Subscriber identity module which has multiple profiles and which is designed for an authentication command

US11202201B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11202201-B2
Application numberUS-201615779256-A
CountryUS
Kind codeB2
Filing dateNov 30, 2016
Priority dateDec 1, 2015
Publication dateDec 14, 2021
Grant dateDec 14, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A subscriber identity module (eUICC), comprises profiles for the utilization of a mobile terminal that include at least a first profile and at least a second profile, of which the second profile (Pr 1 , Pr 2 ) is devised as an active profile. The first profile is designed as a root profile (PrR) which in a normal state of the subscriber identity module is in an inactive state, and which is devised to be activated in response to an authentication command (AUTHENTICATE) received at the subscriber identity module. The authentication command is specially parameterized for the root profile (PrR) with a specific root value of the network parameter (P 2 ) to be activated during a change-over period. The initially active second profile (Pr 1 , Pr 2 ) is deactivated during the change-over period. After the end of the change-over period, the first profile (PrR) is again deactivated and the second profile (Pr 1 , Pr 2 ) is again activated.

First claim

Opening claim text (preview).

The invention claimed is: 1. A subscriber identity module (eUICC), comprising profiles, stored in a non-transitory memory, for the utilization of a mobile terminal in mobile communication networks, wherein the profiles comprise at least a first profile and at least a second profile, of which the second profile (Pr 1 , Pr 2 ) is devised as an active profile, the subscriber identity module devised to receive and to process an authentication command (AUTHENTICATE) parameterized with a network parameter (P 2 ), and as a result of this to compute authentication data for a mobile communication network determined by a network value of the network parameter (P 2 ), wherein the first profile is designed as a root profile (PrR) which in a normal state of the subscriber identity module is in an inactive state, and which is devised to be activated for a duration of processing of an authentication command (AUTHENTICATE) received at the subscriber identity module, said authentication command being specially parameterized for the root profile (PrR) with a predefined specific root value of the network parameter (P 2 ) to be activated during a change-over period, wherein the initially active second profile (PR 1 , Pr 2 ) is deactivated during the change-over period, and wherein after the end of the change-over period, the first profile (PrR) is automatically deactivated and the second profile (Pr 1 , Pr 2 ) is automatically activated; wherein the change-over period is limited in time to the duration of the processing of the authentication command. 2. The subscriber identity module according to claim 1 , wherein as a value of the network parameter (P 2 ) there is provided: P 2 =P 3 G as a network value for network 3G, P 2 =P 2 G as a network value for network 2G, a value P 2 =PR different from P 2 =P 3 G and P 2 =P 2 G possibly further network values and preferably different from further pre-allocated values as a root value for the transient activation of the root profile. 3. The subscriber identity module according to claim 1 , wherein an application protocol data unit (APDU) command is provided as an authentication command. 4. The subscriber identity module according to claim 1 , wherein as first profile a profile of an owner of the subscriber identity module is provided, and as second profile a profile of an owner of the subscriber identity module is provided, in particular of a network provider. 5. The subscriber identity module according to claim 1 , wherein as first profile one of the following is provided: an emergency profile for outputting an emergency call in an emergency situation in an emergency call network; a test profile for carrying out an end-device test on a test network; a service profile for calling a service network of a service provider. 6. The subscriber identity module according to claim 1 , wherein the profile (P) comprises respectively an authentication key (Ki), and wherein the authentication command (AUTHENTICATE) is devised for computing, originating from the authentication key (Ki- 1 , Ki- 2 , Ki-R) of the currently active profile (Pr 1 , Pr 2 , PrR), the authentication data. 7. The subscriber identity module according to claim 1 , wherein the profile (Pr 1 , Pr 2 , PrR) comprises respectively an Issuer Security Domain (ISD-P 1 , ISD-P 2 , ISD-R). 8. The subscriber identity module according to claim 1 , which further comprises an Issuer Security Domain Root (ISD-R) which is devised in particular as an end point situated in the subscriber identity module of the channel provided for provisioning the subscriber identity module between the Sub Man Secure Router (SM-SR) and the subscriber identity module and wherein the first profile has an Issuer Security Domain (ISD-R), which is identical to the Issuer Security Domain Root (ISD-R). 9. A subscriber identity module (eUICC), comprising profiles, stored in a non-transitory memory, for the utilization of a mobile terminal in mobile communication networks, wherein the profiles comprise at least a first profile and at least a second profile, of which the second profile (Pr 1 , Pr 2 ) is devised as an active profile, the subscriber identity module devised to receive and to process an authentication command (AUTHENTICATE) parameterized with a network parameter (P 2 ), and as a result of this to compute authentication data for a mobile communication network determined by a network value of the network parameter (P 2 ), wherein the first profile is designed as a root profile (PrR) which in a normal state of the subscriber identity module is in an inactive state, and which is devised to be activated in response to an authentication command (AUTHENTICATE) received at the subscriber identity module said authentication command being specially parameterized for the root profile (PrR) with a predefined specific root value of the network parameter (P 2 ) to be activated during a change-over period, wherein the initially active second profile (Pr 1 , Pr 2 ) is deactivated during the change-over period, and wherein after the end of the change-over period, the first profile (PrR) is again deactivated and the second profile (Pr 1 , Pr 2 ) is again activated. 10. The subscriber identity module according to claim 9 , wherein as a value of the network parameter (P 2 ) there is provided: P 2 =P 3 G as a network value for network 3G, P 2 =P 2 G as a network value for network 2G, a value P 2 =PR different from P 2 =P 3 G and P 2 =P 2 G possibly further network values and preferably different from further pre-allocated values as a root value for the transient activation of the root profile. 11. The subscriber identity module according to claim 9 , wherein an application protocol data unit (APDU) command is provided as an authentication command. 12. The subscriber identity module according to claim 9 , wherein as first profile a profile of an owner of the subscriber identity module is provided, and as second profile a profile of an owner of the subscriber identity module is provided, in particular of a network provider. 13. The subscriber identity module according to claim 9 , wherein as first profile one of the following is provided: an emergency profile for outputting an emergency call in an emergency situation in an emergency call network; a test profile for carrying out an end-device test on a test network; a service profile for calling a service network of a service provider. 14. The subscriber identity module according to claim 9 , wherein the profile (P) comprises respectively an authentication key (Ki), and wherein the authentication command (AUTHENTICATE) is devised for computing, originating from the authentication key (Ki- 1 , Ki- 2 , Ki-R) of the currently active profile (Pr 1 , Pr 2 , PrR), the authentication data. 15. The subscriber identity module according to claim 9 , wherein the profile (Pr 1 , Pr 2 , PrR) comprises respectively an Issuer Security Domain (ISD-P 1 , ISD-P 2 , ISD-R). 16. The subscriber identity module according to claim 9 , which further comprises an Issuer Security Domain Root (ISD-R) which is devised in particular as an end point situated in the subscriber identity module of the channel provided for provisioning the subscriber identity module between the Sub Man Secure Router (SM-SR) and the subscriber identity module and wherein the first profile has an Issuer Security Domain (ISD-R), which is identical to the Issuer Security Domain Root (ISD-R). 17. The subscriber identity module according to claim 9 , wherein the deactivation of the first profile (PrR) and activation of the second profile (Pr 1 , Pr 2 ) are autom

Assignees

Inventors

Classifications

  • H04W12/06Primary

    Authentication · CPC title

  • Services for handling of emergency or hazardous situations, e.g. earthquake and tsunami warning systems [ETWS] · CPC title

  • Terminal profiles · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

  • Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11202201B2 cover?
A subscriber identity module (eUICC), comprises profiles for the utilization of a mobile terminal that include at least a first profile and at least a second profile, of which the second profile (Pr 1 , Pr 2 ) is devised as an active profile. The first profile is designed as a root profile (PrR) which in a normal state of the subscriber identity module is in an inactive state, and which is devi…
Who is the assignee on this patent?
Giesecke & Devrient Mobile Security Gmbh
What technology area does this patent fall under?
Primary CPC classification H04W12/06. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 14 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).