Method for enabling traceability of USIM profile transfer from source device to target device, corresponding system and remote server - Patents.com
The method ensures traceability and prevents profile duplication in USIM transfers by deriving a new long-term key and validating through a remote server, addressing the lack of MNO involvement in existing 5G network profile transfer methods.
Patent Information
- Application Number
- JP2025530570
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-11-30
- Filing Date
- 2023-11-28
- Publication Date
- 2025-12-16
Smart Images

Figure 2025540727000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to telecommunications products and services, and in particular to a method for providing traceability of a USIM profile involved in the transfer of said USIM profile between devices.
[0002] More precisely, the present invention relates to a method and system for enabling traceability of a USIM profile transfer from a source device to a target device in 5G networks and future telecommunication networks.
[0003] The devices are typically smartphones, PDAs, mobile terminals, PCs in cooperation with a secure element that is not removable from the terminal, such as an eUICC (embedded UICC) or iUICC (integrated UICC).
[0004] The background to the present invention is that the GSMA is working on a mechanism to simplify the transfer of USIM profiles from one device to another (from source device to target device), which today can be done in a proprietary way and without the intervention of a remote server connected to the network of the home MNO (Mobile Network Operator).
[0005] A problem that remains unsolved so far is tracing profiles transferred by the home MNO.
[0006] In this respect, the present invention proposes a solution that allows the home MNO, which is not involved during the transfer of USIM profiles between the source device and the target device, to keep track of the transfer of these USIM profiles and to prevent duplication of profiles containing the same long-term key K.
[0007] The proposed solution consists in a method that allows traceability of a USIM profile transfer from a source device to a target device, said method comprising: - performing mutual trust verification of the target device by the source device and vice versa; generating, at the source device, derived data that is verifiable by a remote server connected to the source device's home network; - deriving a new long-term key K' at the source device from a source long-term key K of the source device and derivation data; generating a new USIM profile in the source device, the new USIM profile including the derived long-term key K′ and the derivation data; - confidentiality and integrity protecting the new profile based on the public key of the target device to obtain an installation package; transferring the installation package to the target device; - if the installation of the installation package in the target device is successful, deactivating the source USIM profile in the source device; - transmitting at least its IMSI and derivation data from the target device to a remote server in a registration request as specified in 3GPP TS 23.501; - retrieving, at a remote server, a source long-term key K of the source device and derivation data associated with the IMSI; - verifying the validity of the received derived data based on subscription information associated with the IMSI by a remote server; - deriving a new long-term key K* from the source long-term key K and the received derivation data; - performing authentication of the target device based on K* and the retrieved subscription data associated with the IMSI, as specified in 3GPP TS 33.501; If K* is equal to K', then updating, in the home network, its local subscriber information associated with the IMSI, including the long-term key associated with the IMSI, with the new value of K*.
[0008] The 3GPP TS 23.501 specification, for example, is for Release 15 dated December 22, 2017.
[0009] Preferably, the verification of trust of the target device by the source device consists in verifying at the source device whether the certificate of the target device is valid.
[0010] Advantageously, the derived data is: The transfer counter decremented by -1, -random number, - a cryptographic token provisioned to the source device by the home network; - the current authentication sequence number, - the identity of the source device, e.g. its eUICCID or IMEI, -Identification of the target device, for example one or more of its eUICCID or IMEI.
[0011] Preferably, in the source device, the step of deriving the new long-term key K' from the source long-term key K consists in calculating a hash of the long-term key K using the derivation data. -Derived data; a hash of the USIM profile originally received by the source device, or - one or more of a certificate or a certificate fingerprint of the USIM profile originally received by the source device.
[0012] Preferably, upon receiving the installation package from the source device, the target device: - Validate that the installation package is valid and comes from a valid source device, -Install the installation package, -Storing derived data locally.
[0013] Preferably, the step of transmitting at least its IMSI and derivation data from the target device to the home network of the source device consists in using in the registration request as specified in 3GPP TS 23.501 a specific routing ID of a remote server capable of processing such transferred USIM profile.
[0014] Preferably, the remote server: - if the derived data is a sequence number of the source device, that the received sequence number is valid with respect to the sequence number stored locally by the home network; - if the derived data is a forwarding counter, the forwarding counter is valid against a forwarding counter stored locally by the home network; - if the derived data is a cryptographic token, the cryptographic token is derived from or associated with the IMSI; If the derived data is a source device identity, verify that the source identity is equal to the source device identity associated with the IMSI.
[0015] The remote server advantageously updates the binding information in the HPLMN SM-DP+ between the USIM profile and the secure element of the target device by providing the HPLMN SM-DP+ with at least the IMSI, the new long-term key K*, the source EUID, and the destination EUID.
[0016] The present invention also relates to a system for enabling traceability of a USIM profile transfer from a source device to a target device, the system comprising a remote server, the source device comprising: -Performing mutual trust verification of the target device by the source device; generating derived data that is verifiable by a remote server connected to the source device's home network; Deriving a new long-term key K' from the source device's source long-term key K and the derivation data; generating a new USIM profile containing the derived long-term key K′ and the derivation data; Confidentiality and integrity protection of the new profile based on the public key of the target device to obtain the installation package; Transfer the installation package to the target device, configured to deactivate the source USIM profile if installation of the installation package on the target device is successful; The target device is - configured to transmit at least its IMSI and derivation data to a remote server in a registration request as specified in 3GPP TS 23.501; The remote server is Retrieving a source long-term key K of the source device and derivation data associated with the IMSI; - verifying the validity of the received derived data based on the subscription information associated with the IMSI; deriving a new long-term key K* from the source long-term key K and the received derivation data; - performing authentication of the target device based on K* and the retrieved subscription data associated with the IMSI, as specified in 3GPP TS 33.501; If K* is equal to K', then the home network is configured to update its local subscriber information associated with the IMSI, including the long-term key associated with the IMSI, with the new value of K*.
[0017] The invention also relates to a remote server that allows traceability of a USIM profile transfer from a source device to a target device, the remote server being connected to a home network of the source device; receiving from the target device in a registration request as specified in 3GPP TS 23.501 at least its IMSI, derivation data, and a new long-term key K′ generated by the source device from the derivation data of the source device's long-term key K; Retrieving a source long-term key K of the source device and derivation data associated with the IMSI; - verifying the validity of the received derived data based on the subscription information associated with the IMSI; deriving a new long-term key K* from the source long-term key K and the received derivation data; Performing authentication of the target device based on K* and the retrieved subscription data associated with the IMSI, as specified in 3GPP TS 33.501; If K* is equal to K', then the home network is configured to update its local subscriber information associated with the IMSI, including the long-term key associated with the IMSI, with the new value of K*.
[0018] The invention will be better understood from a reading of the following description of the drawings. [Brief explanation of the drawings]
[0019] [Figure 1] 1 illustrates the transfer of a USIM profile from a source device to a target device. [Figure 2]Indicates the validation by the home network of the transfer of the USIM profile from the source device (contained in a secure element cooperating with this source device, this profile including the subscription profile of this secure element to the home MNO) to the target device.
[0020] 1 illustrates the transfer of a USIM profile from a source device to a target device, where the source device is labeled 10 and the target device is labeled 11. In a first step 13, the source device 10 performs a trust verification of the target device 11, for example by verifying that the target device's 11 certificate is valid, to ensure that the target device 11 is authorized to receive the USIM profile from the source device 10.
[0021] If the target device 11 has the right to obtain the USIM profile from the source device 10 (meaning that the target device 11 has a valid certificate, has been successfully authenticated based on that certificate, and is eligible to receive the profile from the source device), the source device 10 generates derivation data.
[0022] This derived data can be, for example, - Transfer counter decremented by 1, - Random number, - a cryptographic token provisioned to the source device by the home network; - the current authentication sequence number (at the level of the source device 10 there is no such generation, but only the extraction of the sequence number, also called SQN), - the identity of the source device, for example its eUICCID (embedded UICC identity) or IMEI (International Mobile Equipment Identity), which may in fact be the identity of the execution platform of the source device 10, -Identification of the target device, for example its eUICCID (embedded UICC identifier) or IMEI, -A token configured in the source device by the home MNO.
[0023] The use of a forwarding counter makes it possible to limit the number of times the source device 10 is allowed to attempt to forward a new USIM profile to the target device 11. For example, if this counter is equal to 0, the source device 10 is no longer allowed to attempt to forward the USIM profile. Alternatively, the forwarding counter may represent the number of forwardings, in which case the maximum number for this counter is configured in the source profile by the home MNO. In step 15, the source device 10 derives a new long-term key K' from the source device's source long-term key K and the derivation data, the validity of which is verifiable by a remote server at the home MNO, where K' = Derivation(K, DD), where DD is the derivation data. The derivation algorithm may, for example, consist in computing a hash of the long-term key K concatenated with the derivation data.
[0024] In step 16, the source device 10 generates a new USIM profile that includes the derived long-term key K' and the derivation data DD.
[0025] In step 17, to obtain the installation package, the source device 10 confidentially and integrity protects the new profile based on the public key of the target device 11, which is included in the target device 11 certificate and was verified by the source device 10 in step 13.
[0026] In step 18, the source device 10 transfers the installation package to the target device 11, for example via a local communication channel, for example 3GPP PC5 (device-to-device communication), Bluetooth, direct WIFI access, or NFC.
[0027] The installation package is -Derived data and: a hash of the USIM profile originally received by the source device 10, or - It may include any or all of the certificates or certificate fingerprints of the USIM profile originally received by the source device 10.
[0028] Preferably, upon receiving the installation package from the source device 10, the target device 11: - Validate that the installation package is valid and comes from a valid source device, -Install the installation package, - The derived data is stored locally.
[0029] In step 20, the target device 11 verifies the validity of the installation package by verifying that the installation package is signed by the source device 10. Note that the source device 10 was authenticated by the target device 11 during step 14 based on the certificate of the source device 10. If the source device 10 is authorized by the user to install the package (i.e., authorized by the user's consent) and the installation package is valid, the target device 11 installs the package (in its secure element) in step 21 and notifies the source device 10 (in step 22) that the installation was successful.
[0030] The source device 10 can deactivate its own profile (ie, the source profile) since the installation package has been successfully installed on the target device 11 (step 23).
[0031] The source device 10 then locally deactivates its original USIM profile and a new USIM profile with the long-term key K' is installed in the target device, but the subscriptions contained in this new USIM profile are not active from the network's point of view at this step, i.e. the long-term key K' of the target device 11 is currently unknown to the home network.
[0032] Figure 2 illustrates the verification by the home network of the transfer of a new USIM profile from a source device 10 (contained in a secure element cooperating with this source device, this profile including the subscription profile of this secure element to the home MNO) to a target device 11.
[0033] Here, the home network of the source device 10 includes an activation function 12 (e.g., an interface similar to the UDM or a dedicated server exposing the UDM), which is located on a dedicated server (hereinafter referred to as a remote server) connected to or integrated into the Home MNO Network (HPLMN).
[0034] In step 24, the target device 11 is in the activation phase of the new USIM application or the installation package has been successfully installed. The activation phase means that the target device 11 must be informed of and authorized for its subscription by the home MNO activation function through the following steps:
[0035] The target device 11 sends an activation request, i.e. a registration request as described in 3GPP TS 33.501 and 3GPP TS 23.501, but with specific information required for the activation process, to the activation function 12 in step 25. The registration request is sent either via 3GPP access (e.g. NG-RAN, 5G satellite access) or non-3GPP access (e.g. WLAN).
[0036] The 3GPP TS 23.501 specification, for example, is for Release 15 dated December 22, 2017.
[0037] This activation or registration request includes at least the IMSI of the target device 11 (which is the same as the IMSI of the source device 10) and derivation data.
[0038] The activation request may be, for example, a SUCI containing the IMSI and derived data with a specific routing identifier that allows the 5G system to route the activation request to an activation function, or a UDM that can process this activation request for registration purposes.
[0039] In step 26, the activation function 12 extracts the IMSI and derived data (eg, SQN, forwarding counter, or eUID) from the received activation request, for example by unmasking the received SUCI.
[0040] Once the IMSI is retrieved, the activation function 12 can associate this IMSI with the long-term key K of the source device 10 (step 27).
[0041] In step 28, the activation function 12 verifies the validity of the derived data, for example if an SQN is used, this SQN is within a given window known by the activation function 12 (the activation function knows the last used SQN). If the derived data is a forwarding counter, the activation function 12 (remote server) can check that the forwarding counter is valid against a locally stored forwarding counter in the home network.
[0042] It is also possible to verify that: - if the derived data is a cryptographic token, the cryptographic token is derived from or associated with the IMSI; - If the derived data is a source device identity, the source identity is equal to the source device identity associated with the IMSI.
[0043] In step 29, the activation function 12 derives a new long-term key K*, where K*=Derivation(K,DD). Typically, K* is equal to K' if everything was done correctly during the previous steps. In step 30, mutual authentication is performed (according to 3GPP TS 33.501) between the target device 11 and the activation function 12 by using: -K* with activation function 12, -K' by target device 11.
[0044] In step 31, mutual authentication has been successfully performed, which means that K' and K* are equal, and the validity of the subscription is then verified.
[0045] In step 32, the target device 11 is granted access to the home network and the subscription is renewed (the home network updates its local subscriber information, including the long-term key associated with said IMSI, with the new value of K*).
[0046] For example, if an SM-DP+ is used, the activation function 12 may update the binding information in the HPLMN SM-DP+ between the USIM profile and the secure element (eUICC) by providing the HPLMN SM-DP+ with at least the IMSI, the key K*, the source EUID, and the destination EUID.
[0047] If the mutual authentication is not performed successfully, K' and K* are different, meaning something has failed, and processing stops at step 31 .
[0048] The subscriptions that existed on the source terminal 10 are thus transferred to the target terminal 11, and the source terminal can no longer access the home MNO network. The source device profile is now deactivated by the network-side activation function.
[0049] The present invention also relates to a system for enabling traceability of a USIM profile transfer from a source device to a target device, the system comprising a remote server, the source device comprising: -Performing mutual trust verification of the target device by the source device; generating derived data that is verifiable by a remote server connected to the source device's home network; Deriving a new long-term key K' from the source device's source long-term key K and the derivation data; generating a new USIM profile containing the derived long-term key K′ and the derivation data; confidentiality and integrity protecting the new profile based on the public key of the target device to obtain the installation package; -Transfer the installation package to the target device, configured to deactivate the source USIM profile if installation of the installation package on the target device is successful; The target device is - configured to transmit at least its IMSI and derivation data to a remote server in a registration request as specified in 3GPP TS 23.501; The remote server is Retrieving a source long-term key K of the source device and derivation data associated with the IMSI; - verifying the validity of the received derived data based on the subscription information associated with the IMSI; deriving a new long-term key K* from the source long-term key K and the received derivation data; Performing authentication of the target device based on K* and the retrieved subscription data associated with the IMSI, as specified in 3GPP TS 33.501; If K* is equal to K', then the home network is configured to update its local subscriber information associated with the IMSI, including the long-term key associated with the IMSI, with the new value of K*.
[0050] The invention also relates to a remote server that allows traceability of a USIM profile transfer from a source device to a target device, the remote server being connected to a home network of the source device; receiving from the target device in a registration request as specified in 3GPP TS 23.501 at least its IMSI, derivation data, and a new long-term key K′ generated by the source device from the derivation data of the source device's long-term key K; Retrieving a source long-term key K of the source device and derivation data associated with the IMSI; - verifying the validity of the received derived data based on the subscription information associated with the IMSI; deriving a new long-term key K* from the source long-term key K and the received derivation data; Performing authentication of the target device based on K* and the retrieved subscription data associated with the IMSI, as specified in 3GPP TS 33.501; If K* is equal to K', then the home network is configured to update its local subscriber information associated with the IMSI, including the long-term key associated with the IMSI, with the new value of K*.
[0051] Based on the derivation of the long-term key K of the network access application based on verifiable data by the home network activation function, the advantages provided by the present invention are as follows: enabling the activation server 12 to trace the transfer of a subscription from the source device 10 to the target device 11; There is no transfer (or export) of the long-term key K of the source device 10 and K is unknown to the target device 11. -Prevents cloning or duplication of profiles (i.e., the same IMSI / long-term key K pair) while allowing offline transfer of profiles.
Claims
1. A method for enabling traceability of a USIM profile transfer from a source device (10) to a target device (11), the source device (10) and the target device (11) having the same IMSI, the method comprising: - a step (13) of performing mutual trust verification of said target device (11) by said source device (10) and vice versa; - generating (14) at the source device (10) derived data that can be verified by a remote server (12) connected to the home network of the source device (10); - deriving (15) in said source device (10) a second new long-term key K' from a first source long-term key K of said source device (10) and said derivation data; - generating (16) in the source device (10) a new USIM profile containing the second derived new long-term key K' and the derived data; - a step (17) of confidentiality and integrity protecting said new USIM profile based on the public key of the target device (11) to obtain an installation package; - transferring (18) said installation package to said target device (11); - deactivating (23) a source USIM profile in the source device (10) if the installation of the installation package in the target device (11) is successful based on information from the target device (11); - sending (25) from said target device (11) to said remote server (12) at least its IMSI and said derivation data in a registration request as specified in 3GPP TS 23.501; - retrieving (27) in the remote server (12) the derived data associated with the first source long-term key K and the IMSI of the source device (10); - verifying (28) by the remote server (12) the validity of the received derived data based on subscription information associated by the remote server (12) with the IMSI; - deriving (29) by said remote server (12) a second new long-term key K* from said first source long-term key K and said received derivation data; - performing (30) an authentication of the target device (11) by the remote server (12) based on K* and the retrieved subscription data associated with the IMSI, as specified in 3GPP TS 33.501; - if K* is equal to K', updating (32) in the home network its local subscriber information associated with said IMSI, including said long-term key associated with said IMSI, with the new value of K*; A method comprising:
2. 2. The method of claim 1, wherein the trust verification of the target device by the source device includes verifying at the source device whether a certificate of the target device is valid.
3. The derived data is the transfer counter decremented by -1, -random number, - a cryptographic token provisioned to the source device (10) by the home network; - the current authentication sequence number, - the identity of said source device (10), for example its eUICCID or IMEI, - the identification of said target device (11), e.g. its eUICCID or IMEI 3. The method of claim 1, wherein the method is one or more of:
4. 4. The method according to claim 1, wherein in the source device (10), the step of deriving a second new long-term key K′ from the first source long-term key K consists in calculating a hash of the first long-term key K using the derivation data.
5. The installation package includes the derived data and - a hash of the USIM profile originally received by said source device (10), or - one or more of a certificate or a fingerprint of a certificate of a USIM profile originally received by the source device (10).
6. When the target device (11) receives the installation package from the source device (10), - verifying that the installation package is valid and comes from a valid source device (10); - installing said installation package, The method according to any one of claims 1 to 5, wherein the derived data is stored locally.
7. 7. The method according to any one of claims 1 to 6, wherein the step (25) of transmitting at least its IMSI and the derivation data from the target device (11) to the remote server (12) in the registration request as specified in 3GPP TS 23.501 consists in using a specific routing ID of the remote server (12) in the registration request as specified in 3GPP TS 23.
501.
8. The remote server - if the derived data is the stored sequence number, - the received sequence number is valid against the sequence numbers stored locally in the home network; - if the derived data is a forwarding counter, the forwarding counter is valid relative to the forwarding counter stored locally by the home network; - if the derived data is a cryptographic token, that the cryptographic token is derived from or associated with the IMSI; - if the derived data is a source device (10) identity, verifying that the source identity is equal to the source device (10) identity associated with the IMSI.
9. 9. The method according to claim 1, wherein the remote server (12) updates binding information in the HPLMN SM-DP+ between a USIM profile and a secure element of the target device (11) by providing at least the IMSI, the second new long-term key K*, a source EUID, and a destination EUID to the HPLMN SM-DP+.
10. A system for enabling traceability of a USIM profile transfer from a source device (10) to a target device (11), wherein the source device (10) and the target device (11) have the same IMSI, the system comprising: a remote server (12), the source device (10), and the target device (11), wherein the source device (10) - performing mutual trust verification of the target device (11) by the source device (10); - generating (14) derived data at the source device (10) that is verifiable by a remote server (12) connected to the home network of the source device (10); - deriving (15) in the source device (10) a second new long-term key K' from the first source long-term key K of the source device (10) and the derived data, generating (16) in the source device (10) a new USIM profile including the second derived new long-term key K′ and the derived data; - confidentiality and integrity protection of said new USIM profile based on the public key of the target device (11) to obtain the installation package, - transferring said installation package to said target device (11); - configured to deactivate the source USIM profile if the installation of the installation package on the target device (11) is successful, The target device (11) - configured to transmit at least its IMSI and said derivation data to said remote server (12) in a registration request as specified in 3GPP TS 23.501; The remote server (12) - retrieving the first source long-term key K of the source device (10) and derived data associated with the IMSI, - verifying the validity of the received derived data based on subscription information associated with the IMSI; - deriving a second new long-term key K* from said first source long-term key K and said received derivation data; - performing authentication of the target device (11) based on said K* and the retrieved subscription data associated with said IMSI, as specified in 3GPP TS 33.501; - if K* is equal to K', then at the home network, updating its local subscriber information associated with the IMSI, including the long-term key associated with the IMSI, with the new value of K*.
11. A remote server (12) that enables traceability of a USIM profile transfer from a source device (10) to a target device (11), the source device (10) and the target device (11) having the same IMSI, the remote server (12) being connected to the home network of the source device (10); receiving from the target device (11) in a registration request as specified in 3GPP TS 23.501 at least its IMSI, derivation data, a first long-term key K of the source device (10) and a second new long-term key K′ generated by the source device (10) from the derivation data; - retrieving the source second long-term key K of the source device (10) and the derived data associated with the IMSI, - verifying the validity of the received derived data based on subscription information associated with the IMSI; - deriving a second new long-term key K* from the source first long-term key K and the received derivation data; - performing authentication of the target device (11) based on said K* and the retrieved subscription data associated with said IMSI, as specified in 3GPP TS 33.501; - if K* is equal to K', a remote server (12) configured to update, in the home network, its local subscriber information associated with said IMSI, including said long-term key associated with said IMSI, with the new value of K*.
Citation Information
Patent Citations
Systems and methods for transferring SIM profiles between eUICC devices
US10349267B1
Method and apparatus for reinstalling SIM profile in wireless communication system
US20210105609A1