SoR) phase immediately after authentication, during which the home network AUSF / UDM can send a secured packet containing a PLMN list to the device, which in turn transparently provides it to the eUICC.
[0050] The present invention thus lies in leveraging the SoR procedure to send additional data: the server 11 acting as the AUSF / UDM can send a secured packet containing these data to the client of the eUICC instead of the PLMN list, and the client can interpret and process its specific data.
[0051] Figure 3 represents the "Procedure for Steering of UE within the VPLMN during Registration" as defined by 3GPP TS 33.501 V17.5.0 (2022-03), Figure 6.14.2.1-1, named "3rd Generation Partnership Project, Technical Specification Group Services and System Aspects, Security Architecture and Procedures for 5G Systems (Release 17)", and the following elements are shown:
[0052] 10 is a user equipment that collaborates with a secure element, 13 is a visited PLMN (VPLMN), and 11 is a server acting as an AUSF / UDM.
[0053] Since these elements constitute the state of the art, they will not be further described.
[0054] The present invention also lies in a server 11 acting as an AUSF / UDM, the server being configured to send a temporary IMSI to a secure element that collaborates with the user equipment, the server also sending some data to the secure element, and for sending data from the server to the secure element, using procedures for steering the user equipment within the VPLMN during registration as defined by 3GPP TS 33.501 V17.5.0 (2022-03) entitled "3rd Generation Partnership Project, Technical Specification Group Services and System Aspects, Security Architecture and Procedures for 5G Systems (Release 17)".
[0055] As already stated, these data are: - information enabling the calculation of a 5G SUCI, or - a Ki that will be used for the initial connection, or - an "activation code" indicating to the SM-DP+ where to download the profile. That is.
Claims
1. A method for sending data to a user equipment (10) that collaborates with a secure element, the method comprising: - Exchanging information in a signaling message between the secure element and a server (11) acting as an AUSF / UDM to send a temporary IMSI to the secure element, and using procedures for steering the user equipment within the VPLMN during registration, as defined by 3GPP TS 33.501 V17.5.0 (2022-03) entitled "3rd Generation Partnership Project, Technical Specification Group Services and System Aspects, Security Architecture and Procedures for 5G Systems (Release 17)", to send the data from the server (11) to the secure element.
2. The method according to claim 1, wherein the data is - information enabling the calculation of a 5G SUCI, or - Ki to be used for an initial connection, or - an "activation code" indicating to the SM-DP+ where to download a profile.
3. The method according to claim 1 or 2, wherein the secure element is an eUICC.
4. A server (11) acting as an AUSF / UDM, the server being configured to send a temporary IMSI to a user equipment (10) that collaborates with a secure element, the server (11) also sending some data to the secure element and using procedures for steering the user equipment within the VPLMN during registration, as defined by 3GPP TS 33.501 V17.5.0 (2022-03) entitled "3rd Generation Partnership Project, Technical Specification Group Services and System Aspects, Security Architecture and Procedures for 5G Systems (Release 17)", to send the data from the server to the secure element.
5. The server (11) according to claim 4, wherein the data is - information enabling the calculation of a 5G SUCI, or - Ki to be used for an initial connection, or - an "activation code" indicating to the SM-DP+ where to download a profile.
Citation Information
Patent Citations
Method for establishing a bidirectional communication channel between a server and a secure element, corresponding servers and secure element
EP3358868A1
Method for managing communication between a server and a user equipment
EP3358867A1