WO2018019999A1 - Profilautorisierungsserver für das herunterladen von sim profilen - Google Patents
Profilautorisierungsserver für das herunterladen von sim profilen Download PDFInfo
- Publication number
- WO2018019999A1 WO2018019999A1 PCT/EP2017/069173 EP2017069173W WO2018019999A1 WO 2018019999 A1 WO2018019999 A1 WO 2018019999A1 EP 2017069173 W EP2017069173 W EP 2017069173W WO 2018019999 A1 WO2018019999 A1 WO 2018019999A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- profile
- communication
- server
- request
- electronic
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
- H04W8/20—Transfer of user or subscriber data
- H04W8/205—Transfer to or from user equipment or user record carrier
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/30—Security of mobile devices; Security of mobile applications
- H04W12/35—Protecting application or service provisioning, e.g. securing SIM application provisioning
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0861—Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
Definitions
- eSIM electronic Subscriber Identification Module
- eSIMs Electronic subscriber identification modules
- Each eSIM requires one to communicate over a communications network
- Communication profile assigned to an operator of the communication network.
- the communication profile determines the communication capability, such as a data volume for the mobile equipped with an eSIM
- the electronic communication profile is through a mobile
- the present invention is based on the finding that the above object can be achieved by an intermediate instance which precedes the profile server and which authorizes the profile request of a user by means of a biometric feature of the user.
- the authorized profile request is transmitted to the profile server, together with the electronic identification of the subscriber identification module and possibly a digital signature of the intermediate instance.
- the profile server can verify the authorization of the profile request.
- the intermediate instance can be considered a Profile authorization server may be communicatively connected between the mobile communication device and the profile server.
- the invention relates to a profile authorization server for obtaining a communication profile for an electronic
- a subscriber identification module (eSIM) of a mobile communication device of a user comprising: a communication interface for receiving a profile request for the communication profile, for example an eSIM profile, wherein the profile request comprises an electronic identification of the electronic identification module, wherein the communication interface is further configured to be a biometric feature of User to receive; a processor configured to authorize the received profile request based on the received biometric feature to obtain an authorized profile request; wherein the communication interface is adapted to send the authorized profile request for the communication profile to a profile server via a communication network.
- eSIM subscriber identification module
- the profile authorization server is arranged in communication between the mobile communication device and the profile server and ensures that only authenticated or authorized profile requests are transmitted to the profile server.
- the communication interface is formed,
- the communication interface is for example a WiFi, LTE or UMTS communication interface.
- the communication interface is configured to associate with the authorized profile request a network address of the mobile
- the communication interface is formed
- the processor is configured to retrieve the biometric feature from the mobile communication device in response to receiving the profile request, and wherein the communication section is configured to receive the retrieved biometric feature, or wherein the profile request includes the biometric feature and the processor is configured; extract the biometric feature from the profile query.
- the processor is configured to compare the biometric feature with a pre-stored reference feature of the user and when the biometric feature matches the reference feature
- the communication interface is configured to communicate the biometric feature to an authentication server to authenticate the biometric feature, wherein the communication interface is configured to receive an authentication message indicating the successful authentication of the biometric feature from the authentication server, and wherein the processor is adapted to authorize the profile request in response to the receipt of the authentication message.
- the biometric feature is a user's fingerprint or vein history or image capture or iris capture.
- the invention relates to a profile server for providing a communication profile of a communication profile for an electronic
- Subscriber identification module of a mobile communication device of a
- a user comprising: a memory in which a plurality of communication profiles are stored; a communication interface, such as a
- Mobile radio interface to receive a profile request for a Communication profile for the electronic subscriber identification module, wherein the profile request an electronic identification of the electronic
- Subscriber identification module comprises; and a processor configured to verify the authorization of the profile request, wherein the processor is adapted to verify the electronic authorization of the profile request
- the processor is configured to authorize the
- the invention relates to a mobile communication device having an electronic subscriber identification module to which an electronic identification is assigned, wherein the mobile communication device is assigned to a user, comprising: a receiving device for receiving a biometric feature of the user; and a communication interface configured to send a profile request for an electronic communication profile to a profile server, the request comprising the electronic identification and the captured biometric feature, wherein the communication interface is further configured to receive the requested electronic communication profile.
- the recording device comprises a fingerprint scanner or a camera for recording the biometric feature, in particular an image of the person or an iris image of the user.
- the invention relates to a subnetwork of a
- the subnetwork comprises the profile server according to the second aspect, wherein the profile server can be reached via the profile authorization server,
- the invention relates to a method for obtaining a communication profile for an electronic subscriber identification module (eSIM) of a user's mobile communication device, comprising: receiving a profile request for the communication profile from the mobile communication device, the profile request comprising an electronic identification of the electronic identification module; Receiving a biometric feature of the person, in particular the mobile communication device; Authorizing the profile request based on the received biometric feature to obtain an authorized profile request; Sending the authorized profile request to a profile server managing electronic communication profiles; Receiving the electronic communication profile from the profile server in response to the sending of the authorized profile request; and forwarding the received electronic communication profile to the mobile communication device.
- eSIM electronic subscriber identification module
- the method may be performed by the subnetwork of the fourth aspect or by the servers of the first aspect and the second aspect.
- FIG. 3 shows a mobile communication device; and Fig. 4 is a subnetwork.
- FIG. 1 shows a profile authorization server 100 for procuring or providing a communication profile for an electronic subscriber identification module (eSIM).
- eSIM electronic subscriber identification module
- an exemplary illustrated mobile communication device 105 of a user having a communication interface 107 for receiving a profile request for the communication profile, the profile request having an electronic identification of the electronic identification module 103, wherein the communication interface 107 is further configured to receive a biometric feature of the user Processor 109, which is configured to authorize the received profile request based on the received biometric feature, to an authorized one
- eSIM electronic subscriber identification module
- Profile request to receive wherein the communication interface 107 is configured to send the authorized profile request for the communication profile to a profile server 1 1 1 shown as an example via a communication network.
- the profile server 1 1 1 for providing a communication profile of a communication profile for an electronic subscriber identification module (eSIM) of the exemplified mobile communication device 105 of a user, with a memory 1 13 in which a plurality of communication profiles is stored, a communication interface 1 15 for receiving a profile request for a communication profile for the electronic subscriber identification module 103, wherein the profile request is an electronic identification of the electronic
- eSIM electronic subscriber identification module
- Subscriber identification module 103 includes, and a processor 1 17, which is adapted to verify the authorization of the profile request, wherein the processor 1 17 is further formed, upon successful verification of the authorization of the
- Profile request the electronic communication profile from the memory 1 13 based on the electronic identification of the electronic
- Communication interface 1 15 is formed, the read-out electronic
- the profile server can be an eSIM profile server and can be in one
- FIG. 3 shows the mobile communication device 105 with an electronic
- Subscriber identification module 103 to which an electronic identification is assigned, wherein the mobile communication device 105 is assigned to a user, with a recording device 301 for recording a biometric feature of the user, and a communication interface 301 configured to send a profile request for an electronic communication profile to a profile server 1 1 1, the request comprising the electronic identification and the captured biometric feature, wherein the communication interface 301 is further configured to receive the requested electronic communication profile ,
- the profile authorization server 100 and the profile server 11 1 form a communication system for providing electronic
- Communication profiles in a communication network such as in an LTE or UMTS communication network.
- the authorization of the profile request may be by a
- the subnetwork 400 is, for example, a point-to-point subnetwork between the mobile communication device 105 and the profile authorization server 100.
- Subnetwork may include other network entities, such as a router or gateway or base station, which are not shown in FIG.
- the subnetwork 400 has, for example, its own network address and / or a network identifier for addressing the subnetwork 400.
- the subnetwork can be a slice of a 5G communication network
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Databases & Information Systems (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Die vorliegende Erfindung betrifft ein einen Profilautorisierungsserver (100) zur Beschaffung eines Kommunikationsprofils für ein elektronisches Teilnehmeridentifikationsmodul (eSIM) eines mobilen Kommunikationsgerätes eines Benutzers, mit: einer Kommunikationsschnittstelle (107) zum Empfangen einer Profilanfrage nach dem Kommunikationsprofil, wobei die Profilanfrage eine elektronische Identifikation des elektronischen Identifikationsmoduls (103) aufweist, wobei die Kommunikationsschnittstelle (107) ferner ausgebildet ist, ein biometrisches Merkmal des Benutzers zu empfangen; einem Prozessor (109), welcher ausgebildet ist, die empfangene Profilanfrage auf der Basis des empfangenen biometrischen Merkmals zu autorisieren, um eine autorisierte Profilanfrage zu erhalten; wobei die Kommunikationsschnittstelle (107) ausgebildet ist, die autorisierte Profilanfrage nach dem Kommunikationsprofil an einen Profilserver (111) über ein Kommunikationsnetzwerk auszusenden.
Description
PROFILAUTORISIERUNGSSERVER FÜR DAS HERUNTERLADEN VON SI M PROFILEN
Die vorliegende Erfindung betrifft das Gebiet der elektronischen
Teilnehmeridentifikationsmodule (eSIM: electronic Subscriber Identification Module). Elektronische Teilnehmeridentifikationsmodule (eSIMs) sind in mobilen
Kommunikationsgeräten als festverdatete Hardwareschaltungen implementiert. Für eine Kommunikation über ein Kommunikationsnetzwerk benötigt jedes eSIM ein
Kommunikationsprofil (eSIM-Profil), das einem Betreiber des Kommunikationsnetzwerks zugeordnet ist. Das Kommunikationsprofil bestimmt die Kommunikationsfähigkeit, wie beispielsweise ein Datenvolumen für das mit einem eSIM ausgestattete mobile
Kommunikationsgerät in einem Kommunikationsnetzwerk eines
Mobilfunknetzwerkbetreibers.
Üblicherweise wird das elektronische Kommunikationsprofil durch ein mobiles
Kommunikationsgerät von einem Profilserver, beispielsweise von einem SMDP+-
Profilserver abgerufen und für das elektronische Teilnehmeridentifikationsmodul aktiviert.
Es ist die Aufgabe der Erfindung, die Sicherheit des Abrufs eines elektronischen
Kommunikationsprofils von einem Profilserver, insbesondere für eSIM-Anwendungen, zu erhöhen.
Diese Aufgabe wird durch die Merkmale der unabhängigen Ansprüche gelöst. Vorteilhafte Weiterbildungsformen sind Gegenstand der abhängigen Ansprüche, der Figuren sowie der Beschreibung.
Die vorliegende Erfindung basiert auf der Erkenntnis, dass die obige Aufgabe durch eine Zwischeninstanz gelöst werden kann, welche dem Profilserver vorgeschaltet ist und welche die Profilanfrage eines Benutzers mittels eines biometrischen Merkmals des Benutzers autorisiert. Die autorisierte Profilanfrage wird an den Profilserver, zusammen mit der elektronischen Identifikation des Teilnehmeridentifikationsmoduls und ggf. einer digitalen Signatur der Zwischeninstanz, übermittelt. Auf diese Weise kann der Profilserver die Autorisierung der Profilanfrage verifizieren. Die Zwischeninstanz kann als ein
Profilautorisierungsserver kommunikationstechnisch zwischen dem mobilen Kommunikationsgerät und dem Profilserver geschaltet sein.
Gemäß einem ersten Aspekt betrifft die Erfindung einen Profilautorisierungsserver zur Beschaffung eines Kommunikationsprofils für ein elektronisches
Teilnehmeridentifikationsmodul (eSIM) eines mobilen Kommunikationsgerätes eines Benutzers, mit: einer Kommunikationsschnittstelle zum Empfangen einer Profilanfrage nach dem Kommunikationsprofil, beispielswiese ein eSIM-Profil, wobei die Profilanfrage eine elektronische Identifikation des elektronischen Identifikationsmoduls aufweist, wobei die Kommunikationsschnittstelle ferner ausgebildet ist, ein biometrisches Merkmal des Benutzers zu empfangen; einem Prozessor, welcher ausgebildet ist, die empfangene Profilanfrage auf der Basis des empfangenen biometrischen Merkmals zu autorisieren, um eine autorisierte Profilanfrage zu erhalten; wobei die Kommunikationsschnittstelle ausgebildet ist, die autorisierte Profilanfrage nach dem Kommunikationsprofil an einen Profilserver über ein Kommunikationsnetzwerk auszusenden.
Der Profilautorisierungsserver ist kommunikationstechnisch zwischen dem mobilen Kommunikationsgerät und dem Profilserver angeordnet und stellt sicher, dass nur authentifizierte bzw. autorisierte Profilanfragen an den Profilserver übermittelt werden. In einer Ausführungsform ist die Kommunikationsschnittstelle ausgebildet ist,
ansprechend auf das Aussenden der autorisierten Profilanfrage das Kommunikationsprofil von dem Profilserver zu empfangen und das empfangene Kommunikationsprofil an das mobile Endgerät weiterzuleiten. Die Kommunikationsschnittstelle ist beispielsweise eine WiFi, LTE- oder UMTS- Kommunikationsschnittstelle.
In einer Ausführungsform ist die Kommunikationsschnittstelle ausgebildet, zusammen mit der autorisierten Profilanfrage eine Netzwerkadresse des mobilen
Kommunikationsgerätes an den Profilserver zu übermitteln.
In einer Ausführungsform ist die Kommunikationsschnittstelle ausgebildet, die
Profilanfrage mit einer digitalen Signatur des Profilautonsierungsservers zu signieren, um die autorisierte Profilanfrage zu erhalten.
In einer Ausführungsform ist der Prozessor ausgebildet, ansprechend auf den Empfang der Profilanfrage das biometrische Merkmal von dem mobilen Kommunikationsgerät abzurufen und wobei die Kommunikationsschnittelle ausgebildet ist, das abgerufene biometrische Merkmal zu empfangen, oder wobei die Profilanfrage das biometrische Merkmal enthält und der Prozessor ausgebildet ist, das biometrische Merkmal aus der Profilabfrage zu extrahieren.
In einer Ausführungsform ist der Prozessor ausgebildet, das biometrische Merkmal mit einem vorgespeicherten Referenzmerkmal des Benutzers zu vergleichen und bei einer Übereinstimmung des biometrischen Merkmals mit dem Referenzmerkmal die
Profilanfrage zu autorisieren.
In einer Ausführungsform ist die Kommunikationsschnittstelle ausgebildet, das biometrische Merkmal an einen Authentifizierungsserver zu übermitteln, um das biometrische Merkmal zu authentifizieren, wobei die Kommunikationsschnittstelle ausgebildet ist, eine Authentifikationsnachricht, welche die erfolgreiche Authentifizierung des biometrischen Merkmals anzeigt, von dem Authentifizierungsserver zu empfangen, und wobei der Prozessor ausgebildet ist, die Profilanfrage ansprechend auf den Empfang der Authentifikationsnachricht zu autorisieren.
In einer Ausführungsform ist das biometrische Merkmal ein Fingerabdruck oder ein Venenverlauf oder eine Bildaufnahme des Benutzers oder eine Iris-Aufnahme des Benutzers.
Gemäß einem zweiten Aspekt betrifft die Erfindung einen Profilserver zur Bereitstellung eines Kommunikationsprofils eines Kommunikationsprofils für ein elektronisches
Teilnehmeridentifikationsmodul (eSIM) eines mobilen Kommunikationsgerätes eines
Benutzers, mit: einem Speicher, in welchem einer Mehrzahl von Kommunikationsprofilen gespeichert ist; einer Kommunikationsschnittstelle, beispielsweise einer
Mobilfunkschnittstelle, zum Empfangen einer Profilanfrage nach einem
Kommunikationsprofil für das elektronische Teilnehmeridentifikationsmodul, wobei die Profilanfrage eine elektronische Identifikation des elektronischen
Teilnehmeridentifikationsmoduls umfasst; und einem Prozessor, welche ausgebildet ist, die Autorisierung der Profilanfrage zu verifizieren, wobei der Prozessor ausgebildet ist, bei erfolgreicher Überprüfung der Autorisierung der Profilanfrage das elektronische
Kommunikationsprofil aus dem Speicher auf der Basis der elektronischen Identifikation des elektronischen Teilnehmeridentifikationsmoduls aus dem Speicher auszulesen; und wobei die Kommunikationsschnittstelle ausgebildet ist, das ausgelesene elektronische Kommunikationsprofil über ein Kommunikationsnetzwerk auszusenden. In einer Ausführungsform ist der Prozessor ausgebildet, die Autorisierung der
empfangenen Profilanfrage durch Überprüfung einer digitalen Signatur der Profilanfrage zu verifizieren.
Gemäß einem dritten Aspekt betrifft die Erfindung ein mobiles Kommunikationsgerät mit einem elektronischen Teilnehmeridentifikationsmodul, welchem eine elektronische Identifikation zugeordnet ist, wobei das mobile Kommunikationsgerät einem Benutzer zugeordnet ist, mit: einer Aufnahmevorrichtung zur Aufnahme eines biometrischen Merkmals des Benutzers; und einer Kommunikationsschnittstelle, welche ausgebildet ist, eine Profilanfrage nach einem elektronischen Kommunikationsprofil an einen Profilserver auszusenden, wobei die Anfrage die elektronische Identifikation und das aufgenommene biometrische Merkmal aufweist, wobei die Kommunikationsschnittstelle ferner ausgebildet ist, das angeforderte elektronische Kommunikationsprofil zu empfangen.
In einer Ausführungsform umfasst die Aufnahmevorrichtung ein Fingerabdruckscanner oder eine Kamera zur Aufnahme des biometrischen Merkmals, insbesondere eines Bildes der Person oder eines Iris-Bildes des Benutzers.
Gemäß einem vierten Aspekt betrifft die Erfindung ein Subnetzwerk eines
Kommunikationsnetzwerks mit einer Mehrzahl von Punkt-Zu-Punkt-Netzwerken, insbesondere ein Slice eines 5G-Kommunukationsnetzwerks, mit: dem
Profilautorisierungsserver nach dem ersten Aspekt, wobei der Profilautorisierungsserver ausschließlich über das Subnetzwerk adressierbar ist.
In einer Ausführungsform umfasst das Subnetzwerk den Profilserver nach dem zweiten Aspekt, wobei der Profilserver über den Profilautorisierungsserver erreichbar,
insbesondere ausschließlich über den Profilautorisierungsserver erreichbar ist.
Gemäß einem fünften Aspekt betrifft die Erfindung ein Verfahren zum Beschaffen eines Kommunikationsprofils für ein elektronisches Teilnehmeridentifikationsmodul (eSIM) eines mobilen Kommunikationsgerätes eines Benutzers, mit: Empfangen einer Profilanfrage nach dem Kommunikationsprofil von dem mobilen Kommunikationsgerät, wobei die Profilanfrage eine elektronische Identifikation des elektronischen Identifikationsmoduls aufweist; Empfangen eines biometrischen Merkmals der Person, insbesondere von dem mobilem Kommunikationsgerät; Autorisieren der Profilanfrage auf der Basis des empfangenen biometrischen Merkmals, um eine autorisierte Profilanfrage zu erhalten; Aussenden der autorisierten Profilanfrage an einen Profilserver, welcher elektronische Kommunikationsprofile verwaltet; Empfangen des elektronischen Kommunikationsprofils von dem Profilserver ansprechend auf das Aussenden der autorisierten Profilanfrage; und Weiterleiten des empfangenen elektronischen Kommunikationsprofils an das mobile Kommunikationsgerät.
Das Verfahren kann durch das Subnetzwerk nach dem vierten Aspekt oder durch die Server nach dem ersten Aspekt und zweiten Aspekt ausgeführt werden.
Weitere Ausführungsbeispiele der Erfindung werden Bezug nehmend auf die beiliegenden Figuren erläutert. Es zeigen:
Fig. 1 einen Profilautorisierungsserver;
Fig. 2 einen Profilserver;
Fig. 3 ein mobiles Kommunikationsgerät; und Fig. 4 ein Subnetzwerk.
Fig. 1 zeigt einen Profilautorisierungsserver 100 zur Beschaffung bzw. zur Bereitstellung eines Kommunikationsprofils für ein elektronisches Teilnehmeridentifikationsmodul (eSIM)
eines beispielhaft dargestellten mobilen Kommunikationsgerätes 105 eines Benutzers, mit einer Kommunikationsschnittstelle 107 zum Empfangen einer Profilanfrage nach dem Kommunikationsprofil, wobei die Profilanfrage eine elektronische Identifikation des elektronischen Identifikationsmoduls 103 aufweist, wobei die Kommunikationsschnittstelle 107 ferner ausgebildet ist, ein biometrisches Merkmal des Benutzers zu empfangen, einem Prozessor 109, welcher ausgebildet ist, die empfangene Profilanfrage auf der Basis des empfangenen biometrischen Merkmals zu autorisieren, um eine autorisierte
Profilanfrage zu erhalten, wobei die Kommunikationsschnittstelle 107 ausgebildet ist, die autorisierte Profilanfrage nach dem Kommunikationsprofil an einen beispielhaft dargestellten Profilserver 1 1 1 über ein Kommunikationsnetzwerk auszusenden.
Fig. 2 zeigt den Profilserver 1 1 1 zur Bereitstellung eines Kommunikationsprofils eines Kommunikationsprofils für ein elektronisches Teilnehmeridentifikationsmodul (eSIM) des beispielhaft dargestellten mobilen Kommunikationsgerätes 105 eines Benutzers, mit einem Speicher 1 13, in welchem einer Mehrzahl von Kommunikationsprofilen gespeichert ist, einer Kommunikationsschnittstelle 1 15 zum Empfangen einer Profilanfrage nach einem Kommunikationsprofil für das elektronische Teilnehmeridentifikationsmodul 103, wobei die Profilanfrage eine elektronische Identifikation des elektronischen
Teilnehmeridentifikationsmoduls 103 umfasst, und einem Prozessor 1 17, welcher ausgebildet ist, die Autorisierung der Profilanfrage zu verifizieren, wobei der Prozessor 1 17 ferner ausgebildet ist, bei erfolgreicher Überprüfung der Autorisierung der
Profilanfrage das elektronische Kommunikationsprofil aus dem Speicher 1 13 auf der Basis der elektronischen Identifikation des elektronischen
Teilnehmeridentifikationsmoduls 103 auszulesen, und wobei die
Kommunikationsschnittstelle 1 15 ausgebildet ist, das ausgelesene elektronische
Kommunikationsprofil über ein Kommunikationsnetzwerk auszusenden.
Der Profilserver kann ein eSIM-Profilserver sein und kann in einem
Kommunikationsnetzwerk angeordnet sein. Fig. 3 zeigt das mobile Kommunikationsgerät 105 mit einem elektronischen
Teilnehmeridentifikationsmodul 103, welchem eine elektronische Identifikation zugeordnet ist, wobei das mobile Kommunikationsgerät 105 einem Benutzer zugeordnet ist, mit einer Aufnahmevorrichtung 301 zur Aufnahme eines biometrischen Merkmals des Benutzers,
und einer Kommunikationsschnittstelle 301 , welche ausgebildet ist, eine Profilanfrage nach einem elektronischen Kommunikationsprofil an einen Profilserver 1 1 1 auszusenden, wobei die Anfrage die elektronische Identifikation und das aufgenommene biometrische Merkmal aufweist, wobei die Kommunikationsschnittstelle 301 ferner ausgebildet ist, das angeforderte elektronische Kommunikationsprofil zu empfangen.
In einer Ausführungsform bilden der Profilautorisierungsserver 100 und der Profilserver 1 1 1 ein Kommunikationssystem zur Bereitstellung von elektronischen
Kommunikationsprofilen in einem Kommunikationsnetzwerk, wie beispielsweise in einem LTE- oder UMTS-Kommunikationsnetzwerk.
In einer Ausführungsform kann die Autorisierung der Profilanfrage durch einen
elektronischen Dienst erfolgen, welcher durch das in Fig. 4 dargestellte Subnetzwerk 400 mit dem Profilautorisierungsserver 100 und, optional, mit dem Profilserver 1 1 1 , welcher dem Profilautorisierungsserver 100 nachgeschaltet ist, bereitgestellt ist.
Das Subnetzwerk 400 ist beispielsweise ein Punkt-zu-Punkt-Subnetzwerk zwischen dem mobilen Kommunikationsgerät 105 und dem Profilautorisierungsserver 100. Das
Subnetzwerk kann weitere Netzwerkentitäten wie beispielsweise einen Router oder ein Gateway oder eine Basisstation aufweisen, welche in Fig. 4 nicht dargestellt sind.
Das Subnetzwerk 400 hat beispielsweise eine eigene Netzwerkadresse und/oder einen Netzwerk-Identifizierer für die Adressierung des Subnetzwerks 400 aufweisen.
Das Subnetzwerk kann ein Slice eines 5G-Kommunikationsnetzwerks sein,
Claims
1 . Profilautorisierungsserver (100) zur Beschaffung eines Kommunikationsprofils für ein elektronisches Teilnehmeridentifikationsmodul (eSIM) eines mobilen
Kommunikationsgerätes eines Benutzers, mit: einer Kommunikationsschnittstelle (107) zum Empfangen einer Profilanfrage nach dem Kommunikationsprofil, wobei die Profilanfrage eine elektronische Identifikation des elektronischen Identifikationsmoduls (103) aufweist, wobei die
Kommunikationsschnittstelle (107) ferner ausgebildet ist, ein biometrisches Merkmal des Benutzers zu empfangen; einem Prozessor (109), welcher ausgebildet ist, die empfangene Profilanfrage auf der Basis des empfangenen biometrischen Merkmals zu autorisieren, um eine autorisierte Profilanfrage zu erhalten; wobei die Kommunikationsschnittstelle (107) ausgebildet ist, die autorisierte Profilanfrage nach dem Kommunikationsprofil an einen Profilserver (1 1 1 ) über ein Kommunikationsnetzwerk auszusenden.
2. Profilautorisierungsserver (100) nach Anspruch 1 , wobei die
Kommunikationsschnittstelle (107) ausgebildet ist, ansprechend auf das Aussenden der autorisierten Profilanfrage das Kommunikationsprofil von dem Profilserver (1 1 1 ) zu empfangen und das empfangene Kommunikationsprofil an das mobile
Kommunikationsgerät (105) weiterzuleiten.
3. Profilautorisierungsserver (100) nach Anspruch 1 oder 2, wobei die
Kommunikationsschnittstelle (107) ausgebildet ist, zusammen mit der autorisierten Profilanfrage eine Netzwerkadresse des mobilen Kommunikationsgerätes (105) an den Profilserver (1 1 1 ) zu übermitteln.
4. Profilautorisierungsserver (100) nach einem der vorstehenden Ansprüche, wobei die Kommunikationsschnittstelle (107) ausgebildet ist, die Profilanfrage mit einer digitalen
Signatur des Profilautorisierungsservers (100) zu signieren, um die autorisierte
Profilanfrage zu erhalten.
5. Profilautorisierungsserver (100) nach einem der vorstehenden Ansprüche, wobei der Prozessor (109) ausgebildet ist, ansprechend auf den Empfang der Profilanfrage das biometrische Merkmal von dem mobilen Kommunikationsgerät (105) abzurufen, wobei die Kommunikationsschnittelle (107) ausgebildet ist, das abgerufene biometrische Merkmal zu empfangen, oder wobei die Profilanfrage das biometrische Merkmal enthält und der Prozessor (109) ausgebildet ist, das biometrische Merkmal aus der Profilabfrage zu extrahieren.
6. Profilautorisierungsserver (100) nach einem der vorstehenden Ansprüche, wobei der Prozessor (109) ausgebildet ist, das biometrische Merkmal mit einem
vorgespeicherten Referenzmerkmal des Benutzers zu vergleichen und bei einer
Übereinstimmung des biometrischen Merkmals mit dem Referenzmerkmal die
Profilanfrage zu autorisieren.
7. Profilautorisierungsserver (100) nach einem der vorstehenden Ansprüche, wobei die Kommunikationsschnittstelle (107) ausgebildet ist, das biometrische Merkmal an einen Authentifizierungsserver zu übermitteln, um das biometrische Merkmal zu authentifizieren, wobei die Kommunikationsschnittstelle (107) ferner ausgebildet ist, eine
Authentifikationsnachricht, welche die erfolgreiche Authentifizierung des biometrischen Merkmals anzeigt, von dem Authentifizierungsserver zu empfangen, und wobei der Prozessor (109) ausgebildet ist, die Profilanfrage ansprechend auf den Empfang der Authentifikationsnachricht zu autorisieren.
8. Profilautorisierungsserver (100) nach einem der vorstehenden Ansprüche, wobei das biometrische Merkmal ein Fingerabdruck oder ein Venenverlauf oder eine
Bildaufnahme des Benutzers oder eine Iris-Aufnahme des Benutzers ist.
9. Profilserver (1 1 1 ) zur Bereitstellung eines Kommunikationsprofils eines
Kommunikationsprofils für ein elektronisches Teilnehmeridentifikationsmodul (eSIM) eines mobilen Kommunikationsgerätes (105) eines Benutzers, mit:
einem Speicher (1 13), in welchem einer Mehrzahl von Kommunikationsprofilen gespeichert ist; einer Kommunikationsschnittstelle (1 15) zum Empfangen einer Profilanfrage nach einem Kommunikationsprofil für das elektronische Teilnehmeridentifikationsmodul (103), wobei die Profilanfrage eine elektronische Identifikation des elektronischen
Teilnehmeridentifikationsmoduls (103) umfasst; und einem Prozessor (1 17), welcher ausgebildet ist, die Autorisierung der Profilanfrage zu verifizieren, wobei der Prozessor (1 17) ferner ausgebildet ist, bei erfolgreicher
Überprüfung der Autorisierung der Profilanfrage das elektronische Kommunikationsprofil aus dem Speicher (1 13) auf der Basis der elektronischen Identifikation des elektronischen Teilnehmeridentifikationsmoduls (103) auszulesen; und wobei die Kommunikationsschnittstelle (1 15) ausgebildet ist, das ausgelesene elektronische Kommunikationsprofil über ein Kommunikationsnetzwerk auszusenden.
10. Profilserver (1 1 1 ) nach Anspruch 9, wobei der Prozessor (1 17) ausgebildet ist, die Autorisierung der empfangenen Profilanfrage durch Überprüfung einer digitalen Signatur der Profilanfrage zu verifizieren.
1 1 . Mobiles Kommunikationsgerät (105) mit einem elektronischen
Teilnehmeridentifikationsmodul (103), welchem eine elektronische Identifikation zugeordnet ist, wobei das mobile Kommunikationsgerät (105) einem Benutzer zugeordnet ist, mit: einer Aufnahmevorrichtung (301 ) zur Aufnahme eines biometrischen Merkmals des Benutzers; und einer Kommunikationsschnittstelle (301 ), welche ausgebildet ist, eine Profilanfrage nach einem elektronischen Kommunikationsprofil an einen Profilserver (1 1 1 ) auszusenden, wobei die Anfrage die elektronische Identifikation und das aufgenommene biometrische Merkmal aufweist, wobei die Kommunikationsschnittstelle (301 ) ferner ausgebildet ist, das angeforderte elektronische Kommunikationsprofil zu empfangen.
12. Mobiles Kommunikationsgerät (105) nach Anspruch 1 1 , wobei die Aufnahmevorrichtung (301 ) ein Fingerabdruckscanner oder eine Kamera zur Aufnahme des biometrischen Merkmals, insbesondere eines Bildes der Person oder eines Iris-Bildes des Benutzers, aufweist.
13. Subnetzwerk (401 ) eines Kommunikationsnetzwerks mit einer Mehrzahl von Punkt-Zu-Punkt-Netzwerken, insbesondere ein Slice eines 5G- Kommunukationsnetzwerks, mit: dem Profilautonsierungsserver (100) nach einem der Ansprüche 1 bis 8, wobei der
Profilautonsierungsserver (100) ausschließlich über das Subnetzwerk (401 ) adressierbar ist.
14. Subnetzwerk (401 ) nach Anspruch 13, mit dem Profilserver (1 1 1 ) nach einem der Ansprüche 9 oder 10, wobei der Profilserver (1 1 1 ) über den Profilautonsierungsserver
(100) erreichbar, insbesondere ausschließlich über den Profilautonsierungsserver erreichbar ist.
15. Verfahren zum Beschaffen eines Kommunikationsprofils für ein elektronisches Teilnehmeridentifikationsmodul (103) eines mobilen Kommunikationsgerätes (105) eines
Benutzers, mit:
Empfangen einer Profilanfrage nach dem Kommunikationsprofil von dem mobilen Kommunikationsgerät (105), wobei die Profilanfrage eine elektronische Identifikation des elektronischen Identifikationsmoduls (103) aufweist;
Empfangen eines biometrischen Merkmals der Person, insbesondere von dem mobilem Kommunikationsgerät (105); Autorisieren der Profilanfrage auf der Basis des empfangenen biometrischen Merkmals, um eine autorisierte Profilanfrage zu erhalten;
Aussenden der autorisierten Profilanfrage an einen Profilserver (1 1 1 ), welcher elektronische Kommunikationsprofile verwaltet;
Empfangen des elektronischen Kommunikationsprofils von dem Profilserver (1 1 1 ) ansprechend auf das Aussenden der autorisierten Profilanfrage; und
Weiterleiten des empfangenen elektronischen Kommunikationsprofils an das mobile Kommunikationsgerät (105).
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP16182103.8A EP3276998A1 (de) | 2016-07-29 | 2016-07-29 | Profilautorisierungsserver für das herunterladen von sim profilen |
| EP16182103.8 | 2016-07-29 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2018019999A1 true WO2018019999A1 (de) | 2018-02-01 |
Family
ID=56615844
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/EP2017/069173 Ceased WO2018019999A1 (de) | 2016-07-29 | 2017-07-28 | Profilautorisierungsserver für das herunterladen von sim profilen |
Country Status (2)
| Country | Link |
|---|---|
| EP (1) | EP3276998A1 (de) |
| WO (1) | WO2018019999A1 (de) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115484585A (zh) * | 2020-12-24 | 2022-12-16 | 恒宝股份有限公司 | 用户配置文件下载方法、装置、智能卡及存储介质 |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102018207161B4 (de) * | 2018-05-08 | 2022-05-05 | Bayerische Motoren Werke Aktiengesellschaft | Kommunikation in einem Mobilfunknetz |
| CN120676038A (zh) | 2019-06-21 | 2025-09-19 | 华为技术有限公司 | 一种eSIM换卡方法及相关设备 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20080051062A1 (en) * | 2006-08-28 | 2008-02-28 | Samsung Electronics Co., Ltd. | Apparatus and method for downloading sim data in mobile communication system |
| US20090163175A1 (en) * | 2007-12-24 | 2009-06-25 | Guangming Shi | Virtual sim card for mobile handsets |
| US20160006728A1 (en) * | 2014-07-01 | 2016-01-07 | Samsung Electronics Co., Ltd. | Method and apparatus for installing profile for euicc |
-
2016
- 2016-07-29 EP EP16182103.8A patent/EP3276998A1/de not_active Withdrawn
-
2017
- 2017-07-28 WO PCT/EP2017/069173 patent/WO2018019999A1/de not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20080051062A1 (en) * | 2006-08-28 | 2008-02-28 | Samsung Electronics Co., Ltd. | Apparatus and method for downloading sim data in mobile communication system |
| US20090163175A1 (en) * | 2007-12-24 | 2009-06-25 | Guangming Shi | Virtual sim card for mobile handsets |
| US20160006728A1 (en) * | 2014-07-01 | 2016-01-07 | Samsung Electronics Co., Ltd. | Method and apparatus for installing profile for euicc |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115484585A (zh) * | 2020-12-24 | 2022-12-16 | 恒宝股份有限公司 | 用户配置文件下载方法、装置、智能卡及存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| EP3276998A1 (de) | 2018-01-31 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP2235978B1 (de) | Verfahren zur verwaltung der autorisierung von mobiltelefonen mit und ohne sim-karte | |
| EP2865198B1 (de) | Verfahren zum eintragen von kennungsdaten eines fahrzeugs in eine benutzerdatenbank einer internet-servereinrichtung | |
| EP3198903B1 (de) | Verfahren und vorrichtungen zum bereitstellen eines subskriptionsprofils auf einem mobilen endgerät | |
| EP2966605B1 (de) | Verfahren und System zur Authentifizierung eines Benutzers | |
| DE102012103106A1 (de) | Verfahren zum Authentifizieren eines Nutzers an einem Dienst auf einem Diensteserver, Applikation und System | |
| EP2632104B1 (de) | Verfahren und Telekommunikationssystem zur Anmeldung eines Nutzers an einem gesicherten personalisierten IPTV-Dienst | |
| WO2018019999A1 (de) | Profilautorisierungsserver für das herunterladen von sim profilen | |
| EP2654365B1 (de) | Konfiguration eines Endgerätes für einen Zugriff auf ein leitungsloses Kommunikationsnetz | |
| WO2016050333A1 (de) | Verfahren und system zum personalisieren eines sicherheitselements eines endgeräts | |
| DE102018207161A1 (de) | Kommunikation in einem Mobilfunknetz | |
| EP2835946A1 (de) | Verfahren zur Personalisierung von Cloud basierenden Web RCS-Clients | |
| DE102015219365B4 (de) | Erstellen einer Kommunikationsverbindung zwischen Mobilgerät und Fahrzeug | |
| EP2575385A1 (de) | Verfahren zur Initialisierung und/oder Aktivierung wenigstens eines Nutzerkontos, zum Durchführen einer Transaktion, sowie Endgerät | |
| DE102011007534A1 (de) | Datenübermittlung zu einem Identifizierungsmodul in einem Mobilfunkendgerät | |
| EP1519603A1 (de) | Verfahren zur Authentisierung eines Teilnehmers für einen über ein Kommunikationssystem angebotenen Dienst | |
| WO2014117939A1 (de) | Verfahren zum zugriff auf einen dienst eines servers über eine applikation eines endgeräts | |
| DE102013202426A1 (de) | Verfahren zum Ermöglichen einer Datenkommunikation zwischen einer Kommunikationseinrichtung eines Kraftfahrzeugs und einem Internetserver und entsprechendes System | |
| EP2456157B1 (de) | Schutz der Privatsphäre bei der Anmeldung eines Nutzers an einem gesicherten Webdienst mittels eines Mobilfunkgerätes | |
| DE10138381B4 (de) | Computersystem und Verfahren zur Datenzugriffskontrolle | |
| EP3853752B1 (de) | Authentifizieren eines nutzers einer softwareapplikation | |
| EP4203387B1 (de) | Verfahren und system zur authentifizierung eines endgeräts eines nutzers | |
| DE10225784A1 (de) | Verfahren und Vorrichtungen zum Aufbau einer Kommunikationsverbindung zwischen einer Zentrale und einem Endgerät | |
| DE102006060967A1 (de) | Überprüfung von Authentisierungsfunktionen | |
| DE102020201470A1 (de) | Verfahren zum Authentifizieren eines Benutzers an einem digitalen Fahrtenschreiber eines Fahrzeugs mittels einer Mobilvorrichtung, eines digitalen Fahrtenschreibers, einer Mobilvorrichtung und einer Datenbankvorrichtung | |
| DE102012007430A1 (de) | System und Verfahren zur sicheren Kommunikation |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 17751055 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 17751055 Country of ref document: EP Kind code of ref document: A1 |