Method for configuring a user device, as well as user device and secure element
The method of configuring user devices with a separate installation program and data component ensures secure element compatibility and security through over-the-air updates, addressing the challenge of maintaining functional safety and security while preserving deployability and availability.
Patent Information
- Application Number
- PCT/EP2025/058082
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-26
- Filing Date
- 2025-03-25
- Publication Date
- 2025-10-02
AI Technical Summary
Existing methods for configuring and updating secure elements in user devices, such as eUICCs, do not adequately ensure functional safety and security while maintaining deployability and availability, often leading to improper device configuration due to mismatched or outdated operating systems and secure elements.
A method involving a separate installation program and data component configuration, allowing for secure elements to be personalized and updated over-the-air, with the installation program remaining static and the data component being dynamically updated, ensuring compatibility and security through trusted entity control.
Ensures functional safety and security of secure elements and their operating systems without compromising deployability and availability by allowing for flexible, efficient, and secure configuration and updates.
Smart Images

Figure EP2025058082_02102025_PF_FP_ABST
Abstract
Description
[0001] METHOD FOR CONFIGURING A USER DEVICE, AS WELL AS USER DEVICE
[0002] AND SECURE ELEMENT
[0003] Technical Field
[0004] The present disclosure relates to the field of providing data to secure elements, such as embedded Universal Integrated Circuit Cards (eUICCs), holding user profiles of user devices, for example, network devices in the form of mobile phones, or alike. In particular, the present disclosure relates to a method of configuring a user device, to a communication module configured to communicate via a telecommunication network, comprising a secure element, such as an eUICC, and to a user device configured to communicate via a telecommunication network, comprising a secure element, such as an eUICC.
[0005] Background of the Invention
[0006] User devices, such as personal mobile devices or loT-devices, configured to employ electronic subscriber profiles for communicating on mobile networks are known from the prior art. Such user devices are typically equipped with electronic / embedded secure elements (SE, eSE), such as an UICC, eUICC, iUICC, SIM, eSIM, or iSIM, configured to store one or more electronic subscriber profiles that may allow the user devices to connect to one or more mobile networks. A subscriber profile (e.g., an eSIM profile) may be generated by a mobile network operator (MNO) and may be stored, e.g., downloaded to a mobile user device. The subscriber profile may then be installed on a secure element of the user device and used for communication over a corresponding mobile network by the user device.
[0007] The secure elements are run by operation systems (OS) containing software and / or firmware for operating the secure elements. Those OS need to be up to date in order to provide full and reliable functionality of the secure elements. An OS Update is especially relevant with the deployment of embedded Secure Elements (eSE) in the form of eUICC or alike. As opposite of traditional pluggable SIMs that can be inserted and removed, eSEs are soldered into user devices, making it very difficult (or costly) to replace them during the life cycle of the user devices. For this reason, there is a need for so-called firmwareupgrades that allow to modify the content of the eSE in the event that it has to be kept up to date and / or a technical issue has to be fixed. Firmware upgrades can be carried out with the help of an Open Firmware Loader (OFL), or alike, which is specifically designed software component in charge of firmware upgrades including OS updates in the secure element.
[0008] DE 10 2021 001 850 Al, for example, relates to a method for personalizing a security element, which method is provided with the following method steps: receiving a request for a bundle of memory images for a plurality of security elements in a data generator, each requested memory image of the received bundle relating to one of the plurality of security elements, and wherein the memory images of the received bundle relating to one of the plurality of security elements; one of the plurality of security elements is fixedly mounted in a corresponding terminal device of the plurality of terminal devices; obtaining, in the data generator, at least one subscription data set for at least one secure element to be personalized of the plurality of secure elements, the subscription data set being obtained from the subscription management server; providing, by the data generator, an operating system or a portion of an operating system for the secure element to be personalized; generating, by the data generator, a memory image for each secure element according to the received request, the memory image of the secure element to be personalized comprising the provided operating system or part of the operating system and additionally comprising the obtained at least one subscription data set; and bundling the generated memory images and providing the bundled memory images as a memory image bundle by a data generator in order to complete the terminal device in order to introduce at least the memory image of the security element to be personalized into the security element in order to personalize the security element.
[0009] US 10 277 587 B2 refers to methods for instantiating multiple electronic subscriber identity modules (eSIMs) to an electronic universal integrated circuit card (eUICC) using a manufacturer-installed data binary large object (data blob). An eSIM package including the data blob in encrypted form is securely installed in the eUICC in a manufacturing environment. A key encryption key (KEK) associated with the eSIM package is separately provided to an original equipment manufacturer (OEM) wireless device factory. The OEM wireless device factory provides the KEK to the eUICC within a given wireless device. The eUICC uses the KEK to decrypt the eSIM package and provide the data blob. The eUICC can receive a request to instantiate a first eSIM. The eUICC can instantiate the first eSIM using data from the data blob. A user can then access network services using the wireless device. Subsequently, a second eSIM can be instantiated by the eUICC using the data blob.
[0010] EP 2 533 485 Bl relates to methods and devices in a mobile communications system for over the air management of mobile stations containing a secure identification element, preferably a subscriber identity module. Generally, the methods and devices are based on the idea to use the standard challenge-response authentication procedure implemented in a mobile communications system not for its intended authentication purpose, but for providing a mobile station with subscription and / or instruction data. The standard challenge-response authentication procedure is modified in that the challenge is used as a carrier for subscription and / or instruction data. This challenge containing the subscription and / or instruction data is provided to the mobile station in response to a request of the mobile station to be allowed access or attachment to the mobile communications system containing a special mode indicator data element, which indicates to the mobile communications system that the mobile station is requesting subscription and / or instruction data and, therefore, is suitably forwarded to a data providing unit configured to provide subscription and / or instruction data.
[0011] Methods for providing and upgrading secure elements of user devices, including OS updates, as described above, may not fully satisfy all requirements regarding their deployability and availability on the one hand, as well as functional safety and security on the other hand. For example, it is desirable that both, the OS, and the secure elements have the same origin and preferably same state of development in order to ensure functional safety and security. However, due to deployability and availability restrictions, it may not be always assured that the OS, as well as the secure elements have the same origin or corresponding versions. This may compromise functional safety and security when operating user devices, may even lead to that the devices cannot be configured properly.
[0012] Summary of the Invention
[0013] It may be seen as an object to improve the interaction between the secure elements and their OS. In particular, it may thus be seen as an object to provide a way to handle secure elements and OS in a way that functional safety and security may be assured, while not compromising deployability and availability. These objects are at least partly achieved by the subject-matter of the independent claims.
[0014] According to an aspect, a method of configuring a user device is provided, the method comprising the steps of providing a secure element, such as an eUICC, with an installation program for loading at least one data component onto the secure element; installing the secure element on the user device, and loading the at least one data component onto the secure element involving the installation program; wherein the at least one data component comprises at least one of a user profile dataset and an operation system dataset for operating the secure element. According to an aspect, a user device is provided, comprising a secure element, such as an eUICC, installed on the user device when containing an installation program for loading at least one data component onto the secure element, and including at least one data component loaded onto the secure element after its installation involving the installation program; wherein the at least one data component comprises at least one of a user profile dataset and an operation system dataset for operating the secure element.
[0015] According to an aspect, a secure element, such as an eUICC, to be installed on a user device, the secure element comprising an installation program for loading at least one data component onto the secure element; wherein the at least one data component comprises at least one of a user profile dataset and an operation system dataset for operating the secure element.
[0016] The proposed solution allows for configuring user devices in a distributed manner, e.g., step by step, for example, for being personalized for an intended user, including but not limited to configuring the user device for communicating via a telecommunication network in line with the GSMA specification SGP.02 v4.2. Providing the installation program, for example, to a fabrication facility, such as a microchip factory, fabricating the secure element, and providing the at least one data component to a manufacturing facility manufacturing the user device may take place at different steps. The at least one data component can be loaded onto the secure element with the aid of the installation program and can and / or has to activated on the secure element before initializing operation of the device by a user. The user profile dataset may refer to any kind of individualized data used to associate the user device to a certain entity or use case.
[0017] The proposed solution has the advantage over the prior art, that the OS can be provided to any manufacturing facility, including OEM / ODM vendor facilities instead of to fabrication facilities of the secure element. The installation program, for example, an OFL component, can be shared among several OS types and / or generations and does not need to be updated once installed in a secure element. From one deployment to another, merely any personalization of the installation program needs to be adapted to respective user requirements, such as specifications by certain MNO (e.g., specific customer credentials to avoid that one OS update dedicated for a specific customer can be deployed to a different one, and / or optional MNO profiles).
[0018] Hence, the proposed solution allows for a configuration and personalization of the installation program along with some credentials and diversified data (i.e., GSMA keys and certificates) with following options: In contrary to the prior art, the OS is not configured together with the installation program, such as an OFL. Diversified data can be configured directly to the installation program as a standalone component, instead of storing the personalization record is an embedded operating system (eOS) and afterwards transferring it to an OFL to be used later on during OS updates for recovery operations, as it is known from the prior art. In that manner, it is possible to update the secure element “Over-The-Air”, removing the necessity of physically replace the secure element for updates and / or upgrades. Thereby, secure elements and their OS can be handled in a way that functional safety and security may be assured, while not compromising their deployability and availability.
[0019] Alternatively, or additionally to said standalone concept, the proposed solution further allows for a combination of the installation program with a very simple (possibly standardized) OS, such as a mini OS, bootloader, etc. In that manner a rather standardized OS can be used to at a fabrication facility providing the secure element to pre-configure certain fundamental data (e.g., GSMA credentials), leaving open for future OS upgrades in manufacturing facilities installing the secure element in the user device. Having the possibility to configure some diversification data including GSMA credentials in the installation program (or alternatively at the simple standard OS), allows to keep GSMA keys and certificates in respective premises of a trusted entity at a desired and / required the same level of protection, thereby assuring that respective security requirement are met.
[0020] Further developments can be derived from the dependent claims and from the following description. Features described with reference to a user device, secure element, and components thereof may be implemented as method steps, or vice versa. Therefore, the description provided in the context of the user device, secure element, and their components apply in an analogous manner also to respective methods. In particular, features and functions of the user device, secure element, and their components may be implemented as method steps which in turn may be implemented as respective device features or functions.
[0021] According to a possible embodiment of the method, the installation program enables the load, install, and / or activate the at least one data component on the secure element. Thereby, respective technical and safety requirements regarding the provision of the at least one data component to the secure element and their interaction can be met. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0022] According to a possible embodiment of the method, the installation program and the at least one data component are being configured separately. In other words, the installation program and the at least one data component are not configured together. The installation program can be preinstalled on the secure element to be ready to install the at least one data component at a later stage. Thereby, the at least one data component can be updated and / or provided in the version most suitable, for example, the latest version available for the secure element. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0023] According to a possible embodiment of the method, the at least one data component is built and / or compiled after providing the secure element. The at least one data component can be provided after initial manufacturing of the secure element. The installation program can then be made available, when the user devise is being manufactured, which then involves installing the secure element in the user device. Thereby, the at least one data component can be updated and / or provided in the version most suitable, for example, the latest version available for the secure element, which may have been compiled after the secure element was fabricated and / or delivered to a manufacturing facility. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0024] According to a possible embodiment of the method, the at least one data component comprises or is comprised of a data image. The at least one data component and / or image may comprise user profile configuration data. As a static data composition, such as a data blob, the data image may help to provide the at least one data component in a way that its integrity can be assured. Thereby, respective technical and safety requirements regarding the provision of the at least one data component to the secure element and their interaction can be met. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0025] According to a possible embodiment of the method, the step of providing the at least one data component to the secure element involves mounting at least a part of the at least one data component on the secure element. A data image including user profile configuration can be mounted in the respective storage unit of the secure element. Thereby, respective technical and safety requirements regarding the provision of the at least one data component to the secure element and their interaction can be met. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0026] According to a possible embodiment of the method, the step of providing the at least one data component to the secure element involves updating at least one previous data component of the secure element. Hence, any kind of data previously installed on the secure element may be updated. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0027] According to a possible embodiment of the method, at least one of the installation program and the at least one data component is or are, respectively, issued and / or provided by a trusted entity. An issuer and / or manufacturer of the secure element may serve as and / or control the trusted entity. Control by the trusted entity can at least implicitly by ensured in that only data components from a certain origin, such as a certain issuer and / or manufacturer, can be used. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0028] According to a possible embodiment of the method, the method further comprises the step of providing at least one of the installation program and the at least one data component via a telecommunication network. The installation program may be sent to a fabrication facility for the secure elements from the trusted entity, for example, from a respective server device controlled by the trusted entity, in order to be received by the fabrication facility. The at least one data component may be sent to a manufacturing facility for the user device from the trusted entity, for example, from a respective server device controlled by the trusted entity, in order to be received by the manufacturing facility. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0029] According to a possible embodiment of the method, multiple secure elements are provided with the installation program for preparing installation of the secure elements. Each of the secure elements may be provided with the installation program before the step of installing the secure elements. The secure elements may be provided with the installation program at a fabrication facility producing the secure elements. This allows for a fast and efficient batch-wise configuration and preparation of the secure elements.
[0030] According to a possible embodiment of the method, the multiple secure elements are provided with the at least one data component for configuring respective user devices. In other words, the at least one data component can be provided in a broadcast mode to a desired number of secure elements. This allows for a fast and efficient batch-wise configuration and preparation of the secure elements, which again helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0031] According to a possible embodiment of the method, the at least one data component is being individualized for a respective secure element. In other words, the at least one data component may be customized and then provided to a specific secure element in a unicast mode. This helps in personalizing the secure element in a highly efficient way.
[0032] According to a possible embodiment of the method, the at least one of the user profile dataset and the operation system dataset is or are, respectively, being individualized for a respective secure element. In other words, either one of the user profile dataset and the operation system dataset can be provided in a broadcast mode, while the respective other one is provided in a unicast mode. Such a provision may be regarded as a hybrid mode. This helps in combining efficient batchwise provision of respective components along with customized components in a highly efficient way.
[0033] According to a possible embodiment of the user device, the installation program is kept static. The installation program may serve for interaction with several types and / or generations of the at least one data component. In other words, the installation program may never be updated, or even be designed such that it cannot be updated once installed in a secure element. Nevertheless, although the installation program may remain static within itself, it can contain diversified data, such as personalized data, e.g., different credentials, per secure element. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0034] According to a possible embodiment of the secure element, the installation program comprises security credentials. The security credentials may comprise any kind of identifier, including software identifiers, device identifiers, network identifiers, access codes, usernames, personal identification numbers (PIN), or alike. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0035] According to a possible embodiment of the secure element, the installation program comprises at least one security key. The at least one security key may comprise any kind of encryption key, access key, personal unlock key (PUK), or alike. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0036] According to a possible embodiment of the secure element, the installation program comprises at least one authentication certificate. The at least one authentication certificate may serve for authenticating the installation program and / or the at least one data component. The at least one authentication certificate can help in validating an origin of the installation program, the profile user profile dataset, the operation system dataset and / or at least one component thereof or related thereto. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0037] According to a possible embodiment of the secure element, the installation program comprises a basic operating system enabling to load the at least one data component onto the secure element. Such a basic operating system may enable the secure element, the user device and / or any computing device communicating therewith, to carry out any of the steps of a method as described herein. The basic operating system may function as a firmware updater, bootloader or mini OS in charge of OS and / or profile updates including first installations. A respective installation program may comprise instructions causing at least one computing device to execute a method, to control a secure element, a user device, and / or a sever device, to perform any of the steps of a method as described herein. A computer-readable data carrier, such as a computer-readable medium and / or a data carrier signal, may carry the installation program. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability. A corresponding computer program may comprise instructions which, when the program is executed by a computing device, such as a server device, cause the computing device to execute a method, control a secure element, a user device, and / or a sever device, to perform any of the steps of a method as described herein. In particular, the computer program can comprise instructions which, when the program is executed by a computer device and / or a user device, for example, in order to configure the user device to communicate via a telecommunication network, cause an interaction with a secure element, such as an eUICC, and / or with a user device comprising the secure element, by means of the installation program, in order to carry out any steps of a method as described herein. A computer-readable data carrier, such as a computer-readable medium and / or a data carrier signal, may carry the computer program. This further helps in handling secure elements and their OS in a way that functional safety and security may be assured, while not compromising deployability and availability.
[0038] Brief Description of the Drawings
[0039] Fig. 1 is a schematic illustration of a computing device as a part of a configuration system for providing an installation program and a data component for secure elements of user devices.
[0040] Fig. 2 is a schematic illustration of an embodiment of a configuration system for configuring user devices involving the installation program and the data component for the secure elements of the user devices.
[0041] Fig. 3 is a schematic illustration of a further embodiment of a configuration system for configuring user devices involving the installation program and the data component for the secure elements of the user devices. Fig. 4 is a schematic illustration of another embodiment of a configuration system for configuring user devices involving the installation program and the data component for the secure elements of the user devices.
[0042] Detailed Description of Embodiments
[0043] The following detailed description is merely exemplary in nature and is not intended to limit the invention and uses of the invention. Furthermore, there is no intention to be bound by any theory presented in the preceding background or the following detailed description. The representations and illustrations in the drawings are schematic and not to scale. Like numerals denote like elements. A greater understanding of the described subject matter may be obtained through a review of the illustrations together with a review of the detailed description that follows.
[0044] Fig. 1 shows a schematic illustration of a configuration system 1 comprising a computer device 2, for instance a server device controlled by a trusted entity T, comprising a hardware security module 3 and data transmission lines 4 adapted to manage and transfer, respectively, data for configuring user devices 5 (see Figs. 2 to 4), for example, in the form of a personal mobile device, such as a smart phone, smartwatch, etc., to be associated with a personal entity, and / or in the form of an Internet of Things (loT) device, such as a multimedia device, camera, speaker, household appliance, vehicle, vending machine, or alike, to be associated with a machine entity, respectively. In the present example, the user devices 5 may be adapted for communication via a telecommunication network (not shown) by means of at least one user profile dataset P to be saved in a respective secure element 6, such as an UICC, eUICC, iUICC, SIM, eSIM, iSIM, SE, eSE, or alike, provided in the form of a computer chip (see Figs. 2 to 4).
[0045] The user profile data sets P are generated based on respective personal records R contained in data files F on the computer device 2, in particular, the hardware security module 3 thereof. The data files F with the personal records R can be viewed as diversified data D. Each user profile dataset P may contain at least a part of a respective personal record R. The user profile dataset P has to be stored on the secure element 6. For storing and managing user profile data sets P on the secure elements 6, and operating system dataset O has to be installed on the secure elements 6. The user profile dataset P and the operating system dataset O can be provided as a combined data component N.
[0046] An installation program I is provided for installing the data component N on the secure element 6. The installation program I can comprise a basic operating system M for the secure elements 6. The basic operating system M can be regarded as a mini operating system, boot loader, or alike, helping to install the data component N on the secure elements 6, for example, in providing a basic framework and / or functions which allow to address a storage area 7 of the secure elements 6 (see Figs. 2 to 4). Additionally, the installation program I can comprise security credentials H, security keys K, and / or authentication certificates J. The security credentials H may comprise any kind of credentials defined by e.g., the GSMA, or alike. The security keys K may comprise any kind of cryptographic code or key element which may be adapted to interact with the the user devices 5, the secure elements 6, as assurer any part of the data component M.
[0047] The authentication certificates J may be any kind of electronic certificate, for example, that can be issued by the trusted entity T, for authenticating an origin of the devices 5, the secure elements 6, the installation program I and / or the data component N.
[0048] The data component N and / or the installation program I can be handled by the computing device 2, in particular in the hardware security module 4, as a protected and / or secured storage, for example, combined as static data G, separately from the file structure F containing the personalisation data R as diversified data D. The static data G and / or the diversified data D may be protected against unauthorised access by respective encryption measures E. The transmission lines 4 handling and / or transferring the static data G and / or the diversified data D may comprise any kind of wired and / or wireless transmission chains, including the Internet (for transmissions “Over-The-Air”) as well as other physical and / or non-physical data carriers, which can be configured and secured as desired and required. Fig. 2 shows a schematic illustration of an embodiment of a configuration system 1 for configuring the user devices 6 involving the installation program I and the data component N for the secure elements 6 of the user devices 5 being provided in a broadcast mode V. A method for configuring mobile devices 5 in the broadcast mode may have several steps S which may be carried out by and / or with the help of the installation program I. In the present example, the configuration system 1 and respective method involve a data facility A serving as the trusted entity T, providing the installation program I and / or the data component N, a fabrication facility B fabricating the secure elements 6, and a manufacturing facility C manufacturing the user devices 5. The data facility A, the fabrication facility B and / or the manufacturing facility C may be combined in function and / or premises as desired or required.
[0049] At the data facility A, the installation program I and / or the data component N may be kept along with the respective personalisation data R in a latent data composition L in a in data provision stage X, for example, at the respective computer device 2, in particular, at the hardware security module 3 thereof. In the data provision stage X all data in the latent data composition L can be kept up-to-date as the static data G (see Fig. 1) to be provided to the fabrication facility B and / or the manufacturing facility C as required in the respective fabrication stage Y and / or manufacturing stage Z, respectively, of configuring the user devices 5. Alternatively, or additionally, the fabrication stage Y / or the manufacturing stage Z may be situated at and / or combined with the data facility A as desired or required. The latent data composition L may be protected by respective encryption measures E.
[0050] In a first step SI, the installation program I may be provided from the data facility A to the fabrication facility B via respective transmission lines 4 (see Fig. 1). Depending on respective security requirements, the installation program I may be provided from and / or to the hardware security module 3 of the corresponding computing device 2 of the data facility A and / or fabrication facility B, respectively. Hence, it indicated in Fig. 2 that in the first step SI, the installation program I can be provided via the hardware security modules 3 of the data facility A and the fabrication facility B, in particular, if the installation program I contains the security credentials H, the security keys K and / or the authentication certificates J, which may require a respective level of protection. In an alternative or additional first step SI’, the installation program I is provided from the computing device 2 of the data facility A to the computing device 2 of the fabrication facility B, possibly without involving the hardware security module 3 on either side, in particular, if the installation program I merely contains the basic operating system M and / or if the basic operating system M is provided separately from the security credentials H, the security keys K and / or the authentication certificates J, and is regarded as requiring a lower degree security as the beforementioned. Nevertheless, the encryption measure E should be applied to the installation program I at least for the data transfer from the data facility A to the fabrication facility B.
[0051] In a second step S2, the installation program I can be mounted on the secure elements 6 fabricated at the fabrication facility B, for example, by storing the installation program I in the storage area 7 of the secure elements 6 in the fabrication stage Y. Thereby, the secure elements 6 can be enabled and / or prepared to be provided with the data component N. in a third step S3, secure elements 6 can be provided from fabrication stage Y at the fabrication facility B to the manufacturing stage Z at the manufacturing facility C. For example, batches of the secure elements 6 having installed thereon the installation program I in a version relating to the respective latent data composition L may be delivered to the manufacturing facility C.
[0052] At the manufacturing facility C, the user devices 5 can be provided with the secure elements 6, for example, in the form of an UICC, eUICC, iUICC, SIM, eSIM, iSIM, SE, or eSE. In a fourth step S4, at least one of the secure elements 6 containing the installation program I can be installed in the designated user device 5 at the manufacturing stage Z. in a fifth step S5, the data component N, for example, a stack thereof, in a manner as organized in the file structure F, can be provided by the data facility A to the manufacturing facility C via respective transmission lines (see Fig. 1). As the component N, the profile dataset P and / or the operation system dataset O contains or is at least based on or provided along with the personalization data R, the component N should be preferably sent from the computing device 2 of the data facility A to the computing device of the manufacturing facility B via the respective hardware security modules 3 and / or secured by respective encryption measures E.
[0053] In a sixth step S6, the secure elements 6 of the user devices 6 can then be provided with their intended component N, which may be associated to the respective user device 5 with the help of the personalization data R, for example, enabling communication via the telecommunication network associated with a respective MNO. In the broadcast mode V, a unified and / or standardized version of the data component N, both of the user profile dataset P and the operation system dataset O can be provided to the mobile devices 5 at the manufacturing stage Z. User profile dataset P may stem from the respective latent data composition L intended to be provided for the user devices 5 which can have a later version date then the installation program I mounted on the secure elements 6 at the fabrication stage Y at an earlier point of time.
[0054] In other words, the installation program I, such as an OFL component, can be shared amongst several possibly different operating system datasets O and may be the only component that is never updated once installed in the respective secure element 6. Usually from one deployment to another, the only change can be a personalization of the installation program I, for example, with specific security credentials H to avoid that one update of the data component N dedicated for a specific recipient, such as a customer, of the user devices 5 can be deployed to another recipient. This concept allows the configuration and / or personalization of the installation program I along with at least some of the security credentials H and possibly diversified data D (e.g., GSMA keys and certificates). Therefore, the data component N may not be configured together with the installation program I. Having the possibility to configure at least some of the diversification data D including GSMA credentials in the installation program (or alternatively in the basic operating system M), allows for instance to keep the GSMA keys and certificates in the data facility A at the premises of a respective trusted entity T, which can be certified accordingly for the retention and / or management of the security credentials H. In the broadcast mode V, the same data component N, for example, provided as a data image can be used for all secure elements E. The respective data image can be generated and / or prepared according to the latent data composition L at the data facility A along with all the necessary diversified data D (i.e., OFL keys, OFL personalization, SD keys, GSMA credentials, EID, ...). Production images of the data component N, for example, using a respective chip vendor format, determined by the manufacturing facility C including the diversification data D can be created and securely sent to manufacturing facility C for manufacturing the user devices 5. in a similar manner, the installation program I can be provided, for example as an OFL image, to the respective fabrication facility B.
[0055] The secure elements 6 fabricated in the fabrication facility B can be personalized by means of the installation program I at the fabrication facility B in order to be then delivered to the manufacturing facility C, for example, in the form of chips having an OFL personalized (and optionally simple standard OS) that are sent to OEM / ODM facilities for final production. With a first reset of the user devices 5 and / or their secure elements 6 after the manufacturing stage Z, for example by means of a respective recovery mechanism used during an OS Update process, diversified keys (i.e., GSMA keys, certificates, etc.) can be restored into the new operation system dataset O, for instance, provided in the form of an eOS. Respective scripts can be included to diversify security keys K provided with the installation program I from one customer to another. In that way, exactly the same installation program I can be provided as an original image in order to be reused among different customers. For instance, a first command, to be carried out by respective user devices 5 and / or secure elements 6 a respective personalized operation system dataset O, such as a specific customer OS, can include an upgrade of the security keys K provided for that customer by the data facility A. In broadcast mode V, the security keys K provided in and / or for the installation program I and / or the data component N are preferably the same for all secure elements 6 at the fabrication stage Y and / or manufacturing stage Z, respectively.
[0056] Fig. 3 shows a schematic illustration of a further embodiment of the configuration system 1 for configuring the user devices 5 involving the installation program I and the data component N for the secure elements 6 of the user devices 5 being provided in a unicast mode U. For the sake of brevity and conciseness, only the differences between the unicast mode U and the broadcast mode V, as described above, will be addressed the following. In the unicast mode U, in the fifth step S5 of providing the data component N, a respective stack of data components N can be provided from the data facility A to the manufacturing facility C. Each of the data components N can contain an individually personalized user profile dataset P and operation systems dataset O to be provided to a designated one of the user devices 5 in the manufacturing stage Z according to the respective personalization data R.
[0057] In other words, the unicast mode U allows to generate the data component N for the secure elements 6 in the form of an OS image encrypted with individual images per individual secure element, i.e., chip. This will open the possibility to include diversified security keys K, for example, along with each eOS image. This allows for customizing profile configurations, e.g., MNO profiles, including unique subscription user data. At the data facility A, the respective installation program I, for example, in the form of an OFL image, can be generated with personalization data for the installation program I only. Production images using a respective chip vendor format including the installation program I personalization data can be created and sent to the fabrication facility B, such as a chip vendor, for production. In this case, the security keys K and / or user specific configuration data, e.g., subscription information, such as ICCID, IMSI or other keys and data, can be diversified per secure element 6. i.e., chip.
[0058] The installation programs I can be personalized in the form of OFL images at the fabrication facility B. Secure elements 6 personalized with the respective installation program I can be sent to the manufacturing facility C, such as an OEM / ODM, for final production. Unique security keys K per chip can thus be included in diversification data D in the profile configuration of the operation system dataset O or even as an MNOs profile embedded into the image. Hybrid solutions may be possible to address any possible security concerns. Since a unique image may be delivered per chip, the unicast mode U could even be used to personalize eSIM profiles in the image, as it will be possible to include diversified data D for the eSIM profile. In the unicast mode U, preferably diversified security keys K are provided for each data component N.
[0059] Fig. 4 shows a schematic illustration of another embodiment of the configuration system 1 for configuring user devices 5 involving the installation program I and the data component for N the secure elements of the user 5 devices being provided in a hybrid mode W. For the sake of brevity and conciseness, again only the differences between the hybrid mode W and the unicast mode U and / or the broadcast mode V, as described above, will be addressed the following. In the hybrid mode W, in the fifth step S5 of providing the data component N, a respective stack of data components N can be provided from the data facility A to the manufacturing facility C. Each of the data components N can contain an individually personalized user profile dataset P and a standardized asset or common operation systems dataset O to be provided to a designated one of the user devices 5 in the manufacturing stage Z according to the respective personalization data R.
[0060] In other words, any intermediate solution between the unicast mode U and broadcast mode V is possible as well. In such a hybrid mode W, the operation system dataset O, such as an OS image, can be the same across all the secure elements 6, i.e., chips, as in the broadcast mode V, possibly with the same operation systemdataset O, but in addition the user profile datasets P 4 profile configurations contain diversified data D. Therefore, any image, for instance provided as a combination between the operation system dataset O and the user profile dataset P will be unique. In the hybrid mode W, preferably diversified security keys K can be provided for each data component N.
[0061] Consequently, in the data facility A, the installation program I, such as an OFL image and optionally in combination the basic operating system M, can be generated along with all the diversified data D (e.g., OFL keys, OFL personalization, SD keys, GSMA credentials, EID, etc.). Production images using chip vendor format including the diversification data can be created at the data facility A and securely sent to the fabrication facility B, such as a chip vendor, for production. The installation programs I, for example, in the form of the OFL images optionally provided with the basic operating system M, can be personalized at the fabrication facility B. The secure elements 6, for example, in the form of chips personalized with the respective OFL personalized can then be sent to the manufacturing facility C, such as OEM / ODM factories, for final production. At First reset of the user devices 5 and / or secure elements 6 after production can trigger the recovery mechanism for the diversified security keys K, authentication certificates J and / or security credentials H
[0062] (including GSMA certificates) to be restored into the operation system dataset O, e.g., provided in the form of an eOS.
[0063] In any of the embodiments of the configuration system 1 as described herein, in particular the computing device 2, and / or the network device 3 are or is, respectively, can be configured to execute a computer program 10. A computer-readable data carrier 11 can have stored thereon the computer program 10 and may take the form of a computer- readable medium 12 and / or data carrier signal 13. When carrying out the computer program 10, the configuration system 1 and any components thereof communicate as specified in the computer program 10. Parameters associated with and / or underlying the configuration system 1, any of the components thereof and / or any of the steps S carried out thereby, can be defined in and / or by the computer program 10 (see Fig. 2).
[0064] List of Reference Signs
[0065] 1 configuration system
[0066] 2 computing device / server device
[0067] 3 hardware security module / safe storage
[0068] 4 transmission line
[0069] 5 user device
[0070] 6 secure element
[0071] 7 storage area / non-volatile memory
[0072] 10 computer program
[0073] 11 computer-readable data carrier
[0074] 12 computer-readable medium
[0075] 13 data carrier signal
[0076] A data facility / data provider / EUM factory
[0077] B fabrication facility / chip vendor factory
[0078] C manufacturing facility / OEM and / or ODM factory
[0079] D diversified data
[0080] E encryption measures
[0081] F file structure
[0082] G static data
[0083] H security credentials
[0084] I installation program
[0085] J authentication certificate
[0086] K security key
[0087] L latent data composition
[0088] M basic operating system / boot loader
[0089] N data component
[0090] O operation system dataset
[0091] P user profile dataset / subscriber profile R personalization data / record
[0092] S step
[0093] T trusted entity
[0094] U unicast mode V broadcast mode
[0095] W hybrid mode
[0096] X data provision state
[0097] Y fabrication stage
[0098] Z manufacturing stage
[0099] 51 provide installation program
[0100] 52 mount installation program
[0101] 53 provide secure elements
[0102] 54 install secure element S5 provide data component
[0103] S6 personalise user device
[0104] ASPECTS
[0105] 1. A method of configuring a user device, the method comprising the steps of providing a secure element, such as an eUICC, with an installation program for loading at least one data component onto the secure element; installing the secure element on the user device, and loading the at least one data component onto the secure element involving the installation program; wherein the at least one data component comprises at least one of a user profile dataset and an operation system dataset for operating the secure element.
[0106] 2. The method according to aspect 1, wherein the installation program enables the load, install, and / or activate the at least one data component on the secure element.
[0107] 3. The method according to aspect 1, wherein the installation program and the at least one data component are being configured separately.
[0108] 4. The method according to aspect 1, wherein the at least one data component is built and / or compiled after providing the secure element.
[0109] 5. The method according to aspect 1, wherein the at least one data component comprises or is comprised of a data image.
[0110] 6. The method according to aspect 1, wherein the step of providing the at least one data component to the secure element involves mounting at least a part of the at least one data component on the secure element. 7. The method according to aspect 1, wherein the step of providing the at least one data component to the secure element involves updating at least one previous data component of the secure element.
[0111] 8. The method of aspect 1, wherein at least one of the installation program and the at least one data component is or are, respectively, issued and / or provided by a trusted entity.
[0112] 9. The method according to aspect 1, further comprising the step of providing at least one of the installation program and the at least one data component via a telecommunication network.
[0113] 10. The method according to aspect 1, wherein multiple secure elements are provided with the installation program for preparing installation of the secure elements.
[0114] 11. The method according to aspect 1, wherein multiple secure elements are provided with the at least one data component for configuring respective user devices.
[0115] 12. The method according to aspect 1, wherein the at least one data component is being individualized for a respective secure element.
[0116] 13. The method according to aspect 1, wherein at least one of the user profile dataset and the operation system dataset is or are, respectively, being individualized for a respective secure element.
[0117] 14. A user device comprising a secure element, such as an eUICC, installed on the user device when containing an installation program for loading at least one data component onto the secure element, and including at least one data component loaded onto the secure element after its installation involving the installation program; wherein the at least one data component comprises at least one of a user profile dataset and an operation system dataset for operating the secure element. 15. The user device of aspect 14, wherein the installation program is kept static.
[0118] 16. A secure element, such as an eUICC, to be installed on a user device, the secure element comprising an installation program for loading at least one data component onto the secure element; wherein the at least one data component comprises at least one of a user profile dataset and an operation system dataset for operating the secure element.
[0119] 17. The secure element of aspect 16, wherein the installation program comprises security credentials.
[0120] 18. The secure element of aspect 16, wherein the installation program comprises at least one security key.
[0121] 19. The secure element of aspect 16, wherein the installation program comprises at least one authentication certificate. 0. The secure element of aspect 16, wherein the installation program comprises a basic operating system enabling to load the at least one data component onto the secure element.
Claims
Claims1. A method of configuring a user device (5), the method comprising the steps of providing a secure element (6), such as an eUICC, with an installation program (I) for loading at least one data component (N) onto the secure element (6); installing the secure element (6) on the user device (5), and loading the at least one data component (N) onto the secure element (6) involving the installation program (I); wherein the at least one data component (N) comprises at least one of a user profile dataset (P) and an operation system dataset (O) for operating the secure element (6).
2. The method according to claim 1, wherein the installation program (I) enables the load, install, and / or activate the at least one data component (N) on the secure element (6).
3. The method according to claim 1 or 2, wherein the installation program (I) and the at least one data component () are being configured separately; wherein the at least one data component () is built and / or compiled after providing the secure element (6); and / or wherein the at least one data component (N) comprises or is comprised of a data image.
4. The method according to at least one of claims 1 to 3, wherein the step of providing the at least one data component (N) to the secure element (6) involves mounting at least a part of the at least one data component (N) on the secure element (6).
5. The method according to at least one of claims 1 to 4, wherein the step of providing the at least one data component (N) to the secure element (6) involves updating at least one previous data component (N) of the secure element (6).
6. The method according to at least one of claims 1 to 5, wherein at least one of the installation program (I) and the at least one data component (N) is or are, respectively, issued and / or provided by a trusted entity (T).
7. The method according to at least one of claims 1 to 6, further comprising the step of providing at least one of the installation program (I) and the at least one data component (N) via a telecommunication network.
8. The method according to at least one of claims 1 to 7, wherein multiple secure elements (6) are provided with the installation program (I) for preparing installation of the secure elements (6).
9. The method according to at least one of claims 1 to 8, wherein multiple secure elements (6) are provided with the at least one data component (N) for configuring respective user devices (5).
10. The method according to at least one of claims 1 to 9, wherein the at least one data component (N) is being individualized for a respective secure element ().
11. The method according to at least one of claim 1 to 10, wherein at least one of the user profile dataset (P) and the operation system dataset (O) is or are, respectively, being individualized for a respective secure element (6).
12. A user device (5) comprising a secure element (6), such as an eUICC, installed on the user device (5) when containing an installation program (I) for loading at least one data component onto the secure element (6) , and including at least one data component (N) loaded onto the secure element (6) after its installation involving the installation program (I); wherein the at least one data component (N) comprises at least one of a user profile dataset (P) and an operation system dataset (O) for operating the secure element (6).
13. The user device (5) of claim 12, wherein the installation program (I) is kept static.
14. A secure element (6), such as an eUICC, to be installed on a user device (5), the secure element (6) comprising an installation program (I) configured to carry out a method according to at least one of claims 1 to 11.
15. The secure element of claim 14, wherein the installation program (I) comprises security credentials (), at least one security key (K), at least one authentication certificate (J) , and / or a basic operating system enabling to load the at least one data component (N) onto the secure element (6).
Citation Information
Patent Citations
Methods and devices for OTA management of subscriber identify modules
EP2533485B1
Instantiation of multiple electronic subscriber identity module (eSIM) instances
US10277587B2
Procedure for personalizing a secure element
DE102021001850A1
Software update in a security element
EP4124979A1
Pre-personalized secure element and embedded personalization
US20230030478A1