eUICC Profile Delegation Management

Delegated eUICC profile management via a server-based interface allows companies to manage profiles outside the GSMA specification, reducing the workload on MNOs and addressing the bottleneck in managing numerous subscriber profiles.

JP7851395B2Active Publication Date: 2026-04-24GIESECKE PLUS DEFRIENT MOBILE SECURITY GERMANY GMBH
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
GIESECKE PLUS DEFRIENT MOBILE SECURITY GERMANY GMBH
Filing Date
2022-08-09
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Current eUICC profile management solutions burden Mobile Network Operators (MNOs) with the task of generating and downloading numerous subscriber profiles, which becomes a bottleneck as the number of connected devices increases, particularly in IoT and M2M applications.

Method used

A method and apparatus for delegated management of eUICC profiles, allowing third parties to manage profiles through a server-based interface, reducing MNO workload by enabling companies to directly manage and update profiles outside the GSMA specification.

Benefits of technology

This solution reduces the burden on MNOs by allowing companies to efficiently manage and update eUICC profiles, thereby alleviating the management bottleneck and supporting a large number of connected devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007851395000001
    Figure 0007851395000001
  • Figure 0007851395000002
    Figure 0007851395000002
  • Figure 0007851395000003
    Figure 0007851395000003
Patent Text Reader

Abstract

The present invention relates to an embedded universal integrated circuit card, a method, an interface and an apparatus for delegated management of profiles of an eUICC included in a mobile device. The delegated management is provided by registering the eUICC with a server to certain profiles selected from a list of profiles available in the eUICC and adding the selected profiles to an existing subscription group of profiles on the server or by creating a new subscription group on the server based on the selected profiles.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method and apparatus for managing a plurality of profiles for an eUICC (embedded Universal Integrated Circuit Cards), and more particularly, to a method and apparatus for managing an entrusted eUICC profile.

Background Art

[0002] Background of the Invention In recent years, mobile devices configured to utilize electronic subscriber profiles for communication over a mobile network have emerged. Such mobile devices typically comprise an electronic / embedded secure element device, such as an electronic / embedded Universal Integrated Circuit Card (eUICC), configured to store one or more electronic subscriber profiles, such as an electronic Subscriber Identity Module (eSIM) profile, which may enable the mobile device to connect to one or more mobile networks. A subscriber profile (e.g., an eSIM profile) may be generated by a Mobile Network Operator (MNO) and downloaded to a mobile network device. The subscriber profile is then installed on the secure element of the mobile device and may be used for communication over the corresponding mobile network by the mobile device.

[0003] Figure 1 shows a simplified representation of the architecture of a remote eSIM provisioning system as described in the SGP.22 RSP Technical Specification, Version 2.2.2 issued by the GSM Association. The eSIM provisioning system 100 is organized around several elements, namely SM-DP+ (Subscription Manager - Data Preparation and Secure Routing, 110), SM-DS (Subscription Manager - Discovery Server, 150), LPA (Local Profile Assistance, 142), and eUICC, 141, the latter of which is part of the mobile devices 140 of the end users 130.

[0004] SM-DP+ is responsible for creating, remotely managing (enabling, disabling, updating, deleting), and protecting subscriber profiles provided by MNO 120. LPA (Local Profile Assistant, 142) is a set of functions within device 140 that is responsible for providing the ability to download (encrypted) profiles to eUICC 141. It also presents a local management end-user interface to end users 130, allowing them to manage the status of profiles on eUICC 141. SM-DS 150 provides a means for SM-DP+ 110 to communicate with eUICC 141.

[0005] Current solutions for profile management by MNOs include the MNO creating a profile, which is then associated with a unique identifier (EID) of the eUICC 141, and the profile is downloaded there. When a mobile device 140 containing the eUICC 141 accesses the SM-DP+ 110, it begins downloading the profile and then uses it. When device 140 stops using the profile, the MNO 120 decouples it from the EID, and the profile becomes available for use by other eUICCs. Such solutions are known, for example, from Korean Patent Application Publication No. 20130026351A. "GSMA eSIM Group feedback on the request from ETSI TC SCP" provides a technical description of the GSMA's "Remote SIM Provisioning (RSP) Architecture for Consumer Devices" applicable to eSIM products. U.S. Patent Application Publication No. 2020 / 288300A1 discloses a server that retrieves the unique identifier of an eSIM from a device having an embedded subscriber identification module (eSIM). U.S. Patent Application Publication 2014 / 038563A1 discloses a versatile embedded universal integrated circuit card that includes multiple active MNO (Mobile Network Operator) profiles. U.S. Patent Application Publication 2018 / 206123A1 discloses a method by which the management of subscription credentials is delegated from a mobile network operator to an enterprise server.

[0006] The use of eUICC allows OEMs and end customers to flexibly select or change service providers (and therefore mobile networks) without replacing SIM cards, while simultaneously enabling a wide range of consumer, M2M, and IoT use cases for MNOs, automakers, device vendors, and IoT service providers.

[0007] Because MNOs play a central role, any modifications or changes to service providers and profiles must be made by the MNO. However, as the number of connected devices in IoT and M2M applications continues to increase, generating numerous subscriber profiles and downloading them to devices places a significant burden on MNOs. The MNO's central role therefore becomes a bottleneck in the management chain for managing subscriber profiles. [Overview of the Initiative] [Problems that the invention aims to solve]

[0008] Therefore, it is desirable to provide a solution for eUICC profile management that addresses the aforementioned shortcomings. [Means for solving the problem]

[0009] Summary of the Invention The present invention addresses the above-mentioned objectives by subject matter covered by the independent claims. Preferred embodiments of the present invention are defined in the dependent claims.

[0010] According to a first aspect of the present invention, a method for delegated management of profiles of an embedded universal integrated circuit card, eUICC, is provided. The eUICC is included in a mobile device, which further includes a Local Profile Assistant, LPA. In a first step, the LPA registers the eUICC with a server. In the next step, the LPA obtains a list of profile identifiers, each of which uniquely identifies a profile available for the eUICC. A profile identifier is then selected from the obtained list, and delegated management is added to the profile identified by the selected profile identifier by adding it to an existing subscription group of profiles on the server, or by creating a new subscription group on the server based on the selected profile identifier.

[0011] Preferably, the profile identifier is a unique serial number or ICCID (Integrated Circuit Card ID) that uniquely identifies a particular profile.

[0012] Profiles within a subscription group on the server, specifically those with delegated management added, are no longer under the control of the MNO, and can be directly managed by third parties such as companies or corporations.

[0013] This significantly reduces the workload for MNOs, particularly for IoT applications that require handling a large number of connected devices and their profiles.

[0014] In some embodiments of the present invention, registering an eUICC with a server includes obtaining an eUICC identifier, an EID, from the eUICC; obtaining a public key from the eUICC; generating a certificate signing request (CSR) including the public key; and registering a mobile device with the server along with the EID and CSR.

[0015] This enables mutual authentication between eUICC and the server.

[0016] In some embodiments of the present invention, registering a mobile device with a server includes receiving an acknowledgment message from the server containing a signed certificate, and storing the certificate.

[0017] Preferably, the certificate is signed by a certification authority, such as a GSMA certificate issuer, i.e., a certification authority trusted by the GSMA. The signed certificate allows for verification of the server's integrity.

[0018] In some embodiments of the present invention, obtaining a list of profile identifiers includes checking on a server whether there is a mobile network operator (MNO) to which the server is connected that provides support for eUICC. If there is an MNO performing this function, a first list of profile identifiers is received from the MNO. A second list of profile identifiers is received from the eUICC. The first list of profile identifiers and the second list of profile identifiers are then combined to obtain a list of profile identifiers available to that eUICC.

[0019] This makes it possible to retrieve the identifiers of all profiles available on the mobile device, regardless of whether they are provided by various MNOs or are already stored on the device's eUICC.

[0020] Preferably, the LPA is instructed to request a list of profiles from the MNO by receiving a command from the server that directs the MNO to redirect.

[0021] In some embodiments of the present invention, obtaining a list of profiles from an MNO includes signing in to the MNO using personally identifiable data stored in the eUICC, particularly username and password; receiving an authentication token from the MNO; requesting a list of profile identifiers from the MNO using the authentication token; receiving a first list of profile identifiers from the MNO, which includes the profile identifier and profile name of the profile provided by the MNO; and storing the first list of profile identifiers.

[0022] In some embodiments of the present invention, obtaining a second list of profile identifiers from eUICC includes sending a GSMA-compliant command to eUICC and receiving a second list of profiles from eUICC. Preferably, the second list of profiles includes, for each profile installed in eUICC, the profile metadata of that eUICC, in particular the profile identifier, ICCID and International Mobile Subscriber Identity, IMSI.

[0023] In some embodiments of the present invention, the method further includes establishing a secure communication channel with a server by LPA before adding delegated management to the selected profile. Preferably, the established secure communication channel supports multiple security protocols that provide secure private communication through identifier authentication and encryption.

[0024] In some embodiments of the present invention, when a list of profile identifiers is obtained from an MNO, adding it to a subscription group on the server includes instructing the server to add the selected profile identifiers along with the profile names to the subscription group, and creating a subscription group on the server includes instructing the server to create a new subscription group with a subscription group identifier and to add the profile identifiers along with the profile names to the new subscription group.

[0025] In some embodiments of the present invention, when a list of profile identifiers is obtained from the eUICC, adding to a subscription group on the server includes instructing the server to add the selected profile identifier to the subscription group together with the IMSI. Creating a subscription group on the server includes instructing the server to create a new subscription group with a subscription group identifier and add profile metadata, particularly the ICCID and IMSI, to the new subscription group.

[0026] According to a second aspect of the present invention, an interface for managing the profiles of an embedded universal integrated circuit card, eUICC, included within a mobile device is provided. The interface is located on a server and can be connected to at least one mobile network operator, MNO. The interface is configured to assist in the authentication of the eUICC at the server, provide for the creation and management of a subscription group including a plurality of profiles at the server, and provide for the upload and / or download of profiles to / from at least one MNO.

[0027] In some embodiments of the present invention according to the second aspect, the interface is further configured to assist in the registration of the mobile device to the server, particularly through an application call or through a private invitation link.

[0028] According to a third aspect of the present invention, an apparatus, particularly a server, is provided, which is configured to store and manage eUICC profiles provided by at least one mobile network operator, MNO. Preferably, the apparatus includes an interface according to the second aspect.

[0029] In some embodiments of the invention according to a third aspect, the device is further configured to manage profile groups, receive instructions in particular for updating profiles, and upload the updated profiles to at least one MNO. Preferably, the instructions are received from the company via application calls or by accessing a dedicated website.

[0030] According to a fourth aspect of the present invention, a remote eUICC profile management system is provided, which includes a mobile device, the mobile device including an embedded universal integrated circuit card, eUICC, and a local profile assistant, LPA. The system further includes a server according to a third aspect, the server including an interface according to a second aspect. The system is configured to receive delegated management requests from a company, and upon receiving a delegated management request, to perform the method according to a first aspect.

[0031] According to a further aspect of the present invention, a computer program product is provided which includes instructions that, when the program is executed by a computer, cause the computer to perform eUICC authentication and registration on a server, the server manages multiple subscriber profiles of eUICC and includes an interface that can connect to a mobile network operator, MNO, to obtain a list of profile identifiers, each profile identifier uniquely identifies the respective profile available to eUICC, and delegated management is added to the selected profile identifier by adding it to an existing subscription group of profiles on the server, or by creating a new subscription group on the server based on the selected profile identifier.

[0032] The embodiments and designs described herein enable a company to effectively and efficiently manage the mobile network subscriptions it provides to mobile devices equipped for provisioning electronic subscriber profiles, because any modifications and changes to service providers and profiles can be made by the company itself through direct access to the server. Furthermore, the company can manage, in particular, modify / update eUICC profiles through interfaces outside the scope of the GSMA specification, thus reducing the number of profiles that need to be uploaded to mobile devices.

[0033] It should be noted that all devices, elements, units, and means described herein can be performed by software, hardware elements, or combinations thereof. In addition to all steps performed by the various entities described herein, the functions described hereof mean that each entity is made or configured to perform its respective steps and functions.

[0034] Other aspects, features, and advantages of the present invention will become apparent to those skilled in the art by carefully reading the following detailed description of preferred embodiments and variations of the invention together with the accompanying drawings.

[0035] Brief explanation of the drawing From here, please refer to the attached diagram below. [Brief explanation of the drawing]

[0036] [Figure 1] This shows a simplified representation of the architecture of a remote eSIM provisioning system. [Figure 2] This document shows the architecture of a remote eSIM provisioning system according to one embodiment of the present invention. [Figure 3] This is a flowchart of a method for delegated management of eUICC profiles according to one embodiment. [Figure 4]Further steps of a method for delegating the management of eUICC profiles to a server, according to one embodiment, are shown. [Figure 5] Further steps of a method for delegated management of eUICC profiles according to one embodiment are shown. [Figure 6A] A flowchart for adding delegated management to a free profile, according to another embodiment, is shown. [Figure 6B] A flowchart for adding delegated management to an installed profile, according to another embodiment, is shown. [Figure 7A] A portion of the signal diagram for a method of delegated management of eUICC profiles according to one embodiment is shown. [Figure 7B] A portion of the signal diagram for a method of delegated management of eUICC profiles according to one embodiment is shown. [Figure 7C] A portion of the signal diagram for a method of delegated management of eUICC profiles according to one embodiment is shown. [Modes for carrying out the invention]

[0037] Detailed explanation A detailed description of the present invention is provided below with reference to the accompanying drawings illustrating specific embodiments of the invention. These embodiments are described in sufficient detail to enable those skilled in the art to carry out the invention. It should be understood that the various embodiments of the invention, though different, are not necessarily mutually exclusive. For example, a particular feature, structure, or characteristic described in one embodiment herein may be implemented in other embodiments without departing from the scope of the invention. In addition, it should be understood that the position or arrangement of individual elements in each disclosed embodiment may be modified without departing from the scope of the invention. Accordingly, the following detailed description should not be construed as restrictive, and the scope of the invention is defined only by the accompanying claims and the entire scope of equivalents available therein, as appropriately interpreted. In the figures, similar numbers throughout multiple drawings refer to the same or similar function.

[0038] Throughout this specification, the term “eUICC” should be understood as an integrated circuit, IC, intended to securely store at least one subscription profile having profile data. A profile within an eUICC may host an International Mobile Subscriber Identification Number (IMSI), a unique serial number, an ICCID, cryptographic encryption / decryption keys, security authentication and encryption information, temporary information about the local network, a list of services the user can access, and two passwords used to uniquely identify and authenticate the subscriber on terminal equipment such as M2M devices, mobile phones, and personal computers: a Personal Identification Number (PIN) for normal use and a Personal Unblock Code (PUK) for PIN unlocking. In addition, a profile within an eUICC may include a profile name.

[0039] This invention proposes a solution for delegating profile management of profile groups from an MNO to a third party, such as a company or enterprise, via a dedicated interface and server. This interface is located on a server and is therefore outside the scope of the GSMA specification.

[0040] Through this application, the profile group to which delegated management has been added is also called a subscription group.

[0041] Figure 2 shows a remote eSIM provisioning system according to one embodiment.

[0042] System 300 includes, in addition to the components of the known eSIM provisioning system shown in Figure 1, a server 210 (hereinafter also referred to as the Profile-To-Go-Server). The server can be located in a specific company 300, such as a company or corporation that provides mobile devices to its employees. The server can also be implemented as a virtual cloud server accessible to the company.

[0043] Interface 220 resides on Server 210, allowing the company to manage profiles, update profiles, revoke profiles, or purchase new profiles. Interface 220 provides eUICC authentication on Server 210. Furthermore, Interface 220 provides support for accepting device enrollment in different ways, such as from applications or through private invitation links, including registration of mobile devices with eUICC.

[0044] Company 300 can access the server through an application and / or website to manage profile groups, which can, for example, update existing profiles, delete existing profiles, and purchase new profiles. When a profile group is updated, it is uploaded to MNO 120. MNO 120 automatically accepts the profiles when they are received through interface 220. Then, in accordance with GSMA specifications, the target device establishes an internet connection and receives the new profile.

[0045] Figure 3 is a flowchart of a method for delegated management of eUICC profiles according to one embodiment. This method can be performed on the remote eSIM provisioning system 200 shown in Figure 2.

[0046] In step S10, the LPA 142 registers the eUICC 141 with the e-server 210. In step S20, the LPA 142 obtains a list of profile identifiers, ICCIDs, each ICCID uniquely identifying the respective profile available for that eUICC 141. In step S30, a profile ICCID is selected from the obtained list, and delegated management is added to the profile with the selected ICCID. In particular, delegated management can be added in step S50 by adding it to an already established subscription group, or in step S60 by creating a subscription group with the selected ICCID. The subscription group for the profile ICCID is preferably located on the server. Details of the execution of steps S50 and S60 will be described later with reference to Figures 6A and 6B, as well as Figures 7B and 7C.

[0047] Before adding delegated management to the selected profile, a secure communication channel may be established between the LPA 142 and the server 210 in step S40.

[0048] Figure 4 shows the substeps of the preferred execution of registration step S10 in Figure 3, and Figure 7A shows the signal diagram of registration step S10 (indicated by the Roman numeral I in Figure 7A).

[0049] In some embodiments of the present invention, registration of eUICC 141 in server 220 may include obtaining the eUICC identifier EID from eUICC in step S11.

[0050] With respect to Figure 7A, step S11 can be performed by LPA 141 by sending the retrieveEID() command to eUICC in step S111 and receiving the retrieveEIDResponse(EID) command from eUICC in step S112. Both commands may be GSMA-compliant commands as described, for example, in SGP, 22 RSP Technical Specification, Version 2.2.2, June 2020.

[0051] In step S12, the LPA may request eUICC to create a key pair by sending, for example, the command createKeypair() to eUICC (step S121 in Figure 7A), receiving createKeyPairResponse(PublicKey) (step S122 in Figure 7A), and thus obtaining the public key of eUICC in step S13.

[0052] Subsequently, LPA 141 may generate a Certificate Signing Request (CSR) in step S14. The CSR includes the public key received from eUICC in step S121. Then, in step S15, LPA may register the identifier EID, CSR, and device name received from eUICC in step S11 with server 210.

[0053] Once registration with the server is performed, the certificate is received by the LPA in step S16 and stored in step S17. The certificate is signed by the certificate authority to enable verification of the server's integrity.

[0054] Figure 5 shows a substep of a preferred execution of step S20 in Figure 3, which obtains a list of available profile ICCIDs for the device user, including the eUICC. The corresponding signal diagram is shown in Figure 7B.

[0055] Referring to Figure 5, steps S27-S28, and Figure 7C, the list of profile ICCIDs is obtained from eUICC.

[0056] Step S27 can be performed using a conventional GSMA command as described in the SGP.22 RSP Technical Specification, for example, ES10b.GetProfilesInfo, shown by S27 in Figure 7C.

[0057] Optionally, if the MNO provides assistance for the registered eUICC (a check performed in step S21), the ICCIDs of the corresponding user profiles may be obtained in addition to the steps of obtaining them from the MNO and eUICC (steps S22-S26 in Figure 5 and the part indicated by the Roman numeral II in Figure 7B). In particular, the LPA 142 may be notified by the server 210 to perform a redirection to the MNO site in step 213. This signal / message prompts the LPA to sign in to the MNO with a username and password in step S22 and to receive a sign-in confirmation from the MNO, including an authentication token, in step S23. Using this authentication token, the LPA may request a list of profile ICCIDs from the MNO in step S24 and receive the ICCIDs in step S25.

[0058] The use of authentication tokens provides a way to authenticate a protected profile once (perhaps within a limited-duration session), and then use that token to perform further authentication during that session.

[0059] The list of received profile ICCIDs can be saved by the LPA in step S26 for future use.

[0060] When a list of profile ICCIDs is retrieved, one profile ICCID is selected, and delegated management is added to the corresponding profile identified by the selected ICCID. This is preferably achieved by adding the selected ICCID to an existing subscription group, or by creating a new subscription group and adding the selected ICCID to that new subscription group. Preferably, a new subscription group is created if there are no subscription groups available on the server for delegated management. Alternatively, several subscription groups can be created and stored on the server.

[0061] Profiles added to a subscription group accessible by the server using that ICCID are managed by delegation, that is, by a third party rather than by the MNO. In other words, profile management for a given profile group is delegated by the MNO to a third party.

[0062] A preferred embodiment for adding delegated management to a profile is described below with reference to Figures 6A and 6B. Figure 6A shows a flowchart for adding delegated management to a free profile, and Figure 6B shows a flowchart for adding delegated management to an installed free profile. The corresponding signal diagrams are the lower portion indicated by Roman numeral III in Figure 7B and Figure 7C (Roman numeral IV). A free profile refers to a profile supported by the MNO that has not been downloaded and installed in the eUICC. An already installed profile refers to a profile that has already been downloaded and installed in the eUICC.

[0063] Referring to parts III in Figures 6A and 7B, in step S31, one profile ICCID is selected from the list of profile ICCIDs received from the MNO, and delegated management is added to it.

[0064] In step S41, a secure channel is established between LPA 142 and server 210.

[0065] Once the list of profile ICCIDs is obtained from the MNO, in step S31, a free profile is selected for which delegated management will be added. That is, a profile is selected, removed from the MNO's management scope, and managed by company 300. If there is already a subscription group established on a server to support delegated management for the identified profile, in step S51, the server is instructed to add the selected ICCID along with the profile name to this subscription group.

[0066] The corresponding signaling communication may include sending a request, joinSubscriptionGroup(subscriptionGroupID, ICCID, profileName) command to the server, as shown in step S511 of Figure 7B. subscriptionGroupID is an identifier that identifies the subscription group, ICCID is an identifier of the selected profile, and profileName is the name of the selected profile. The joinSubscriptionGroupResponse() received from the server in step S512 confirms receipt of the request.

[0067] If a new subscription group is to be created for delegated management (Figure 6A, step S61), the createSubscriptionGroup(ICCID, profileName) command is sent to the server in step S611 of Figure 7B, where ICCID is an identifier and profileName is the name of the selected profile. In step S612, an acknowledgment is received from the server in the LPA, which contains the identifier of the created subscription group.

[0068] If the list of profile ICCIDs is obtained from eUICC, the procedure is the same as in the case described above, with a significant difference in the steps of adding to an existing subscription group or creating a new subscription group, which will be explained below with reference to Figures 6B and 7C. In particular, the profile IMSI is considered instead of the profile name.

[0069] In other words, if there is already a subscription group established on a server that supports delegated management for the profile identified therein, in step S52 the server is instructed to add the selected profile ICCID along with the profile IMSI to the subscription group.

[0070] The corresponding signal communication in Figure 7C may include sending the request joinSubscriptionGroup(subscriptionGroupID, ICCID, IMSI) command to the server in step S511.

[0071] If a new subscription group is to be created for delegated management (step S62 in Figure 6B), the createSubscriptionGroup(ICCID, IMSI) command is sent to the server in step S621 in Figure 7C. In step S622, the LPA receives an acknowledgment from the server, which includes the identifier of the created subscription group.

[0072] The methods, interfaces, and apparatus described through the embodiments above allow the management of profile groups to be delegated to a third party, such as a company providing mobile devices equipped with eUICC. By delegating the management of eUICC profiles to a third-party company via a server and dedicated interface, the workload on MNOs in handling a large number of connected devices and their profiles is significantly reduced.

[0073] In the above description, the present invention has been described in relation to specific embodiments thereof. However, it will be apparent that various improvements and modifications can be made to these without departing from the broader scope of the invention. For example, the process flow described above describes a particular sequence of process operations. However, many of the sequences of process operations described can be changed without affecting the scope or operation of the invention. The specification and drawings should therefore be considered illustrative rather than restrictive.

Claims

1. A method for delegated management of profiles of an embedded universal integrated circuit card, eUICC (141), included in a mobile device (140), wherein the mobile device (140) further includes a local profile assistant, LPA (142), - Registering the eUICC (141) with the server (210) using the LPA (142) (S10), - In the LPA (142), obtain a list of profile identifiers, where each profile identifier uniquely identifies the respective profile available for the eUICC (141) (S20), - Select a profile identifier from the acquired list using the LPA (142) (S30), - To add delegated management to the profile identified by the selected profile identifier, by adding it to an existing subscription group of profiles on the server (210) using the selected profile identifier in accordance with the instructions of the LPA (142) (S50), or by creating a new subscription group on the server (210) based on the selected profile identifier in accordance with the instructions of the LPA (142) (S60) (S50, S60), Includes, A management method in which a third party directly modifies or updates a profile, which is a profile within a subscription group on the server (210) that was under the management of the MNO (120), and to which delegated management has already been added, based on the delegated management.

2. Registering the eUICC (141) with the server (210) (S10) - Obtaining the eUICC identifier, EID from the eUICC (141) (S11), - Obtaining the public key from the eUICC (141) (S12, S13), - To generate a certificate signing request and CSR including the public key (S14), - Registering the mobile device with the EID and CSR on the server (S15), The method according to claim 1, including the method described in claim 1.

3. The method according to claim 1, wherein registering the eUICC (142) with the server (210) (S15) includes receiving a confirmation message from the server (210) that includes a signed certificate (S16) and storing the certificate (S17).

4. Obtaining the list of profile identifiers (S20) - The server (210) checks whether there is a mobile network operator, MNO (120) to which the server (210) is connected and which performs functions for the eUICC (141) (S21), - If there is an MNO(120) that performs the above function, obtain a first list of profile identifiers from the MNO(120), - Obtain a second list of profile identifiers from the eUICC(141), - Combining the first list with the second list to obtain the list of profile identifiers, The method according to claim 1, including the method described in claim 1.

5. Obtaining the first list of the aforementioned profiles from the MNO(120) is: - Signing in to the MNO (120) using the personal identification data stored in the eUICC (141) (S22), - Receiving an authentication token from the aforementioned MNO (120) (S23), - Using the authentication token, request the MNO (120) to provide the first list of profile identifiers (S24), - Receiving a first list of profile identifiers from the MNO (S25), wherein the first list includes the profile identifier and profile name of the profile provided by the MNO, - To store the first list of the profile identifiers (S26), The method according to claim 4, including the method described in claim 4.

6. Obtaining a second list of profile identifiers from the eUICC is: - Sending a GSMA-compliant command to the eUICC (141) (S27), - Receiving a second list of profiles from the eUICC (141) (S28), wherein the second list of profiles includes the profile metadata of the eUICC for each profile installed in the eUICC. The method according to claim 4, including the method described in claim 4.

7. The method according to claim 1, further comprising establishing a secure communication channel with the server (210) by the LPA (142) (S40, S41) before adding delegated management to the selected profile (S50, S60).

8. When the list of profile identifiers is obtained from the MNO(120), Adding to the subscription group on the server (210) (S50) includes instructing the server (210) to add the selected profile identifier along with the profile name to the subscription group (S511), The method according to claim 5, wherein creating a subscription group on the server (210) (S60) includes instructing the server (210) to create a new subscription group with a subscription group identifier and to add the profile identifier along with the profile name to the new subscription group (S611).

9. If the list of profile identifiers is obtained from the eUICC(141), Adding to the subscription group on the server (210) (S50) includes instructing the server (210) to add the selected profile identifier to the subscription group along with the IMSI (S52), The method according to claim 6, wherein creating a subscription group on the server (210) (S60) includes instructing the server (210) to create a new subscription group with a subscription group identifier and to add the profile metadata to the new subscription group (S62).

10. A device (210) for managing the profile of an embedded universal integrated circuit card, eUICC (141), contained in a mobile device (140), which can be connected to at least one mobile network operator, MNO (120), - The device (210) assists in the authentication of the eUICC (141), and the authentication becomes possible upon registration of the eUICC (141). - Provides the creation and management of subscription groups containing multiple profiles, and allows a third party to directly modify or update a profile within the subscription group on the device (210) that has already been added with delegated management, which was under the management of the MNO (120), based on the delegated management. - Provides uploading and / or downloading profiles to / from the at least one MNO (120). A device (210) configured in such a way.

11. Furthermore, the apparatus (210) according to claim 10 is configured to assist in the registration of the mobile device (140).

12. The apparatus (210) according to claim 10, configured to store and manage eUICC profiles provided by at least one mobile network operator, MNO (120).

13. The apparatus (210) according to claim 12, further configured to manage profile groups, receive instructions for performing profile updates, and upload updated profiles to the at least one MNO (120).

14. A remote eUICC profile management system (200), - A mobile device (140) comprising an embedded universal integrated circuit card, eUICC (141) and a local profile assistant, LPA (142), - The apparatus (210) according to any one of claims 10 to 13, Includes, - A system (200) configured to receive a request for delegated management from a company (300), and upon receiving the request for delegated management, to perform the method described in any one of claims 1 to 9.

15. A computer program, which, when executed by a computer, sends a signal to the LPA (142) in the mobile device (140). - Perform eUICC (141) registration on the server (210), - Obtain a list of profile identifiers, each profile identifier uniquely identifies the respective profile available for the eUICC(141), - Select a profile identifier from the acquired list, and - By adding the profile on the server (210) to an existing subscription group, or by creating a new subscription group on the server (210) based on the selected profile identifier, delegated management is added to the profile identified by the selected profile identifier. A computer program that allows a third party to directly modify or update a profile, which is a profile within a subscription group on the server (210) that was under the management of the MNO (120), and to which delegated management has already been added, based on the delegated management.

Citation Information

Patent Citations

  • Delegated profile and policy management

    US20180206123A1