Subscription management comprising subscription-specific profiles for restricting the functionalities of the security element

US11003797B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11003797-B2
Application numberUS-201615739509-A
CountryUS
Kind codeB2
Filing dateJun 22, 2016
Priority dateJun 23, 2015
Publication dateMay 11, 2021
Grant dateMay 11, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method and a system for subscription management in a security element for a mobile end device, wherein one subscription profile is associated with one subscription. For a subscription profile, an access to functionalities of the security element is subscription-profile-specifically restricted.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for subscription management in a security element for a mobile end device, the method comprising: initializing the secure element with a standard initialization, the standard initialization allowing access to functionalities of the secure element to a plurality of subscriptions that can be loaded into the secure element, wherein access to the functionalities of the secure element varies among the plurality of subscriptions, wherein the standard initialization allows access to the functionalities of the secure element to a first subscription of the plurality of subscriptions while also allowing access to the functionalities of the secure element to a second subscription of the plurality of subscriptions that is loaded later onto the security element than the standard initialization, assigning a subscription profile to a subscription of the plurality of subscriptions in the security element, providing access of the subscription profile to functionalities of the security element in a manner that is specific to the subscription profile, the subscription profile defining conditions of use of a mobile radio network assigned to the subscription by means of the secure element and the mobile end device, and providing access of an application executable in the security element and associated with the subscription profile to the functionalities of the security element in the manner that is specific to the subscription profile, wherein information about which functionalities of the security element are accessible for the subscription profile are included in the subscription profile itself, and where the subscription profile with the information about the accessible functionalities is loaded into the secure element. 2. The method according to claim 1 , wherein the functionalities of the security element are supplied by programming interfaces of the security element. 3. The method according to claim 1 , wherein for a pre-specified subscription profile, metadata for specifying the subscription profile are generated which designate those functionalities of the security element which the subscription profile can access; wherein the functionalities of the security element are supplied by programming interfaces of the security element. 4. The method according to claim 1 , wherein for a pre-specified subscription profile, metadata for specifying the subscription profile are generated which designate those functionalities of the security element which the subscription profile cannot access; wherein the functionalities of the security element are supplied by programming interfaces of the security element. 5. The method according to claim 3 , wherein the metadata are generated before the loading of the subscription profile into the security element or that the metadata are generated or are changed after the subscription profile has been already loaded into the security element. 6. The method according to claim 1 , wherein a manufacturer or issuer of the security element subscription-specifically restricts the access of a subscription profile to functionalities of the security element. 7. A hardware security element for a mobile end device, the hardware security element comprising: a storage configured to store at least one subscription profile that is assigned to a subscription of a plurality of subscriptions associated with the security element, the hardware security element being initialized with a standard initialization, the standard initialization allowing access to functionalities of the secure element to the plurality of subscriptions that can be loaded into the storage of hardware security element, wherein access to the functionalities of the hardware security element varies among the plurality of subscriptions, wherein the standard initialization allows access to the functionalities of the secure element to a first subscription of the plurality of subscriptions while also allowing access to the functionalities of the secure element to a second subscription of the plurality of subscriptions that is loaded later onto the security element than the standard initialization, the hardware security element configured to: provide access of the subscription profile to functionalities of the security element in a manner that is specific to the subscription profile, the subscription profile defining conditions of use of a mobile radio network assigned to the subscription by means of the hardware security element and the mobile end device, and provide access of an application executable in the security element and associated with the subscription profile to the functionalities of the security element in the manner that is specific to the subscription profile, wherein information about which functionalities of the security element are accessible for the subscription profile are included in the subscription profile itself, wherein an access of the subscription profile to functionalities of the security element is subscription-profile-specifically restricted, and where the subscription profile with the information about the accessible functionalities is loaded into the hardware security element. 8. The security element according to claim 7 , wherein in the storage of the security element additional metadata are stored for the subscription profile stored in the security element, which designate those functionalities or those programming interfaces of the security element which the subscription profile can access and/or which designate those functionalities or those programming interfaces of the security element which the subscription profile cannot access. 9. A mobile end device having a security element according to claim 7 . 10. A system, comprising: a subscription management device and at least one security element for a mobile end device, the security element being initialized with a standard initialization, the standard initialization allowing access to functionalities of the secure element to the plurality of subscriptions that can be loaded into the storage of hardware security element, wherein access to the functionalities of the security element varies among the plurality of subscriptions, wherein the standard initialization allows access to the functionalities of the secure element to a first subscription of the plurality of subscriptions while also allowing access to the functionalities of the secure element to a second subscription of the plurality of subscriptions that is loaded later onto the security element than the standard initialization, wherein a subscription profile is assigned to a subscription of the plurality of subscriptions within the security element, the subscription profile defining conditions of use of a mobile radio network assigned to the subscription by means of the security element and the mobile end device, wherein the subscription management device is configured to specify the subscription profile in such a way that access of the subscription profile and of an application executable in the security element and associated with the subscription profile to functionalities of the security element are limited in a manner that is specific to the subscription profile, wherein information about which functionalities of the security element are accessible for the subscription profile are included in the subscription profile itself, and where the subscription profile with the information about the accessible functionalities is loaded into the secure element. 11. The system according to claim 10 , wherein the subscription management device is devised to generate metadata for a pre-specified subscription profile which designate those functionalities or those pro

Assignees

Inventors

Classifications

  • Processing at user equipment or user record carrier · CPC title

  • G06F21/629Primary

    to features or functions of an application · CPC title

  • Subscription-based services using application servers or record carriers, e.g. SIM application toolkits · CPC title

  • Access rights, e.g. capability lists, access control lists, access tables, access matrices · CPC title

  • Access security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11003797B2 cover?
A method and a system for subscription management in a security element for a mobile end device, wherein one subscription profile is associated with one subscription. For a subscription profile, an access to functionalities of the security element is subscription-profile-specifically restricted.
Who is the assignee on this patent?
Giesecke & Devrient Mobile Security Gmbh
What technology area does this patent fall under?
Primary CPC classification G06F21/629. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue May 11 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 11 related publications on this page (citations in our corpus or others sharing the same primary CPC).