Method for installing a profile of a mobile network operator (MNO) in a secure element integrated in a telecommunication device
The tag-based method for installing MNO profiles in secure elements addresses the limitations of existing IFPP solutions by enabling flexible and scalable profile installation in IoT and M2M devices, reducing operational complexity and costs without EID tracking.
Patent Information
- Application Number
- PCT/EP2025/068701
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-23
- Filing Date
- 2025-07-01
- Publication Date
- 2026-01-29
AI Technical Summary
Current IFPP solutions require advance knowledge of the Embedded Universal Integrated Circuit Card Identifier (EID) and specific integration on the factory floor, necessitating strict supply chain tracking and adaptation for IoT and M2M devices, lacking flexibility and scalability.
A method for installing a Mobile Network Operator (MNO) profile in a secure element using a tag-based approach, where a tag corresponding to the MNO is obtained and used to retrieve an activation code from an external server, allowing secure element to connect to a remote server for profile download and installation, without requiring EID tracking.
Enables flexible and scalable profile installation in IoT and M2M devices, reducing operational complexity and costs by eliminating the need for EID tracking and minimizing factory setup changes, while being forward-compatible with emerging standards.
Smart Images

Figure EP2025068701_29012026_PF_FP_ABST
Abstract
Description
[0001] Method for installing a profile of a Mobile Network Operator (MNO) in a secure element integrated in a telecommunication device
[0002] TECHNICAL FIELD
[0003] The present disclosure concerns telecommunications and in particular the loading of one or several profiles in a secure element (e.g., Embedded Universal Integrated Circuit Card - eUlCC) in a telecommunication device at the last stage of production of this device. This solution is also called IFPP (In-Factory Profile Provisioning).
[0004] BACKGROUND
[0005] IFPP manages and integrates embedded Subscriber Identity Module (eSIM) profiles while an Internet of things (loT) device (or Consumer Equipment - CE) is still in production in a factory. This is achieved through an over-the-air profile loader in the manufacturing line, allowing profiles to be securely loaded during the manufacturing process. By provisioning profiles in-factory rather than in the field, IFPP helps reduce logistics and manufacturing complexity and can also extend battery life for the loT device itself (compared to loading the profile in the field).
[0006] In-Factory Profile Provisioning capitalizes on the benefits introduced by eUlCC - eSIMs and integrated Subscriber Identity Module (iSIMs) - which embeds the Subscriber Identification Module (SIM) into loT device’s main circuit board, and eliminates the need fora separate physical SIM card. IFPP also applies to consumer equipments like smartphones for example.
[0007] IFPP securely loads relevant Mobile Network Operator (MNO) or Mobile Virtual Network Operator (MVNO) SIM profiles or Original Equipment Manufacturer (OEM) profiles (in general a profile of the end-user of the device) onto devices during the manufacturing or order fulfilment process. This approach offers significant advantages for manufacturers in terms of streamlining their own processes, and allowing for dynamic changes to the production line based on characteristics such as the geographic location into which the device is to be deployed.
[0008] Instead of managing a physical inventory of physical SIM cards that would be manually fitted into each device, the manufacturer can request eSIM profiles from different operators and these are loaded over-the-air when the device first connects to a network. This network can either be a test network or a public network depending on the initial startup profile on the SIM.
[0009] Typically, this process will be combined with other factory processes such as the flashing of the device firmware or other software as part of manufacturing or fulfillment to consolidate and optimize the production or fulfillment workflow.
[0010] While IFPP can be used in conjunction with Remote Sim Provisioning (RSP) to offer even greater flexibility for loT deployments, it is seen as an alternative to in-the-field provisioning, which may not be appropriate for many forms of loT and Machine-to-Machine (M2M) devices.
[0011] IFPP is a great asset for embedding cellular SIM profiles into loT and M2M devices, simplifying supply chains, reducing operational costs, and improving in-the-field operational performance.
[0012] The journey to highly scalable loT and M2M deployments via eSIM and RSP doesn’t stop with SGP.41. Standardized support for IFPP is to be realized through GSMA specification SGP.41 / SGP.42, where the working group is developing a specification as part of its eSIM and RSP standardization activities.
[0013] The specifications (SGP.41 / SGP.42) aim to streamline the loading of operator profiles at the manufacturing stage. However, the standard is still under development, with commercial implementations still a few years out.
[0014] While the SGP.42 standard can be expected to arrive around 2024-2025 timeframe, there are proprietary IFPP-enabled solutions already on the market that will bridge the evolution gap and offer an upgrade path.
[0015] The current IFPP solution, which is proposed in WG1 of the GSMA, is based on the Bound Profile Package (as defined in SGP.22) and requires to know the EID and the public key of the eSIM ahead of time which requires strict tracking of the supply chain. This solution is leveraging a lot from SGP.22 and does not require to modify the eSIM and does not require SAS certification of the factory.
[0016] However, this approach has multiple challenges: it requires new eSIM (SGP.42) and needs specific integration on the factory floor and in the device; the FPA (Factory Profile Assistant) used in the future IFPP standard to load a profile in the eSIM needs to be installed and managed by the device manufacturer;
[0017] It requires to know the Embedded Universal Integrated Circuit Card Identifier (EID) in advance; and
[0018] It needs to be adapted depending on the eSIM installed in the device, either loT SGP.32 or Consumer SGP.22.
[0019] SUMMARY
[0020] The present disclosure proposes a solution to these problems.
[0021] The present disclosure proposes a method for installing a profile of a Mobile Network Operator (MNO) in a secure element integrated in a telecommunication device. The method is executed in a factory. The method comprises obtaining, by the secure element, through the telecommunication device, a tag corresponding to the MNO to which the secure element is to be connected. The method comprises connecting, through a provisioning box, the secure element to an external server, wherein the external server stores a plurality of activation codes, each activation code corresponding to a particular MNO. The method further comprises retrieving, based on the tag, an activation code corresponding to the MNO to which the secure element is to be connected, from the external server. The activation code serves as an authorization to download a profile from a remote server of the MNO. The method further comprises sending the activation code through the provisioning box to the remote server of the MNO to request a profile and upon verification of the activation code, receiving a profile from the remote server and installing the profile in the secure element.
[0022] According to some example embodiments, the tag is either stored in said telecommunication device, or stored in the secure element.
[0023] According to some example embodiments, the step of retrieving comprises sending to the external server the tag corresponding to the MNO to which the secure element is to be connected, and obtaining the activation code corresponding to the tag from the external server. According to some example embodiments, the method comprises connecting through a provisioning box the secure element to the external server of the MNO in order to download the profile in the secure element.
[0024] The present disclosure also proposes a secure element installing a profile of a Mobile Network Operator (MNO), where the secure element is integrated in a telecommunication device. The secure element is configured for obtaining a tag corresponding to the MNO to which the secure element is to be connected. The secure element is configured for connecting, through a provisioning box, to an external server. The external server stores a plurality of activation codes, each corresponding to a particular MNO. The secure element is configured for retrieving, based on the tag, an activation code corresponding to the MNO to which the secure element is to be connected, from the external server. The activation code serves as an authorization to download a profile from a remote server. The secure element is configured for sending the activation code through the provisioning box to the remote server of the MNO to request a profile. Upon verification of the activation code, the secure element is configured for receiving a profile from the remote server and installing the profile.
[0025] According to some example embodiments, the secure element is configured for sending to the external server the tag corresponding to the MNO to which the secure element is to be connected, and obtaining the activation code corresponding to the tag from the external server.
[0026] According to some example embodiments, the secure element is configured for connecting through a provisioning box the secure element to the external server of the MNO in order to download the profile in the secure element.
[0027] According to some example embodiments, the tag is either stored in the telecommunication device or stored in the secure element.
[0028] The present disclosure also proposes a server external to a factory for installing a profile of a Mobile Network Operator (MNO) in a secure element integrated in a telecommunication device. The installation is executed in the factory. The server is configured for receiving, from the secure element or the telecommunication device, a tag corresponding to the MNO to which the secure element is to be connected. The server is configured for identifying an activation code, among the plurality of activation codes, corresponding to the received tag. The server is configured for sending the activation code to the secure element. The activation code serves as an authorization to download a profile from a remote server of the MNO. The secure element connects to the remote server of the MNO for downloading the profile.
[0029] BRIEF DESCRIPTION OF THE DRAWINGS
[0030] The present disclosure will be better understood by reading the following description of the figures that represent:
[0031] FIG. 1 , an environment indicating a system for provisioning devices, with at least one profile of an MNO or MVNO, in accordance with an embodiment of the present disclosure.
[0032] FIG. 2, a method for installing a profile of an MNO in a secure element, in accordance with another embodiment of the present disclosure.
[0033] FIG. 3, an exemplary computing system for implementation of a method for installing a profile of an MNO in a secure element, in accordance with an exemplary embodiment of the present disclosure.
[0034] The present disclosure will be better understood by reading the following description of the above figures.
[0035] DETAILED DESCRIPTION
[0036] Unless the context suggests otherwise, the term “applet” refers to a software program or application designed to perform a specific, limited function within a larger system or environment. The applet operates within a controlled execution environment, ensuring secure operation and isolation from other system components.
[0037] Unless the context suggests otherwise, the term “Embedded Universal Integrated Circuit Card (eUlCC)” refers to a reprogrammable embedded secure element, primarily used in mobile and loT devices to enable secure storage and remote provisioning of subscription profiles. Unlike traditional SIM cards, the eUlCC is soldered directly onto the device’s mainboard and supports multiple profiles, allowing over-the-air (OTA) management of carrier subscriptions without physical replacement.
[0038] Unless the context suggests otherwise, the terms “Secure System Element (sSE)” and “secure element (SE)” may be used interchangeably throughout the description, and they refer to a tamper-resistant component that can be used to securely host cryptographic functions, sensitive data, and trusted applications. The sSE can be implemented as a discrete chip, embedded within a system-on-chip (SoC), or integrated into other modules such as eUlCCs. It provides hardwarebased isolation for secure execution.
[0039] Unless the context suggests otherwise, the term “Embedded Subscriber Identity Module (eSIM)” refers to a digital SIM card built into a device, eliminating the need for a physical SIM card, offering flexibility and convenience for switching between carriers or plan. The eSIM facilitates remote provisioning and management of mobile network operator profiles, thereby enabling seamless connectivity without physical SIM swaps. It allows end users to download and switch between multiple carrier profiles as needed, improving user experience and simplifying logistics for mobile network operators.
[0040] Unless the context suggests otherwise, the term “Local Profile Assistant - embedded (LPAe)” refers to an embedded version of the Local Profile Assistant (LPA), integrated directly into the device firmware. It manages eSIM profiles in coordination with remote servers like SM-DP+ and SM-DS. LPA serves as a bridge between the device and various mobile network operators (MNOs) without needing physical SIM cards.
[0041] Unless the context suggests otherwise, the term “loT Profile Assistant - embedded (IPAe)” refers to a software component embedded within the eUlCC (embedded Universal Integrated Circuit Card) of an loT device, specifically designed to manage eSIM profiles. It acts as an intermediary between the eSIM (eUlCC) and the eSIM loT Remote Manager (elM), embedded directly into the device's firmware, enabling secure profile management.
[0042] The present disclosure proposes to overcome the above-mentioned issues and is designed to be forward-compatible with SGP.32 and SGP.42. More precisely, it provides a simplified approach to have simple provisioning at the factory requiring minimal changes to the factory setup or configuration. The disclosure will be better understood by reading the following description of a preferred embodiment of the disclosure in FIGs. 1-3. FIG. 1 represents an environment indicating a system for provisioning devices, like loT devices or consumer equipment, with at least one profile of an MNO or MVNO, in accordance with embodiments of the present disclosure.
[0043] FIG. 1 illustrates an OEM factory 10 that can comprise a plurality of devices 11 (also called DUT for “Device Under Test”). Each device 11 can comprise a secure element, like for example an eSIM or eUlCC 12. Each eSIM 12 can comprise an applet 13 with an loT Profile Assistant - embedded (IPAe) or Local Profile Assistant - embedded (LPAe) and is pre-provisioned with a factory profile 14. Therefore, either IPAe or LPAe is responsible for managing SIM profiles directly on the eSIM. The factory profile 14 is a basic, default SIM profile that is loaded onto the eSIM before the device is shipped out of the factory.
[0044] In a preferred embodiment, the secure element 12 is an embedded secure element (eSE) comprising a processor and a non-volatile memory.
[0045] In the OEM factory 10, a provisioning box 15 is also foreseen - the provisioning box 15 can be a standalone dedicated equipment or can be a private network used in the OEM factory and covering the production line. The provisioning box 15 is a tool used to load and manage eSIM profiles on devices as they pass through the production line.
[0046] Outside of the OEM factory 10, there is a server 16 (interchangeably referred to as “external server 16”) which function will be explained below, Internet 17, and MNO partners 18 having remote servers, each SM-DP+ 19a, 19b, and 19c storing profiles.
[0047] The workflow of the method of the disclosure is the following:
[0048] At a preliminary step 100, a production planner configures the server 16 with rules mapping tag to pools of generic activation codes. The production planner can be a user or a software system in charge of preparing devices for deployment. Each tag comprises data corresponding to a target MNO SM-DP+ (tag1 for MNO1 , tag2 for MNO2,...). MNO SM-DP+ refers to the Subscription Manager - Data Preparation+, a remote server specified in the GSMA eSIM architecture that handles profile download to eSIMs.
[0049] The tag can comprise any or a combination of string, QR code or any other identifier, that uniquely or generically identifies the target MNO (Mobile Network Operator). The mapping between the activation codes and tags allows the system to automatically select an appropriate activation code later in the process, based on the tag detected on the device. The server can be configured with logic that associates each tag with one or more activation codes. The server 16 is an el M server (eSIM loT Manager) according to SGP.32 that governs how eSIM provisioning should happen in an loT environment.
[0050] Otherwise said, the production planner provisions in the server 16 the activation codes for the candidate MNOs for the devices 11 that are in production.
[0051] If the production planner wants to produce devices for a given MNO, for example, Orange™, he will provision in the server 16, for a fleet of devices 11 , a tag (or label) corresponding to the Orange™ network. And as he knows which devices are to be provisioned in the factory 10, he can plan it well in advance, in order to configure the devices for its target market with the chosen MNO. Each tag corresponds to a pool of activation codes. These tags are used to identify which MNO each batch of devices is intended for. For example, if a group of devices is meant to work with Orange™, the planner provisions a tag like tag Orange™ and associates it with a pool of Orange™-specific activation codes.
[0052] A tag can be either a number or a string referring to a pool of activation codes, each activation code being later on affected to a given device 11.
[0053] At step 21 , a given device 11 (DUT) is powered on in factory mode. In this mode, the device 11 operates using the sole factory profile 14 pre-installed and present in its secure element 12. This factory profile is typically a minimal, temporary profile used solely for manufacturing and provisioning processes. Previously, the device 11 has been tagged with a target MNO through the use of the tag. This tag represents the target MNO for which the device is intended and can be stored in the device 11 , in various forms. For instance, the tag may be stored internally in the device 11 or within the secure element 12. The tag can be printed on a paper physically attached to the device 11 such as a sticker. Alternatively, the tag may be stored externally, such as on the factory test PC that controls and communicates with the device 11 on the factory line. A tag can be implemented as, for example, a QR code printed on surface of the device 11. This makes it easy to scan and associate the device with its corresponding MNO. The important point is that regardless of where or how the tag is stored, this tag can be read and sent later on to the eSIM 12 at step 22 where the tag is transmitted to the applet. When the device under test is powered, the DUT 11 sends, at step 22, the tag to the applet 13, for example through an Application programming interface (API) call or Application Protocol Data Unit (APDU) command. For example, for smart meter product, if the production manager intends to deploy his products in France with a given MNO-A, at the external server 16, he will set up a rule on the elM server side:
[0054] The rule can be expressed as follows: “when I receive a request for a profile with a tag “Tag1”, provide an activation code from this pool of activation codes from MNO-A.
[0055] At step 23, the DUT 11 connects to the private network provided by the provisioning box 15. Following this, the applet 13 establishes a connection with the server 16 through the provisioning box 15, at step 24, to retrieve an activation code (or a pool of activation codes) corresponding to the transmitted tag that was transmitted at step 22.
[0056] This activation code is sent from the server 16 to the applet 13. Then, at step 25, the IPAe / LPAe uses this activation code to retrieve, from the SM-DP+ identified by the tag, an eSIM profile (from remote servers 19a, 19b, or 19c) corresponding to one of the profiles identified by the production planner at step 100. This profile can be then installed and activated (in a provisioned profile 20). The activation code acts as a right to download a profile. In other words, the activation code serves as an authorization to download a profile from a remote server (19a, 19b, 19c) of the MNO.
[0057] In this disclosure, the profile resolution is done indirectly via the tag rather than through direct tracking of the EID. Thus, it is not necessary to monitor or reference the EID during production. Instead, the important factor is to know which deployment and the resolution is done at the last moment at the server level.
[0058] The connection between the provisioning box 15 and the Internet 17 can be provided through a network such as a wired, fibered, or cellular network. This connection enables device 11 to connect to the firewall of the factory and if a port is authorized to the provisioning box or if a backhaul to the local network is configured, the connection is successful.
[0059] The network may comprise, without limitation, a light fidelity (Li-Fi) network, a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a satellite network, the Internet, a fiber optic network, a coaxial cable network, an infrared (IR) network, a radio frequency (RF) network, a virtual network, and / or another suitable public and / or private network capable of supporting communication among the entities illustrated in FIG. 1 , or any combination thereof.
[0060] It is also possible to download multiple profiles, either sequentially i.e. one after the other, or at the same time (in parallel) if this operator is authorized by the production planner and in agreement with the MNO’s partners.
[0061] The activation code acts as a right or credential to download a profile and it is sent to the MNO partners 19a, 19b, 19c. For this reason, the activation code is a critical element in the provisioning workflow.
[0062] The disclosure also concerns a method where the tag is sent to the secure element 12 through the telecommunication device 11.
[0063] The disclosure also concerns an applet 13 installed in a secure element 12 comprising an IPAe / LPAe, the applet 13 comprising instructions for executing the following steps: receiving a tag corresponding to an MNO to which the secure element 12 has to be connected; connecting to an external server 16 with the tag, the external server 16 comprising activation codes for the secure element 12 for downloading a profile of the MNO; receiving from the external server 16 the activation code; connecting through a provisioning box 15 the applet to a remote server e.g., SM-DP+19a, SM- DP+19b, SM-DP+19c of the MNO in order to download the profile in the secure element 12 if the activation code is correct.
[0064] Finally, the disclosure concerns a server 16 external to a factory 10 intended for sending and installing a profile of an MNO 18 in a secure element 12 integrated in a telecommunication device 11 , the sending and installing being done in the factory 10, the server 16 being configured for: receiving from a secure element 12 or the telecommunication device a tag corresponding to an MNO 18 from which a SM-DP+ 19a, 19b, 19c profile has to be installed, the server 16 having been before provisioned with activation codes of profiles stored at a SM-DP+ 19a, 19b, 19c of at least an elected MNO 18;
[0065] Sending on the basis of the tag one of the activation codes to the secure element 12, the activation code corresponding to the MNO to which the secure element 12 has to be connected in order that the secure element 12 connects to a SM-DP+ 19a, 19b, 19c of the MNO 18 for downloading a profile from the MNO 18.
[0066] FIG. 2 illustrates a method 200 for installing a profile of a Mobile Network Operator (MNO) 18 in a secure element 12, in accordance with another embodiment of the present disclosure. The secure element 12 can be integrated in a telecommunication device 11. The method is executed in a factory 10. The secure element comprises a processor that executes a set of instructions to perform the steps 202-210.
[0067] Operations of the method 200, and combinations of the operations in the method 200, may be implemented by, for example, hardware, firmware, a processor, circuitry, and / or a different device associated with the execution of software that comprises one or more computer program instructions. The sequence of operations of the method 200 may not be necessarily executed in the same order as they are presented. Further, one or more operations may be grouped and performed in the form of a single step, or one operation may have several sub-steps that may be performed in parallel or a sequential manner.
[0068] At step 202, the secure element 12 obtains through the telecommunication device 11 a tag corresponding to the MNO 18 to which the secure element 12 is to be connected. The tag can be stored in the telecommunication device 11 , or stored in the secure element 12.
[0069] At step 204, the secure element connects, through a provisioning box 15, to an external server 16. The external server 16 stores a plurality of activation codes, each corresponding to a particular MNO 18.
[0070] At step 206, the secure element retrieves, based on the tag, an activation code corresponding to the MNO 18 to which the secure element 12 is to be connected, from the external server 16. The activation code serves as an authorization to download a profile from a remote server 19a, 19b, 19c of the MNO 18.
[0071] In an embodiment, step of retrieving 206 comprises sending the tag corresponding to the MNO 18 to which the secure element 12 is to be connected, to the external server 16, and obtaining the activation code corresponding to the tag from the external server 16. In an embodiment, the secure element 12 connects through a provisioning box 15 to the remote server 19a, 19b, 19c of the MNO 18 in order to download the profile in the secure element 12.
[0072] At step 208, the secure element 12 sends the activation code through the provisioning box 15 to the remote server 19a, 19b, 19c of the MNO 18 to request a profile.
[0073] At step 210, upon verification of the activation code, the secure element 12 receives a profile from the remote server 19a, 19b, 19c and, at step 212, the secure element 12 installs the profile.
[0074] FIG. 3 illustrates an exemplary computing system 300 for implementation of a method for installing a profile of an MNO in a secure element, in accordance with an exemplary embodiment of the present disclosure.
[0075] The computing system 300 may represent, for example, an end device that involves network connection. In an embodiment, the end device may comprise, but not limited to a smart phone, a laptop computer, a desktop computer, a workstation, a portable computer, a handheld, or a mobile device. In an embodiment, the computing system 300 may represent, for example, an end-device with the provision of mobility. Examples of the end-device with the provision of mobility may comprise but not limited to a Telematics Control Unit (TCU), an infotainment system, a Vehicle- to-Everything Device (V2X) device, an On-board Diagnostics Device (OBD), an Advanced Driver Assistance Systems (ADAS) sensor, and the like. The computing system 300 may comprise one or more processors, such as a processor 302 that may be implemented using a general or special purpose processing engine such as, for example, a microprocessor, microcontroller or other control logic. In this example, the processor 302 is connected to a bus 304 or other communication medium. In an embodiment, examples of processor 302 may comprise, but are not limited to, microcontrollers, microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), system-on-chip (SoC) components, or any other suitable programmable logic devices, system-on-a-chip processors or other future processors.
[0076] The computing system 300 may also comprise a memory 306 (main memory), for example, Random Access Memory (RAM) or other dynamic memory, for storing information and instructions to be executed by the processor 302. The memory 306 also may be used for storing temporary variables or other intermediate information during execution of instructions to be executed by the processor 302. The computing system 300 may likewise comprise a read only memory (“ROM”) or other static storage device coupled to bus 304 for storing static information and instructions for the processor 302.
[0077] The computing system 300 may also comprise a storage device 308, which may comprise, for example, a media drive 310 and a removable storage interface 314. The media drive 310 may comprise a drive or other mechanism to support fixed or removable storage media, such as a hard disk drive, a floppy disk drive, a magnetic tape drive, an SD card port, a USB port, a micro- USB, an optical disk drive, a CD or DVD drive (R or RW), or other removable or fixed media drive. A storage media 312 may comprise, for example, a hard disk, magnetic tape, flash drive, or other fixed or removable medium that is read by and written to by the media drive 310. As these examples illustrate, the storage media 312 may comprise a computer-readable storage medium having stored therein particular computer software or data.
[0078] In some embodiments, the storage devices may comprise other similar instrumentalities for allowing computer programs or other instructions or data to be loaded into the computing system 300. Such instrumentalities may comprise, for example, a removable storage unit 314 and a storage unit interface 316, such as a program cartridge and cartridge interface, a removable memory (for example, a flash memory or other removable memory module) and memory slot, and other removable storage units and interfaces that allow software and data to be transferred from the removable storage unit 314 to the computing system 300.
[0079] The computing system 300 may also comprise a communications interface 318. The communications interface 318 may be used to allow software and data to be transferred between the computing system 300 and external devices. Examples of the communications interface 318 may comprise a network interface (such as an Ethernet or other NIC card), a communications port (such as for example, a USB port, a micro-USB port), Near field Communication (NFC), etc. Software and data transferred via the communications interface 318 are in the form of signals which may be electronic, electromagnetic, optical, or other signals capable of being received by the communications interface 318. These signals are provided to the communications interface 318 via a channel 320. The channel 320 may carry signals and may be implemented using a wireless medium, wire or cable, fiber optics, or another communications medium. Some examples of the channel 320 may comprise a phone line, a cellular phone link, an RF link, a Bluetooth link, a network interface, a local or wide area network, and other communications channels. The computing system 300 may further comprise Input / Output (I / O) devices 322. Examples may comprise, but are not limited to a display, keypad, microphone, audio speakers, vibrating motor, LED lights, etc. The I / O devices 322 may receive input from a user and also display an output of the computation performed by the processor 302. In this document, the terms “computer program product” and “computer-readable medium” may be used generally to refer to media such as, for example, the memory 306, the storage devices 308, the removable storage unit 314, or signal(s) on the channel 320. These and other forms of computer-readable media may be involved in providing one or more sequences of one or more instructions to the processor 302 for execution. Such instructions, generally referred to as “computer program code” (which may be grouped in the form of computer programs or other groupings), when executed, enable the computing system 300 to perform features or functions of embodiments of the present disclosure.
[0080] In an embodiment where the elements are implemented using software, the software may be stored in a computer-readable medium and loaded into the computing system 300 using, for example, the removable storage unit 314, the media drive 310 or the communications interface 318. The control logic (in this example, software instructions or computer program code), when executed by the processor 302, causes the processor 302 to perform the functions of the invention as described herein.
[0081] Various embodiments of the present disclosure may comprise one or more computer programs stored or otherwise embodied on a computer-readable medium, wherein the computer programs are configured to cause a processor or the computer to perform one or more operations. A computer-readable medium storing, embodying, or encoded with a computer program, or similar language may be embodied as a tangible data storage device storing one or more software programs that are configured to cause a processor or computer to perform one or more operations. Such operations may be, for example, any of the steps or operations described herein. In some embodiments, the computer programs may be stored and provided to a computer using any type of non-transitory computer-readable media.
Claims
CLAIMS1 . A method (200) for installing a profile of a Mobile Network Operator (MNO) (18) in a secure element (12) integrated in a telecommunication device (11), said method (200) being executed in a factory (10), said method (200) comprising: obtaining (202), by said secure element (12), through said telecommunication device (11), a tag corresponding to the MNO (18) to which said secure element (12) is to be connected; connecting (204), through a provisioning box (15), said secure element (12) to an external server (16), wherein the external server (16) stores a plurality of activation codes, each activation code corresponding to a particular MNO (18); retrieving (206), based on the tag, an activation code corresponding to the MNO (18) to which said secure element (12) is to be connected, from the external server (16), wherein the activation code serves as an authorization to download a profile from a remote server (19a, 19b, 19c) of the MNO (18); sending (208) said activation code through said provisioning box (15) to the remote server (19a, 19b, 19c) of said MNO (18) to request a profile; upon verification of the activation code, receiving (210) a profile from the remote server (19a, 19b, 19c) and installing (212) the profile in said secure element (12).
2. The method (200) according to claim 1 , wherein said tag is: stored in said telecommunication device (11), or stored in said secure element (12).
3. The method (200) according to claim 1 , wherein the step of retrieving (206) comprises: sending the tag corresponding to the MNO (18) to which said secure element (12) is to be connected, to the external server (16); and obtaining the activation code corresponding to the tag from the external server (16).
4. The method (200) according to claim 1 , further comprising: connecting through a provisioning box (15) said secure element (12) to the remote server (19a, 19b, 19c) of said MNO (18) in order to download said profile in said secure element (12).
5. A secure element (12) for installing a profile of a Mobile Network Operator (MNO), the secure element (12) integrated in a telecommunication device (11), said secure element being configured for: obtaining a tag corresponding to the MNO (18) to which said secure element (12) is to be connected; connecting, through a provisioning box (15), to an external server (16), wherein the external server (16) stores a plurality of activation codes, each activation code corresponding to a particular MNO (18); retrieving, based on the tag, an activation code corresponding to the MNO to which said secure element (12) is to be connected, from the external server (16), wherein the activation code serves as an authorization to download a profile from a remote server (19a, 19b, 19c) of the MNO (18); sending said activation code through said provisioning box (15) to the remote server (19a, 19b, 19c) of the MNO (18) to request a profile; upon verification of the activation code, receiving a profile from the remote server (19a, 19b, 19c) and installing the profile.
6. The secure element (12) according to claim 5, wherein the secure element (12) is configured for: sending the tag corresponding to the MNO to which said secure element (12) is to be connected, to the external server (16); and obtaining the activation code corresponding to the tag from the external server (16).
7. The secure element (12) according to claim 5, wherein the secure element (12) is configured for: connecting through a provisioning box (15) said secure element (12) to the remote server (19a, 19b, 19c) of said MNO (18) in order to download said profile in said secure element (12).
8. The secure element (12) according to claim 5, wherein said tag is: stored in said telecommunication device (11) orstored in said secure element (12).
9. A server (16) external to a factory (10) for installing a profile of a Mobile Network Operator (MNO) (18) in a secure element (12) integrated in a telecommunication device (11), said installation being executed in said factory (10), said server (16) being configured for: receiving, from the secure element (12) or said telecommunication device, a tag corresponding to the MNO (18) to which said secure element (12) is to be connected; identifying an activation code, among the plurality of activation codes, corresponding to the received tag; sending the activation code to said secure element (12), wherein the activation code serves as an authorization to download a profile from a remote server (19a, 19b, 19c) of the MNO (18), wherein the secure element (12) connects to the remote server (19a, 19b, 19c) of said MNO (18) for downloading the profile.
Citation Information
Patent Citations
System and method for provisioning profiles
GB2605772A
System and method for remote provisioning of embedded universal integrated circuit cards
US20140004827A1
Technique for Remote SIM Provisioning
US20200186992A1
Operational subscription profile download
WO2023219540A1
KR20240022974A