Method for managing remote manager modules in an embedded universal integrated circuit card, corresponding device and system architecture

WO2025186651A8PCT designated stage Publication Date: 2025-10-02STMICROELECTRONICS INT NV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/051686
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-04
Filing Date
2025-02-17
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Firmware upgrades of embedded UICCs for IoT devices can lead to a security risk by disrupting the association with remote manager modules, making the devices vulnerable to replay attacks and rendering existing profiles and management operations unavailable until re-association is performed.

Method used

A method to manage remote manager modules by storing configuration data related to these modules in a non-volatile memory during firmware upgrades, ensuring the association is retained post-upgrade through commands like StoreEimData and RestoreEimData, which maintain the security state and prevent replay attacks.

Benefits of technology

This approach enhances the security of IoT devices by preventing them from entering an insecure state after firmware upgrades, maintaining the association with remote manager modules and protecting against replay attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025051686_02102025_PF_FP_ABST
    Figure IB2025051686_02102025_PF_FP_ABST
Patent Text Reader

Abstract

Method for managing at least one remote manager module (112) in an embedded Universal Integrated Circuit Card, eUICC for Internet of Things, IoT devices, said eUICC for IoT devices having an upgradable firmware and comprising a memory, in particular a non-volatile memory, and configuration registers, said method comprising: - associating (110; 208) said eUICC for IoT devices with said at least one remote manager module (112) based on a configuration state, said configuration state being stored in said configuration registers; - storing (302; StoreEimData) said configuration state in said memory, obtaining a copy configuration state; - performing (210) a firmware upgrade, said firmware upgrade being configured to affect said configuration state stored in said configuration registers and to not affect said copy configuration state stored in said memory; and - restoring (304; RestoreEimData) said configuration state in said configuration registers by copying the copy configuration state stored in said memory in said configuration registers.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] "Method for managing remote manager modules in an embedded Universal Integrated Circuit Card, corresponding device and system architecture"

[0002] ★ ★ ★ ★

[0003] Technical field

[0004] The description relates to integrated circuit cards .

[0005] One or more embodiments can be applied to integrated circuit cards such as , for instance , embedded UICCs , eUICCs .

[0006] Background

[0007] Integrated circuit cards such as Universal Integrated Circuit Cards , UICCs are widely used in a variety of contexts and applications such as in mobile terminals (mobile network devices ) in order to facilitate establishing a connection with the Global System for Mobile Communications , GSM or the Universal Mobile Telecommunications System, UMTS networks , maintaining the integrity and security of personal data .

[0008] Embedded UICCs , eUICCs are a type of integrated circuit card based on architectural standards published by the GSM Association, GSMA and configured to facilitate a secure storage of one or more S IM ("Subscriber Identity Module" ) card profiles , each of such one or more S IM card profiles comprising unique identi fiers and cryptographic keys used by a cellular network service providers in order to uniquely identi fy each of the profiles .

[0009] For instance , such profiles may be used in a mobile network device comprising a corresponding eUICC, thus , enabling such mobile network device to register and securely communicate via the cellular network .

[0010] The technical speci fication of the GSMA SGP . 32 standard facilitates broadening the use of such eUICCs to loT (" Internet of Things" ) devices by describing the architecture of the eSIM loT system, that is, of an eUICC for loT devices (see, for instance, eSIM loT Technical Specification, Version 1.0.1, 04 July 2023) . loT devices may be devices comprising sensors, processing ability, software and / or other technologies that can be configured to connect and exchange data with other devices and / or systems over the Internet or other communications networks, for instance, the cellular network .

[0011] The general architecture of a system for remotely provisioning and managing an eUICC for loT devices is illustrated in Figure 1.

[0012] Figure 1 illustrates an loT device 100 comprising: an eUICC for loT devices 102, such eUICC for loT devices 102 comprising an ISD-R ("Issuer Security Domain - Root") block 104 and an ISD-P ("Issuer Security Domain - Profile") block 106 that comprises an MNO-SD ("Mobile Network Operator Security Domain") block 108; and an IPAd ("loT Profile Assistant in the loT Device") block 110 configured to serve as a proxy between the eUICC for loT devices 102 and an eSIM loT remote Manager, elM 112.

[0013] The eUICC for loT devices 102, in particular, its ISD-R block 104, may be configured to be interfaced with the IPAd block 110 through: a first IPA--eUICC interface ESlOa, for performing profile download and installation operations and handling profile discovery, and a second IPA--eUICC interface ESlOb, for performing generic eUICC package download and execution.

[0014] The IPAd block 110 may be configured to be interfaced with the elM 112 through an eIM--IPA interface ESipa, for performing profile download and installation operations. Such eIM--IPA interface ESipa may be used for triggering profile download at the IPAd block 110 and for providing a secure transport of the downloaded profiles to the eUICC for loT devices 102 .

[0015] The elM 112 is a module , usually a software implemented module , for instance , a server, conf igured to be external to the loT device 100 and configured to perform profile state management operations .

[0016] The profile state management operations may comprise for instance , sending profile state management packages to the eUICC for ToT devices 102 , enable , disable , and delete profiles or to trigger profile downloads at eUICC of the loT devices . The elM 112 can either be a stand-alone component or a component of a higher-level functional system ( e . g . , device management platform) .

[0017] Such elM 112 may be configured to manage a single device , for instance , the loT device 100 , or a plurality of loT devices , facilitating the management of such devices and their profiles .

[0018] To manage a given device , such elM 112 may be configured to be interfaced with the eUICC for loT devices 102 of such given device through an eIM--eUICC interface ESep, such eIM--eUICC interface ESep being a logical end-to-end interface between elM 112 and such eUICC for loT devices 102 used to transfer eUICC packages for profile state management and elM configuration data by the elM 112 .

[0019] The eUICC packages for profile state management may comprise a REMOTE administration command or a plurality of REMOTE administration commands , that is , a session . A session could comprise even a single command .

[0020] Such REMOTE administration commands may comprise , for instance , the following types of commands : an enable command, used to enable an installed profile in the eUICC 102 ; a disable command, used to disable an enabled profile in the eUICC 102 ; a delete command, used to delete an installed profile in the eUICC 102 ; a list of profile information command, used by the elM 112 to retrieve a list of profile information for installed profiles , including their current state , that is , enabled or disabled, and their associated profile metadata ; a get RAT ( "Rules Authorisation Table" ) command, used by the elM 112 to retrieve the Rules Authorisation Table , RAT from the eUICC 102 ; a configure auto-enable command, used to configure an automatic enabling of a profile in the eUICC 102 ; an ADD elM command, used to add an associated elM 112 to the eUICC 102 by providing elM configuration data ; an update elM command, used to update elM configuration data within the eUICC 102 ; a DELETE elM command, used to delete an associated elM 112 from the eUICC 102 ; and / or a list elM command, used by the elM 112 to request the eUICC 102 to provide a list of currently configured associated elMs .

[0021] Such elM 112 is further configured to communicate with : a SM-DP+ ("Subscription Manager Data Preparation +" ) block 114 , which is a server configured to prepare , store , and deliver digital eS IM profiles based on information obtained from an operator 116 through an operator--SM-DP+ interface ES2+ , such operator--SM-DP+ interface ES2+ being used by the operator to request the preparation of a profile for one or more eUICCs for loT devices 102 and for other administrative functions , and a SM-DS ("Subscription Manager Discovery Server" ) block 118 , which is a server configured to hold a list of the profiles that are available to each o f the considered devices .

[0022] The communication between the elM 112 and the SM- DP+ block 114 may be implemented through an eIM--SM-DP+ interface ES 9+ ' , such eIM--SM-DP+ interface ES 9+ ' being used for profile download and installation and being secured with an HTTPS ("HyperText Trans fer Protocol Secure" ) protocol in server authentication mode .

[0023] The communication between the elM 112 and the SM- DS block 118 may be implemented through an eIM--SM-DS interface ES 11 ' , such eIM--SM-DS interface ES 11 ' being used to retrieve records of the events between such elM 112 and such SM-DS block 118 and being secured by TLS ("Transport Layer Security" ) in server authentication mode .

[0024] In addition, such SM-DP+ block 114 may be configured to be interfaced with the SM-DS block 118 through an SM- DS — SM-SP+ interface ES 12 , such SM-DS — SM-SP+ interface ES 12 being used by the SM-DP+ block 114 to manage event registrations and event deletions on the SM-DS block 118 .

[0025] The MNO-SD block 108 may be configured to be interfaced with the operator 116 through an operator-- eUICC interface ES 6 , such operator--eUICC interface ES 6 being used by the operator in order to manage their profiles stored within the eUICC for loT devices 102 via OTA ( "Over-The-Air" ) services .

[0026] The IPAd block 110 may be further configured to be interfaced with the SM-DP+ block 114 through an IPA--SM- DP+ interface ES 9+ , such IPA--SM-DP+ interface ES 9+ being used for providing a secure transport of profile packages between the SM-DP+ block 114 and the IPAd block 110 , for instance , using an HTTPS ("HyperText Trans fer Protocol Secure" ) protocol in server authentication mode to communicate .

[0027] In addition, such IPAd block 110 may be further configured to be interfaced with the SM-DS block 118 through an IPA--SM-DS interface ES 11 , such IPA--SM-DS interface ES 11 being used to retrieve records of events between such IPAd block 110 and such SM-DS block 118 and being secured by TLS ("Transport Layer Security" ) in server authentication mode .

[0028] The eUICC for loT devices 102 may be further configured to be interfaced with the SM-DP+ block 114 through an SM-DP+--eUICC interface ES 8+ , such SM-DP+-- eUICC interface ES 8+ being configured to couple the ISD- P block 106 of the eUICC for loT devices 102 with the SM-DP+ block 114 in order to provide a secure end-to-end channel between them for the administration of such ISD- P block 106 and the associated profiles during download and installation operations .

[0029] Such coupling provided by such SM-DP+--eUICC interface ES 8+ may be intended to be tunneled either over : the IPA--SM-DP+ interface ES 9+ and the second IPA--eUICC interface ES l Ob for a direct profile download, that is , wherein the IPAd block 110 can directly communicate with the SM-DP+ block 114 , or the elM — SM-DP+ interface ES 9+ ' , the elM — IPA interface ESipa, and the second IPA--eUICC interface ES l Ob for an indirect profile download, that is , wherein the IPAd block 110 communicates with the SM-DP+ block 114 via the elM 112 .

[0030] In the general architecture o f the system for remotely provisioning and managing eUICCs for loT devices 102 as described in Figure 1 , such eUICC for loT devices 102 is to be associated with at least one elM 112 before being able to do any profile state management operations .

[0031] Such association between the eUICC for loT devices 102 and the at least one elM 112 may be done by exchanging data .

[0032] For instance , the elM may send to the eUICC for loT devices 102 , through the eIM--eUICC interface ESep implemented on a communication network N, at least one set of data comprising configuration data of the at least one elM 112 .

[0033] For instance , such association may be performed through a command ADD elM compri sing such at least one set of data and sent by the at least one elM 112 to the eUICC for loT devices 102 , for instance , using the elM- -eUICC interface ESep implemented over the communication network N .

[0034] Such set of data may be sent either by the elM 112 itsel f ( as previously described) already associated with the eUICC or by the IPAd block 110 in case of the first elM adding .

[0035] In response to the reception of the at least one set of data comprising the configuration data of the at least one elM 112 , that is , in response to the reception of a command ADD elM, the eUICC for loT devices 102 is configured to store such set of data, for instance , in the OS ("Operating System" ) of such eUICC 102 .

[0036] After such storing operation, the eUICC for loT devices 102 and the elM 112 may be considered associated .

[0037] For instance , a set of data comprising configuration data of a corresponding elM 112 may comprise : an elM ID, that is , an elM identi fier, unique for each of the elMs associated with a corresponding eUICC for loT devices , for instance , a text string, one or more elM keys , for instance , a public key of an asymmetric key pair, and one or more elM certi ficates , that is , one or more electronic documents attesting a unique association between a public key and the identity of a subj ect , for instance , attesting a unique association between a public key and a corresponding elM .

[0038] It is noted that a di f ferent set of data comprising configuration data of a corresponding elM 112 is to be sent to the eUICC for loT devices 102 for each of the elMs 112 that is to be associated with such eUICC 102 , therefore , a command ADD elM may be sent for each of the elMs 112 that is to be associated with the eUICC 102 by an already associated elM .

[0039] In addition, an elM 112 may be associated with an eUICC for loT devices 102 at any time in the li fecycle of such eUICC for loT devices 102 , and a single eUICC for loT devices 102 may be associated with more than one elM 112 .

[0040] In order to associate an additional elM 112 with an eUICC for loT devices 102 , the set of data comprising configuration data of such additional elM 112 is to be sent , for instance , by an elM that is already associated with such eUICC for loT devices 102 , to such eUICC for loT devices 102 .

[0041] The sending of such set of data may be done , for instance , using a command ADD elM comprising such set of data of the additional elM 112 and sending such ADD elM command from such already associated elM to the eUICC for loT devices 102 , for instance , through the network N .

[0042] Moreover, an elM 112 ( for instance , a first elM to be associated with an eUICC ) may be associated by the IPAd block 110 with an eUICC for loT devices 102 by sending a set of data comprising configuration data of such elM 112 to the eUICC 102 . These configuration data may be used for instance for veri fication of profile state manage operation .

[0043] Even in the case of a first elM association, the sending of such set of data may be done , for instance , using a command ADD elM, that is , an ADD Initial EIM command in case of a first elM association, comprising such set of data and sending such ADD Initial elM command from the IPAd block 110 directly to the eUICC for loT devices 102 , for instance , without using the network N .

[0044] In addition, it is noted that such ADD Initial elM command send by the IPAd block 110 to the eUICC for loT devices 102 shall not comprise a signature in the set of data of the first elM, that is , is not authenticated, while further ADD elM commands that associate additional elMs to the eUICC for loT devices 102 shall comprise a digital cryptographic signature in the set of data of such additional elMs 112 to allow the eUICC 102 to authenticate the set of data, that is , are authenticated .

[0045] Once an elM 112 has been associated with an eUICC for loT devices 102 , such eUICC 102 may be configured to process commands coming from such elM 112 , such commands being signed with an elM private key of an asymmetric key pair, such asymmetric key pair comprising the elM private key and an elM public key, and veri fied on the eUICC side with the elM public key of the asymmetric key pair, for instance , stored by the eUICC 102 .

[0046] An association token generation unit 120 , for instance , a global counter, is configured to generate , i f required in an ADD elM command sent to the eUICC for loT devices 102 by a given elM 112 , an association token AT that is associated with such given elM 112 in order to avoid reply attacks .

[0047] Replay attacks consist in sni f fing and resending previously sent command or a session to the eUICC for loT devices 102 in order to deceive such eUICC for loT devices 102 in accepting and performing such previously sent command or session .

[0048] It is noted that it is also possible to dissociate an elM 112 .

[0049] For instance , the association of the elM 112 and the eUICC 102 may be ended by deleting the set of data comprising the configuration data of the elM 112 from the OS of such eUICC for loT devices 102 .

[0050] For example , the deletion may be performed using a command DELETE elM indicating which elM is to be deleted .

[0051] Such command DELETE elM is sent from an associated elM or from a backend system to the eUICC for loT devices 102 through the network N, for instance .

[0052] A problem of known solutions is a lowering of security arising from firmware upgrades of eUICCs for loT devices 102 .

[0053] In fact , according to the GSMA SGP . 32 standard, an eUICC for loT devices 102 should comprise , for instance stored in its OS , sets of data comprising configuration data related to the elMs 112 to which such eUICC for loT devices 102 is associated, such sets of data being used, as previously described, by the eUICC for loT devices 102 to operate in the general architecture of the system illustrated in Figure 1 .

[0054] Firmware upgrade procedures can be used by eUICC for loT devices manufacturers to provide an updated version of the OS stored in the eUICCs for loT devices 102 , for instance , in order to add new features to the OS , to fix vulnerabilities , and / or the like .

[0055] Known solutions perform such firmware upgrade procedures without considering such sets of data comprising configuration data related to the elMs 112 to which a given eUICC for loT devices 102 is associated, therefore , bringing the given eUICC for loT devices 102 to an insecure state . Furthermore , profile state management operations comprising REMOTE administration commands , ADD elM commands , DELETE elM commands , or the like , are unavailable until a first elM association is performed by the IPAd block 110 through an ADD Initial EIM command .

[0056] Such ADD Initial EIM command can associate the eUICC for loT devices 102 with one of the elMs to which such eUICC for loT devices 102 was associated before a firmware upgrade procedure , while further elM associations are performed through ADD elM commands , for instance , by the others of the elMs to which such eUICC for loT devices 102 was associated before such firmware upgrade procedure .

[0057] Figure 2 illustrates an exemplary scenario 20 bringing a given eUICC for loT devices 102 to an insecure state 212 .

[0058] For instance , in a first step 200 , a given eUICC for loT devices 102 , for example , comprised in an loT device 100 , may be shipped to a customer with a first version of the OS .

[0059] In a second step 202 , the IPAd block 110 performs an unauthenticated first elM association using an ADD Initial EIM command, allowing the association between a first elM 112i and the given eUICC for loT devices 102 , for instance , comprised in the loT device 100 .

[0060] Therefore , in a third step 204 , the given eUICC for loT devices 102 is associated with the first elM 112i, thus , it can be both : remotely managed by such first elM 112i, for instance , via profile state management operations , and associated with other elMs , for instance , via further ADD elM commands , and remotely managed by them .

[0061] Hence , a plurality of management operations may occur, for instance , other elMs may be added, some of the associated elMs may be deleted, profile state management operations may be performed, or the like .

[0062] For instance , in the considered scenario 20 : in a fourth step 206 , the first elM 112i remotely manages the given eUICC for loT devices 102 via profile state management commands PSM, that is , indicating to the given eUICC for loT devices 102 to perform profile state management operations corresponding to the sent profile state management commands PSM; and in a fi fth step 208 , the given eUICC for loT devices 102 is further associated with a second 1122 and a third 112s elM, for instance , via respective ADD elM commands , and is remotely managed by them, for instance , via respective profile state management commands .

[0063] Then, in a sixth step 210 , a firmware upgrade procedure is pushed by the eUICC for loT devices manufacturer to the given eUICC for loT devices 102 in order to , for instance , update the OS to a second version .

[0064] In response to the performing of the firmware upgrade procedure , the eUICC for loT devices 102 is brought , in a seventh step 212 , into an unsecure state , waiting that the IPAd block 110 associates such eUICC 102 , for instance , again with the first elM 112i .

[0065] In addition, such eUICC for loT devices 102 cannot be managed by previously configured elMs , that is , by either the first elM 112i, the second elM 1122 , or the third elM 112s, util their configuration is reapplied, that is , util they are associated again with the eUICC for loT devices 102 .

[0066] Moreover, since any previous association of the eUICC for loT devices 102 with an elM 112 is lost , the eUICC for loT devices 102 is exposed to replay attacks .

[0067] In fact , a malicious entity can sni f f one or more sessions related to the elMs 112 to which such eUICC for loT devices 102 was associated before the firmware upgrade procedure and resend such sni f fed sessions during the unsecure state , for instance , after the first elM association performed by the IPAd block 110 , to deceive the eUICC for loT devices 102 in performing a requested operation .

[0068] Solutions that mitigate the previously described problems , facilitating preventing eUICCs for loT devices from being brought into an unsecure state following the performing of a firmware upgrade procedure may be advantageous to enhance the security of such eUICCs for loT devices .

[0069] Obj ect and summary

[0070] An obj ect of one or more embodiments is to contribute in providing solutions facilitating preventing eUICCs for loT devices from being brought into an unsecure state following the performing of a firmware upgrade procedure in order to enhance the security of such eUICCs for loT devices .

[0071] According to one or more embodiments , that obj ect is achieved via a method for managing remote manager modules having the features set forth in the claims that follow .

[0072] One or more embodiments concern a corresponding device .

[0073] One or more embodiments concern a corresponding system architecture .

[0074] The claims are an integral part of the technical teaching provided in respect of the embodiments .

[0075] Solutions as described herein include a method for managing at least one remote manager module in an embedded Universal Integrated Circuit Card, eUICC for Internet of Things , loT devices , said eUICC for loT devices having an upgradable firmware and comprising a memory, in particular a non-volatile memory, and configuration registers , said method comprising : associating said eUICC for loT devices with said at least one remote manager module based on a configuration state , said configuration state being stored in said configuration registers ; storing said configuration state in said memory, obtaining a copy configuration state ; performing a firmware upgrade , said firmware upgrade being configured to af fect said configuration state stored in said configuration registers and to not af fect said copy configuration state stored in said memory; and restoring said configuration state in said configuration registers by copying the copy configuration state stored in said memory in said configuration registers .

[0076] In various embodiments , said performing operation is performed in response to said eUICC for loT devices receiving a firmware upgrade command from an eUICC for loT devices manufacturer .

[0077] In various embodiments , said firmware upgrade is configured to update an operating system of the eUICC for loT devices , in particular adding features and / or fixing vulnerabilities .

[0078] In various embodiments , said eUICC for loT devices comprises an association token generation unit configured to generate an association token value , said association token value being used in the associating operation of said eUICC for loT devices with said at least one remote manager module , and wherein said configuration state comprises : a state of said association token generation unit , said state being indicative of a last generated association token value ; and configuration data of said at least one remote manager module .

[0079] In various embodiments , said configuration data of said at least one remote manager module may comprise at least one element selected out of a group consisting of : a remote manager module identi fier, such remote manager module identi fier being unique for each remote manager module out of the at least one remote manager module , in particular a text string; at least one cryptographic key related to said at least one remote manager module , said at least one cryptographic key being used to secure communications between said at least one remote manager module and said eUICC for loT devices ; at least one cryptographic certi ficate related to the at least one remote manager module , said at least one cryptographic certi ficate being used to attest an association between said at least one remote manager module and said at least one cryptographic key; an identi fier unit , said identi fier unit being configured to select the at least one cryptographic certi ficate related to the at least one remote manager module out of a plurality of cryptographic certi ficates ; a counter value , said counter value being comprised in communications sent by the at least one remote manager module to the eUICC for loT devices ; said association token value used in the associating operation of said eUICC for loT devices with said at least one remote manager module ; and indications related to at least one communication protocol supported by said at least one remote manager module .

[0080] In various embodiments , said storing operation is performed in response to said eUICC for loT devices receiving a storing command from an eUICC for loT devices manufacturer, in particular wherein said storing command is comprised in a firmware upgrade command sent by the eUICC for loT devices manufacturer, and said restoring operation is performed in response to said eUICC for loT devices receiving a restoring command from the eUICC for loT devices manufacturer, in particular wherein said restoring command is comprised in a firmware upgrade command sent by the eUICC for loT devices manufacturer .

[0081] In various embodiments , said storing operation is performed in response to said eUICC for loT devices receiving said firmware upgrade command sent by the eUICC for loT devices manufacturer and prior performing the firmware upgrade , and said restoring operation is performed in response to said eUICC for loT devices ending the firmware upgrade .

[0082] In various embodiments , said at least one remote manager module is configured to perform profile state management operations in said eUICC for loT devices through profile state management commands signed by said at least one remote manager module .

[0083] In various embodiments , said at least one remote manager module is an eS IM loT remote Manager, elM .

[0084] In various embodiments , the embedded Universal Integrated Circuit Cards , eUICC for Internet of Things , loT devices is operated according to the GSMA SGP . 32 standard .

[0085] Solutions as described herein facilitate preventing eUICCs for loT devices from being brought into an unsecure state following the performing of a firmware upgrade procedure in order to enhance the security of such eUICCs for loT devices .

[0086] Brief description of the figures

[0087] One or more embodiments will now be described, by way of example only, with reference to the annexed figures , wherein : Figure 1 , as previously described, illustrates a general architecture of a system for remotely provisioning and managing an eUICC for loT devices ;

[0088] Figure 2 illustrates , as previously described, an exemplary scenario bringing a given eUICC for loT devices to an insecure state ; and

[0089] Figure 3 illustrates an exemplary scenario according to embodiments of the present description .

[0090] Corresponding numerals and symbols in the di f ferent figures generally refer to corresponding parts unless otherwise indicated .

[0091] The figures are drawn to clearly illustrate the relevant aspects of the embodiments and are not necessarily drawn to scale .

[0092] The edges of features drawn in the figures do not necessarily indicate the termination of the extent of the feature .

[0093] Detailed description

[0094] In the ensuing description one or more speci fic details are illustrated, aimed at providing an in-depth understanding of examples of embodiments of this description . The embodiments may be obtained without one or more of the speci fic details , or with other methods , components , materials , etc . In other cases , known structures , materials , or operations are not illustrated or described in detail so that certain aspects of embodiments will not be obscured .

[0095] Reference to "an embodiment" or "one embodiment" in the framework of the present description is intended to indicate that a particular configuration, structure , or characteristic described in relation to the embodiment is comprised in at least one embodiment . Hence , phrases such as " in an embodiment" or " in one embodiment" that may be present in one or more points of the present description do not necessarily refer to one and the same embodiment .

[0096] Moreover, particular conf igurations , structures , or characteristics may be combined in any adequate way in one or more embodiments .

[0097] The headings / ref erences used herein are provided merely for convenience and hence do not define the extent of protection or the scope of the embodiments .

[0098] For simplicity and ease of explanation, throughout this description, and unless the context indicates otherwise , like parts or elements are indicated in the various figures with like reference signs , and a corresponding description will not be repeated for each and every figure .

[0099] As described in the above , solutions as described herein can prevent eUICCs for loT devices from being brought into an unsecure state following the performing of a firmware upgrade procedure in order to enhance the security of such eUICCs for loT devices .

[0100] Solutions as described herein aims at retaining, in a eUICC for loT devices 102 , sets of data comprising configuration data related to one or more elMs 112 to which such eUICC for loT devices 102 is associated in order to maintain the association with such one or more elMs 112 even after a firmware upgrade procedure .

[0101] Therefore , solutions as described herein aims at retaining an elMs configuration state while a firmware upgrade procedure is performed .

[0102] Such elMs configuration state may comprise : a state of the association token generation unit 120 , for instance, an information about a last association token AT generated by such association token generation unit 120 ; and sets of data comprising configuration data of respective elMs 112 associated to the eUICC for loT devices 102 , for instance , stored in respective registries .

[0103] It is noted that such state of the association token generation unit 120 can be retained in order to prevent replay attacks due to a malicious entity that resends previously sni ffed sessions ( that is , sessions related to one or more elMs 112 to which such eUICC for loT devices 102 was associated before the firmware upgrade procedure ) to the eUICC for loT devices 102 after the end of the firmware upgrade procedure .

[0104] For instance , a set of data comprising configuration data of a respective elM 112 may comprise one or more of : the elM ID, that is , the elM identi fier of the respective elM 112 , as described previously; one or more elM keys of the respective elM 112 as described previously; one or more elM certi ficates of the respective elM 112 as described previously; a Certi ficate I ssuer Public Key Identi fier ("CI Public Key ID" ) , used to select a certi ficate of the respective elM 112 between the one or more elM certi ficates and / or one or more EUM certi ficates , that is , one or more electronic documents attesting a unique association between a public key and a corresponding eUICC for loT devices manufacturer . an anti-replay counter value , used to protect the eUICC for loT devices 102 against replay attacks on eUICC packages sent by the respective elM 112 to the eUICC for loT devices 102 . It is noted that the highest value of the anti-replay counter , that is , the highest anti-replay counter value received from the respective elM 112 and related to such respective elM 112 , is stored within the eUICC for loT devices 102 ; a respective association token AT related to such respective elM 112 either generated by the association token generation unit 120 or by such respective elM 112 ; and one or more communication protocols supported by the respective elM 112 related to the trans fer of such eUICC packages , that is , related to a communication between such respective elM 112 and the eUICC for loT devices 102 .

[0105] The operation of retaining the eTMs configuration state within the eUICC for loT devices 102 during a firmware upgrade procedure may be based on two commands : a StoreEimData command, to be sent to the eUICC for loT devices 102 before performing a firmware upgrade procedure , such StoreEimData command being used to store in a secure area, for instance , in a Non-Volatile Memory of the eUICC for loT devices M ( referring to Figure 1 ) , the elMs configuration state ; and a RestoreEimData command, to be sent to the eUICC for loT devices 102 after the firmware upgrade procedure is completed, such RestoreEimData command being used to restore the elMs configuration state using the data stored in such secure area, that is , copying : the state of the association token generation unit 120 in a given register, for instance , of such association token generation unit 120 , configured to store such state of the association token generation unit 120 during standard operations of the eUICC for loT devices 102 ; and for each of the e lMs 112 that was associated to the eUICC for loT devices 102 before the firmware upgrade procedure , the respective set of data comprising respective configuration data into a respective registry .

[0106] Therefore , solutions as described herein disclose a method for managing at least one remote manager module , for instance , at least one elM 112 , in an embedded Universal Integrated Circuit Card, eUICC for Internet of Things , loT devices 102 , such eUICC for loT devices 102 having an upgradable firmware and comprising a memory M, in particular a non-volatile memory, and configuration registers , for instance , comprising : the given register configured to store the state of the association token generation unit 120 during standard operations of the eUICC for loT devices 102 , and the registries configured to store the respective set of data comprising configuration data of the remote manager modules associated with the eUICC for loT devices 102 .

[0107] Such method comprises : associating, for instance , in a step 202 (via an IPAd block 110 ) and in a step 208 described in the following, such eUICC for loT devices 102 with such at least one remote manager module 112 based on a configuration state , such configuration state being stored in such configuration registers and, for instance , comprising : the state of the association token generation unit 120 , which is indicative of a last generated association token value AT and of a next association token that is to be generated in order to be used in the association operation, and the set of data related to the at least one remote manager module 112 comprising the respective configuration data of such at least one remote manager module 112 ; storing, for instance , in a step 302 described in the following, for instance , through the StoreEimData command, such configuration state in such memory M, obtaining a copy configuration state ; performing, for instance , in a step 210 described in the following, a firmware upgrade , such firmware upgrade being configured to af fect such configuration state stored in such configuration registers and to not af fect such copy configuration state stored in such memory M; and restoring, for instance , in a step 304 described in the following, for instance , through the RestoreEimData command, such configuration state in such configuration registers by copying the copy configuration state stored in such memory M in such configuration registers .

[0108] It is noted that such operation of performing 210 may be performed in response to such eUICC for loT devices 102 receiving a firmware upgrade command from an eUICC for loT devices manufacturer 300 .

[0109] In addition, such firmware upgrade may be configured to update an operating system of the eUICC for loT devices 102 , in particular adding features and / or fixing vulnerabilities .

[0110] As previously described, the eUICC for loT devices 102 may comprise an association token generation unit 120 that is configured to generate an association token value AT , such association token value AT being used in the associating operation, for instance , in the step 202 or 208 , of such eUICC for loT devices 102 with such at least one remote manager module 112 .

[0111] The configuration state may comprise : the state of such association token generation unit 120 , such state being indicative of a last generated association token value AT ; and configuration data of such at least one remote manager module 112 .

[0112] The configuration data of such at least one remote manager module 112 may comprise , as previously described, at least one element selected out of a group consisting of : a remote manager module identi fier, such remote manager module identi fier being unique for each remote manager module out of the at least one remote manager module 112 , in particular a text string; at least one cryptographic key related to such at least one remote manager module 112 , such at least one cryptographic key being used to secure communications between such at least one remote manager module 112 and such eUICC for loT devices 102 ; at least one cryptographic certi ficate related to the at least one remote manager module 112 , such at least one cryptographic certi ficate being used to attest an association between such at least one remote manager module 112 and such at least one cryptographic key; an identi fier unit , such identi fier unit being configured to select the at least one cryptographic certi ficate related to the at least one remote manager module 112 out of a plurality of cryptographic certi ficates ; a counter value , such counter value being comprised in communications sent by the at least one remote manager module 112 to the eUICC for loT devices 102 ; such association token value AT used in the associating operation of such eUICC for loT devices 102 with such at least one remote manager module 112 ; and indications related to at least one communication protocol supported by such at least one remote manager module 112 .

[0113] Figure 3 illustrates an exemplary scenario 30 , for instance , the same scenario of Figure 2 but using the StoreEimData and the RestoreEimData commands , according to embodiments of the present description .

[0114] For instance , in the first step 200 , a given eUICC for loT devices 102 , for example , comprised in an loT device 100 , may be shipped to a customer with a first version of the OS .

[0115] In the second step 202 , the IPAd block 110 performs an unauthenticated first elM association using an ADD Initial EIM command, allowing the association between a first elM 112i and the given eUICC for loT devices 102 , for instance , comprised in the loT device 100 .

[0116] Therefore , in the third step 204 , the given eUICC for loT devices 102 is associated with the first elM 112i, thus , it can be both : remotely managed by such first elM 112i, for instance , via profile state management operations , and associated with other elMs , for instance , via further ADD elM commands , and remotely managed by them .

[0117] Hence , a plurality of management operations may occur, for instance , other elMs may be added, some of the associated elMs may be deleted, profile state management operations may be performed, or the like .

[0118] For instance , in the exemplary scenario 30 , for instance , equal to the previously described scenario 20 : in the fourth step 206 , the first elM 112 i remotely manages the given eUICC for loT devices 102 via profile state management commands PSM, that is , indicating to the given eUICC for loT devices 102 to perform profile state management operations corresponding to the sent profile state management commands PSM; and in the fi fth step 208 , the given eUICC for loT devices 102 is further associated with a second 1122 and a third 112s elM, for instance , via respective ADD elM commands , and is remotely managed by them, for instance , via respective profile state management commands .

[0119] In a sixth step 302 , an eUICC for loT devices manufacturer 300 may send the StoreEimData command to the eUICC for loT devices 102 .

[0120] Such eUICC for loT devices 102 , in response to the reception of such StoreEimData command, may be configured to store in a secure area, for instance , in a Non-Volatile Memory of the eUICC for loT devices M ( referring to Figure 1 ) , the elMs configuration state , that is , the previously described state of the association token generation unit 120 and the sets of data comprising configuration data of respective elMs 112 .

[0121] It is noted that such StoreEimData command may be integrated in a command sent from the eUICC for loT devices manufacturer 300 indicating to perform a firmware upgrade procedure .

[0122] It is noted that such StoreEimData command may be generated within the eUICC for loT devices 102 , for instance , in response to the reception of the command sent from the eUICC for loT devices manufacturer 300 indicating to perform the firmware upgrade procedure . In such a case the eUICC for loT devices 102 may be configured to store in a secure area, for instance , in a Non-Volatile Memory of the eUICC for loT devices M, the elMs configuration state , that is , to execute such StoreEimData command, before performing such firmware upgrade procedure .

[0123] Then, in the seventh step 210 , the firmware upgrade procedure is pushed by the eUICC for loT devices manufacturer to the given eUICC for loT devices 102 in order to , for instance , update the OS to a second version .

[0124] At the end of such firmware upgrade procedure , in an eighth step 304 , the eUICC for loT devices manufacturer 300 may send the RestoreEimData command to the eUICC for loT devices 102 .

[0125] Such eUICC for loT devices 102 , in response to the reception of such RestoreEimData command, may be configured to restore such elMs configuration state , that is , the previously described state of the association token generation unit 120 and the sets of data comprising configuration data of respective elMs 112 , from the secure area, for instance , the Non-Volatile Memory of the eUICC for loT devices M .

[0126] As previously described, such restoring operation may be performed by copying : the state of the association token generation unit 120 in the given register configured to store such state of the association token generation unit 120 during standard operations of the eUICC for loT devices 102 ; and for each of the e lMs 112 that was associated to the eUICC for loT devices 102 before the firmware upgrade procedure , the respective set of data comprising respective configuration data into a respective registry .

[0127] It is noted that such RestoreEimData command may be integrated in the command sent from the eUICC for loT devices manufacturer 300 indicating to perform the firmware upgrade procedure .

[0128] It is noted that such RestoreEimData command may be generated within the eUICC for loT devices 102 , for instance , in response to the end of such firmware upgrade procedure . In such a case the eUICC for loT devices 102 may be configured to restore such elMs configuration state from the secure area, for instance , the Non- Volatile Memory of the eUICC for loT devices M, that is , to execute such RestoreEimData command, after the end of such firmware upgrade procedure .

[0129] Therefore , the storing operation of the method disclosed herein, for instance , performed in the sixth step 302 , may be performed in response to said eUICC for loT devices 102 receiving a storing command, for instance , the StoreEimData command, from an eUICC for loT devices manufacturer 300 , in particular wherein said storing command is comprised in a firmware upgrade command sent by the eUICC for loT devices manufacturer 300 .

[0130] Similarly, the restoring operation of the method disclosed herein, for instance , performed in the eight step 304 , may be performed in response to said eUICC for loT devices 102 receiving a restoring command, for instance , the Res toreEimData command, from the eUICC for loT devices manufacturer 300 , in particular wherein said restoring command is comprised in a firmware upgrade command sent by the eUICC for loT devices manufacturer 300 .

[0131] Alternatively, the storing operation of the method disclosed herein, for instance , performed in the sixth step 302 , may be performed in response to said eUICC for loT devices 102 receiving said firmware upgrade command sent by the eUICC for loT devices manufacturer 300 and prior performing, for instance , in the seventh step 210 , the firmware upgrade .

[0132] Similarly, the restoring operation of the method disclosed herein, for instance , performed in the eight step 304 , may be performed in response to said eUICC for loT devices 102 ending the firmware upgrade .

[0133] In a ninth step 306 , the eUICC for loT devices 102 , for instance , comprised in the loT device 100 , is not in an unsecure state .

[0134] In fact , by using such StoreEimData command and such RestoreEimData command, the eUICC for loT devices 102 comprises , in such ninth step 306 , both the state of the association token generation unit 120 and the sets of data comprising configuration data of respective elMs 112 that were available before the firmware upgrade procedure .

[0135] Therefore , in such ninth step 306 , the eUICC for loT devices 102 is still associated with the elMs 112 to which it was as sociated before the firmware upgrade procedure and is ready to be remotely managed by them, thus , the eUICC for loT devices 102 do not require the IPAd block 110 for being associated to such elMs 112 .

[0136] In addition, since the eUICC for loT devices 102 is still associated with the elMs 112 to which it was associated before the firmware upgrade procedure and since the state of the association token generation unit 120 is known, usually it is recovered to the last value before firmware upgrade , the eUICC for loT devices 102 is not exposed to the replay attacks previously described .

[0137] Solutions as described herein re fers also to an embedded Universal Integrated Circuit Card, eUICC for Internet of Things , loT devices 102 configured to be associated with at least one remote manager module , for instance , an elM 112 , such eUICC for loT devices 102 having an upgradable firmware and comprising a memory M, in particular a non-volatile memory, and configuration registers , for instance , comprising : the given register configured to store the state of the association token generation unit 120 during standard operations of the eUICC for loT devices 102 , and the registries configured to store the respective set of data comprising configuration data of the remote manager modules associated with the eUICC for loT devices 102 , wherein such eUICC for loT devices 102 is configured to perform the operations of the previously described method .

[0138] Solutions as described herein refers also to a system architecture , for instance , the system architecture 10 , comprising : an embedded Universal Integrated Circuit Card, eUICC for Internet of Things , loT devices 102 operating in an loT device 100 , having an upgradable firmware , and comprising a memory M, in particular a non-volatile memory, and configuration registers , for instance , comprising : the given register configured to store the state of the association token generation unit 120 during standard operations of the eUICC for loT devices 102 , and the registries configured to store the respective set of data comprising configuration data of the remote manager modules associated with the eUICC for loT devices 102 , and at least one remote manager module , in particular an eS IM loT remote Manager elM 112 , such at least one remote manager module 112 being configured to be associated with the eUICC for loT devices 102 , wherein such system architecture 10 is configured to perform the operations of the previously described method .

[0139] In addition, such at least one remote manager module 112 may be configured to perform profile state management operations in such eUICC for loT devices 102 , and / or such system architecture 10 may further comprise at least a server 114 , in particular a SM-DP+ server, which is configured to prepare profiles , store profiles , and deliver digital profiles to embedded Universal Integrated Circuit Cards , eUICCs 102 .

[0140] Solutions as described herein facilitate achieving a method for managing remote manager modules in an embedded Universal Integrated Circuit Card to retain, for instance , a state of the association token generation unit and sets of data comprising configuration data related to one or more e lMs to which the eUICC 102 is associated .

[0141] Thus , solutions as described herein facilitate preventing eUICCs for loT devices from being brought into an unsecure state following the performing of a firmware upgrade procedure in order to enhance the security of such eUICCs for loT devices .

[0142] Without prej udice to the underlying principles , the details and the embodiments may vary, even signi ficantly, with respect to what has been described by way of example only without departing from the scope of the embodiments .

[0143] The extent of protection is determined by the annexed claims .

Claims

CLAIMS1. Method for managing at least one remote manager module (112) in an embedded Universal Integrated Circuit Card, eUICC for Internet of Things, loT devices (102) , said eUICC for loT devices (102) having an upgradable firmware and comprising a memory (M) , in particular a non-volatile memory, and configuration registers, said method comprising: associating (110; 208) said eUICC for loT devices (102) with said at least one remote manager module (112) based on a configuration state, said configuration state being stored in said configuration registers ; storing (302; StoreEimData) said configuration state in said memory (M) , obtaining a copy configuration state ; performing (210) a firmware upgrade, said firmware upgrade being configured to affect said configuration state stored in said configuration registers and to not affect said copy configuration state stored in said memory (M) ; and restoring (304; RestoreEimData) said configuration state in said configuration registers by copying the copy configuration state stored in said memory (M) in said configuration registers.

2. Method according to claim 1, wherein said performing (210) operation is performed in response to said eUICC for loT devices (102) receiving a firmware upgrade command from an eUICC for loT devices manufacturer (300) .

3. Method according to claim 1 or claim 2, wherein said firmware upgrade is configured to update an operating system of the eUICC for loT devices (102) , in particular adding features and / or fixing vulnerabilities .

4. Method according to any of the previous claims, wherein said eUICC for loT devices (102) comprises an association token generation unit (120) configured to generate an association token value (AT) , said association token value (AT) being used in the associating (110; 208) operation of said eUICC for ToT devices (102) with said at least one remote manager module (112) , and wherein said configuration state comprises: a state of said association token generation unit (120) , said state being indicative of a last generated association token value (AT) ; and configuration data of said at least one remote manager module (112) .

5. Method according to claim 4, wherein said configuration data of said at least one remote manager module (112) comprises at least one element selected out of a group consisting of: a remote manager module identifier, such remote manager module identifier being unique for each remote manager module out of the at least one remote manager module (112) , in particular a text string; at least one cryptographic key related to said at least one remote manager module (112) , said at least one cryptographic key being used to secure communications between said at least one remote manager module (112) and said eUICC for loT devices (102) ; at least one cryptographic certificate related to the at least one remote manager module (112) , said at least one cryptographic certificate being used to attest an association between said at least one remote manager module (112) and said at least one cryptographic key; an identifier unit, said identifier unit being configured to select the at least one cryptographic certificate related to the at least one remote managermodule (112) out of a plurality of cryptographic certificates ; a counter value, said counter value being comprised in communications sent by the at least one remote manager module (112) to the eUICC for loT devices (102) ; said association token value (AT) used in the associating (110; 208) operation of said eUICC for loT devices (102) with said at least one remote manager module (112) ; and indications related to at least one communication protocol supported by said at least one remote manager module (112) .

6. Method according to any of the previous claims, wherein said storing (302; StoreEimData) operation is performed in response to said eUICC for loT devices (102) receiving a storing command from an eUICC for loT devices manufacturer (300) , in particular wherein said storing command is comprised in a firmware upgrade command sent by the eUICC for loT devices manufacturer (300) , and said restoring (304; RestoreEimData) operation is performed in response to said eUICC for loT devices (102) receiving a restoring command from the eUICC for loT devices manufacturer (300) , in particular wherein said restoring command is comprised in a firmware upgrade command sent by the eUICC for loT devices manufacturer (300) .

7. Method according to any of claims 2 to 5, wherein said storing (302; StoreEimData) operation is performed in response to said eUICC for loT devices (102) receiving said firmware upgrade command sent by the eUICC for loT devices manufacturer (300) and prior performing (210) the firmware upgrade, andsaid restoring (304; RestoreEimData) operation is performed in response to said eUICC for loT devices (102) ending the firmware upgrade.

8. The method according to any of the previous claims, wherein said at least one remote manager module (112) is configured to perform profile state management operations in said eUICC for loT devices (102) through profile state management commands (PSM) signed by said at least one remote manager module (112) .

9. The method according to any of the previous claims, wherein said at least one remote manager module (112) is an eSIM loT remote Manager, elM.

10. The method according to any of the previous claims, wherein the embedded Universal Integrated Circuit Cards, eUICC for Internet of Things, loT devices (102) is operated according to the GSMA SGP.32 standard.

11. An embedded Universal Integrated Circuit Card, eUICC for Internet of Things, loT devices (102) configured to be associated with at least one remote manager module (112) , said eUICC for loT devices (102) having an upgradable firmware and comprising a memory (M) , in particular a non-volatile memory, and configuration registers, and being configured to execute the method according to any of the previous claims.

12. A system architecture (10) , comprising: an embedded Universal Integrated Circuit Card, eUICC for Internet of Things, loT devices (102) operating in an loT device (100) , having an upgradable firmware, and comprising a memory (M) , in particular a non-volatile memory, and configuration registers, and at least one remote manager module (112) , in particular an eSIM loT remote Manager elM (112) , said at least one remote manager module (112) being configured to be associated with the eUICC for loT devices (102) , and characterized in that said system architecture(10) is configured to perform the operations of the method of any of claims 1 to 10.

13. A system architecture (10) according to claim 12, wherein said at least one remote manager module (112) is configured to perform profile state management operations in said eUICC for loT devices (102) and / or said system architecture (10) further comprises at least a server (114) , in particular a SM-DP+ server, which is configured to prepare profiles, store profiles, and deliver digital profiles to embedded Universal Integrated Circuit Cards, eUICCs (102) .