A method of monitoring update operations in a storage memory of a universal integrated circuit card (UICC) and uicc

The method of monitoring update operations in the storage memory of a UICC addresses the issue of storage memory deterioration by detecting and counting update operations, allowing for timely countermeasures to prevent malfunctions.

WO2025131335A1PCT designated stage expired Publication Date: 2025-06-26GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/061923
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-22
Filing Date
2024-04-30
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

The storage memory of a universal integrated circuit card (UICC) can be deteriorated or damaged due to frequent update operations, leading to potential malfunctions of the UICC and the device it is embedded in.

Method used

A method is provided to monitor update operations in the storage memory of a UICC, involving detection of update operations, obtaining counter information indicative of the number of operations within a predetermined time period, and providing this information via a communication interface to a terminal device.

Benefits of technology

This method allows for the detection of an unexpected high number of update operations, enabling users to take countermeasures to prevent further damage to the storage memory, thereby preventing malfunctions of the UICC and the device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024061923_26062025_PF_FP_ABST
    Figure EP2024061923_26062025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method of monitoring update operations (110) in a storage memory (10) of a universal integrated circuit card (UICC) (1), in particular an embedded universal integrated circuit (eUICC). The method comprises detecting one or more update operations (105) in a storage memory (10) of the UICC (1), the one or more update operations (105) being initiated by an application (21) executed on the UICC (1, S10). The method further comprises obtaining a counter information based on the one or more detected update operations (105) in the storage memory (10), the counter information being indicative of a number of detected update operations (105) performed in the storage memory (10) over a predetermined time period (S20). The method further comprises providing the counter information via a communication interface (2) of the UICC (1) to a terminal device (100, S30). Th invention also relates to an UICC (1) which is configured to perform said method.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] A method of monitoring update operations in a storage memory of a universal integrated circuit card (UICC) and UICC

[0002] Technical Field

[0003] The disclosure generally relates to the detection of an unexpected number of update operations in a storage memory. In particular, the invention relates to a method of monitoring update operations in a storage memory of a universal integrated circuit card (UICC) as well as to a UICC.

[0004] Technical Background

[0005] Terminal devices, in particular devices having the ability to communicate in a mobile network, or having the same wireless network, of a mobile network operator (MNO) can be operated with a universal integrated circuit card (UICC) or an embedded universal integrated circuit card (UICC) holding one or more MNO owned profiles, i.e., subscriber profiles, that enable an authentication in the mobile network of the respective MNO. The terminal device is often referred to as device only, as compared to the eUICC hosted in the device. A smart phone is an example for such a terminal device.

[0006] An embedded subscriber identity module (eSIM) is issued by an MNO providing network access credentials and implementing the MNO's business logic, like for a pluggable SIM card. Remote SIM provisioning procedures may be implemented in order to load and enable an eSIM to the eUICC without revealing the MNO specific content and logic. There may be operations during which a storage memory of an eUICC is updated. For example, applications of an eSIM may frequently update the storage memory based on so-called command application protocol data units (C- APDUs). Such update operations may deteriorate or even damage the storage memory, in particular non-volatile storage memory, over time which may result in a malfunction of the eUICC and, possibly, also the device in which the eUICC is embedded.

[0007] Summary

[0008] It may be seen as an object of the invention to improve recognition of lifetime reducing events in a storage memory of a UICC or an eUICC.

[0009] A method and a UICC according to the features of the independent claims are provided. Further embodiments are evident from the dependent claims and from the following description.

[0010] According to an aspect, a method of monitoring update operations in a storage memory of a universal integrated circuit card (UICC) is provided. The universal integrated circuit card (UICC) may be a non-embedded universal integrated circuit card, an embedded universal integrated circuit card (eUICC) or an integrated universal integrated circuit card (iUICC). A step of the method comprises detecting one or more update operations in a storage memory, e.g., in a storage memory of the UICC, wherein the one or more update operations are initiated by an application executed on the UICC. A further step of the method comprises obtaining a counter information based on the one or more detected update operations, wherein the counter information is indicative of a number of detected update operations performed in the storage memory during a predetermined time period. A further step of the method comprises providing the counter information via a communication interface of the UICC to a terminal device. The method steps may be performed in the indicated order.

[0011] The inventive method provides a technique or procedure allowing a detection that an unexpected (high) number of update operations in the storage memory, in particular in a non-volatile or persistent storage memory, of the UICC has been performed during the predetermined time period. This in turn allows a user to take appropriate countermeasures to avoid a continuation of such undesired update operations in the storage memory. For example, the detection of an unexpected (high) number of update operations during the time period may indicate a harmful implementation of a subscriber identity module (SIM) or an embedded subscriber identity module (eSIM). For example, an application executed on the UICC may initiate a high number of update operations in the storage memory due to a malfunction of the application.

[0012] As described above, the UICC may particularly be an eUICC. An eUICC may be a SIM hardware that can be personalized remotely with a network operator’s credentials. The eUICC may include a specific operating system (OS), which allows the download or management of MNO specific credentials, the so called eSIM profile. The eUICC may be a soldered chip and can have any form factor, e.g., physical nano SIM, SMD (surface mounted device) or integrated SIM (iSIM).

[0013] The one or more update operations in the storage memory, for example a storage memory of the UICC, may represent interactions with the storage memory that are initiated by an application which is currently executed on the UICC. Such an application may be invoked by a respective command, for example a command application protocol data unit (C-APDU) transmitted from a terminal device to the UICC.

[0014] The update operations may erase or change information in memory cells of the storage memory. In particular, each of the one or more update operations may be allocated to a respective storage memory address, e.g., physical or virtual memory address, for which a corresponding information is to be erased or changed. The one or more update operations in the storage memory can be frequently or irregularly performed. The inventive method now provides the advantage that a malfunction of the UICC, for example a malfunction of a subscriber identity module of the UICC, can be identified by counting the number of update operations which are performed in the storage memory of the UICC during a specified time period.

[0015] In particular, not all update operations performed in the storage memory can be attributed to a regular or normal performance of the UICC. Rather, some of the update operations may, for example, be attributed to an irregular or abnormal performance of the UICC. This may not necessarily be harmful. However, if a certain number of update operations over a certain time period is too high, then there is a risk that the storage memory of the UICC may be adversely affected due to the repeated erases or changes in the memory cells of the storage memory. This aspect becomes important when storage memories like EEPROM or Flash memories are used.

[0016] Therefore, the inventive method provides a technique in which the one or more update operations in the storage memory are detected and can thus be counted. This means that based on the detected update operations the number of detected update operations performed in the storage memory over a predetermined time period can be determined such that the counter information can be obtained. The counter information may at least include the number, i.e., the counts, of detected update operations during the time period. In order to count the update operations in the memory, a counter unit or counter integrated into the UICC may be used.

[0017] The counting of the one or more detected update operations in the storage memory may provide a counter value, for example the number of counted update operations. The counter value may be represented by the counter information. This counter information is then provided via the communication interface of the UICC to the terminal device. The counter information may be automatically sent to the terminal device after specified time intervals or may be actively requested by the terminal device, for example by a corresponding request command received from the terminal device or from another external device.

[0018] The detection and thus the counting of the one or more update operations in the storage memory of the UICC may be initiated by a specific command, for example an APDU, in particular C-APDU. This specific command may trigger the application executed on the UICC, thereby starting the entire counting procedure as described herein.

[0019] According to an embodiment, the one or more detected update operations in the storage memory include one or more erase operations for erasing an information in a memory unit of the storage memory.

[0020] The storage memory may include a plurality of memory units, herein also referred to as memory cells, wherein each of the memory units has a corresponding memory address. An information, e.g., a value, may be stored in the memory units. In order to erase the information in any of the memory units, an update operation in the form of an erase operation may be performed on the memory unit. An erase operation may also precede an update operation, e.g., a changing operation like writing or rewriting an information in a particular memory unit. Such update operations in the form of a changing operation will be described in the following.

[0021] According to an embodiment, the one or more detected update operations in the storage memory include one or more change operations for changing, e.g., exchanging or modifying, an information in a memory unit of the storage memory.

[0022] In order to change the information in any of the memory units, an update operation in the form of a changing operation may be performed on the memory unit.

[0023] According to an embodiment, the one or more update operations in the storage memory are initiated by an application of a subscriber identity module (SIM) or an embedded subscriber identity module (eSIM).

[0024] For example, if the UICC is provided in the form of an eUICC, the one or more update operations in the storage memory can be initiated by an application of an embedded subscriber identity module (eSIM). In particular, the eUICC may include one or more eSIMs. An eSIM is an embedded SIM, i.e., a SIM loadable into the eUICC. The eSIM may include files, application code, application data, etc. The eSIM may be enabled or disabled over-the-air. The one or more eSIMs including their files and applications may be stored in the storage memory of the eUICC.

[0025] In another example, the one or more update operations in the storage memory are initiated by an operating system of the UICC, for example in case of a bug that has occurred in the operating system. According to an embodiment, obtaining the counter information based on the one or more detected update operations in the storage memory includes increasing a counter value for each of the one or more detected update operations.

[0026] A counter unit may count the detected update operations performed in the storage memory by increasing a counter value every time an update operation occurs. In other words, a counter of the counter unit is incremented each time an update operation occurs. The counter information may represent the counter value current set in the counter unit or may represent a time-averaged counter value indicating the counts during a particular time period. The counter information may be stored on the UICC and can be provided to the terminal device upon request by the terminal device.

[0027] According to an embodiment, a further step of the method comprises comparing the counter value to an expected counter value, wherein, when the counter value exceeds the expected counter value, the counter information includes an indication of an unexpected operation of the UICC. This indication of an unexpected operation of the UICC may be sent to the terminal device.

[0028] This comparison may be performed on the UICC itself, for example initiated by the operating system of the UICC. Alternatively, this comparison may be performed by the terminal device or another external device after the counter value has been sent from the UICC to the terminal device or the other external device.

[0029] The expected counter value may represent a predetermined counter value that sets the limit for a normal operation of an application executed on the UICC. This means that the expected counter value may not be exceeded during a normal operation of the UICC such that, during normal operation, the number of update operations is below the expected counter value. If this expected counter value is exceeded, i.e., if the number of update operations performed in the storage memory is higher than the expected counter value, this may indicate an abnormal operation of the UICC. The expected counter value may thus represent a threshold value that is used to determine whether or not the UICC is working properly.

[0030] According to an embodiment, the storage memory is a non-volatile storage memory, for example an electrically erasable programmable read-only memory (EEPROM) or a Flash memory.

[0031] A non-volatile memory, herein also referred to as persistent storage, can retain stored information also in an unpowered mode, whereas volatile memory needs constant power to retain the information stored therein. For a non-volatile storage memory, the information may be stored on a semiconductor memory chip.

[0032] The volatile storage memory may store the application based on which the update operation is performed and may further store the information that is erased or changed by the performance of the application. In particular, the UICC may include one or more SIMs which are stored in the non-volatile storage memory and which include the application(s). In case the UICC is specifically an eUICC, the UICC may include one or more eSIMs which are stored in the non-volatile storage memory and which include the application(s).

[0033] According to an embodiment, the storage memory comprises a physical memory, wherein detecting the one or more update operations in the storage memory comprises detecting one or more update operations in the physical memory, and wherein the method further comprises obtaining the counter information by obtaining a first counter information being indicative of a number of detected update operations performed in the physical memory.

[0034] This means that all update operations which are performed in the physical memory can be detected to obtain the counter information. Therefore, the counter information may also be indictive of whether the counted update operations were performed in the physical memory of the storage memory.

[0035] According to an embodiment, the storage memory comprises a virtual memory, wherein detecting the one or more update operations in the storage memory comprises detecting one or more update operations in the virtual memory, and wherein the method further comprises obtaining the counter information by obtaining a second counter information being indicative of a number of detected update operations performed in the virtual memory.

[0036] This means that all update operations which are performed in the virtual memory can be detected to obtain the counter information. Therefore, the counter information may also be indictive of whether the counted update operations were performed in the virtual memory of the storage memory.

[0037] This provides the possibility that the counting procedure for the update operations may distinguish between update operations performed in the physical memory of the storage memory and update operations performed in the virtual memory of the storage memory. Accordingly, the counter information may include the first counter information, i.e., the information indicating the counts of update operations performed in the physical memory, and the second counter information, i.e., the information indicating the counts of update operations performed in the virtual memory. According to an embodiment, another step of the method comprises receiving, at the UICC, a request command from the terminal device via the communication interface of the UICC, wherein the request command is configured to retrieve the counter information from the UICC, and providing the counter information via the communication interface of the UICC to the terminal device upon receiving the request command from the terminal device.

[0038] This means that the counter information may be actively requested by the terminal device, for example from time to time, in order to evaluate the counter information and thus recognize whether the counter information, e.g., the counter value, indicates an unexpected high number of update operations that were recently performed in the storage memory of the UICC.

[0039] However, it may also be possible that the counter information may be actively sent by the UICC, for example from time to time and / or when an unexpected high number of update operations has occurred in the storage memory of the UICC, e.g., when the current counter value exceeds the expected counter value.

[0040] According to an embodiment, another step of the method comprises obtaining an additional information which is associated to the one or more detected update operations in the storage memory, and preferably providing the additional information via the communication interface of the UICC to the terminal device.

[0041] The additional information may be included in the counter information provided to the terminal device or may be provided along with the counter information to the terminal device. After transmitting the additional information along with the counter information from the UICC to the terminal device, it may be read by the terminal device together with the counter information. This additional information helps to more accurately identify a possible origin or reason of an unexpected high number of update operations.

[0042] For example, it is possible that the execution of an application on the UICC performs too many update operations in the storage memory due to a malfunction of the application of the UICC. In this case, the too high number of update operations can be traced back to said application and the information of the malfunction of this application can be provided as the additional information.

[0043] Obtaining an additional information, in particular tracing the origin of an unexpected high number of update operations may be enabled or disabled using a configuration APDU. For each APDU, the counter information as well as the additional information may be retrieved. However, as described above, the counter information may be requested by the terminal device, for example for each time a corresponding request command like a C-APDU is received from the terminal device. The C-APDU may also be used to configure an amount or type of the additional information that is to be determined and / or retrieved.

[0044] According to an embodiment, obtaining the additional information includes identifying a triggering event based on which the one or more update operations are performed in the storage memory.

[0045] For example, a triggering event like command request, e.g., a C-APDU, may erroneously invoke an application or may provoke an erroneous execution of the application such that undesired update operations are performed in the storage memory due to the execution of the application. The erroneous execution of the application or of another component on the UICC can thus be traced back to the triggering event that led to this erroneous execution. The additional information may then comprise an indication of this triggering event, for example by identifying or flagging this particular triggering event.

[0046] According to an embodiment, obtaining the additional information includes identifying a selected application which is executed on the UICC when the one or more update operations are performed in the storage memory.

[0047] In particular, an application which was intentionally invoked on the UICC may have a malfunction or the like, leading to an erroneous execution of the application that initiates an undesired high number of update operations. The additional information may then comprise an indication of this erroneous execution of the selected application, for example by identifying or flagging this particular application.

[0048] According to an embodiment, obtaining the additional information includes identifying a user profile, e.g., an eSIM, based on which the one or more update operations are performed in the storage memory.

[0049] In particular, update operations by an application in the UICC may be based on a specific user profile, for example a user profile currently activated for the UICC. However, if there is an unexpected high number of update operations that can be traced back the specific user profile, this may indicate a malfunction associated to the user profile or a malfunction of applications associated to the user profile. The additional information may then comprise an indication of this user profile, for example by identifying or flagging this particular user profile. According to an aspect, an embedded universal integrated circuit card (UICC) is provided. The universal integrated circuit card (UICC) may be a non-embedded universal integrated circuit card or an embedded universal integrated circuit card (eUICC). The UICC may be configured to perform the inventive method as described herein. The UICC, for example an operating system of the UICC, is configured to perform one or more update operations in a storage memory, e.g., in a storage memory of the UICC, wherein the one or more update operations are initiated by an application executed on the UICC. The UICC, for example a counter unit of the UICC, is further configured to obtain a counter information based on the one or more update operations, wherein the counter information is indicative of a number of update operations performed in the storage memory during a predetermined time period. The UICC, for example the operating system of the UICC, is configured to provide the counter information via a communication interface of the UICC to a terminal device.

[0050] Brief description of the drawings

[0051] The present invention will hereinafter be described in conjunction with the following drawing figures, wherein like numerals denote like elements, and wherein:

[0052] Fig. 1 shows an exemplary block diagram of a UICC, in particular an eUICC, communicatively coupled to a terminal device.

[0053] Fig. 2 shows a flow diagram of a method of monitoring update operations in a storage memory of a UICC, in particular an eUICC.

[0054] Detailed description of exemplary embodiments The representations and illustrations in the drawings may be schematic and not to scale. A better understanding of the method, system and application described above may be obtained through a review of the shown illustrations together with a review of the detailed description that follows.

[0055] Fig. 1 shows an exemplary block diagram of a UICC which in this case is an eUICC 1. The eUICC 1 comprises a non-volatile storage memory 10, a first eSIM 20, a second eSIM 30, an operating system 40 including a virtual machine 41, e.g., a JAVA virtual machine, and a communication layer 50. The eUICC 1 may comprise further eSIMs (not illustrated), however, in the present example the functioning of the eUICC 1 will be explained with respect to the first eSIM 20. The first eSIM 20 may be loaded to the eUICC 1 and may comprise applications 21, 22, 23, files 24, application code, application data, etc. Analogously, a second eSIM 30 may be loaded to the eUICC 1 as well and may comprise applications 31, 32, files 34, application code, application data, etc.

[0056] The eUICC 1 may interface with a terminal device 100, wherein a communication interface 2, for example according to ISO-7816 may be provided, via which the eUICC 1 can communicate with the terminal device 100.

[0057] For example, the terminal device 100 may comprise or constitute a modem baseband of a mobile device, e.g., a smart phone, a tablet computer, a B2B (business to business) device such as a smart meter, etc. The modem baseband may be configured to communicate via the above-mentioned communication interface 2 with the eUICC 1. The terminal device 100 may further comprise a radio interface via which it can communicate with a mobile network, for example a mobile network of an MNO. In the following, a command flow for operating the eUICC 1 of Fig. 1 will be explained in more detail.

[0058] In a first step 101, the terminal device 100 sends a command application protocol data unit (C-APDU) to the eUICC 1. The C-APDU is sent via the communication interface 2 to the communication layer 50 of the eUICC 1. The communication layer 50 decodes the C-APDU and, in a second step 102, forwards it to the operating system 40 of the eUICC 1.

[0059] In a third step 103, the operating system 40 manages the C-APDU according to the command type, e.g., file read command, update command or status command. The command may read or change the data of the first eSIM 20 which is loaded and enabled in the eUICC 1. The eUICC 1 may use the virtual machine 41, e.g., a JavaCard virtual machine, to read or change the data of the first eSIM 20. In the same way, the virtual machine 41, based on the command, may read or change data of the second eSIM 30 and / or any further eSIM loaded and enabled in the eUICC 1.

[0060] In a fourth step 104, the eUICC further checks whether an application 21, 22, 23, e.g., a JavaCard Applet that is part of the targeted eSIM, e.g., the first eSIM 20, has registered to be triggered on the current command type. In this case, methods or procedures of one or more of the applications 21, 22, 23 are invoked by the virtual machine 41. In the illustrated example, the first application 21 is invoked by the virtual machine 41.

[0061] Thereupon, in a fifth step 105, the first application 21 may read or update variables stored in the non-volatile storage memory 10 of the eUICC 1. Reading or updating the variables in the non-volatile storage memory 10 may depend on the mobile network operator’s (MNO’s) business logic implemented by the first eSIM 20. In a sixth step 106 and in a seventh step 107, the first application 21 returns the control to the virtual machine 41 and to the operating system 40. Simultaneously, the first application 21 may further provide an output. In an eighth step 108 and in a ninth step 109, eUICC 1 returns a response application protocol data unit (R-APDU) to the terminal device 100. The return of the R-APDU may depend on the command type and on the output from the first application 21.

[0062] As explained above with respect to the fifth step 105, the first application 21 may perform an update operation 105 on a memory unit 11, e.g., a memory cell, of the nonvolatile storage memory 10. This update operation 105 may include one or more erase operations for erasing an information in the memory unit 11 or one or more change operations for changing an information in the memory unit 11.

[0063] The non-volatile storage memory 10 used in the fifth step 105 may be a storage memory based on Flash or EEPROM technology. Such storage memories may have limited lifetime if memory cells are updated frequently. Furthermore, the eSIM 20 and its applications 21, 22, 23 including their content and logics may not be revealed to the eUICC 1 and the terminal device 100, such that the first eSIM 20 and its applications 21, 22, 23 may be some kind of “black box” to the eUICC 1 and the terminal device 100. The first eSIM 20 is issued by an MNO providing the network access credentials and implementing the MNO’s business logic, similar to a pluggable SIM card. A remote SIM provisioning procedure may be defined to load and enable the first eSIM 20 to the eUICC 1 without revealing their content and logic.

[0064] If the first application 21 of the first eSIM 20 frequently updates the non-volatile storage memory 10 based on the C-APDUs, as explained above with respect to the fifth step 105, the non-volatile storage memory 10 of the eUICC 1 may possibly deteriorate or even be damaged over time, thereby possibly causing a malfunction of the eUICC 1 and the terminal device 100 in which it is embedded.

[0065] The inventive method, as explained herein and also in further detail with respect to Fig. 2 below, may intercept the fifth step 105, i.e., the update operation 105, by providing a counter information regarding a number of detected update operations 105 performed in the storage memory 10. In particular, a counter unit may increase one or more counters for each update operation 105 performed in the non-volatile storage memory 10. As indicated above, an update operation 105 may constitute an erasing or a changing, e.g., programming, of memory cells of the non-volatile storage memory 10.

[0066] The counter information, in particular the counter values determined by the counter(s), can be provided to the terminal device 100 and the terminal device 100 reads the counter information using C-APDUs configured for that purpose. The interpretation of the counter information, e.g., whether the counter value is unexpectedly high, can be performed externally to the eUICC 1, for example by the terminal device 100 or another external device, which allows to identify harmful eSIM implementations.

[0067] The non-volatile storage memory 10 may be partly or completely virtualized to mitigate lifetime limitations. In particular, virtual addresses may be mapped to changing physical addresses such that repeated update operations 105 of the same virtual address are physically updating changing memory cells. The counter information may be divided into a first counter information, i.e., an information indicating the counts of update operations 105 in the physical memory, and a second counter information, i.e., an information indicating the counts of update operations 105 in the virtual memory, such that the counter information provided to the terminal device 100 may allow a distinction between non-virtualized and virtualized memory update operations 105.

[0068] An additional information may be collected which is associated to the detected update operations 105 in the non-volatile storage memory 10. The additional information is provided, for example along with the counter information, via the communication interface 2 of the eUICC 1 to the terminal device 100. The additional information may include an information about the enabled first eSIM 20, an information about a triggered application 21, 22, 23, an information about a C-APDU or a triggering event.

[0069] The additional information may be read in addition to the counter information by the terminal device 100 such that the additional information helps to more accurately identify the origin or reason of an unexpected high number of update operations 105.

[0070] Fig. 2 shows a flow diagram of a method of monitoring update operations in a storage memory of a UICC, in particular the eUICC 1 as described with respect to Fig. 1 above. In a step S10 of the method, one or more update operations 105 are detected in a storage memory 10 of the eUICC 1, wherein the one or more update operations 105 are initiated by an application 21 executed on the eUICC 1. In another step S20 of the method, a counter information is obtained based on the one or more detected update operations 105 in the storage memory 10, wherein the counter information is indicative of a number of detected update operations 105 performed in the storage memory 10 during a predetermined time period. In a step S30 of the method, the counter information is provided via a communication interface 2 of the eUICC 1 to a terminal device 100.

[0071] In a further step S40, a request command from the terminal device 100 may be received via the communication interface 2 at the eUICC 1, wherein the request command is configured to retrieve the counter information from the eUICC 1. In this case, the provision of the counter information via the communication interface 2 of the eUICC 1 to the terminal device 100 is carried out upon receiving the request command from the terminal device 100. However, it is also possible, that the counter information may be retrieved from the eUICC 1 without a specific command from the terminal device 100. For example, the counter information may be sent to the terminal device 100 at predetermined time intervals or if an expected counter value has been exceeded which indicates to the terminal device 100 that an unexpected operation of the UICC 1 has occurred. This may for instance be indicated by a response status word sent to the terminal device 100.

[0072] The following explanations describe step S20 of the above introduced method in more detail.

[0073] During step S20, a counter value may be obtained which, in a further step S21, is compared to an expected counter value. When the counter value exceeds the expected counter value, the counter information obtained in step S20 further includes an indication of an unexpected operation of the eUICC 1.

[0074] The storage memory 10 may comprise a physical memory, wherein the detection of the one or more update operations 105 in the storage memory 10 as carried out in step S10 comprises detecting one or more update operations 105 in the physical memory. Obtaining the counter information in step S20 may then include obtaining, in a further step S22, a first counter information being indicative of a number of detected update operations 105 performed in the physical memory. The storage memory 10 may also comprise a virtual memory, wherein the detection of the one or more update operations 105 in the storage memory 10 as carried out in step S10 comprises detecting one or more update operations 105 in the virtual memory.

[0075] Obtaining the counter information in step S20 may then include obtaining, in a further step S23, a second counter information being indicative of a number of detected update operations 105 performed in the virtual memory.

[0076] During step S20, a further step S24 may include obtaining an additional information which is associated to the one or more detected update operations 105. In another step S31, said additional information may be provided via the communication interface 2 of the eUICC 1 to the terminal device 100.

Claims

Claims1. A method of monitoring update operations (105) in a storage memory (10) of a universal integrated circuit card (UICC) (1), comprising: detecting one or more update operations (105) in a storage memory (10), the one or more update operations (105) being initiated by an application (21) executed on the UICC (1, S10); obtaining a counter information based on the one or more detected update operations (105), the counter information being indicative of a number of detected update operations (105) performed in the storage memory (10) during a predetermined time period (S20); providing the counter information via a communication interface (2) of the UICC (1) to a terminal device (100, S30).

2. The method of claim 1, wherein the one or more detected update operations (105) in the storage memory (10) include one or more erase operations for erasing an information in a memory unit (11) of the storage memory (10).

3. The method according to any one of the preceding claims, wherein the one or more detected update operations (105) in the storage memory (10) include one or more change operations for changing an information in a memory unit (11) of the storage memory (10).

4. The method according to any one of the preceding claims,wherein the one or more update operations (105) in the storage memory (10) are initiated by an application (21) of a subscriber identity module (SIM) or an embedded subscriber identity module (eSIM) (20).

5. The method according to any one of the preceding claims, wherein obtaining the counter information based on the one or more detected update operations (105) in the storage memory (10) includes increasing a counter value for each of the one or more detected update operations (105).

6. The method according to claim 5, further comprising: comparing the counter value to an expected counter value (S21); wherein, when the counter value exceeds the expected counter value, the counter information includes an indication of an unexpected operation of the UICC (1).

7. The method according to any one of the preceding claims, wherein storage memory (10) is a non-volatile storage memory, in particular an electrically erasable programmable read-only memory (EEPROM) or a Flash memory.

8. The method according to any one of the preceding claims, wherein the storage memory (10) comprises a physical memory; wherein detecting the one or more update operations (105) in the storage memory (10) comprises detecting one or more update operations (105) in the physical memory; wherein the method further comprises:obtaining the counter information by obtaining a first counter information being indicative of a number of detected update operations (105) performed in the physical memory (S22).

9. The method according to any one of the preceding claims, wherein the storage memory (10) comprises a virtual memory; wherein detecting the one or more update operations (105) in the storage memory (10) comprises detecting one or more update operations (105) in the virtual memory; wherein the method further comprises: obtaining the counter information by obtaining a second counter information being indicative of a number of detected update operations (105) performed in the virtual memory (S23).

10. The method according to any one of the preceding claims, comprising: receiving, at the UICC (1), a request command from the terminal device (100) via the communication interface (2) of the UICC (1), the request command being configured to retrieve the counter information from the UICC (1, S40); providing the counter information via the communication interface (2) of the UICC (1) to the terminal device (100) upon receiving the request command from the terminal device (100).

11. The method according to any one of the preceding claims, obtaining an additional information which is associated to the one or more detected update operations (105) in the storage memory (10, S24); providing the additional information via the communication interface (2) of the UICC (1) to the terminal device (100, S31).

12. The method according to claim 11, wherein obtaining the additional information includes identifying a triggering event based on which the one or more update operations (105) are performed in the storage memory (10).

13. The method according to any one of claims 11 or 12, wherein obtaining the additional information includes identifying a selected application (21) which is executed on the UICC (1) when the one or more update operations (105) are performed in the storage memory (10).

14. The method according to any one of claims 11 to 13, wherein obtaining the additional information includes identifying a user profile based on which the one or more update operations (105) are performed in the storage memory (10).

15. A universal integrated circuit card (UICC) (1) configured to: perform one or more update operations (105) in a storage memory (10), the one or more update operations (105) being initiated by an application (21) executed on the UICC (1); obtain a counter information based on the one or more update operations (105), the counter information being indicative of a number of update operations (105) performed in the storage memory (10) during a predetermined time period; provide the counter information via a communication interface (2) of the UICC (1) to a terminal device (100).

Citation Information

Patent Citations

  • Tracking read accesses to regions of non-volatile memory

    US20140173180A1

  • Maintenance operations for memory devices

    US20210019050A1