Factory reset applet
The factory reset applet in secure elements addresses the challenge of securely deleting user data during a factory reset, ensuring secure element functionality and user data confidentiality.
Patent Information
- Application Number
- PCT/EP2025/067790
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-09
- Filing Date
- 2025-06-24
- Publication Date
- 2026-01-15
AI Technical Summary
There is no efficient method to perform a factory reset of a secure element in electronic devices while preserving applet functionality, posing a security risk due to residual user data that can be accessed by subsequent users.
A factory reset applet is installed within the secure element to manage the factory reset process by identifying and deleting personal user data from applicative applets upon receiving a factory reset command.
Ensures secure and selective deletion of user data during a factory reset, maintaining applet functionality and preventing unauthorized access to sensitive information.
Smart Images

Figure EP2025067790_15012026_PF_FP_ABST
Abstract
Description
[0001] Factory Reset Applet
[0002] TECHNICAL FIELD
[0003] The present invention concerns electronic devices and in particular, the factory reset of user devices or terminals like smartphones, PDAs, tablets, and computers, for example, but more generally any device using a secure element.
[0004] BACKGROUND
[0005] A factory reset is a procedure to restore a device to its original state, erasing all data, settings, and installed applications. This procedure ensures that the device is in the same configuration as when it is issued the first time to its user. This process can be triggered either by the device owner or by a third party for various reasons such as repairing the device or preparing a device for resale or ensuring privacy when a device changes ownership.
[0006] One of the most critical aspects of a factory reset is data confidentiality. This factory reset, for confidential issues, has to delete all user’s confidential data that have been stored in the terminal. This includes personal files, account credentials, messages, and any sensitive information that may have been entered into the system. In many cases, this data is stored in applicative applets, which are small software applications that are installed either before the device issuance or after, when the device is used in the field.
[0007] This procedure has the purpose of deleting all the personal confidential data that have been stored in different applets. For example, banking and payment applications, transit applications, access control applications, personal ID (virtual passport or ID), ... , often contain sensitive user data that must be securely deleted during a factory reset. If not done properly, residual data could pose a security risk, allowing unauthorized access to personal information. These applications are stored in a secure environment like an Embedded Secure Element (eSE), an Embedded Universal Integrated Circuit Card (eUlCC), or even a Universal Integrated Circuit Card (UICC) for example.
[0008] When the UICC is not soldered in a mobile terminal (e.g. its form factor is a SIM card) i.e. when the UICC exists in the form of a removable SIM card, it is easy for the user to keep the control of these personal data. By simply extracting the SIM card from the mobile terminal, the user can keep the SIM card for future use in another terminal or simply destroy it, ensuring that no personal information remains accessible on the original mobile terminal.
[0009] But when the Secure Element is soldered in the terminal (like an eUlCC or an eSE), the user cannot extract it. If the device is transferred to a new user, this poses a significant risk as the next user of the device can access the personal and confidential data stored and available in the applets of the soldered Secure Element. This is also valid for sensitive data like digital keys for example. Next users can misuse such data for political, personal, or financial reasons and even under a government umbrella.
[0010] The problem is that there is no simple way to perform a factory reset of a secure element which has several applets installed. Currently, the only way is to fully delete all applet instances of the secure element, which may not always be desirable. In certain cases, particularly for applets that were pre-installed before the device was issued, it may be required to keep applet’s instances and to only remove user’s data from these applets. Thus, there is a challenge for developing a secure and efficient method to selectively erase user data while preserving essential applet functionality remains an ongoing challenge in Secure Element management.
[0011] SUMMARY
[0012] The present disclosure proposes a solution to these problems. The present disclosure proposes a device for performing a factory reset. The device comprises a secure element soldered within the device. The device further comprises a factory reset applet installed in the secure element. The factory reset applet is configured to receive a factory reset command from an external entity and upon receipt of the factory reset command, generate a factory reset event based on the factory reset command. The factory reset event indicates an occurrence of a factory reset of the device to delete personal user data stored within the secure element. The factory reset applet is configured to send a request corresponding to the factory reset event to each of a plurality of applicative applets to delete corresponding personal user data stored within the secure element.
[0013] According to some example embodiments, each of the plurality of applicative applets, upon receipt of the request corresponding to the factory reset event, is configured to delete the personal user data that the corresponding applicative applet has.
[0014] According to some example embodiments, the factory reset applet is configured to identify the plurality of applicative applets among all applets of the secure element based on a list of registered applicative applets.
[0015] According to some example embodiments, the applicative applets notify said factory reset applet that the plurality of applicative applets are eligible to the factory reset.
[0016] According to some example embodiments, the secure element is an Embedded Universal Integrated Circuit Card (eUlCC), an Embedded Secure Element (eSE), or an application (Integrated Universal Integrated Circuit Card or Integrated Secure Element ) running in a Security Processor Unit (SPU) in a System on Chip (SOC).
[0017] The present disclosure also proposes a method implemented in a secure element soldered in a terminal equipment for performing a factory reset. The method comprises receiving a factory reset command from an external entity. The method further comprises upon receipt of the factory reset command, generating a factory reset event based on the factory reset command. The factory reset event indicates an occurrence of a factory reset of the device to delete personal user data stored within the secure element. The method further comprises sending a request corresponding to the factory reset event to each of a plurality of applicative applets to delete corresponding personal user data stored within the secure element.
[0018] According to some example embodiments, the method further comprises upon receipt of the request corresponding to the factory reset event, deleting the personal user data that the corresponding applicative applet has.
[0019] According to some example embodiments, the method further comprises identifying the plurality of applicative applets among all applets of the secure element based on a list of registered applicative applets.
[0020] According to some example embodiments, the method further comprises notifying said factory reset applet that plurality of applicative applets are eligible to the factory reset.
[0021] The present disclosure proposes a secure element for performing a factory reset. The secure element is soldered in a terminal equipment. The secure element comprises a factory reset applet installed in the secure element. The factory reset applet is configured to receive a factory reset command from an external entity, and upon receipt of the factory reset command, generate a factory reset event based on the factory reset command. The factory reset event indicates an occurrence of a factory reset of the device to delete personal user data stored within the secure element. The factory reset applet is further configured to send a request corresponding to the factory reset event to each of a plurality of applicative applets to delete corresponding personal user data stored within the secure element.
[0022] BRIEF DESCRIPTION OF THE DRAWINGS The present invention will be better understood by reading the following description of the figures that represent:
[0023] Figure 1 illustrates a line diagram representing a method for performing registration of an applicative applet to a factory reset applet, in accordance with embodiments of the present disclosure;
[0024] Figure 2 illustrates a line diagram representing a method for performing a factory reset of the device, in accordance with embodiments of the present disclosure; and
[0025] Figure 3 illustrates a flow chart representing a method implemented in a secure element soldered in a terminal equipment for performing a factory reset, in accordance with another embodiment of the present disclosure.
[0026] Figure 4 illustrates an exemplary computing system 400 for implementation of a method for performing a factory reset, in accordance with an exemplary embodiment of the present disclosure.
[0027] The present invention will be better understood by reading the following description of the above figures.
[0028] DETAILED DESCRIPTION
[0029] Unless the context suggests otherwise, the term “applet” refers to a software program or application designed to perform a specific, limited function within a larger system or environment. The applet operates within a controlled execution environment, ensuring secure operation and isolation from other system components. The secure element provides a restricted environment where the applet can securely store, process, and delete sensitive data as required. Unless the context suggests otherwise, the term “factory reset event” refers to a system- triggered occurrence within a secure element that indicates a factory reset process to be executed.
[0030] Unless the context suggests otherwise, the term “Embedded Universal Integrated Circuit Card (eUlCC)” refers to a reprogrammable embedded secure element, primarily used in mobile and loT devices to enable secure storage and remote provisioning of subscription profiles. Unlike traditional SIM cards, the eUlCC is soldered directly onto the device’s mainboard and supports multiple profiles, allowing over-the-air (OTA) management of carrier subscriptions without physical replacement.
[0031] Unless the context suggests otherwise, the terms “Secure System Element (sSE)” and “secure element (SE)” may be used interchangeably throughout the description, and they refer to a tamper-resistant component that can be used to securely host cryptographic functions, sensitive data, and trusted applications. The sSE can be implemented as a discrete chip, embedded within a system-on-chip (SoC), or integrated into other modules such as eUlCCs. It provides hardware-based isolation for secure execution.
[0032] Unless the context suggests otherwise, the term “Embedded Subscriber Identity Module (eSIM)” refers to a digital SIM card built into a device, eliminating the need for a physical SIM card, offering flexibility and convenience for switching between carriers or plan. The eSIM facilitates remote provisioning and management of mobile network operator profiles, thereby enabling seamless connectivity without physical SIM swaps. It allows end users to download and switch between multiple carrier profiles as needed, improving user experience and simplifying logistics for mobile network operators.
[0033] Unless the context suggests otherwise, the term “security processor unit (SPU)” refers to a dedicated hardware module or subsystem within an integrated circuit, designed to perform security-critical operations independently of a main processor of the system. The invention will be better understood thanks to the following description of an applet, comprised in a secure element. Since the secure element is permanently soldered and cannot be physically removed from a terminal, like a smartphone, a new approach is needed to securely erase personal user data during a factory reset. For example, this applet, called a factory reset applet, where the factory reset applet is a specialized software component installed within the secure element. The factory reset applet is designed to manage the factory reset process for applicative applets, which are smaller software programs within the secure element that store and process user data. The factory reset applet has a function to inform applicative applets containing personal user data installed in a secure element of the occurrence of a factory reset event when it receives a factory reset command. The applicative applets, upon receipt of the information of the factory reset event, delete the personal user data that they contain.
[0034] Figure 1 illustrates a method for performing registration of an applicative applet to a factory reset applet, in accordance with embodiments of the present disclosure.
[0035] As illustrated in Figure 1 , at step 20, an entity 10, called External World, (e.g., an end user), installs an applicative applet 11 in a terminal equipment, more precisely in the embedded secure element 40 of this terminal equipment. At step 21 , this applicative applet 11 informs a factory reset applet 12 that it has been installed in the secure element 40. The factory reset applet 12 can be pre-installed in the secure element 40 at the stage of its production (in a factory).
[0036] At step 22, the factory reset applet 12 stores an applicative applet reference such as an identifier of the applicative applet 11 in a list of applets that can store user’s personal data.
[0037] The applicative applet 11 knows where personal data, associated with the corresponding applet 11 , entered by the user are stored.
[0038] Figure 2 illustrates a line diagram representing a method for performing a factory reset of the device, in accordance with embodiments of the present disclosure. Here, the External World 10 refers to an external entity 10 for example a repair service or a factory responsible for repairing or recycling a device. This entity initiates the process by sending a factory reset command 30 to the factory reset applet 12 according to step 30. Since the factory reset applet 12 maintains (registration step 12 of figure 1) a list of registered applicative applets (also referred to as “plurality of applicative applets”) which application applets have registered in his list, the factory reset applet can identify the plurality of applicative applets among all applets of the secure element based on a list of registered applicative applets.
[0039] The applet 12 sends, at steps 31 and 33, a request for Factory Reset to all the applets 13 and 14 (i.e. registered applicative applets) that have been registered with the factor reset applet 12. In response, these applicative applets 13, 14 then perform deletions of the user data (as they know where these user data are stored therein). At steps 32 and 34, the applicative applets 13, 14 ensure that all personal user information is securely erased, completing the factory reset process in a controlled and structured manner.
[0040] At step 35, the factory reset applet 12 resets the user’s credentials, ensuring the user’s personal data are thus deleted from the application applets.
[0041] In order to simplify the process, it is also possible to bypass the registration of the application applets that have been installed in the device. Instead, the factory reset applet 12 can scan all the application applets installed in the secure element 40 and directly request them to perform a factory reset. Upon receiving the request, the applicative applets will proceed with the deletion of user data, ensuring a complete and secure reset process.
[0042] In an embodiment, the factory reset Applet 12 implements a registration service for applets that request for a Factory Reset notification.
[0043] This can be performed by the following command: / / interface to be implemented by FactoryReset Applet public interface FactoryReset implements Shareable { public void register (FactoryResetEvent applet);
[0044] }
[0045] For the protected applets to implement a shareable service which allows the factory reset applet to call each previously registered applet to check if user data has been deleted, the following command can be used:
[0046] / / interface to be implemented by all Applets public interface FactoryResetEvent implements Shareable {
[0047] / / return ‘true’ if applet’s user data deleted public boolean requestFactoryRequest();
[0048] }
[0049] In an embodiment, the factory reset applet 12 can be installed at the same location as the application applets 13, 14.
[0050] A factory reset applet, installed in a secure element soldered in terminal equipment and including, the list is not exhaustive, eSE, Embedded Subscriber Identity Module (eSIM), Integrated Subscriber Identity Module (iSIM), SPU (Security Processor Unit) of a SOC (System on Chip), etc..
[0051] The invention also concerns a method implemented in a secure element soldered in a terminal equipment. The method comprises the step of informing by a factory reset applet at least one applicative applet containing personal user data installed in the secure element of the occurrence of a factory reset event when it receives a factory reset command, so that the applet deletes the personal user data that they contain.
[0052] Finally, the invention concerns a secure element comprising a factory reset applet, the secure element being soldered in a terminal equipment. The factory reset applet is configured for informing applicative applets containing personal user data installed in the secure element of the occurrence of a factory reset event when it receives a factory reset command, so that the applicative applets delete the personal user data that they contain.
[0053] Figure 3 illustrates a method 300 implemented in a secure element 40 soldered in a terminal equipment for performing a factory reset, in accordance with another embodiment of the present disclosure. The secure element is a UICC, an iUICC or a elllCC. The device comprises a processor that executes a set of instructions to perform the steps of factory reset applet.
[0054] At step 302, the device, particularly the factory reset applet, receives a factory reset command from an external entity 10.
[0055] At step 304, upon receipt of the factory reset command, the factory reset applet generates a factory reset event based on the factory reset command. The factory reset event indicates an occurrence of a factory reset of the device to delete personal user data stored within the secure element 40.
[0056] At step 306, the factory reset applet sends a request corresponding to the factory reset event to each of a plurality of applicative applets 13, 14 to delete corresponding personal user data stored within the secure element 40.
[0057] In an embodiment, upon receipt of the request corresponding to the factory reset event, the applicative applets delete the personal user data that the corresponding applicative applet 13 or 14 has.
[0058] In an embodiment, each of the applicative applets notify said factory reset applet 12 that the plurality of applicative applets are eligible to the factory reset.
[0059] In an embodiment, the factory reset applet 12 maintains the list of registered applicative applets. Based on the list of the registered applicative applets, the factory reset applet identifies the plurality of applicative applets 13, 14 among all applets of the secure element based on a list of registered applicative applets.
[0060] FIG. 4 illustrates an exemplary computing system 400 for implementation of a method for performing a factory reset, in accordance with an exemplary embodiment of the present disclosure.
[0061] The computing system 400 may represent, for example, an end device that involves network connection. In an embodiment, the end device may comprise, but not limited to a smart phone, a laptop computer, a desktop computer, a workstation, a portable computer, a handheld, or a mobile device. In an embodiment, the computing system 400 may represent, for example, an end-device with the provision of mobility. Examples of the end-device with the provision of mobility may comprise but not limited to a Telematics Control Unit (TCU), an infotainment system, a Vehicle-to-Everything Device (V2X) device, an On-board Diagnostics Device (OBD), an Advanced Driver Assistance Systems (ADAS) sensor, and the like. The computing system 400 may comprise one or more processors, such as a processor 402 that may be implemented using a general or special purpose processing engine such as, for example, a microprocessor, microcontroller or other control logic. In this example, the processor 402 is connected to a bus 404 or other communication medium. In an embodiment, examples of processor 402 may comprise, but are not limited to, microcontrollers, microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), system-on-chip (SoC) components, or any other suitable programmable logic devices, system-on-a-chip processors or other future processors.
[0062] The computing system 400 may also comprise a memory 406 (main memory), for example, Random Access Memory (RAM) or other dynamic memory, for storing information and instructions to be executed by the processor 402. The memory 406 also may be used for storing temporary variables or other intermediate information during execution of instructions to be executed by the processor 402. The computing system 400 may likewise comprise a read only memory (“ROM”) or other static storage device coupled to bus 404 for storing static information and instructions for the processor 402. The computing system 400 may also comprise a storage device 408, which may comprise, for example, a media drive 410 and a removable storage interface 414. The media drive 410 may comprise a drive or other mechanism to support fixed or removable storage media, such as a hard disk drive, a floppy disk drive, a magnetic tape drive, an SD card port, a USB port, a micro-USB, an optical disk drive, a CD or DVD drive (R or RW), or other removable or fixed media drive. A storage media 412 may comprise, for example, a hard disk, magnetic tape, flash drive, or other fixed or removable medium that is read by and written to by the media drive 410. As these examples illustrate, the storage media 412 may comprise a computer-readable storage medium having stored there in particular computer software or data.
[0063] In some embodiments, the storage devices may comprise other similar instrumentalities for allowing computer programs or other instructions or data to be loaded into the computing system 400. Such instrumentalities may comprise, for example, a removable storage unit 414 and a storage unit interface 416, such as a program cartridge and cartridge interface, a removable memory (for example, a flash memory or other removable memory module) and memory slot, and other removable storage units and interfaces that allow software and data to be transferred from the removable storage unit 414 to the computing system 400.
[0064] The computing system 400 may also comprise a communications interface 418. The communications interface 418 may be used to allow software and data to be transferred between the computing system 400 and external devices. Examples of the communications interface 418 may comprise a network interface (such as an Ethernet or other NIC card), a communications port (such as for example, a USB port, a micro-USB port), Near field Communication (NFC), etc. Software and data transferred via the communications interface 418 are in the form of signals which may be electronic, electromagnetic, optical, or other signals capable of being received by the communications interface 418. These signals are provided to the communications interface 418 via a channel 420. The channel 420 may carry signals and may be implemented using a wireless medium, wire or cable, fiber optics, or another communications medium. Some examples of the channel 420 may comprise a phone line, a cellular phone link, an RF link, a Bluetooth link, a network interface, a local or wide area network, and other communications channels.
[0065] The computing system 400 may further comprise Input / Output (I / O) devices 422. Examples may comprise, but are not limited to a display, keypad, microphone, audio speakers, vibrating motor, LED lights, etc.. The I / O devices 422 may receive input from a user and also display an output of the computation performed by the processor 402. In this document, the terms “computer program product” and “computer-readable medium” may be used generally to refer to media such as, for example, the memory 406, the storage devices 408, the removable storage unit 414, or signal(s) on the channel 420. These and other forms of computer-readable media may be involved in providing one or more sequences of one or more instructions to the processor 402 for execution. Such instructions, generally referred to as “computer program code” (which may be grouped in the form of computer programs or other groupings), when executed, enable the computing system 400 to perform features or functions of embodiments of the present invention.
[0066] In an embodiment where the elements are implemented using software, the software may be stored in a computer-readable medium and loaded into the computing system 400 using, for example, the removable storage unit 414, the media drive 410 or the communications interface 418. The control logic (in this example, software instructions or computer program code), when executed by the processor 402, causes the processor 402 to perform the functions of the invention as described herein.
[0067] Various embodiments of the present disclosure may include one or more computer programs stored or otherwise embodied on a computer-readable medium, wherein the computer programs are configured to cause a processor or the computer to perform one or more operations. A computer-readable medium storing, embodying, or encoded with a computer program, or similar language may be embodied as a tangible data storage device storing one or more software programs that are configured to cause a processor or computer to perform one or more operations. Such operations may be, for example, any of the steps or operations described herein. In some embodiments, the computer programs may be stored and provided to a computer using any type of non-transitory computer-readable media.
Claims
CLAIMS1 . A device for performing a factory reset, the device comprising: a secure element (40) soldered within the device; a factory reset applet (12) installed in the secure element (40), said factory reset applet (12) is configured to: receive a factory reset command from an external entity (10); upon receipt of the factory reset command, generate a factory reset event based on the factory reset command, the factory reset event indicating an occurrence of a factory reset of the device to delete personal user data stored within the secure element (40); and send a request corresponding to the factory reset event to each of a plurality of applicative applets (13, 14) to delete corresponding personal user data stored within the secure element (40).
2. The device according to claim 1 , wherein each of said plurality of applicative applets (13, 14), upon receipt of the request corresponding to the factory reset event, is configured to delete the personal user data that the corresponding applicative applet (13, 14) has.
3. The device according to claim 1 , wherein the factory reset applet (12) is configured to identify the plurality of applicative applets (13, 14) among all applets of the secure element (40) based on a list of registered applicative applets.
4. The device according to claim 1 or 2, wherein said applicative applets (13, 14) notify said factory reset applet (12) that said applicative applets (13, 14) are eligible to the factory reset.
5. The device according to any of claims 1 -3, wherein said secure element (40) is an Embedded Universal Integrated Circuit Card (eUlCC), an Embedded Secure Element (eSE), or an application (Integrated Universal Integrated Circuit Card or Integrated Secure Element) running in a Security Processor Unit (SPU) in a System on Chip (SOC).
6. A method (300) implemented in a secure element (40) soldered in a terminal equipment for performing a factory reset, said method comprising: receiving (302) a factory reset command from an external entity (10); upon receipt of the factory reset command, generating (304) a factory reset event based on the factory reset command, the factory reset event indicating an occurrence of a factory reset of the device to delete personal user data stored within the secure element (40); and sending (306) a request corresponding to the factory reset event to each of a plurality of applicative applets (13, 14) to delete corresponding personal user data stored within the secure element (40).
7. The method (300) as claimed in claim 6, further comprising upon receipt of the request corresponding to the factory reset event, deleting the personal user data that the corresponding applicative applet (13, 14) has.
8. The method (300) as claimed in claim 6, further comprising notifying said factory reset applet (12) that said applicative applets (13, 14) are eligible to the factory reset.
9. The method (300) as claimed in claim 6, further comprising identifying the plurality of applicative applets (13, 14) among all applets of the secure element based on a list of registered applicative applets.
10. A secure element (40) for performing a factory reset, said secure element (40) being soldered in a terminal equipment, the secure element (40) comprising: a factory reset applet (12) installed in the secure element (40), said factory reset applet (12) is configured to:receive a factory reset command from an external entity (10); upon receipt of the factory reset command, generate a factory reset event based on the factory reset command, the factory reset event indicating an occurrence of a factory reset of the device to delete personal user data stored within the secure element (40); and send a request corresponding to the factory reset event to each of a plurality of applicative applets (13, 14) to delete corresponding personal user data stored within the secure element (40).