Method for configuring a network device, as well as communication module and network device comprising same
The authentication certificate system for network devices with secure elements addresses the issue of mismatched origins and versions, ensuring secure and reliable operation by verifying the application program's origin and version, thus maintaining functional safety and security.
Patent Information
- Application Number
- PCT/EP2025/058000
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-26
- Filing Date
- 2025-03-24
- Publication Date
- 2025-10-02
AI Technical Summary
Existing methods for configuring network devices with secure elements like eUICCs do not adequately ensure functional safety and security while maintaining deployability and availability, often due to mismatched origins and versions of application programs and secure elements.
Implementing an authentication certificate system where the secure element checks the origin of the application program, ensuring it comes from a trusted source, and verifying the program's version, thereby enabling secure interaction and configuration.
This approach guarantees reliable and secure operation by verifying the application program's origin and version, ensuring functional safety and security without compromising deployability and availability.
Smart Images

Figure EP2025058000_02102025_PF_FP_ABST
Abstract
Description
[0001] METHOD FOR CONFIGURING A NETWORK DEVICE, AS WELL AS
[0002] COMMUNICATION MODULE AND NETWORK DEVICE COMPRISING SAME
[0003] Technical Field
[0004] The present disclosure relates to the field of authenticating application programs, such as Local Profile Assistants (LPAs) and / or Internet-of-Things (loT) Profile Assistants (IPAs) for interacting with secure elements, such as embedded Universal Integrated Circuit Cards (eUICCs) of network devices. In particular, the present disclosure relates to a method for configuring a network device, to a communication module configured to communicate via a telecommunication network, comprising a secure element, such as an eUICC, and to a network device configured to communicate via a telecommunication network, comprising a secure element, such as an eUICC.
[0005] Background of the Invention
[0006] Network devices, such as personal mobile devices or loT-devices, configured to employ electronic subscriber profiles for communicating on mobile networks are known from the prior art. Such network devices are typically equipped with electronic / embedded secure elements (SE, eSE), such as an UICC, eUICC, iUICC, SIM, eSIM, or iSIM, configured to store one or more electronic subscriber profiles that may allow the network devices to connect to one or more mobile networks. A subscriber profile (e.g., an eSIM profile) may be generated by a mobile network operator (MNO) and may be stored, e.g., downloaded to a mobile network device. The subscriber profile may then be installed on a secure element of the network device and used for communication over a corresponding mobile network by the network device.
[0007] Corresponding application programs, such as LPAs and / or IPAs, assist in storing, installing, and managing the subscriber profiles. Hence, LPAs and / or IPAs are functional elements in the network device or in the SE that provides the Local Profile Download (LPD), Local Discovery Services (LDS) and Local User Interface (LUI) features. When the LPA and / or IPA is located in the Device, they are called LPAd, LPDd, LUId, LDSd. When the LPA is located in the eUICC, they are called LPAe, LPDe, LUIe, LDSe. Where LPA, LPD, LDS or LUI are used, they apply to the element independent of its location in the device or in the eUICC.
[0008] Typically, LPA services provide necessary access to the services and data required by functions of the LPA. These services may comprise providing a Profile Package transfer from the LPA to the ISD-P, a list of installed Profiles, retrieve an identifier of a SE, such as a so-called EID, and further local profile management operations. IPA services provide necessary access to the services and data required by functions of the IPA. These services may include providing the address of the Root SM-DS and (if configured) the default SM- DP+, Transfer Bound Profile Packages from the IP Ad to the ISD-P, lists of installed profiles and their profile metadata, retrieving EIDs, as well as providing Profile State Management Operations, eUICC execution results and Notifications.
[0009] WO 2023 / 017031 Al, for example, relates to methods, interfaces, sand devices for delegated management of profiles of an eUICC, included in a mobile device. Delegated management is provided to a profile selected from a list of profiles available at the eUICC by registering the eUICC with a server and joining with the selected profile an existing subscription group of profiles on the server or by creating a new subscription group on the server based on the selected profile.
[0010] WO 2021 / 047765 Al describes mechanisms for profile handling of a batch of identity modules. Each identity module in the batch of identity modules has credentials for secure installation of profiles. A method is performed by an LPA of a proxy device. The LPA comprises credentials for profile download. The credentials comprise a certificate. The credentials enable the LPA to act as a virtual identity module. Another method is performed by a subscription management entity. Yet another method is performed by an identity module in the batch of identity modules.
[0011] Methods for handling application programs, such as LPAs and IPAs, subscriber profiles and related system architecture for network devices, for example, their operating system (OS) according to the prior art, as described above, may not fully satisfy all requirements regarding their deploy ability and availability on the one hand, as well as functional safety and security on the other hand. For example, it is desirable that both, the application programs, and secure elements have the same origin and preferably same state of development in order to ensure functional safety and security. However, due to deployability and availability restrictions, it may not be always assured that the application programs, as well as the secure elements have the same origin or corresponding versions. This may compromise functional safety and security when operating method devices, may even lead to that the devices cannot be configured properly.
[0012] Summary of the Invention
[0013] It may be seen as an object to improve the interaction between the application programs and the secure elements. In particular, it may thus be seen as an object to provide a way to handle application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability. These objects are at least partly achieved by the subject-matter of the independent claims.
[0014] According to an aspect, a method for configuring a network device is provided, the method comprising the steps of providing an application program, in particular an LPA and / or IPA, adapted to interact with a secure element, such as an eUICC, of the network device, and checking an authentication certificate authenticating an origin of the local application program with the secure element.
[0015] According to an aspect, a communication module configured to communicate via a telecommunication network is provided, comprising a secure element, such as an eUICC, configured to check an authentication certificate authenticating an origin of an application program, in particular an LPA and / or IPA, adapted to interact with the secure element.
[0016] According to an aspect, a network device configured to communicate via a telecommunication network is provided, comprising a secure element, such as an eUICC, configured to check an authentication certificate authenticating an origin of an application program, in particular an LPA and / or IPA, adapted to interact with the secure element.
[0017] The proposed solution has the advantage over the prior art, that the authentication of the origin of the application program can help in verifying and thus assuring that the application program stems from a trusted supplier or supply chain. Thereby, a reliable interaction between the application program and the secure element may be guaranteed to the extent that application programs from a certain origin can be specifically designed, tried and structure are tested in order to be operated with respective types of secure elements. In letting the secure element check the authentication certificate, the authenticating step itself becomes highly secure and can be carried out at a set of stage with limited communication capacities of the network device or even off-line before the network device is enabled to communicate via a communication network.
[0018] Furthermore, e.g., version control may be carried out in the course of authenticating the origin of the application program, assuring that a proper version of the application program and / or the secure element is at hand. In other words, the step of checking the authentication certificate may be part of a routine for configuring the network device to be enabled to communicate via a telecommunication network. This helps handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability. Further developments can be derived from the dependent claims and from the following description. Features described with reference to a communication module, network device and components thereof may be implemented as method steps, or vice versa. Therefore, the description provided in the context of the communication module, network device and their components apply in an analogous manner also to respective methods. In particular, features and functions of the communication module, network device and their components may be implemented as method steps which in turn may be implemented as respective device features or functions, respectively.
[0019] According to a possible embodiment of the method, the method further comprises the step of issuing the authentication certificate to the secure element. The authentication certificate may be issued and / or provided by a trusted entity. An issuer and / or manufacturer of the secure element may serve as and / or control the trusted entity. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0020] According to a possible embodiment of the method, the method further comprises the step of providing the authentication certificate to the network device via a telecommunication network. The authentication certificate may be sent to the network device from the trusted entity, for example, from respective server device controlled by the trusted entity, in order to be received by the network device. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0021] According to a possible embodiment of the method, the method further comprises the step of handing the authentication certificate from the application program to the secure element. The authentication certificate can be handed to the secure element via a respective application programming interface (API), which may assure a proper interaction between the application program at the secure element. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0022] According to a possible embodiment of the method, the method further comprises the step of storing the authentication certificate in the secure element. The secure element may provide secure memory space, for example as a part of a non-volatile memory implemented in the secure element. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0023] According to a possible embodiment of the method, the method further comprises the step of obtaining an identifier from the secure element. The identifier may help in verifying an origin of the secure element. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0024] According to a possible embodiment of the method, the identifier is a unique device identifier of the secure element. Hence, the authentication process can be carried out individually for the respective unique secure element. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0025] According to a possible embodiment of the method, the method further comprises the step of requesting the secure element to check the authentication certificate. Thereby, the authentication process can be initiated at a desired point of time or state of configuring the network device. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0026] According to a possible embodiment of the method, the step of checking the authentication certificate involves determining a presence of the authentication certificate. Based on the presence of the authentication certificate, certain configurations of the network device may be carried out and / or selected. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0027] According to a possible embodiment of the method, the method further comprises the step of enabling at least one function of the application program if the authentication certificate is present or disabling at least one function of the application program if the authentication certificate is not present. Thereby, again certain configurations of the network device may be carried out and / or selected. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0028] According to a possible embodiment of the method, the step of checking involves assessing a validity of the application certificate. For assessing validity of the application certificate, a certificate signature may be checked. The certificate signature may be issued and / or provided by the trusted entity. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0029] According to a possible embodiment of the method, the method further comprises the step of enabling at least one function of the application program if the authentication certificate is valid or disabling at least one function of the application program if the authentication certificate is not valid. Thereby, again certain configurations of the network device may be carried out and / or selected. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0030] According to a possible embodiment of the method, the method further comprises the step of denying responses from the secure element to the application program if the step of checking the authentication indicates certification problems. Thereby, unauthorized combinations of application programs and secure elements can be prevented. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0031] According to a possible embodiment of the method, the method further comprises the step of returning results of the step of checking the authentication certificate to a trusted entity. The trusted entity may be an issuer of the authentication certificate. The results will be sent to a respective server device. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0032] According to a possible embodiment of the method, the method further comprises the step of implementing an action if the step of checking the authentication indicates certification problems. The trusted entity may implement the action. The action may involve obtaining data regarding the network device and / or the secure element. A provider providing the and / or access to the telecommunication network may be provided with the data. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0033] According to a possible embodiment of the network device, the network device comprises a storage unit containing the application program. For example, the application program may be stored in a dedicated memory space of the storage unit. This further helps in handling application programs and secure elements in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0034] According to a possible embodiment of the network device, the application program is configured to handle at least one subscriber profile of a subscriber of the telecommunication network. Hence, any desired or required profile management function may be carried out help of the application program. This further helps in improving functional safety and security of network devices. According to a possible embodiment of the network device, the network device is configured to be associated to at least one of a personal entity and a machine entity. The personal entity may relate to a personal mobile device, such as a smart phone, smartwatch, etc. The machine entity may relate to an Internet of Things (loT) device, such as a multimedia device, camera, speaker, household appliance, vehicle, vending machine, or alike, adapted for communication via the telecommunication network. This further helps in improving functional safety and security of personal communications or machine communications, respectively.
[0035] A computer program may comprise instructions which, when the program is executed by a computing device, cause the computing device to execute a method, control a communication module, a network device, and / or a sever device, to perform any of the steps of a method as described herein. In particular, the computer program can comprise instructions which, when the program is executed by a network device, configured to communicate via a telecommunication network, cause a secure element, such as an eUICC, of the network device to check an authentication certificate authenticating an origin of an application program, in particular an LPA, adapted to interact with a secure element, with the secure element. A computer-readable data carrier, such as a computer-readable medium and / or a data carrier signal, may carry the computer program.
[0036] Brief Description of the Drawings
[0037] Fig. 1 is a schematic illustration of an authentication system for authenticating an application program in line with a method according to the present invention.
[0038] Fig. 2 is a schematic illustration of a communication hierarchy of components involved in the authentication system illustrated in Fig. 1.
[0039] Detailed Description of Embodiments The following detailed description is merely exemplary in nature and is not intended to limit the invention and uses of the invention. Furthermore, there is no intention to be bound by any theory presented in the preceding background or the following detailed description. The representations and illustrations in the drawings are schematic and not to scale. Like numerals denote like elements. A greater understanding of the described subject matter may be obtained through a review of the illustrations together with a review of the detailed description that follows.
[0040] Fig. 1 shows a schematic illustration of an authentication system 1 comprising a computer device 2, for instance a server device controlled by a trusted entity T, and network device 3, for example, in the form of a personal mobile device, such as a smart phone, smartwatch, etc, to be associated with a personal entity, and / or in the form of an Internet of Things (loT) device, such as a multimedia device, camera, speaker, household appliance, vehicle, vending machine, or alike, to be associated with a machine entity, respectively, and adapted for communication via the telecommunication network (not shown) by means of at least one subscriber profile P. The network device 3 may comprise a storage unit 4 for storing an application program A, such as a LPA and / or IPA, and a communication module 5 having a secure element 6, such as an UICC, eUICC, iUICC, SIM, eSIM, iSIM, SE, or eSE, enabling communication via the telecommunication network. The secure element 6 may be identified by an identifier E, such as an EID, and may comprise a storage area 7, such as a non-volatile memory, for storing the subscriber profile P and an authentication certificate C for authenticating an origin O of the application program A.
[0041] A method for authenticating the origin O of the application program may have several steps S which may be carried out by and / or with the help of an authentication module M that can be stored in the storage unit 4 and can be a part of the application program A. In a first step SI, the application program A may obtain the identifier E from the secure element 6, for example by reading the identifier E. In a second step S2, at least one function F according to a respective functionality of the network device 2 may be restricted for a period of time before the authentication is carried out successfully. For example, the secure element 6 may be muted to not carry out any communication functions via the communication network before the authentication is not carried out successfully. In a third step S3, the application program A may send a verification request to the secure element 6 to carry out an authentication of the origin O of the application program A.
[0042] In a fourth step S4, the authentication of the origin O of the application program A is carried out by the secure element 6, example, within the secure element 6. The application step may involve checking a signature D of the certificate C, which can be issued by the computing device 2. After authentication, in a fifth step S5, the functionality of the network device 3, in particular the communication module 5, may be determined, for example, by returning to the second step S2 of restricting functionality, if the authentication is not (fully) successful, for example, by blocking any communication by or at least responses to Application Protocol Data Units (APDU) between the application program A and the secure element 6. If, on the contrary, the authentication is (fully) successful, restrictions of functionality of the network device 3 and / or the communication module 5, can be removed, thus enabling a desired set of the respective functions F. In a sixth step S6, authentication results R of the authentication can be returned from the secure element 6 to the application program A. In a seventh step S7, the network device 3 can forward the authentication results R to the computer device 2.
[0043] In an eighth step S8, the certificate C, for example, provided with the signature D, can be sent from the computing device 2 to the network device 3. For example, the certificate request can be initiated by sending the identifier E to the computing device 2 and the seventh step S7, such that the computing device 2 can assessed, whether the secure element 6 is fulfilling certain requirements, such as that it may have a same or at least certified origin O. The provision of the certificate C from the computing device 2 to the network device 3, in particular the application program A, may be regarded as zeroth step SO, preceding all previous steps, for example, if the application program A and / or the secure element 6 are or is, respectively, provided with the certificate during manufacturing of the network device 3. In a ninth step S9, certificate data, for example, comprising the authentication results R and / or the signature D can be routinely sent from the network device 3 to the computing device 2, for instance, after a certain amount of time or after a reset or any other kind of specific operation carried out by the network device 3. Therefore, the application program A, in particular the application module M may return to the first step S 1 and / or the third step S3 in order to then carry out all subsequent steps. In a tenth step S10, the authentication results R may be confirmed, if the authentication is (fully) successful, and / or it may be acted upon the authentication results R by the computing device 2 if the authentication is not (fully) successful. For example, if the latter is the case, the application program A, in particular the authentication module M may cause the secure element 6 to return to the second step S2 and / or the fifth step S5 for determining, in particular, restricting, functionality of the network device 3, especially the communication module 5 and / or secure element 6 thereof, by disabling certain functions F to be carried out.
[0044] The authentication system 1, in particular the computing device 2, and / or the network device 3 are or is, respectively, configured to execute a computer program 10. A computer- readable data carrier 11 can have stored thereon the computer program 10 and may take the form of a computer-readable medium 12 and / or data carrier signal 13. When carrying out the computer program 10, the authentication system 1 and any components thereof communicate as specified in the computer program 10. Parameters associated with and / or underlying the authentication system 1, any of the components thereof and / or any of the steps carried out thereby, can be defined in and / or by the computer program 10.
[0045] Fig. 2 shows a schematic illustration of a communication hierarchy of components involved in the authentication system 1 illustrated in Fig. 1, for example, in line with the X.509 format specification of the International Telecommunication Union (ITU) for structuring the certificate D and its provision. The trusted entity T, for example, as the origin O, can be at the highest hierarchy level and may provide and / or create the application program A, the authentication module M, the certificate C, the signature D, and the computing device 2, which can be regarded as being arranged at the second highest hierarchy level. The trusted entity may further provide and / or create the secure element 6 which can be configured to communicate through the application program A and / or the authentication module M, and therefore can be regarded as being arranged at a third highest hierarchy level.
[0046] List of Reference Signs
[0047] 1 authentication system
[0048] 2 computing device / server device
[0049] 3 network device / mobile device / loT device
[0050] 4 storage unit
[0051] 5 communication module
[0052] 6 secure element
[0053] 7 storage area / non-volatile memory
[0054] 10 computer program
[0055] 11 computer-readable data carrier
[0056] 12 computer-readable medium
[0057] 13 data carrier signal
[0058] A application program
[0059] C certificate
[0060] D signature
[0061] E identifier
[0062] F function
[0063] M authentication module
[0064] O origin
[0065] P subscriber profile
[0066] R authentication result
[0067] S step
[0068] T trusted entity
[0069] 50 create / provide certificate
[0070] 51 obtain identifier
[0071] 52 restrict functionality
[0072] 53 request authentication carry out authentication / check certificate determine functionality return authentication results forward identification results send certificate (routinely) check authentication confirm / act on authentication results
[0073] ASPECTS A method for configuring a network device, the method comprising the steps of providing an application program, in particular an LPA and / or IPA, adapted to interact with a secure element, such as an eUICC, of the network device, and checking an authentication certificate authenticating an origin of the application program with the secure element. The method according to aspect 1, further comprising the step of issuing the authentication certificate to the secure element. The method according to aspect 1, further comprising the step of providing the authentication certificate to the network device via a telecommunication network. The method according to aspect 1, further comprising the step of handing the authentication certificate from the application program to the secure element. The method according to aspect 1, further comprising the step of storing the authentication certificate in the secure element. The method according to aspect 1, further comprising the step of obtaining an identifier from the secure element. The method according to aspect 6, wherein the identifier is a unique device identifier of the secure element. The method according to aspect 1, further comprising the step of requesting the secure element to check the authentication certificate. The method according to aspect 1, wherein the step of checking the authentication certificate involves determining a presence of the authentication certificate. The method according to aspect 9, further comprising the step of enabling at least one function of the application program if the authentication certificate is present or disabling at least one function of the application program if the authentication certificate is not present. The method according to aspect 1, wherein the step of checking involves assessing a validity of the application certificate. The method according to aspect 11, further comprising the step of enabling at least one function of the application program if the authentication certificate is valid or disabling at least one function of the application program if the authentication certificate is not valid. The method according to aspect 1, further comprising the step of denying responses from the secure element to the application program if the step of checking the authentication indicates certification problems. The method according to aspect 1, further comprising the step of returning results of the step of checking the authentication certificate to a trusted entity. The method according to aspect 14, further comprising the step of implementing an action if the step of checking the authentication indicates certification problems. A communication module configured to communicate via a telecommunication network, comprising a secure element, such as an eUICC, configured to check an authentication certificate authenticating an origin of an application program, in particular an LPA and / or IPA, adapted to interact with the secure element. A network device configured to communicate via a telecommunication network, comprising a secure element, such as an eUICC, configured to check an authentication certificate authenticating an origin of an application program, in particular an LPA and / or IPA, adapted to interact with the secure element. The network device of aspect 17, comprising a storage unit containing the application program. The network device of aspect 17, wherein the application program is configured to handle at least one subscriber profile of a subscriber of the telecommunication network. The network device of aspect 17, wherein the network device is configured to be associated to at least one of a personal entity and a machine entity.
Claims
CLAIMS1. A method for configuring a network device (3), the method comprising the steps of providing an application program (A), in particular an LPA and / or IPA, adapted to interact with a secure element (6), such as an eUICC, of the network device (3), and checking an authentication certificate(C) authenticating an origin of the application program (A) with the secure element (6).
2. The method according to claim 1, further comprising the step of issuing the authentication certificate (C) to the secure element (6); the step of providing the authentication certificate (C) to the network device (3) via a telecommunication network; the step of handing the authentication certificate (C) from the application program (A) to the secure element (6); and / or the step of storing the authentication certificate (C) in the secure element (6).
3. The method according to claim 1 or 2, further comprising the step of obtaining an identifier (E) from the secure element (6).
4. The method according to claim 3, wherein the identifier (E) is a unique device identifier of the secure element (6).
5. The method according to at least one of claims 1 to 4, further comprising the step of requesting the secure element (6) to check the authentication certificate (C).
6. The method according to claim 5, wherein the step of checking the authentication certificate (C) involves determining a presence of the authentication certificate (C) and / or assessing a validity of the application certificate (C).
7. The method according to claim 6, further comprisingthe step of enabling at least one function (F) of the application program (A) if the authentication certificate (C) is present or disabling at least one function (F) of the application program (A) if the authentication certificate (C) is not present; and / or the step of enabling at least one function (F) of the application program (A) if the authentication certificate (C) is valid or disabling at least one function (F) of the application program (A) if the authentication certificate (C) is not valid.
8. The method according to at least one of claims 1 to 7, further comprising the step of denying responses from the secure element (6) to the application program (A) if the step of checking the authentication indicates certification problems.
9. The method according to at least one of claims 1 to 8, further comprising the step of returning results of the step of checking the authentication certificate (C) to a trusted entity (T).
10. The method according to at least one of claims 1 to 9, further comprising the step of implementing an action if the step of checking the authentication indicates certification problems.
11. A communication module (5) configured to communicate via a telecommunication network, comprising a secure element (6), such as an eUICC, configured to carry out a method according to at least one of claims 1 to 10.
12. A network device (3) configured to communicate via a telecommunication network, comprising a secure element (6), such as an eUICC, configured to carry out a method according to at least one of claims 1 to 10 for checking an authentication certificate (C) authenticating an origin of an application program (A), in particular an LPA and / or IPA, adapted to interact with the secure element (6).
13. The network device (3) of claim 12, comprising a storage unit (4) containing the application program (A).
14. The network device (3) of claim 12 or 13, wherein the application program (A) is configured to handle at least one subscriber profile (P) of a subscriber of the telecommunication network.
15. The network device (3) of at least one of claims 12 to 14, wherein the network device (3) is configured to be associated to at least one of a personal entity and a machine entity.
Citation Information
Patent Citations
Profile handling of a batch of identity modules
WO2021047765A1
Delegated euicc profile management
WO2023017031A1
An access control method, apparatus and system
CN107766717B
LPA automatic compiling method and system of eSIM device and medium
CN116017403A
Subscription Profile Downloading Method, Device, and Server
US20190373448A1