EP4639934A1 - Endgerät mit einem assistenzmodul zur verwaltung von in dem endgerät gespeicherten telekommunikationsprofilen und verwaltungsverfahren - Google Patents
Endgerät mit einem assistenzmodul zur verwaltung von in dem endgerät gespeicherten telekommunikationsprofilen und verwaltungsverfahrenInfo
- Publication number
- EP4639934A1 EP4639934A1 EP23840885.0A EP23840885A EP4639934A1 EP 4639934 A1 EP4639934 A1 EP 4639934A1 EP 23840885 A EP23840885 A EP 23840885A EP 4639934 A1 EP4639934 A1 EP 4639934A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- profile
- assistance module
- module
- assistance
- embedded identification
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/30—Security of mobile devices; Security of mobile applications
- H04W12/35—Protecting application or service provisioning, e.g. securing SIM application provisioning
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/40—Security arrangements using identity modules
- H04W12/42—Security arrangements using identity modules using virtual identity modules
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/69—Identity-dependent
- H04W12/72—Subscriber identity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/50—Service provisioning or reconfiguring
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/70—Services for machine-to-machine communication [M2M] or machine type communication [MTC]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
- H04W8/183—Processing at user equipment or user record carrier
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
- H04W8/20—Transfer of user or subscriber data
- H04W8/205—Transfer to or from user equipment or user record carrier
Definitions
- Terminal device with an assistance module for managing telecommunications profiles and management procedures stored in the terminal device
- the invention relates to the management of telecommunication profiles in terminal devices that can be controlled via a data network and have restricted network access or a restricted user interface.
- the GSMA GSM Association
- M2M devices The GSMA (GSM Association) has already standardized architectures for the remote provision of eSIM profiles for end-user devices and for M2M devices.
- the former provides for the installation of a local profile assistant (LPA) on the user device, which controls the life cycle of the profile on the device.
- LPA local profile assistant
- the loading of an eSIM profile is initiated by a user.
- M2M devices is based on the use of SMS messages and requires the integration of the entities involved. Both known solutions cannot be transferred to IoT devices or can only be transferred with disadvantages. IoT devices usually have only limited hardware and no user interface of their own.
- DE 102021127364 A1 discloses an implementation for securely connecting an IoT device to a wireless network, wherein the IoT device communicates with an authentication server via an access point to obtain access data for the network.
- US 20220295281 A1 describes a system for reconfiguring an embedded identification module in a terminal device, whereby identification profiles can be provided to the terminal device from a server via a remote management unit ("remote loT manager").
- the new GSMA standard SGP.31 "eSIM loT Architecture and Requirements", version 1.0, April 19, 2022, describes an architecture for the remote management of telecommunications profiles specifically for loT devices.
- the new standard is based on the GSMA standard SGP.21 for user terminals and adopts essential elements from it, including the concept of a profile provisioning instance (SM-DP+).
- New features compared to the known architecture are a remote management unit that is connected to the loT device and the profile provisioning instance (SM-DP+), as well as an assistance module that can be implemented in two variants.
- the support module is part of the loT device, in a second variant it is formed in the identification module that is embedded in the loT terminal.
- the architecture enables the loading and modification of profiles stored in the embedded identification module. Regardless of the implementation, the download of a telecommunications profile always takes place between the support module and the Profile provisioning instance.
- An assistance module is more complex to implement in the IoT terminal than in the embedded identification module and is less secure in comparison, but is more powerful and flexible than the latter.
- the object of the invention is to provide a terminal that combines the advantages of both implementations.
- the problem is solved by a terminal device and a method having the features of the independent claims.
- the terminal according to the invention is characterized in that it has a first assistance module installed in the embedded identification module and a second assistance module installed in the terminal itself, whereby only one of the two assistance modules is active at any one time.
- Two operating modes are defined by the activity of the first or the second assistance module.
- the division into two assistance modules has the advantage that the first assistance module can be flexibly adapted to a given situation. If the remote management unit only supports profile status actions, the implementation of the first assistance module in the embedded identification module can be very streamlined. Since profile status actions only require small amounts of data, there are only low requirements for the performance of the first assistance module when implemented in the embedded identification module.
- An embedded identification module equipped with a corresponding first assistance module can be easily set up by downloading it onto a terminal device.
- Fig. 1 an architecture for setting up and managing a telecommunications profile stored in an embedded identification module in an IoT terminal
- Fig. 2 a flow of a profile status action
- Fig. 1 shows an architecture for setting up and managing a telecommunications profile that is stored in an embedded identification module in an IoT terminal. It comprises a profile provisioning instance 10 (Subscription Manager Data Preparation, in short: SM-DP+), a remote management unit 20 (eSIM IoT remote Manager, in short: elM), a mediation server 30 (Subscription Manager Discovery Server, in short: SM-DS), a network operator 40 and a terminal 50 as shown, for example, in the GSMA standard SGP.31-V1.0.
- a profile provisioning instance 10 Subscribescription Manager Data Preparation, in short: SM-DP+
- eSIM IoT remote Manager in short: elM
- a mediation server 30 Subscription Manager Discovery Server, in short: SM-DS
- network operator 40 for example, in the GSMA standard SGP.31-V1.0.
- the terminal 50 contains a profile support module 60 formed from two components 52, 72 and an embedded identification module 70.
- the embedded identification module 70 contains a primary domain 74 (ISD-R) of a publisher and at least one profile domain 76 (ISD-P), as are also known from the GSMA standard SGP.31-V1.0.
- ISD-R primary domain 74
- ISD-P profile domain 76
- MNO-SD security area 78
- Telecommunications profile 80 hereinafter also referred to as profile, is stored.
- the components of the architecture shown in Fig. 1 each provide one or more interfaces by means of which they are connected to one another via data connections and/or data networks, as explained in more detail below.
- the Profile Provisioning Instance 10 (SM-DP+) has the function of making profile packages containing telecommunications profiles 80 available for download in a secure manner.
- the function of the remote management unit 20 is to set up and manage profiles 80 stored in the embedded identification module 70 (eUlCC).
- the remote management unit 20 (elM) uses command data sets to control the loading of profiles 80 into the embedded identification module 70 (eUlCC) and the changing of states of stored profiles 80.
- Command data sets contain profile management operations, which can refer in particular to loading operations (profile download) and profile state management operations (profile state management operation, in short: PSMO).
- the remote management unit 20 (elM) can be set up to convert profile packages as part of loading processes in order to convert them into a protocol that is required for using an interface, for example into a narrow band protocol.
- the task of the mediation server 30 is to provide the addresses of profile provisioning instances 10 (SM-DP+) in response to discovery requests from the connected components 20, 50.
- network operator 40 is a mobile network operator.
- the terminal 50 can be, for example, a component in a consumer object, such as a car or a camera, or part of a sensor unit. It generally has no user interface.
- the terminal 50 can in particular be an IoT terminal.
- the profile support module 60 communicates with the profile provisioning instance 10 (SM-DP+), the remote management unit 20 (elM) and the embedded identification module 70 (eUlCC) and enables the loading of profiles 80 into the embedded identification module 70 (eUlCC) as well as the changing of the states of loaded profiles 80.
- SM-DP+ profile provisioning instance 10
- elM remote management unit 20
- eUlCC embedded identification module 70
- the embedded identification module 70 is designed, for example, as an eUlCC, i.e. in the form of a hardware and software-secured HW element that is installed in a terminal device 50.
- the architecture and its components comply with the GSMA standard SGP.31-V1.0 or the associated standards.
- the profile support module 60 consists of two components, a first assistance module 72 (IPAe) and a second assistance module 52 (IPAd).
- the first assistance module 72 (IPAe) is formed in the embedded identification module 70 (eUlCC).
- the second assistance module 52 (IPAd) is designed as part of the terminal 50.
- the components 10, 20, 30, 40, 50, 52, 70, 72 each provide one or more interfaces by means of which they are connected to one another via conventional data connections and/or data networks.
- the profile provision instance 10 (SM-DP+) provides interfaces 100 (ES8+), 110 (ES9+'), 120 (ES9+), 130 (ES12), 140 (ES2+) to the remote management unit 20 (elM), the mediation server 30 (SM-DS), the second assistance module 52 (IPAd) and to the network operator 40.
- the profile provision instance 10 (SM-DP+) communicates with the second assistance module 52 (IPAd) via the protocols and interfaces defined in the GSMA standard SGP.22. This means that a profile provision instance 10 (SM-DP+) in accordance with the GSSMA standard SGP.22 can be used to implement the architecture, without the implementation of a special communication channel for communication with the second assistance module 52 (IPAd).
- the first assistance module 72 (IPAe) provides an external interface 150 (ES8+) to the remote management unit 20 and an external interface 160 (Eil) to the mediation server 30 (SM-DS). Furthermore, it has an interface 200 to the profile domain 76 (ISD-P) within the embedded identification module 70.
- the second assistance module 52 (IPAd) is connected within the terminal 50 via internal interfaces 220, 230 to the embedded identification module 70 (eUlCC) and further has an external side interface 170 (ESipa) to the remote management unit 20 (elM).
- the second assistance module 52 (IPAd) is set up to exchange data with the profile provision instance 10 (SM-DP+) in order to load a new profile 80 into the embedded identification module 70 (eUlCC).
- the communication between the second HW assistance module 52 (IPAd) and the profile provision instance 10 (SM-DP+) takes place using a second protocol, preferably using the protocol defined in SGP.22.
- the second assistance module 52 can request and receive activation codes from the remote management unit 20 (elM).
- the security area of the network operator 78 (MNO-SD) in the embedded identification module 70 (eUlCC) further has an external interface 240 (ES6) to the network operator 40 via the terminal device 50.
- network operator 40 controls administrative functions according to GSMA standard SGP.21 and orders profiles 80 for embedded identification modules 70 (eUlCC).
- network operator 40 manages profile contents using OTA services.
- a secure end-to-end connection is provided for managing the profile domain 76 (ISD-P) and the profiles stored therein during download and installation via the logical interface 100, 150 (ES8+) between the first assistance module 72 IPAe and the profile provisioning instance 10 (SM-DP+) and between the second assistance module 52 IPAd and the profile provisioning instance 10 (SM-DP+).
- Profile packages for example in the form of Bound Profile Packages, are transmitted securely via the interface 120 (ES9+) between profile provisioning instance 10 (SM-DP+) and second assistance module 52 (IPAd).
- the secure transmission of profile packages takes place via the interface 110 (ES9+ 1 ) between the profile provisioning instance 10 (SM-DP+) and the remote management unit 20 (elM).
- the remote management unit 20 (elM) acts on behalf of the first assistance module 72 (IPAe).
- the second assistance module 52 receives configured addresses for the mediation server 30 (SM-DS) and optionally for the profile provisioning instance 10 (SM-DP+).
- the second assistance module 52 transmits profile packages (Bound Profile Packages) to the embedded identification module 70 (eUlCC).
- the first assistance module 72 can retrieve event data records for the embedded identification module 70 (eUlCC).
- the remote management unit 20 (elM) retrieves event data records for the respective embedded identification module 70 (eUlCC).
- the remote management unit 20 (elM) can act on behalf of the first assistance module 72 (IPAe).
- Profile Provisioning Instance 10 creates or removes event registrations on Mediation Server 30 (SM-DS).
- the logical interface 210 allows secure end-to-end communication between the remote management unit 20 (elM) and the embedded identification module 70 (eUlCC) and is used to transmit profile management actions (PSMO).
- the remote management unit 20 communicates with the first assistance module 72 (IPAe) via the logical interface 190 (ESipa).
- the embedded identification module 70 (eUlCC) is adapted to support the interface 190.
- the interface 190 allows a secure end-to-end connection between the remote management unit 20 (elM) and the embedded identification module 70 (eUlCC).
- the remote management unit 20 controls profile management actions via the interface 190.
- the remote management unit 20 (elM) always communicates with the first assistance module 72 (IPAe) in the embedded identification module 70 (eUlCC).
- the remote management unit 20 (elM) can trigger the loading of a profile 80 via the interface 190.
- Profile status actions (PSMO) also take place via the interface 190.
- a profile is loaded by providing a profile 80 in the profile provisioning instance 10 (SM-DP+) and passing it on to the network operator's security area 78 (MNO-SD) via the architecture.
- SM-DP+ profile provisioning instance 10
- MNO-SD network operator's security area 78
- the modification of a profile 80 loaded into an embedded identification module is carried out using profile status actions (PSMO).
- Profile status actions can in particular be the activation of a profile, the deactivation of a profile, the deletion of a profile, the listing of profile information, the output of profile metadata or the updating of a profile.
- the two assistance modules 52, 72 (IPAd, IPAe) are operated in such a way that only the first assistance module 72 or the second assistance module 52 is active at the same time. If the first assistance module 72 (IPAe) is active and the second assistance module 52 (IPAd) is deactivated, this forms a first operating mode. If the second assistance module 52 (IPAd) is activated and the first assistance module 72 (IPAe) is deactivated, this forms a second operating mode. Which assistance module is activated and which operating mode is set depends on the type of profile management action to be carried out.
- the first assistance module 72 (IPAe) is activated when it receives a profile management action from the remote management unit 20 (elM).
- Profile management actions are loading profiles and changing profiles through a profile status action.
- a profile management action is a profile status action relating to a change in the state (PSMO) of a telecommunications profile 80 stored in the embedded identification module (eUlCC)
- the first assistance module 72 causes its execution by the embedded identification module 70 (eUlCC).
- the first assistance module 72 sends a feedback about the execution to the remote management unit 20 (elM), wherein the feedback is sent by means of a first protocol, preferably by means of an ESPSMO protocol, e.g. an MQ.TT or lightweight M2M protocol.
- a first protocol preferably by means of an ESPSMO protocol, e.g. an MQ.TT or lightweight M2M protocol.
- a profile management action sent to the first assistance module 72 concerns the loading of a new profile 80
- the first assistance module 72 passes the execution of the profile management action to the second assistance module 52 (IPAd).
- the first assistance module 72 (IPAe) deactivates itself and activates the second assistance module 52 (IPAd).
- the second assistance module 52 (IPAd) is activated when a profile management action concerns the loading of a new profile (Profile Download). It then causes this profile management action to be executed.
- the second assistance module 52 (IPAd) is expediently activated at least until a first telecommunications profile 80 has been loaded into the embedded identification module (eUlCC).
- the first assistance module 72 (IPAe) is expediently activated as soon as a telecommunications profile 80 has been loaded into the embedded identification module 70 (eUlCC) via the second assistance module 52 (IPAd).
- the activation of the first or second assistance module 52 is expediently carried out on the basis of a command from the remote management unit 20 (elM).
- Profile management actions are carried out effectively through the interaction of the assistance modules 52, 72 or by setting the first or second operating mode.
- a profile management action can be a profile status action that changes the state of a profile 80 stored in the embedded identification module 70 (eUlCC). For example, an activated profile 80 is deactivated and another activated, or a deactivated profile 80 is deleted. Profile status actions are conveniently triggered via the remote management unit 20 (elM). The sequence of a profile status action is shown in Fig. 2. To implement a change intended by a profile status action (PSMO), the remote management unit 20 establishes a secure connection to the first assistance module 72 (IPAe) via the interface 190 (ESipa) and a secure connection to the embedded identification element 70 (eUlCC) via the interface 210 (ESpsmo).
- PSMO profile status action
- the remote management unit 20 sends a command data record with a profile management action to the first assistance module 72 (IPAe), step 1000.
- the terminal 50 is in the first operating mode, the first assistance module 72 (IPAe) is activated, the second assistance module 52 (IPAd) is deactivated.
- the first assistance module 72 (IPAe) checks the command data record to determine whether the profile management action is a profile status action or involves loading a profile 80. If the profile management action is a profile status action, for example in the form of a PSMO message, the first assistance module 72 (IPAe) executes it, step 1010, and initiates the corresponding change to the addressed profile. For example, it is possible to switch from a first profile to a second profile.
- a profile management action can also be the loading of a profile 80 into the embedded identification element 70.
- Fig. 3 illustrates the signal flow when loading a profile 80 from the profile provision instance 10 (SM-DP+) into the embedded identification module 70 (eUlCC).
- the initial setup of a profile 80 on an embedded identification module 70 (eUlCC) or the loading of a new profile 80 is preferably carried out via the second assistance module 52 (IPAd) in the second operating mode.
- IPAd second assistance module 52
- the loading of a profile 80 is initialized by the remote management unit 20 via the interface 150 (E8+) via the first assistance module 72 (IPAe).
- the remote management unit 20 (elM) sends a command data set with a loading message to the first assistance module 72 (IPAe), step 1100.
- the first assistance module 72 (IPAe) activates the second assistance module (IPAd) 52 using an activation message, step 1110, and deactivates itself.
- the second assistance module 52 (IPAd) contacts the remote management unit 20 (elM) via the side interface 170 and requests an activation code, step 1120.
- the remote management unit 20 (elM) sends the activation code, step 1130.
- the second assistance module 52 determines the responsible profile provision instance 10 (SM-DP+) and establishes a secure connection to it via the interface 120 (S9+).
- the second assistance module 52 (IPAd) presents the activation code to the profile provision instance (SM-DP+), step 1400.
- the profile provision instance 10 SM-DP+
- the profile provision instance 10 SM-DP+
- the second assistance module 52 loads the profile package into the embedded identification module 70 (eUlCC), step 1420.
- the profile 80 contained in the profile package is installed by the embedded identification module 70 (eUlCC).
- the remote management unit 20 triggers the loading of a profile 80 by switching on the mediation server 30 (SM-DS).
- SM-DS mediation server 30
- a secure connection is established between the remote management unit 20 and the first assistance module 52 (IPAe) via the interface 190 (ESipa).
- the second assistance module 52 (IPAd) is deactivated so that the first operating mode is set.
- the first assistance module 72 (IPAe) initiates, after mutual authentication using information received from the embedded identification module 70 (eUlCC), the establishment of a secure connection to a mediation server 30 (SM-DS) via the interface 160 (Eil) in order to retrieve an event data record from it.
- the first assistance module 72 identifies the responsible profile provision instance 10 (SM-DP+) and communicates it to the second assistance module 72 (IPAd). To do this, it sets the second operating mode by deactivating itself and activating the second assistance module 52 (IPAd). The second assistance module 52 (IPAd) then loads a profile into the embedded identification module 70 (eUlCC) as described.
- the remote management unit 20 accepts the request for the event data record and forwards it to the first assistance module 52 (IPAe).
- the loading process is triggered by the remote management unit 20 (elM) using an activation code provided to the remote management unit 20.
- the remote management unit 20 (elM) sends a message containing the activation code to the first assistance module 72 (IPAe) via the interface 210 (EPpsmo), step 1200.
- the first assistance module 72 recognizes the message as a call to load a profile. It activates the second assistance module 52 using an activation message containing the activation code, step 1210.
- the terminal 50 is then in the second operating mode.
- the second assistance module 52 uses the activation code to determine the appropriate profile provision instance 10 (SM-DP+) and establishes a secure connection to it via the interface 120 (S9+).
- the second assistance module 52 (IPAd) presents the activation code to the profile provision instance (SM-DP+), step 1400.
- the profile provision instance 10 SM-DP+
- the profile provision instance 10 SM-DP+
- the second assistance module 52 loads the profile package into the embedded identification module 70 (eUlCC), step 1420.
- the profile 80 contained in the profile package is installed by the embedded identification module 70 (eUlCC).
- Remote Management Unit 20 elM
- Profile Provisioning Instance 10 SM-DP+
- a profile provisioning instance 10 (SM-DP+) is preset and the determination from an activation code is omitted.
- the charging process is triggered by the remote management unit 20 (elM) using an activation code provided to the remote management unit 20. Charging takes place in the first operating mode, i.e. the first assistance module 72 (IPAe) is activated, the second assistance module 52 (IPAd) is deactivated.
- the remote management unit 20 (elM) establishes a secure connection to the first assistance module 72 (IPAe) via the interface 190 (ESipa), determines the profile provision unit 10 (SM-DP+) from the activation code and also establishes a secure connection to it via the interface 100 (ES8+).
- the profile provision unit 10 (SM-DP+) then carries out mutual authentication with the embedded identification module 70 (eUlCC) via the then consistently secure connection.
- the profile provision unit 10 (SM-DP+) then provides a profile package and transmits it to the remote management unit 20 (elM). This sets the second operating mode and passes the profile package on to the embedded Identification module 70 (eULCC), which installs profile 80 and further notifies management unit 20 (elM) and profile provisioning instance 10 (SM-DP+).
- eULCC embedded Identification module 70
- the second assistance module 52 triggers the loading process by determining that a condition for loading a profile 80 is met, step 1300.
- the second assistance module 52 (IPAd) contacts the remote management unit 20 (elM) via the side interface 170 and requests an activation code, step 1310.
- the remote management unit 20 (elM) sends the activation code via the side interface 170, step 1320.
- the second assistance module 52 determines the responsible profile provision instance 10 (SM-DP+) and establishes a secure connection to it via the interface 120 (S9+).
- the second assistance module 52 (IPAd) presents the activation code to the profile provision instance (SM-DP+), step 1400.
- the profile provision instance 10 After carrying out mutual authentication with the embedded identification module 70 (eUlCC), the profile provision instance 10 provides a profile package to the second assistance module 52 (IPAd), step 1410.
- the second assistance module 52 (IPAd) loads the profile package into the embedded identification module 70 (eUlCC), step 1420.
- the profile 80 contained in the profile package is installed by the embedded identification module 70 (eUlCC).
- Remote Management Unit 20 elM
- Profile Provisioning Instance 10 SM-DP+
- an application is executed within the terminal 50 or in the embedded identification module 70 (eUlCC), which controls the status of profiles 80 stored in the embedded identification module 70 (eUlCC).
- an application can, for example, be an application that recognizes the current location of a terminal 50 and sets a profile 80 that matches the location. If suitable conditions exist, the application sends a message to the first assistance module 72 (IPAe), which in turn then causes the profile status to change.
- IPAe first assistance module 72
- the remote management unit 20 (elM) is designed to provide a repair profile that is loaded into an embedded identification module 70 (eUlCC) when required.
- the repair profile is loaded as described above.
- a first assistance module 72 (IPAe) is available in the terminal device 50 and the second assistance module 52 (IPAd) is only set up when a need to load a profile 80 arises for the first time.
- first assistance module 72 and a second assistance module 52 for the execution of profile management actions, one of which is formed in the embedded identification module 70 and the other in the terminal 50, the first assistance module 72 causing the execution of a profile management action if it is a profile status action and the second assistance module 52 causing the execution of a profile management action if it involves the loading of a profile
- the solution described allows a number of modifications which are not explained in more detail for reasons of clarity.
- the triggering of a Profile management action may be taken based on other possible event occurrences.
- additional measures to secure communications may be provided, or fewer may be required.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Databases & Information Systems (AREA)
- Computer And Data Communications (AREA)
- Information Transfer Between Computers (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Vorgeschlagen wird ein Endgerät (50) mit einem eingebettetem Identifikationsmodul (70), das dazu eingerichtet ist Profilverwaltungsaktionen auszuführen, mittels derer ein in dem eingebetteten Identifikationsmodul (70) gespeichertes Telekommunikationsprofil (80) verändert oder ein neues Telekommunikationsprofil (80) geladen werden kann. Das eingebettete Identifikationsmodul (70) weist ein erstes Assistenzmodul (72) auf, das eine erste Schnittstelle zu einer Fernverwaltungseinheit (20) bereitstellt, und ein zweites Assistenzmodul (72), das mit dem eingebetteten Identifikationsmodul (70) verbunden ist und eine zweite Schnittstelle zu einer Profilbereitstellungsinstanz (10) bereitstellt. Zur gleichen Zeit ist entweder das erste Assistenzmodul (72) oder das zweite Assistenzmodul (52) aktiv. Das Endgerät (50) erhält von der Fernverwaltungseinheit (20) Kommandodatensätze, die Profilverwaltungsaktionen enthalten. Das erste Assistenzmodul (72) ist aktiv ist und bewirkt die Ausführung einer Profilverwaltungsaktion, wenn die Profilverwaltungsaktion eine Änderung des Zustands eines in dem eingebetteten Identifikationsmodul (70) gespeicherten Telekommunikationsprofils (80) betrifft. Das zweite Assistenzmodul (52) ist aktiv und bewirkt die Ausführung einer Profilverwaltungsaktion, wenn diese das Laden eines neuen Telekommunikationsprofils (80) betrifft.
Description
Endgerät mit einem Assistenzmodul zur Verwaltung von in dem Endgerät gespeicherten Telekommunikationsprofilen und Verwaltungsverfahren
Die Erfindung betrifft die Verwaltung von Telekommunikationsprofilen in über ein Datennetz steuerbaren Endgeräten mit eingeschränktem Netzwerkzugang oder eingeschränkter Benutzeroberfläche.
Von der GSMA (GSM Association) wurden bereits Architekturen für die Fernbereitstellung von eSIM- Profilen für Endnutzergeräte sowie für M2M-Geräte standardisiert. Erstere sieht die Einrichtung eines lokalen Profilassistenten (Local Profile Assistant, LPA) auf dem Nutzergerät vor, der den Lebenszyklus des Profils auf dem Gerät steuert. Das Laden eines eSIM-Profils wird durch einen Nutzer veranlasst. Der Standard für M2M-Geräte basiert auf der Verwendung von SMS-Nachrichten und erfordert die Integration der beteiligten Instanzen. Beide bekannten Lösungen lassen sich nicht oder nur mit Nachteilen auf loT-Geräte übertragen. loT-Geräte besitzen in der Regel nur eine eingeschränkte Hardwareausstattung und keine eigene Nutzerschnittstelle.
DE 102021127364 Al offenbart eine Implementierung zur sicheren Verbindung eines loT-Gerätes mit einem drahtlosen Netzwerk, wobei das loT-Gerät über einen Zugangspunkt mit einem Authentifizierungsserver kommuniziert, um Zugangsdaten für das Netzwerk zu erhalten.
US 20220295281 Al beschreibt ein System zur Rekonfiguration eines eingebetteten Identifikationsmoduls in einem Endgerät, wobei dem Endgerät Identifikationsprofile von einem Server über eine entfernte Verwaltungseinheit („remote loT manager") bereitgestellt werden können.
In dem neuen GSMA-Standard SGP.31 „eSIM loT Architecture and Requirements", Version 1.0, 19 April 2022, ist eine Architektur für die Fernverwaltung von Telekommunikationsprofilen speziell für loT-Geräte beschrieben. Der neue Standard basiert auf dem GSMA-Standard SGP.21 für Nutzerendgeräte und übernimmt daraus wesentliche Elemente, unter anderem das Konzept einer Profilbereitstellungsinstanz (SM-DP+). Neu gegenüber der bekannten Architektur eingeführt werden eine Fernverwaltungseinheit, die mit dem loT-Gerät und der Profilbereitstellungsinstanz (SM-DP+) verbunden ist, sowie ein Assistenzmodul, das in zwei Varianten implementiert sein kann. In einer ersten Variante ist das Unterstützungsmodul Teil des loT-Gerätes, in einer zweiten Variante ist es in dem Identifikationsmodul ausgebildet, das in das loT-Endgerät eingebettet ist. Über Profilverwaltungsaktionen ermöglicht die Architektur das Laden und die Änderung von in dem eingebetteten Identifikationsmodul gespeicherten Profilen. Das Herunterladen eines Telekommunikationsprofils erfolgt unabhängig von der Implementierung stets zwischen dem Unterstützungsmodul und der Profilbereitstellungsinstanz.
Beide Implementierungen haben jeweils Vor- und Nachteile. Ein Assistenzmodul ist im loT-Endgerät komplexer zu implementieren als im eingebetteten Identifikationsmodul und im Vergleich weniger sicher, dafür aber gegenüber letzterem leistungsfähiger und flexibler.
Aufgabe der Erfindung ist es, ein Endgerät anzugeben, das die Vorteile beider Implementierungen auf sich vereint.
Die Aufgabe wird gelöst durch ein Endgerät und ein Verfahren mit den Merkmalen der unabhängigen Ansprüche.
Das erfindungsgemäße Endgerät zeichnet sich dadurch aus, dass es ein erstes, im eingebetteten Identifikationsmodul eingerichtetes Assistenzmodul, sowie ein zweites, im Endgerät selbst eingerichtetes Assistenzmodul aufweist, wobei stets nur eines der beiden Assistenzmodul aktiv ist. Durch die Aktivität des ersten oder des zweiten Assistenzmodul werden zwei Betriebsarten definiert.
Die Aufteilung in zwei Assistenzmodule hat den Vorteil, dass das erste Assistenzmodul flexibel an eine jeweils gegebene Situation angepasst werden kann. Unterstützt die Fernverwaltungseinheit nur Profilstatusaktionen, kann die Implementierung des ersten Assistenzmoduls im eingebetteten Identifikationsmodul sehr schlank ausgestaltet sein kann. Da Profilstatusaktionen nur geringe Datenmengen erfordern, bestehen an die Leistungsfähigkeit des ersten Assistenzmoduls bei der Implementierung in dem eingebetteten Identifikationsmodul nur geringe Anforderungen.
Ein mit einem entsprechenden ersten Assistenzmodul ausgestattetes eingebettetes Identifikationsmodul kann in einfacher Weise durch Herunterladen auf einem Endgerät eingerichtet werden.
Ein Ausführungsbeispiel der Erfindung wird nachfolgend unter Bezugnahme auf die Zeichnung näher beschrieben.
Es zeigen:
Fig. 1 eine Architektur zur Einrichtung und Verwaltung eines Telekommunikationsprofils, das in einem eingebetteten Identifikationsmodul in einem loT-Endgerät gespeichert ist,
Fig. 2 einen Ablauf einer Profilstatusaktion,
Fig. 3 das Laden eines Profils von einer Profilbereitstellungsinstanz in ein eingebettetes
Identifikationsmodul.
Beschreibung
Fig. 1 zeigt eine Architektur zur Einrichtung und Verwaltung eines Telekommunikationsprofils, das in einem eingebetteten Identifikationsmodul in einem loT-Endgerät gespeichert ist. Sie umfasst eine Profilbereitstellungsinstanz 10 (Subscription Manager Data Preparation, kurz: SM-DP+), eine Fernverwaltungseinheit 20 (eSIM loT remote Manager, kurz: elM), einen Vermittlungsserver 30 (Subscription Manager Discovery Server, kurz: SM-DS), einen Netzbetreiber 40 sowie ein Endgerät 50 wie sie beispielsweise im GSMA-Standard SGP.31-V1.0 dargestellt sind.
In dem Endgerät 50 befinden sich ein aus zwei Komponenten 52, 72 gebildetes Profilunterstützungsmodul 60 sowie ein eingebettetes Identifikationsmodul 70. In dem eingebetteten Identifikationsmodul 70 sind eine Urdomäne 74 (ISD-R) eines Herausgebers sowie mindestens eine Profildomäne 76 (ISD-P) ausgebildet, wie sie ebenfalls aus dem GSMA-Standard SGP.31-V1.0 bekannt sind. In jeder Profildomäne 76 (ISD-P) befindet sich ein Sicherheitsbereich 78 (MNO-SD) eines Netzbetreibers 40. In dem Sicherheitsbereich 78 (MNO-SD) ist mindestens ein
Telekommunikationsprofil 80, im folgenden auch kurz als Profil bezeichnet, gespeichert. Die Komponenten der in Fig. 1 gezeigten Architektur stellen jeweils eine oder mehrere Schnittstellen bereit, mittels derer sie über Datenverbindungen und/oder Datennetze wie nachfolgend näher erläutert miteinander verbunden sind.
Die Profilbereitstellungsinstanz 10 (SM-DP+) hat die Funktion, Telekommunikationsprofile 80 enthaltende Profilpakete in sicherer Art und Weise zum Download bereitzustellen.
Funktion der Fernverwaltungseinheit 20 (elM) ist die Einrichtung und Verwaltung von im eingebetteten Identifikationsmodul 70 (eUlCC) abgelegten Profilen 80. Die Fernverwaltungseinheit 20 (elM) steuert hierzu mittels Kommandodatensätzen das Laden von Profilen 80 in das eingebettete Identifikationsmodul 70 (eUlCC) sowie die Änderung von Zuständen gespeicherter Profile 80. Kommandodatensätze beinhalten hierzu Profilverwaltungsoperation, die insbesondere Ladeoperationen (Profile Download) und Profilzustandsoperationen (Profile State Management Operation, kurz: PSMO) bezeichnen können. Optional kann die Fernverwaltungseinheit 20 (elM) dazu eingerichtet sein, im Rahmen von Ladevorgängen Profilpakete zu konvertieren, um sie in ein Protokoll zu konvertieren, das für die Nutzung einer Schnittstelle erforderlich ist, beispielsweise in ein Narrow Band Protokoll.
Aufgabe des Vermittlungsservers 30 (SM-DS) ist die Bereitstellung der Adressen von Profilbereitstellungsinstanzen 10 (SM-DP+) in Antwort auf Ermittlungsanfragen der verbundenen Komponenten 20, 50.
Der Netzbetreiber 40 ist beispielsweise ein Mobilfunknetzbetreiber.
Das Endgerät 50 kann beispielsweise ein Bauelement in einem Gebrauchsgegenstand, etwa einem Auto oder einer Kamera, oder Teil einer Sensoreinheit sein. Es besitzt in der Regel keine Benutzeroberfläche. Das Endgerät 50 kann insbesondere ein loT-Endgerät sein.
Das Profilunterstützungsmodul 60 kommuniziert mit der Profilbereitstellungsinstanz 10 (SM-DP+), der Fernverwaltungseinheit 20 (elM) und dem eingebetteten Identifikationsmodul 70 (eUlCC) und ermöglicht das Laden von Profilen 80 in das eingebettete Identifikationsmodul 70 (eUlCC) sowie die Änderung der Zustände von geladenen Profilen 80.
Das eingebettete Identifikationsmodul 70 ist beispielsweise als eUlCC ausgeführt, d.h. in Form eines hardware- und softwaremäßig abgesicherten HW-Elements, das in ein Endgerät 50 verbaut ist.
Die Architektur und ihre Komponenten entsprechen insoweit dem GSMA-Standard SGP.31-V1.0 bzw. den verbundenen Standards.
Abweichend von der Architektur nach dem GSMA-Standard SGP.31-V1.0. besteht in der erfindungsgemäßen Architektur gemäß Fig. 1 das Profilunterstützungsmodul 60 aus zwei Komponenten, einem ersten Assistenzmodul 72 (IPAe) und einem zweiten Assistenzmodul 52 (IPAd). Das erste Assistenzmodul 72 (IPAe) ist in dem eingebetteten Identifikationsmodul 70 (eUlCC) ausgebildet. Das zweite Assistenzmodul 52 (IPAd) ist als Teil des Endgerätes 50 ausgeführt.
Die Komponenten 10, 20, 30, 40, 50, 52, 70, 72 stellen jeweils eine oder mehrere Schnittstellen bereit, mittels derer sie über an sich übliche Datenverbindungen und/oder Datennetze miteinander verbunden sind.
Die Profilbereitstellungsinstanz 10 (SM-DP+) stellt Schnittstellen 100 (ES8+), 110 (ES9+'), 120 (ES9+), 130 (ES12), 140 (ES2+) zu der Fernverwaltungseinheit 20 (elM), dem Vermittlungsserver 30 (SM-DS), dem zweiten Assistenzmodul 52 (IPAd) und zu dem Netzbetreiber 40 bereit. Mit dem zweiten Assistenzmodul 52 (IPAd) kommuniziert die Profilbereitstellungsinstanz 10 (SM-DP+) über die in dem GSMA-Standard SGP.22 definierten Protokolle und Interfaces. Damit kann zur Implementierung der Architektur insbesondere eine Profilbereitstellungsinstanz 10 (SM-DP+) nach dem GSSMA-Standard SGP.22 eingesetzt werden, ohne dass die Implementierung eines besonderen Kommunikationskanals zur Kommunikation mit dem zweiten Assistenzmodul 52 (IPAd) erforderlich ist.
Das erste Assistenzmodul 72 (IPAe) stellt eine externe Schnittstelle 150 (ES8+) zu der Fernverwaltungseinheit 20 sowie eine externe Schnittstelle 160 (Eil) zu dem Vermittlungsserver 30 (SM-DS) bereit. Weiter weist es innerhalb des eingebetteten Identifikationsmoduls 70 eine Schnittstelle 200 zu der Profildomäne 76 (ISD-P) auf.
Das zweite Assistenzmodul 52 (IPAd) ist innerhalb des Endgerätes 50 über interne Schnittstellen 220, 230 mit dem eingebetteten Identifikationsmodul 70 (eUlCC) verbunden und besitzt weiterhin eine externe Seitenschnittstelle 170 (ESipa) zu der Fernverwaltungseinheit 20 (elM).
Das zweite Assistenzmodul 52 (IPAd) ist dazu eingerichtet einen Datenaustausch mit der Profilbereitstellungsinstanz 10 (SM-DP+) zu führen, um ein neues Profil 80 in das eingebettete Identifikationsmodul 70 (eUlCC) zu laden. Die Kommunikation zwischen dem zweiten HW- Assistenzmodul 52 (IPAd) und der Profilbereitstellungsinstanz 10 (SM-DP+) erfolgt mittels eines zweiten Protokolls, bevorzugt mittels des in SGP.22 definierten Protokolls.
Über die Seitenschnittstelle 170 (ESipa) kann das zweite Assistenzmodul 52 (IPAd) von der Fernverwaltungseinheit 20 (elM) Aktivierungscodes anfordern und erhalten.
Der Sicherheitsbereich des Netzbetreibers 78 (MNO-SD) im eingebetteten Identifikationsmodul 70 (eUlCC) besitzt über das Endgerät 50 weiter eine externe Schnittstelle 240 (ES6) zu dem Netzbetreiber 40.
Über die Schnittstelle 140 (ES2+) zwischen Netzbetreiber 40 und Profilbereitstellungsinstanz 10 (SM- DP+) steuert der Netzbetreiber 40 administrative Funktionen gemäß dem GSMA-Standard SGP.21 und bestellt Profile 80 für eingebettete Identifikationsmodule 70 (eUlCC).
Über die Schnittstelle 240 (ES6) zwischen Netzbetreiber 40 und eingebettetem Identifikationsmodul 70 (eUlCC) verwaltet der Netzbetreiber 40 mit Hilfe von OTA-Diensten Profilinhalte.
Über die logische Schnittstelle 100, 150 (ES8+), die zwischen dem ersten Assistenzmodul 72 IPAe und der Profilbereitstellungsinstanz 10 (SM-DP+) und zwischen dem zweiten Assistenzmodul 52 IPAd und der Profilbereitstellungsinstanz 10 (SM-DP+) besteht, wird eine sichere Ende-zu-Ende-Verbindung für die Verwaltung der Profildomäne 76 (ISD-P) und der darin gespeicherten Profile während des Downloads und der Installation bereitgestellt
Über die Schnittstelle 120 (ES9+) zwischen Profilbereitstellungsinstanz 10 (SM-DP+) und zweitem Assistenzmodul 52 (IPAd) erfolgt eine sichere Übermittlung von Profilpaketen, beispielsweise in Form von Bound Profile Packages.
Über die Schnittstelle 110 (ES9+1) zwischen Profilbereitstellungsinstanz 10 (SM-DP+) und Fernverwaltungseinheit 20 (elM) erfolgt die sichere Übermittlung von Profilpaketen. Die Fernverwaltungseinheit 20 (elM) handelt im Namen des ersten Assistenzmoduls 72 (IPAe).
Über die Schnittstelle 220 (ESlOa) zwischen zweitem Assistenzmodul 52 (LPAd) und eingebettetem Identifikationsmodul 70 (eUlCC) erhält das zweite Assistenzmodul 52 (IPAd) konfigurierte Adressen für den Vermittlungsserver 30 (SM-DS) und optional für das die Profilbereitstellungsinstanz 10 (SM- DP+). Über die Schnittstelle 220 (ESlOa) überträgt das zweite Assistenzmodul 52 (IPAd) Profilpakete (Bound Profile Packages) an das eingebettete Identifikationsmodul 70 (eUlCC).
Über die Schnittstelle 160 (ES11) zwischen Vermittlungsserver 30 (SM-DS) und erstem Assistenzmodul 72 (IPAe) kann das erste Assistenzmodul 72 (IPAe) Ereignisdatensätze für das eingebettete Identifikationsmodul 70 (eUlCC) abrufen.
Über die Schnittstelle 180 (ESU1) zwischen Fernverwaltungseinheit 20 (elM) und Vermittlungsserver 30 (SM-DS) ruft die Fernverwaltungseinheit 20 (elM) Ereignisdatensätze für die jeweilige eingebettete Identifikationsmodul 70 (eUlCC) ab. Die Fernverwaltungseinheit 20 (elM) kann im Namen des ersten Assistenzmoduls 72 (IPAe) handeln.
Über die Schnittstelle 130 (ES12) zwischen Profilbereitstellungsinstanz 10 (SM-DP+) und Vermittlungsserver 30 (SM-DS) erstellt oder entfernt die Profilbereitstellungsinstanz 10 Ereignisregistrierungen auf dem Vermittlungsserver 30 (SM-DS).
Die logische Schnittstelle 210 (ESpsmo) erlaubt eine sichere Ende-zu-Ende-Kommunikation zwischen der Fernverwaltungseinheit 20 (elM) und dem eingebetteten Identifikationsmodul 70 (eUlCC) und dient zur Übertragung von Profilverwaltungsaktionen (PSMO).
Über die logische Schnittstelle 190 (ESipa) kommuniziert die Fernverwaltungseinheit 20 (elM) mit dem ersten Assistenzmodul 72 (IPAe). Das eingebettete Identifikationsmodul 70 (eUlCC) ist so angepasst, dass es die Schnittstelle 190 unterstützt. Die Schnittstelle 190 erlaubt eine sichere Ende- zu-Ende Verbindung zwischen der Fernverwaltungseinheit 20 (elM) und dem eingebetteten Identifikationsmodul 70 (eUlCC).
Über die Schnittstelle 190 steuert die Fernverwaltungseinheit 20 (elM) Profilverwaltungsaktionen. Die Fernverwaltungseinheit 20 (elM) kommuniziert dabei stets mit dem ersten Assistenzmodul 72 (IPAe) im eingebetteten Identifikationsmodul 70 (eUlCC). Über die Schnittstelle 190 kann die Fernverwaltungseinheit 20 (elM) das Laden eines Profils 80 auslösen. Ebenso erfolgen über die Schnittstelle 190 Profilstatusaktionen (PSMO).
Das Laden eines Profils erfolgt, indem ein Profil 80 in der Profilbereitstellungsinstanz 10 (SM-DP+) bereitgestellt und über die Architektur in den Sicherheitsbereich 78 (MNO-SD) des Netzbetreibers übergeben wird.
Die Änderung eines in ein eingebettetes Identifikationsmodul (eUlCC) geladenen Profils 80 erfolgt mithilfe von Profilstatusaktionen (PSMO). Profilstatusaktionen können insbesondere die Aktivierung eines Profils, die Deaktivierung eines Profils, das Löschen eines Profils, das Auflisten einer Profilinformation, die Ausgabe von Profil-Metadaten oder die Aktualisierung eines Profils sein.
Die beiden Assistenzmodule 52, 72 (IPAd, IPAe) werden so betrieben, dass zur gleichen Zeit nur entweder das erste Assistenzmodul 72 aktiv ist oder das zweite Assistenzmodul 52. Ist das erste Assistenzmodul 72 (IPAe) aktiv und das zweite Assistenzmodul 52 (IPAd) deaktiviert, bildet das eine erste Betriebsart. Ist das zweite Assistenzmodul 52 (IPAd) aktiviert und das erste Assistenzmodul 72 (IPAe) deaktiviert, bildet das eine zweite Betriebsart. Welches Assistenzmodul aktiviert und welche Betriebsart eingestellt ist, hängt vom Typ der auszuführenden Profilverwaltungsaktion ab.
Das erste Assistenzmodul 72 (IPAe) ist aktiviert, wenn es von der Fernverwaltungseinheit 20 (elM) eine Profilverwaltungsaktion erhält. Profilverwaltungsaktionen sind das Laden von Profilen und die Änderung von Profilen durch eine Profilstatusaktionen.
Ist eine Profilverwaltungsaktion eine Profilstatusaktion, die eine Änderung des Zustands (PSMO) eines in dem eingebetteten Identifikationsmodul (eUlCC) gespeicherten Telekommunikationsprofils 80 betrifft, bewirkt das erste Assistenzmodul 72 (IPAe) deren Ausführung durch das eingebettete Identifikationsmodul 70( eUlCC).
Nach Ausführung einer Profilstatusaktion schickt das erste Assistenzmodul 72 (IPAe) eine Rückmeldung über die Ausführung an die Fernverwaltungseinheit 20 (elM), wobei das Senden der Rückmeldung mittels eines ersten Protokolls erfolgt, bevorzugt mittels eines ESPSMO-Protokolls, z.B. eines MQ.TT- oder Lightweight M2M-Protokolls.
Betrifft eine an das erste Assistenzmodul 72 (IPAe) geschickte Profilverwaltungsaktion das Laden eines neuen Profils 80, übergibt das erste Assistenzmodul 72 (IPAe) die Ausführung der Profilverwaltungsaktion an das zweite Assistenzmodul 52 (IPAd). Das erste Assistenzmodul 72 (IPAe) deaktiviert sich selbst und aktiviert das zweite Assistenzmodul 52 (IPAd).
Das zweite Assistenzmodul 52 (IPAd) ist aktiviert, wenn eine Profilverwaltungsaktion das Laden eines neuen Profils betrifft (Profile Download). Es bewirkt dann die Ausführung dieser Profilverwaltungsaktion.
Zweckmäßig ist das zweite Assistenzmodul 52 (IPAd) zumindest solange aktiviert, bis ein erstes Telekommunikationsprofil 80 in das eingebettete Identifikationsmodul (eUlCC) geladen wurde.
Zweckmäßig ist das erste Assistenzmodul 72 (IPAe) aktiviert, sobald über das zweite Assistenzmodul 52 (IPAd) ein Telekommunikationsprofil 80 in das eingebettete Identifikationsmodul 70 (eUlCC) geladen wurde.
Zweckmäßig erfolgt die Aktivierung des ersten oder des zweiten Assistenzmoduls 52 (IPAd) aufgrund eines Kommandos von der Fernverwaltungseinheit 20 (elM).
Durch das Zusammenspiel der Assistenzmodule 52, 72 bzw. durch Einstellung der ersten oder der zweiten Betriebsart werden Profilverwaltungsaktionen effektiv ausgeführt.
Eine Profilverwaltungsaktion kann eine Profilstatusaktion sein, mit der der Zustand eines im eingebetteten Identifikationsmodul 70 (eUlCC) gespeicherten Profils 80 verändert wird. Beispielsweise wird ein aktiviertes Profil 80 deaktiviert und ein anderes aktiviert oder ein deaktiviertes Profil 80 wird gelöscht. Profilstatusaktionen werden zweckmäßig über die Fernverwaltungseinheit 20 (elM) ausgelöst. Der Ablauf einer Profilstatusaktion ist in Fig. 2 dargestellt.
Zur Umsetzung einer durch eine Profilstatusaktion (PSMO) beabsichtigten Veränderung baut die Fernverwaltungseinheit 20 über die Schnittstelle 190 (ESipa) eine sichere Verbindung zu dem ersten Assistenzmodul 72 (IPAe) sowie über die Schnittstelle 210 (ESpsmo) eine sichere Verbindung zu dem eingebetteten Identifikationselement 70 (eUlCC) auf.
Über die sichere Verbindung 190 schickt die Fernverwaltungseinheit 20 (elM) einen Kommandodatensatz mit einer Profilverwaltungsaktion an das erste Assistenzmodul 72 (IPAe), Schritt 1000. Das Endgerät 50 befindet sich in der ersten Betriebsart, das erste Assistenzmodul 72 (IPAe) ist aktiviert, das zweite Assistenzmodul 52 (IPAd) ist deaktiviert.
Das erste Assistenzmodul 72 (IPAe) prüft den Kommandodatensatz darauf, ob die Profilverwaltungsaktion eine Profilstatusaktion ist oder das Laden eines Profils 80 beinhaltet. Ist die Profilverwaltungsaktion eine Profilstatusaktion, etwa in Form einer PSMO Message, führt das erste Assistenzmodul 72 (IPAe) sie aus, Schritt 1010, und veranlasst die entsprechende Veränderung des adressierten Profils. Beispielsweise kann von einem ersten Profil auf ein zweites Profil umgeschaltet werden.
Eine Profilverwaltungsaktion kann daneben das Laden eines Profils 80 in das eingebettete Identifikationselement 70 sein. Fig. 3 veranschaulicht den Signalfluss beim Laden eines Profils 80 von der Profilbereitstellungsinstanz 10 (SM-DP+) in das eingebettete Identifikationsmodul 70 (eUlCC). Das erstmalige Einrichten eines Profils 80 auf einem eingebetteten Identifikationsmodul 70 (eUlCC) oder das Laden eines neuen Profils 80 erfolgt vorzugsweise über das zweite Assistenzmodul 52 (IPAd) in der zweiten Betriebsart.
In einer ersten Ausführungsvariante 01 wird das Laden eines Profils 80 durch die Fernverwaltungseinheit 20 über die Schnittstelle 150 (E8+) über das erste Assistenzmodul 72 (IPAe) initialisiert. Die Fernverwaltungseinheit 20 (elM) schickt einen Kommandodatensatz mit einer Ladenachricht an das erste Assistenzmodul 72 (IPAe), Schritt 1100. Das erste Assistenzmodul 72 (IPAe) aktiviert mittels einer Aktivierungsnachricht das zweite Assistenzmodul (IPAd) 52, Schritt 1110, und deaktiviert sich selbst. Das zweite Assistenzmodul 52 (IPAd) kontaktiert über die Seitenschnittstelle 170 die Fernverwaltungseinheit 20 (elM) und fordert einen Aktivierungscode an, Schritt 1120. Die Fernverwaltungseinheit 20 (elM) schickt den Aktivierungscode, Schritt 1130.
Aus dem Aktivierungscode ermittelt das zweite Assistenzmodul 52 (IPAd) die zuständige Profilbereitstellungsinstanz 10 (SM-DP+) und baut über die Schnittstelle 120 (S9+) eine sichere Verbindung zu dieser auf. Den Aktivierungscode präsentiert das zweite Assistenzmodul 52 (IPAd) der Profilbereitstellungsinstanz (SM-DP+), Schritt 1400. Nach Durchführung einer wechselseitigen Authentisierung mit dem eingebetteten Identifikationsmodul 70 (eUlCC) stellt die Profilbereitstellungsinstanz 10 (SM-DP+) ein Profilpaket an das zweite Assistenzmodul 52 (IPAd) bereit, Schritt 1410. Das Profilpaket lädt das zweite Assistenzmodul 52 (IPAd) in das eingebettete Identifikationsmodul 70 (eUlCC), Schritt 1420. Das in dem Profilpaket enthaltene Profil 80 wird von dem eingebetteten Identifikationsmodul 70 (eUlCC) installiert.
In einer Ausführungsvariante zu 01 löst die Fernverwaltungseinheit 20 (elM) das Laden eines Profils 80 unter Einschaltung des Vermittlungsservers 30 (SM-DS) aus. Dazu wird über die Schnittstelle 190 (ESipa) eine sichere Verbindung zwischen Fernverwaltungseinheit 20 und erstem Assistenzmodul 52 (IPAe) aufgebaut. Das zweite Assistenzmodul 52 (IPAd) wird deaktiviert, so dass die erste Betriebsart eingestellt ist. Das erste Assistenzmodul 72 (IPAe) veranlasst, nach wechselseitiger Authentisierung
mithilfe einer von dem eingebetteten Identifikationsmodul 70 (eUlCC) erhaltenen Information, über die Schnittstelle 160 (Eil) den Aufbau einer sicheren Verbindung zu einem Vermittlungsserver 30 (SM-DS), um von diesem einen Ereignisdatensatz abzurufen. Mit dem Ereignisdatensatz identifiziert das erste Assistenzmodul 72 (IPAe) die zuständige Profilbereitstellungsinstanz 10 (SM-DP+) und teilt sie an das zweite Assistenzmodul 72 (IPAd) mit. Dazu stellt es die zweite Betriebsart ein, indem es sich selbst deaktiviert und das zweite Assistenzmodul 52 (IPAd) aktiviert. Das zweite Assistenzmodul 52 (IPAd) lädt anschließend wie beschrieben ein Profil in das eingebettete Identifikationsmodul 70 (eUlCC).
In einer Abwandlung der Ausführungsvariante übernimmt die Fernverwaltungseinheit 20 (elM) die Anforderung des Ereignisdatensatzes und leitet diesen an das erste Assistenzmodul 52 (IPAe) weiter.
In einer zweiten Ausführungsvariante O2 wird der Ladevorgang durch die Fernverwaltungseinheit 20 (elM) mithilfe eines an die Fernverwaltungseinheit 20 bereitgestellten Aktivierungscodes ausgelöst. Die Fernverwaltungseinheit 20 (elM) schickt über die Schnittstelle 210 (EPpsmo) eine den Aktivierungscode beinhaltende Nachricht an das erste Assistenzmodul 72 (IPAe), Schritt 1200. Das erste Assistenzmodul 72 erkennt die Nachricht als Aufruf zum Laden eines Profils. Es aktiviert mittels einer den Aktivierungscode beinhaltenden Aktivierungsnachricht das zweite Assistenzmodul 52, Schritt 1210. Das Endgerät 50 befindet sich danach in der zweiten Betriebsart.
Zu dem Aktivierungscode ermittelt das zweite Assistenzmodul 52 (IPAd) die zuständige Profilbereitstellungsinstanz 10 (SM-DP+) und baut über die Schnittstelle 120 (S9+) eine sichere Verbindung zu dieser auf. Den Aktivierungscode präsentiert das zweite Assistenzmodul 52 (IPAd) der Profilbereitstellungsinstanz (SM-DP+), Schritt 1400. Nach Durchführung einer wechselseitigen Authentisierung mit dem eingebetteten Identifikationsmodul 70 (eUlCC) stellt die Profilbereitstellungsinstanz 10 (SM-DP+) ein Profilpaket an das zweite Assistenzmodul 52 (IPAd) bereit, Schritt 1410. Das Profilpaket lädt das zweite Assistenzmodul 52 (IPAd) in das eingebettete Identifikationsmodul 70 (eUlCC), Schritt 1420. Das in dem Profilpaket enthaltene Profil 80 wird von dem eingebetteten Identifikationsmodul 70 (eUlCC) installiert.
Fernverwaltungseinheit 20 (elM) und Profilbereitstellungsinstanz 10 (SM-DP+) werden über die erfolgreiche Profileinrichtung informiert.
In einer Abwandlung der Ausführungsvariante ist eine Profilbereitstellungsinstanz 10 (SM-DP+) voreingestellt und die Ermittlung aus einem Aktivierungsodes entfällt.
In einer Ausführungsvariante zu O2 wird der Ladevorgang durch die Fernverwaltungseinheit 20 (elM) mithilfe eines an die Fernverwaltungseinheit 20 bereitgestellten Aktivierungscodes ausgelöst. Das Laden erfolgt in der ersten Betriebsart, d.h. das erste Assistenzmodul 72 (IPAe) ist aktiviert, das zweite Assistenzmodul 52 (IPAd) deaktiviert. Die Fernverwaltungseinheit 20 (elM) baut über die Schnittstelle 190 (ESipa) eine sichere Verbindung zu dem ersten Assistenzmodul 72 (IPAe) auf, ermittelt aus dem Aktivierungscode die Profilbereitstellungseinheit 10 (SM-DP+) und baut zu dieser über die Schnittstelle 100 (ES8+) ebenfalls eine sichere Verbindung auf. Die Profilbereitstellungseinheit 10 (SM-DP+) führt über die dann durchgängig sichere Verbindung eine wechselseitige Authentisierung mit dem eingebetteten Identifikationsmodul 70 (eUlCC) durch. Anschließend stellt die Profilbereitstellungseinheit 10 (SM-DP+) ein Profilpaket bereit und überträgt dieses an die Fernverwaltungseinheit 20 (elM). Diese stellt die zweite Betriebsart ein und übergibt das Profilpakt über das zweite Assistenzmodul 52 (IPAd) weiter an das eingebettete
Identifikationsmodul 70 (eUlCC), welches das Profil 80 installiert und ferner Verwaltungseinheit 20 (elM) und Profilbereitstellungsinstanz 10 (SM-DP+) benachrichtigt.
In einer dritten Ausführungsvariante 03 löst das zweite Assistenzmodul 52 (IPAd) den Ladevorgang aus, indem es feststellt, dass eine Bedingung für das Laden eines Profils 80 erfüllt ist, Schritt 1300. Das zweite Assistenzmodul 52 (IPAd) kontaktiert über die Seitenschnittstelle 170 die Fernverwaltungseinheit 20 (elM) und fordert einen Aktivierungscode an, Schritt 1310. Die Fernverwaltungseinheit 20 (elM) schickt über die Seitenschnittstelle 170 den Aktivierungscode, Schritt 1320.
Aus dem Aktivierungscode ermittelt das zweite Assistenzmodul 52 (IPAd) die zuständige Profilbereitstellungsinstanz 10 (SM-DP+) und baut über die Schnittstelle 120 (S9+) eine sichere Verbindung zu dieser auf. Den Aktivierungscode präsentiert das zweite Assistenzmodul 52 (IPAd) der Profilbereitstellungsinstanz (SM-DP+), Schritt 1400. Nach Durchführung einer wechselseitigen Authentisierung mit dem eingebetteten Identifikationsmodul 70 (eUlCC) stellt die Profilbereitstellungsinstanz 10 ein Profilpaket an das zweite Assistenzmodul 52 (IPAd) bereit, Schritt 1410. Das Profilpaket lädt das zweite Assistenzmodul 52 (IPAd) in das eingebettete Identifikationsmodul 70 (eUlCC), Schritt 1420. Das in dem Profilpaket enthaltene Profil 80 wird von dem eingebetteten Identifikationsmodul 70 (eUlCC) installiert.
Fernverwaltungseinheit 20 (elM) und Profilbereitstellungsinstanz 10 (SM-DP+) werden über die erfolgreiche Profileinrichtung informiert.
In einer zweckmäßigen Weiterbildung der Lösung wird innerhalb des Endgerätes 50 oder im eingebetteten Identifikationsmodul 70 (eUlCC) eine Anwendung ausgeführt, die den Status von im eingebetteten Identifikationsmodul 70 (eUlCC) gespeicherten Profilen 80 steuert. Eine solche Anwendung kann beispielsweise eine Anwendung sein, die den aktuellen Standort eines Endgerätes 50 erkennt und ein zu dem Standort passendes Profil 80 einstellt. Bei Vorliegen geeigneter Bedingungen schickt die Anwendung eine Nachricht an das erste Assistenzmodul 72 (IPAe), das daraufhin wiederum die Änderung des Profilstatus bewirkt.
In einer Weiterbildung der beschriebenen Lösung ist die Fernverwaltungseinheit 20 (elM) dazu ausgebildet, ein Reparaturprofil bereitzustellen, das bei Bedarf in ein eingebettetes Identifikationsmodul 70 (eUlCC) geladen wird. Das Laden des Reparaturprofils erfolgt wie vorstehend beschrieben.
In einer anderen Weiterbildung ist vorgesehen, dass im Endgerät 50 grundsätzlich nur ein erstes Assistenzmodul 72 (IPAe) bereitsteht und das zweite Assistenzmodul 52 (IPAd) erst eingerichtet wird, wenn erstmals ein Bedarf zum Laden eines Profils 80 auftritt.
Unter Beibehaltung des grundlegenden Gedankens, für die Ausführung von Profilverwaltungsaktionen ein erstes Assistenzmodul 72 und zweites Assistenzmodul 52 bereitzustellen, von denen eines im eingebetteten Identifikationsmodul 70 und das andere im Endgerät 50 ausgebildet ist, wobei das erste Assistenzmodul 72 die Ausführung einer Profilverwaltungsaktion bewirkt, wenn es sich um eine Profilstatusaktion handelt und wobei das zweite Assistenzmodul 52 die Ausführung einer Profilverwaltungsaktion bewirkt, wenn sie das Laden eines Profils beinhaltet, gestattet die beschriebene Lösung eine Reihe von Abwandlungen, die aus Gründen der Übersichtlichkeit nicht näher erläutert sind. So kann das Auslösen einer
Profilverwaltungsaktion aufgrund weiterer möglicher Ereigniseintritte erfolgen. Beispielsweise können zusätzliche Maßnahmen zur Absicherung von Kommunikationen vorgesehen sein oder gegebenenfalls auch weniger.
Claims
1. Endgerät mit einem eingebettetem Identifikationsmodul (70), das dazu eingerichtet ist Profilverwaltungsaktionen auszuführen, mittels derer ein in dem eingebetteten Identifikationsmodul (70) gespeichertes Telekommunikationsprofil (80) verändert oder ein neues Telekommunikationsprofil (80) geladen werden kann,
• wobei das eingebettete Identifikationsmodul (70) ein erstes Assistenzmodul (72) aufweist, das eine erste Schnittstelle (150) zu einer Fernverwaltungseinheit (20) bereitstellt,
• und das Endgerät (50) ein zweites Assistenzmodul (52) aufweist, das mit dem eingebetteten Identifikationsmodul (70) verbunden ist und eine zweite Schnittstelle (120) zu einer Profilbereitstellungsinstanz (10) bereitstellt,
• wobei zur gleichen Zeit entweder das erste Assistenzmodul (72) oder das zweite Assistenzmodul (52) aktiv ist,
• wobei das Endgerät (50) von der Fernverwaltungseinheit (20) Kommandodatensätze erhält, die Profilverwaltungsaktionen enthalten,
• wobei das erste Assistenzmodul (72) aktiv ist und die Ausführung einer Profilverwaltungsaktion bewirkt, wenn die Profilverwaltungsaktion eine Änderung des Zustands eines in dem eingebetteten Identifikationsmodul (70) gespeicherten Telekommunikationsprofils (80) betrifft,
• und wobei das zweite Assistenzmodul (52) aktiv ist und die Ausführung einer Profilverwaltungsaktion bewirkt, wenn diese das Laden eines neuen Profils betrifft.
2. Endgerät nach Anspruch 1, dadurch gekennzeichnet, dass das Kommandodatensätze mit Profilverwaltungsaktionen über die Schnittstelle (150) übertragen werden und im ersten Assistenzmodul (72) eingehen.
3. Endgerät nach Anspruch 1 oder 2, dadurch gekennzeichnet, dass das zweite Assistenzmodul (52) dazu eingerichtet ist einen Datenaustausch mit der Profilbereitstellungsinstanz (10) zu führen, um ein neues Profil (80) in das eingebettete Identifikationsmodul (70) zu laden.
4. Endgerät nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das erste Assistenzmodul (72) die Ausführung einer Profilverwaltungsaktion an das zweite Assistenzmodul (52) übergibt, wenn die Profilverwaltungsaktion das Laden eines Telekommunikationsprofils (80) betrifft.
5. Endgerät nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das erste Assistenzmodul (72) nach Ausführung einer Profilverwaltungsaktion eine Rückmeldung über die Ausführung an die Fernverwaltungseinheit (20) schickt.
6. Endgerät nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das zweite Assistenzmodul (52) eine Seitenschnittstelle (170) zu der Fernverwaltungseinheit (20) aufweist, die von der Fernverwaltungseinheit (20) die Anforderung eines Aktivierungscodes ermöglicht.
7. Endgerät nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass die Kommunikation zwischen dem ersten Assistenzmodul (72) und der Fernverwaltungseinheit (20) mittels eines ersten Protokolls erfolgt.
8. Endgerät nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass die Kommunikation zwischen dem zweiten Assistenzmodul (52) und der Profilbereitstellungsinstanz (10 mittels eines zweiten Protokolls erfolgt.
9. Endgerät nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass, das zweite Assistenzmodul (52) aktiviert ist, bis ein erstes Telekommunikationsprofil (80) in das eingebettete Identifikationsmodul (70) geladen wurde.
10. Endgerät einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das erste Assistenzmodul (72) aktiviert ist, sobald über das zweite Assistenzmodul (52) ein Telekommunikationsprofil (80) in das eingebettete Identifikationsmodul (70) geladen wurde.
11. Endgerät einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass die Aktivierung des ersten Assistenzmoduls (72)oder des zweiten Assistenzmoduls (52) aufgrund eines Kommandos von der Fernverwaltungseinheit (20) erfolgt.
12. Verfahren zur Verwaltung eines Telekommunikationsprofils in einem eingebettetem Identifikationsmodul (70) eines Endgerätes (50) mithilfe von Profilverwaltungsaktionen, mit folgenden Schritten:
• Einrichten eines ersten Assistenzmoduls (72) in dem Identifikationsmodul (70), wobei das erste Assistenzmodul (72) eine Schnittstelle (150) zu einer Fernverwaltungseinheit (20) bereitstellt,
• Einrichten eines zweiten Assistenzmoduls (52) in dem Endgerät (50), wobei das zweite Assistenzmodul (52) mit dem Identifikationsmodul (70) verbunden ist und eine Schnittstelle (120) zu einer Profilbereitstellungsinstanz (10) bereitstellt,
• Einrichten einer ersten Betriebsart, in der das erste Assistenzmodul (72) aktiviert und das zweite Assistenzmodul (52) deaktiviert ist,
• Einrichten einer zweiten Betriebsart, in der das zweite Assistenzmodul (52) aktiviert und das erste Assistenzmodul (72) deaktiviert ist,
• Übermitteln eines Kommandodatensatzes, das eine Profilverwaltungsaktion beinhaltet, von der Fernverwaltungseinheit (20) an das Endgerät (50),
• Ausführen der Profilverwaltungsaktion durch das erste Assistenzmodul (72) in der ersten Betriebsart, wenn die Profilverwaltungsaktion eine Änderung des Zustands eines in dem eingebetteten Identifikationsmodul (70) gespeicherten Telekommunikationsprofils (80) betrifft,
• Einstellung der zweiten Betriebsart und Ausführung der Profilverwaltungsaktion durch das zweite Assistenzmodul (52), wenn die Profilverwaltungsaktion das Laden eines neuen Profils (80) betrifft.
13. Verfahren nach Anspruch 12, dadurch gekennzeichnet, dass Kommandodatensätze, die eine Profilverwaltungsaktion beinhalten, im ersten Assistenzmodul (72) eingehen und eine Profilverwaltungsaktion an das zweite Assistenzmodul (52) übergeben und die zweite Betriebsart eingestellt wird, wenn die Profilverwaltungsaktion das Laden eines neuen Telekommunikationsprofils (80) betrifft.
14. Verfahren nach Anspruch 12 oder 13, dadurch gekennzeichnet, dass die Kommandodatensätze in der Fernverwaltungseinheit (20) aufgrund von über eine Nutzerschnittstelle eingegangenen Aufforderungen gebildet werden.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102022004853.1A DE102022004853B4 (de) | 2022-12-21 | 2022-12-21 | Endgerät mit einem Assistenzmodul zur Verwaltung von in dem Endgerät gespeicherten Telekommunikationsprofilen und Verwaltungsverfahren |
| PCT/DE2023/100985 WO2024132039A1 (de) | 2022-12-21 | 2023-12-20 | Endgerät mit einem assistenzmodul zur verwaltung von in dem endgerät gespeicherten telekommunikationsprofilen und verwaltungsverfahren |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4639934A1 true EP4639934A1 (de) | 2025-10-29 |
Family
ID=89618993
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP23840885.0A Pending EP4639934A1 (de) | 2022-12-21 | 2023-12-20 | Endgerät mit einem assistenzmodul zur verwaltung von in dem endgerät gespeicherten telekommunikationsprofilen und verwaltungsverfahren |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20260032420A1 (de) |
| EP (1) | EP4639934A1 (de) |
| CN (1) | CN120345274A (de) |
| DE (1) | DE102022004853B4 (de) |
| WO (1) | WO2024132039A1 (de) |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11595813B2 (en) * | 2018-01-15 | 2023-02-28 | Telefonaktiebolaget Lm Ericsson (Publ) | Profile handling of a communications device |
| EP4057661A1 (de) | 2021-03-09 | 2022-09-14 | Kigen (UK) Limited | System, modul, schaltung und verfahren |
| JP2024515008A (ja) * | 2021-04-23 | 2024-04-04 | サムスン エレクトロニクス カンパニー リミテッド | 電子装置及び電子装置に組み込み型加入者識別モジュールのプロファイルをインストールする方法 |
| US12095770B2 (en) | 2021-06-14 | 2024-09-17 | Hewlett Packard Enterprise Development Lp | Connecting internet of thing (IoT) devices to a wireless network |
| CN114125892B (zh) * | 2021-10-13 | 2024-10-01 | 东信和平科技股份有限公司 | eSIM远程配置管理方法、终端设备、融合RSP平台及系统 |
-
2022
- 2022-12-21 DE DE102022004853.1A patent/DE102022004853B4/de active Active
-
2023
- 2023-12-20 CN CN202380086928.3A patent/CN120345274A/zh active Pending
- 2023-12-20 WO PCT/DE2023/100985 patent/WO2024132039A1/de not_active Ceased
- 2023-12-20 EP EP23840885.0A patent/EP4639934A1/de active Pending
- 2023-12-20 US US19/139,579 patent/US20260032420A1/en active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| DE102022004853B4 (de) | 2024-07-11 |
| WO2024132039A1 (de) | 2024-06-27 |
| DE102022004853A1 (de) | 2024-06-27 |
| CN120345274A (zh) | 2025-07-18 |
| US20260032420A1 (en) | 2026-01-29 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE69319325T2 (de) | Prozeduren für zusätzliche dienste im verwaltungsverfahren von der besucherdatei (vlr) nach der heimatdatei (hlr) im globalen mobil-kommunikationssystem (gsm). | |
| EP3939344B1 (de) | Verfahren zum bereitstellen von subskriptions-profilen, teilnehmeridentitätsmodul und subskriptions-server | |
| DE69531698T2 (de) | Flusssteuerungsverfahren für kurznachrichtendienst an einen teilnehmer, dessen leitung besetzt ist | |
| DE60215335T2 (de) | Verfahren zum Erstellen eines anwendungseingeleiteten Rufs an eine Mobilstation in einem CAMEL-Netzwerk, und ein Telekommunikationssystem mit einem CAMEL-Netzwerk | |
| DE102022004853B4 (de) | Endgerät mit einem Assistenzmodul zur Verwaltung von in dem Endgerät gespeicherten Telekommunikationsprofilen und Verwaltungsverfahren | |
| EP2040447A1 (de) | Verfahren zum Herstellen einer Kommunikationsverbindung und Telekommunikationsanlage zur Durchführung des Verfahrens | |
| WO2016206813A1 (de) | Kommunizieren eines teilnehmeridentitätsmoduls zu einem server, insbesondere bei profilwechsel | |
| EP0806879A2 (de) | Testeinrichtung zur Überprüfung der Leitweglenkung und Gebührenerfassung in einem Mobilkommunikationsnetz und Verfahren zu dessen Betrieb | |
| DE60214688T2 (de) | Verfahren zur aktualisierung von programmen in einem netzwerkserver mit zugehörigem system und softwareprodukt | |
| WO2002032176A1 (de) | Verfahren zur positionsermittlung mindestens eines teilnehmergeräts eines funkkommunikationssystems sowie zugehöriges funkkommunikationssystem | |
| DE10142193A1 (de) | Verfahren zum Versenden von Zugangsdaten an eine insbesondere in einem Kraftfahrzeug befindliche Teilnehmerstation für eine spezielle Zugangsart zu einer Dienstleisterstation | |
| EP3918822A1 (de) | Verfahren und vorrichtungen zum verwalten von subskriptionsprofilen eines sicherheitselements | |
| DE60118512T2 (de) | System und Verfahren zur Dienststeuerung einer Mobilkommunikation | |
| DE19947083A1 (de) | Konfigurieren eines Telekommunikationsnetzes mit mehreren Netzregionen | |
| EP1658743B1 (de) | Verfahren, einrichtung und system zur regelgesteuerten verzögerten ausführung von software-download | |
| EP2613494B1 (de) | Vorrichtung zur Verfügungstellung einer Schnittstelle für eine Fernwartung von elektronischen, mit dem Internet verbundenen IP-Geräten und Verfahren zur Herstellung einer Kommunikationsverbindung für die Fernwartung von elektronischen, mit dem Internet verbundenen IP-Geräten über eine Schnittstelle | |
| EP1271881A1 (de) | Verfahren zur Übertragung von Daten | |
| DE10229879A1 (de) | Datenverarbeitungssystem mit Diensten zur Bereitstellung von Funktionalitäten | |
| DE10160526A1 (de) | Verfahren zum Betreiben eines mobilen Telekommunikationsgerätes nach mindestens zwei Mobilfunkstandards,entsprechende Vorrichtung sowie Steuerungssoftware-Programme | |
| DE102023124349B3 (de) | Exportverfahren für ein nutzer-identifikations-profil eines kommunikations-steuergeräts, sowie ein importverfahren für ein nutzer-identifikations-profil eines kommunikations-steuergeräts | |
| DE102022001848B3 (de) | Verfahren zum nutzerbezogenen Einrichten eines Endgerätes | |
| DE102024108995B3 (de) | Verfahren zum einrichten eines benutzergerätes sowie selbiges nebst computerprogramm, computerlesbarem datenträger und einrichtungsanordnung dafür | |
| EP3855866B1 (de) | Verbesserte ressourcennutzung bei speicherung von gtp-kontextinformationen in einem mobilfunknetz | |
| EP1424816B1 (de) | Verfahren zum Austausch von Daten zwischen Bluetooth-Geräten | |
| EP1187501A2 (de) | Verfahren und anordnung zum Übertragen einer schriftlichen Kurzinformation an ein Kommunikationsendgerät |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20250410 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) |