Method, configuration program, operating system dataset, computer-readable data carrier as well as server device for configuring a user device and same

The method of using auxiliary and default data subsets in secure elements' operating system datasets allows user devices to adapt to evolving standards with over-the-air updates, ensuring future-proof functionality, safety, and security while maintaining deployability and availability.

WO2025214617A1PCT designated stage Publication Date: 2025-10-16GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/063294
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-10
Filing Date
2024-05-14
Publication Date
2025-10-16

AI Technical Summary

Technical Problem

Existing methods for configuring and updating secure elements in user devices, such as eUICCs, do not ensure future-proof functional spectrum, safety, and security while maintaining deployability and availability, especially when new standards are implemented during the device's lifetime.

Method used

A method involving an operating system dataset with auxiliary and default data subsets for secure elements, where the auxiliary subset is activated initially for basic functionality, and the default subset is activated later to comply with evolving standards, allowing over-the-air updates without physical replacement.

Benefits of technology

Ensures future-proof functional spectrum, safety, and security for user devices by enabling seamless adaptation to new standards without compromising deployability and availability through over-the-air updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024063294_16102025_PF_FP_ABST
    Figure EP2024063294_16102025_PF_FP_ABST
Patent Text Reader

Abstract

A method, as well as a corresponding configuration program (10), an operating system dataset (O), a computer-readable data carrier (11, 12, 13), a user device (3), and a server device (4) are provided, wherein for configuring the user device (5), in particular for communication via mobile telecommunication networks, the method comprises the steps of providing a secure element (6) of the user device (5), such as an eUICC, with an operating system dataset (O) for operating the secure element (6), the operating system dataset (O) comprising an auxiliary data subset (A) and a default data subset (B); and sending an activation signal (R) to the secure element (6); wherein the auxiliary data subset (A) is activated when the operating system dataset (O) is provided to the secure element (6), and the default data subset (B) is activated by the secure element (6) after receipt of the activation signal (R).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Method, Configuration Program, Operating System Dataset, computer-readable Data Carrier as well as Server Device for Configuring a User Device and Same

[0002] Technical Field

[0003] The present disclosure relates to the field of configuring user devices, for example, Intemet-of- Things (loT) devices, for participating in communication networks. In particular, the present disclosure relates to a method of configuring a user device, in particular, for communication via mobile telecommunication networks, to a configuration program (10) for configuring a user device, in particular for communication via mobile telecommunication networks, to an operating system dataset for a secure element of a user device, such as an eUICC, for operating the secure element, to a computer-readable data carrier, to a user device, in particular an loT device to be configured for communication via mobile telecommunication networks, and to a server device , in particular a security server providing a secure location for handling subscriber profiles for communication via mobile telecommunication networks.

[0004] Background of the Invention

[0005] User devices, such as personal mobile devices or loT-devices, configured to employ electronic subscriber profiles for communicating on mobile networks, are known from the prior art. Such user devices are typically equipped with an electronic / embedded secure element (SE, eSE), also known as tamper resistant element (TRE), which may take the form of an UICC, eUICC, iUICC, SIM, eSIM, iSIM, or alike, configured to store one or more electronic subscriber profiles that may allow the user devices to connect to one or more mobile networks. A subscriber profile (e.g., an eSIM profile) may be generated by a mobile network operator (MNO) and may be stored, e.g., downloaded to a mobile user device. The subscriber profile may then be installed on a secure element of the user device and used for common ication over a corresponding mobile network by the user device. The secure elements are run by operation systems (OS) containing software and / or firmware for operating the secure elements. Those OS need to be up to date in order to provide full and reliable functionality of the secure elements. An OS Update is especially relevant with the deployment of embedded Secure Elements (eSE) in the form of eUICC or alike. As opposite of traditional pluggable SIMs that can be inserted and removed, eSEs are soldered into user devices, making it very difficult (or costly) to replace them during the life cycle of the user devices.

[0006] Consequently, there is a need for so-called firmware-upgrades that allow to modify the content of the eSE in the event that it has to be kept up to date and / or a technical issue has to be fixed. For example, one possible reason for that firmware has to be kept up to date is if a related standard, such as a GSMA specification, relating to the user device changes or is being newly implemented. In any case, firmware upgrades can be carried out with the help of an Open Firmware Loader (OFL), or alike, which is specifically designed software component in charge of firmware upgrades including OS updates in the secure element.

[0007] WO 2023 / 142764 Al, for example, relates to the technical field of electronic devices, and discloses a wake-up method and apparatus for an operating system, an electronic device, and a storage medium. The method is applied in an electronic device, the electronic device can run a first operating system and a second operating system, and the method comprises: when the first operating system and / or the second operating system are in a dormant state, if a target wakeup module generates a wake-up signal, controlling a target operating system corresponding to the target wake-up module to switch from the dormant state to a running state according to the wake-up signal. By implementing an embodiment of the present application, an electronic device can be automatically switched to an optimal operating system, and the degree of intelligence of the electronic device is improved.

[0008] DE 102021 001 850 Al refers to a method for personalizing a security element, which method is provided with the following method steps: receiving a request for a bundle of memory images for a plurality of security elements in a data generator, each requested memory image of the received bundle relating to one of the plurality of security elements, and wherein the memory images of the received bundle relating to one of the plurality of security elements; one of the plurality of security elements is fixedly mounted in a corresponding terminal device of the plurality of terminal devices; obtaining, in the data generator, at least one subscription data set for at least one secure element to be personalized of the plurality of secure elements, the subscription data set being obtained from the subscription management server; providing, by the data generator, an operating system or a portion of an operating system for the secure element to be personalized; generating, by the data generator, a memory image for each secure element according to the received request, the memory image of the secure element to be personalized comprising the provided operating system or part of the operating system and additionally comprising the obtained at least one subscription data set; and bundling the generated memory images and providing the bundled memory images as a memory image bundle by a data generator in order to complete the terminal device in order to introduce at least the memory image of the security element to be personalized into the security element in order to personalize the security element.

[0009] US 10277587 B2 refers to methods for instantiating multiple electronic subscriber identity modules (eSIMs) to an electronic universal integrated circuit card (eUICC) using a manufacturer-in- stalled data binary large object (data blob). An eSIM package including the data blob in encrypted form is securely installed in the eUICC in a manufacturing environment. A key encryption key (KEK) associated with the eSIM package is separately provided to an original equipment manufacturer (OEM) wireless device factory. The OEM wireless device factory provides the KEK to the eUICC within a given wireless device. The eUICC uses the KEK to decrypt the eSIM package and provide the data blob. The eUICC can receive a request to instantiate a first eSIM. The eUICC can instantiate the first eSIM using data from the data blob. A user can then access network services using the wireless device. Subsequently, a second eSIM can be instantiated by the eUICC using the data blob.

[0010] Methods for providing and upgrading secure elements of user devices, including OS updates, as described above, may not fully satisfy all requirements regarding their deployability and availability on the one hand, as well as functional safety and security on the other hand. For example, it is desirable that both, the OS, and the secure elements have the same origin and preferably same state of development in order to ensure functional safety and security. However, due to deployability and availability restrictions, it may not be always assured that the OS, as well as the secure elements have the same origin or corresponding versions and meet certain future requirements, especially if an implementation of a new specification or standard for operating the user devices is expected to be issued during lifetime of the user device and / or respective secure element. This may limit the functionality, especially a spectrum of (future) capabilities, of the user device, may compromise functional safety and security when operating user devices, or may even lead to that the devices cannot be configured properly.

[0011] Summary of the Invention

[0012] It may be seen as an object to improve the interaction between the secure elements and their OS. In particular, it may thus be seen as an object to provide a way to handle secure elements and their OS in a way that a future proof functional spectrum, safety and security may be assured, while not compromising deployability and availability. These objects are at least partly achieved by the subject-matter of the independent claims.

[0013] According to an aspect, a method of configuring a user device, in particular for communication via mobile telecommunication networks, is provided, the method comprising the steps of providing a secure element of the user device, such as an eUICC, with an operating system dataset for operating the secure element, the operating system dataset comprising an auxiliary data subset and a default data subset; and sending an activation signal to the secure element; wherein the auxiliary data subset is activated when the operating system is provided to the secure element, and the default data subset is activated by the secure element upon and / or after receipt of the activation signal.

[0014] According to an aspect, a configuration program for configuring a user device, in particular for communication via mobile telecommunication networks, is provided wherein the configuration program comprises instructions which, when the application program is executed by a secure element, cause the secure element to carry out a corresponding method.

[0015] According to an aspect, an operating system dataset for a secure element of a user device, such as an eUICC, for operating the secure element, is provided, the operating system dataset comprising an auxiliary data subset and a default data subset; and configured to react to an activation signal; wherein the auxiliary data subset is activated when the operating system is provided to the secure element, and the default data subset is activated upon receipt of the activation signal.

[0016] According to an aspect, a computer-readable data carrier having stored thereon a corresponding configuration program and / or operating system dataset is provided.

[0017] According to an aspect, a user device, in particular an loT device to be configured for communication via mobile telecommunication networks, is provided, wherein the user device is configured to carry out a corresponding method, comprises a corresponding configuration program, a corresponding operating system dataset, and / or a corresponding computer-readable data carrier.

[0018] According to an aspect, a server device, in particular a security server providing a secure location for handling subscriber profiles for communication via mobile telecommunication networks, is provided, wherein the server device is configured to carry out a corresponding method, comprises a corresponding configuration program, comprises a corresponding operating system dataset, and / or comprises a corresponding computer-readable data carrier.

[0019] The operating system can be activated upon first activation of the user device which then operates by means of the auxiliary data subset in a respective auxiliary mode with all respective setups. The auxiliary mode may thus allow the user to set up at least a basic configuration of the user device enabling a certain functionality, including telecommunications. The user device can be an loT device, which can be switched to be operated by means of the default data subset in a respective default mode upon receiving the activation signal.

[0020] The proposed solution allows for providing a sort of transitional operating system setup which can be particularly helpful for configuring loT devices and may be abbreviated as eOS eSIM IOT. For example, the solution can be implemented by providing the operating system dataset in the form of an eOS supporting both SGP.22 and SGP.32 functionalities but initially only SGP.22 is activated / visible to external applications as included in the auxiliary data subset. Such an eOS can be configured (i.e., in factory) with a minimum eSIM loT remote manager (elM) configuration implemented by means of the auxiliary data subset and owned by a respective trusted entity (including respective identification codes and keys, such as an eimld and activation elM public key, respectively) to perform the activation of the default data subset later on in the field.

[0021] The proposed solution has the advantage over the prior art, that the operating system dataset can be delivered to any manufacturing facility, including OEM / ODM vendor facilities, as well as fabrication facilities of the secure element, regardless of a change to standards and / or specifications relating to the user device between the delivery and a later point of the time of deployment of user devices and / or the secure elements to customers. At first, the operating system dataset allows for configuring the user device and / or the secure element in a way that it can be deployed to customers, allowing them to adopt upcoming or following standards and / or specifications along with a respective functional spectrum, safety, and security by means of the default data subset later on.

[0022] Hence, the proposed solution allows for a configuration and update of the secure element "Over-The-Air", removing the necessity of physically replace the secure element for updates and / or upgrades. The data to be updated can be kept minimal as a preferably large amount of data for default operation of the user device can be implemented in the default data subset. Thereby, secure elements and their OS can be handled in a way that a future-proof functional spectrum, safety and security may be assured, while not compromising their deployability and availability.

[0023] Further developments can be derived from the dependent claims and from the following description. Features described with reference to a user device, secure element, server device and components thereof may be implemented as method steps, or vice versa. Therefore, the description provided in the context of the user device, secure element, server device and their components apply in an analogous manner also to respective methods. In particular, features and functions of the user device, secure element, server device and their components may be implemented as method steps which in turn may be implemented as respective device features or functions. According to a possible embodiment of the method, the auxiliary data subset includes a first set of functionalities, and the default subset includes a second set of functionalities. The functionalities included in the first set of functionalities and the second set of functionalities may overlap. They can be tailored to meet respective specific standards and / or specifications. This further helps in assuring a future-proof functional spectrum, safety, and security, while not compromising deploy ability and availability of user devices and their secure elements.

[0024] According to a possible embodiment of the method, the default commands for operating the default data subset are generally blocked and / or ignored before activation of the default data subset. For example, SGP.32 functionalities included in the default data subset (including specific commands or specific data i.e., eUICCInfo2) can be blocked and / or no SGP.32-specific data is retrieved until activation of the default data subset takes place. Thereby, any unintended or authorised operations can be avoided.

[0025] According to a possible embodiment of the method, a data request command of the default data subset is supported before receiving the activation signal. The data request command can be and / or comprise a package request command. For example, as an only exception of a command belonging to the default data subset which is not blocked and / or ignored activation of the default data subset, an EuiccPackageRequest command (Tag 'BF51') may be allowed. Before the SGP.32 activation, this command may be only supported in case of an initial eimID activation elM and elMSignature is validated with elM Public key configured in factory, for instance by a trusted entity. Alternatively, or additionally, a newly defined customized command, for example, configured as a proprietary command can be used. Thereby, respective data requests can be enabled further helping to assure a future-proof functional spectrum, safety, and security, while not compromising deployability and availability of user devices and their secure elements.

[0026] According to a possible embodiment of the method, the method further comprises the step of providing a remote management application for enabling the data request command. The remote management application may be provided in the form of an eSIM loT remote manager (elM). This may particularly help to configure user devices in the form of loT devices which do not process their own data input and / or output devices enabling in situ (manual) configuration by a user. Thereby, the configuration process can be facilitated. According to a possible embodiment of the method, the method further comprises the step of authenticating the remote management application. The remote management application may be provided along with the operating system dataset and may be activated at a later point of time. This further helps in avoiding unintended and / or an authorised configurations and helps to assure a future-proof functional spectrum, safety, and security, while not compromising deployability and availability of user devices and their secure elements.

[0027] According to a possible embodiment of the method, the method further comprises the step of providing an application identifier and / or authentication certificate to the secure element. The application identifier may be provided in form of an eimID. The authentication certificate may be provided in the form of an elM Signature. The step of authenticating the remote management application can be carried out by means of the application identifier and / or the authentication certificate. This further helps in avoiding unintended and / or an authorised configurations and helps to assure a future-proof functional spectrum, safety, and security, while not compromising deployability and availability of user devices and their secure elements.

[0028] According to a possible embodiment of the method, the auxiliary data subset is adapted for communication according to a first communication standard and / or the default data subset is adapted for communication according to a second communication standard. The first communication standard can be a previous communication standard. The second communication standard can be a following communication standard. Such standards may be defined by respective standardisation bodies, such as the GSM Association (GSMA). For example, the first standard can be GSMA standard SGP.22, and the second standard can be GSMA standard SGP.32. This further helps in assuring a future-proof functional spectrum, safety, and security, while not compromising deployability and availability of user devices and their secure elements.

[0029] According to a possible embodiment of the method, before activation, the default data subset is hidden to external applications. Thereby, external applications may be hindered of trying to access the default data subset. This further helps in preventing unintended and / or unauthorised access to the default data subset. According to a possible embodiment of the method, the wherein the activation signal is sent via a communication interface. In the present example, when SGP.32 functionality is supposed to be activated (GSMA certification has been completed, customer is ready to deploy SGP.32, etc.) an activation signal or a respective command can be sent using the ESep interface (ESep: Logical end-to-end interface between the elM and the eUICC used to transfer eUICC Packages for Profile State Management and elM configuration by elM). For example, the activation signal can be sent according to the following two options: either an eimID initial configuration is only used for activation and after activation it is deleted / put to sleep (just in case it is needed to go back to SGP.22) and / or a specific (proprietary) ECO (eUICC Configuration Operation) command allows usage of the initial elM configuration as a regular elM (proprietary command is used to explicitly instruct the activation). This further helps in handling secure elements and their OS in a way that future-proof capabilities, safety, and security may be assured, while not compromising deployability and availability.

[0030] A corresponding computer program, for example, in the form of the configuration program, may comprise instructions which, when the program is executed by a computing device, cause the computing device to execute a method, control a secure element, a user device, and / or a sever device, to perform any of the steps of a method as described herein. In particular, the computer program can comprise instructions which, when the program is executed by a computer device, cause the computer device to configure the user device to communicate via a telecommunication network, cause an interaction with a secure element, such as an eUICC, and / or with a user device comprising the secure element, by means of the configuration program, in order to carry out any steps of a method as described herein. A computer-readable data carrier, such as a computer-readable medium and / or a data carrier signal, may carry the computer program.

[0031] Brief Description of the Drawings

[0032] Fig. 1 is a schematic illustration of a configuration system for carrying out a method according to the present invention. Detailed Description of Embodiments

[0033] The following detailed description is merely exemplary in nature and is not intended to limit the invention and uses of the invention. Furthermore, there is no intention to be bound by any theory presented in the preceding background or the following detailed description. The representations and illustrations in the drawings are schematic and not to scale. Like numerals denote like elements. A greater under standing of the described subject matter may be obtained through a review of the illustrations together with a review of the detailed description that follows.

[0034] Fig. 1 shows a schematic illustration of a configuration system 1 comprising a computing device 2, for instance, in the form of a server device 3 controlled by a trusted entity T, comprising a hardware security module 4 adapted to store, manage and / or provide operating system datasets D for configuring a further computing devices 2, for example, in the form of a user device 5 which may be embodied as an Internet of Things (loT) device, such as a multimedia device, camera, speaker, household appliance, measurement device, industrial installation, vehicle, vending machine, or alike, to be associated with a machine entity, and / or as a personal mobile device, such as a smartphone, smartwatch, etc., to be associated with a personal entity. For example, the server device 3 may be provided in the form of a Server for Subscription Manager Data Preparation + (SM-DP+).

[0035] In the present example, the user devices 5 may be adapted for communication via a telecommunication network (not shown) by means of at least one user profile dataset P to be saved in a respective secure element 6 or tamper resistant element (TRE), such as an UICC, eUICC, iUICC, SIM, eSIM, iSIM, SE, eSE, or alike, provided in the form of a computer chip. The user profile data sets P are generated based on respective personal records contained in data files on the computer device 2, in particular, the hardware security module 4 thereof. For storing and managing user profile data sets P on the secure elements 6, an operating system dataset O is installed on the secure element 6, for example, in a secure storage location 7, such as an Issuer Security Domain - Root (ISD-R) provided on the secure element 6.

[0036] The operating system dataset O comprises an auxiliary data subset A and a default data subset B which may provide a first set of functionalities E and a second set of functionalities F, respectively. The first set of functionalities E and the second set of functionalities F may relate to a first communication standard X and / or a second communication standard Y, respectively. Therefore, the auxiliary data subset A and default data subset B may comprise auxiliary commands C, and / or default commands D, respectively. Furthermore, a data request command Q may be provided which may be allowed to be executed as a part of the default data subset B before an activation signal R is received by the secure element 6.

[0037] A remote management application 8 may be provided which can be configured to allow a user U to communicate with the user device 5, in particular the secure element 6, for example, through a communication interface 9 to the user device 5. The remote management application 8 can be provided in the form of an eSIM loT remote manager (elM) which may be securely identified by means of an application identifier I and / or authenticated by means of an authentication certificate J. The communication interface 9 may be provided in the form of a logical end- to-end interface (ESep) enabling secure communications between the remote management application 8 and the secure element 6, which can be used to transfer data packages, such as eUICC Packages, for instance to carry out Profile State Management and elM configuration tasks by means of the elM. For example, the communication interface 9 may be provided as a part of a local management application, such as a loT Profile Assistant (IPA), which may take the form of an loT Profile Assistant (IPAd) provided to the user device 5, and / or an loT Profile Assistant provided (IPAe) arranged in the secure element 6.

[0038] Furthermore, the operating system dataset O may comprise a user profile P and security credentials H, including the application identifier I, authentication certificate J and / or security key K. The security credentials H may comprise any kind of credentials defined by e.g., the GSMA, or alike. The security keys K may comprise any kind of cryptographic code or key element which may be adapted to interact with the user devices 5, the secure elements 6, and / or the server device 3 of the trusted entity T as an issuer of any part of the operating system dataset O and / or any component thereof. The authentication certificates J may be any kind of electronic certificate, for example, that can be issued by the trusted entity T, for authenticating an origin of the user devices 5, the secure elements 6, the secure storage location 7 and / or the operating system dataset O. Transmission lines (not shown) may be provided for handling and / or transferring the operating system dataset O may comprise any kind of wired and / or wireless transmission chains, including the Internet (for transmissions "Over-The-Air") as well as other physical and / or non-physical data carriers, which can be configured and secured as desired and required.

[0039] In any of the embodiments of the configuration system 1 as described herein, in particular the computing devices 2, can be configured to execute a computer program in the form of a configuration program 10. A computer-readable data carrier 11 can have stored thereon the configuration program 10 and may take the form of a computer-readable medium 12 and / or data carrier signal 13. When carrying out the configuration program 10, the security system 1 and any components thereof communicate as specified in the security program 10. Parameters associated with and / or underlying the security system 1, any of the components thereof and / or any steps S carried out thereby, can be defined in and / or by the configuration program 10.

[0040] In a first step SI, the server device 3 may provide any of the data components of the configuration system 1, including the operating system dataset O, to the secure element 6 of the user device 5, for example through the communication interface 9 to be stored in the secure storage location 7 for deployment to the user U. In a second step S2, the auxiliary data subset A including the auxiliary commands C and / or the first set of functionalities E may be activated, for example, by the user U through the remote management application 8, in order to enable the user device 5 for communications according to the first communication standard X. For activating the auxiliary data subset A, the user may use respective security credentials H. Upon activation and / or authorization through the security credentials H, the data request command Q may be made available to be used by the user device 5.

[0041] In a third step S3, the second communication standard Y may be implemented, for example, involving respective notification signal N which can be sent from the server device 2 to the user U, and of which the user U may be made available through the remote management application 8 or alike. In a fourth step, S4, the activation signal R (e.g., named "activatelOT" or "lOTacti- vate") can be sent to the secure element 6, for example, by means of the remote management application 8 and / or through the communication interface 9 upon respective configuration setting applied by the user U, thus allowing the user to trigger activation of the default data subset B. At least two options are possible to send the activation signal R in the present example, namely that (a) either the eimID initial configuration is only used for activation and after activation it is deleted / put to sleep (just in case it is needed to go back to SGP.22, and / or (b) a specific (proprietary) ECO command is applied to allow the usage of the initial elM configuration as a regular elM (proprietary command is used to explicitly instruct the activation), giving the application of the activation signal R the following exemplary form:

[0042] - ASN1START

[0043] Eco ::= CHOICE { addEim [8] EimConfigurationData, deleteEim [9] SEQUENCE {eimld [0] UTF8String}, updateEim

[0010] EimConfigurationData, listEim

[0011] SEQUENCE {}, activatelOT [XX]

[0044] }

[0045] - ASN1STOP

[0046] A proprietary data tag can be included in the activation signal R to configure further information required by SGP.31 / SGP.32 specifications (i.e., sasAcreditationNumber, Certifica- tionDataObject, in eUICCInfo2 Tag ...). Regardless of the above two options (new activatelOT command used or not), the activation signal R can be used to add a new elM configuration. If no new elM is added and an elM configuration is hidden or deleted, "ESlOb.AddlnitialEim" may be permitted (e.g., this command can be used by an IPA to configure first elM when there is no elM previously configured). If, for instance an elM configuration is hidden, it shall be rather kept invisible to external applications, for example, in that it is not be retrievable via commands like "ESlOb.GetEimConfigurationData". In a fifth step S5, the user device 5, in particular the secure element 6, may authenticate the activation signal R, and / or the remote management application 8 configured to send the activation signal R, for example, by means of respective security credentials H, such as the application identifier I , authentication certificate J and / or security key K. If the authentication is successful, then in a sixth step S, the secure element 6 may send the data request command Q to the server device 2 through the communication interface 9. Upon receipt of the data request command Q, the in a seventh step S7, the server device 2 may send a respective data package, which may include updated profile data P for communication over the second communication standard Y to the user device 5, in particular to the secure element 6, for example, again through the communication interface 9, in order to enable activation of the default data subset B.

[0047] In an eighth step S8, the user device 5, in particular the secure element 6, can again check respective security credentials H, for instance, in order to authenticate the updated profile data P and / or any further data provided for activation of the default data subset B, for example, the complete activation of the default data subset B. If that authentication is successful, then in a ninth step S9, the fault data subset B can be finally activated, for example, enabling communication according to the second communication standard Y. Once, the activation of the default data subset B is completed, the user device 5 maybe reset, and in the present example, all functions of the second communication standard Y may be made available, e.g., as required according to the SGP.32 specification, including specific information from eUICCInfo2 present only in case of SGP.32 (i.e., ipaMode, iotSpecificInfo, ...).

[0048] Reference Signs

[0049] 1 configuration system T trusted entity

[0050] 2 computing device U user

[0051] 3 server device 35 X first communication standard

[0052] 4 hardware security module Y second communication standard

[0053] 5 user device

[0054] 6 secure element 51 provide data

[0055] 7 secure storage location 52 activate auxiliary data subset

[0056] 8 remote management application 40 53 notify user

[0057] 9 communication interface 54 send activation signal

[0058] 10 configuration program 55 authenticate activation request

[0059] 11 computer-readable data carrier 56 send data request

[0060] 12 computer-readable medium 57 provide activation data

[0061] 13 data carrier signal 45 58 authenticate activation data

[0062] 59 activate default data subset

[0063] A auxiliary data subset

[0064] B default data subset

[0065] C auxiliary command

[0066] D default command

[0067] E first set of functionalities

[0068] F second set of functionalities

[0069] H security credentials

[0070] I application identifier

[0071] J authentication certificate

[0072] K security key

[0073] N notification signal

[0074] O operating system dataset

[0075] P user profile

[0076] Q data request command

[0077] R activation signal

[0078] S step

Claims

Claims1. Method of configuring a user device (5), in particular for communication via mobile telecommunication networks, the method comprising the steps of providing a secure element (6) of the user device (5), such as an eUICC, with an operating system dataset (O) for operating the secure element (6), the operating system dataset (O) comprising an auxiliary data subset (A) and a default data subset (B); and sending an activation signal (R) to the secure element (6); wherein the auxiliary data subset (A) is activated when the operating system dataset (O) is provided to the secure element (6), and the default data subset (B) is activated by the secure element (6) after receipt of the activation signal (R).

2. Method according to claim 1, wherein the auxiliary data subset (A) includes a first set of functionalities (E), and the default data subset (B) includes a second set of functionalities (F).

3. Method according to claim 1 or 2, wherein default commands (D) for operating the default data subset (B) are generally blocked and / or ignored before activation of the default data subset (B).

4. Method according to at least one of claims 1 to 3, wherein a data request command (Q) of the default data subset (B) is supported before receiving the activation signal (R).

5. Method according to claim 4, further comprising the step of providing a remote management application (8) for enabling the data request command (Q).

6. Method according to claim 5, further comprising the step of authenticating the remote management application (8).

7. Method according to at least one of claims claim 1 to 6, further comprising the step of providing an application identifier (I) and / or authentication certificate (J) to the secure element (6).

8. The method according to at least one of claims 1 to 7 , wherein the auxiliary data subset (A) is adapted for communication according to a first communication standard (X) and / or the default data subset (B) is adapted for communication according to a second communication standard (Y).

9. Method according to claim at least one of claims 1 to 8, wherein before activation, the default data subset (B) is hidden to external applications.

10. Method according to at least one of claims 1 to 9, wherein the activation signal (R) is sent via a communication interface (9).

11. Configuration program (10) for configuring a user device (5), in particular for communication via mobile telecommunication networks, wherein the configuration program (10) comprises instructions which, when the application program (10) is executed by a secure element (6), cause the secure element (6) to carry out a method of at least one of claims 1 to 10.

12. Operating system dataset (O) for a secure element (6) of a user device (5), such as an eUICC, for operating the secure element (6), the operating system dataset (O) comprising an auxiliary data subset (A) and a default data subset (B); and configured to react to an activation signal (R); wherein the auxiliary data subset (A) is activated when the operating system () is provided to the secure element (6), and the default data subset (B) is activated upon receipt of the activation signal (R).

13. Computer-readable data carrier (11, 12, 13) having stored thereon a configuration program (10) according to claim 11 and / or an operating system dataset (O) according to claim 12.

14. User device (3), in particular an loT device to be configured for communication via mobile telecommunication networks, wherein the user device (3) is configured to carry out a method according to at least one of claims 1 to 10, comprises a configuration program(10) according to claim 11, an operating system dataset (O) according to claim 12 and / or a computer-readable data carrier (11, 12, 13) according to claim 13.

15. Server device (4), in particular a security server providing a secure location for handling subscriber profiles for communication via mobile telecommunication networks, wherein the server device (4) is configured to carry out a method according to at least one of claims 1 to 10, comprises a configuration program (10) according to claim 11, an operating system dataset (O) according to claim 12 and / or a computer-readable data carrier (11, 12, 13) according to claim 13.

Citation Information

Patent Citations

  • Procedure for personalizing a secure element

    DE102021001850A1

  • Instantiation of multiple electronic subscriber identity module (eSIM) instances

    US10277587B2

  • Wake-up method and apparatus for operating system, electronic device, and storage medium

    WO2023142764A1

  • System and methods for using embedded subscriber identity module (ESIM) provisioning processes to provide and activate device configuration packages on a wireless communication device

    CN108886683A