A system for switching the connection of a secure element from a public network to a private network, corresponding applet and entity
The system uses a secure element applet with real-time network topology updates to facilitate immediate switching from a public to a private network, addressing inefficiencies in existing methods and enhancing user experience and battery efficiency.
Patent Information
- Application Number
- PCT/EP2024/087881
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-27
- Filing Date
- 2024-12-20
- Publication Date
- 2025-07-03
AI Technical Summary
Existing solutions for switching a telecommunication terminal from a globally accessible public network to a local private network are inefficient, leading to prolonged delays and increased battery consumption, without requiring modifications to the terminal.
A system comprising a secure element with an applet that switches connections from a public network to a private network based on real-time updates from a global private network database, using a bi-directional channel to share local network topology information, allowing immediate connection to the private network upon detection of coverage.
Enables rapid and efficient switching to a private network with minimal battery impact and improved user experience, supporting various NPN architectures without complex network planning or administrative overhead.
Smart Images

Figure EP2024087881_03072025_PF_FP_ABST
Abstract
Description
[0001] A system for switching the connection of a secure element from a public network to a private network, corresponding applet and entity
[0002] FIELD OF THE INVENTION
[0003] The present invention concerns telecommunications and more precisely secure elements like UICCs (Universal Integrated Circuit Cards), SIM (Subscriber Identity Module) cards, USIMs (Universal Subscriber Identity Modules), eUlCCs (embedded UICCs) or iUICCs (integrated UICCs). These secure elements cooperate with telecommunication terminals (UE for User Equipment) like smartphones, mobile phones, PDAs (Personal Digital Assistants) or loT (Internet of Things) devices.
[0004] BACKGROUND
[0005] Secure elements have the purpose to establish and secure communications between telecommunication terminals and telecommunication networks.
[0006] There are two major kinds of telecommunication networks: Public and private. Public telecommunication networks are also called PLMNs (Public Land Mobile Networks). A PLMN can be a Home PLMN (HPLMN) or a visited PLMN (VPLMN).
[0007] In schools, airports, big factories, energy utilities, manufacturing sites, ports or offshore platforms for example, private cellular networks or NPN (Non-Public Networks) can be installed to restrict the access to these networks to given and identified users of telecommunication terminals that are covered by these private cellular networks.
[0008] In an example, a NPN is installed in a large-scale airport and it is desired to provide good quality mobile connection in this area. It is thus possible to build a privately owned mobile network, "rent" some of the mobile operator's or ask the mobile operator to build / provide one for this purpose.
[0009] Whilst the concept has been implemented in previous generations, 5G specifications support various configurations of NPNs.
[0010] NPNs provide three benefits in terms of performance. First, a NPN brings optimized coverage for the owner as the network is deployed for the owner's purpose and not for the public in general. Second, the local presence of some network entities reduces physical distance and number of network hops required for the use case, reducing the latency of the NPN. Finally, the local presence reduces uncertainty of network operation, as the disruption (e.g., outage, fault) of the corresponding entities can be managed / resolved inside.
[0011] NPNs also enable more control from the owner's side in general. The security of the network can be enhanced by restricting unauthorized users and the privacy of the data treated can be enhanced. In addition, traffic can be prioritized depending on the types of users in the organization as per its requirements. Similarly, management of congestion and interference can be optimized according to the requirement of the organization.
[0012] While there are many possible configurations of NPNs, 3GPP defines two major categories of NPNs: Standalone Non-Public Network (SNPN) and Public network integrated NPN (PNI-NPN).
[0013] In one extreme, there is SNPN, which refers to an NPN that does not rely on network functions provided by a Public Land Mobile Network (PLMN), mobile network operator in simple words. SNPN deployed in isolation corresponds to the concept of private network and indicates that SNPN involves more investment and commitment from the owner. In the other extreme, there is PNI-NPN, which refers to an NPN that is deployed with the support of a PLMN. PNI-NPN may be deployed as a private slice (dedicated network slice by the PLMN for the sole use of the owner), or may involve part of the networks being deployed by the PLMN and others by the owner.
[0014] The purpose of the invention is to switch from a globally accessible public network to a locally accessible private network. This switch is initiated by the secure element as soon as it detects the presence of the private network (the terminal with which it cooperates is covered by the private network). This switch is notably performed to minimize communication costs, tackle security risks and narrow the attack surface.
[0015] The term “private network” used in this invention is equivalent to Non-Public Network (or NPN in 3GPP specifications) or is also sometimes called Mobile Private Network (MPN). 3GPP does not allow a search for higher priority PLMN when a UE is camping on a HPLMN or EHPLMN (Equivalent Home PLMN). Existing solutions for switching from a globally accessible public network to a local private network either rely on:
[0016] Setting the global public network as a visited PLMN (VPLMN) with the related issues e.g. on user experience or due to user preference to limit data access when in roaming, and by default mobile terminals (telecommunication terminals) are setup to prevent data usage when in roaming;
[0017] Using the SIM Toolkit location status event sent by the UE to the USIM, but such a method is not optimal when the Private Network is not immediately available after such an event; Support by the UE of a specific method for the USIM to force the UE to perform Network Selection procedure.
[0018] These existing methods have however an impact either on the battery usage or on the User Experience e.g., long delay before switching to the private network or frequent period of UE reinitialization (unavailable for normal use).
[0019] It is outlined in 3GPP standard TS 22.011 that, when connected to a home network or a visited network, a counter (which value is stored in EF_HPPLMN) can be setup to define a time interval between two attempts to connect to a private network. EFHPPLMN (Higher Priority PLMN search period) is a file that contains the interval of time between searches for a higher priority PLMN.
[0020] But even if this counter is set up to one (6F31 field equals 1), the secure element will wait nx6 minutes (i.e. 6 minutes if n=1) between two attempts to connect to a private network. Here
[0021] 6F31 refers to a specific file identifier (FID) within the SIM file system used in mobile telecommunication systems. It is part of the 3GPP SIM file structure. This time interval is too long for many applications: It is desired to shorten this time interval to the lowest duration possible, especially when the private network is a military network or for IOPS (Isolated Operation for Public Safety) use cases for disaster recovery.
[0022] So, the technical problem the invention intends to solve is: How to automatically force the UE to switch from a globally accessible Public Network to a local Private Network, as soon as possible, without modification of the UE, and with lowest impact on battery consumption and usability.
[0023] The problem will be better understood in regard of figure 1. Figure 1 represents a User Equipment (UE or telecommunication terminal) 10a registered on a PLMN (Public and Mobile Network). Reference 11 represents a HPPLMN search period: After this period, the UE is referenced 10b since it has moved 12 in direction of a NPN 15. After another period of time defined in the HPPLMN, the UE is under coverage of the private network 15 and referenced 10c and can connect to it. However, as already said, the UE will only connect to the NPN 15 after maximum 6 minutes that is a too long duration.
[0024] European Patent Application Publication No. EP4258714A1 describes a secure element application for triggering a mobile equipment to perform preferred network selection procedure to attach to a private network and corresponding secure element.
[0025] International Patent Application Publication No. WO2023106347A1 describes a method for sending first information indicating a first network slice which is available in a first network where the UE is located and second information indicating a second network slice which is required by a service or an application activated in the UE and is not available on the first network.
[0026] SUMMARY
[0027] The proposed invention proposes a solution to this problem.
[0028] More precisely, the invention proposes a system for switching a connection of a secure element from a public network to a private network. The system comprises an entity connected to or comprising a global private network database storing a physical topology of said private network. The entity is accessible by said telecommunication terminal and the physical topology of said private network, stored in the global private network database, is dynamically updated by a plurality of secure elements of telecommunication terminals having access to said private network. The system further comprises a secure element cooperating with a telecommunication terminal. The secure element having access to said private network and cooperating with telecommunication terminal comprises an applet comprising or being connected to a local private network topology database sharing content of said local private network topology database with the global private network database. The applet switches the connection of the secure element from the public network to the private network when the applet determines that the telecommunication terminal with which the applet cooperates enters in the coverage of the physical topology of said private network, based on the content of said local private network topology database. According to some example embodiments, the secure element is one of:
[0029] - a SIM card,
[0030] - an IIICC (Universal Integrated Circuit Card),
[0031] - an eUlCC (Embedded Universal Integrated Circuit Card), or
[0032] - an iUICC (Integrated Universal Integrated Circuit Card).
[0033] According to some example embodiments, the entity is a server or a SaaS (Software As A Service).
[0034] According to some example embodiments, the global private network database is also updated by inputs from a MNO (Mobile Network Operator) operating said private network.
[0035] According to some example embodiments, the telecommunication terminal having said applet, records in said applet, when registered on said private network, records corresponding current location information and uses a CAT (Card Application Toolkit) command to update the local private network database.
[0036] According to some example embodiments, the location information comprises corresponding MCC (Mobile Country Code), MNC (Mobile Network Code), Cell-Id and Timing Advance.
[0037] According to some example embodiments, if the telecommunication terminal having said applet determines an identifier of said private network in a high Priority PLMN (Public Land Mobile Networks) list of the said telecommunication terminal, and after registration attempt to said private network is successful, the applet updates the local private network database with the corresponding current location information.
[0038] According to some example embodiments, if the applet has switched the connection of the secure element from said public network to the private network and if the registration of the secure element with the private network fails, the applet updates the local private network database to indicate that said private network is not available. According to some example embodiments, if the applet determines that an entry in said local private network database is no longer valid, the applet updates said global private network database with information corresponding to the determination.
[0039] According to some example embodiments, the entity is configured to update said global private network database with the content of the local private network topology databases of each of said telecommunication terminals. The entity is further configured to update the local private network topology databases of each of the telecommunication terminals in the vicinity of the coverage of said private network.
[0040] According to some example embodiments, the applet shares the content of the local private network topology database with the global private network database through a bi-directional channel.
[0041] According to some example embodiments, the bidirectional channel comprises SMS-PP (Short Message Service - Point to Point) or BIP (Bearer Independent Protocol).
[0042] According to some example embodiments, the telecommunication terminals is configured to connect to the private network when the applet determines that the telecommunication terminal with which said applet cooperates enters in the coverage of the physical topology of said private network.
[0043] The invention also concerns an applet and an entity for performing such a switch of network.
[0044] BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The invention will be better understood by reading the following description of a preferred architecture of the invention, in regard of the figures that represent:
[0046] Figure 1 the state of the art;
[0047] Figure 2 the result of an accelerated switching from a PLMN to a private network, according to the invention; and
[0048] Figure 3 the architecture of a system according to the invention. Unless the context suggests otherwise, the term “applet” refers to a software program or application designed to perform a specific, limited function within a larger system or environment.
[0049] Figure 1 has already been described in regard of the state of the art.
[0050] Figure 2 represents the result of an accelerated switching from a PLMN to a private network according to the invention.
[0051] In this figure, in a first step, a UE 20a is under coverage of a PLMN having two cells 21 and 22 (i.e. two BTS or eNBs or gNBs). In a second, step, the UE has moved in direction of a NPN 23 and is referenced 20b. At this geographical position, the UE 20b is covered by the cells 21 and 22.
[0052] The UE 20b continues to move in direction of the NPN 23 and a trigger 24 that will be explained herein after switches the connection from the UE 20b ready to enter in the coverage of the NPN 23 from the cell 22 to the cell 23 of the NPN 23. This means that as soon as the UE enters in the cell 23 of a private network, the UE referenced 20c is connected to this private network. Even if, as represented, the NPN is entirely covered by the PLMN cell 22, the UE 20b will not wait for the HPPLMN search duration for trying to connect to the NPN. This means that the switching from a public network to a private network is accelerated.
[0053] This result is obtained thanks to an architecture of a system 300 described herein after in regard of figure 3.
[0054] In this figure, three elements are represented: a secure element 30 like an eUlCC; a User Equipment (UE) 31 cooperating with the secure element 30; and a cloud 32.
[0055] The secure element 30 stores an applet 33, called TPC applet (standing for Topology Private Connect applet), that comprises or is connected to a local private network topology database 34. More precisely, the secure elements of the present invention having access to a given private network comprise an applet comprising or being connected to a local private network topology database 34. The secure elements having access to the private network that do not embed such an applet do not have the advantages proposed by the invention. As illustrated in FIG. 3, the UE (or telecommunication terminal) 31 and the secure element 30 cooperate. In the case the secure element is an elllCC (Embedded Universal Integrated Circuit Card) or an iUICC (Integrated Universal Integrated Circuit Card), the secure element 30 is embedded in the telecommunication terminal 31. It is also possible that the form factor of the secure element 30 is one of a SIM card or an UICC, in which case the secure element 30 is extractible from the UE 31. The UE 31 comprises classically a modem 35 communicating with the TPC applet 33, for example but not limited to by CAT (Card Application Toolkit) commands.
[0056] The cloud 32 can be replaced by a dedicated server.
[0057] The TPC applet 33 communicates with a private network topology service 36 comprised in the cloud or the dedicated server. This private network topology service 36 is an entity, for example a server or a SaaS (Software as a service). Software as a service allows users to connect to and use cloud-based applications over the Internet. The private network topology service 36 can be either in a public cloud or a private cloud or in premises. It is a service accessible from the Internet.
[0058] The entity 36 is connected to or comprises a global private network database 37 storing the physical topology of a private network, at least one private network, this entity 36 being accessible by the UE 31. The physical topology of the private network geographic coverage of the cells of the private network essentially, stored in the global private network database 37, is dynamically updated by a plurality of secure elements 30 embedding the TPC applet 33 having access to the private network. In other words, the information associated with the physical topology of the private network is updated within the global private network database 37 by a plurality of secure elements.
[0059] The TPC applet 33 shares the content of its local private network topology database 34 with the global private network database 37 through a bi-directional channel, being SMS-PP (Point to Point) or BIP (Bearer Independent Protocol) in order to share its knowledge of geographical topology of the private network with other eUlCCs having also access to the private network and comprising also a TPC applet 33 and a local private network topology database.
[0060] The function of the TPC applet is to order a switch of the connection of the UE 31 from a public network to which it is connected to a private network when the private network is reachable by the UE 31 (establish a radio link). This switch is operated when the applet considers that the telecommunication terminal with which it cooperates enters in the coverage of the physical topology of the private network. This consideration is based on the content of the local private network topology database 34.
[0061] The switch can be ordered via a CAT command (e.g., SIM_REFRESH) sent to the modem 35 of the UE 31.
[0062] The result is that the UE 31 will connect to the private network (to one of the cells of the private network) immediately, based on the physical topology of the private network (e.g., coverage of its cells).
[0063] The global private network database 37 can not only be updated by the content of the different local private network topology databases 34 of the eUlCCs 30 embedding such local databases, but also by inputs from the MNO (Mobile Network Operator) operating the private network. To this end, the MNO can provide to the global private network database 37 data permitting eUlCCs of the present invention to improve their knowledge of the physical topology of the private network. This is particularly important when the MNO installs, decommissions or changes the configuration of cells since the physical topology of the private network can then be importantly modified.
[0064] The CAT commands can also be used by the UE 31 to record in the TPC applet 33, when registered on a private network, its current location information. The UE then uses a CAT Command e.g. EVENT DOWNLOAD - Location Status Event, to update the local private network database 34.
[0065] This location information can include for example, but not limited to, its MCC (Mobile Country Code), MNC (Mobile Network Code), Cell-Id, and Timing Advance.
[0066] In order to improve the accuracy of its local private network database 34, when a UE 31 has determined an identifier of the private network in his high Priority PLMN list, and if the registration attempt to the private network is successful, the TPC applet 33 updates its local private network database 34 with its current location information.
[0067] In contrast, if the TPC applet 33 has switched the connection of its secure element 30 from a public network to the private network and if the registration of the secure element 30 with the private network fails, the applet updates its local private network database 34 to indicate that the private network is not available. For the same purpose, if a TPC applet 33 determines that an entry in its private network database 34 is no longer valid, the TPC applet 33 updates the global private network database 37 with information corresponding to the determination.
[0068] The entity 36 has also another important function: It updates the global private network database 37 with the content of the local private network topology databases 34 of each of the telecommunication terminals having such a database and, it updates the local private network topology databases of each of the telecommunication terminals in the vicinity of the coverage of the private network.
[0069] In this manner: each local database 34 has the physical topology of a private network and uses this knowledge to order or not the switch of the modem 35 of its UE 31 from a PLMN to the private network; the physical topology of a private network comprised in a given local database 34 is shared with the local databases of other elllCCs, through the global database 37.
[0070] The entity 36 thus learns the topology of one or a plurality of private networks dynamically from the secure elements 30 of the UEs 31 and shares this information with all secure elements 30 of other UEs 31 so that they can switch as soon as they are camped on the PLMN cells overlapping a private network.
[0071] The entity 36 learns the global topology of NPNs from all UEs and updates devices in the vicinity of location - either while a UE is uploading local NPN database updates or via regular polling (like every day for example).
[0072] The updates sent by the entity 36 to the eUlCCs can be deltas, e.g., the entity 36 sends only the changes to each UE topology database 34. There is then no need to maintain a digital twin of the NPN database of each UE in the entity 36.
[0073] The entity 36 can be implemented using AI / ML (Artificial Intelligence I Machine Learning) techniques to extrapolate the coverage and remove outliers. Additionally, this can be used to detect fake cells aka IMSI (International Mobile Subscriber Identity) catchers and alert the owner of the NPN (cyber defense application). Possible refinements of the invention are:
[0074] - An aging of database entries can be added (to handle better lOPS / tactical bubbles etc.) and avoid wrong systematic switch;
[0075] The connection to the entity 36 is not guaranteed, e.g., in case of SNPN. Therefore, pending changes could be buffered and sent only when connection to the entity 36 is possible;
[0076] The convergence of the system 300 can be accelerated in case of PNI-NPN and the MNO knows the mapping of its network;
[0077] The use of network measurements and timing advance (retrieved via Provide Local Information) can ensure more accurate topology and better where there is real coverage overlap (PLMN cells are usually higher power and therefore larger coverage than NPN cells);
[0078] The entity 36 can use topology information to deduce more accurate coverage area of a NPN;
[0079] The geolocation information can be added to the entity 36 which allows to reconstruct a map of the private network dynamically, in case the UE 31 supports geolocation info reporting;
[0080] Geolocation can help also delay switching from PLMN to NPN to location where there is real coverage overlap (PLMN cells are usually higher power than NPN coverage). In this case, the system 300 can be operated in a stealth mode where connection to PLMN is always disabled and based on geolocation (periodically fetched from the ME, the search of NPN can be triggered, without scanning for cellular networks which can take longer and consume more battery).
[0081] The advantages of the invention are that all NPN architectures, SNPN (Standalone NPN) and PNI-NPN (Public Network Integrated NPN) are supported seamlessly, the switching from a HPLMN to a NPN is fast because this switching does not require complicated network planning and administrative overhead.
[0082] The invention also supports the case when private network is a part of HPLMN and HPPLMN search is not available.
[0083] The invention also concerns an applet 33, an entity 36, and an entity 32 of such a system 300.
Claims
CLAIMS1. A system (300) for switching a connection of a secure element (30) from a public network to a private network, wherein the system (300) comprises:- an entity (32) connected to or comprising a global private network database (37) storing a physical topology of said private network, said entity (32) being accessible by a telecommunication terminal (31), said physical topology of said private network, stored in said global private network database (37), being dynamically updated by a plurality of secure elements of telecommunication terminals having access to said private network,- each of said plurality of secure elements (30) cooperating with a telecommunication terminal (31), each of said secure element (30) having access to said private network comprising an applet (33) comprising or being connected to a local private network topology database (34) sharing content of said local private network topology database (34) with said global private network database (37), said applet (33) switching the connection of said secure element (30) from said public network to said private network when said applet (33) determines that the telecommunication terminal (31) with which said applet (33) cooperates enters in a coverage of the physical topology of said private network, based on the content of said local private network topology database (34).
2. The system (300) according to claim 1 , wherein said secure element (30) is one of:- a SIM card,- an UICC (Universal Integrated Circuit Card),- an eUlCC (Embedded Universal Integrated Circuit Card), or- an iUICC (Integrated Universal Integrated Circuit Card).
3. The system (300) according to claims 1 or 2, wherein said entity (32) is a server or a SaaS (Software As A Service).
4. The system (300) according to any of the claims 1 to 3, wherein said global private network database (37) is also updated by inputs from a MNO (Mobile Network Operator) operating said private network.
5. The system (300) according to any of the claims 1 to 4, wherein the telecommunication terminal (31) having said applet (33) records in said applet (33), when registered on said privatenetwork, records corresponding current location information and uses a CAT (Card Application Toolkit) command to update the local private network database (34).
6. The system (300) according to claim 5, wherein said location information comprises corresponding MCC (Mobile Country Code), MNC (Mobile Network Code), Cell-Id and Timing Advance.
7. The system (300) according to any of the claims 1 to 6, wherein if said telecommunication terminal (31) having said applet (33) determines an identifier of said private network in a Priority PLMN (Public Land Mobile Network) list of the said telecommunication terminal (31), and after registration attempt to said private network is successful, said applet (33) updates the local private network database (34) with the corresponding current location information.
8. The system (300) according to any of the claims 1 to 7, wherein if said applet (33) has switched the connection of the secure element (30) from said public network to said private network and if the registration of said secure element (30) with said private network fails, said applet (33) updates the local private network database (34) to indicate that said private network is not available.
9. The system (300) according to any of the claims 1 to 8, wherein if said applet (33) determines that an entry in said local private network database (34) is no longer valid, said applet (33) updates said global private network database (37) with information corresponding to the determination.
10. The system (300) according to any of the claims 1 to 9, wherein said entity (32) is configured to: update said global private network database (37) with the content of the local private network topology databases of each of said telecommunication terminals; update the local private network topology databases of each of the telecommunication terminals in the vicinity of the coverage of said private network.
11. The system (300) according to any of the claims 1 to 10, wherein said applet (33) shares the content of the local private network topology database (34) with the global private network database (37) through a bi-directional channel.
12. The system (300) according to claim 11 , wherein the bidirectional channel comprises SMS-PP (Short Message Service - Point to Point) or BIP (Bearer Independent Protocol).
13. The system (300) according to any of the claims 1 to 12, wherein the telecommunication terminal (31) is configured to connect to the private network when said applet (33) determines that the telecommunication terminal (31) with which said applet (33) cooperates enters in the coverage of the physical topology of said private network.
14. An applet (33) of a system (300) according to any of the claims 1 to 13.
15. An entity (32) of a system (300) according to any of the claims 1 to 13.
Citation Information
Patent Citations
A secure element application for triggering a mobile equipment to perform preferred network selection procedure to attach to a private network and corresponding secure element
EP4258714A1
Method of user equipment (UE), method of communication apparatus, UE and communication apparatus
WO2023106347A1