Download your production subscription profile

The described method and system provide secure, automated download and installation of subscription profiles in IoT devices by authenticating the eSIM server and using cryptographic keys, addressing the vulnerability of fraudulent profile installations and enabling automated configuration.

JP7804094B2Active Publication Date: 2026-01-21TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024552297
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-05-12
Filing Date
2022-09-22
Publication Date
2026-01-21
Estimated Expiration
2042-09-22

AI Technical Summary

Technical Problem

Existing GSMA eSIM IoT architecture does not prevent malware from downloading and installing fraudulent subscription profiles, and lacks secure automated handling of subscription profiles in IoT devices without user interface.

Method used

A method and system for secure, automated download and installation of operational subscription profiles using initial cellular connectivity, involving a subscriber module that authenticates the eSIM server and downloads the profile from an SM-DP+ entity, utilizing subscription data and cryptographic keys for authorization and protection.

Benefits of technology

Ensures secure and automated handling of subscription profiles, preventing fraudulent installations and enabling automated configuration without user intervention, enhancing security and efficiency in IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007804094000001
    Figure 0007804094000001
  • Figure 0007804094000002
    Figure 0007804094000002
  • Figure 0007804094000003
    Figure 0007804094000003
Patent Text Reader

Abstract

A method for downloading and installing an operational subscription profile performed by a subscriber module (1200) in a communication device (180), the method including: obtaining (S102) download information for the operational subscription profile from an eSIM server (1400) over an initial cellular connectivity connection for the communication device, the subscriber module authenticating the eSIM server with the subscription data during a cellular network access authentication for establishing the initial cellular connectivity connection; downloading (S104) the operational subscription profile from an extended subscription manager data preparation entity (150) according to the download information, the operational subscription profile being downloaded over the initial cellular connectivity connection for the communication device; and installing the operational subscription profile in the subscriber module. Communication devices, eSIM servers, subscription modules, computer programs, computer program products, and further methods are also disclosed.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The invention presented herein relates to a method, a subscriber module, a communication device, a computer program and a computer program product for downloading and installing an operational subscription profile. The invention further relates to a method, an embedded subscriber identity module (eSIM) server, a computer program and a computer program product for enabling downloading and installing an operational subscription profile to a subscriber module. [Background technology]

[0002] The Global System for Mobile communications Alliance (GSMA) is standardizing how subscribers are provided with a third generation partnership project (3GPP) subscription profile, often referred to as a Subscriber Identity Module (SIM) subscription profile, referred to herein as a subscription profile. Such a subscription profile can be remotely downloaded over the Internet to the physical hardware within a communications device, known as an embedded UICC / embedded universal integrated circuit card (eUICC), integrated UICC / universal integrated circuit card (uUICC), or integrated embedded UICC / universal integrated circuit card (ieUICC). The Remote SIM Provisioning Protocol (RSP) is followed to remotely communicate the subscription profile from a provisioning server (an enhanced Subscription Manager Data Preparation (SM-DP+) server, hereafter referred to as an SM-DP+ entity) to the communications device. Remote SIM provisioning for consumer devices is described in the documents "SGP.21 - RSP Architecture Specification v2.4" and "SGP.22 - RSP Technical Specification v2.4."

[0003] The communication device downloads the subscription profile from the SM-DP+ entity. The Mobile Network Operator (MNO) orders the subscription profile from the SM-DP+ entity, which prepares the subscription profile and makes it available for download to the communication device. During the subscription profile ordering phase, the MNO also performs the necessary network provisioning actions. In particular, the appropriate SIM subscription profile that works in the location where the communication device is located needs to be installed in the communication device at the time of manufacture so that the communication device can obtain initial cellular-based connectivity when it is powered up for the first time. Such a SIM subscription profile is hereafter referred to as the bootstrap subscription profile or provisioning subscription profile. It is often unknown where a specific communication device will end up at the time of manufacture of the eUICC / module / device. For this reason, an MNO provisioning subscription profile with global roaming agreements is desirable.

[0004] Generally speaking, eSIM services for Internet of Things (IoT) type communication devices are available where, based on the geographic location of the IoT device, knowledge of pre-negotiated agreements with MNOs, IoT device information, etc. are used as inputs to a localization procedure to determine the appropriate MNO, provisioning server, and subscription profile to use for the specific IoT device, and then trigger the download of an operational subscription profile. Such eSIM services would be provided by an eSIM server, triggered, for example, when the IoT device is powered up for the first time.

[0005] Since IoT devices typically lack a user interface, they should not be able to establish user consent for operations related to subscription profiles. A possible provisioning technique for IoT devices is to configure them to accept subscription profile download trigger operations and subscription profile management operations (such as enabling, disabling, and deleting subscription profiles) sent to the IoT device over an established secure communication channel from an authorized (remote) server (hereafter referred to as the management entity) without requiring user confirmation via any local or remote user interface. This enables automated subscription profile handling for a fleet of IoT devices, e.g., hundreds or thousands. The management entity may also be referred to as the eSIM IoT Remote Manager (eIM). According to the document "SGP.31 - eSIM IoT Architecture and Requirements v1.0" published by the GSMA, the intention is for the IoT eSIM variant to be able to utilize the existing SM-DP+ and Subscription Manager Discovery Service (SM-DS) infrastructure based directly on the eSIM consumer variant. Thus, the IoT eSIM variant supports the same three ways as in the eSIM consumer variant to provide information to a communication device that a subscription profile is pending for download (summarised below): For secure subscription profile management in an IoT device, a secure communication must be established between the IoT device and the management entity, relying on key material available at the IoT device and the management entity. For example, a pre-shared key may be used, or a private-public key pair and certificates for the two entities.In the GSMA eSIM IoT architecture (SGP.31), a secure communication channel between the IoT device and the device management server acting as a management entity can be leveraged to protect the download of subscription profiles and the triggering of subscription profile management operations. Establishing key material between both parties is outside the scope of the solution proposed by GSM. Setting up key material may, for example, rely on a bootstrapping process for the IoT device. The GSMA eSIM IoT architecture for low-power IoT devices addresses memory- and / or power-constrained IoT devices as well as IoT devices connected over low-power wide-area (LPWA) networks. Such devices typically cannot support HTTPS (Hypertext Transfer Protocol Secure) communication with the SM-DP+ entity as required by SGP.22. For such devices, the download of subscription profiles (and handling of notifications) is performed via the management entity to the SM-DP+ entity, leveraging secure communication between the IoT device and the management entity, which handles the HTTPS communication with the SM-DP+ entity.

[0006] Three options are currently defined for providing information to a communication device that a subscription profile is pending for download, hereinafter referred to as Option 1, Option 2, and Option 3.

[0007] Option 1: During the subscription profile ordering phase, the MNO either receives an activation code (AC) from the SM-DP+ (over the ES2+ interface) or generates the AC from data received from the SM-DP+. The MNO then distributes the AC to the customer, for example in the form of a Quick Response (QR) code that is readable by the communication device and can be used by the communication device to contact the SM-DP+ device. When the customer triggers the download of the subscription profile by providing the AC to the communication device, the communication device can connect to the appropriate SM-DP+ and download the subscription profile based on the information from the AC.

[0008] Option 2: The communications device is configured with, or at least has access to, a default SM-DP+ address that defines the SM-DP+ to be used for downloading the subscription profile. For example, upon initial power-up during commissioning of the communications device, or based on some other defined trigger, the communications device connects to the default SM-DP+ to download the subscription profile.

[0009] Option 3: During the subscription profile ordering phase, the MNO requests the SM-DP+ to register information about available subscription profiles for a specific communication device with a discovery service (such as the SM-DS). An event is then generated in the SM-DS for the specific communication device, instructing the communication device to connect to the SM-DP+ and download the subscription profile. The communication device is configured to contact the SM-DS to check for pending subscription profile download events, for example, when first powered on during the device's commissioning period. Upon successful download of the event from the SM-DS, the communication device connects to the SM-DP+ indicated by the event and downloads the subscription profile. The GSMA currently defines a root SM-DS that is common to all communication devices. However, there may be secondary SM-DS servers and vendor-specific discovery services, and thus multiple SM-DS servers.

[0010] According to options 2 and 3, the MNO provides the eUICC identifier (EID) of the communication device, and the subscription profile package prepared for download is bound to the EID in the SM-DP+. According to option 1, it is not necessary for the MNO (or SM-DP+) to know the EID at the time of ordering the subscription profile. In option 1, the communication device receives a matching ID (MID) via the AC, and the communication device presents this MID to the SM-DP+ during the download of the subscription profile in order to identify the correct subscription profile package prepared.

[0011] In the GSMA eSIM IoT architecture as specified in the aforementioned document "SGP.31 - eSIM IoT Architecture and Requirements v1.0," in addition to the secure channel between the communication device and the management entity, an additional layer of protection is added between the management entity and the subscriber module to protect against potential malware residing on the communication device. According to the architecture, the management entity must sign all commands / operations to the subscriber module related to subscription profile state management operations using its private key, and the subscriber module must verify the signature using the management entity's public key, which is securely configured in the subscriber, before accepting subscription profile state management operations (PSMOs) such as subscription profile enable, subscription profile disable, and subscription profile delete. This is to ensure that malware cannot download, install, and enable a fraudulent subscription profile on the subscriber module or disable or delete an already installed subscription profile, resulting in a loss of connectivity or the need to reinstall the subscription profile. The signed PSMO protects management operations, data that uniquely identifies the subscription profile (e.g., an ICCID, which is an Integrated Circuit Card ID), and data for replay protection (e.g., a counter or random).

[0012] The configuration of the management entity's public key to the subscriber module may be performed at various stages, such as during production of the subscriber module, during production of the communication device, and in the field when the communication device is switched on to service. Currently, subscription profile state management is only possible if the management entity's public key has already been configured for the subscriber module. In addition, automatic activation of the subscriber profile is possible without a signed PSMO if the subscription profile is downloaded from a default SM-DP+ entity (as in option 2) or from an SM-DP+ entity obtained via the SM-DS entity (as in option 3).

[0013] While the GSMA eSIM IoT architecture prevents malware on a communications device from changing the state of a subscription profile, it does not prevent the malware from attempting to download and install a new subscription profile. Furthermore, the architecture does not prevent a person with knowledge of the EID of a particular communications device from ordering an undesired subscription profile for that particular communications device and making it available for download via an SM-DP+ entity, which information about the SM-DP+ entity is obtained via the same SM-DS entity that the communications device uses, for example, to check for subscription profiles to download. Summary of the Invention

[0014] An object of the embodiments herein is to solve at least one of the above problems and / or to enable improved security in handling operational subscription profiles.

[0015] According to a first aspect, a method for downloading and installing an operational subscription profile is provided. The method is performed by a subscriber module. The subscriber module is provided to a communication device. The subscriber module is provided with subscription data for use in establishing initial cellular connectivity. The method includes obtaining download information for the operational subscription profile from an eSIM server over an initial cellular connectivity connection for the communication device. The download information is used by the subscriber module in determining that downloading of a subscription profile is authorized for the subscriber module. The subscriber module authenticates the eSIM server using the subscription data during cellular network access authentication to establish the initial cellular connectivity connection. The method includes downloading the operational subscription profile from an SM-DP+ entity in accordance with the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device. The method includes installing the operational subscription profile in the subscriber module.

[0016] According to a second aspect, a subscriber module for downloading and installing an operational subscription profile is presented. The subscriber module is provided to a communication device. The subscriber module is provided with subscription data for use in establishing initial cellular connectivity. The subscriber module includes processing circuitry configured to cause the subscriber module to obtain download information for the operational subscription profile from an eSIM server over an initial cellular connectivity connection for the communication device. The download information is used by the subscriber module in determining that downloading of a subscription profile is authorized for the subscriber module. The subscriber module authenticates the eSIM server using the subscription data during cellular network access authentication to establish the initial cellular connectivity connection. The processing circuitry is configured to cause the subscriber module to download the operational subscription profile from an SM-DP+ entity in accordance with the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device. The processing circuitry is configured to cause the subscriber module to install the operational subscription profile on the subscriber module.

[0017] According to a third aspect, a subscriber module for downloading and installing an operational subscription profile is provided. The subscriber module is provided to a communication device. The subscriber module is provided with subscription data for use in establishing initial cellular connectivity. The subscriber module comprises an acquisition module configured to acquire download information for the operational subscription profile from an eSIM server over an initial cellular connectivity connection for the communication device. The download information is used by the subscriber module to determine whether downloading of a subscription profile is authorized for the subscriber module. The subscriber module authenticates the eSIM server using the subscription data during cellular network access authentication to establish the initial cellular connectivity connection. The subscriber module comprises a download module configured to download the operational subscription profile from an SM-DP+ entity in accordance with the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device. The subscriber module comprises an installation module configured to install the operational subscription profile on the subscriber module.

[0018] According to a fourth aspect, a computer program for downloading and installing an operational subscription profile is provided. The subscriber module is provided on a communication device. The subscriber module is provided with subscription data for use in establishing initial cellular connectivity. The computer program includes computer program code that, when executed on processing circuitry of the subscriber module, causes the subscriber module to obtain download information for the operational subscription profile from an eSIM server over an initial cellular connectivity connection for the communication device. The download information is used by the subscriber module to determine whether downloading of a subscription profile is authorized for the subscriber module. During cellular network access authentication to establish the initial cellular connectivity connection, the subscriber module authenticates the eSIM server using the subscription data. The computer program includes computer program code that, when executed on processing circuitry of the subscriber module, causes the subscriber module to download the operational subscription profile from an SM-DP+ entity in accordance with the download information. The operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device. The computer program includes computer program code that, when executed on processing circuitry of the subscriber module, causes the subscriber module to install the operational subscription profile on the subscriber module.

[0019] According to a fifth aspect, a method is provided for enabling download and installation of an operational subscription profile to a subscriber module, the method being performed by an eSIM server. Operationand obtaining a trigger for downloading a subscription profile to the subscriber module. The method includes providing, to the subscriber module, download information for the operational subscription profile over an initial cellular connectivity connection for a communication device on which the subscriber module is provided, the download information being specified for the subscriber module to determine that the subscriber module is authorized to download a subscription profile. The eSIM server provides authentication data to the subscriber module for authenticating the subscriber module to the eSIM server during cellular network access authentication to establish the initial cellular connectivity connection.

[0020] According to a sixth aspect, an eSIM server for enabling download and installation of an operational subscription profile to a subscriber module is provided. The eSIM server includes a processing circuit configured to cause the eSIM server to obtain a trigger for downloading the operational subscription profile to the subscriber module. The processing circuit is configured to cause the eSIM server to provide, to the subscriber module, download information for the operational subscription profile over an initial cellular connectivity connection for a communication device on which the subscriber module is provided. The download information is identified to determine that the subscriber module is authorized to download a subscription profile for the subscriber module. The eSIM server provides, to the subscriber module, authentication data for the subscriber module to authenticate the eSIM server during cellular network access authentication to establish the initial cellular connectivity connection.

[0021] According to a seventh aspect, an eSIM server is provided for enabling download and installation of an operational subscription profile to a subscriber module. The eSIM server includes an acquisition module configured to acquire a trigger for downloading the operational subscription profile to the subscriber module. The eSIM server includes a provisioning module configured to provide, to the subscriber module, download information for the operational subscription profile over an initial cellular connectivity connection for a communication device on which the subscriber module is provided. The download information is identified to determine that the subscriber module is authorized to download a subscription profile for the subscriber module. The eSIM server provides the subscriber module with authentication data for authenticating the subscriber module to the eSIM server during cellular network access authentication to establish the initial cellular connectivity connection.

[0022] According to an eighth aspect, a computer program for enabling download and installation of an operational subscription profile to a subscriber module is provided. The computer program includes computer program code that, when executed on processing circuitry of an eSIM server, causes the eSIM server to obtain a trigger for downloading the operational subscription profile to the subscriber module. When executed on processing circuitry of the eSIM server, the computer program code causes the eSIM server to provide, to the subscriber module, download information for the operational subscription profile upon an initial cellular connectivity connection for a communication device to which the subscriber module is provided. The download information is specified to determine that the subscriber module is authorized to download a subscription profile for the subscriber module. The eSIM server provides, to the subscriber module, authentication data for the subscriber module to authenticate the eSIM server during cellular network access authentication to establish the initial cellular connectivity connection.

[0023] According to a ninth aspect, there is provided a computer program product including a computer program according to at least one of the fourth and eighth aspects and a computer-readable storage medium on which the computer program is stored. The computer-readable storage medium may be a non-transitory computer-readable storage medium.

[0024] A tenth aspect relates to a communication device including a subscriber module according to the second or third aspect.

[0025] Advantageously, these aspects provide a secure procedure for downloading and installing subscription profiles onto communication devices, avoiding the problems mentioned above.

[0026] Advantageously, these aspects mitigate the download and installation of fraudulent subscription profiles to a subscriber module of a communication device.

[0027] Advantageously, these aspects allow for automated handling of downloaded information without the involvement of the device owner or user, thereby allowing for automated provision of an operational subscription profile.

[0028] Advantageously, these aspects allow for automated ex post / subsequent configuration of information for use in the subscriber module in conjunction with downloading a subscription profile using Option 2 and Option 3 disclosed above. Such information includes SM-DP+ / SM-DS object identifiers (OIDs) and addresses.

[0029] Other objects, features, and advantages of the included embodiments will become apparent from the following detailed disclosure, from the claims, and from the drawings.

[0030] In general, all terms used in the embodiments and claims should be interpreted according to their ordinary meaning in the art unless expressly defined otherwise. All references to an element, apparatus, component, means, module, step, etc., unless expressly stated otherwise, should be openly interpreted as a reference to at least one instance of that element, apparatus, component, means, module, step, etc. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless expressly stated otherwise. [Brief explanation of the drawings]

[0031] The inventive concepts will now be described by way of example with reference to the accompanying drawings in which:

[0032] [Figure 1]1 is a schematic diagram illustrating a communication network according to an embodiment. [Figure 2] 1 is a flowchart of a method according to an embodiment. [Figure 3] 1 is a flowchart of a method according to an embodiment. [Figure 4] FIG. 2 is a sequence diagram according to an embodiment. [Figure 5] FIG. 2 is a sequence diagram according to an embodiment. [Figure 6] FIG. 2 is a sequence diagram according to an embodiment. [Figure 7] FIG. 2 is a sequence diagram according to an embodiment. [Figure 8] FIG. 2 is a sequence diagram according to an embodiment. [Figure 9] FIG. 2 is a sequence diagram according to an embodiment. [Figure 10] FIG. 2 is a sequence diagram according to an embodiment. [Figure 11] FIG. 2 is a sequence diagram according to an embodiment. [Figure 12] FIG. 2 is a schematic diagram illustrating functional units of a subscriber module according to one embodiment. [Figure 13] FIG. 2 is a schematic diagram illustrating functional modules of a subscriber module according to one embodiment. [Figure 14] FIG. 1 is a schematic diagram illustrating functional units of an eSIM server according to an embodiment. [Figure 15] FIG. 1 is a schematic diagram illustrating a functional module group of an eSIM server according to an embodiment. [Figure 16] 1 illustrates an example of a computer program product including computer-readable means according to one embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0033] The inventive concepts will now be more fully described with reference to the accompanying drawings, in which certain embodiments of the inventive concepts are depicted. The inventive concepts may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, the embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the inventive concepts to those skilled in the art. Like numbers refer to like elements throughout the description. Any steps or features indicated with dashed lines should be considered optional.

[0034] The phrase "a data item or piece of information is obtained" by a first device should be interpreted as the data item or piece of information being retrieved, fetched, received, or otherwise made available to the first device. For example, the data item or piece of information may be pushed to the first device from a second device or pulled by the first device from the second device. Furthermore, in order for the first device to obtain the data item or piece of information, the first device may be configured to perform a series of operations, possibly including interactions with the second device. Such operations or interactions may involve a message exchange, including any of a request message for the data item or piece of information, a response message including the data item or piece of information, and a message acknowledging the data item or piece of information. If the data item or piece of information is not explicitly or implicitly requested by the first device, the request message may be omitted.

[0035] The phrase "a data item or piece of information is provided" by a first device to a second device should be interpreted as the data item or piece of information being sent or otherwise made available to the second device by the first device. For example, the data item or piece of information may be pushed to the second device from the first device or pulled from the second device by the second device. Furthermore, in order for the first device to provide the data item or piece of information to the second device, the first and second devices may be configured to perform a series of operations for their interaction with each other. Such operations or interactions may involve a message exchange including any of a request message for the data item or piece of information, a response message including the data item or piece of information, and an acknowledgment message for the data item or piece of information. If the data item or piece of information is not explicitly or implicitly requested by the second device, the request message may be omitted.

[0036] FIG. 1 is a schematic diagram illustrating a communication network 100 in which the embodiments presented herein can be applied.

[0037] The communication device 180 is the device to which the operational subscription profile is downloaded. The communication device 180 may be a mobile phone, laptop, computer tablet, or user equipment (UE). Alternatively, it may be an IoT device. The communication device 180 includes a subscriber module 1200 (illustrated as an eUICC in the figure), such as an iUICC, eUICC, or ieUICC, that supports remote provisioning of subscription profiles according to the GSMA consumer variant, including signed subscription profile state management operations according to the GSMA eSIM IoT architecture (as defined in the aforementioned document "SGP.31 - eSIM IoT Architecture and Requirements v1.0"). The communication device 180 supports secure download, installation, and activation of the subscription profile, utilizing an authorization secret or download and installation data. The subscriber module 1200 holds credentials for secure interaction with both a provisioning server (such as the SM-DP+ entity 150) and a discovery server (such as the SM-DS entity 160). The certificate includes an elliptic curve (EC) private key and the subscriber module's 1200 certificate, which contains the corresponding public key. The subscriber module's 1200 certificate also contains an identifier for the subscriber module, such as an EID. The subscriber module 1200 is provided with a first profile in the form of a provisioning subscription profile at the time of manufacturing, personalization, or module / device manufacture. The provisioning subscription profile provides initial cellular connectivity that enables download of an operational subscription profile. Alternatively, if the subscriber module 1200 does not have a subscription profile installed, the subscriber module's 1200 operating system (OS) may act as the provisioning subscription profile in establishing initial cellular connectivity.The communication device 180 may be manufactured by an original equipment manufacturer (OEM), and the subscriber module 120 may be manufactured by an eUICC manufacturer (UEM), both represented by a manufacturer entity 130.

[0038] Management of subscription profiles on subscriber module 1200 (e.g., enabling, disabling, and deleting subscription profiles) is handled remotely by management entity 210. Management entity 210 may also handle device and data management for communication device 180. When communication device 180 first boots up, the information for connecting to management entity 210 may not yet be configured. Such information may be obtained by communication device 180, for example, via an operational subscription profile or via an application layer bootstrapping procedure.

[0039] The communication device 180 includes a cellular modem configured to connect to a mobile network based on an active subscription profile. Upon initial power-up of the communication device 180, the provisioning subscription profile is the active subscription profile and provides initial cellular connectivity. The initial cellular connectivity is established with a first mobile network (MNO1 120). Using remote SIM provisioning of an eSIM, the subscriber module 1200 can then be provided with a second profile in the form of an operational subscription profile from a second mobile network (MNO2 200). It is noted that MNO1 120 and MNO2 200 may be the same network or, in other embodiments, different networks. The terms MNO1, MNO2, and MNO3 may be used interchangeably in the following description to refer to mobile network operators and their respective mobile networks in some examples. After the operational subscription profile is activated, the operational subscription profile is used to provide network connectivity for the communication device 180. In other words, the operational subscription profile is intended for long-term use (than the provisioning subscription profile) for connectivity services for communication device 180. The operational subscription profile, in one embodiment, includes MNO data and applications intended for the provisioning of services by the MNO. In that embodiment, the operational subscription profile supports a subscription to an MNO, enabling connectivity to a mobile network, which in the above example is typically MNO2 200. The operational subscription profile may also include one or more applications for non-communication services.The provisioning subscription profile, in one embodiment, contains a combination of MNO data and applications for the purpose of enabling connectivity to MNO1 120 for the sole purpose of providing an operational subscription profile to the subscriber module 1200. The provisioning subscription profile thus contains information / applications not present in the operational subscription profile, such as how to download the operational subscription profile.

[0040] The communications device 180 typically includes an IoT Subscription Profile Assistant (IPA) 170, as part of the modem, to assist in downloading subscription profiles and managing subscription profile operations. The IPA 170 interacts with a provisioning server for subscription profile download and notification handling, and with a management entity for subscription profile management operations. The IPA 170 may also be configured to interact with a discovery service to check for pending subscription profile download events. If the communications device 180 is network, energy, and / or memory constrained, interactions with the SM-DP+ entity 150 and the SM-DS entity 160 may be via the management entity 210.

[0041] The eSIM server 1400 serves as a home mobile network when the communication device 180 connects to a first mobile network (i.e., a visited / serving mobile network) during initial power-up to gain initial cellular connectivity. The eSIM server 1400 provides a provisioning subscription profile that is installed during manufacturing or personalization of the subscriber module 1200. This may be a common subscription profile for all communication devices 180 that use the service. Alternatively, one individual subscription profile is used per communication device 180. The provider of the eSIM server 1400 may be, for example, a mobile network operator, a communications service provider (CSP), a mobile virtual network operator (MVNO), or a mobile network vendor. The provider of eSIM server 1400 may have an agreement with an MNO (shown in the figure as mobile network MNO3 110) to use a set of international mobile subscriber identities (IMSIs) for eSIM server 1400 so that communication devices such as communication device 180 can be routed to eSIM server 1400 during initial cellular connectivity establishment.

[0042] The MNO (or CSP) provides cellular connectivity for communication devices and potentially also provides a localization server 140 for remote subscription profile download. If the provider of the eSIM server 1400 is an MVNO, it has roaming agreements with a set of MNOs (shown in the figure as mobile network MNO1 120) that assist in providing initial cellular connectivity for communication devices 180 using the eSIM server 1400.

[0043] An enterprise, IoT service provider, device owner, or end user using eSIM server 1400 orders a subscription profile for their communication device 180 from an MNO (shown in the figure as mobile network MNO2 200). The MNO interacts with a provisioning server to prepare an operational subscription profile for remote download. Upon successful download and activation of the operational subscription profile to communication device 180, the MNO provides cellular connectivity to communication device 180. Note that MNO2 200 ,first time It may be one of 120 mobile network operators offering state-of-the-art cellular connectivity.

[0044] The SM-DP+ entity 150 handles the download of subscription profiles to IoT devices according to the GSMA eSIM consumer variant. The SM-DP+ entity 150 is either operated by the MNO (shown in the figure as mobile network MNO2 200) that provides the operational subscription profile to be downloaded, or it is operated by a third party trusted by the MNO. The SM-DP+ entity 150 is attested and has obtained certificates that allow it to be part of the eSIM ecosystem. The SM-DP+ certificates for authentication and for downloading the subscription profile contain the SM-DP+ OID, which is used to ensure that communication is taking place with the intended SM-DP+ entity 150.

[0045] The SM-DS entity 160 provides discovery services for use by communication devices 180 in accordance with the aforementioned documents "SGP.21 - RSP Architecture Specification v2.4" and "SGP.22 - RSP Technical Specification v2.4." The GSMA currently defines a root SM-DS for the eSIM ecosystem, although there may be auxiliary SM-DS entities and vendor-specific SM-DS entities. The SM-DS entity 160 is certified and has one or more obtained certificates that allow it to be part of the eSIM ecosystem. The authenticating SM-DS certificate contains the SM-DS OID, which is used to ensure that communication occurs with the intended SM-DS entity 160.

[0046] As part of the initial cellular connectivity provision, the localization server 140 may determine the appropriate MNO / MNO device that should provide an operational subscription profile for the particular communication device 180. This is referred to as the localization process and may be more or less complex depending on the scenario at hand. For example, the appropriate MNO, provisioning server, and operational subscription profile to be used may be determined based on the geographic location of the communication device 180, knowledge of a pre-negotiated agreement with the MNO, or information about the communication device 180. Such localization may be offered as a service by the provider of the localization server 140 to an enterprise or communication service provider 190.

[0047] There can be several different approaches for how the localization server 140 is provided and connected to the eSIM server 1400. In a first option, the localization server 140 manages connectivity for a set of MNOs and handles provisioning server interactions on behalf of the MNOs (even the provisioning server may be provided by the provider of the localization server 140), as well as updating / controlling Home Subscriber Servers (HSSs) etc. (such as a Unified Data Management (UDM) in the MNO's 5G Core Network (5GC)). In a second option, the localization server 140 simply performs localization based on input data, and the enterprise handles the interaction with the MNOs itself. Other options are also possible. For example, in the first option, the eSIM server 1400 may be tightly connected to the localization server 140 (or part of it), or it may have no relationship and simply use a localization application programming interface (API) to trigger localization and receive information about the operational subscription profile to be selected. Such interactions may also be via businesses.

[0048] The management entity 210 manages one or more subscription profiles on the subscriber module 1200 of the communication device 180. The management entity 210 may also assist in the interaction between the communication device 180 and the SM-DS entity 160 for downloading subscription profiles. The management entity 210 supports signed subscription profile state management operations (PSMOs) using the management entity's 210 private key, such as an EC private key, and its corresponding public key, such as an EC public key, configured into each subscriber module 1200 managed by the management entity 210. The management entity 210 is configured with a list of subscriber 1200 identifiers (such as EIDs) of the communication devices 180 or subscriber modules 1200 managed by the management entity 210. A device owner / end user / enterprise / service provider or other actor may interact with the management entity 210 to configure it with management operations. Such information may include, for example, the ICCID of the subscription profile of the particular subscriber module 1200 for which a particular subscription profile management operation is to be performed, or may include an activation code (AC) with information from which a particular communication device 180 is to download the subscription profile.

[0049] Embodiments disclosed herein relate to techniques for downloading and installing operational subscription profiles to a subscriber module 1200. To achieve such techniques, a computer program product is provided that includes a subscriber module 1200, a method to be performed by the subscriber module 1200, and code, e.g., in the form of a computer program, that, when executed on processing circuitry of the subscriber module 1200, causes the subscriber module 1200 to perform the method. To achieve such techniques, a computer program product is provided that includes an eSIM server 1400, a method to be performed by the eSIM server 1400, and code, e.g., in the form of a computer program, that, when executed on processing circuitry of the eSIM server 1400, causes the eSIM server 1400 to perform the method.

[0050] Reference is now made to Figure 2, which illustrates a method for downloading and installing an operational subscription profile performed by a subscriber module 1200 according to one embodiment. The subscriber module 1200 is provided to a communication device 180. The subscriber module 1200 is provided with subscription data for use in establishing initial cellular connectivity.

[0051] S102: The subscriber module 1200 obtains download information for an operational subscription profile from the eSIM server 1400. The download information is obtained over an initial cellular connectivity connection for the communication device 180. The download information is used by the subscriber module 1200 in determining that download of the subscription profile is authorized for the subscriber module 1200. The subscriber module 1200 authenticates the eSIM server 1400 with the subscription data during cellular network access authentication to establish the initial cellular connectivity connection.

[0052] S104: The subscriber module 1200 downloads the operational subscription profile according to the download information from the SM-DP+ entity 150. The operational subscription profile is downloaded upon an initial cellular connectivity connection for the communication device 180.

[0053] S106: The subscriber module 1200 installs the operational subscription profile in the subscriber module 1200.

[0054] Embodiments relating to further details of the download and installation of operational subscription profiles performed by the subscriber module 1200 will now be disclosed.

[0055] In some embodiments, after S106, the operational subscription profile is activated upon download and installation (and storage). Thus, in some embodiments, the subscriber module 1200 is configured to perform (optional) step S108.

[0056] S108: The subscriber module 1200 activates the operational subscription profile in the subscriber module 1200 in response to the installation of the operational subscription profile.

[0057] Network access authentication will rely on a secret shared between the eSIM server 1400 and a provisioning profile (accessed by the subscriber module 1200). The shared secret may be a pre-configured part of the provisioning profile or may be derived from data included in the provisioning profile. Thus, in some embodiments, authentication of the eSIM server 1400 is performed using a secret shared with the eSIM server 1400 that is contained in or derivable from the subscription data. In some examples, the subscription data is contained in a provisioning subscription profile installed in the subscriber module 1200. In some examples, the subscription data is contained as part of the operating system of the subscriber module 1200. If a subscription profile is not installed in the subscriber module 1200, the subscriber module 1200 uses the subscription data to behave to the communication device 180 as if a provisioning profile exists in the subscriber module 1200. In some examples, a secret shared with the eSIM server 1400 to protect the transfer of downloaded information from the eSIM server 1400 to the subscriber module 1200 over an initial cellular connectivity connection for the communication device 180 is contained in or derivable from the subscription data. In some examples, the secret shared with the eSIM server 1400 is derivable from the subscription data based on the private key of the private-public key pair of the subscriber module 1200 and the public key of the private-public key pair of the eSIM server 1400. The public key of the private-public key pair of the eSIM server 1400 is part of the subscription data.

[0058] In some examples, the download information is securely transferred from the eSIM server 1400 to the subscriber module 1200 using SIM over-the-air (OTA) procedures. The operational subscription profile could be downloaded from a default SM-DP+ entity 150 or from an SM-DP+ entity 150 provided by the SM-DS entity 160. If the SM-DS entity 160 is used, the SM-DP+ information from which the operational subscription profile is to be downloaded is first securely obtained from the SM-DS. An authorization secret is used to ensure that the subscriber module 1200 is authorized to download the operational subscription profile. Thus, in some examples, the download information specifies an authorization secret used by the subscriber module 1200 to determine that downloading the operational subscription profile from the SM-DP+ entity 150 is authorized and / or to determine that downloading the SM-DP+ information from the SM-DS is authorized, which identifies the SM-DP+ entity 150 from which the operational subscription profile is to be downloaded. The determination that the download is authorized is then based on the subscriber module 1200 obtaining proof of knowledge of the SM-DP+ / SM-DS authorization secret obtained during profile download preparation for the operational subscription profile.

[0059] In some examples, the download of the operational subscription profile is secured by utilizing SM-DS or SM-DP+ information (such as addresses and OIDs) within the subscriber module 1200. The SM-DS or SM-DP+ information is used to verify information obtained from the SM-DP+ during the download of the operational subscription profile, and from the SM-DS, if used, to secure the profile. DownloadThe download information is used by subscriber module 1200 to determine whether the SM-DS or SM-DP+ information is authorized. The SM-DS or SM-DP+ information is selected by communication device 180 using unsigned download and installation data that points to the SM-DS or SM-DP+ information. Thus, in some examples, the download information identifies the OID of the SM-DP+ entity 150 and / or the SM-DS entity 160 that subscriber module 1200 will use to download and install the operational subscription profile. In some examples, the SM-DP+ entity from which the operational subscription profile is downloaded is provided by the OID identified in the download information if the OID is for SM-DP+ entity 150, or by an event record received by subscriber module 1200 from SM-DS entity 160 if the OID identified in the download information is for SM-DS entity 160. SM-DS entity 160 is then provided by the OID identified in the download information.

[0060] An Authentication and Key Agreement (AKA) protocol, such as that enabled through UMTS-AKA, IMS-AKA, 5G AKA, or Extensible Authentication Protocol-AKA, could be utilized to securely transfer the download information while operating to authenticate the communication device 180 and obtain initial cellular connectivity between the subscriber module 1200 and the eSIM server 1400. Thus, in some examples, the download information is obtained as part of performing network access authentication using the AKA protocol when establishing the initial cellular connectivity connection.

[0061] Reference is now made to FIG. 3, which illustrates a method performed by the eSIM server 1400 for enabling the download and installation of an operational subscription profile to the subscriber module 1200 according to one embodiment.

[0062] S202: The eSIM server receives a trigger for downloading an operational subscription profile to the subscriber module 1200.

[0063] S206: The eSIM server 1400 provides, to the subscriber module 1200, download information for an operational subscription profile upon an initial cellular connectivity connection for the communication device 180 on which the subscriber module 1200 is provided. The download information is identified to determine that the subscriber module 1200 is authorized to download a subscription profile for the subscriber module 1200. The eSIM server 1400 provides authentication data to the subscriber module 1200 for the subscriber module 1200 to authenticate the eSIM server 1400 during cellular network access authentication to establish the initial cellular connectivity connection.

[0064] Embodiments relating to further details that enable the download and installation of operational subscription profiles to the subscriber module 1200 performed by the eSIM server 1400 will now be disclosed.

[0065] The trigger obtained in S202 may be in the form of a network access authentication being triggered at the eSIM server 1400. This in turn is triggered by a subscription identifier, such as an IMSI or network access identifier (NAI), being provided / received from the subscriber module 1200 via the communication device 180 and the serving network to the eSIM server 1400.

[0066] In some aspects, the download information is generated or determined by the eSIM service in preparation for the profile download. Thus, in some embodiments, the eSIM server 1400 is configured to perform (optional) step S204.

[0067] S204: The eSIM server 1400 determines download information during profile download preparation for the operational subscription profile.

[0068] It should be noted that step S204 may occur either after step S202 (as in FIG. 3) or before step S202, i.e., after or before the trigger is obtained in S202.

[0069] As disclosed above, in some examples, authentication data provided by eSIM server 1400 to subscriber module 1200 is derived using a secret (hence, a shared secret) shared with subscriber module 1200. As disclosed above, in some examples, transfer of download information from eSIM server 1400 to subscriber module 1200 over an initial cellular connectivity connection for communication device 180 is protected using the secret shared with subscriber module 1200. As disclosed above, in some examples, the secret shared with subscriber module 1200 is based on the public key of the subscriber module 1200's private-public key pair and the private key of the eSIM server 1400's private-public key pair. As disclosed above, in some examples, download information is securely transferred from eSIM server 1400 to subscriber module 1200 using a SIM OTA procedure.

[0070] As disclosed above, in some examples, the download information identifies an authorization secret for use by the subscriber module 1200 to determine that downloading of an operational subscription profile from the SM-DP+ entity 150 is authorized and / or to determine that downloading of SM-DP+ information from the SM-DS is authorized, which identifies the SM-DP+ entity 150 from which to download the operational subscription profile. The determination that the download is authorized is based on the subscriber module 1200 obtaining assurance of SM-DP+ / SM-DS knowledge of the authorization secret obtained during profile download preparation for the operational subscription profile.

[0071] As disclosed above, in some examples, the download information identifies the OID of the SM-DP+ entity 150 and / or the SM-DS entity 160 from which the subscriber module 1200 downloads and installs the operational subscription profile. As disclosed above, in some examples, the SM-DP+ entity from which the operational subscription profile is downloaded is provided by the OID identified in the download information if the OID is for the SM-DP+ entity 150, or by the event record received by the subscriber module 1200 from the SM-DS entity 160 if the OID identified in the download information is for the SM-DS entity 160. The SM-DS entity 160 is provided by the OID identified in the download information.

[0072] As disclosed above, in some examples, the download information is provided as part of performing network access authentication using the AKA protocol when establishing an initial cellular connectivity connection. In some examples, the download information is provided in an authentication vector.

[0073] In the following examples, the subscriber module 1200 will be represented by an eUICC for non-limiting and illustrative purposes, however, the following examples are also applicable to other types of subscriber modules 1200 already mentioned in this disclosure.

[0074] In the following examples, the communications device 180 will be represented by an IoT device for non-limiting and illustrative purposes. However, the following examples are also applicable to other types of communications device 180 already mentioned in this disclosure. When the communications device is in the form of an IoT device, it may be a device for use in one or more application domains, including, but not limited to, home, urban, wearable technology, augmented reality, industrial applications, and healthcare. By way of example, an IoT device for a home, office, building, or infrastructure may be a baking scale, a coffee machine, a grill, a refrigerator, a freezer, a microwave, an oven, a toaster, a water faucet, a water heater, a hot water heater, a sauna, a vacuum cleaner, a washing machine, a dryer, a dishwasher, a door, a window, a curtain, a blind, furniture, a light bulb, an electric fan, an air conditioner, a cooler, an air purifier, a humidifier, a speaker, a television, a laptop, a personal computer, a game console, a remote control, an air vent, an iron, a steamer, a pressure cooker, a stove, an electric stove, a hair dryer, a hair styler, a mirror, a printer, a scanner, a copier, a projector, a hologram projector, a 3D printer, a drill, a hand dryer, an alarm clock, a clock, a security camera, a smoke detector, a fire alarm, a connected doorbell, an electronic door lock, a lawn mower, a thermostat, a plug, an irrigation control device, a water leak sensor, a humidity sensor, a motion detector, a weather station, an electricity meter, a water meter, and a gas meter.

[0075] By way of further example, an IoT device for use in a city, urban, or suburban area may be a connected street light, a connected traffic light, a traffic camera, a connected road sign, an air control / monitor, a sound level detector, a traffic congestion monitoring device, a traffic control device, an automatic toll payment device, a parking payment device, a parking usage monitoring sensor, a traffic management device, a digital kiosk, a trash can, an air quality monitoring sensor, a bridge condition monitoring sensor, a fire hydrant, a manhole sensor, a tarmac sensor, a fountain sensor, a connected closed circuit television, a scooter, a hoverboard, a ticket machine, a turnstile, a subway rail, a subway station device, a passenger information panel, an in-car camera, and other connected devices on public transportation vehicles.

[0076] By way of further example, the communicating IoT device may be a wearable device or an augmented reality related device, which may be an augmented reality (AR), virtual reality (VR), merged reality (MR), or mixed reality (MR) related device. Examples of such IoT devices may be a smart band, an activity tracker, a haptic glove, a haptic suit, a smart watch, clothing, glasses, a head mounted display, ear pods, an activity monitor, a fitness monitor, a heart rate monitor, a finger ring, a key tracker, a blood glucose meter, and a pressure meter.

[0077] As a further example, the IoT device may be an industrial application device, which may be an industrial unmanned aerial vehicle, an intelligent industrial robot, a vehicle assembly robot, and an automated guided vehicle.

[0078] As a further example, the IoT device may be a transportation vehicle, which may be a bicycle, a motorbike, a scooter, a moped, an autorickshaw, rail transport, a train, a tram, a bus, a car, a truck, an airplane, a boat, a ship, skis, snowboards, snowmobiles, hoverboards, skateboards, roller skates, cargo vehicles, drones, robots, stratospheric aircraft, airplanes, helicopters, and hovercraft.

[0079] As a further example, the IoT device may be a health or fitness device, which may be a surgical robot, an implantable medical device, a non-invasive medical device, and a stationary medical device, which may be an in-vitro diagnostic device, a radiology device, an imaging device, and an x-ray device.

[0080] A general aspect of the secure download of an operational subscription profile using download information obtained by an eUICC utilizing an eSIM server will now be disclosed with reference to the sequence diagram of FIG.

[0081] Referring to Figure 4, a procedure is described for an IoT device to obtain initial cellular connectivity and for the IoT device to download an initial operational subscription profile. The download information required for secure download of the operational subscription profile (e.g., in the presence of malware) is determined or generated during the subscription profile download preparation phase and provided to the eUICC using the eSIM server as part of providing initial cellular connectivity to the IoT device.

[0082] It is assumed (step 0) that the eSIM server's database is populated with the EIDs of each IoT device that uses that eSIM server. The eUICC of each IoT device is configured with a provisioning subscription profile from the eSIM server. That subscription profile is the eUICC's currently active subscription profile. The IoT device wakes up (e.g., initially) and leverages the eUICC's provisioning subscription profile to connect to MNO1, perform network access authentication, and obtain initial cellular connectivity (step 1a). Typically, roaming is used, and the eSIM server acts as the home operator and handles network access authentication. MNO1 determines the eSIM server based on the IMSI provided by the IoT device (or MNO3, if the eSIM server has an agreement with MNO3 to use a specific IMSI range).

[0083] The network access authentication performed as part of step 1a relies on a shared secret shared between the eSIM server and the provisioning subscription profile. In order to select the correct shared secret and trigger localization in step 2, the eSIM server determines the EID of the eUICC in step 1b. This may be done based on the received IMSI, for example, if a mapping between IMSI and EID is maintained at the eSIM server, or the EID may be transferred from the eUICC to the eSIM server during network access authentication (step 1b is performed in combination with step 1a).

[0084] To prepare for downloading the operational subscription profile appropriate for the IoT device, the eSIM server requests localization (in step 2) to be performed by the localization server. The EID of the IoT device's eUICC and, optionally, the MCC (+MNC) of MNO1 (the country / territory where the IoT device is located) are also provided for use in localization. The eSIM server does not necessarily interact directly with the entity performing the localization, as shown here. The localization mechanism is performed in step 3, where the MNO that should provide the operational subscription profile is determined, denoted MNO2 in the figure. The operational subscription profile from MNO2 is either prepared for download in advance (in step 4a), for example for all IoT devices in the group, or the localization server interacts directly with the SM-DP+ (in step 4b) to prepare the subscription profile for download. If SM-DS is used, an event is registered with the SM-DS.

[0085] Once an operational subscription profile has been determined and prepared for download, the download information required for secure download of the subscription profile is securely provided from the localization server to the eSIM server (step 5) and then to the eUICC (step 1c). Depending on the method used to securely transfer the download information, the transfer either occurs as part of obtaining initial cellular connectivity (in combination with step 1a) or after initial cellular connectivity has been obtained, leveraging that connectivity to transfer the download information. In the first case, steps 2-5 occur while the establishment of initial cellular connectivity is in progress, while in the other case, the steps typically occur after initial cellular connectivity has been established.

[0086] After receiving the download information, the eUICC stores the download information in the ISD-R security domain along with a help eUICC OS command for use during the download of the operational subscription profile (step 6). In step 7, the modem, with the assistance of the eUICC and the obtained download information, securely downloads the operational subscription profile from the SM-DP+ provided by the information in the IoT device and / or eUICC. If SM-DS is used, the SM-DP+ from which the subscription profile will be downloaded is first securely obtained from the SM-DS. Upon successful download, the subscription profile is installed and automatically activated. The provisioning subscription profile then uses a refresh command (step 8), which triggers the modem to detach from the current network and discard all cached information related to that network. The modem then attaches to the MNO2 network and gains connectivity using the newly installed and activated operational subscription profile (step 9).

[0087] An example will now be described with reference to the sequence diagram of Figure 5, in which the download of the first operational subscription profile is protected using an authorization secret. The authorization secret is generated during preparation of the subscription profile download by the localization server and is provided to the eUICC with the help of the eSIM server using a SIM OTA procedure.

[0088] Step 0: The eSIM Server's database is populated with the EIDs of each IoT device that uses the eSIM Server for the Bootstrap Connectivity Service. The eUICC of each IoT device that uses the service is configured with a provisioning subscription profile from the eSIM Server. That subscription profile is the eUICC's currently active subscription profile. The eUICC is provided with a default SM-DP+ address and / or SM-DS address.

[0089] Step 1: The IoT device leverages the provisioning subscription profile on the eUICC to connect to MNO1 and perform network access authentication to gain initial cellular connectivity. Roaming may be used, and the eSIM server acts as the home operator and handles network access authentication. MNO1 determines the eSIM server based on the IMSI provided by the IoT device (or MNO3, if the eSIM server has an agreement with MNO3 to use a specific IMSI range). Network access authentication relies on a shared secret shared between the eSIM server and the provisioning subscription profile. The shared secret may be pre-configured as part of the provisioning subscription profile, or it may be derived by the subscription module (and eSIM server) based on the eUICC private-public key pair and the eSIM server private-public key pair, with the eSIM server's public key as part of the provisioning subscription profile. In the latter case, the provisioning subscription profile is configured / included with the eSIM server's public key, and the eSIM server's database contains the public key (e.g., the eSIM server's database contains an eUICC certificate containing the eUICC's public key) and the EID of each IoT device that uses the eSIM server. As known in the art, an eUICC certificate is a certificate issued by an EUM for a specific eUICC. To select the correct key and trigger localization in step 2, the eSIM server determines the eUICC's EID. This may be done based on the IMSI, e.g., a mapping between IMSI and EID is maintained in the eSIM server. If the IMSI is randomly selected from the IMSI range, the EID may be transferred from the eUICC to the eSIM server during AKA authentication, as described in more detail below. In another example, the EID is encoded into the IMSI.For example, in the case of 5G, the EID may be transmitted as part of or together with the SUbscription Concealed Identifier (SUCI) (in encrypted form).

[0090] Step 2: The eSIM server requests to perform localization. The EID of the IoT device's eUICC and optionally the Mobile Country Code (MCC) of MNO1 (the country / region where the IoT device is located) are also provided as input. The eSIM server does not necessarily interact directly with the entity performing the localization as shown here.

[0091] Step 3: A localization mechanism is executed to determine the MNO that should provide the operational subscription profile, which is denoted as MNO2 in the figure.

[0092] Step 4: The operational subscription profile from the MNO selected in step 4 needs to be prepared for download. An authorization secret is randomly generated by the localization server for use in preparing the operational subscription profile for download.

[0093] Step 5: The localization server interacts with the SM-DP+ directly or via the MNO / CSP to prepare the subscription profile for download. The authorization secret is provided to the SM-DP+ along with the EID. If SM-DS is used, an event is registered with the SM-DS, including the authorization secret, the EID, and SM-DP+ information such as address and matching ID. The SM-DS here is the same as the one configured in the eUICC; if SM-DS is not used, the SM-DP+ here is the same as the default SM-DP+ configured in the IoT device.

[0094] Step 6: The localization server provides the authorization secret to the eSIM server.

[0095] Step 7: The eSIM server provides the authorization secret to the provisioning subscription profile of the eUICC using the SIM OTA procedure. The shared secret between the eSIM server and the provisioning subscription profile used to protect the SIM OTA procedure may be pre-configured as part of the provisioning subscription profile, or may be derived by the provisioning subscription profile (and the eSIM server) based on the eUICC private-public key and eSIM server private-public key pairs.

[0096] Step 8: The eUICC stores the authorization secret together with the help eUICC OS command in the ISD-R security domain for use during the download of the operational subscription profile.

[0097] Step 9: The modem determines that the eUICC is ready for download of the subscription profile.

[0098] Step 10: The modem, with the assistance of the eUICC, downloads the subscription profile from the default SM-DP+, where the eUICC determines that the download is authorized using the authorization secret, as described above. If an SM-DS is used, the SM-DP+ from which to download the subscription profile is first securely obtained from the SM-DS, whereupon the eUICC determines that it is authorized to download the SM-DP+ information obtained from the SM-DS using the authorization secret. Upon successful verification, the subscription profile is installed and automatically activated.

[0099] Step 11: The eUICC uses a refresh command, which triggers the modem to detach from the current network and discard all cached information related to that network.

[0100] Step 12: The modem attaches to the MNO2 network using the newly installed and activated operational subscription profile and gains connectivity.

[0101] In step 0, the SM-DP+ and / or SM-DS addresses may be configured in the IoT device, e.g., in the modem, during manufacture of the device (or modem module) instead of being configured in the eUICC during manufacture or personalization of the eUICC. This allows for later configuration of the SM-DP+ / SM-DS to be used during the initial subscription profile download. It is also possible to provide the SM-DP+ / SM-DS addresses to be used together with the authorization secret in step 7.

[0102] As a variation of this example, the IoT device may belong to a group of IoT devices for which a set of subscription profiles is already prepared for download when the IoT device first connects. This derivation is then illustrated by the sequence diagram in Figure 6, where an authorization secret is used.

[0103] The steps in the sequence diagram of FIG. 6 are identical to the steps in the sequence diagram of FIG. 5, except for the following points:

[0104] Step 1: The localization server generates authorization secrets for a group of IoT devices and stores them in a database.

[0105] Step 2: This step is the same as step 5 in the sequence diagram of FIG.

[0106] Step 3: See step 1 in the sequence diagram in Figure 5.

[0107] Step 4: The eSIM server requests the authorization secret for the EID obtained in step 3 from the localization server.

[0108] Step 5: The localization server retrieves the authorization secret for the particular EID from its database.

[0109] Next, with reference to the sequence diagram of Figure 7, an example will be described in which the initial download of an operational subscription profile is protected by utilizing SM-DP+ / SM-DS information in the eUICC during the download of the operational subscription profile to verify information obtained from the SM-DP+ and, if used, SM-DS to determine that the download of the operational subscription profile is authorized, as previously described. The SM-DP+ / SM-DS information is selected by the communications device using unsigned download and installation data in the device that points to SM-DS or SM-DP+ information in the eUICC. The SM-DS / SM-DP+ information defines the download information and is determined during subscription profile download preparation by the localization server and provided to the eUICC using the eSIM server using a SIM OTA procedure. In the case where SM-DP+ information is provided, it may also include a matching ID.

[0110] The steps in the sequence diagram of FIG. 7 are the same as the steps in the sequence diagram of FIG. 5, except for the following points:

[0111] Step 0: The eSIM server's database is populated with the EIDs of each IoT device that uses that eSIM server. The eUICC of each IoT device that uses its services is configured with a provisioning subscription profile from the eSIM server provider. That subscription profile is the eUICC's currently active subscription profile.

[0112] Step 4: Step 4 in the sequence diagram of FIG. 5 is not executed in the sequence diagram of FIG.

[0113] Step 6: SM-DP+ or SM-DS information is returned from the localization server to the eSIM server. The information consists of the SM-DP+ / SM-DS OID and possibly its address. In the case where SM-DP+ information is provided, the information may also contain a matching ID that identifies the subscription profile for download in the SM-DP+. Alternatively, the ICCID may be used to uniquely identify the subscription profile.

[0114] Step 7: The eSIM server provides the SM-DP+ / SM-DS information to the provisioning subscription profile of the eUICC using the SIM OTA procedure. The shared secret between the eSIM server and the provisioning subscription profile used to secure the SIM OTA procedure may be pre-configured as part of the provisioning subscription profile, or may be derived by the provisioning subscription profile (and the eSIM server) based on the eUICC private-public key and eSIM server private-public key pair.

[0115] Step 8: The eUICC stores its SM-DP+ / SM-DS information together with the help eUICC OS command in the ISD-R security domain for use during the download of the operational subscription profile.

[0116] Step 10: With the assistance of the eUICC, the modem downloads the subscription profile from the SM-DP+, which verifies the information obtained from the SM-DP+ / SM-DS during the download of the operational subscription profile using the SM-DP+ / SM-DS information in the eUICC. If the SM-DS is used, the SM-DP+ from which the subscription profile is to be downloaded is first securely obtained from the SM-DS. To prevent the download, installation, and activation of an unauthorized subscription profile, the information obtained from the SM-DP+ and from the IoT device is verified by the eUICC using the SM-DP+ information. For example, the OID, address, and matching identifier of the SM-DP+ provided to the eUICC are checked against the information obtained in step 7. If the match is successful, the subscription profile is downloaded, installed, and automatically activated.

[0117] The derivation of Figure 6, where the IoT device belongs to a group of IoT devices for which a set of operational subscription profiles is already prepared for download when the IoT device first connects, is also applicable if the download of the subscription profiles is protected using SM-DP+ / SM-DS information stored in the eUICC and used to verify information obtained from the SM-DP+ / SM-DS during the download of the operational subscription profiles, where the SM-DP+ / SM-DS information is obtained by the eUICC via a SIM OTA procedure.

[0118] An example will now be described with reference to the sequence diagram of Figure 8, where the download of an initial operational subscription profile is protected by using an authorization secret to determine that the download of the operational subscription profile is permitted, as previously described, and where the authorization secret is generated by the localization server during preparation for the subscription profile download and provided to the eUICC with the help of the eSIM server. In this example, the authorization secret is communicated as part of the execution of the AKA protocol.

[0119] The transfer of the authorization secret to the eUICC is performed as part of the establishment of initial cellular connectivity for the IoT device.

[0120] Step 0: See step 0 in the sequence diagram in Figure 5.

[0121] Step 1: When an IoT device first wakes up, to attach to a network, the device's modem reads the IMSI from the eUICC.

[0122] Step 2: The provisioning subscription profile of the eUICC provides the IMSI to the modem. The provisioning subscription profile is unique per IoT device and may be configured with a unique IMSI, which is returned. Alternatively, a provisioning subscription profile that is common to a large set of IoT devices is used. The subscription profile may contain one or more IMSI ranges, from which the provisioning subscription profile randomly selects an IMSI to use. In yet another alternative, the provisioning subscription profile uses an IMSI range (pre-configured in the provisioning subscription profile) where the MCC+MNC digits and possibly a few more digits are fixed, and the remaining IMSI digits are derived from the EID of the eUICC. For example, the remaining digits are assigned as a truncated SHA-256 hash of the EID. The EID is obtained by the subscription profile using the OS functions of the eUICC.

[0123] Step 3: The modem scans for available networks to attach to. Using the MCC+MNC from the IMSI, the modem analyzes the available networks and determines MNO1 as the suitable one. The modem then requests to attach to the selected network.

[0124] Step 4: An identity request is provided by the network.

[0125] Step 5: The modem responds by providing the IMSI.

[0126] Step 6: MNO1 analyzes the IMSI to determine the home mobile network.

[0127] Step 7: A roaming request is made to the home network, which can be either an eSIM server acting as an MVNO or another mobile network operator MNO3 whose IMSI range the IMSI belongs to is served by an eSIM server, and which controls an HSS or similar entity.

[0128] Step 8: The eSIM server determines the EID of the IoT device's eUICC. In one version, this is done based on the received IMSI, using a pre-configured mapping between IMSI and EID and the EID stored in a database at the eSIM server. For example, if a unique IMSI is used per provisioning subscription profile, or if the provisioning subscription profile encodes the EID to the IMSI, such a database can be used. When encoding the EID to the IMSI, there may be multiple EIDs that encode to the same IMSI, resulting in multiple valid entries in the database. How frequently such collisions occur depends on the size of the IMSI range and the number of IoT devices currently using the service. In case of a collision, the full EID value must be provided from the provisioning subscription profile to the eSIM server. This may be done via the AKA protocol, which is described further below. Alternatively, if the IMSI is randomly selected from the IMSI range by the provisioning subscription profile in step 2, the EID is transferred to and from the eSIM server via the AKA protocol.

[0129] Step 9: See step 2 in the sequence diagram in Figure 5.

[0130] Step 10: See step 3 in the sequence diagram in Figure 5.

[0131] Step 11: See step 4 in the sequence diagram in Figure 5.

[0132] Step 12: See step 5 in the sequence diagram in Figure 5.

[0133] Step 13: See step 6 in the sequence diagram in Figure 5.

[0134] Step 14: Network access authentication is performed according to the AKA procedure using AV, based on the cellular technology used (with minor modifications depending on the generation of the 3GPP cellular network). The provisioning subscription profile of the eUICC and the HSS of the eSIM server use a modified behavior according to the following description, however, the behavior is transparent to the visited network (MNO1) and the data and message formats follow the cellular standard used. As part of the network access authentication, the provisioning subscription profile of the eUICC obtains an authorization secret.

[0135] Step 14: See step 8 in the sequence diagram in Figure 5.

[0136] Step 15: See step 9 in the sequence diagram in Figure 5.

[0137] Step 16: See step 10 in the sequence diagram of Figure 5.

[0138] Step 17: See step 11 in the sequence diagram of Figure 5.

[0139] Step 18: See step 12 in the sequence diagram of Figure 5.

[0140] Next, an example of the transfer of the authorization secret from the eSIM server to the provisioning protocol using the AKA protocol will be disclosed with reference to the sequence diagram of Fig. 9. This example is based on step 14 of Fig. 8.

[0141] The authorization secret is transferred as part of the authentication vector prepared by the sSIM server. During transfer, the authorization secret is both encrypted and integrity protected. The key used for encryption and integrity protection is derived from a secret shared between the provisioning subscription profile and the eSIM server. Preferably, the shared secret is an ECDH shared secret derived from an eUICC private-public key pair for use with the eSIM and an eSIM server private-public key pair. The eSIM server's HSS stores the eSIM server's private key and obtains the eUICC public key needed to calculate the shared secret from the eUICC certificate stored in its database, which corresponds to the EID determined in step 8 of FIG. 8. The eUICC stores the eSIM server's public key and derives the shared secret using eUICC OS functions, using the eUICC private key and the stored eSIM server public key. Alternatively, the provisioning subscription profile can hold a global secret, from which the eUICC-specific shared secret can be derived using the EID.

[0142] To make the encryption and MAC keys session-dependent, they are derived from a shared secret (ECDH or derived from a global secret) and a seed. The seed can be a random value or a challenge conveyed as RAND as part of the authentication vector. The RAND is concatenated with a string, e.g., "NAA", used to derive separate keys for different purposes (see below). For example, the ANSI-16.63-KDF algorithm could be used for key derivation. The encryption and MAC algorithms used for IMSI encryption and integrity protection could be, for example, the AES and HMAC-SHA-256 algorithms, respectively. The MAC algorithm could alternatively be the Milenage f1 function, where the IMSI and flags replace the SQN and AMF as inputs. The following substeps of step 14 are executed, in which the authentication vector is first generated and then the AKA protocol is executed.

[0143] Step 14a: The HSS of the eSIM server generates a random value RAND for use in authentication.

[0144] Step 14b: The eSIM server derives the encryption keys K_enc and K_mac using the RAND and the shared secret (ECDH or derived from the global secret) as described above. In addition, temporary values ​​for Ki and OPc, denoted Ki_tmp and OPc_tmp, are derived (using the same key derivation method) for use in network access authentication. In other words, the shared secret is derived using the public key of the eUICC and the private key of the eSIM bootstrap connectivity service.

[0145] Step 14c: The authorization secret is encrypted using K_enc and integrity protected by computing a MAC over the encrypted data using K_mac. The concatenation of the encrypted data and the MAC forms the AUTN value of the authentication vector: AUTN = (encrypted data | MAC).

[0146] Step 14d: Using RAND, Ki_tmp and OPc_tmp as inputs, the values ​​of XRES, CK and IK are calculated according to the normal network access authentication algorithm.

[0147] Step 14e: The authentication vector (RAND, AUTN, XRES, CK, IK) is communicated from the eSIM server to the visited mobile network (i.e., MNO1).

[0148] Step 14f: The visited network sends the RAND and AUTN as an authentication challenge to the IoT device's modem.

[0149] Step 14g: The modem invokes an authentication command on the eUICC and RAND and AUTN are provided.

[0150] Step 14h: The eUICC derives the shared secret according to the above and derives K_enc, K_mac, Ki_tmp and OPc_tmp according to the above description.

[0151] Step 14i: The eUICC extracts the MAC from the AUTN and verifies the MAC using K_mac. If the MAC verification is successful, the encrypted data in the AUTN is extracted and de-encrypted to obtain the authorization secret.

[0152] Step 14j: The eUICC uses RAND, Ki_tmp and OPc_tmp as input to calculate RES, CK and IK according to the normal network access authentication algorithm.

[0153] Step 14k: RES, CK and IK are provided in response to the authentication command.

[0154] Step 14l: The modem returns the RES to the visited network in response to the authentication challenge.

[0155] Step 14m: The visited network verifies that RES is equal to XRES, and if so, the authentication is successful.

[0156] The size of the authorization secret is variable and may be, for example, 64 bits. The size of the AUTN parameter may be 128 bits. The encryption may be performed, for example, using the AES encryption algorithm as follows: first, the encrypted data is obtained by encrypting a string (for example, "AUTN") using K_enc, then the result is truncated to the size of the data to be encrypted (for example, 64 bits), and then an exclusive-or operation (XOR) is applied between the truncated result and the data to be encrypted. Assuming a final size of 64 bits, this can be expressed in pseudo-code as follows: E(secret for authorization)=(secret for authorization) XOR E("AUTN")_trunc

[0157] The MAC portion of the AUTN can be represented as 64 bits, for example, based on HMAC-SHA-256 with K_mac and truncated to 64 bits. As an example, a full 128-bit AUTN would then look like a 64-bit encrypted authorization secret followed by a 64-bit MAC.

[0158] If a larger authorization secret is used, e.g., 128 bits, the first half may be sent in the first AUTN, and the Provisioning Subscription Profile, even if it successfully receives the first part, will signal a synchronization error, and a new authentication will be performed using a new authentication vector (with a new RAND) in which the second half of the authorization secret is transferred to the Provisioning Subscription Profile. This principle can be extended to accommodate even larger authorization secrets.

[0159] An example where an IMSI is randomly selected according to a provisioning subscription profile and the EID is transferred to the eSIM server via the AKA protocol will now be described with reference to the sequence diagram in Figure 10. Step 8 of Figure 8 for this specific case is detailed in Figure 10.

[0160] Step 8a: The eSIM server's HSS generates a random value RAND for use in the AKA protocol.

[0161] Step 8b: The eSIM server derives an encryption key K_enc using the RAND and the global secret shared with the provisioning subscription profile. In addition, temporary values ​​for Ki (the subscriber key) and OPc (a key derived with Ki and the operator code as input), denoted Ki_tmp and OPc_tmp, are derived (using the same key derivation method) for use in network access authentication.

[0162] Step 8c: Using RAND, Ki_tmp and OPc_tmp as inputs, the authentication token (AUTN), expected response (XRES), cipher key (CK) and integrity key (IK) values ​​are calculated according to the normal network access authentication algorithm.

[0163] Step 8d: The authentication vector (RAND, AUTN, XRES, CK, IK) is communicated from the eSIM server to the visited mobile network (MNO1).

[0164] Step 8e: The visited network sends the RAND and AUTN as an authentication challenge to the IoT device's modem.

[0165] Step 8f: The modem invokes an authentication command on the eUICC and RAND and AUTN are provided.

[0166] Step 8g: The provisioning subscription profile uses the RAND and the shared secret to derive K_enc, Ki_tmp, and OPc_tmp.

[0167] Step 8h: The Provisioning Subscription Profile verifies the AUTN using RAND, Ki_tmp and OPc_tmp.

[0168] Step 8i: If the verification is successful, the EID is encrypted using K_enc and the encrypted data is formatted into an AUTS message.

[0169] Step 8j: The provisioning subscription profile enables the signaling of synchronization errors by the eUICC and provides an AUTS in response to the request in step 8f.

[0170] Step 8k: The modem responds with a sync error to the visitor network and provides an AUTS.

[0171] Step 8i: The visitor network responds with a synchronization error to the eSIM server and provides AUTS.

[0172] Step 8m: The eSIM server decrypts the encrypted part of the AUTS with the K_enc derived in step 8b to obtain the EID.

[0173] In other words, AUTS is used here for EID transfer / acquisition and does not indicate a true synchronization error, even though step 8i above mentions that a synchronization error is signaled.

[0174] The EID can be represented by a 32-digit number. One possibility for encoding the EID is to group three digits together and encode them as a number between 0 and 999, represented by 10 bits. A 32-digit EID can then be represented by 110 digits, but since the last two digits of the EID are check digits, a 30-digit number (100 bits) is sufficient. The size of the AUTS parameter may be 112 bits. Encryption may be performed, for example, using the AES encryption algorithm as follows: first, the encrypted data is obtained by encrypting a string (e.g., "AUTS" for the EID) using K_enc, the result is truncated to the size of the data to be encrypted, and then an XOR operation is performed between the truncated result and the data to be encrypted. Assuming a final size of 100 bits, this can be expressed in pseudocode as follows: E(EID)=EID XOR E("AUTS")_trunc

[0175] As an example, a complete 112-bit AUTS could be a 100-bit encrypted EID followed by 12 random bits.

[0176] The shared secret used to derive K_enc may be a static, global secret between the provisioning subscription profile and the eSIM server. Even if RAND is used to derive K_enc so that it is session-specific, it would still be desirable to use a session-specific key to derive the shared secret. In the case of 5G cellular connectivity and SUCI usage, the eSIM server's private-public key pair and an ephemeral key pair generated by the eUICC for SUCI protection could be used to establish an ECDH shared secret from which K_enc can be derived.

[0177] Next, the aspect of IMSI collision will be disclosed. The MAC verification in step 14i of Fig. 9 can fail for various reasons. One reason is that in the case where the EID is encoded into the IMSI, there is an IMSI collision, which should be very rare. For IMSI, a collision means that in the eSIM server's database there is at least one EID with the same IMSI as the one determined for the eUICC in step 8 of Fig. 8, and the eSIM server's HSS selected the wrong entry in the database (i.e., the wrong EID). This results in an incorrect shared secret being derived and the MAC verification failing. In this case, the provisioning subscription profile needs to send its own EID to the eSIM server. Another reason for a MAC failure is that the AUTN value has changed somehow during the transfer. The provisioning server cannot distinguish between these two cases and therefore always provides the EID in case of a MAC failure.

[0178] If there is an IMSI collision, the eSIM server will know that the wrong EID may have been selected. In the case of an IMSI collision, there is more than one entry in the eSIM server's database that matches the IMSI in step 8 of FIG. 8. A localization procedure may help in selecting the correct EID (correct entry). A localization rule may be that a given EID range belongs to IoT devices from a certain company that, based on a pre-negotiated MNO contract, validates a certain set of countries for where IoT devices may be deployed. As an example, suppose an IoT device connects via a visited network in a certain country and there are two possible EIDs inferred from the IMSI. However, according to the localization rule, only one of the EIDs is within the EID range from a company that is localizable for the MNO in the specific country in question, which means that this EID shall be selected.

[0179] Depending on the relationship between the eSIM server and the localization server, localization may be leveraged in the selection of the EID. Referring now to the sequence diagram of Figure 10, where a collision occurs.

[0180] Step 8: There is more than one entry (ie more than one EID) in the database that matches the received IMSI.

[0181] Step 9: The entire list of possible EIDs is provided to the localization server in a localization request.

[0182] Step 10: The localization server performs localization to determine the MNO.

[0183] Step 11: The localization server selects from the list an appropriate EID for which to generate an authorization secret.

[0184] Steps 12a, 12b: An operational subscription profile is prepared for download for the selected EID (denoted as EID1).

[0185] Step 13: The authorization secret is provided from the localization server to the eSIM server.

[0186] Step 14: The eSIM server executes the AKA protocol (according to steps 14a to 14h in Fig. 8), in which the authorization secret is transferred to the provisioning subscription profile. A MAC failure occurs (as in step 14i in Fig. 9), and the EID (in encrypted form) is returned to the eSIM server in an AUTS-formatted message (steps corresponding to steps 8i to 8m in Fig. 9 are performed). A re-localization is requested from the localization server. Steps 9 to 13 are repeated with the new EID (called EID2) received from the eUICC, and a new authorization secret is generated and returned to the eSIM server. Then, according to step 14 (as detailed in Fig. 8) and step 15, the authorization secret is communicated to the provisioning subscription profile and stored in the ISD-R. A new authentication vector is generated together with the new RAND.

[0187] The use of the SIM OTA procedure to securely transfer information to the eUICC allows for more information to be provided than when using the AKA protocol. For example, in the example disclosed with reference to Figures 5 and 6, the eUICC may not have a default SM-DP+ address. The address of the SM-DP+ (or SM-DS, if the appropriate option is used) can be provided to the eUICC using the SIM OTA procedure, along with the authorization secret.

[0188] The SM-DP+ / SM-DS OID typically has a size small enough for provisioning using the AKA protocol. For example, the SM-DS OID may be securely provided to the eUICC using the AKA protocol. As long as the SM-DS address is configured for use by the IPA, e.g., configured in the IoT device during device manufacturing, a secure subscription profile download can be performed, with the eUICC verifying information obtained from the SM-DS during the operational subscription profile download using the SM-DS information in the eUICC. Similarly, the SM-DP+ OID may be provided to the eUICC over the AKA protocol, e.g., in combination with the ICCID. As long as the SM-DP+ address is configured for use by the IPA, a secure operational subscription profile download can be performed by verifying information obtained from the SM-DP+ during the profile download.

[0189] As already mentioned above, the SIM OTA procedure has fewer restrictions on the size of information that can be transferred from the eSIM server to the eUICC compared to the AKA protocol. However, the SIM OTA procedure relies on the use of Short Message Service (SMS) messages or HTTPS as the information bearer, which suggests that the SIM OTA procedure may not be suitable for low-power IoT devices connected over LPWA networks, such as narrowband (NB) IoT networks. Using the AKA protocol for information transfer is possible for all IoT devices that support the required protocols. Furthermore, to address low-power IoT devices, in addition to HTTPS over Transmission Control Protocol (TCP), Constrained Application Protocol (CoAP) over Datagram Transport Layer Security (DTLS) over User Datagram Protocol (UDP) can be used, making the SIM OTA procedure applicable to low-power IoT devices as well.

[0190] Figure 12 illustrates, in terms of several functional units, components of a subscriber module 1200 according to one embodiment. The processing circuitry 1210 may be implemented using any combination of one or more suitable central processing units (CPUs), multiprocessors, microcontrollers, digital signal processors (DSPs), etc., capable of executing software instructions stored, for example, in a computer program product 1610a (such as in Figure 16) in the form of a storage medium 1230. The processing circuitry 1210 may also be implemented as at least one application specific integrated circuit (ASIC) or field programmable gate array (FPGA).

[0191] Specifically, processing circuitry 1210 is configured to cause subscriber module 1200 to perform the set of operations or steps disclosed above. For example, storage medium 1230 may store the set of operations, and processing circuitry 1210 may be configured to read the set of operations from storage medium 1230 and cause subscriber module 1200 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus, processing circuitry 1210 is adapted to thereby perform the method as disclosed herein.

[0192] Storage medium 1230 may also include persistent storage, which may be any one or combination of, for example, magnetic memory, optical memory, solid-state memory, or remotely mounted memory.

[0193] Subscriber module 1200 may further include a communication interface 1220 for communication with other entities, functions, nodes, and devices, such as those of Figure 1. As such, communication interface 1220 may include one or more transmitters and receivers, including analog and digital components.

[0194] Processing circuitry 1210 controls the overall operation of subscriber module 1200, for example, by sending data and control signals to communication interface 1220 and storage medium 1230, by receiving data and reports from communication interface 1220, and by reading data and instructions from storage medium 1230. Other components and associated functionality of subscriber module 1200 have been omitted so as not to obscure the concepts presented herein.

[0195] FIG. 13 illustrates, in schematic form, components of a subscriber module 1200 according to one embodiment in terms of several functional modules. The subscriber module 1200 of FIG. 13 includes multiple functional modules, such as an acquisition module 1210a configured to perform step S102, a download module 1210b configured to perform step S104, and an installation module 1210c configured to perform step S106. The subscriber module 1200 of FIG. 13 may also include a number of optional functional modules, such as an activation module 1210d configured to perform step S108. Generally, each functional module 1210a:1210d may be implemented in hardware or software. Preferably, one or more or all of the functional modules 1210a:1210d may be implemented by a processing circuit 1210, possibly in cooperation with a communication interface 1220 and / or a storage medium 1230. The processing circuitry 1210 may thus be configured to retrieve instructions provided by the functional modules 1210a:1210d from the storage medium 1230 and execute those instructions to thereby perform any steps of the subscriber module 1200 as disclosed herein.

[0196] Figure 14 illustrates, in terms of several functional units, components of an eSIM server 1400 according to one embodiment. The processing circuitry 1410 may be implemented using any combination of one or more suitable central processing units (CPUs), multiprocessors, microcontrollers, digital signal processors (DSPs), etc., capable of executing software instructions stored in a computer program product 1610b (such as in Figure 16), for example, in the form of a storage medium 1430. The processing circuitry 1410 may also be implemented as at least one application specific integrated circuit (ASIC) or field programmable gate array (FPGA).

[0197] Specifically, the processing circuitry 1410 is configured to cause the eSIM server 1400 to perform the set of operations or steps disclosed above. For example, the storage medium 1430 may store the set of operations, and the processing circuitry 1410 may be configured to read the set of operations from the storage medium 1430 and cause the eSIM server 1400 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus, the processing circuitry 1410 is adapted to thereby perform the method as disclosed herein.

[0198] The storage medium 1430 may also include persistent storage, which may be any one or combination of, for example, magnetic memory, optical memory, solid-state memory, or remotely mounted memory.

[0199] The eSIM server 1400 may further include a communication interface 1420 for communication with other entities, functions, nodes, and devices, such as those in Figure 1. As such, the communication interface 1420 may include one or more transmitters and receivers, including analog and digital components.

[0200] The processing circuit 1410 controls the overall operation of the eSIM server 1400, for example, by sending data and control signals to the communication interface 1420 and the storage medium 1430, receiving data and reports from the communication interface 1420, and reading data and instructions from the storage medium 1430. Other components and associated functionality of the eSIM server 1400 have been omitted so as not to obscure the concepts presented herein.

[0201] FIG. 15 illustrates, in schematic form, components of an eSIM server 1400 according to one embodiment in terms of several functional modules. The eSIM server 1400 of FIG. 15 may further include several functional modules, such as an obtaining module 1410a configured to perform step S202 and a providing module 1410c configured to perform step S206. The eSIM server 1400 of FIG. 15 may further include several optional functional modules, such as a determining module 1410b configured to perform step S204. Generally, each of the functional modules 1410a:1410c may be implemented in hardware or software. Preferably, one or more or all of the functional modules 1410a:1410c may be implemented by a processing circuit 1410, possibly in cooperation with a communication interface 1420 and / or a storage medium 1430. The processing circuit 1410 may thus be configured to retrieve instructions provided by the functional modules 1410a:1410c from the storage medium 1430 and execute those instructions to perform any of the steps of the eSIM server 1400 as disclosed herein.

[0202] 16 illustrates an example of a computer program product 1610a, 1610b including a computer-readable means 1630. The computer-readable means 1630 may have stored thereon a computer program 1620a that causes entities and devices, such as the processing circuit 1210 and the communication interface 1220 and storage medium 1230 operatively coupled thereto, to perform methods according to embodiments described herein. The computer program 1620a and / or the computer program product 1610a may thus provide means for performing any of the steps of the subscriber module 1200 as disclosed herein. The computer-readable means 1630 may have stored thereon a computer program 1620b that causes entities and devices, such as the processing circuit 1410 and the communication interface 1420 and storage medium 1430 operatively coupled thereto, to perform methods according to embodiments described herein. The computer program 1620a and / or computer program product 1610a may thus provide means for performing any of the steps of the eSIM server 1400 as disclosed herein.

[0203] In the example of Figure 16, the computer program products 1610a, 1610b are shown as optical discs, such as compact discs (CDs), digital versatile discs (DVDs), or Blu-ray discs. The computer program products 1610a, 1610b may also be embodied as memory, such as random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or electrically erasable programmable read-only memory (EEPROM), or more particularly as non-volatile storage media in external memory devices, such as Universal Serial Bus (USB) memory or flash memory, such as CompactFlash memory. Thus, although the computer programs 1620a, 1620b are shown here diagrammatically as tracks on the depicted optical disc, the computer programs 1620a, 1620b can be stored in any manner suitable for the computer program products 1610a, 1610b.

[0204] The inventive concepts have been described above primarily with reference to a few embodiments. However, as will be readily apparent to those skilled in the art, other embodiments than those disclosed above are equally possible within the scope of the inventive concepts as defined by the claims.

Claims

1. 1. A method for downloading and installing an operational subscription profile performed by a subscriber module (1200), the subscriber module being provided to a communications device (180), the subscriber module being provided with subscription data for use in establishing initial cellular connectivity, the method comprising: obtaining (S102) download information for the operational subscription profile from an eSIM server (1400) over an initial cellular connectivity connection for the communication device (180), the download information being used by the subscriber module in determining whether the subscriber module is authorized to download a subscription profile, and the subscriber module authenticating the eSIM server using the subscription data during cellular network access authentication to establish the initial cellular connectivity connection; downloading (S104) the operational subscription profile from an Enhanced Subscription Manager Data Preparation (SM-DP+) entity (150) according to the download information, wherein the operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device (180); Installing the operational subscription profile in the subscriber module (1200) (S106); A method comprising:

2. 10. The method of claim 1, further comprising: activating the operational subscription profile in the subscriber module (1200) in response to installing the operational subscription profile (S108); A method comprising:

3. 2. The method of claim 1, wherein the authentication of the eSIM server (1400) is performed using a secret shared with the eSIM server that is contained in or derivable from the subscription data.

4. 4. The method of claim 3, wherein the subscription data is contained in a provisioning subscription profile installed in the subscriber module (1200).

5. 4. The method of claim 3, wherein the subscription data is contained as part of the subscriber module's operating system, and when a subscription profile is not installed in the subscriber module, the subscriber module (1200) uses the subscription data to behave as if a provisioning profile exists for the communication device (180).

6. 2. The method of claim 1, wherein a secret shared with the eSIM server to protect the transfer of the download information from the eSIM server to the subscriber module over the initial cellular connectivity connection for the communication device is contained in or derivable from the subscription data.

7. 4. The method of claim 3, wherein the secret shared with the eSIM server (1400) is derivable from the subscription data based on a private key of a private-public key pair of the subscriber module (1200) and a public key of a private-public key pair of the eSIM server, the public key of the private-public key pair of the eSIM server being part of the subscription data.

8. 2. The method of claim 1, wherein the download information is securely transferred from the eSIM server (1400) to the subscriber module (1200) using a SIM OTA procedure.

9. 2. The method of claim 1, wherein the download information specifies an authorization secret used by the subscriber module (1200) to determine that the download of the operational subscription profile from the SM-DP+ entity (150) is authorized for the subscriber module and / or to determine that the download of SM-DP+ information from a Subscription Manager Discovery Service (SM-DS) entity (160) that identifies the SM-DP+ entity from which the operational subscription profile will be downloaded is authorized, and determining that the download is authorized is based on the subscriber module obtaining assurance of knowledge of the authorization secret for the SM-DP+ entity and / or the SM-DS entity obtained during profile download preparation for the operational subscription profile.

10. 2. The method of claim 1, wherein the download information identifies an object identifier (OID) of the SM-DP+ entity (150) and / or the SM-DS entity (160) that the subscriber module (1200) uses to download and install the operational subscription profile.

11. 11. The method of claim 10, wherein the SM-DP+ entity (150) from which the operational subscription profile is downloaded is given by the OID identified in the download information if the OID is that of the SM-DP+ entity, or is given by an event record received by the subscriber module (1200) from the SM-DS entity (160) if the OID identified in the download information is that of the SM-DS entity, and the SM-DS entity is given by the OID identified in the download information.

12. 2. The method of claim 1, wherein the download information is obtained as part of performing network access authentication using an AKA protocol when establishing the initial cellular connectivity connection.

13. 1. A subscriber module (1200) for downloading and installing an operational subscription profile, the subscriber module being provided to a communications device (180), the subscriber module being provided with subscription data for use in establishing initial cellular connectivity, the subscriber module comprising processing circuitry (1210) that causes the subscriber module to: obtaining, from an eSIM server (1400), download information for the operational subscription profile upon an initial cellular connectivity connection for the communication device, the download information being used by the subscriber module in determining that download of a subscription profile is authorized for the subscriber module, and during cellular network access authentication to establish the initial cellular connectivity connection, the subscriber module authenticating the eSIM server using the subscription data; downloading the operational subscription profile from an Enhanced Subscription Manager Data Preparation (SM-DP+) entity (150) according to the download information, wherein the operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device (180); installing the operational subscription profile on the subscriber module; A subscriber module (1200) configured to cause:

14. A subscriber module (1200) as described in claim 13, further configured to perform a method as described in any one of claims 2 to 12.

15. 16. A computer program (1620a) for downloading and installing an operational subscription profile, the computer program comprising computer code that, when executed on processing circuitry of a subscriber module (1200) provided in a communications device (180) and that is provided with subscription data for use in establishing initial cellular connectivity, causes the subscriber module to: obtaining, from an eSIM server (1400), download information for the operational subscription profile upon an initial cellular connectivity connection for the communication device, the download information being used by the subscriber module in determining that download of a subscription profile is authorized for the subscriber module, and during cellular network access authentication to establish the initial cellular connectivity connection, the subscriber module authenticating the eSIM server using the subscription data; downloading the operational subscription profile from an Enhanced Subscription Manager Data Preparation (SM-DP+) entity (150) according to the download information, wherein the operational subscription profile is downloaded over the initial cellular connectivity connection for the communication device; installing the operational subscription profile on the subscriber module; A computer program (1620a) for causing the computer to perform the above.

16. A communication device (180) including a subscriber module (1200) as described in claim 13.

17. The communication device (180) of claim 16, which is an IoT device.

Citation Information

Patent Citations

  • METHOD AND APPARATUS FOR MANAGING TERMINAL PROFILES IN A WIRELESS COMMUNICATION SYSTEM - Patent application

    JP2018512822A

  • SYSTEM AND METHOD FOR OPERATING A USER DEVICE WITH A PERSONALIZED IDENTITY MODULE PROFILE - Patent application

    JP2023530896A

  • Esim subscription management system

    US20190349743A1

  • Radio communication system, radio access network node, communication device, and core network node

    WO2014097517A1