System and method for securely using multiple subscriber profiles with a security component and a mobile telecommunications device

US9647984B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9647984-B2
Application numberUS-201113814067-A
CountryUS
Kind codeB2
Filing dateAug 4, 2011
Priority dateAug 5, 2010
Publication dateMay 9, 2017
Grant dateMay 9, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

System and method for allowing a mobile telecom device to use multiple profiles. The system and method includes operating a security function to perform a cryptographic operation on a profile using a cryptography key of the security function thereby producing a cryptographically protected profile, storing the cryptographically protected profile, and activating the cryptographically protected profile by operating the security function to verify that the cryptographically protected profile has been cryptographically protected using the cryptography key of the security function, and upon verifying that the cryptographically protected profile has been protected using the cryptography key of the security function, activating the cryptographically protected profile.

First claim

Opening claim text (preview).

We claim: 1. A method for allowing a user of a mobile telecom device to use multiple subscriber profiles, comprising: (a) operating a security function to perform, by a portable security device, a cryptographic operation on one subscriber profile stored in a tamper-resistant element cooperating with said mobile telecom device, by using a cryptography key of said security function thereby producing a cryptographically protected subscriber profile, wherein said one subscriber profile is associated with one particular network; and (b) exporting said cryptographically protected subscriber profile outside said tamper-resistant element; (c) importing said cryptographically protected subscriber profile into said tamper-resistant element; (d) when importing said cryptographically protected subscriber profile into said tamper-resistant element, operating said security function to verify that said cryptographically protected subscriber profile has been cryptographically protected for said tamper-resistant element; (e) verifying that the cryptographically protected subscriber profile has been cryptographically protected for said tamper-resistant element; and (f) upon verifying that the cryptographically protected subscriber profile has been cryptographically protected for said tamper-resistant element, activating said cryptographically protected subscriber profile in said tamper-resistant element, in order that only a subscriber profile that has been encrypted or cryptographically signed for said tamper-resistant element is activated in said tamper-resistant element. 2. The method of claim 1 , wherein said portable security device is a universal integrated circuit card (“UICC”). 3. The method of claim 1 , wherein said security function is performed by a secure zone of said mobile telecom device. 4. The method of claim 1 , wherein a subscriber profile includes the full set of data associating a particular subscriber to an operator. 5. The method of claim 1 , wherein a profile comprises the specific applications or OS modifications specific to an operator. 6. The method of claim 1 , wherein step (b) comprises exporting the cryptographically protected subscriber profile to a storage device selected from the set including a portable security device, said mobile telecom device, a server connected to said mobile telecom device, and a server located on a network accessible by said telecom device. 7. The method of claim 6 , further comprising retrieving said cryptographically protected subscriber profile from said storage device. 8. The method of claim 1 , wherein step (a) comprises encrypting said subscriber profile using a secret key of said security function. 9. The method of claim 1 , wherein step (a) comprises digitally signing said subscriber profile using a secret key of said security function. 10. The method of claim 1 , wherein step (d) deactivating a currently active subscriber profile. 11. The method of claim 1 , further comprising determining a location of said mobile telecom device, wherein step (a) comprises using the location of said mobile telecom device to determine which cryptographically protected subscriber profile to activate and to automatically activate a cryptographically protected subscriber profile upon a change in location dictating use of a different cryptographically protected subscriber profile. 12. A portable security device comprising: a memory; and a processor, wherein the processor of said portable security device is configured to execute the following method steps: operate a security function to perform a cryptographic operation on a subscriber profile stored in a tamper-resistant element cooperating with a mobile telecom device, by using a cryptography key of said security function, thereby producing a cryptographically protected subscriber profile, wherein said subscriber profile is associated with one particular network; export said cryptographically protected subscriber profile from said tamper-resistant element; and when importing said cryptographically protected subscriber profile into said tamper-resistant element, operate said security function to verify that said cryptographically protected subscriber profile has been cryptographically protected for said tamper-resistant element, and upon verifying that said cryptographically protected subscriber profile has been cryptographically protected for said temper-resistant element, activate the cryptographically protected subscriber profile in said tamper-resistant element, in order that only a subscriber profile has been encrypted or cryptographically signed for said tamper-resistant element is activated in said tamper-resistant element. 13. A non-transitory computer readable medium of a portable security device having stored thereon instructions to cause a processor of said portable security device to execute the following method steps: operate a security function to perform a cryptographic operation on a subscriber profile stored in a tamper-resistant element cooperating with a mobile telecom device, by using a cryptography key of said security function thereby producing a cryptographically protected subscriber profile, wherein said subscriber profile is associated with one particular network; export said cryptographically protected subscriber profile from said tamper-resistant element; and when importing said cryptographically protected subscriber profile into said tamper-resistant element, operate said security function to verify that said cryptographically protected subscriber profile has been cryptographically protected for said tamper-resistant element, and upon verifying that said cryptographically protected subscriber profile has been cryptographically protected for said tamper-resistant element, activate said cryptographically protected subscriber profile in said tamper-resistant element, in order that only a subscriber profile that has been encrypted or cryptographically signed for said tamper-resistant element is activated in said tamper-resistant element.

Assignees

Inventors

Classifications

  • H04L63/00Primary

    Network architectures or network communication protocols for network security (cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00; network architectures or network communication protocols for wireless network security H04W12/00; security arrangements for protecting computers or computer systems against unauthorised activity G06F21/00) · CPC title

  • H04L63/102Primary

    Entity profiles · CPC title

  • Electricity · mapped topic

  • User profiles · CPC title

  • Services specially adapted for wireless communication networks; Facilities therefor · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9647984B2 cover?
System and method for allowing a mobile telecom device to use multiple profiles. The system and method includes operating a security function to perform a cryptographic operation on a profile using a cryptography key of the security function thereby producing a cryptographically protected profile, storing the cryptographically protected profile, and activating the cryptographically protected pr…
Who is the assignee on this patent?
Merrien Lionel, Barbe Serge, Gemalto Sa
What technology area does this patent fall under?
Primary CPC classification H04L63/00. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 09 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).