Profile provisioning from eUICC manufacturing equipment to eUICC
By separating profile provisioning steps and using an in-factory controller to transfer only dynamic data, the method addresses the inefficiencies and errors in existing eUICC provisioning, enhancing factory efficiency and reducing processing time.
Patent Information
- Application Number
- JP2024033279
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2023-03-07
- Filing Date
- 2024-03-05
- Publication Date
- 2025-09-11
- Estimated Expiration
- 2044-03-05
AI Technical Summary
Existing profile provisioning methods for eUICCs are time-consuming and prone to errors, particularly in factory settings, as they involve lengthy authentication and data transfer processes.
The method involves splitting the profile provisioning steps, creating a profile container with static data beforehand, and only transferring dynamic data during the provisioning process, using an in-factory profile provisioning controller to reduce processing time and error risk.
This approach significantly reduces the time required for profile provisioning on manufacturing equipment and minimizes data transfer errors, making in-factory provisioning more efficient and reliable.
Smart Images

Figure 0007738111000001 
Figure 0007738111000002
Abstract
Description
[Technical Field]
[0001] The present invention relates to profile provisioning to an eUICC designed to be hosted on a wireless network communication device (also simply referred to as device). [Background technology]
[0002] The world is connected through wireless communication networks, also known as mobile communication networks, and devices hosting eUICCs communicate with each other and with background servers of the wireless networks in a secure manner. An eUICC hosted on a device contains at least one or more subscriber profiles (also simply referred to as profiles), which contain profile data such as an International Mobile Subscriber Identity (IMSI), an authentication key (Ki), a profile number (ICCID), an OTA key, and further profile data. The profiles hosted on the eUICC enable the device hosting the eUICC to communicate in the wireless communication network.
[0003] There are several known form factors for eUICCs, including plug-in SIM cards, more strictly embedded types, soldered eUICCs, and integrated iUICCs, which are integrated into a chip in the chipset of the device that hosts the eUICC.
[0004] The device is known as a consumer wireless network communication device such as a smartphone or a network-enabled tablet PC, or as an M2M wireless network communication device, including an in-vehicle wireless network communication device or an industrial wireless network communication device. In the following, a device is meant to be a wireless network communication device that hosts an eUICC containing one or more profiles and is configured to communicate with other devices and network servers over a mobile communication network, and is intended to include in this specification an eUICC for security-related tasks such as authentication.
[0005] References [1][SGP.22] GSMA SGP.22 RSP Technical Specification, Version 2.2.2, June 5, 2020 and [2][SGP.02] SGP.02 Remote Provisioning Architecture for Embedded UICC Technical Specification, Version 4.2, July 7, 2020, describe the procedures and architecture for provisioning profiles to an eUICC hosted on a device. Reference [3][SGP.31] GSMA SGP.31 eSIM IoT Architecture and Requirements, Version 1.0, April 19, 2022, describes the procedures and architecture for provisioning profiles to an eUICC hosted on a device in an IoT environment.
[0006] Provisioning a profile to an eUICC involves authentication between the profile server and the eUICC, profile download, and profile installation. [1][SGP.22] describes common mutual authentication in Chapter 3.1.2, and profile download and installation on the eUICC for consumer devices in Chapter 3.1.3. [2][3] describe similar procedures for M2M and IoT environments. The profile download architecture includes a profile provisioning server (SM-DP+ in [1][SGP.22] or [3], or SM-DP in [2][SGP.02]), a profile assistant on the device and / or eUICC (Local Profile Assistant LPA in [1][2], IoT Profile Assistant IPA in [3]), and the eUICC. Profiles are downloaded from the profile provisioning server to the eUICC via the profile assistant (LPA or IPA).
[0007] According to [1][SGP.22] and [2][SGP.02], profiles are typically downloaded from a profile provisioning server in a bound profile package (BPP) that contains a large amount of data.
[0008] The profile installation subprocedure includes several substeps. According to step [3] of [SGP.22], chapter 3.1.3.3 "Profile Installation Subprocedure" (Figure 14 and the following description), a profile container ISD-P is first established and configured. Then, in steps [4], [5] and [6] (also Figure 14 and the following description), metadata, replacement session keys and profile data elements are installed in the profile container ISD-P. The profile container ISD-P is created from static profile data. The profile data elements installed in the profile container ISD-P are dynamic profile data, are part of dynamic profile data or contain dynamic profile data.
[0009] Common mutual authentication, profile download from the profile provisioning server to the eUICC, and profile installation on the eUICC take a lot of time, typically 10 seconds or more.
[0010] Profile generation is outside the scope of [1][SGP.22] and [2][SGP.02]. To generate a profile, the profile data, including static and dynamic profile data, is provided to the profile provider's data generation platform as a proprietary profile, a profile data structure in the profile provider's proprietary data format. For profile download from the profile provisioning server to the eUICC, the profile is required to be provided in a non-proprietary, standardized, interoperable format, as described in [5][PP IF] SIM Alliance eUICC Profile Package: Interoperable Format Technical Specification, Version 2.3, October 2019, which, following the name change from SIM Alliance to Trusted Connectivity Alliance, is also referred to as the TCA-compliant format or Trusted Connectivity Alliance-compliant format. Therefore, the data generation platform converts the proprietary profile into a TCA-compliant profile, which is then provided from the data generation platform to a profile provisioning platform, such as SM-DP+ or SM-DP, for download to the eUICC.
[0011] In-factory personalization or provisioning is a setup where profiles are provisioned locally to the eUICC in the factory, as opposed to the standard remote provisioning procedure envisaged in [1][SGP.22], [2][SGP.02] and [3][SGP.31], where profiles are downloaded to the eUICC from a remote profile provisioning server.
[0012] In in-factory provisioning, profiles are downloaded to the eUICC from a local personalization device present in a secure manufacturing environment, rather than from a remote profile provisioning server such as SM-DP+. The secure manufacturing environment may be the secure manufacturing environment of an eUICC manufacturer that manufactures the eUICC, the secure manufacturing environment of a semiconductor chip manufacturer that manufactures the semiconductor chip hosted on the eUICC, or the secure manufacturing environment of a device manufacturer that manufactures the device. Furthermore, in in-factory provisioning, the eUICC is not necessarily attached to the device yet, but may be attached to an eUICC reader that is coupled to or integrated with the personalization device. In this case, the eUICC is provisioned from the personalization device via the eUICC reader. The personalization device may, for example, be part of the manufacturing equipment for manufacturing the eUICC.
[0013] Profile generation in a factory provisioning setup can be performed by the eUICC manufacturer instead of the profile provider, or it can be performed by the profile provider as in a standard provisioning setup.
[0014] Prior art document [4] DE 102019001840 A1 discloses a method for provisioning a profile on an eUICC, wherein the profile downloaded to the eUICC contains empty locations into which profile data from another profile already present on the eUICC is inserted upon installation of the profile on the eUICC after download.
[0015] Prior art document [5] EP 2 802 162 A1 discloses a method for provisioning a profile on an eUICC, in which an empty profile template is created by running an executable file and profile data is loaded into the profile template.
[0016] Device manufacturers, including M2M device manufacturers and smartphone manufacturers, who are or have been provisioning devices, are required to reduce the processing time for profile provisioning to eUICC to 10 seconds or less per profile provisioning, especially when provisioning devices in the factory.
[0017] Such a short profile provisioning processing time cannot be achieved with the full cycle of authentication, profile download, and profile installation according to [1][SGP.22].
[0018] Profiles provided outside the eUICC, on a platform or server, are also called virtual profiles, while profiles installed on the eUICC are simply called profiles. Summary of the Invention [Problem to be solved by the invention]
[0019] An object of the present invention is to provide a method for profile provisioning to an eUICC that reduces the processing time for profile provisioning.
[0020] In particular, a provisioning solution is provided that is suitable for making in-factory provisioning more efficient and less error prone.
[0021] The object of the invention is achieved by a method as defined in claim 1, which has the following characteristics: Embodiments of the invention are set out in the dependent claims.
[0022] The basic idea of the present invention is to divide the preparatory steps for profile provisioning and execute the divided steps separately, thereby shortening the processing time required for actual profile provisioning.
[0023] In particular, the creation of a profile container, eg an ISD-P, on the eUICC can be split and performed at leisure.
[0024] Then, during profile provisioning, only the profile data needs to be provisioned into the already existing profile container.
[0025] In particular, according to the present invention, an eUICC is provided to an eUICC manufacturing device in a state in which at least one profile container created from static profile data already exists, but at least some (or all) of the dynamic profile data required for the operational profile does not exist in the profile container.
[0026] An in-factory profile provisioning controller (IFPP controller) that has the capability to handle static profile data of a profile and dynamic profile data of a separated profile writes only the dynamic profile data to the prepared profile container.
[0027] This reduces the processing time for profile provisioning on manufacturing equipment, as the items that create the profile container have already been downloaded and implemented.
[0028] The method is particularly useful and applicable to in-factory personalization using such eUICC manufacturing equipment.
[0029] The dynamic profile data may be obtained from the generated profile by an IFPP dynamic converter, as described in particular in other patent applications, and provided from the IFPP dynamic converter to the IFPP controller.
[0030] More specifically, a method for provisioning a profile on an eUICC designed to be hosted on a device comprises: S0-1) providing an eUICC manufacturing device that includes eUICC read / write functionality or has eUICC read / write functionality connected thereto and is installed in a secure manufacturing environment; S0-2) Providing an IFPP controller installed in a secure manufacturing environment; S4-1) Providing dynamic profile data to an IFPP controller; S4-2) in an eUICC manufacturing device, providing an eUICC having at least one already-existing created profile container created from static profile data; S4-3) Providing dynamic profile data to an eUICC manufacturing device by an IFPP controller; S4-4) The step of downloading the dynamic profile data to the eUICC via the eUICC read / write function by the eUICC manufacturing device and writing the dynamic profile data (EDP-P1) to a profile container to install the profile and provision the profile to the eUICC.
[0031] According to the present invention, only dynamic profile data is required to be provisioned into an already existing profile container while the eUICC occupies the eUICC manufacturing equipment. This significantly reduces the time the eUICC occupies the eUICC manufacturing equipment for profile provisioning compared to the conventional method of provisioning the entire profile in a single step. This method therefore offers significant advantages in an IFPP eUICC manufacturing environment where equipment occupancy time is at a premium. Furthermore, the risk of data transfer errors can be reduced because the amount of data transferred from the eUICC manufacturing equipment to the eUICC is small. Therefore, the provisioning method of the present invention is suitable for making in-factory provisioning more efficient and less prone to errors.
[0032] The eUICC is designed to be hosted in a device, and preferably is not already hosted in a device. According to some use case scenarios, the eUICC designed to be hosted in a device may already be hosted in a device, or may be provided to the manufacturer together with the device, rather than being an eUICC alone.
[0033] According to some embodiments, step S4-3) further includes: by the IFPP controller obtaining from the manufacturing equipment eUICC information, such as the EID of the eUICC on which the dynamic profile data is provisioned and / or MNO or MVNO information of the MNO or MVNO that owns the dynamic profile data; and selecting, from the plurality of dynamic profile data sets from the plurality of profiles, a matching set of dynamic profile data that matches the obtained eUICC information, e.g., the EID, and / or the MNO or MVNO information.
[0034] According to some embodiments, before the dynamic profile data is provided to the eUICC, the IFPP controller further sends the dynamic profile data to an HSM for encryption, the HSM encrypts the dynamic profile data with a profile encryption key and sends the encrypted dynamic profile data to the IFPP controller, and the IFPP controller receives the encrypted dynamic profile data from the HSM and provides the encrypted dynamic profile data to the eUICC manufacturing device in step S4-3).
[0035] According to some embodiments further developing the above-described embodiments, the dynamic profile data provided in step S4-1) is encrypted with a transport key, a reference to the transport key is sent together with the encrypted dynamic profile data in step S4-1), the encrypted dynamic profile data is decrypted in the HSM with the referenced transport key and re-encrypted in the HSM with the profile encryption key.
[0036] According to some embodiments that further develop the above-described embodiments, the profile encryption is specific to the eUICC or / and the mobile device, and the eUICC-specific profile encryption is achieved by an encryption algorithm that processes an eUICC identifier, in particular the EID, as input to the encryption algorithm.
[0037] According to some embodiments, the eUICC provided in step S4-2) has two or more already existing created profile containers created from static profile data of different profiles, and step S4-3) further comprises selecting the correct profile container corresponding to the dynamic profile data provided in step S4-1).
[0038] According to some embodiments, in steps S4-1 and S4-3), a profile identifier is provided along with the provided dynamic profile data, the profile identifier is provided along with the correct profile container that is already created and the correct profile container is selected based on the provided profile identifier.
[0039] According to some embodiments, the profile identifier is or includes a profile container identifier ISD-P AID, or a profile number ICCID, or a profile name, or a combination of one or more or all of the profile container identifier ISD-P AID, the profile number ICCID, and the profile name.
[0040] According to some embodiments, the dynamic profile data is extracted from an existing profile that has already been generated.
[0041] According to some embodiments, the dynamic profile data comprises: International Mobile Subscriber Identity (IMSI), Authentication key Ki, Further authentication parameters (OP(c)), Profile number ICCID, Access control conditions ACC, One or more personal identification numbers (PINs), one or more personal unblocking keys (PUKs), Default Issuer Security Domain Profile Default-ISD-P, and other dynamic parameters relating to the MNO or MVNO, including roaming partners.
[0042] According to some embodiments, the secure manufacturing environment in which the eUICC manufacturing equipment is installed is the secure manufacturing environment of the device manufacturer.
[0043] The present invention includes, before step S4-2), creating a profile container, and for this purpose: S3-0) Providing the eUICC with static profile data for at least one profile, designed to create a profile container in the eUICC; S3-1) creating at least one profile container in the eUICC.
[0044] According to some embodiments of the profile container creation, steps S3-0) and S3-1) are performed at the eUICC manufacturer, and after steps S3-0) and S3-1) have been performed at the eUICC manufacturer, the eUICC is sent from the eUICC manufacturer to a secure production environment, in particular a secure production environment of a device manufacturer. According to these embodiments, a profile container is created in the eUICC at the eUICC manufacturer without profile data already inserted in the profile container, or at least without all necessary profile data inserted in the profile container. The eUICC is then transported from the eUICC manufacturer to the device manufacturer. The device manufacturer receives the eUICC from the eUICC manufacturer and provides the eUICC to its (the device manufacturer's) secure manufacturing environment. In the secure manufacturing environment, the device manufacturer embeds or installs the eUICC into a device. Also in the secure manufacturing environment, the device manufacturer loads and stores the profile data into the already pre-installed profile container. In this way, the device manufacturer can reduce the download and installation time required to download and install (save) the profile data in the secure manufacturing environment.
[0045] According to some embodiments of the profile container creation, in step S3-0), the static profile data is provided to the eUICC together with an operating system of the eUICC, step S3-0) further comprising installing the operating system on the eUICC. In comparison to a traditional profile provisioning setup, where the eUICC manufacturer provides only the operating system to the eUICC, the entire profile is downloaded in a secure manufacturing environment by the device manufacturer by downloading static profile data, creating a profile container, and then downloading and storing dynamic profile data in the created profile container.
[0046] According to some embodiments, the dynamic profile data is designed to be combined with static profile data, the static profile data being designed to create a profile container in the eUICC, and the dynamic profile data being designed to install a profile in the created profile container.
[0047] Embodiments of the present invention will now be described with reference to the accompanying drawings, wherein like parts are referred to by like reference numerals throughout. [Brief explanation of the drawings]
[0048] [Figure 1] FIG. 3 illustrates a profile provisioning setup including an IFPP dynamic converter suitable for combination with the embodiment of FIG. 2. [Figure 2] FIG. 1 illustrates a profile provisioning setup including an IFPP controller according to one embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0049] Figure 1 shows a profile provisioning setup including an IFPP dynamic converter suitable for combination with the embodiment of the present invention in Figure 2. Any steps shown in Figure 1 are preferably performed before the steps of the present invention whose embodiment is shown in Figure 2.
[0050] According to FIG. 1 , in a first step S1), a wireless network operator (also called a mobile network operator (MNO)) provides a data generation platform with profile generation data MNO1, which includes static profile data and dynamic profile data EDP-P1 for generating a profile container T_ISD-P[]. The data generation platform is a server or computer capable of processing the profile data to generate a profile. The data generation platform is located at the eUICC manufacturer, but may alternatively be located at the profile provider. In step S2), a first profile P1 is generated from the first profile generation data MNO1, which includes static profile data and dynamic profile data for generating the profile container ISD-P. Since the first profile P1 is currently provided on the server serving as the data generation platform and is not yet installed on the eUICC, it can also be called a virtual profile P1 in its current state. Furthermore, a dynamic data description file D-XML is generated, which indicates the content and storage location of at least the dynamic profile data in the first profile P1. The wireless network operator MNO may also provide a further set of profile data similar to the first profile data MNO1, e.g., second profile data MNO2, from which a second profile P2 is generated (not described in detail here).
[0051] In an embodiment in which the profile provisioning server SM-DP+ is provided with an IFPP converter, step S2-1) is executed and the generated profile P1 and the generated dynamic data description file D-XML are provided to the profile provisioning server SM-DP+. On the SM-DP+, the profile P1 can also be called a virtual profile P1, since it is not yet installed on the eUICC.
[0052] In a further step S3-1) at least one profile container T_ISD-P[] is created in the eUICC from the static profile data of the first profile data MNO1.
[0053] In a further step S3-2), the generated first profile P1 and the dynamic data description file D-XML of the first profile P1 are provided to an IFPP dynamic converter, which extracts dynamic profile data EDP-P1 from the first profile P1 with the support of the dynamic data description file D-XML. Profile data MNOi of further profiles Pi may also be present (not shown).
[0054] According to the first option 1, the IFPP dynamic converter is provided in or connected to a data generation platform, in particular at the eUICC manufacturer.
[0055] According to the second option 2, the IFPP dynamic converter is provided in or connected to the profile provisioning server SM-DP+, which in step S2-1) is provided with the generated profile P1 and the generated dynamic data description file D-XML.
[0056] In a subsequent step S4, the extracted dynamic profile data EDP-P1 is sent to the eUICC and installed in the profile container T_ISD-P[] created in step S3-1.
[0057] In the embodiment of Figure 1, the dynamic profile EDP-P1 data of the first profile P1 includes the profile container identifier ISD-PAID of the profile container T_ISD-P[] created in step S3-1, the profile name, the ICCID (profile number), the IMSI (subscriber identity number), the ACC, the Opc, the authentication key Ki, the PIN and PUK, the key, and possibly further parameters.
[0058] FIG. 2 illustrates a profile provisioning setup involving an IFPP controller in a manufacturing environment, according to one embodiment of the present invention.
[0059] According to the embodiment of Fig. 2, in step S4, the dynamic profile data EDP-P1 is sent from the IFPP controller to the eUICC and installed in the profile container T_ISD-P[] created in step S3-1. In combination with the embodiment of Fig. 1, the dynamic profile data EDP-P1 is extracted profile data extracted from the profile P1 as described in relation to Fig. 1. However, the present invention can also be effective with dynamic data provided by other methods.
[0060] In detail, step S4 includes: S4-1) Providing dynamic profile data EDP-P1 (for example, but not necessarily, extracted profile data extracted in step S3-2 above) to an IFPP controller installed in the eUICC manufacturing environment (where the dynamic profile data EDP-P1 may be encrypted with a transport key, sent to an HSM, re-encrypted in the HSM with an eUICC-specific key, and sent back to the IFPP controller). S4-2) Providing an eUICC having the created profile container T_ISD-P[] in an eUICC read / write facility connected to or integrated into an eUICC manufacturing device installed in an eUICC manufacturing environment; S4-3) Providing dynamic profile data EDP-P1 to an eUICC manufacturing device by an IFPP controller; S4-4) The step of downloading the dynamic profile data EDP-P1 to the eUICC by the eUICC manufacturing device and writing the transferred dynamic profile data EDP-P1 into the profile container T_ISD-P[ ] created in step S3-1) to create a profile and provision it to the eUICC.
[0061] (Prior art document) [1][SGP.22] GSMA SGP.22 RSP Technical Specification, Version 2.2.2, June 5, 2020 [2][SGP.02] SGP.02 Remote Provisioning Architecture for Embedded UICC Technical Specification, Version 4.2, July 7, 2020 [3][SGP.31] GSMA SGP.31 eSIM IoT Architecture and Requirements, Version 1.0, April 19, 2022 [4] German Patent No. 102019001840
Claims
1. A method of provisioning a profile to an eUICC designed to be hosted on a device using an eUICC manufacturing device that has eUICC read / write functionality or has eUICC read / write functionality connected thereto and is installed in a secure manufacturing environment, and an IFPP controller that is installed in the secure manufacturing environment, comprising: S4-1) Acquiring dynamic profile data (EDP-P1) by the IFPP controller; S4-2) A step of obtaining an eUICC having at least one already-existing created profile container (T_ISD-P[]) created from static profile data by the eUICC manufacturing device; S4-3) Providing the dynamic profile data (EDP-P1) to the eUICC manufacturing device by the IFPP controller; S4-4) The method includes a step of installing the profile and provisioning the profile to the eUICC by the eUICC manufacturing device downloading the dynamic profile data (EDP-P1) to the eUICC via the eUICC read / write function and writing the dynamic profile data (EDP-P1) to the profile container (T_ISD-P[ ]).
2. The method of claim 1, wherein step S4-3) further comprises: acquiring, by the IFPP controller, eUICC information (EID) of an eUICC to which dynamic profile data (EDP-P1) is provisioned and / or MNO or MVNO information of an MNO or MVNO that owns the dynamic profile data (EDP-P1) from the manufacturing device; and selecting, from a plurality of dynamic profile data sets from a plurality of profiles, a matching set of dynamic profile data (EDP-P1) that matches the acquired eUICC information (EID) and / or MNO or MVNO information.
3. 3. The method of claim 1 or 2, wherein before the dynamic profile data (EDP-P1) is provided to the eUICC, the IFPP controller further sends the dynamic profile data (EDP-P1) to an HSM for encryption, the HSM encrypts the dynamic profile data (EDP-P1) with a profile encryption key and sends the encrypted dynamic profile data (EDP-P1) to the IFPP controller, and the IFPP controller receives the encrypted dynamic profile data (EDP-P1) from the HSM and, in step S4-3), provides the encrypted dynamic profile data (EDP-P1) to the eUICC manufacturing device.
4. 4. A method according to claim 3, wherein the dynamic profile data (EDP-P1) provided in step S4-1) is encrypted with a transport key, a reference to the transport key is sent together with the encrypted dynamic profile data (EDP-P1) in step S4-1), the encrypted dynamic profile data (EDP-P1) is decrypted in the HSM with the referenced transport key and re-encrypted in the HSM with the profile encryption key.
5. 4. The method of claim 3, wherein profile encryption is specific to the eUICC or / and mobile device, and wherein the eUICC-specific profile encryption is achieved by an encryption algorithm that processes an eUICC identifier, in particular an EID, as input to the encryption algorithm.
6. The method according to claim 1 or 2, wherein the eUICC provided in step S4-2) has two or more already-existing created profile containers created from static profile data of different profiles, and step S4-3) further comprises selecting a correct profile container (T_ISD-P[ ]) corresponding to the dynamic profile data (EDP-P1) provided in step S4-1).
7. 7. The method of claim 6, wherein in steps S4-1 and S4-3, a profile identifier is provided together with the provided dynamic profile data (EDP-P1), the profile identifier is provided together with an already existing and created correct profile container (T_ISD-P[]), and the correct profile container (T_ISD-P[]) is selected based on the provided profile identifier.
8. The profile identifier is a profile container identifier ISD-P AID, or Profile number ICCID, or Profile name, or 8. The method of claim 7, wherein the profile container identifier is or includes a combination of one or more or all of a profile container identifier ISD-P AID, a profile number ICCID, and a profile name.
9. The method according to claim 1 or 2, wherein said dynamic profile data (EDP-P1) is extracted from a generated profile.
10. The dynamic profile data (EDP-P1) is International Mobile Subscriber Identity (IMSI), Authentication key Ki, Further authentication parameters (OP(c)); Profile number ICCID, Access control conditions ACC, one or more personal identification numbers PINs; one or more personal unblocking keys PUK, Default Issuer Security Domain Profile Default-ISD-P, 3. The method of claim 1 or 2, further comprising one or more or all of: other dynamic parameters relating to the MNO or MVNO, including roaming partners.
11. The method according to claim 1 or 2, wherein the secure manufacturing environment in which the eUICC manufacturing equipment is installed is a secure manufacturing environment of a device manufacturer.
12. Before step S4-2), S3-0) Providing static profile data to the eUICC for at least one profile, designed to create a profile container (T_ISD-P[]) in the eUICC; S3-1) The method according to 1 or 2, further comprising the step of creating at least one profile container (T_ISD-P[]) in the eUICC.
13. The method according to claim 12, wherein steps S3-0) and S3-1) are performed at an eUICC manufacturer, and after steps S3-0) and S3-1) have been performed at the eUICC manufacturer, the eUICC is sent from the eUICC manufacturer to the secure manufacturing environment, in particular a secure manufacturing environment of a device manufacturer.
14. In step S3-0), the static profile data is provided to the eUICC together with an operating system of the eUICC; The method of claim 12, wherein step S3-0) further comprises installing the operating system on the eUICC.
15. The dynamic profile data (EDP-P1) is designed to be combined with the static profile data; The static profile data is designed to create a profile container (T_ISD-P[ ]) in the eUICC; 3. The method according to claim 1 or 2, wherein the dynamic profile data (EDP-P1) is designed to install a profile (P1) in a created profile container (T_ISD-P[]).
Citation Information
Patent Citations
Profile setting method and device
JP2016531459A
Management system and management method
JP2018061083A
Method for providing an enrollment profile, a subscriber identity module, and an enrollment server - Patent Application 20070122997
JP2022535181A
PROFILE GENERATION FOR PROVISIONING PROFILE TO eUICC
JP2024127826A
Embedded Universal Integrated Circuit Card Supporting Two-Factor Authentication
US20220103538A1