Process and Communication Profile Management Device

A centralized communication profile management system addresses dual LPA location issues by remotely managing profiles in vehicles, ensuring secure and efficient profile updates through network-based tasks and encryption, benefiting automobile manufacturers.

JP7709304B2Active Publication Date: 2025-07-16IDEMIA FRANCE SAS
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2021089609
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-05-28
Filing Date
2021-05-27
Publication Date
2025-07-16
Estimated Expiration
2041-05-27

AI Technical Summary

Technical Problem

Existing communication profile management mechanisms, particularly in vehicles, are inadequate for managing and updating communication profiles due to the dual location of the entity LPA, leading to management challenges and concerns about after-sales service quality for automobile manufacturers.

Method used

A centralized communication profile management device and process that dynamically creates execution tasks to manage communication profiles remotely, using a communication agent as a gateway between the device and secure elements, ensuring secure communication through certificate-based encryption and establishing sessions via 'push' or 'pull' modes.

Benefits of technology

Enables automobile manufacturers to efficiently manage communication profiles in vehicles, enhancing security and reducing the need for after-sales service by centralizing profile management functions in the network, while maintaining compliance with GSMA standards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007709304000001
    Figure 0007709304000001
  • Figure 0007709304000002
    Figure 0007709304000002
  • Figure 0007709304000003
    Figure 0007709304000003
Patent Text Reader

Abstract

To provide a centralized communication profile management device, process and computer program adapted to novel services.SOLUTION: A centralized communication profile management device CLPA comprises: a profile management module MGP capable of dynamically creating and executing an execution task CLPAi to respond to a need for remote management of a communication profile PROFeid in a secure element eUICC embedded in a terminal T; a communication module COM-NET to obtain the communication profile from a communication profile manager SM-DP+ via a first communications channel CC2 set up between the execution task and the manager and to send a management command of the profile encapsulated during a communications session SC1 set up between the execution task and a communication agent DAG to the secure element; and a module MI to delete the execution task CLPAi when an action responding to the need has been performed.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention is applicable to the field of managing communication profiles.

Background Art

[0002] As is known, communication profiles used by a terminal are supplied by an operator and stored in a secure element (SIM card, entity eSIM, eUICC) of this terminal.

[0003] In the GSMA (GSM Association) standard, an entity LPA (Local Profile Administration) for managing these profiles is defined. This entity LPA embodies an interface between a secure element (e.g., eUICC) and an entity of a profile management operator (e.g., a subscription management server SM-DP+ "Subscription Manager Data Preparation+").

[0004] Based on the GSMA regulations, this entity LPA is arranged in an operating system or a secure element of a terminal. Due to the possible dual location of this entity LPA, problems related to the management, use, and update of the entity LPA, as well as problems related to profile management, may occur.

[0005] This entity LPA provides an interface for a user of a terminal to manage profiles stored in a secure element of the terminal. Profile management is, for example, for installing a new profile in a secure element and activating, deactivating, or deleting such a profile.

[0006] Today, for example, it has become common to install a communication terminal in an automobile to provide, for example, entertainment services. For such an automobile manufacturer, it may not be preferable to leave the management of communication profiles for accessing such services to the user. In particular, automobile manufacturers are afraid of being required to ensure after-sales service regarding problems related to the quality of services provided by the operator selected by the vehicle user.

[0007] Therefore, the communication profile management mechanisms known so far are not adapted to these new services. SUMMARY OF THE INVENTION

[0008] An object of the present invention is a new communication profile management mechanism.

[0009] Thus, according to a first aspect, the present invention relates to a centralized communication profile management device, the device comprising: · a profile management module capable of dynamically creating an execution task for responding to a request for remote management of a communication profile in a secure element incorporated in a terminal, the profile management module being capable of executing the execution task, · a communication module capable of setting up a first communication channel on a network between the execution task and a communication profile manager, the execution task being capable of obtaining the communication profile from the manager via the first communication channel, · the communication module being capable of setting up a communication session between the execution task and a communication agent, the communication agent being configured to send at least one management command of the profile encapsulated in at least one message sent by the execution task during this session to the secure element, · a module configured to delete the execution task when an action responding to the request is executed; including.

[0010] In connection therewith, the present invention relates to a communication profile management process executed by a centralized communication profile management device, and this process · dynamically creating an execution task (CLPAi) to respond to a request for remote management of a communication profile in a secure element incorporated in a terminal; · executing the execution task; · setting a first communication channel on a network between this execution task and a communication profile manager, where · this execution task can obtain the communication profile from the manager via the first communication channel; · setting a communication session between this execution task and a communication agent, where the communication agent is configured to transmit at least one management command of this profile encapsulated in at least one message transmitted by this execution task during this session to the secure element; · deleting this execution task when an action responding to the request is executed; including.

[0011] According to a second aspect, the present invention relates to a communication agent, and this communication agent · a first communication module configured to set up a communication session with an execution task of a centralized communication profile management device as described above; · a second communication module configured to transmit at least one management command of a profile encapsulated in at least one message received from this execution task during this session to a secure element incorporated in a terminal; including.

[0012] In connection therewith, the present invention relates to a communication process executed by a communication agent, the process comprising: · setting a communication session with the execution tasks of the centralized communication profile management device as described above; · transmitting, to a secure element incorporated in a terminal, at least one management command of a profile encapsulated in at least one message received from the execution task during the session; and the like.

[0013] Accordingly, generally speaking, the present invention proposes to transfer the communication profile management function to a centralized device of a communication network, and this device can communicate with a communication agent configured to ensure an interface between this device and a secure element.

[0014] Viewed from another perspective, the present invention proposes to transfer the function of the LPA to the network, and it can be considered that the communication agent plays a minimal role as a gateway between this device and the secure element.

[0015] When the terminal is incorporated in a vehicle, the vehicle manufacturer can easily manage the communication profiles stored in the secure elements of these terminals by connecting its information system to the centralized profile management device according to the present invention.

[0016] In the present invention, as is known, the execution task is dynamically created to respond to any request for management (profile management, auditing, installation, activation, deactivation, deletion) of the profile of the secure element eUICC, and is deleted when the action responding to this request is executed. The execution task may be implemented, for example, in the form of a process.

[0017] According to the present invention, the communication agent according to the present invention provides the same API (Application Programming Interfaces) defined by the GSMA standard to the secure element. When the secure element wants to use the LPA function, it calls the API standard and sends commands to the centralized device in the network, and thus executes the corresponding function of the LPA migrated to the (latter) network.

[0018] The communication agent can be regarded as a proxy. The communication agent may or may not be integrated into the terminal including the secure element. In a specific example of integration, the proxy (communication agent) may be integrated into a secure element, for example, an eUICC type.

[0019] Another object of the present invention is a terminal including the communication agent and the secure element as described above.

[0020] In one embodiment of the present invention, the secure element is an eSIM type or an eUICC type (embedded UICC) as defined by the GSMA.

[0021] In one embodiment of the present invention, the command is a command APDU (Application Protocol Data Unit) defined by the ISO7816 standard.

[0022] According to a specific embodiment, the execution task is configured to implement or at least participate in the mutual authentication mechanism between the profile manager and the secure element. For example, the execution task may start this authentication mechanism.

[0023] According to a specific embodiment of the centralized profile management apparatus according to the present invention, the command is, for example, a command for loading a profile into the secure element and / or a command for activating, deactivating, or deleting a profile in the secure element.

[0024] In a specific embodiment, the device profile management according to the present invention is characterized in that the execution task is configured to communicate with the profile manager according to a secure protocol through a first communication channel set using a certificate CERT shared between the profile manager and the secure element. SM In this specific embodiment, the profile management command is pre-protected in the profile manager by using this shared certificate before being transmitted via a secure communication channel set between the profile manager and the execution task. According to a specific embodiment, the execution task CLPAi is also configured to transmit a profile management command to the communication agent DAG according to a secure protocol during the session SC1, and this secure protocol uses a certificate CERT stored in the secure element eUICC. SIM By storing the certificate in the secure element, the security of the profile management process is greatly enhanced. Therefore, in this embodiment, before the profile management command is transmitted to the communication agent, the centralized device unpacks a message received in advance from the profile manager and encapsulated with the certificate CERT of the profile manager, and encapsulates the message by using the certificate CERT used during the communication session SC1. SM SIM

[0025] ​​In the present invention, the following two types of encryption are possible. The first type of encapsulation of commands corresponding to the first secure communication channel established between the profile manager and the execution task CLPAi, and the second type of encapsulation of commands corresponding to the secure protocol of the communication session SC1. A certain type of encapsulation means using a dedicated certificate (for example, CERT SIM , CERT SM ) to protect the communication (message) between the first entity and the second entity. Security is enhanced accordingly.

[0026] In another specific embodiment, the same certificate is used in each type of encryption.

[0027] In this embodiment, a communication agent, for example, its first communication module, obtains the certificate stored in the secure element and / or uses this certificate to communicate with the centralized profile management device according to the secure protocol during the session.

[0028] The present invention needs to establish a session between the execution task of the centralized profile management device and the communication agent associated with the secure element. The present invention proposes two particular variants for establishing this session.

[0029] In the first variant, which can be classified as the "push" mode, the session is established under the initiative of the centralized profile management device. When the centralized profile management device has a command to send to the secure element, the centralized profile management device sends an invitation message to the communication agent, causing the communication agent to establish a session with the centralized profile management device.

[0030] Thus, according to a specific embodiment of this first modification example, the profile management device according to the present invention includes a session setting module, and the session setting module is configured to transmit an invitation message for the purpose of inviting the communication agent to set a session with the centralized management device.

[0031] This invitation message is, for example, an SMS type, preferably a signed and / or encrypted message.

[0032] In the second modification example, although this can be classified as a "pull" mode, the communication agent has the option to directly start setting a session with the centralized profile management device, for example, periodically, without the communication agent having to pre-receive an invitation message to start setting this session. During this session once set, under the initiative of the communication agent, the centralized profile management device may send a command to the secure element once such a command becomes available and is targeted at the secure element.

[0033] According to a specific aspect of this second modification embodiment, the centralized profile management device according to the present invention includes a session setting module configured to receive an inquiry request sent from a communication agent, and the session setting module is configured to set a session with the communication agent in response to such a request.

[0034] According to a specific embodiment, the centralized profile management device includes, for example, · Loading a communication profile into the secure element, or · Activating, deactivating, or deleting a communication profile in the secure element, and includes an interface module capable of receiving a management request from a third party for this purpose.

[0035] The management requirements may be sent by the owner of the terminal, the user of the terminal, or the management entity of the terminal, for example, the management entity of the bank of the terminal to which this terminal belongs.

[0036] In certain embodiments, the process is executed by a computer program.

[0037] As a result, another object of the present invention is a computer program on a recording medium, and this program is likely to be executed by a device, more generally a computer. This program includes instructions configured to execute a profile management process as described above.

[0038] Each of these programs can use any programming language and can be in the form of source code, object code, or intermediate code between source code and object code such as partially compiled form, or other preferred forms.

[0039] Another object of the present invention is a computer-readable information medium or recording medium containing instructions of a computer program as described above.

[0040] The information medium or recording medium may be any entity or device capable of storing a program. For example, the medium may include a ROM, such as a CD ROM or a microelectronic circuit ROM, and further may include recording means such as a disk (floppy disk), a hard drive, or a flash memory.

[0041] On the other hand, the information medium or recording medium may be a transmissible medium that can be transmitted via an electric cable, an optical cable, a wireless line, or a wireless optical line, or other means, such as an electric signal or an optical signal.

[0042] The program according to the present invention may be particularly loaded onto an Internet-type network.

[0043] Alternatively, each information medium or recording medium may be an integrated circuit in which a program is incorporated, and this circuit is configured to execute one of the processes according to the present invention or to be used when executing.

Brief Description of the Drawings

[0044] Other features and advantages of the present invention are represented by the following description with reference to the accompanying drawings showing exemplary embodiments having non-limiting features.

[0045]

Figure 1

Figure 2

Figure 3

Modes for Carrying Out the Invention

[0046] FIG. 1 shows a terminal T and a centralized communication profile management apparatus CLPA according to a specific embodiment of the present invention in their environment.

[0047] In the embodiment described here, the terminal T is incorporated in an automobile (not shown). The terminal T is remotely managed by the information system SI-AUTO of this automobile manufacturer in this example.

[0048] This terminal T includes a communication agent DAG according to the present invention and a secure element eUICC.

[0049] The secure element eUICC has a unique identifier eid and a cryptographic certificate CERT SIMIt includes the like. The secure element may store one or more communication profiles.

[0050] Also, FIG. 1 shows the communication profile manager SM-DP+. This profile manager SM-DP+ stores a plurality of profiles including the profile PROF for the secure element eUICC of the terminal T. Also, the profile manager realizes respective roles for protecting the profile and a role for attributing the profile to the eUICC targeted by the profile. eid It stores a plurality of profiles including the like. Also, the profile manager realizes respective roles for protecting the profile and a role for attributing the profile to the eUICC targeted by the profile.

[0051] The terminal T, the centralized profile management device CLPA, the information system SI-AUTO of the automobile manufacturer, and the communication profile manager SM-DP+ communicate via the network NET. Each includes a communication module COM-NET for this purpose.

[0052] This network NET is, for example, the Internet network or a mobile phone network of the 2G, 3G, 4G, or 5G type.

[0053] In the embodiment described here, the centralized profile management device CLPA includes a profile management module MGP, and this module includes: · For example, an interface sub-module IF that can receive a management request RAQ from the owner of the terminal T or the information system SI-AUTO of the automobile manufacturer, and · An execution task management sub-module MI that can create, execute, and delete an execution task CLPAi for managing the communication profile of the secure element eUICC from the network NET, and · A session setting sub-module MES that can set and cancel a communication session SC1 between the execution task CLPAi and the communication agent DAG. It includes the like.

[0054] In the embodiment described herein, these communication sessions SC1 comply with the protocol TLS and use the certificate CERT of the secure element eUICC SIM for use.

[0055] The certificate CERT SIM protects the exchange of session SC1 between the communication agent DAG and the centralized profile management device CLPA.

[0056] In the embodiment described herein, the centralized profile management device CLPA can set up a communication channel CC2 between the execution task CLPAi and the profile manager SM-DP+.

[0057] In the embodiment described herein, this communication channel CC2 is secure, executes the protocol TLS, and the communication channel CC2 uses the certificate CERT SM of the profile manager SM-DP+ to protect the exchange between the centralized device CLPA and the profile manager SM-DP+.

[0058] The protocol TLS may be replaced by other cryptographic protocols.

[0059] Certificates other than the certificates used to protect the communication channel CC2 and the communication session SC1 may also be used to protect the exchange between the communication profile manager SM-DP+ and the secure element eUICC of the terminal T.

[0060] As will be described later, the secure communication channel CC2 may be used by the execution task CLPAi to download the communication profile PROF, for example, the profile PROF targeted at the secure element eUICC of the terminal T eid from the profile manager SM-DP+.

[0061] The messages sent by the execution task CLPAi to the communication agent DAG encapsulate profile management commands for the secure element eUICC. In the exemplary embodiments described herein, these commands are command APDUs.

[0062] These commands specifically include · A command APDU for installing a profile, such as profile PROF eid on the secure element eUICC · A command APDU for activating, deactivating, or deleting a profile installed on the secure element eUICC may be used.

[0063] The communication agent DAG includes a module COM-SIM configured to send to the secure element eUICC the profile management commands (e.g., command APDUs) encapsulated in the messages received from the centralized communication profile management device CLPA.

[0064] Before being sent via the secure communication channel CC2, the profile management commands are first protected within the profile manager SM-DP+ by using the certificate CERT3 shared between the secure element eUICC and the profile manager SM-DP+. This realizes double encryption to enhance the security of the commands.

[0065] The transmission of the profile management commands between the centralized device CLPA and the communication agent DAG is protected by using the certificate CERT SIM of the secure element eUICC (encapsulation of the commands in the message). As described above, during this session SC1, when the commands are first protected within the profile manager SM-DP+ by using the certificate CERT3, this also realizes double encryption of the commands.

[0066] Communication channel CC2 enables secure encapsulation of management commands transmitted between the profile manager SM-DP+ and the centralized device CLPA by using the certificate CERT of the profile manager SM-DP+ SM Thereby enabling secure encapsulation of management commands transmitted between the profile manager SM-DP+ and the centralized device CLPA by using the certificate CERT of the profile manager SM-DP+

[0067] Therefore, before the profile management command is transmitted to the communication agent DAG, the centralized device CLPA decapsulates the previously received message that was sent from the profile manager SM-DP+ and encapsulated with the certificate CERT SM and encapsulates the message by using the certificate CERT used during the communication session SC1 to ensure the security of transmission between the centralized device CLPA and the communication agent DAG SIM Thereby enabling secure encapsulation of management commands transmitted between the profile manager SM-DP+ and the centralized device CLPA by using the certificate CERT of the profile manager SM-DP+

[0068] In the embodiment described herein, the execution task CLPAi of the centralized device CLPA is configured to execute or participate in the mutual authentication mechanism between the profile manager and the secure element

[0069] The session setting sub-module MES of the centralized device CLPA can set and cancel the communication session SC1 between the execution task CLPAi and the communication agent DAG

[0070] In the embodiment described herein, this sub-module MES may function according to the "pull" mode or may function according to the "push" mode

[0071] In the "push" mode, this session setting sub-module MES sends an invitation message for the purpose of inviting the communication agent DAG to set up a communication session SC1 with the centralized management device CLPA

[0072] More precisely, in certain embodiments, the information system SI-AUTO sends a management request to the centralized profile management device CLPA. After receiving the request via the centralized device CLPA, the session setting sub-module MES sends a message MINV to the communication agent DAG associated with the secure element eUICC, inviting the communication agent DAG to set up a communication session SC1 with the centralized device CLPA.

[0073] In a push-mode variant embodiment, the management request is sent from the terminal to the information system SI-AUTO. The information system receives this request and sends the request to the centralized profile management device CLPA as described above.

[0074] In another particular embodiment, the session setting sub-module MES sends this invitation message MINV directly to the communication agent DAG, for example, in the form of a provable signature and / or encrypted SMS by the agent DAG.

[0075] In the "pull" mode, the session setting sub-module MES is configured to receive an inquiry request from the communication agent DAG and, when having at least one management profile command for the centralized profile management device CLPA to send to the secure element eUICC, respond to such a request to set up a session SC1 with the communication agent.

[0076] In the embodiments described herein, the interface sub-module IF of the centralized profile management device CLPA is configured to receive a management request RAQ, for example, from the owner of the terminal T or the information system SI-AUTO of the automobile manufacturer.

[0077] In practice, this interface sub-module IF may communicate with the software application of the terminal T or the software application of the information system SI-AUTO. This software application may be classified as an external agent AE. The external agent AE presents to the user the profile of the manager SM-DP+ that can be downloaded to any secure element eUICC. The external agent AE also provides the user with a menu for activating, deactivating, or deleting the profile installed in the secure element.

[0078] Next, with reference to FIG. 2, the main steps of the profile management process and the main steps of the communication process according to a specific embodiment of the present invention for installing a profile in a secure element will be described.

[0079] More precisely, assume that the user wishes to download a new profile PROF eid to the secure element eUICC of his terminal T. To do this, the user scans the QR code provided by the telecommunications operator (step T10).

[0080] This action causes the transmission of a request RACT_DWLD for downloading the profile to the information system SI-AUTO of the automobile manufacturer. This request includes the identifier eid of this secure element, the identifier PROF eid of this profile, and an activation code CA. This activation code CA causes the information system SI_AUTO to confirm the validity of the request.

[0081] Upon receiving this request, the external agent AE of the information system SI-AUTO sends a management request RADM_DWLD to the profile management module MGP of the centralized profile management device CLPA (step S20). In the example described here, this request is a request download profile (downloadProfile)(eid) defined in the document "GSMA SGP.22 RSP Technical Specification Version 2.2", hereinafter [1].

[0082] The execution task management sub-module MI creates an execution task CLPAi for downloading the profile PROF from the manager SM-DP+ to the secure element eUICC (step M30). eid to the secure element eUICC (step M30).

[0083] The session setting sub-module MES sends a MINV, which is a signed and / or encrypted SMS, to the communication agent DAG associated with the secure element eUICC to invite the communication agent DAG to set up a communication session SC1 with the execution task CLPAi (step M40).

[0084] The secure communication session TLS SC1 is set up between the communication agent DAG and the execution task CLPAi (step D50), and this session uses the certificate CERT of the secure element eUICC SIM for use.

[0085] In step C60, the execution task CLPAi queries the secure element eUICC to obtain the information to be provided to the profile manager SM-DP+. In the embodiment described here, the execution task CLPAi utilizes the function GetEUICCInfo of [1].

[0086] In step C70, the execution task CLPAi obtains the certificate CERT of this manager SMBy using this, a communication channel TLS CC2 with the profile manager SM-DP+ is created.

[0087] In step C80, the execution task CLPAi executes an authentication mechanism between the security element eUICC and the profile manager SM-DP+. In the embodiment described herein, this step uses the functions ES10b.GetEUICCChallenge, ES9+.InitiateAuthentication, ES10b.AuthenticateServer, and ES9+.AutenticateClient of [1].

[0088] In a specific embodiment not shown here, the function ES10b.GetEUICCChallenge is executed between step C60 and step C70 and is not executed in step C80.

[0089] The execution task CLPAi downloads a profile from the profile manager SP-DP+ via the communication channel TLS CC2 (step C90). In the embodiment described herein, for this purpose, step C90 uses the function ES9+.GetBoundProfilePackage of [1].

[0090] The execution task CLPAi SIM sends a message protected by the certificate CERT via the session TLS SC1 to the communication agent DAG (step C100), and these messages encapsulate command APDUs for installing the profile on the secure element eUICC. These command APDUs are sent to the secure element eUICC via the module COM-SIM. In the embodiment described herein, the execution task CLPAi utilizes the function LoadBoundProfilePackage of [1] to transfer the profile to the secure element eUICC.

[0091] When the download is successfully performed, the execution task CLPAi sends a message ES9+.HandleNotification of successful installation to the profile manager SM-DP+ (step C110), and sends a notification message ES10BRemoveNotificationfromList to the secure element eUICC (step C120).

[0092] In step C130, the execution task CLPAi terminates the communication session SC1.

[0093] In step C140, the execution task terminates the communication channel CC2 with the communication profile manager SM-DP+.

[0094] In step M140, the sub-module MES of the profile management module sends information to the external agent AE of the information system SI-AUTO. This information is that the requested profile has been downloaded to the secure element eUICC according to the information.

[0095] The sub-module MI for execution task management terminates / deletes the execution task CLPAi (step M50).

[0096] FIG. 3 shows the main steps of the profile management process and the main steps of the communication process according to a specific embodiment of the present invention for activating a profile in a secure element.

[0097] More precisely, it is assumed that an automobile manufacturer desires to activate a profile PROF eid in the secure element eUICC of the terminal T.

[0098] For this purpose, the user activates the profile (eid, PROF eidTo send the management request RADM_ACT for ( ) to the profile management module MGP of the centralized profile management device CLPA (more precisely, to the interface sub-module IF) (step S200), the external agent AE of the information system SI-AUTO is used. In the example described here, this request is the request enableProfile(eid) of [1].

[0099] The execution task management sub-module MI creates an execution task CLPAi for activating the profile PROF in the secure element eUICC (step M300). eid to activate the profile PROF in the secure element eUICC (step M300).

[0100] The session setting sub-module MES sends the SMS-signed MINV to the communication agent DAG associated with the secure element eUICC to invite the communication agent DAG to set up a communication session SC1 with the execution task CLPAi (step M400).

[0101] The secure communication session TLS SC1 is set up between the communication agent DAG and the execution task CLPAi (step D500), and this session uses the certificate CERT of the secure element eUICC. SIM to use the certificate CERT of the secure element eUICC.

[0102] The execution task CLPAi sends messages protected by the certificate CERT to the communication agent DAG via the session TLS SC1 (step C1000), and these messages encapsulate the command APDUs for activating the profile in the secure element eUICC. These command APDUs are sent to the secure element eUICC via the module COM-SIM. In the embodiment described here, the execution task CLPAi utilizes the function ES10cEnable of [1] to activate the profile PROF in the secure element eUICC. SIM to activate the profile PROF in the secure element eUICC. eid to activate the profile PROF in the secure element eUICC.

[0103] When the activation is performed correctly, the execution task CLPAi terminates the communication session SC1 (step C1300).

[0104] The sub-module MI for execution task management terminates / deletes the execution task CLPAi (step M500).

[0105] In step M140, the sub-module MES of the profile management module transmits information to the external agent AE of the information system SI-AUTO. This information is such that, according to the information, the profile PROF eid has been activated in the secure element eUICC.

Claims

Claim 1: A centralized communication profile management device (CLPA) comprising a profile management module (MGP) and a communication module (COM-NET), wherein the profile management module (MGP) includes a session setting module (MES) and a sub-module (MI), ・ The profile management module (MGP) can dynamically create an execution task (CLPAi) for responding to a request for remote management of a communication profile (PROF) in a secure element (eUICC) incorporated in a terminal (T). eid ​ wherein the profile management module (MGP) is capable of executing the execution task (CLPAi), wherein the execution task (CLPAi) is capable of setting up a first communication channel (CC2) on the network between the execution task (CLPAi) and a communication profile manager (SM-DP+), ・The execution task (CLPAi) can obtain the communication profile (PROF eid ) from the communication profile manager (SM-DP+) via the first communication channel (CC2). wherein the session setting module (MES) is capable of setting up a communication session (SC1) between the execution task (CLPAi) and a communication agent (DAG), - The communication agent (DAG) transmits at least one management command of the profile (PROF eid ) encapsulated in at least one message transmitted by the execution task (CLPAi) during the communication session (SC1) to the secure element (eUICC), wherein the sub-module (MI) is configured to delete the execution task (CLPAi) when an action responding to the request is executed, wherein the communication module (COM-NET) is configured to communicate with the communication profile manager (SM-DP+) and the communication agent (DAG). Claim 2 The centralized communication profile management device (CLPA) according to claim 1, wherein the execution task (CLPAi) is configured to implement or at least participate in a mutual authentication mechanism between the communication profile manager (SM-DP+) and the secure element (eUICC). Claim 3 The centralized communication profile management device (CLPA) according to claim 1 or 2, wherein the at least one command is at least one command for loading the profile into the secure element (eUICC) and / or at least one command for activating, deactivating, or deleting the profile in the secure element (eUICC). Claim 4 The execution task (CLPAi) is configured to communicate with the communication agent (DAG) according to a secure protocol during at least one of the communication sessions (SC1), and the secure protocol uses a certificate (CERT SIM ) stored in the secure element (eUICC). The centralized communication profile management device (CLPA) according to any one of claims 1 to 3, characterized in that. Claim 5 The execution task (CLPAi) is configured to communicate with the communication profile manager (SM-DP+) according to a secure protocol in the first communication channel (CC2), and the secure protocol uses a certificate (CERT SM ) stored in the communication profile manager (SM-DP+). The centralized communication profile management device (CLPA) according to any one of claims 1 to 3, characterized in that. **Claim 6**: The session setting module (MES) is configured to send an invitation message (MINV) for the purpose of inviting the communication agent (DAG) to set up the communication session (SC1) with the centralized communication profile management device (CLPA). The centralized communication profile management device (CLPA) according to any one of claims 1 to 5, characterized in that. **Claim 7** The centralized communication profile management device (CLPA) according to claim 6, characterized in that the invitation message is an SMS type, signed and / or encrypted message. **Claim 8** The centralized communication profile management device (CLPA) includes a session setting module (MES) configured to receive an inquiry request sent from the communication agent (DAG). The session setting module (MES) is configured to set up the communication session (SC1) with the communication agent (DAG) in response to the request. The centralized communication profile management device (CLPA) according to any one of claims 1 to 5, characterized in that. **Claim 9** The centralized communication profile management device (CLPA) ・ Load the communication profile (PROF eid ) into the secure element (eUICC), or ・ Activating, deactivating, or deleting the communication profile (PROF) in the secure element (eUICC) eid ), includes an interface module (IF) capable of receiving management requests from a third party for the purpose of. The centralized communication profile management device (CLPA) according to claim 1, characterized in that. **Claim 10** A communication agent (DAG), - The communication agent (DAG) includes a first communication module (COM-NET) and a second communication module (COM-SIM). - The first communication module (COM-NET) is configured to communicate with the centralized communication profile management device (CLPA). - The session setting module (MES) of the centralized communication profile management device (CLPA) can set up a communication session (SC1) between the execution task (CLPAi) of the centralized communication profile management device (CLPA) and the communication agent (DAG). - The second communication module (COM-SIM) encapsulates at least one management command of the profile (PROF eid ) received from the execution task (CLPAi) during the communication session (SC1) and transmits it to a secure element (eUICC) incorporated in the terminal (T). A communication agent (DAG) configured to do so. **Claim 11** The communication agent (DAG) obtains the certificate (CERT SIM ) stored in the secure element (eUICC) and / or uses this certificate (CERT SIM ) to communicate with the centralized communication profile management device (CLPA) according to a secure protocol during the communication session (SC1). The communication agent (DAG) according to claim 10, characterized in that it is configured to do so. **Claim 12** A terminal (T) including the communication agent (DAG) according to any one of claims 10 or 11 and a secure element (eUICC). **Claim 13** A communication profile management process executed by a centralized communication profile management apparatus (CLPA), the process comprising: ・ To respond to a request for remote management of a communication profile (PROF eid ) in a secure element (eUICC) incorporated in a terminal (T), a step of dynamically creating an execution task (CLPAi); - Executing the execution task (CLPAi); - Setting a first communication channel (CC2) on a network between the execution task (CLPAi) and a communication profile manager (SM-DP+); ・The execution task (CLPAi) can obtain the communication profile (PROF eid ) from the communication profile manager (SM-DP+) via the first communication channel (CC2), step and - A step of setting up a communication session (SC1) between the execution task (CLPAi) and the communication agent (DAG), wherein the communication agent (DAG) is configured to send at least one management command of the profile (PROF eid ) encapsulated in at least one message sent by the execution task (CLPAi) during the communication session (SC1) to the secure element (eUICC). - Deleting the execution task (CLPAi) when an action responding to the request is executed; The process including the above steps.

14. A communication process executed by a communication agent (DAG), the process comprising: - Setting up a communication session (SC1) with an execution task (CLPAi) of a centralized communication profile management apparatus (CLPA). ・ At least one management command of a profile (PROF eid ) encapsulated in at least one message received from the execution task (CLPAi) during the communication session (SC1) is transmitted to a secure element (eUICC) incorporated in a terminal (T); The process including the above step.

15. A computer program comprising instructions for executing the communication profile management process according to Claim 13 when the program is executed by a computer.

16. A computer program comprising instructions for executing the communication process according to Claim 14 when the program is executed by a computer.

Citation Information

Patent Citations

  • Embedded subscriber identity module that can manage communication profiles

    JP2017517987A

  • Implicit file generation in apdu scripts

    JP2018506761A

  • Method of provisioning a subscriber profile for a secure module

    US20160165433A1