Method for managing embedded UICC and embedded UICC, MNO system, provision method, and method for changing MNO using same

US9521547B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9521547-B2
Application numberUS-201214342980-A
CountryUS
Kind codeB2
Filing dateSep 4, 2012
Priority dateSep 5, 2011
Publication dateDec 13, 2016
Grant dateDec 13, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The present invention relates to profile access credentials used for encoding profiles in a system comprising an mobile network operator (MNO), a subscription manager (SM), an embedded UICC (eUICC) and the like, that is, a method for storing/managing an eUICC publication key and a corresponding secret or the like inside the eUICC. In addition, the invention also provides a method for transmitting information on profile access credentials inside the eUICC to external entities for encoding and the like.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method of managing key information of an embedded universal integrated circuit card (eUICC), performed in the eUICC interworking with external entities including a mobile network operator (MNO) system and a subscription manager (SM) system, the method comprising: the eUICC performing a procedure of checking status and capability with at least one of the external entities; the eUICC providing information about its status and capability during the procedure of checking status and capability, wherein the information about its status and capability is key information including information about at least one of a key generation algorithm, a key length, and a key generation manner, wherein the MNO is separate from the SM system, wherein the SM includes a subscription manager-data preparation (SM-DP) and a subscription manager-secure routing (SM-SR), the SM-DP encrypts the profile by using the public key of the eUICC, and the SM-SR encrypts the profile which is encrypted using the public key by using a separate management key so that the encrypted profile becomes a double ciphered profile, and wherein the MNO separately communicates with the SM-SR and SM-DP via separate channels. 2. The method of claim 1 , wherein the eUICC further includes profile access credentials for decrypting an encrypted profile received from at least one of the external entities, and the profile access credentials are a public key of the eUICC or a private key corresponding to the public key. 3. The method of claim 2 , wherein the eUICC public key is generated in a manufacturing step of the eUICC, and stored in the eUICC. 4. The method of claim 2 , wherein the eUICC public key is generated by the eUICC according to a request of the MNO system or the SM. 5. The method of claim 2 , wherein the profile transmitted from the MNO system or the SM is a double ciphered profile, and the eUICC decrypts the encrypted profile by using a separate management key and decrypts the profile which is decrypted using the separate management key by using the public key of the eUICC. 6. The method of claim 2 , wherein the key information is stored in the eUICC in a form of a profile. 7. The method of claim 6 , wherein the key information is stored in the eUICC in at least one form among an elementary file (EF) form, a file structure form of tag, length, value (TLV), and an applet form. 8. A method of provisioning, performed in an embedded universal integrated circuit card (eUICC) system including a mobile network operator (MNO) system, a subscription manager (SM), and a eUICC interworking with the MNO system and the SM, the method comprising: receiving, by the MNO system, PKI key information about a eUICC public key which can encrypt a profile from the eUICC; encrypting, by the MNO system or the SM, the profile using the eUICC public key primarily; and transmitting, by the MNO system, the encrypted profile to the eUICC, wherein the SM is separate from the MNO system, wherein the SM includes a subscription manager-data preparation (SM-DP) and a subscription manager-secure routing (SM-SR), the SM-DP encrypts the profile by using the public key of the eUICC, and the SM-SR encrypts the profile which is encrypted using the public key by using a separate management key so that the encrypted profile becomes a double ciphered profile, and wherein the MNO separately communicates with the SM-SR and SM-DP via separate channels. 9. The method of claim 8 , wherein the PKI key information includes information about at least one of a public key generation algorithm, a key length, and a key generation manner. 10. A method of changing MNO, performed in an embedded universal integrated circuit card (eUICC) system including a mobile network operator (MNO) system, a subscription manager (SM), and a eUICC interworking with the MNO system and the SM, the method comprising: receiving, by a receiving MNO system, PKI key information about a eUICC public key which can encrypt a profile from the eUICC; encrypting, by the receiving MNO system or the SM, the profile using the eUICC public key primarily; notifying, by the receiving MNO system, a fact that an MNO is changed, to a donor MNO system, and being certificated, the donor MNO system being a previous system of the eUICC prior to a current MNO; requesting, by the receiving MNO system, a second encryption to the SM by transmitting the primarily encrypted profile to the SM, and receiving a secondarily encrypted profile from the SM in response to the request; and transmitting, by the receiving MNO system, the secondarily encrypted profile to the eUICC, wherein the SM includes a subscription manager-data preparation (SM-DP) and a subscription manager-secure routing (SM-SR), the SM-DP encrypts the profile by using the public key of the eUICC, and the SM-SR encrypts the profile which is encrypted using the public key by using a separate management key so that the encrypted profile becomes a double ciphered profile, wherein the MNO separately communicates with the SM-SR and SM-DP via separate channels. 11. The method of claim 10 , wherein the PKI key information includes information about at least one of a public key generation algorithm, a key length, and a key generation manner. 12. An embedded universal integrated circuit card (eUICC) interworking with external entities including a mobile network operator (MNO) system and a subscription manager (SM) system, wherein the eUICC includes profile access credentials which can decrypt a profile transmitted from one of the external entities, and the eUICC provides key information which is information about its status and capability, and the key information includes information about at least one of a key generation algorithm, a key length, and a key generation manner, wherein the SM system is separate from the MNO system, wherein the SM includes a subscription manager-data preparation (SM-DP) and a subscription manager-secure routing (SM-SR), the SM-DP encrypts the profile by using the public key of the eUICC, and the SM-SR encrypts the profile which is encrypted using the public key by using a separate management key so that the encrypted profile becomes a double ciphered profile, and wherein the MNO separately communicates with the SM-SR and SM-DP via separate channels. 13. The eUICC of claim 12 , wherein the profile access credentials are a public key of the eUICC or a private key corresponding to the public key.

Assignees

Inventors

Classifications

  • H04W12/04Primary

    Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title

  • Transfer to or from user equipment or user record carrier · CPC title

  • Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data · CPC title

  • Protecting application or service provisioning, e.g. securing SIM application provisioning · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9521547B2 cover?
The present invention relates to profile access credentials used for encoding profiles in a system comprising an mobile network operator (MNO), a subscription manager (SM), an embedded UICC (eUICC) and the like, that is, a method for storing/managing an eUICC publication key and a corresponding secret or the like inside the eUICC. In addition, the invention also provides a method for transmitti…
Who is the assignee on this patent?
Park Jaemin, Lee Jinhyoung, Kt Corp
What technology area does this patent fall under?
Primary CPC classification H04W12/04. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 13 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).