Method and device for in-factory loading of limited-use profiles
By associating an authentication counter with profiles to limit factory loading mode authentications, the security vulnerability of devices is mitigated, ensuring factory loading mode is deactivated post-manufacturing, thus preventing unauthorized profile loading.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- IDEMIA FRANCE SAS
- Filing Date
- 2025-11-04
- Publication Date
- 2026-06-04
AI Technical Summary
The persistence of factory loading mode after devices leave the factory poses a security vulnerability, allowing malicious actors to exploit it for unauthorized profile loading, which is difficult to manage due to complex manufacturing processes involving multiple subcontractors.
Associating an authentication counter with profiles, where a maximum number of authentications is set, and triggering countermeasures when this limit is reached, including notifications to operators and disabling the factory loading mode.
Prevents unauthorized profile loading by ensuring the factory loading mode is deactivated after devices leave the factory, enhancing security and compliance with intended usage.
Smart Images

Figure EP2025081816_04062026_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Title: Method and device for loading profiles in a factory for limited use
[0003] technical field
[0004] The invention relates to a mechanism that allows a manufacturer of devices connectable to a cellular communication network to load profiles onto the device in factory-loaded mode. This mechanism, known as In Factory Profile Provisioning (IFPP), is primarily used by device manufacturers to enable devices to connect to cellular communication networks via the loaded profiles. Furthermore, it also allows for factory testing of the connectivity features of the manufactured devices.
[0005] Previous technique
[0006] A device that connects to a cellular communication network, such as a mobile phone, traditionally includes a secure element used for authentication on the communication network(s), typically mobile telephony. Such secure elements include Universal Integrated Circuit Cards (UICCs), notably SIM cards (Subscriber Identity Modules), and their embedded version known as eUlCCs (embedded UICCs), also called eSIMs. An eUlCC module is a secure hardware element, generally small in size, that can be integrated into a host mobile terminal to implement the functions of a traditional SIM card.
[0007] eUlCCs can contain multiple subscriptions or profiles, each corresponding to a mobile network operator (or cellular network operator), referred to as "operator" hereafter. Each profile includes subscription data, such as an IMSI (International Mobile Subscriber Identity), cryptographic keys, and algorithms specific to a subscription provided by that operator. eUlCC cards offer greater flexibility in subscription management, particularly in the remote provisioning and management of profiles. eUlCC cards are reprogrammable, allowing multiple subscriber profiles (or communication profiles, or connection profiles) to be loaded, deleted, and updated over time on the same eUlCC card.Each subscriber profile is contained in a secure container (noted ISD-P for "Issuer Security Domain Profile" which can only contain one profile) which contains, like a classic SIM card, the data allowing, when the profile is active, to authenticate with a corresponding mobile telephony network to access a service (for example voice or data).
[0008] By changing the active subscriber profile in the eUlCC card, it is possible to change operators or modify access to associated services.
[0009] The specification "SGP.22 - RSP Technical Specification - Version 2.3 - 30 June 2021", hereinafter referred to as "SGP.22", describes, among other things, a technical solution for the remote provisioning and management of eUICCs in consumer devices. The procedures described are typically initiated by the device (including the eUICC).
[0010] The specification "SGP.02 - Remote Provisioning Architecture for Embedded UICC Technical Specification - Version 4.2 - 07 July 2022", hereinafter referred to as "SGP.02", describes a technical solution for the remote provisioning and management of eUlCCs embedded in M2M ("machine to machine") terminals. The procedures described are typically initiated by a pair of servers, within the framework of a technical solution for the remote provisioning and management of eUlCCs governed by SGP.02, referred to as SM-DP (for "Subscription Manager Data Preparation") and SM-SR (for "Subscription Manager Data Secure Routing"), and initiated by a single server, within the framework of a technical solution for the remote provisioning and management of eUlCCs governed by SGP.22, referred to as SM-DP+ (for "Subscription Manager Data Preparation enhanced").
[0011] Typical eUlCC management procedures as described in these specifications include, among others, profile loading and installation, profile activation, profile deactivation, and profile deletion. Profile loading described in these specifications can be performed using two distinct loading methods.
[0012] The first method, known as the standard loading method, is the profile loading method used by the device user when subscribing to or modifying a service with their operator. This standard loading method involves the generation of keys exchanged between the secure element and the server providing the profiles to secure the loading process, and is controlled by the device user.
[0013] A second loading method, known as factory loading, is a profile loading method used by the device manufacturer within the manufacturing plant. This loading method is based on pre-calculated keys and is controlled by the manufacturer. This method allows, for example, the loading of a temporary profile for testing purposes during manufacturing. It can also be used in the context of the Internet of Things (IoT). In this context, it is generally desired that devices be operational directly from the factory and therefore have a factory-loaded profile.
[0014] Once the device has left the factory—that is, once it has been sold to its end user, or, for example, deployed in the field—only the standard profile loading mode should be operational. The factory loading mode must be disabled. This deactivation is the responsibility of the device manufacturer.
[0015] Due to the increasing complexity of the manufacturing process, which is now often shared by a number of subcontractors—including manufacturers of the device's integrated components, the secure element, the modem, and the motherboard—it is sometimes difficult for the device manufacturer to ensure the factory reset is disabled. There is also always a risk of theft of a device from the factory before the factory reset is deactivated.
[0016] This poses a problem. Indeed, the persistence of an alternative profile loading mode to the standard loading mode after the device leaves the factory is a security vulnerability. This profile loading mode (i.e., the factory loading mode) could be exploited by malicious actors to load profiles designed to take control of the device from its legitimate user.
[0017] The invention presented aims to solve this problem.
[0018] Description of the invention
[0019] To this end, the invention proposes a mechanism for associating an authentication counter with a profile. An operator can set a maximum number of authentications linked to a loaded profile when factory loading mode is enabled. A value indicating this maximum number of authentications is included in the profile, typically in the profile's associated metadata. When this profile is loaded into a secure element of a device connectable to a cellular communication network, a corresponding counter is created by the secure element's operating system. This counter is initialized to the value contained in the profile. Then, during each authentication, if this authentication occurs while the profile's factory loading mode is enabled, the counter is, for example, decremented by one. When the counter value reaches, for example, zero, a countermeasure is triggered.This countermeasure can take different forms depending on the embodiment of the invention. This countermeasure can take the form of a simple information message to the operator, it can also include the deactivation of the corresponding profile or even the deactivation of the factory loading mode of the secure element.
[0020] According to a first aspect of the invention, a method is proposed for loading a profile into a secure element of a device connectable to a cellular communication network, comprising, via an operating system of the secure element, a step of receiving a connection profile; a step of installing the received connection profile; characterized in that the method further comprises:
[0021] - a step to determine a value indicating a maximum number of authentications present in the connection profile; and - a step to initialize an authentication counter based on the determined value.
[0022] According to another aspect of the invention, a method of communication is proposed between a device connectable to a cellular communication network and the cellular communication network comprising the connectable device
[0023] - a step of connecting to the cellular communication network based on a connection profile loaded onto a secure element of the connectable device; characterized in that, the connection profile includes a value indicating a maximum number of authentications, the method further comprising:
[0024] - a step of counting each authentication performed by the connectable device to the cellular communication network while a profile loading mode in factory load mode is active; and
[0025] - a step to trigger a countermeasure when the number of authentications counted reaches the value indicating a maximum number of authentications.
[0026] In one embodiment of the invention, the countermeasure includes sending a notification to a cellular communication network operator.
[0027] In one embodiment of the invention, the countermeasure includes sending a notification to a manufacturer of the connectable device and / or to a server in charge of preparing and distributing a profile and / or to a server responsible for remotely managing a profile state.
[0028] In one embodiment of the invention, the countermeasure includes disabling the connection profile.
[0029] In one embodiment of the invention, the countermeasure includes disabling the factory profile loading mode.
[0030] In one embodiment of the invention, the method further comprises:
[0031] - a step to reset the counting when reactivating the factory profile loading mode.
[0032] According to another aspect of the invention, a computer program is proposed, comprising instructions for implementing the method according to the invention, when this program is executed by a processor. According to another aspect of the invention, a non-transient, computer-readable recording medium is proposed on which a program for implementing the method according to the invention is recorded when this program is executed by a processor.
[0033] According to another aspect of the invention, a device connectable to a cellular communication network is proposed, comprising a secure element, the secure element comprising a processor configured to perform a step of receiving a connection profile; a step of installing the received connection profile; characterized in that the processor is further configured to perform:
[0034] - a step to determine a value indicating the maximum number of authentications present in the connection profile; and
[0035] - an initialization step for an authentication counter based on the determined value.
[0036] According to another aspect of the invention, a device connectable to a cellular communication network is proposed, comprising a processor configured to execute
[0037] - a step of connecting to the cellular communication network based on a connection profile loaded onto a secure element of the connectable device; characterized in that, the connection profile including a value indicating a maximum number of authentications, the processor is further configured to execute:
[0038] - a step of counting each authentication performed by the connectable device to the cellular communication network while a profile loading mode in factory load mode is active; and
[0039] - a step to trigger a countermeasure when the number of authentications counted reaches the value indicating a maximum number of authentications.
[0040] Brief description of the drawings. Other features, details, and advantages of the invention will become apparent upon reading the detailed description below. This description is purely illustrative and should be read in conjunction with the accompanying drawings, in which:
[0041] Figure 1a illustrates the profile loading architecture in one embodiment of the invention;
[0042] Figure 1b illustrates the profile loading architecture in another embodiment of the invention;
[0043] Figure 2 illustrates the main steps of a profile loading process according to one embodiment of the invention;
[0044] Figure 3 illustrates the main steps of an authentication process according to one embodiment of the invention;
[0045] Figure 4 illustrates the architecture of an information processing device for the implementation of one or more embodiments of the invention.
[0046] Detailed description
[0047] Figure 1a illustrates the architecture of the profile loading in the factory in one embodiment of the invention.
[0048] Connection profiles are generated by a 102 server called SM-DP+ (for Subscriber Management - Data Preparation enhanced) following a generation request sent by a 101 operator called an MNO (for Mobile Network Operator). The connection profiles are generated by the 102 server based on data files or data provided by the 101 operator as part of the generation request sent by the 101 operator.
[0049] The SM-DP+ 102 server is responsible for preparing (or generating) and distributing (or providing) profiles to devices connectable to a cellular communication network. This 102 server implements security measures and manages the encryption keys used to encrypt the profiles and transmit them to the devices for loading and installation into the device's integrated secure element.
[0050] Manufacturer 103 manages the production of devices 106 that can be connected to a cellular communication network. The SM-DP+ server 102 communicates with an administration server 104 operated by manufacturer 103 to manage a fleet of devices 106. Each device 106 includes a secure element 108, typically an eUlCC.
[0051] It should be noted that device 106 is an information processing device with a processor, memory, and input / output ports. As such, device 106 is controlled by an operating system, for example, Google's Android or
[0052] Apple's 105 (Android, Google, iOS, and Apple are registered trademarks) allows a set of applications to run on the device. Similarly, the secure element 108 is also an information processing device with its own processor and memory, operated by its own operating system that allows applications to run within the secure element. The operating system of device 106 should not be confused with the operating system of secure element 108.
[0053] Among the features of the operating system of device 106 is a module 107 for local assistance for profiles, or LPA for Local Profile Assistant in English.
[0054] When the manufacturer 103 wants to load connection profiles onto the devices
[0055] 106 is being manufactured; the administration server 104 sends its request to the SM-DP+ server 102. This request typically contains the identifiers of the devices 106 and the relevant secure elements 108.
[0056] The SM-DP+ 102 prepares the profiles and makes them available (i.e., provides, distributes, or provisions the profiles) upon request to the administration server 104. The LPA module 107 requests its intended profile from the administration server 104. In response, the LPA module 107 receives the profile from the administration server 104 and loads it into the secure element 108.
[0057] The profile is encrypted using keys, typically pre-calculated, by the SM-DP+ 102. These encryption keys are specific to each secured element, so as to ensure that only the secured element for which the profile was created can decrypt this profile.
[0058] Once loaded into the secure element 108, the profile can be decrypted and installed within the secure element. The profile is then ready to be activated and used to establish a connection between device 106 and the mobile network operated by operator 101.
[0059] This profile loading mode is referred to as the factory loading mode. It differs from the standard loading mode, among other things, by using pre-calculated keys for profile encryption. For it to be operational, secure element 108 must have its factory profile loading mode activated.
[0060] Figure 1b illustrates the profile loading architecture in another embodiment of the invention. Elements in the figure with common references and already described will not be described again for the sake of brevity. This loading method is more specifically dedicated to Internet of Things (IoT) devices. An IoT device is a device typically involved in machine-to-machine communication without human user intervention.
[0061] The process is similar to the process described in relation to Figure 1a, except for the use of an elM 105 server (optionally, the elM can also correspond to a module that is an integral part of a server), for eSIM loT remote Manager in English, in charge of managing the secure elements 108 deployed in the loT devices 106. The elM 105 is responsible for remote management operations of the state of profiles (e.g., activation, deactivation, deletion, ...) on a single loT device or a fleet of loT devices.The consumer device's LPA 107 agent is replaced by a LoT profile agent 109, IPA (for LoT Profile Assistant), which has the same functionality for installing profiles in the secure element integrated into the LoT device 106 and is also responsible for managing profile states or relaying profile state management instructions (or operations) from the elM server 105 (e.g., activation, deactivation, deletion, etc.). Communication between the elM server 105 and the IPA 109 agent is standardized by the GSMA document SGP.32 "eSIM LoT Technical Specification, Version 1.0.1, 04 July 2023".
[0062] Figure 2 illustrates the main steps of a profile installation process according to an embodiment of the invention. The process in Figure 2 is carried out by the operating system of the secure element. During a reception step 201, by the secure element, of the profile to be installed, transmitted by the LPA 107 module or the IPA 109 module, the profile is decrypted in the usual way.
[0063] During a verification step 202, it is checked whether the profile includes a value indicating a maximum number of authentications associated with that profile. In one embodiment, this verification may correspond to detecting the presence of said value indicating a maximum number of authentications within a dataset belonging to the received profile, and named metadata. Furthermore, countermeasures data associated with said value indicating the maximum number of authentications associated with the received profile may also be included in said metadata dataset belonging to the received profile.
[0064] When the profile includes a value indicating a maximum number of authentications, corresponding to branch O of step 202, a corresponding authentication counter is initialized during a counter initialization step 203 associated with the profile. In the preferred embodiment, the authentication counter is initialized to this maximum value and then decremented until it reaches zero. Alternatively, the authentication counter is initialized to zero and then incremented until it reaches the specified maximum value.
[0065] When the profile does not include a value indicating a maximum number of authentications, corresponding to branch N of step 202, or after the initialization of the authentication counter during step 203, the profile is installed within the secure element in the usual way during a profile installation step 204.
[0066] Figure 3 illustrates the main steps of a communication process between a device connectable to a cellular communication network comprising authentication steps according to an embodiment of the invention.
[0067] During a 301 step, an authentication step occurs. Authentication is required at least when the device connects to a cellular network. It may also be required at other stages while the device is connected to the cellular network. The frequency and events that trigger an authentication step are determined by the cellular network operator when defining its security policy.
[0068] During a 302 verification step, the secure element checks whether the profile factory load mode is active. Typically, the operating system maintains a flag indicating whether the profile factory load mode is active or not. Alternatively, it is possible to execute a function specific to this active load mode that returns a specific error code when the profile factory load mode is inactive.
[0069] If the factory profile loading mode is inactive, corresponding to branch N of step 302, the process continues, typically by continuing the connection during a step 307 of connection to the cellular communication network.
[0070] If the factory profile loading mode is active, corresponding to branch O of step 302, during a verification step 303, it is checked whether the current active profile is associated with an authentication counter. If not, corresponding to branch N of step 303, the process continues, typically by continuing the connection during step 307.
[0071] If an authentication counter is associated with the current active profile, corresponding to branch O of step 303, then during a counter decrement step 304, the authentication counter is decremented. This is because the goal is to count the authentications related to the current active profile that occur while the profile factory load mode is active. Once these two conditions are met, the authentication counter decrement step 304 is executed. Note that if the authentication counter is incremental rather than decremental, then this step increments the authentication counter.
[0072] During step 305 of the authentication counter's current value verification, the counter's current value is compared to a limit value. This limit value is zero in the case of a decremental counter, and the maximum value indicated in the profile in the case of an incremental counter.
[0073] As long as the counter value has not reached the limit value, corresponding to branch N of step 305, nothing special happens and the process continues, typically by continuing the connection during step 307. When the counter value has reached the limit value, corresponding to branch O of step 305, a countermeasure is triggered during a countermeasure triggering step 306.
[0074] The countermeasure triggered during step 306 depends on the embodiments of the invention.
[0075] In one embodiment, the countermeasure consists of sending a warning notification to the operator. In practice, the warning notification is sent by the secure element's operating system to a server of the MNO operator 101, which is responsible for processing warning notifications. In one embodiment, the warning notification is sent to the SM-DP+ server 102. In another embodiment, the warning notification received by the SM-DP+ server 102 is forwarded to the MNO operator 101. When the devices 106 are IoT devices, a warning notification can also be sent to the elM server 105. Thus, the MNO operator 101, the SM-DP+ server 102, and the elM server 105 can all be notified when this limit is reached.In a particular embodiment, the manufacturer 103 is notified of the reaching of this limit by sending the warning notification to the administration server 104.
[0076] In another embodiment, the associated profile is deactivated. Any new activation request for this profile is also rejected. Thus, it is no longer possible to use this profile to connect to the operator's cellular communication network.
[0077] In another embodiment, the factory profile loading mode is disabled. Therefore, in this embodiment, it is no longer possible to load profiles onto the device using the factory loading mode.
[0078] Disabling the factory profile loading mode is typically permanent. Once the device leaves the factory, it can no longer activate this loading mode. However, in some embodiments, reactivating the factory profile loading mode may be permitted. This might be the case, for example, when the device is returned to the manufacturer for repair. As part of this repair process, it may be useful for the manufacturer to be able to reactivate the factory profile loading mode to test the device after repair or for diagnostic purposes.
[0079] In one embodiment, when the profile factory load mode is reactivated, if the active profile is associated with an authentication counter, the count of completed authentications resumes from the current value of the authentication counter associated with the profile. In this mode, the maximum number of authentications specified in the profile is valid for all activations of the profile factory load mode. Alternatively, when the profile factory load mode is reactivated, the current counters associated with the profiles loaded into the secure element are reset. In this mode, the maximum number of authentications specified in the profile is valid for a single activation of the profile factory load mode. Reactivating this mode will again allow this maximum number of authentications.
[0080] These different countermeasures can be freely combined. It is thus possible to send a warning notification to the operator, for example to a server, to the MNO 101 operator, in charge of processing warning notifications, and / or to the server in charge of preparing and distributing profiles (for example, the SM-DP+ 102 server) and / or to the server responsible for remote management of profile states (for example, the elM 105 server) and / or to the manufacturer and to deactivate the associated profile for example.
[0081] It should be noted that the operator defines the security policy and therefore the frequency and events that trigger authentication. The operator also defines the profiles and thus the value indicating a maximum number of authentications. This value can therefore be adjusted to the authentication frequency required by the operator.
[0082] In some embodiments, two maximum values are associated with the profile. A maximum warning value and a maximum limit value are then included in and associated with the profile. Typically, the maximum limit value is higher than the maximum warning value. When the counter reaches the maximum warning value, a warning notification is sent to the operator, for example, to a server, the MNO 101 operator responsible for processing warning notifications, and / or to the server responsible for preparing and distributing profiles (for example, the SM-DP+ 102 server), and / or to the server responsible for remotely managing profile states (for example, the elM 105 server), and / or to the manufacturer. When the maximum limit value is reached, the profile and / or the profile factory loading mode are deactivated.
[0083] This allows an operator to monitor the use of a profile prepared for factory loading and prevent its use outside of its intended scope. It also allows for notification when the factory profile loading mode is not deactivated when it should be.
[0084] Figure 4 is a schematic block diagram of an information processing device 400 for implementing one or more embodiments of the invention. The information processing device 400 may be a peripheral device such as a microcomputer, a workstation, or a mobile telecommunications terminal. The device 400 includes a communication bus connected to:
[0085] - a central processing unit 401, such as a microprocessor, denoted CPU;
[0086] - a 402 random access memory, noted as RAM, to store the executable code of the process of implementing the invention as well as registers adapted to record variables and parameters necessary for the implementation of the process according to embodiments of the invention; the memory capacity of the device can be supplemented by an optional RAM memory connected to an expansion port, for example;
[0087] - a read-only memory 403, denoted ROM, for storing computer programs for the implementation of embodiments of the invention;
[0088] - a network interface 404, denoted NET, normally connected to a communication network on which digital data to be processed is transmitted or received. The network interface 404 can be a single network interface, or composed of a set of different network interfaces (for example, wired and wireless, or different types of wired or wireless interfaces). Data packets are sent over the network interface for transmission or are read from the network interface for reception under the control of the software application running in the processor 401;
[0089] - a 405 user interface, denoted GUI, to receive input from a user or to display information to a user;
[0090] - a storage device 406 as described in the invention and denoted HD;
[0091] - an input / output module 407, labeled I / O, for receiving / sending data from / to external devices such as hard drives, removable storage media or others.
[0092] The executable code can be stored in read-only memory 403, on the storage device 406, or on removable digital media such as a disk. In one variant, the executable code of programs can be received via a communication network, through the network interface 404, in order to be stored in one of the storage means of the communication device 400, such as the storage device 406, before being executed.
[0093] The central processing unit 401 is adapted to command and direct the execution of instructions or portions of software code of the program or programs according to one of the embodiments of the invention, instructions which are stored in one of the aforementioned storage means. After power-up, the CPU 401 is capable of executing instructions from the main RAM 402, relating to a software application. Such software, when executed by the processor 401, triggers the execution of the processes described.
[0094] In this embodiment, the device is a programmable device that uses software to implement the invention. However, alternatively, the present invention can be implemented in hardware (for example, in the form of an application-specific integrated circuit, or ASIC).
[0095] Naturally, to satisfy specific needs, a person competent in the field of the invention may make modifications to the preceding description. Although the present invention has been described above with reference to specific embodiments, the present invention is not limited to those specific embodiments, and modifications that fall within the scope of the present invention will be obvious to a person versed in the art.
Claims
Demands 1. Method for loading a profile into a secure element of a device connectable to a cellular communication network, including an operating system of the secure element: - a step of receiving a connection profile; - a step for installing the received connection profile; characterized in that the process further comprises: - a step to determine a value indicating the maximum number of authentications present in the connection profile; and - an initialization step for an authentication counter based on the determined value.
2. A method for communication between a device connectable to a cellular communication network and the cellular communication network, comprising, by the connectable device: - a step of connecting to the cellular communication network based on a connection profile loaded onto a secure element of the connectable device; characterized in that, the connection profile includes a value indicating a maximum number of authentications, the method further comprising: - a step of counting each authentication performed by the connectable device to the cellular communication network while a profile loading mode in factory load mode is active; and - a step to trigger a countermeasure when the number of authentications counted reaches the value indicating a maximum number of authentications.
3. Method according to claim 2, characterized in that the countermeasure comprises sending a notification to a cellular communication network operator.
4. A method according to claim 2 or 3, characterized in that the countermeasure comprises sending a notification to a manufacturer of the connectable device and / or to a server responsible for preparation and distribution of a profile and / or to a server responsible for remote management operations of a profile state.
5. A method according to any one of claims 2 to 4, characterized in that the countermeasure comprises the deactivation of the connection profile.
6. A method according to any one of claims 2 to 5, characterized in that the countermeasure comprises deactivating the profile factory loading mode.
7. A method according to any one of claims 2 to 6, characterized in that it further comprises: - a step to reset the counting when reactivating the factory profile loading mode.
8. Product computer program comprising instructions for implementing the process according to any one of claims 1 to 7, when this program is executed by a processor.
9. Non-transient computer-readable recording medium on which a program is recorded for the implementation of the method according to any one of claims 1 to 7 when this program is executed by a processor.
10. A device connectable to a cellular communication network comprising a secure element, the secure element comprising a processor configured to execute: - a step of receiving a connection profile; - an installation step for the received connection profile; characterized in that the processor is further configured to execute: - a step to determine a value indicating the maximum number of authentications present in the connection profile; and - an initialization step for an authentication counter based on the determined value.
11. Device connectable to a cellular communication network comprising a processor configured to execute: - a step of connecting to the cellular communication network based on a connection profile loaded onto a secure element of the connectable device; characterized in that the connection profile includes a value indicating a maximum number of authentications; the processor is further configured to execute: - a step of counting each authentication performed by the connectable device to the cellular communication network while a profile loading mode in factory load mode is active; and - a step to trigger a countermeasure when the number of authentications counted reaches the value indicating a maximum number of authentications.