Download operational subscription profile

The described method and system enhance the GSMA eSIM IoT architecture by securely downloading and installing operational subscription profiles using initial cellular connectivity, addressing unauthorized profile issues and enabling automated, secure management.

JP2026067890APending Publication Date: 2026-04-21TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Filing Date
2026-01-08
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing GSMA eSIM IoT architecture does not adequately prevent unauthorized subscription profile downloads and installations, particularly in low-power IoT devices, and lacks secure mechanisms for managing subscription profiles without user intervention.

Method used

A method and system for securely downloading and installing operational subscription profiles using initial cellular connectivity, involving a subscriber module that authenticates the eSIM server and obtains download information to determine permission, ensuring secure and automated profile management.

Benefits of technology

This approach enhances security by preventing unauthorized profile downloads and enabling automated, secure handling of subscription profiles, reducing the risk of malware interference and ensuring seamless connectivity setup.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026067890000001_ABST
    Figure 2026067890000001_ABST
Patent Text Reader

Abstract

Improve security in handling operational subscription profiles. [Solution] In the communication network 100, the subscriber module 1200 is provided with subscription data for use in establishing the initial cellular connectivity connection, and authenticates the eSIM server 1400 using the subscription data during the cellular network access authentication period for establishing the initial cellular connectivity connection. The subscriber module obtains download information for the operational subscription profile from the eSIM server on the initial cellular connectivity connection for the communication device 180. The subscriber module downloads the operational subscription profile from the extended subscription manager data preparation entity 150 according to the download information and installs the operational subscription profile.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention presented herein relates to a method, a subscriber module, a communication device, a computer program, and a computer program product for downloading and installing an operational subscription profile. The invention further relates to a method, an embedded subscriber identity module (eSIM) server, a computer program, and a computer program product for enabling the downloading and installation of an operational subscription profile into the subscriber module.

Background Art

[0002] The GSMA (Global System for Mobile Communication Alliance) standardizes how to provide subscribers with 3GPP (third generation partnership project) subscription profiles, often referred to as subscriber identity module (SIM) subscription profiles, but here simply as subscription profiles. These subscription profiles can be remotely downloaded via the internet to the physical hardware within communication devices known as embedded UICC / embedded universal integrated circuit cards (eUICC), integrated UICC / universal integrated circuit cards (uUICC), or integrated embedded UICC / universal integrated circuit cards (ieUICC). By following the Remote SIM Provisioning Protocol (RSP), the subscription profile is remotely transmitted from a provisioning server (Extended Subscription Manager Data Preparation (SM-DP+) server, hereafter abbreviated as SM-DP+ entity) to the communication device. Remote SIM provisioning for consumer devices is described in the documents "SGP.21 - RSP Architecture Specification v2.4" and "SGP.22 - RSP Technical Specification v2.4".

[0003] Communication devices download subscription profiles from SM-DP+ entities. Mobile network operators (MNOs) order subscription profiles from SM-DP+ entities, which then prepare and make available for download to communication devices. During the subscription profile ordering process, MNOs also perform necessary network provisioning actions. In particular, to ensure initial cellular-based connectivity when the communication device is first powered on, it is necessary to install an appropriate SIM subscription profile that operates where the communication device is located during manufacturing. Such SIM subscription profiles will hereafter be referred to as bootstrap subscription profiles or provisioning subscription profiles. It is often unknown where a specific communication device will ultimately end up during the manufacturing of the eUICC / module / device. For this reason, MNO provisioning subscription profiles with global roaming agreements are desirable.

[0004] Generally speaking, eSIM services are available for Internet of Things (IoT) communication devices, where knowledge of pre-negotiated agreements with MNOs and IoT device information, based on the IoT device's geographical location, are used as input to a localization procedure to determine the appropriate MNO, provisioning server, and subscription profile to use for a particular IoT device. This then triggers the download of the operational subscription profile. Such eSIM services should be provided by an eSIM server, which might be triggered, for example, when the IoT device is first powered on.

[0005] Since IoT devices typically lack a user interface, they are unable to establish user consent for operations concerning subscription profiles. Possible provisioning techniques for IoT devices configure them to accept subscription profile download trigger operations and subscription profile management operations (such as enabling, disabling, and deleting subscription profiles) sent to the IoT device over an established, secure communication channel from an authorized (remote) server (hereinafter referred to as the management entity), without requiring user confirmation via any local or remote user interface. This enables automated handling of subscription profiles for a group of IoT devices, for example, hundreds or thousands. The management entity may also be referred to as the eSIM IoT Remote Manager (eIM). According to the GSMA document "SGP.31 - eSIM IoT Architecture and Requirements v1.0," the intention is that IoT eSIM variants can leverage existing SM-DP+ and Subscription Manager Discovery Service (SM-DS) infrastructure based directly on the eSIM consumer variant. Therefore, the IoT eSIM variant supports the same three methods as the eSIM consumer variant for providing information to communication devices for which subscription profiles are pending download (summarized below). For secure subscription profile management on IoT devices, secure communication must be established between the IoT device and the management entity, relying on key materials available to both the IoT device and the management entity. For example, pre-shared keys may be used, or a private-public key pair and certificates for both entities may be used.In the GSMA eSIM IoT architecture (SGP.31), a secure communication channel between the IoT device and a device management server acting as the management entity can be used to protect the download of subscription profiles and the triggering of subscription profile management operations. Establishing key material between both parties is outside the scope of the solution proposed by GSM. Setting up key material may, for example, rely on the IoT device's bootstrap process. The GSMA eSIM IoT architecture for low-power IoT devices deals with IoT devices that are constrained by memory and / or power, as well as IoT devices connected over LPWA (low-power wide-area) networks. Such devices typically cannot support HTTPS (Hypertext Transfer Protocol Secure) communication with SM-DP+ entities as required by SGP.22. For these devices, the download of subscription profiles (and handling of notifications) is performed via the management entity to the SM-DP+ entities, leveraging secure communication between the IoT device and the management entity, and the management entity handles HTTPS communication with the SM-DP+ entities.

[0006] Currently, there are three defined options for providing information to communication devices for which subscription profiles are pending download, and these will be referred to below as Option 1, Option 2, and Option 3.

[0007] Option 1: At the subscription profile ordering stage, the MNO either receives an activation code (AC) from the SM-DP+ (over the ES2+ interface) or generates an AC from data received from the SM-DP+. The MNO then distributes the AC to the customer, for example, in the form of a quick response (QR) code that is readable by the communication device and usable by the communication device to contact the SM-DP+ device. When the customer provides the AC to the communication device, triggering the download of the subscription profile, the communication device can connect to the appropriate SM-DP+ based on the information from the AC and download the subscription profile.

[0008] Option 2: The communication device is configured with a default SM-DP+ address that defines the SM-DP+ to be used for downloading the subscription profile, or has at least access to such default SM-DP+. For example, upon initial power-on during the commissioning period of the communication device, or based on some other defined trigger, the communication device connects to the default SM-DP+ to download the subscription profile.

[0009] Option 3: During the subscription profile ordering phase, the MNO requests SM-DP+ to register information about available subscription profiles for a specific communication device via a discovery service (such as SM-DS). An event is then generated in SM-DS for that specific communication device, instructing it to connect to SM-DP+ and download the subscription profile. The communication device is configured, for example, to contact SM-DS upon initial power-up during its commissioning period to check for pending subscription profile download events. Upon successful download of the event from SM-DS, the communication device connects to SM-DP+ as indicated by the event and downloads the subscription profile. The GSMA currently defines a root SM-DS common to all communication devices. However, auxiliary SM-DS servers and vendor-specific discovery services, thus resulting in a variety of SM-DS servers, may exist.

[0010] According to Options 2 and 3, the MNO provides the eUICC identifier (EID) of the communication device, and the subscription profile package prepared for download is linked to the EID in SM-DP+. According to Option 1, the MNO (or SM-DP+) does not need to know the EID at the time of ordering the subscription profile. In Option 1, the communication device receives a matching ID (MID) via AC, and the communication device presents this MID to SM-DP+ during the subscription profile download period to identify the correct prepared subscription profile package.

[0011] In the GSMA eSIM IoT architecture, as defined in the aforementioned document "SGP.31 - eSIM IoT Architecture and Requirements v1.0," an additional layer of protection is added between the management entity and the subscriber module, in addition to the secure channel between the communication device and the management entity, to protect against potential malware residing in the communication device. According to this architecture, the management entity must sign all commands / operations to the subscriber module related to subscription profile state management operations using its private key, and the subscriber module must verify the signature using the management entity's public key, which has been securely configured on the subscriber, before accepting subscription profile state management operations (PSMO), such as enabling, disabling, and deleting subscription profiles. This ensures that malware cannot enable (download, install, and) a malicious subscription profile on the subscriber module, or that malware cannot disable or delete an already installed subscription profile, resulting in loss of connectivity or the need to reinstall the subscription profile. A signed PSMO protects administrative operations, data that uniquely identifies the subscription profile (e.g., ICCID, which is the integrated circuit card ID), and data for replay protection (e.g., counters or randoms).

[0012] The setting of the management entity's public key for subscriber modules may occur at various stages, such as during subscriber module production, communication device production, and when communication devices are switched to use. Currently, subscription profile state management is only possible if the management entity's public key has been set for the subscriber module. In addition, if the subscription profile is downloaded from a default SM-DP+ entity (as per Option 2) or from an SM-DP+ entity obtained via an SM-DS entity (as per Option 3), automatic activation of the subscriber profile is possible without a signed PSMO.

[0013] The GSMA eSIM IoT architecture prevents malware on a communication device from altering the state of its subscription profile, but it does not prevent malware from attempting to download and install a new subscription profile. Furthermore, the architecture does not prevent a person who knows the EID of a particular communication device from ordering an unwanted subscription profile for that device or preparing it for download via an SM-DP+ entity, as the information for the SM-DP+ entity is obtained via the same SM-DS entity that the communication device uses, for example, to check which subscription profile to download. [Overview of the project]

[0014] The objective of this embodiment is to solve at least one of the above problems and / or to enable improved security in handling operational subscription profiles.

[0015] According to the first aspect, a method for downloading and installing an operational subscription profile is presented. The method is performed by a subscriber module. The subscriber module is provided to a communication device. The subscriber module is provided with subscription data for use in establishing initial cellular connectivity. The method includes obtaining download information for the operational subscription profile from an eSIM server over the initial cellular connectivity connection for the communication device. The download information is used by the subscriber module to determine whether it is permitted to download the subscription profile. The subscriber module authenticates the eSIM server using the subscription data during the cellular network access authentication period for establishing the initial cellular connectivity connection. The method includes downloading the operational subscription profile from an SM-DP+ entity according to the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device. The method includes installing the operational subscription profile on the subscriber module.

[0016] From a second perspective, a subscriber module is provided for downloading and installing an operational subscription profile. The subscriber module is provided to the communication device. The subscriber module is provided with subscription data for use in establishing initial cellular connectivity. The subscriber module comprises a processing circuit. The processing circuit is configured to cause the subscriber module to obtain download information for the operational subscription profile from the eSIM server over the initial cellular connectivity connection for the communication device. The download information is used by the subscriber module to determine whether it is permitted to download the subscription profile. The subscriber module authenticates the eSIM server using the subscription data during the cellular network access authentication period for establishing the initial cellular connectivity connection. The processing circuit is configured to cause the subscriber module to download the operational subscription profile from the SM-DP+ entity according to the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device. The processing circuit described above is configured to cause the subscriber module to install the operational subscription profile described above.

[0017] According to a third perspective, a subscriber module is provided for downloading and installing an operational subscription profile. The subscriber module is provided to a communication device. The subscriber module is provided with subscription data for use in establishing initial cellular connectivity. The subscriber module includes an acquisition module configured to obtain download information for the operational subscription profile from an eSIM server over the initial cellular connectivity connection for the communication device. The download information is used by the subscriber module to determine whether it is permitted to download the subscription profile. The subscriber module authenticates the eSIM server using the subscription data during the cellular network access authentication period for establishing the initial cellular connectivity connection. The subscriber module includes a download module configured to download the operational subscription profile from an SM-DP+ entity according to the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device. The subscriber module includes an installation module configured to install the operational subscription profile into the subscriber module.

[0018] According to the fourth perspective, a computer program for downloading and installing an operational subscription profile is provided. The subscriber module is provided to the communication device. The subscriber module is provided with subscription data for use in establishing initial cellular connectivity. The computer program includes computer program code that, when executed on the processing circuit of the subscriber module, causes the subscriber module to obtain download information for the operational subscription profile from the eSIM server over the initial cellular connectivity connection for the communication device. The download information is used by the subscriber module to determine whether it is permitted to download the subscription profile. During the cellular network access authentication period for establishing the initial cellular connectivity connection, the subscriber module authenticates the eSIM server using the subscription data. The computer program includes computer program code that, when executed on the processing circuit of the subscriber module, causes the subscriber module to download the operational subscription profile from the SM-DP+ entity according to the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device. The above computer program includes computer program code that, when executed on the processing circuit of the subscriber module, causes the subscriber module to install the operational subscription profile on the subscriber module.

[0019] According to the fifth perspective, a method is presented for enabling the download and installation of an operational subscription profile to a subscriber module. The method is performed by an eSIM server. The method includes obtaining a trigger for the download of the operational subscription profile to the subscriber module. The method includes providing the subscriber module with download information for the operational subscription profile over the initial cellular connectivity connection for the communication device to which the subscriber module is provided. The download information is identified to determine that the subscriber module is permitted to download the subscription profile. The eSIM server provides the subscriber module with authentication data for the subscriber module to authenticate the eSIM server during the period of cellular network access authentication for establishing the initial cellular connectivity connection.

[0020] According to the sixth perspective, an eSIM server is presented for enabling the download and installation of an operational subscription profile to a subscriber module. The eSIM server comprises a processing circuit. The processing circuit is configured to cause the eSIM server to acquire a trigger for downloading the operational subscription profile to the subscriber module. The processing circuit is configured to cause the eSIM server to provide download information for the operational subscription profile to the subscriber module over the initial cellular connectivity connection for the communication device to which the subscriber module is provided. The download information is identified to determine that the subscriber module is permitted to download the subscription profile. The eSIM server provides the subscriber module with authentication data for the subscriber module to authenticate the eSIM server during the period of cellular network access authentication for establishing the initial cellular connectivity connection.

[0021] According to the seventh perspective, an eSIM server is presented for enabling the download and installation of an operational subscription profile to a subscriber module. The eSIM server comprises an acquisition module configured to obtain a trigger for the download of the operational subscription profile to the subscriber module. The eSIM server comprises a provision module configured to provide the subscriber module with download information for the operational subscription profile over an initial cellular connectivity connection for the communication device to which the subscriber module is provided. The download information is identified to determine that the subscriber module is permitted to download the subscription profile. The eSIM server provides the subscriber module with authentication data for the subscriber module to authenticate the eSIM server during the period of cellular network access authentication for establishing the initial cellular connectivity connection.

[0022] According to the eighth perspective, a computer program is presented for enabling the download and installation of an operational subscription profile to a subscriber module. The computer program includes computer program code. When executed on the processing circuit of the eSIM server, the computer program code causes the eSIM server to obtain a trigger for downloading the operational subscription profile to the subscriber module. When executed on the processing circuit of the eSIM server, the computer program code causes the eSIM server to provide download information for the operational subscription profile to the subscriber module over the initial cellular connectivity connection for the communication device to which the subscriber module is provided. The download information is identified to determine that the subscriber module is permitted to download the subscription profile. During the period of cellular network access authentication to establish the initial cellular connectivity connection, the eSIM server provides the subscriber module with authentication data for the subscriber module to authenticate the eSIM server.

[0023] According to the ninth aspect, a computer program product is presented which includes a computer program relating to at least one of the fourth and eighth aspects, and a computer-readable storage medium in which the computer program is stored. The computer-readable storage medium may be a non-temporary computer-readable storage medium.

[0024] The tenth aspect relates to communication devices, including subscriber modules, relating to the second or third aspect.

[0025] Advantageously, these perspectives provide a secure procedure for downloading and installing subscription profiles on communication devices, thus avoiding the aforementioned challenges.

[0026] Advantageously, these aspects reduce the download and installation of unauthorized subscription profiles to the subscriber module of the communication device.

[0027] Advantageously, these aspects enable the automated handling of download information without the involvement of the device owner or user, thereby enabling the automated provision of the operational subscription profile.

[0028] Advantageously, these aspects enable the automated post - / subsequent configuration of information for use in the subscriber module along with the download of the subscription profile using Option 2 and Option 3 disclosed above. Such information includes SM - DP+ / SM - DS object identifiers (OIDs) and addresses.

[0029] Other objectives, features and advantages of the embodiments included will become apparent from the following detailed disclosure, from the claims and from the drawings.

[0030] Generally, all terms used in the embodiments and the claims should be interpreted according to their ordinary meaning in the relevant art, unless explicitly defined otherwise herein. All references to an element, apparatus, component, means, module, step, etc. should be construed openly as a reference to at least one instance of those elements, apparatus, components, means, modules, steps, etc., unless otherwise explicitly stated. None of the method steps disclosed herein need to be performed in the exact order disclosed, unless otherwise explicitly stated.

Brief Description of the Drawings

[0031] The inventive concept will be described by way of example with reference to the following attached drawings:

[0032] [Figure 1]This is a schematic diagram showing a communication network according to the embodiment. [Figure 2] This is a flowchart of the method according to the embodiment. [Figure 3] This is a flowchart of the method according to the embodiment. [Figure 4] This is a sequence diagram according to the embodiment. [Figure 5] This is a sequence diagram according to the embodiment. [Figure 6] This is a sequence diagram according to the embodiment. [Figure 7] This is a sequence diagram according to the embodiment. [Figure 8] This is a sequence diagram according to the embodiment. [Figure 9] This is a sequence diagram according to the embodiment. [Figure 10] This is a sequence diagram according to the embodiment. [Figure 11] This is a sequence diagram according to the embodiment. [Figure 12] This is a schematic diagram showing a group of functional units in a subscriber module according to one embodiment. [Figure 13] This is a schematic diagram showing a group of functional modules for a subscriber module according to one embodiment. [Figure 14] This is a schematic diagram showing a group of functional units of an eSIM server according to one embodiment. [Figure 15] This is a schematic diagram showing a set of functional modules for an eSIM server according to one embodiment. [Figure 16] This shows one example of a computer program product that includes computer-readable means according to one embodiment. [Modes for carrying out the invention]

[0033] The inventive concept will be explained more fully hereby with reference to the accompanying drawings depicting certain embodiments of the inventive concept. The inventive concept may, however, be embodied in many different forms and should not be interpreted as being limited to the embodiments described herein. Rather, these embodiments are provided by illustrative means so that the scope of the inventive concept may be fully conveyed to those skilled in the art, making this disclosure thorough and complete. Throughout the description, similar numbers refer to similar elements. Any step or feature indicated by a dashed line should be considered optional.

[0034] The phrase "obtained" by the first device should be interpreted as "retrieved," "fetched," "received," or otherwise "made available" for the first device. For example, the information of a data item or piece may be pushed to the first device from the second device, or pulled from the second device by the first device. Furthermore, in order for the first device to obtain the information of a data item or piece, the first device may be configured to perform a series of operations, possibly including an interaction with the second device. Such operations or interactions may involve a message exchange including any of the following: a request message for the information of the data item or piece, a response message containing the information of the data item or piece, and an acknowledgment message for the information of the data item or piece. If the information of the data item or piece is not explicitly or implicitly requested by the first device, the request message may be omitted.

[0035] The phrase "provided" by the first device to the second device should be interpreted as "sent" or otherwise "made available" by the first device to the second device. For example, the data item or piece of information may be pushed from the first device to the second device, or pulled from the second device by the second device. Furthermore, in order for the first device to provide the data item or piece of information to the second device, the first and second devices may be configured to perform a series of operations for mutual interaction. Such operations or interactions may involve a message exchange including any of the following: a request message for the data item or piece of information, a response message containing the data item or piece of information, and an acknowledgment message for the data item or piece of information. If the data item or piece of information is not explicitly or implicitly requested by the second device, the request message may be omitted.

[0036] Figure 1 is a schematic diagram showing a communication network 100 to which the embodiments presented herein can be applied.

[0037] Communication device 180 is the device to which the operational subscription profile is downloaded. Communication device 180 may be a mobile phone, laptop, computer tablet, or user equipment (UE). Alternatively, it may be an IoT device. Communication device 180 includes a subscriber module 1200 (exemplified as eUICC in the figure), such as iUICC, eUICC, or ieUICC, which supports the remote delivery of subscription profiles for GSMA consumer variants, including signed subscription profile state management operations related to the GSMA eSIM IoT architecture (as specified in the aforementioned document "SGP.31 - eSIM IoT Architecture and Requirements v1.0"). Communication device 180 supports the secure download, installation, and activation of the subscription profile, which utilizes authorization secrets or downloaded and installed data. The subscriber module 1200 holds certificates for secure interaction with both provisioning servers (such as SM-DP+ entity 150) and discovery servers (such as SM-DS entity 160). The certificate includes a certificate for subscriber module 1200 containing an elliptic curve (EC) private key and a corresponding public key. The certificate for subscriber module 1200 also contains an identifier for subscriber module 1200, such as an EID. Subscriber module 1200 is provided with a first profile in the form of a provisioning subscription profile at the time of manufacture, personalization, or module / device manufacturing. The provisioning subscription profile provides initial cellular connectivity that enables the download of the operational subscription profile. Alternatively, if a subscription profile is not installed on subscriber module 1200, the operating system (OS) of subscriber module 1200 may act as the provisioning subscription profile in establishing initial cellular connectivity.The communication device 180 may be manufactured by an original equipment manufacturer (OEM), and the subscriber module 120 may be manufactured by an eUICC manufacturer (UEM), both of which are represented by a manufacturer entity 130.

[0038] The management of subscription profiles on the subscriber module 1200 (e.g., enabling, disabling, and deleting subscription profiles) is handled remotely by the management entity 210. The management entity 210 may also handle device and data management for the communication device 180. When the communication device 180 first starts up, the information necessary to connect to the management entity 210 may not yet be configured. Such information can be obtained by the communication device 180, for example, through the operational subscription profile or through the application layer bootstrap procedure.

[0039] The communication device 180 includes a cellular modem configured to connect to a mobile network based on an active subscription profile. Upon initial startup of the communication device 180, the provisioning subscription profile is the active subscription profile, providing initial cellular connectivity. Initial cellular connectivity is established using a first mobile network (MNO1 120). Subsequently, using remote SIM provisioning of an eSIM, the subscriber module 1200 may provide a second profile from a second mobile network (MNO2 200) in the form of an operational subscription profile. It should be noted that MNO1 120 and MNO2 200 may be a single identical network, or, in other embodiments, multiple different networks. The terms MNO1, MNO2, and MNO3 may, in some examples, be used interchangeably with mobile network operators and their respective mobile networks in the following description. After the operational subscription profile is activated, it is used to provide network connectivity for the communication device 180. In other words, the operational subscription profile is intended for longer-term use (than the provisioning subscription profile) for connectivity services for communication device 180. In one embodiment, the operational subscription profile includes MNO data and applications intended for service provision by the MNO. In its embodiment, the operational subscription profile supports subscriptions to the MNO, enabling connectivity to the mobile network, which in the above example is typically MNO2 200. The operational subscription profile may further include one or more applications for non-communication services.In one embodiment, the provisioning subscription profile includes a combination of MNO data and applications intended to enable connectivity to MNO1 120, solely for the purpose of providing the operational subscription profile to the subscriber module 1200. The provisioning subscription profile thus contains information / applications that are not present in the operational subscription profile, such as a method for downloading the operational subscription profile.

[0040] The communication device 180 typically includes an IoT Subscription Profile Assistant (IPA) 170, which, as part of a modem, assists in the download and management operations of subscription profiles. The IPA 170 interacts with a provisioning server for handling subscription profile downloads and notifications, and with a management entity for subscription profile management operations. The IPA 170 may be configured to interact with a discovery service to check for pending subscription profile download events. If the communication device 180 has network, energy, and / or memory constraints, interaction with the SM-DP+ entity 150 and SM-DS entity 160 may occur via the management entity 210.

[0041] The eSIM server 1400 serves as the home mobile network when the communication device 180 connects to the first mobile network (i.e., the destination / serving mobile network) during the initial startup period for acquiring initial cellular connectivity. The eSIM server 1400 provides a provisioning subscription profile that is installed during the manufacturing or personalization period of the subscriber module 1200. This may be a common subscription profile for all communication devices 180 using the service. Alternatively, one separate subscription profile is used for each communication device 180. The provider of the eSIM server 1400 may be, for example, a mobile network operator, a communications service provider (CSP), a mobile virtual network operator (MVNO), or a mobile network vendor. The provider of the eSIM server 1400 may have an agreement with the MNO (shown in the figure as mobile network MNO3 110) to use a set of international mobile subscriber identities (IMSIs) for the eSIM server 1400 so that communication devices such as communication device 180 can be routed to the eSIM server 1400 during the initial cellular connectivity establishment period.

[0042] The MNO (or CSP) provides cellular connectivity for communication devices and potentially also provides a localization server 140 for remote subscription profile downloads. If the provider of the eSIM server 1400 is an MVNO, it has a roaming agreement with a set of MNOs (shown in the figure as Mobile Network MNO1 120), and these MNOs assist in providing initial cellular connectivity for communication devices 180 using the eSIM server 1400.

[0043] A company, IoT service provider, device owner, or end user using the eSIM server 1400 orders a subscription profile for their communication device 180 from an MNO (shown as Mobile Network MNO2 200 in the diagram). The MNO interacts with a provisioning server to prepare the operational subscription profile for remote download. Upon successful download and activation of the operational subscription profile to the communication device 180, the MNO provides cellular connectivity to the communication device 180. Note that MNO2 200 may be one of the MNO1 120 operators providing initial cellular connectivity.

[0044] SM-DP+ entity 150 handles the download of subscription profiles to IoT devices in accordance with the GSMA eSIM consumer variant. SM-DP+ entity 150 is either operated by an MNO (shown as Mobile Network MNO2 200 in the diagram) providing the operational subscription profile to be downloaded, or by a third party trusted by the MNO. SM-DP+ entity 150 is certified and possesses acquired certificates that enable it to be part of the eSIM ecosystem. The SM-DP+ certificate for authentication and the certificate for downloading the subscription profile include the SM-DP+ OID. This OID is used to ensure that communication with the intended SM-DP+ entity 150 takes place.

[0045] SM-DS entity 160 provides discovery services for use by communication device 180 in accordance with the aforementioned documents “SGP.21 - RSP Architecture Specification v2.4” and “SGP.22 - RSP Technical Specification v2.4”. The GSMA currently defines a root SM-DS for the eSIM ecosystem; however, auxiliary SM-DS entities and vendor-specific SM-DS entities may exist. SM-DS entity 160 is certified and possesses one or more acquired certificates that enable it to be part of the eSIM ecosystem. The SM-DS certificate for certification includes the SM-DS OID. This OID is used to ensure that communication takes place with the intended SM-DS entity 160.

[0046] As part of the initial delivery of cellular connectivity, the localization server 140 may determine the appropriate MNO / MNO device to provide an operational subscription profile for a particular communication device 180. This is referred to as a localization process and may be more or less complex depending on the current scenario. For example, the appropriate MNO, provisioning server, and operational subscription profile to be used may be determined based on the geographical location of the communication device 180, knowledge of any prior agreements negotiated with the MNO, or information about the communication device 180. Such localization may be provided as a service to an enterprise or a communication service provider 190 by the provider of the localization server 140.

[0047] There may be several different ways in which the localization server 140 is provided and connected to the eSIM server 1400. In the first option, the localization server 140 manages connectivity for a set of MNOs, handles provisioning server interactions on behalf of the MNOs (even the provisioning servers may be provided by the provider of the localization server 140), and also handles updates / control of home subscriber servers (HSS) such as Unified Data Management (UDM) within the MNO's 5G core network (5GC). In the second option, the localization server 140 simply performs localization based on input data, and the company handles interactions with the MNOs itself. Other options are also possible. The eSIM server 1400 may be closely connected to the localization server 140 (or a part thereof) in the first option, for example, or it may not have a relationship at all, simply using a localization application programming interface (API) to receive information about the operational subscription profile that triggers localization and is selected. Such interactions may also take place through companies.

[0048] The management entity 210 manages one or more subscription profiles on the subscriber module 1200 of the communication device 180. The management entity 210 may also assist in the download interaction of subscription profiles between the communication device 180 and the SM-DS entity 160. The management entity 210 supports signed subscription profile state management operations (PSMO) using its private keys, such as the EC private key, and its corresponding public key, such as the EC public key, is set on each subscriber module 1200 managed by the management entity 210. The management entity 210 is configured with a list of subscriber 1200 identifiers (such as EIDs) of the communication device 180 or subscriber module 1200 managed by the management entity 210. Device owners / end users / enterprises / service providers or other actors may interact with the management entity 210 to configure it along with management operations. Such information may include, for example, the ICCID of the subscription profile of a specific subscriber module 1200 on which a particular subscription profile management operation is to be performed, or it may include an activation code (AC) with information from which a specific communication device 180 downloads the subscription profile.

[0049] Embodiments disclosed herein relate to techniques for downloading and installing operational subscription profiles to subscriber module 1200. To obtain such techniques, a computer program product is provided that includes subscriber module 1200, a method performed by subscriber module 1200, and code in the form of a computer program that causes subscriber module 1200 to perform the method when executed, for example, on the processing circuit of subscriber module 1200. To obtain such techniques, an eSIM server 1400, a method performed by eSIM server 1400, and a computer program product is provided that includes code in the form of a computer program that causes eSIM server 1400 to perform the method when executed, for example, on the processing circuit of eSIM server 1400.

[0050] Next, refer to Figure 2, which illustrates a method for downloading and installing an operational subscription profile performed by a subscriber module 1200 according to one embodiment. The subscriber module 1200 is provided to the communication device 180. The subscriber module 1200 is provided with subscription data for use in establishing initial cellular connectivity.

[0051] S102: The subscriber module 1200 obtains download information for the operational subscription profile from the eSIM server 1400. The download information is obtained over the initial cellular connectivity connection for the communication device 180. The download information is used by the subscriber module 1200 to determine whether it is permitted to download the subscription profile. The subscriber module 1200 authenticates the eSIM server 1400 using the subscription data during the cellular network access authentication period to establish the initial cellular connectivity connection.

[0052] S104: The subscriber module 1200 downloads the operational subscription profile from the SM-DP+ entity 150 according to the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device 180.

[0053] S106: Subscriber module 1200 installs the operational subscription profile on subscriber module 1200.

[0054] Embodiments relating to further details of the download and installation of operational subscription profiles performed by subscriber module 1200 will be disclosed hereafter.

[0055] In some embodiments, after S106, the operational subscription profile is activated upon download and installation (and storage). Thus, in some embodiments, the subscriber module 1200 is configured to perform step S108 (optionally).

[0056] S108: The subscriber module 1200 activates the operational subscription profile within the subscriber module 1200 in response to the installation of the operational subscription profile.

[0057] Network access authentication will rely on a secret shared between the eSIM server 1400 and the provisioning profile (accessed by the subscriber module 1200). The shared secret may be a pre-configured portion of the provisioning profile or may be derived from data contained in the provisioning profile. Thus, in some embodiments, authentication of the eSIM server 1400 is performed using a secret shared with the eSIM server 1400, which is contained in or derivable from the subscription data. In some examples, the subscription data is contained in a provisioning subscription profile installed within the subscriber module 1200. In some examples, the subscription data is contained as part of the operating system of the subscriber module 1200. If no subscription profile is installed within the subscriber module 1200, the subscriber module 1200 uses the subscription data to behave to the communication device 180 as if a provisioning profile existed within the subscriber module 1200. In some examples, a secret shared with the eSIM server 1400 to protect the transfer of download information from the eSIM server 1400 to the subscriber module 1200 over the initial cellular connectivity connection for the communication device 180 is contained in or derivable from the subscription data. In some examples, the secret shared with the eSIM server 1400 is derivable from the subscription data based on the private key of the subscriber module 1200's private-public key pair and the public key of the eSIM server 1400's private-public key pair. The public key of the eSIM server 1400's private-public key pair is part of the subscription data.

[0058] In some examples, download information is securely transferred from the eSIM server 1400 to the subscriber module 1200 using the SIM OTA (over-the-air) procedure. The operational subscription profile may be downloaded from the default SM-DP+ entity 150, or from an SM-DP+ entity 150 provided by the SM-DS entity 160. If the SM-DS entity 160 is used, the SM-DP+ information from which the operational subscription profile will be downloaded is first securely obtained from the SM-DS. An authorization secret is used to ensure that the subscriber module 1200 is permitted to download the operational subscription profile. Therefore, in some examples, the download information identifies the authorization secret used by the subscriber module 1200 to determine that it is permitted to download the operational subscription profile from the SM-DP+ entity 150, and / or to determine that it is permitted to download the SM-DP+ information from the SM-DS, which identifies the SM-DP+ entity 150 from which the operational subscription profile will be downloaded. Furthermore, determining that a download is permitted is based on subscriber module 1200 obtaining proof of knowledge of the authorization secret SM-DP+ / SM-DS acquired during the profile download preparation period for the operational subscription profile.

[0059] In some examples, the download of the operational subscription profile is protected by leveraging SM-DS or SM-DP+ information (such as addresses and OIDs) within the subscriber module 1200. The SM-DS or SM-DP+ information is used by the subscriber module 1200 to verify information obtained from SM-DP+ and, if used, from SM-DS during the period of the operational subscription profile download to determine whether the download of the profile is permitted. The SM-DS or SM-DP+ information is selected by the communication device 180 using unsigned download and installation data that points to the SM-DS or SM-DP+ information. Thus, in some examples, the download information identifies the OIDs of the SM-DP+ entity 150 and / or SM-DS entity 160 that the subscriber module 1200 uses when downloading and installing the operational subscription profile. In some examples, the SM-DP+ entity from which the operational subscription profile is downloaded is identified by the OID in the download information if the OID is that of SM-DP+ entity 150, or by the event record received by the subscriber module 1200 from SM-DS entity 160 if the OID identified by the download information is that of SM-DS entity 160. The SM-DS entity 160 is identified by the OID in the download information.

[0060] An AKA (Authentication and Key Agreement) protocol, such as UMTS-AKA, IMS-AKA, 5G AKA, or Extended Authentication Protocol-AKA, may be used to securely transfer download information while operating to authenticate the communication device 180 between the subscriber module 1200 and the eSIM server 1400 to obtain initial cellular connectivity. Thus, in some examples, the download information is obtained as part of the execution of network access authentication using the AKA protocol when establishing the initial cellular connectivity connection.

[0061] Next, refer to Figure 3, which shows a method for enabling the download and installation of an operational subscription profile to the subscriber module 1200, as executed by the eSIM server 1400 according to one embodiment.

[0062] S202: The eSIM server receives a trigger for downloading the operational subscription profile to subscriber module 1200.

[0063] S206: The eSIM server 1400 provides download information for the operational subscription profile to the subscriber module 1200 on the initial cellular connectivity connection for the communication device 180 to which the subscriber module 1200 is provided. The download information is identified so that the subscriber module 1200 can determine whether it is permitted to download the subscription profile. During the cellular network access authentication period for establishing the initial cellular connectivity connection, the eSIM server 1400 provides the subscriber module 1200 with authentication data for the subscriber module 1200 to authenticate the eSIM server 1400.

[0064] Embodiments relating to further details enabling the download and installation of operational subscription profiles to subscriber modules 1200, which are executed by eSIM server 1400, will be disclosed hereby.

[0065] The trigger obtained in S202 may take the form of network access authentication being triggered at the eSIM server 1400. Conversely, this is triggered when a subscription identifier, such as an IMSI or Network Access Identifier (NAI), is provided / received from the subscriber module 1200 via the serving network to the communication device 180 and the eSIM server 1400.

[0066] In some respects, the download information is generated or determined by the eSIM service when preparing the profile download. Therefore, in some embodiments, the eSIM server 1400 is configured to perform step S204 (optionally).

[0067] S204: The eSIM server 1400 determines the download information during the period of preparing the profile download for the operational subscription profile.

[0068] It should be noted here that step S204 may be performed either after step S202 (as shown in Figure 3) or before step S202, that is, it may be performed either after or before the trigger is obtained in S202.

[0069] As disclosed above, in some examples, the authentication data provided by the eSIM server 1400 to the subscriber module 1200 is derived using a secret shared with the subscriber module 1200 (hence, a shared secret). As disclosed above, in some examples, the transfer of download information from the eSIM server 1400 to the subscriber module 1200 over the initial cellular connectivity connection for the communication device 180 is protected using a secret shared with the subscriber module 1200. As disclosed above, in some examples, the secret shared with the subscriber module 1200 is based on the public key of the subscriber module 1200's secret-public key pair and the private key of the eSIM server 1400's secret-public key pair. As disclosed above, in some examples, the download information is securely transferred from the eSIM server 1400 to the subscriber module 1200 using the SIM OTA procedure.

[0070] As disclosed above, in some examples, the download information identifies authorization secrets for use by the subscriber module 1200 to determine whether the download of SM-DP+ information from SM-DS is permitted, in order to determine whether the download of operational subscription profiles from SM-DP+ entity 150 is permitted, and / or to identify SM-DP+ entity 150 from which the operational subscription profiles are downloaded. Determining whether the download is permitted is based on the subscriber module 1200 obtaining assurance of SM-DP+ / SM-DS knowledge of authorization secrets obtained during the profile download preparation period for the operational subscription profiles.

[0071] As disclosed above, in some examples, the download information identifies the OIDs of SM-DP+ entity 150 and / or SM-DS entity 160 that the subscriber module 1200 uses when downloading and installing the operational subscription profile. As disclosed above, in some examples, the SM-DP+ entity from which the operational subscription profile is downloaded is given by the OID identified by the download information if the OID is that of SM-DP+ entity 150, or by the event record received by the subscriber module 1200 from SM-DS entity 160 if the OID identified by the download information is that of SM-DS entity 160. SM-DS entity 160 is given by the OID identified by the download information.

[0072] As disclosed above, in some examples, download information is provided as part of the execution of network access authentication using the AKA protocol when establishing the initial cellular connectivity connection. In some examples, download information is provided in the authentication vector.

[0073] In the following example, the subscriber module 1200 will be represented by eUICC for non-limiting and illustrative purposes. However, the following example is also applicable to other types of subscriber modules 1200 already mentioned in this disclosure.

[0074] In the following examples, the communication device 180 will be represented by an IoT device for non-limiting and illustrative purposes. However, the following examples are also applicable to other types of communication devices 180 already mentioned in this disclosure. When the communication device is in the form of an IoT device, it may be a device for use in one or more application domains, which include, but are not limited to, home, urban, wearable technology, augmented reality, industrial applications, and healthcare. For illustrative purposes, IoT devices for homes, offices, buildings, or infrastructure may include baking scales, coffee machines, grills, refrigerators, freezers, microwave ovens, ovens, toasters, water taps, water heaters, hot water heaters, saunas, vacuum cleaners, washing machines, dryers, dishwashers, doors, windows, curtains, blinds, furniture, light bulbs, fans, air conditioners, coolers, air purifiers, humidifiers, speakers, televisions, laptops, personal computers, game consoles, remote controllers, vents, irons, steamers, pressure cookers, stoves, electric stoves, hair dryers, hair stylists, mirrors, printers, scanners, copiers, projectors, hologram projectors, 3D printers, drills, hand dryers, alarm clocks, clocks, security cameras, smoke detectors, fire alarms, connected doorbells, electronic door locks, lawnmowers, thermostats, plugs, irrigation control devices, water leak sensors, humidity sensors, motion detectors, weather stations, electric meters, water meters, and gas meters.

[0075] Further examples of IoT devices for use in urban, metropolitan, or suburban areas may include connected streetlights, connected traffic lights, traffic cameras, connected road signs, air control / monitoring, noise level detectors, traffic congestion monitoring devices, traffic control devices, automated toll payment devices, parking fee payment devices, parking lot usage monitoring sensors, traffic management devices, digital kiosks, trash cans, air quality monitoring sensors, bridge condition monitoring sensors, fire hydrants, manhole sensors, apron sensors, fountain sensors, connected closed-circuit televisions, scooters, hoverboards, ticket machines, ticket gates, subway rails, subway station devices, passenger information panels, in-vehicle cameras, and other connected devices on public transport vehicles.

[0076] As a further example, a communication IoT device may be a wearable device or an augmented reality-related device, and an augmented reality-related device may be an AR (augmented reality), VR (virtual reality), MR (merged reality), or MR (mixed reality) related device. Examples of such IoT devices may be smart bands, activity trackers, haptic gloves, haptic suits, smartwatches, clothing, glasses, head-mounted displays, earpods, activity monitors, fitness monitors, heart rate monitors, rings, key trackers, blood glucose meters, and pressure meters.

[0077] As a further example, an IoT device may be an industrial application device, and an industrial application device may be an industrial unmanned aerial vehicle, an intelligent industrial robot, a vehicle assembly robot, and an automated guided vehicle.

[0078] As a further example, an IoT device may be a transport vehicle, which may be a bicycle, motorbike, scooter, moped, auto rickshaw, rail transport, train, tram, bus, passenger car, truck, airplane, boat, ship, skis, snowboard, snowmobile, hoverboard, skateboard, roller skate, cargo transport vehicle, drone, robot, stratospheric aircraft, aircraft, helicopter, and hovercraft.

[0079] As a further example, an IoT device may be a health or fitness device, and a health or fitness device may be a surgical robot, an implantable medical device, a non-invasive medical device, and a stationary medical device which may be an in vitro diagnostic device, a radiological device, a diagnostic imaging device, and an X-ray device.

[0080] A general perspective on securely downloading operational subscription profiles using download information obtained via eUICC utilizing an eSIM server will be disclosed next with reference to the sequence diagram in Figure 4.

[0081] Referring to Figure 4, the procedure for an IoT device to acquire initial cellular connectivity and download its first operational subscription profile is described. The download information required for the secure download of the operational subscription profile (e.g., in the presence of malware) is determined or generated during the preparation phase for downloading the subscription profile and provided to the eUICC using the eSIM server, which is part of providing initial cellular connectivity to the IoT device.

[0082] Assuming (Step 0), the eSIM server's database contains the EID for each IoT device using that eSIM server. Each IoT device's eUICC is configured with a provisioning subscription profile from the eSIM server. That subscription profile is the active subscription profile for the eUICC at that time. The IoT device wakes up (for example, initially), leverages the provisioning subscription profile in the eUICC to connect to MNO1, performs network access authentication, and obtains initial cellular connectivity (Step 1a). Typically, roaming is used, and the eSIM server acts as the home provider and handles network access authentication. MNO1 determines the eSIM server based on the IMSI provided by the IoT device (or MNO3 if the eSIM server has an agreement with MNO3 to use a specific IMSI range).

[0083] The network access authentication performed as part of step 1a relies on a shared secret shared between the eSIM server and the provisioning subscription profile. In order to select the correct shared secret and trigger localization in step 2, the eSIM server determines the EID of the eUICC in step 1b. This may be done based on the received IMSI, for example, if the eSIM server maintains a mapping between IMSI and EID, or the EID may be transferred from the eUICC to the eSIM server during the network access authentication period (step 1b is performed in combination with step 1a).

[0084] To prepare for the download of an operational subscription profile suitable for IoT devices, the eSIM server requests localization (in step 2) to be performed by the localization server. The EID of the IoT device's eUICC, and optionally the MCC (+MNC) of MNO1 (the country / region where the IoT device is located), are also provided for use in localization. The eSIM server does not necessarily interact directly with the entity performing the localization, as shown here. The localization mechanism is performed in step 3, where the MNO that should provide the operational subscription profile is determined, which is labeled MNO2 in the diagram. The operational subscription profile from MNO2 is either prepared for download in advance (in step 4a) for all of a group of IoT devices, or the localization server interacts directly with the SM-DP+ (in step 4b) to prepare the subscription profile for download. If an SM-DS is used, an event is registered with the SM-DS.

[0085] Once the operational subscription profile is determined and prepared for download, the download information required for the secure download of the subscription profile is securely provided from the localization server to the eSIM server (step 5) and then to the eUICC (step 1c). Depending on the method used to securely transfer the download information, the transfer may occur either as part of the acquisition of initial cellular connectivity (in combination with step 1a) or after initial cellular connectivity has been acquired, utilizing that connectivity for the transfer of the download information. In the first case, steps 2-5 are performed while the establishment of initial cellular connectivity is in progress, while in the other case, these steps typically occur after initial cellular connectivity has been established.

[0086] After receiving the download information, eUICC stores the download information in the ISD-R security domain along with the help eUICC OS command for use during the download period of the operational subscription profile (Step 6). In Step 7, the modem securely downloads the operational subscription profile from the IoT device and / or from the SM-DP+ provided by the information in eUICC, with the assistance of eUICC and the retrieved download information. If an SM-DS is used, the SM-DP+ from which the subscription profile is downloaded is first securely retrieved from the SM-DS. Upon successful download, the subscription profile is installed and automatically activated. The provisioning subscription profile then uses a refresh command (Step 8), which triggers the modem to detach from the current network and discard all cached information associated with that network. The modem then attaches to the MNO2 network and gains connectivity using the newly installed and activated operational subscription profile (Step 9).

[0087] Next, with reference to the sequence diagram in Figure 5, an example will be described in which the download of the first operational subscription profile is protected using an authorization secret. The authorization secret is generated during the period when the localization server prepares the subscription profile for download and is provided to the eUICC using the eSIM server via the SIM OTA procedure.

[0088] Step 0: The eSIM server database contains the EID for each IoT device that uses the eSIM server for the bootstrap connectivity service. The eUICC for each IoT device using the service is configured with a provisioning subscription profile from the eSIM server. That subscription profile is the active subscription profile for the eUICC at that time. The eUICC is provided with a default SM-DP+ address and / or SM-DS address.

[0089] Step 1: The IoT device connects to MNO1 using an eUICC provisioning subscription profile, performs network access authentication, and obtains initial cellular connectivity. Roaming may be used, and the eSIM server acts as the home provider and handles network access authentication. MNO1 determines the eSIM server based on the IMSI provided by the IoT device (or MNO3 if the eSIM server has an agreement with MNO3 to use a specific IMSI range). Network access authentication relies on a shared secret shared between the eSIM server and the provisioning subscription profile. This shared secret may be pre-configured as part of the provisioning subscription profile, or it may be derived by the subscription module (and eSIM server) based on the eUICC secret-public key pair and the eSIM server's secret-public key pair, with the eSIM server's public key as part of the provisioning subscription profile. In the latter case, the provisioning subscription profile is configured / contains the eSIM server's public key, and the eSIM server's database contains the public key (for example, the eSIM server's database contains an eUICC certificate containing the eUICC public key) and the EID of each IoT device using the eSIM server. As is known in this field, an eUICC certificate is a certificate issued by the EUM for a particular eUICC. To select the correct key and trigger localization in step 2, the eSIM server determines the eUICC's EID. This may be done based on the IMSI, for example, by maintaining a mapping between the IMSI and the EID in the eSIM server. If the IMSI is randomly selected from the IMSI range, the EID may be transferred from the eUICC to the eSIM server during the AKA authentication period, as will be explained in more detail below. In other examples, the EID is encoded into the IMSI.For example, in the case of 5G, the EID may be transmitted (in encrypted form) as part of or together with the SUCI (Subscription Concealed Identifier).

[0090] Step 2: The eSIM server requests that localization be performed. The eUICC EID of the IoT device, and optionally the MNO1 Mobile Country Code (MCC) (the country / region where the IoT device is located), are also provided as input. The eSIM server does not necessarily interact directly with the entity performing the localization, as shown here.

[0091] Step 3: The localization mechanism is implemented, and the MNO that should provide the operational subscription profile is determined, which is labeled as MNO2 in the diagram.

[0092] Step 4: The operational subscription profile from the MNO selected in Step 4 needs to be prepared for download. A permission secret for use in preparing the operational subscription profile for download is randomly generated by the localization server.

[0093] Step 5: The localization server interacts with the SM-DP+ directly or via the MNO / CSP to prepare the subscription profile for download. The authorization secret is provided to the SM-DP+ along with the EID. If an SM-DS is used, the event is registered in the SM-DS, including the authorization secret, EID, and SM-DP+ information such as the address and matching ID. The SM-DS here is the same as the one configured in the eUICC, and if an SM-DS is not used, the SM-DP+ here is the same as the default SM-DP+ configured on the IoT device.

[0094] Step 6: The localization server provides the authorization secret to the eSIM server.

[0095] Step 7: The eSIM server provides an authorization secret to the eUICC provisioning subscription profile using the SIM OTA procedure. The shared secret between the eSIM server and the provisioning subscription profile used to secure the SIM OTA procedure may be pre-configured as part of the provisioning subscription profile, or it may be derived by the provisioning subscription profile (and the eSIM server) based on the eUICC secret-public key and the eSIM server's secret-public key pair.

[0096] Step 8: eUICC stores its authorization secret, along with the help eUICC OS command, in the ISD-R security domain for use during the download period of the operational subscription profile.

[0097] Step 9: The modem determines that eUICC is ready to download the subscription profile.

[0098] Step 10: The modem, with the assistance of eUICC, downloads the subscription profile from the default SM-DP+, during which eUICC determines that the download is permitted using the authorization secret as previously described. If an SM-DS is used, the SM-DP+ from which the subscription profile is downloaded is first securely obtained from the SM-DS, during which eUICC determines that the download of the SM-DP+ information obtained from the SM-DS is permitted using the authorization secret. Upon successful verification, the subscription profile is installed and automatically activated.

[0099] Step 11: eUICC uses a refresh command, which triggers the modem to detach from the current network and discard all cached information associated with that network.

[0100] Step 12: The modem attaches to the MNO2 network and gains connectivity using the newly installed and activated operational subscription profile.

[0101] In step 0, instead of configuring the SM-DP+ address and / or SM-DS address in the eUICC during the manufacturing or personalization period of the eUICC, the SM-DP+ address may be configured within the IoT device, e.g., the modem, during the manufacturing period of the device (or modem module). This allows for a later configuration of the SM-DP+ / SM-DS to be used during the initial subscription profile download period. Alternatively, the SM-DP+ / SM-DS address to be used may be provided in step 7 along with the authorization secret.

[0102] As a derivative of this example, the IoT device may belong to a group of IoT devices for which a set of subscription profiles is already prepared for download when the IoT device first connects. Next, refer to the sequence diagram in Figure 6 for this derivative, where an authorization secret is used.

[0103] The step group in the sequence diagram of Figure 6 is identical to the step group in the sequence diagram of Figure 5, except for the following point.

[0104] Step 1: The localization server generates authorization secrets for a group of IoT devices and stores these authorization secrets in a database.

[0105] Step 2: This step is the same as step 5 in the sequence diagram of Figure 5.

[0106] Step 3: Refer to Step 1 in the sequence diagram in Figure 5.

[0107] Step 4: The eSIM server requests the authorization secret for the EID obtained in Step 3 from the localization server.

[0108] Step 5: The localization server retrieves the authorization secret for the specific EID from its database.

[0109] Next, referring to the sequence diagram in Figure 7, an example will be described in which the initial download of the operational subscription profile is protected by verifying the information obtained from SM-DP+ and, if used, SM-DS, using the SM-DP+ / SM-DS information in the eUICC during the download period of the operational subscription profile, and determining, as previously described, that the download of the operational subscription profile is permitted. The SM-DP+ / SM-DS information is selected by the communication device using unsigned download and installation data in the device that points to the SM-DS or SM-DP+ information in the eUICC. This SM-DS / SM-DP+ information defines the download information, is determined during the period when the localization server prepares the subscription profile for download, and is provided to the eUICC using the eSIM server via the SIM OTA procedure. In cases where SM-DP+ information is provided, that information may also include a matching ID.

[0110] The step group in the sequence diagram of Figure 7 is identical to the step group in the sequence diagram of Figure 5, except for the following point.

[0111] Step 0: The eSIM server database contains the EID for each IoT device that uses that eSIM server. The eUICC for each IoT device using the service is configured with a provisioning subscription profile from the eSIM server provider. That subscription profile is the active subscription profile for the eUICC at that time.

[0112] Step 4: Step 4 in the sequence diagram of Figure 5 is not performed in the sequence diagram of Figure 7.

[0113] Step 6: SM-DP+ or SM-DS information is returned from the localization server to the eSIM server. This information consists of the SM-DP+ / SM-DS OID and possibly its address. If SM-DP+ information is provided, it may also include a matching ID that identifies the subscription profile for download in the SM-DP+. Alternatively, an ICCID may be used to uniquely identify the subscription profile.

[0114] Step 7: The eSIM server provides SM-DP+ / SM-DS information to the eUICC provisioning subscription profile using the SIM OTA procedure. The shared secret between the eSIM server and the provisioning subscription profile used to secure the SIM OTA procedure may be pre-configured as part of the provisioning subscription profile, or it may be derived by the provisioning subscription profile (and the eSIM server) based on the eUICC secret-public key and the eSIM server's secret-public key pair.

[0115] Step 8: eUICC stores its SM-DP+ / SM-DS information, along with help eUICC OS commands, in the ISD-R security domain for use during the download period of the operational subscription profile.

[0116] Step 10: The modem, with the assistance of eUICC, downloads the subscription profile from the SM-DP+. During this process, eUICC uses the SM-DP+ / SM-DS information within the eUICC to verify the information obtained from the SM-DP+ / SM-DS during the download of the operational subscription profile. If an SM-DS is used, the SM-DP+ from which the subscription profile is downloaded is first securely obtained from the SM-DS. To prevent the download, installation, and activation of unauthorized subscription profiles, the information obtained from the SM-DP+ and the IoT device is verified by eUICC using the SM-DP+ information. For example, the OID, address, and matching identifier of the SM-DP+ provided to eUICC are checked against the information obtained in Step 7. If the matching is successful, the subscription profile is downloaded, installed, and automatically activated.

[0117] The derivative of Figure 6, in which an IoT device belongs to a group of IoT devices for which a set of operational subscription profiles is already prepared for download when the IoT device first connects, is also applicable when the download of the subscription profile is protected using SM-DP+ / SM-DS information stored in eUICC, which is used to verify the information obtained from SM-DP+ / SM-DS during the period of downloading the operational subscription profile, in which case the SM-DP+ / SM-DS information is obtained by eUICC via the SIM OTA procedure.

[0118] Next, referring to the sequence diagram in Figure 8, an example will be described in which the initial download of the operational subscription profile is protected by determining whether the download of the operational subscription profile is permitted using an authorization secret, as previously explained, in which the authorization secret is generated by the localization server during the subscription profile download preparation period and provided to the eUICC using the eSIM server. In this example, the authorization secret is transmitted as part of the execution of the AKA protocol.

[0119] The transfer of authorization secrets to eUICC is performed as part of establishing initial cellular connectivity for IoT devices.

[0120] Step 0: Refer to Step 0 in the sequence diagram in Figure 5.

[0121] Step 1: To attach to the network during the initial wake-up of the IoT device, the device's modem reads the IMSI from eUICC.

[0122] Step 2: The eUICC provisioning subscription profile provides the IMSI to the modem. The provisioning subscription profile may be unique to each IoT device and may be configured with a unique IMSI, which is then returned. Alternatively, a common provisioning subscription profile may be used for a large set of IoT devices. This subscription profile may contain one or more IMSI ranges, from which the provisioning subscription profile randomly selects the IMSI to use. Another alternative is that the provisioning subscription profile uses an IMSI range where the MCC+MNC numbers and possibly a few more numbers are fixed (pre-configured in the provisioning subscription profile), and the remaining IMSI numbers are derived from the eUICC EID. For example, the remaining numbers may be assigned as a truncated SHA-256 hash of the EID. The EID is obtained by the subscription profile using the eUICC OS functionality.

[0123] Step 3: The modem scans for available networks to attach to. Using MCC+MNC from the IMSI, the modem analyzes the available networks and determines MNO1 as the appropriate one. The modem then requests to attach to the selected network.

[0124] Step 4: An identity request is provided from the network.

[0125] Step 5: The modem provides the IMSI in response.

[0126] Step 6: MNO1 analyzes the IMSI to determine the home mobile network.

[0127] Step 7: A roaming request is made to the home network. The home network is either an eSIM server acting as an MVNO, or another mobile network operator (MNO3) whose IMSI range to which the IMSI belongs is handled by the eSIM server. The eSIM server then controls an HSS or similar entity.

[0128] Step 8: The eSIM server determines the EID of the IoT device's eUICC. In one proposal, this is done based on the received IMSI, using a pre-configured mapping between IMSIs and EIDs and the EIDs stored in the eSIM server's database. For example, if a unique IMSI is used for each provisioning subscription profile, or if the provisioning subscription profile encodes the EID into an IMSI, such a database may be used. When encoding an EID into an IMSI, there may be multiple EIDs encoded into the same IMSI, resulting in multiple valid entries in the database. How frequently such collisions occur depends on the size of the IMSI range and the number of IoT devices using the service at that time. In the case of a collision, the provisioning subscription profile must provide the eSIM server with the full EID value. This may be done via the AKA protocol, which will be further explained below. Also, if in Step 2 the IMSI is randomly selected from the range of IMSIs by the provisioning subscription profile, the EID is transferred to and from the eSIM server via the AKA protocol.

[0129] Step 9: Refer to Step 2 of the sequence diagram in Figure 5.

[0130] Step 10: Refer to step 3 of the sequence diagram in Figure 5.

[0131] Step 11: Refer to step 4 of the sequence diagram in Figure 5.

[0132] Step 12: Refer to Step 5 in the sequence diagram in Figure 5.

[0133] Step 13: Refer to step 6 in the sequence diagram in Figure 5.

[0134] Step 14: Network access authentication is performed using AV in accordance with the AKA procedure, based on the cellular technology used (with minor variations depending on the generation of the 3GPP cellular network). The eUICC provisioning subscription profile and the eSIM server's HSS use the modified behavior described below, however, this behavior is transparent to the visited network (MNO1), and the data and message format conforms to the cellular standards used. As part of network access authentication, the eUICC provisioning subscription profile obtains an authorization secret.

[0135] Step 14: Refer to step 8 in the sequence diagram in Figure 5.

[0136] Step 15: Refer to step 9 in the sequence diagram in Figure 5.

[0137] Step 16: Refer to step 10 in the sequence diagram in Figure 5.

[0138] Step 17: Refer to step 11 in the sequence diagram in Figure 5.

[0139] Step 18: Refer to step 12 in the sequence diagram in Figure 5.

[0140] Next, an example of the transfer of authorization secrets from the eSIM server to the provisioning protocol using the AKA protocol will be disclosed, with reference to the sequence diagram in Figure 9. This example is based on step 14 in Figure 8.

[0141] The authorization secret is transferred as part of the authentication vector prepared by the sSIM server. Both encryption and integrity protection are performed on the authorization secret during transfer. The keys used for encryption and integrity protection are derived from a secret shared between the provisioning subscription profile and the eSIM server. Preferably, the shared secret is an ECDH shared secret derived from the eUICC secret-public key pair and the eSIM server's secret-public key pair for use with the eSIM. The eSIM server's HSS stores the eSIM server's private key and retrieves the eUICC public key needed to compute the shared secret from the eUICC certificate stored in its database, corresponding to the EID determined in step 8 of Figure 8. The eUICC stores the eSIM server's public key and derives the shared secret using the eUICC OS function, using the eUICC private key and the stored eSIM server's public key. Alternatively, the provisioning subscription profile can hold a global secret from which the eUICC-specific shared secret can be derived using the EID.

[0142] To make the encryption key and MAC key session-dependent, these keys are derived from a shared secret (ECDH, or derived from a global secret) and a seed. As the seed, a random value or a challenge transmitted as RAND as part of the authentication vector can be used. The RAND is concatenated with a string such as "NAA" (see below) which is used to derive separate keys for different purposes. For example, the ANSI-16.63-KDF algorithm may be used for key derivation. The encryption algorithm and MAC algorithm used for encryption and integrity protection of the IMSI may be, for example, the AES and HMAC-SHA-256 algorithms, respectively. The MAC algorithm may instead be the f1 function of Milenage, in which case it is replaced by SQN and AMF, given the IMSI and a set of flags as input. The following substeps of step 14 are performed, in which the authentication vector is first generated and then the AKA protocol is executed.

[0143] Step 14a: The eSIM server's HSS generates a random value RAND for use in authentication.

[0144] Step 14b: The eSIM server derives the cryptographic keys K_enc and K_mac using RAND and the shared secret (derived from ECDH, or the global secret) as described above. In addition, provisional values ​​for Ki and OPc, denoted as Ki_tmp and OPc_tmp, are derived (using the same key derivation method) for use in network access authentication. In other words, the shared secret is derived using the public key of eUICC and the private key of the eSIM bootstrap connectivity service.

[0145] Step 14c: The authorization secret is encrypted using K_enc and its integrity is protected by calculating the MAC using K_mac on the encrypted data. The concatenation of the encrypted data and the MAC forms the AUTN value of the authentication vector. AUTN = (encrypted data | MAC)

[0146] Step 14d: Using RAND, Ki_tmp, and OPc_tmp as inputs, the values ​​of XRES, CK, and IK are calculated according to a standard network access authentication algorithm.

[0147] Step 14e: The authentication vector (RAND, AUTN, XRES, CK, IK) is transmitted from the eSIM server to the visited mobile network (i.e., MNO1).

[0148] Step 14f: The visited network sends RAND and AUTN as an authentication challenge to the IoT device's modem.

[0149] Step 14g: The modem invokes the eUICC authentication command, and RAND and AUTN are provided.

[0150] Step 14h: eUICC derives the shared secret according to the above, and derives K_enc, K_mac, Ki_tmp and OPc_tmp according to the above description.

[0151] Step 14i: eUICC extracts the MAC from AUTN and verifies the MAC using K_mac. If MAC verification is successful, the encrypted data of AUTN is extracted and decrypted to obtain the authorization secret.

[0152] Step 14j: eUICC uses RAND, Ki_tmp, and OPc_tmp as inputs to calculate RES, CK, and IK according to a standard network access authentication algorithm.

[0153] Step 14k: RES, CK, and IK are provided as responses to the authentication command.

[0154] Step 14l: The modem returns an RES to the visited network in response to the authentication challenge.

[0155] Step 14m: The visited network verifies that RES is equal to XRES, and if they are equal, authentication is successful.

[0156] The size of the authorization secret is variable and may be, for example, 64 bits. The size of the AUTN parameter may be 128 bits. Encryption may be performed using the AES encryption algorithm, for example, as follows: First, encrypted data is obtained by encrypting a string (e.g., "AUTN") using K_enc, the result is truncated to the size of the data to be encrypted (e.g., 64 bits), and then an exclusive OR or operation (XOR) is applied between the truncated result and the data to be encrypted. If the final size is 64 bits, this can be represented in pseudocode as follows: E(authorization secret)=(authorization secret) XOR E("AUTN")_trunc

[0157] The MAC portion of the AUTN can be represented in 64 bits, for example, based on HMAC-SHA-256 and 64-bit truncation using K_mac. As an example, a complete 128-bit AUTN would then consist of a 64-bit encrypted authorization secret followed by a 64-bit MAC.

[0158] For example, if a larger authorization secret, such as 128 bits, is used, the first part may be sent in the first AUTN, and the provisioning subscription profile, even if it successfully receives the first part, signals a synchronization error and performs a new authentication using a new authentication vector (with a new RAND), in which the second part of the authorization secret is transferred to the provisioning subscription profile. This principle can be adapted to accommodate even larger authorization secrets.

[0159] Next, referring to the sequence diagram in Figure 10, an example will be described in which an IMSI is randomly selected according to the provisioning subscription profile and the EID is transferred to the eSIM server via the AKA protocol. Step 8 in Figure 8 for this specific case is detailed in Figure 10.

[0160] Step 8a: The eSIM server's HSS generates a random value RAND for use in the AKA protocol.

[0161] Step 8b: The eSIM server derives the encryption key K_enc using the RAND and the global secret shared with the provisioning subscription profile. In addition, provisional values ​​for Ki (subscriber key) and OPc (key derived from Ki and the carrier code as input), denoted as Ki_tmp and OPc_tmp, are derived (using the same key derivation method) for use in network access authentication.

[0162] Step 8c: Using RAND, Ki_tmp, and OPc_tmp as inputs, the values ​​of the authentication token (AUTN), expected response (XRES), cryptographic key (CK), and integrity key (IK) are calculated according to a standard network access authentication algorithm.

[0163] Step 8d: The authentication vector (RAND, AUTN, XRES, CK, IK) is transmitted from the eSIM server to the destination mobile network (MNO1).

[0164] Step 8e: The visited network sends RAND and AUTN as an authentication challenge to the IoT device's modem.

[0165] Step 8f: The modem invokes the eUICC authentication command, and RAND and AUTN are provided.

[0166] Step 8g: The provisioning subscription profile derives K_enc, Ki_tmp, and OPc_tmp using RAND and the shared secret.

[0167] Step 8h: The provisioning subscription profile verifies AUTN using RAND, Ki_tmp, and OPc_tmp.

[0168] Step 8i: If verification is successful, the EID is encrypted using K_enc, and the encrypted data is formatted into an AUTS message.

[0169] Step 8j: The provisioning subscription profile enables signaling of synchronization errors by eUICC and provides AUTS in response to the request in Step 8f.

[0170] Step 8k: The modem responds to the visitor network with a synchronization error and provides AUTS.

[0171] Step 8i: The visitor network responds to the eSIM server with a synchronization error and provides AUTS.

[0172] Step 8m: The eSIM server decrypts the encrypted portion of AUTS using K_enc derived in Step 8b to obtain the EID.

[0173] In other words, AUTS is used here for the transfer / retrieval of the EID, and does not indicate a true synchronization error, even though step 8i above mentions that a synchronization error will be signaled.

[0174] The EID can be represented by a 32-digit number. One possibility for encoding the EID is to group three digits together and encode them as a 10-bit number between 0 and 999. Then, a 32-digit EID can be represented by a 110-digit number, but since the last two digits of the EID are check digits, a 30-digit number (100 bits) is sufficient. The size of the AUTS parameter may be 112 bits. Encryption may be performed using the AES encryption algorithm, for example, as follows: First, encrypted data is obtained by encrypting a string (e.g., "AUTS" for the EID) using K_enc, the result is truncated to the size of the data to be encrypted, and then an XOR operation is performed between the truncated result and the data to be encrypted. If the final size is 100 bits, this can be represented in pseudocode as follows: E(EID)=EID XOR E("AUTS")_trunc

[0175] For example, a complete 112-bit AUTS could take the form of a 100-bit encrypted EID followed by 12 random bits.

[0176] The shared secret used to derive K_enc may be a static, global secret between the provisioning subscription profile and the eSIM server. Even if RAND is used to make the K_enc derive session-specific, it would still be preferable to use a session-specific key to derive the shared secret. In the case of 5G cellular connectivity and SUCI use, the eSIM server's secret-public key pair and a temporary key pair generated by eUICC for SUCI protection may be used to establish an ECDH shared secret from which K_enc can be derived.

[0177] Next, the perspective of IMSI collisions will be disclosed. MAC verification in step 14i of Figure 9 can fail for various reasons. One reason is an IMSI collision, which should be very rare, in the case where the EID is encoded to an IMSI. For IMSIs, a collision means that in the eSIM server's database there is at least one EID that has the same IMSI as the one determined for eUICC in step 8 of Figure 8, and the eSIM server's HSS has selected the wrong entry (i.e., the wrong EID) in the database. This results in the derivation of an incorrect shared secret, and MAC verification fails. In this case, the provisioning subscription profile needs to send its own EID to the eSIM server. Another reason for MAC failure is that there has been some change in the value of AUTN during the transfer. The provisioning server cannot distinguish between these two cases and therefore will always provide an EID in the case of MAC failure.

[0178] The eSIM server will know that if there is an IMSI collision, there is a risk that the wrong EID may have been selected. In the case of an IMSI collision, there are more entries in the eSIM server's database than one that matches the IMSI in step 8 of Figure 8. Localization procedures may help in selecting the correct EID (correct entry). A localization rule may be that a given range of EIDs belongs to an IoT device from a certain company that is eligible for a set of countries where the IoT device may be deployed, based on a pre-negotiated MNO contract. For example, suppose an IoT device connects via a destination network in a certain country, and there are two possible EIDs inferred from the IMSI. However, according to the localization rule, only one of those EIDs is within the range of EIDs from a company that is eligible for localization to the MNO in the particular country in question, and this means that the EID will be selected.

[0179] Depending on the relationship between the eSIM server and the localization server, localization may be utilized in the selection of the EID. Next, refer to the sequence diagram in Figure 10 where a collision occurs.

[0180] Step 8: There are more than one entries (i.e., more than one EID) in the database that match the received IMSI.

[0181] Step 9: The entire list of possible EIDs is provided to the localization server in the localization request.

[0182] Step 10: The localization server performs localization and determines the MNO.

[0183] Step 11: The localization server selects an appropriate EID from the list to be used to generate an authorization secret.

[0184] Steps 12a, 12b: The operational subscription profile is prepared for download for the selected EID (referred to as EID1).

[0185] Step 13: The authorization secret is provided from the localization server to the eSIM server.

[0186] Step 14: The eSIM server executes the AKA protocol (according to steps 14a-14h in Figure 8), in which the authorization secret is transferred to the provisioning subscription profile. A MAC failure occurs (as in step 14i in Figure 9), and the EID is returned to the eSIM server in an AUTS format message (in encrypted form) (the steps corresponding to steps 8i-8m in Figure 9 are executed). Re-localization is requested from the localization server. Steps 9-13 are repeated with a new EID (called EID2) received from eUICC, a new authorization secret is generated, and it is returned to the eSIM server. Then, according to steps 14 (as detailed in Figure 8) and 15, the authorization secret is transmitted to the provisioning subscription profile and stored in the ISD-R. A new authentication vector is generated with a new RAND.

[0187] Using the SIM OTA procedure to securely transfer information to the eUICC allows for the provision of more information than when using the AKA protocol. For example, in the example disclosed with reference to Figures 5 and 6, the eUICC does not need to have a default SM-DP+ address. The address to SM-DP+ (or to SM-DS if the applicable option is used) can be provided to the eUICC using the SIM OTA procedure, along with the authorization secret.

[0188] SM-DP+ / SM-DS OIDs are typically small enough to be provided using the AKA protocol. For example, an SM-DS OID may be securely provided to the eUICC using the AKA protocol. As long as the SM-DS address is configured for use by the IPA, for example, by being set up in the IoT device during the manufacturing period, a secure subscription profile download can be performed, in which case the eUICC will use the SM-DS information within the eUICC to verify the information obtained from the SM-DS during the download period of the operational subscription profile. Similarly, an SM-DP+ OID may be provided to the eUICC over the AKA protocol, for example, in combination with an ICCID. As long as the SM-DP+ address is configured for use by the IPA, a secure operational subscription profile download can be performed by verifying the information obtained from the SM-DP+ during the download period of the profile.

[0189] As already mentioned above, the SIM OTA procedure has fewer constraints on the size of information that can be transferred from the eSIM server to the eUICC compared to using the AKA protocol. On the other hand, the SIM OTA procedure relies on the use of Short Message Service (SMS) messages or HTTPS as the information bearer, which suggests that the SIM OTA procedure may not be suitable for low-power IoT devices connected on LPWA networks such as narrowband (NB) IoT networks. Using the AKA protocol for information transfer is possible for all IoT devices that support the required protocol. Furthermore, to address low-power IoT devices, in addition to HTTPS over TCP (Transmission Control Protocol), CoAP (Constrained Application Protocol) over DTLS (Datagram Transport Layer Security) over UDP (User Datagram Protocol) can be used, thereby making the SIM OTA procedure usable for low-power IoT devices as well.

[0190] Figure 12 schematically shows the components of a subscriber module 1200 according to one embodiment in terms of several functional units. The processing circuit 1210 is provided using one or more arbitrary combinations of a suitable CPU (central processing unit), multiprocessor, microcontroller, DSP (digital signal processor), etc., capable of executing a set of software instructions stored in a computer program product 1610a (as in Figure 16) in the form of a storage medium 1230. The processing circuit 1210 may further be provided as at least one ASIC (application specific integrated circuit) or FPGA (field programmable gate array).

[0191] Specifically, the processing circuit 1210 is configured to cause the subscriber module 1200 to perform the set of operations or steps disclosed above. For example, the storage medium 1230 may store the set of operations, and the processing circuit 1210 may be configured to read the set of operations from the storage medium 1230 and cause the subscriber module 1200 to perform that set of operations. The set of operations may be provided as a set of executable instructions. Thus, the processing circuit 1210 is configured to perform the method disclosed herein.

[0192] The storage medium 1230 may also include persistent storage, which may be any one or combination of magnetic memory, optical memory, solid-state memory, or remotely mounted memory.

[0193] The subscriber module 1200 may further include a communication interface 1220 for communication with other entities, functions, nodes, and devices, as shown in Figure 1. Therefore, the communication interface 1220 may include one or more transmitters and receivers, including analog and digital components.

[0194] The processing circuit 1210 controls the overall operation of the subscriber module 1200 by, for example, transmitting data and control signals to the communication interface 1220 and the storage medium 1230, receiving data and reports from the communication interface 1220, and reading data and command sets from the storage medium 1230. Other components and related functionalities of the subscriber module 1200 are omitted to avoid ambiguity of the concepts presented herein.

[0195] Figure 13 schematically shows the components of a subscriber module 1200 according to one embodiment in terms of several functional modules. The subscriber module 1200 in Figure 13 comprises several functional modules, such as an acquisition module 1210a configured to perform step S102, a download module 1210b configured to perform step S104, and an installation module 1210c configured to perform step S106. The subscriber module 1200 in Figure 13 may further comprise a number of optional functional modules, such as an activation module 1210d configured to perform step S108. Generally speaking, each functional module 1210a:1210d can be implemented in hardware or software. Preferably, one or more or all of the functional modules 1210a:1210d may be implemented by a processing circuit 1210 that possibly works with a communication interface 1220 and / or a storage medium 1230. The processing circuit 1210 may therefore be configured to retrieve the instruction sets provided by the function modules 1210a:1210d from the storage medium 1230 and execute those instruction sets, thereby executing any set of steps of the subscriber module 1200 as disclosed herein.

[0196] Figure 14 schematically shows the components of an eSIM server 1400 according to one embodiment in terms of several functional units. The processing circuit 1410 is provided using one or more arbitrary combinations of a suitable CPU (central processing unit), multiprocessor, microcontroller, DSP (digital signal processor), etc., capable of executing a set of software instructions stored in a computer program product 1610b in the form of a storage medium 1430 (as shown in Figure 16). The processing circuit 1410 may further be provided as at least one ASIC (application specific integrated circuit) or FPGA (field programmable gate array).

[0197] Specifically, the processing circuit 1410 is configured to cause the eSIM server 1400 to perform the set of operations or steps disclosed above. For example, the storage medium 1430 may store the set of operations, and the processing circuit 1410 may be configured to read the set of operations from the storage medium 1430 and cause the eSIM server 1400 to perform that set of operations. The set of operations may be provided as a set of executable instructions. In this way, the processing circuit 1410 is configured to perform the method disclosed herein.

[0198] The storage medium 1430 may also include persistent storage, which may be any one or combination of magnetic memory, optical memory, solid-state memory, or remotely mounted memory.

[0199] The eSIM server 1400 may further include a communication interface 1420 for communication with other entities, functions, nodes, and devices, as shown in Figure 1. Therefore, the communication interface 1420 may include one or more transmitters and receivers, including analog and digital components.

[0200] The processing circuit 1410 controls the overall operation of the eSIM server 1400, for example, by transmitting data and control signals to the communication interface 1420 and the storage medium 1430, by receiving data and reports from the communication interface 1420, and by reading data and command sets from the storage medium 1430. Other components and related functionalities of the eSIM server 1400 are omitted to avoid ambiguity of the concepts presented herein.

[0201] Figure 15 schematically shows the components of an eSIM server 1400 according to one embodiment in terms of several functional modules. The eSIM server 1400 in Figure 15 may further comprise a number of functional modules, such as an acquisition module 1410a configured to perform step S202 and a providing module 1410c configured to perform step S206. The eSIM server 1400 in Figure 15 may further comprise a number of optional functional modules, such as a determination module 1410b configured to perform step S204. Generally speaking, each functional module 1410a:1410c can be implemented in hardware or software. Preferably, one or more or all of the functional modules 1410a:1410c may be implemented by processing circuits 1410 that possibly cooperate with a communication interface 1420 and / or a storage medium 1430. The processing circuit 1410 may therefore be configured to retrieve the instruction set provided by the function modules 1410a:1410c from the storage medium 1430 and execute that instruction set, thereby executing any set of steps of the eSIM server 1400 as disclosed herein.

[0202] Figure 16 shows an example of computer program products 1610a, 1610b including a computer-readable means 1630. The computer-readable means 1630 can store a computer program 1620a, which can cause entities and devices, such as a processing circuit 1210 and a communication interface 1220 and storage medium 1230 operably connected thereto, to execute the methods according to the embodiments described herein. The computer program 1620a and / or computer program product 1610a may thus provide means for executing any set of steps of the subscriber module 1200 as disclosed herein. The computer-readable means 1630 can store a computer program 1620b, which can cause entities and devices, such as a processing circuit 1410 and a communication interface 1420 and storage medium 1430 operably connected thereto, to execute the methods according to the embodiments described herein. Computer program 1620a and / or computer program product 1610a may thus provide means for executing any set of steps of the eSIM server 1400 as disclosed herein.

[0203] In the example in Figure 16, computer program products 1610a and 1610b are shown as optical discs such as CDs (compact discs), DVDs (digital versatile discs), or Blu-ray discs. Computer program products 1610a and 1610b may also be embodied as non-volatile storage media in external memory devices, such as RAM (random access memory), ROM (read-only memory), EPROM (erasable programmable read-only memory), or EEPROM (electrically erasable programmable read-only memory), or more specifically, as flash memory such as USB (Universal Serial Bus) memory or CompactFlash memory. Therefore, although computer programs 1620a and 1620b are schematically shown here as tracks on the optical discs depicted, computer programs 1620a and 1620b can be stored by any method suitable for computer program products 1610a and 1610b.

[0204] The concept of the invention has been described above, primarily with reference to a few embodiments. However, as will be readily apparent to those skilled in the art, other embodiments not disclosed above are equally possible within the scope of the concept of the invention as defined by the claims.

Claims

1. A method for downloading and installing an operational subscription profile, performed by a subscriber module (1200), wherein the subscriber module is provided to a communication device (180), the subscriber module is provided with subscription data for use in establishing initial cellular connectivity, and the method is: S102) Obtaining download information for the operational subscription profile from the eSIM server (1400) over the initial cellular connectivity connection for the communication device (180), wherein the download information is used by the subscriber module when determining whether the subscriber module is permitted to download the subscription profile, and during the cellular network access authentication period for establishing the initial cellular connectivity connection, the subscriber module authenticates the eSIM server using the subscription data. Downloading the operational subscription profile from the Extended Subscription Manager Data Preparation (SM-DP+) entity (150) according to the download information (S104), wherein the operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device (180), Installing the operational subscription profile on the subscriber module (1200) (S106), Methods that include...

2. The method according to claim 1, wherein the method further comprises: In response to the installation of the operational subscription profile, the operational subscription profile in the subscriber module (1200) is activated (S108). Methods that include...

3. A method according to claim 1, wherein the authentication of the eSIM server (1400) is performed using a secret shared with the eSIM server, which is contained in or can be derived from the subscription data.

4. A method according to claim 3, wherein the subscription data is contained in a provisioning subscription profile installed within the subscriber module (1200).

5. A method according to claim 3, wherein the subscription data is contained as part of the operating system of the subscriber module, and if no subscription profile is installed in the subscriber module, the subscriber module (1200) uses the subscription data to behave as if a provisioning profile exists for the communication device (180).

6. A method according to claim 1, wherein a secret shared with the eSIM server (1400) to protect the transfer of the download information from the eSIM server to the subscriber module (1200) over the initial cellular connectivity connection for the communication device (180) is contained in or can be derived from the subscription data.

7. A method according to claim 3 or 6, wherein the secret shared with the eSIM server (1400) is derivable from the subscription data based on the private key of the private-public key pair of the subscriber module (1200) and the public key of the private-public key pair of the eSIM server, the public key of the private-public key pair of the eSIM server being part of the subscription data.

8. A method according to claim 1, wherein the downloaded information is securely transferred from the eSIM server (1400) to the subscriber module (1200) using a SIM OTA procedure.

9. A method according to claim 1, wherein the download information identifies an authorization secret used by the subscriber module (1200) to determine whether the download of SM-DP+ information from a Subscription Manager Discovery Service (SM-DS) entity (160) is permitted, to determine whether the download of the operational subscription profile from the SM-DP+ entity (150) is permitted for the subscriber module and / or to identify the SM-DP+ entity from which the operational subscription profile is downloaded, and the determination that the download is permitted is based on the subscriber module obtaining assurance of knowledge of the SM-DP+ / SM-DS of the authorization secret acquired during the profile download preparation period for the operational subscription profile.

10. A method according to claim 1, wherein the downloaded information identifies the object identifiers (OIDs) of the SM-DP+ entities (150) and / or SM-DS entities (160) used by the subscriber module (1200) when downloading and installing the operational subscription profile.

11. A method according to claim 10, wherein the SM-DP+ entity (150), which is the source of the download of the operational subscription profile, is provided by the OID identified by the download information if the OID is that of the SM-DP+ entity, or by an event record received by the subscriber module (1200) from the SM-DS entity (160) if the OID identified by the download information is that of the SM-DS entity, and the SM-DS entity is provided by the OID identified by the download information.

12. A method according to claim 1, wherein the downloaded information is obtained as part of the execution of network access authentication using the AKA protocol when establishing the initial cellular connectivity connection.

13. A method for enabling the download and installation of an operational subscription profile to a subscriber module (1200), which is performed by an eSIM server (1400), wherein the method is: (S202) Obtaining a trigger for downloading the operational subscription profile to the subscriber module, To the subscriber module, download information for the operational subscription profile is provided on the initial cellular connectivity connection for the communication device (180) to which the subscriber module is provided (S206). Includes, The download information is identified for the subscriber module to determine whether the subscriber module is permitted to download a subscription profile, and during the period of cellular network access authentication to establish the initial cellular connectivity connection, the eSIM server (1400) provides the subscriber module (1200) with authentication data for the subscriber module to authenticate the eSIM server.

14. The method according to claim 13, wherein the method further comprises: During the period for preparing the profile download for the aforementioned operational subscription profile, the download information is determined (S204). Methods that include...

15. A method according to claim 13, wherein the authentication data provided to the subscriber module by the eSIM server (1400) is derived using a secret shared with the subscriber module.

16. A method according to claim 13, wherein the transfer of the download information from the eSIM server (1400) to the subscriber module (1200) over the initial cellular connectivity connection for the communication device (180) is protected using a secret shared with the subscriber module.

17. A method according to claim 15 or 16, wherein the secret shared with the subscriber module is based on the public key of the secret-public key pair of the subscriber module (1200) and the private key of the secret-public key pair of the eSIM server (1400).

18. A method according to claim 13, wherein the downloaded information is securely transferred from the eSIM server (1400) to the subscriber module (1200) using a SIM OTA procedure.

19. A method according to claim 13, wherein the download information identifies a authorization secret for use by the subscriber module (1200) to verify that the download of the operational subscription profile from an Extended Subscription Manager Data Preparation (SM-DP+) entity (150) is permitted for the subscriber module, and / or that the subscriber module is permitted to obtain SM-DP+ information from a Subscription Manager Discovery Service (SM-DS) entity (160) that identifies the SM-DP+ entity from which the operational subscription profile is downloaded, wherein the verification is based on the subscriber module having assurance that the SM-DP+ entity and / or the SM-DS entity have knowledge of the authorization secret obtained during the period of profile download preparation for the operational subscription profile.

20. A method according to claim 13, wherein the download information identifies object identifiers (OIDs) of SM-DP+ entities (150) and / or SM-DS entities (160) for use by the subscriber module (1200) when downloading and installing the operational subscription profile.

21. A method according to claim 20, wherein the SM-DP+ entity (150), which is the source of the download of the operational subscription profile, is provided by the OID identified by the download information if the OID is that of the SM-DP+ entity, or by an event record received by the subscriber module (1200) from the SM-DS entity (160) if the OID identified by the download information is that of the SM-DS entity, and the SM-DS entity is provided by the OID identified by the download information.

22. A method according to claim 13, wherein the downloaded information is provided as part of the execution of network access authentication using the AKA protocol when establishing the initial cellular connectivity connection.

23. A method according to claim 22, wherein the download information is provided in the authentication vector.

24. A subscriber module (1200) for downloading and installing an operational subscription profile, wherein the subscriber module is provided to a communication device (180), the subscriber module is provided with subscription data for use in establishing initial cellular connectivity, the subscriber module comprises a processing circuit (1210), the processing circuit provides the subscriber module, The process involves obtaining download information for the operational subscription profile from the eSIM server (1400) over the initial cellular connectivity connection for the communication device, wherein the download information is used by the subscriber module when determining whether the subscriber module is permitted to download the subscription profile, and during the cellular network access authentication period for establishing the initial cellular connectivity connection, the subscriber module authenticates the eSIM server using the subscription data. Downloading the operational subscription profile from the Extended Subscription Manager Data Preparation (SM-DP+) entity (150) according to the download information, wherein the operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device (180), Installing the operational subscription profile on the subscriber module, A subscriber module (1200) configured to perform the following actions.

25. A subscriber module (1200) for downloading and installing an operational subscription profile, wherein the subscriber module is provided to a communication device (180), the subscriber module is provided with subscription data for use in establishing initial cellular connectivity, and the subscriber module An acquisition module (1210a) configured to acquire download information for the operational subscription profile from an eSIM server (1400) over an initial cellular connectivity connection for the communication device (180), wherein the download information is used by the subscriber module when determining whether the subscriber module is permitted to download the subscription profile, and the subscriber module authenticates the eSIM server using the subscription data during the cellular network access authentication period for establishing the initial cellular connectivity connection. A download module (1210b) configured to download the operational subscription profile from an Extended Subscription Manager Data Preparation (SM-DP+) entity (150) according to the download information, wherein the operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device, and the download module An installation module (1210c) configured to install the operational subscription profile on the subscriber module, A subscriber module (1200) is provided with the following:

26. A subscriber module (1200) according to claim 24 or 25, further configured to perform the method described in any one of claims 2 to 12.

27. An eSIM server (1400) for enabling the download and installation of an operational subscription profile to a subscriber module (1200), wherein the eSIM server comprises a processing circuit (1410), and the processing circuit provides the eSIM server with To obtain a trigger for downloading the said operational subscription profile to the said subscriber module, To the subscriber module, download information for the operational subscription profile is provided over the initial cellular connectivity connection for the communication device (180) to which the subscriber module is provided. It is configured to perform the following: The download information is identified so that the subscriber module can determine whether it is permitted to download a subscription profile, and during the period of cellular network access authentication to establish the initial cellular connectivity connection, the eSIM server provides the subscriber module with authentication data for the subscriber module to authenticate the eSIM server. eSIM server (1400).

28. An eSIM server (1400) for enabling the download and installation of an operational subscription profile to a subscriber module (1200), wherein the eSIM server is A retrieval module (1410a) configured to obtain a trigger for downloading the operational subscription profile to the subscriber module, A providing module (1410c) configured to provide download information for the operational subscription profile to the subscriber module on the initial cellular connectivity connection for the communication device (180) to which the subscriber module is provided, Equipped with, The download information is identified so that the subscriber module can determine whether it is permitted to download a subscription profile, and during the period of cellular network access authentication to establish the initial cellular connectivity connection, the eSIM server provides the subscriber module with authentication data for the subscriber module to authenticate the eSIM server. eSIM server (1400).

29. An eSIM server (1400) according to claim 27 or 28, further configured to perform the method described in any one of claims 14 to 23.

30. A computer program (1620a) for downloading and installing an operational subscription profile, wherein the computer program includes computer code, which, when executed on the processing circuit of a subscriber module (1200) provided to a communication device (180) and provided with subscription data for use in establishing initial cellular connectivity, the computer code provides the subscriber module The process involves obtaining download information for the operational subscription profile from the eSIM server (1400) over the initial cellular connectivity connection for the communication device, wherein the download information is used by the subscriber module when determining whether the subscriber module is permitted to download the subscription profile, and during the cellular network access authentication period for establishing the initial cellular connectivity connection, the subscriber module authenticates the eSIM server using the subscription data. Downloading the operational subscription profile from the Extended Subscription Manager Data Preparation (SM-DP+) entity (150) according to the download information, wherein the operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device, Installing the operational subscription profile on the subscriber module, A computer program (1620a) that causes the computer to perform the following action.

31. A computer program (1620b) for enabling the download and installation of an operational subscription profile to a subscriber module (1200), wherein the computer program includes computer code, which, when executed on the processing circuit of an eSIM server (1400), provides to the eSIM server: To obtain a trigger for downloading the said operational subscription profile to the said subscriber module, To the subscriber module, download information for the operational subscription profile is provided over the initial cellular connectivity connection for the communication device (180) to which the subscriber module is provided. Have them do it, The download information is identified so that the subscriber module can determine whether it is permitted to download a subscription profile, and during the period of cellular network access authentication to establish the initial cellular connectivity connection, the eSIM server provides the subscriber module with authentication data for the subscriber module to authenticate the eSIM server. Computer program.

32. A computer program product (1610a, 1610b) comprising a computer program (1620a, 1620b) according to at least one of claims 30 and 31, and a computer-readable storage medium in which the computer program is stored.

33. A communication device (180) comprising a subscriber module (1200) according to any one of claims 24 to 26.

34. The communication device (180) according to claim 33, which is an IoT device.