EP3560226A1 - Procédé d'obtention d'un profil d'accès à un réseau de télécommunications - Google Patents
Procédé d'obtention d'un profil d'accès à un réseau de télécommunicationsInfo
- Publication number
- EP3560226A1 EP3560226A1 EP17825898.4A EP17825898A EP3560226A1 EP 3560226 A1 EP3560226 A1 EP 3560226A1 EP 17825898 A EP17825898 A EP 17825898A EP 3560226 A1 EP3560226 A1 EP 3560226A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- network
- profile
- access
- initial
- new
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
- H04W8/20—Transfer of user or subscriber data
- H04W8/205—Transfer to or from user equipment or user record carrier
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/069—Authentication using certificates or pre-shared keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W84/00—Network topologies
- H04W84/02—Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
- H04W84/04—Large scale networks; Deep hierarchical networks
- H04W84/042—Public Land Mobile systems, e.g. cellular systems
Definitions
- the invention relates to the field of telecommunications.
- It relates more particularly to a method for obtaining a profile for accessing a mobile network from a mobile device.
- a subscriber To access a mobile network, a subscriber must have on his mobile equipment a network access application and associated data. These elements are called “operator credentials”, or “operator profile”, or “network access profile”. They include data such as a subscriber identifier, generally referred to as “IMSI” (for "International Mobile Subscriber Identity”), and a secret key, denoted Kj key for 2G networks and K key for 3G and 4G networks. , whose knowledge is shared between the nominal mobile network, or "HPLMN" ("Home Public Land Mobile Network”), or subscriber's "home” network, and a subscriber card type security module, included in mobile equipment.
- IMSI International Mobile Subscriber Identity
- the subscriber is authenticated by the operator of the nominal network responsible for subscription when accessing the nominal network or a visited network.
- the subscriber To access a mobile network, the subscriber must have an access profile associated with a subscription he has subscribed. Otherwise it does not get access to the network, except for emergency calls, according to the regulations of the country visited.
- UICC type In the case of a removable conventional security module, UICC type, generally called “SIM” card (the “Subscriber Identity Module”), the profile of the operator is usually installed in the security module before acquisition mobile equipment by the subscriber.
- SIM Subscriber Identity Module
- embedded security module of "eUICC” type (for “embedded UICC”), or immovable SIM card
- the profile can be installed before acquisition of the equipment by a user or later, once the equipment mobile in the possession of the user.
- the user of the mobile equipment can control, via an interface of the mobile equipment after subscription of a subscription on a portal of the operator, or when subscribing in an operator's shop or a reseller, downloading the access profile prepared by the operator for that subscriber in the security module.
- This mode of operation offers a certain flexibility during an initial subscription, or during a change of operator.
- the access profile prepared by the operator at the time of the subscription is then sent to the security module through an Internet connection of the mobile equipment, or through the connectivity of an existing operator, when replacing a profile associated with a previous operator.
- a local profile manager (LPA) installed on the mobile device retrieves the profile from the operator via the Internet connection and installs it on the eUICC card included in the equipment. .
- LPA local profile manager
- After installing the access profile on the security module it is activated.
- the subscriber can then authenticate with the operator of the mobile network to access the network of this operator and associated services.
- the security module is authenticated with a card certificate containing its physical identifier EID (for "eUICC Identifier"). This allows the operator to create an access profile that is only intended for this card, to the exclusion of any other, in the context of particularly secure procedures.
- the profile corresponding to a subscription that has been subscribed beforehand to an identified operator must be installed on the security module before any access to the network. Either the profile is preinstalled, or you need existing cellular connectivity or Internet to install the profile.
- One of the aims of the invention is to remedy the shortcomings / disadvantages of the state of the art and / or to make improvements thereto.
- the invention proposes a method for obtaining a profile of access to a telecommunications network by mobile equipment, the method comprising:
- said new access profile comprising a new subscriber identifier and a new secret key, said new profile being arranged to access said network.
- the method provides the ability to obtain a mobile network access profile from an operator, without initially having existing connectivity with another operator, or Internet access to receive the profile of a mobile network. access.
- the mobile equipment has initial operator data (or "credentials") which is an initial profile and which allow a first access to the operator's mobile network limited to obtaining a new profile associated with a subscription.
- the new profile is an operational and sustainable profile in that it allows the subscriber to access the operator's network and related services as a customer.
- the method does not require modifying the existing network architecture and / or defining a specific interface for access to the mobile network. It is up to the operator to provide a dedicated configuration network (or "provisioning").
- the method comprises, when no subscription has been previously subscribed by a user of the mobile equipment from an operator associated with the network entity:
- said message comprising the address of a site of the operator, said site being dedicated to subscription subscriptions,
- the user of the mobile equipment has not yet subscribed to the operator.
- the first access to the network allows him to access a portal of the operator dedicated to taking subscription.
- the method comprises, when no subscription has been previously subscribed by a user of the mobile equipment from an operator associated with the network entity:
- This example is a variant of the previous example in the sense that the subscription subscription is done here by telephone.
- the initial identifier comprises at least one representative field of access limited to obtaining a network access profile.
- the initial identifier of the initial profile has a generic format, in the sense that it comprises one or more specific fields.
- the initial identifier includes an MCC country code field equal to "000" not currently used in the ITU-T E212 identification plan (for "International Telecommunication Union - Telecommunications Sector"), or the combination of an assigned MCC country code field, for example "901", currently shared by transnational networks and an unassigned MNC national network code field, for example "00".
- This initial generic identifier format allows the operator receiving the network attachment request to implement the appropriate processing corresponding to limited access to obtaining an operational access profile.
- the initial identifier is read by means of the mobile equipment on a ticket provided by the operator, said ticket comprising an identifier of a security module included in the mobile equipment.
- This example eliminates the installation of the initial profile that includes the initial identifier and the initial secret key at the time of manufacture of the security module by a module manufacturer. Moreover, the operator already knows this initial key or has the means to compute it from the initial identifier.
- This embodiment is interesting in the sense that the operator is freed from a prior agreement with the manufacturer of security modules for the preliminary injection of initial data in the modules.
- the operator provides this initial data.
- the operator controls the association between an initial profile and a security module by associating the ticket with the identifier of the security module.
- the operational network access profile generated after the first access to the network using the initial profile is sent only to the security module whose module identifier coincides with the identifier that appears on the ticket. This increases the security of the method of obtaining a network access profile.
- the invention also relates to a method for providing mobile equipment with a profile of access to a telecommunications network by a network entity, the method comprising:
- the invention also relates to mobile equipment comprising:
- means for sending arranged to send a request for access to the network, said request comprising an initial subscriber identifier included in an initial profile
- authentication means arranged to implement mutual authentication with the network entity by means of an initial secret key associated with the initial identifier
- the invention also relates to a program for mobile equipment, comprising program code instructions for controlling the execution of the steps of the method of obtaining a network access profile as described above, when the program is executed on said equipment.
- the invention also relates to a data carrier in which the above program is recorded.
- the invention also relates to a device of a telecommunications network, arranged to provide a mobile equipment with a network access profile, said device comprising:
- receiving means arranged to receive from the mobile equipment a request for access to the network, said request comprising an initial subscriber identifier included in an initial profile
- authentication means arranged to implement mutual authentication of the mobile equipment by means of an initial secret key associated with the initial identifier
- the invention also relates to a program for a network device, comprising program code instructions for controlling the execution of the steps of the method of providing a network access profile as described above, when the program is executed on said entity.
- the invention also relates to a data carrier in which the above program is recorded.
- the invention also relates to a system for distributing access profiles to a telecommunications network comprising:
- At least one mobile device as described above.
- FIG. 1 presents the steps of a method of obtaining a mobile network access profile, according to a first exemplary embodiment
- FIG. 2 presents the steps of a method for obtaining an access profile to a mobile network, according to a second exemplary embodiment
- FIG. 3 is a schematic representation of a mobile equipment capable of implementing the method of obtaining an access profile to a mobile network, according to an exemplary embodiment
- FIG. 4 is a schematic representation of a network equipment capable of implementing the method of obtaining an access profile to a mobile network, according to an exemplary embodiment.
- a user has a mobile equipment 10, such as a mobile terminal, a tablet, etc.
- the mobile equipment 10 comprises a security module 101 or subscriber card, such as an "eUICC” card (for "embedded UICC”) intended to contain an operator profile, or access profile, to access a mobile network.
- eUICC embedded UICC
- the operator profile prepared by an operator for a subscriber when subscribing to a subscription with this operator, is intended to be used by this subscriber when accessing the network of this operator and associated services.
- the network of the operator to which he subscribes is called the nominal network, or home network, or HPLMN (for Home Public Land Mobile Network).
- the operator profile comprises operator data such as a subscriber identifier understandable by the network and generally denoted "IMSI” (for "International Mobile Subscriber Identity”), a secret key denoted “K” in the 3G and 4G networks, and "3 ⁇ 4" in the 2G networks, shared between the security module 101 and the operator network, an authentication algorithm, for example Milenage or Tuak, parameters and possible applications specific to the operator, for example a payment application. Subsequently, the secret key is called "K key", regardless of the type of mobile network involved.
- a mobile telecommunications network such as a 3G or 4G network, is schematized in FIG. 1 by a network entity 11.
- a subscriber To access a mobile network, a subscriber must have operator data, or "credentials operators" which include a subscriber identifier, a secret key K shared with the subscriber's nominal network, ie - say the network to which the subscription was subscribed, and parameters specific to the authentication algorithm used to access the network.
- the method for obtaining a mobile network access profile is described here in the context of a 4G LTE (Long Term Evolution) network, LTE-Advanced, or LTE-Advanced network. Pro.
- the invention is however not limited to this type of network and applies also to other types of mobile networks such as for example a network "GPRS” (General Packet Radio Service “), or” UMTS “(English” Uni versai Mobile Telecommunications System “).
- GPRS General Packet Radio Service
- UMTS Universal Mobile Telecommunications System
- the user has his mobile equipment 10 but that he does not yet have a network access profile associated with a subscription of a particular operator installed on his security module 101 allowing him to access this operator's mobile network and associated services.
- the particular operator is the one that is associated with the network schematized by the network entity 11.
- the user has subscribed to the operator by going, for example, to an agency of this type. operator.
- the operator has generated an associated network access profile which, for the time being, is not installed in the security module 101.
- the mobile equipment 10 does not have any alternative connectivity. that is, it does not have an active subscription with another operator, or Internet connectivity to install a profile corresponding to a subscription it has subscribed.
- MNC Mobile Network Code
- MSISDN Mobile Station ISDN
- the security module 101 comprises an initial profile comprising an initial IMSI subscriber identifier. init , for example of type IMSI, an initial secret key denoted K init of an authentication algorithm and parameters of the authentication algorithm.
- the initial profile was installed in the security module 101 during its manufacture. For example, an agreement has been made between a manufacturer of security modules at the origin of the module 101 and one or even several mobile network operators, including the operator who manages the network entity 11, so that the initial identifier IMSI init included in the initial profile installed by the manufacturer is considered as a partner identifier of the operator (s).
- This initial profile is intended to obtain a first restricted connectivity to the operator.
- “Restricted” means that this connectivity only makes it possible to obtain a second network access profile for the operator.
- This restricted access corresponds to access to a configuration network (we speak of "provisioning” in English), or subscription management.
- the second access profile is a perennial and classic access profile in the sense that it provides access to the operator's network and associated services, such as mobile Internet access, voice access, access SMS / MMS (for "Short / Multimedia Message Service”), etc., as a customer of this operator. It corresponds to the subscription subscribed by the user.
- the initial profile is a generic profile in the sense that it is not associated with any particular operator.
- Such a value is intended to allow the network operator receiving a network attachment request that includes such an identifier to process the access request as a request to obtain an access profile associated with a request. sustainable subscription and limit this access to a configuration network dedicated to obtaining and activating the perennial access profile.
- the user tries to access the mobile network. For example, it turns on its mobile equipment 10.
- the mobile equipment 10 then sends a request for attachment to the network on the radio channel.
- the attachment request comprises an identifier of the user equipment 10, in this case the initial identifier IMSI init stored in the security module 101.
- the attachment request is received by the network entity 11 in a reception step El i.
- the network entity 11 analyzes the initial identifier IMSI init received. It identifies that it is an initial identifier associated with an initial profile because of the value of the specific MCC country code, or the combination of MCC country code and specific MNC national network code.
- the network entity 11 obtains the initial secret key K init associated with the initial identifier IMSI in i t .
- the network entity 11 calculates the initial secret key K init by applying a key derivation algorithm "KDF" (for "Key Derivation Function") to a master key “MK” (for "Master Key ”) And the initial identifier IMSI init received in the attachment request.
- KDF KDF (MK, IMSI in i t ).
- the key derivation algorithm KDF is the algorithm "AES” (for "Advanced Encryption Standard”).
- the KDF key derivation algorithm is the PBKDF2 algorithm as defined in RFC2898 ("Request For Comment").
- key derivation algorithm KDF is a function hash with secret key type authentication message "HMAC" (for "Keyed-Hashed Message Authentication Code").
- a partner database stores the initial keys, in association with the initial identifiers and / or operator parameters.
- the network entity 11 accesses the partner database in order to recover the initial secret key K init associated with the initial identifier IMSI init .
- a subsequent authentication phase P14 the attachment procedure to the network continues and authentication between the mobile equipment 10, more precisely the security module 101, and the network entity 11 is implemented according to the registration procedure as described, for example, in the specification 3GPP TS 23.401.
- the mobile equipment 10 is authenticated and encryption keys of the radio channel and integrity control, noted respectively CK and IK, and specific to the mobile equipment 11 were derived from the secret key initial K at .
- the registration procedure described in the specification 3GPP TS 23.401 specifies a mutual authentication between the mobile equipment 10 and the network entity 11. In the case of a 2G network, authentication is one-sided in the sense that only l mobile equipment 10 is authenticated by the network entity 11.
- the network entity 11 proceeds to send the network access profile of the operator associated with the subscription subscribed by the user.
- the access profile prepared by the operator at the time of subscription, includes subscriber-specific data as a customer for access to the operator's network and associated services from the mobile device 10.
- the access profile comprises a new subscriber's own IMSI identifier, a new associated secret key K, operator parameters specific to the authentication algorithm and any operator applications.
- the access profile is sent by the network entity 11 using the encrypted channel of the radio channel. This profile replaces the initial profile on the security module 101.
- the network access profile is received and automatically activated in a next step E16 of reception and activation.
- the network entity 11 sends the access profile and then an explicit activation command for said profile to the mobile equipment 10.
- the user controls the access profile. activation of the access profile once it has been received.
- the initial identifier IMSI init and the initial secret key ⁇ ⁇ , stored on the security module 101 are deleted and replaced by the new identifier IMSI and the new secret key K. This embodiment corresponds to a case where the security relies entirely on the security of the radio channel inherent in the encryption of the radio channel from the encryption key CK generated during the authentication phase P14 to encrypt the voice or the data.
- the described exemplary embodiment fits perfectly into an existing mobile network architecture. Indeed, it does not require modification at the interface with the mobile network. For example, it does not require modifying the network attachment procedure.
- the network entity 11 erases the initial identifier IMSIj n i t and optionally the initial secret key K init associated in its partner database.
- the initial data is transferred to a second database that includes the original data already in use; this second database is consulted by the operator when receiving new requests for attachment to the network. For security reasons, it is considered that such initial access data can only be used once. An attempt to access the network from initial data already in use is detected by the operator. The operator can thus guard against any attacks during which cards containing identifiers and initial secret keys would be cloned and used to obtain perennial access profiles.
- a subsequent network access phase (not shown in FIG. 1), during which the user wishes to access the mobile network of the operator, the mobile equipment 10 sends a second attachment request to the network.
- This second attachment request includes the new IMSI identifier that appears in the operational profile obtained during the implementation of the preceding steps.
- the network entity 11 sends the user a "URL" (of the "Uniform Resource Locator") of access to an operator portal reserved for subscription subscriptions.
- This sending is done via a network access point, or APN ("Access Point Name"), dedicated to the operator and offering limited connectivity, but allowing access to subscription subscriptions.
- APN Access Point Name
- the sending can be done by means of an SMS.
- the subscriber is called by the operator. The subscriber provides the information necessary for the subscription.
- An access profile is then generated by the operator and transmitted to the equipment mobile on the encrypted channel of the radio channel, in accordance with the step E15 of sending the profile. This access profile replaces the initial profile on the security module 101.
- the security module is an eUICC module "M2M" (for "Machine To Machine”).
- M2M for "Machine To Machine”
- the M2M device does not have a user interface, it is necessary that an M2M subscription has been subscribed by an M2M equipment manager for the mobile equipment 10, prior to accessing the network intended for get the subscription profile.
- the network access profile is sent by the network entity 11 via the encrypted radio channel, the data streams being protected in integrity or in an applicative manner.
- the method is not limited to an eUICC type security module and in another exemplary embodiment, the security module is a conventional UICC SIM card type security module.
- the method is identical to that described above and also applies to mobile equipment type customer equipment and M2M equipment.
- the initial identifier IMSI init or the initial secret key K init or the means of generating it are already present in the security module 101 when the user acquires his mobile terminal 10
- the initial identifier IMSLji t or even the initial secret key K init have indeed been installed by the manufacturer during the manufacture of the security module 101.
- none of these data ie the initial identifier IMSI init and the initial secret key K init , is present in the security module 101 at the time of acquisition of the mobile equipment 10 by the user.
- the operator when subscribing to the operator or when acquiring the mobile equipment 10 by the user, the operator generates an initial identifier IMSLji t and an associated initial secret key K init .
- the operator also generates a ticket of QR Code type (for "Quick Response Code") which comprises the initial identifier IMSI init , the initial secret key K init , an identifier of the network of the operator of type "HPLMN" (for "Home Public Land Network” and possible operator parameters.
- the ticket generated also comprises a physical identifier ID of the security module 101, which it stores in association with the initial identifier IMSI init and the initial secret key K init that it has generated.
- the physical identifier ID of the security module 101 is of type ICCID (for "Integrated Circuit Card ID") in the case of a module of the UICC type, and EID (for "eUICC Identifier") in the case of a module security type eUICC.
- the ticket generated is for example glued on the packaging of the mobile equipment 10, or sent to the user, or bought in a supermarket.
- the user When the user wishes to access the network to obtain a network access profile, he flashes the ticket by means of his mobile equipment 10 in order to read the ticket data whose initial identifier IMSI init , the initial secret key ⁇ ⁇ ,.
- the data read on the ticket are transmitted by a local profile manager of the type "LPA" (for "Local Profile Assistant") of the mobile equipment 10 to the security module 101.
- LPA Local Profile Assistant
- the local profile manager of the mobile equipment 10 retrieves the network access profile from the network entity 11 by providing the identifier ID of the security module.
- the operator has added in the ticket information such as an address or a name of the profile server to contact.
- SM-DP + for "Subscription Manager - Data Preparation"
- a security module eUICC type "consumer device” respecting the implementation described in the GSMA specification SGP.22.
- the use of a ticket to obtain the initial data and the network access profile is interesting in the sense that the operator is freed from prior agreement with the manufacturer of security modules for the prior injection of initial data in the security module. Note that in this case, the initial identifiers do not need to respect a specific format; they are specific to the operators.
- an initial profile is also used to access the network to obtain a perennial access profile associated with a subscription.
- the sending of the network access profile to the mobile equipment 10 is secured by predefined procedures based on a certificate specific to the security module.
- the installation of the perennial access profile on the security module 101 is then performed by means of secure procedures based on this certificate, regardless of the security inherent in the encryption of the radio channel.
- the security module 101 of the mobile equipment 10 is a client module, or "consumer device” type eUICC. It comprises an initial profile comprising an initial subscriber identifier IMSI init and an initial secret key K init .
- the way to obtain this profile is identical to that described previously and is done for example following an agreement between a manufacturer of security modules and one or more operators.
- the type of profile is also identical to that described above.
- an initial step E20 the user turns on his mobile equipment to access the network.
- the equipment issues a network attachment request that includes the initial subscriber identifier IMSI init .
- the request is received in a receiving step E21.
- the network entity 11 analyzes the initial identifier IMSI init . It identifies that it is an initial identifier associated with an initial profile, because of the value of the specific MCC country code, or the combination of MCC country code and specific MNC national network code.
- the network entity 11 obtains the initial secret key K init associated with the initial identifier IMSI init .
- the network entity 11 calculates the initial secret key K init by applying a key derivation algorithm KDF to a master key MK and to the initial identifier IMSI init .
- the network entity 11 extracts from a partner database to which it has access the initial secret key K init stored in association with the initial identifier IMSI init .
- a subsequent authentication phase P24 the attachment procedure continues and an authentication phase between the mobile equipment 10, more precisely the security module 101, and the network entity 11 is implemented in a known manner. in accordance with the registration procedure as described, for example, in the specification 3GPP TS 23.401.
- the mobile equipment 10 is authenticated by the network entity 11 and encryption keys of the radio channel and integrity control, denoted CK and IK, were derived from the initial secret key K init .
- the network entity 11 requests the mobile device 10 to send the certificate of the security module 101.
- the network entity 11 sends the mobile equipment 10 a request GET DATA as defined for example by the GlobalPlatform association.
- the request is received by the mobile equipment 10 in a receiving step E26.
- the mobile equipment 10 sends the certificate of the security module 101.
- the certificate is of the form: CERT.EUICC.ECDSA.
- the certificate of the security module 101 is received by the network entity 11 in a reception step E28.
- the network entity 11 proceeds, in a profile sending and activating step E29, sending the access profile to the security module 101 via the mobile equipment 10 in accordance with the GSMA specification SGP.22 which describes an architecture for the provision to profile distance to a security module (or "RSP" for "Remote SIM Provisioning").
- the network access profile is received by the security module 101 and automatically activated. It replaces the initial profile used for the first access to the network. For example, in the case of an eUICC module, the initial profile is disabled and the received access profile becomes the active profile.
- the network entity 11 sends an explicit activation command to the security module 101 via the mobile equipment 10. In another variant embodiment, it is the user of the mobile equipment 10 which explicitly activates its network access profile.
- the initial data IMSI init and K init are transferred to the second database which includes the initial data already in use to check that this initial data is only used once.
- the network entity 11 prior to the step E29 of sending the access profile, sends to the mobile equipment 10 a URL which includes a link to a portal of the operator dedicated to the subscription of the user. subscriptions to this operator.
- the URL is sent by SMS.
- the user selects the link and subscribes to a subscription.
- the operator generates the subscription from the information provided by the user and sends in step E29 the generated profile as described above.
- the operator instead of sending a link to a subscription site, the operator calls the subscriber to subscribe by phone.
- the user has an application on his mobile equipment to make the subscription.
- the security module is an eUICC M2M module.
- the security module is an eUICC M2M module.
- the network access profile is sent by the network entity 11 in accordance with the GSMA specification SGP.02, specific to the M2M equipment.
- the certificate of the security module is of the form: CERT.EUICC.ECKA.
- the second exemplary embodiment has been described in the case of a security module 101 of eUICC type for a client module or "consumer device" and for an M2M module.
- the invention is not limited to these examples.
- the invention also applies to a conventional security module UICC SIM card type.
- the sending of the access profile differs slightly from that described with reference to FIG. 2.
- a subscription has been subscribed by the user and that a profile has been generated by the operator. It is assumed that this profile is stored by the operator and accessible by the network entity 11 and that this profile is encrypted by the operator by means of a random encryption key K rand profiles.
- the network entity 11 sends in the information request step E25 a GET DATA request intended to obtain the certificate of the security module 101.
- the mobile equipment 10 sends in response in the step E27 the certificate of the security module. security 101.
- the network entity 11 retrieves the public key Pkuicc from the certified security module 101 that appears in the certificate of the security module 101.
- the network entity 11 sends the random encryption key profiles K rand , encrypted by means of the public key Pkuicc-
- the network entity 11 sends the encrypted access profile .
- the mobile equipment 10, more precisely the security module 101 decrypts the random encryption key of K rand profiles by means of its private key associated with the certified public key and decrypts the profile by means of the random encryption key K profiles. rand . This mode of obtaining the profile conforms to the GlobalPlatform model "PushModel".
- conforming to the GlobalPlatform model SCP 11 for "Secure Channel Protocol"
- the network entity 11 once the network entity 11 has received the certificate of the public key of the security module 101, the network entity 11 and the mobile equipment 10, more precisely the security module 101 calculate a common session key K sess according to a known protocol, for example Diffie-Hellmann.
- the session key K sess generated is then used by the network entity 11 to encrypt the access profile and send it to the security module 101 via the mobile equipment 10.
- the session key K sess is used to encrypt the random encryption key K rand profiles.
- the initial key K init and the physical identifier ID of the security module 101 are inserted by the operator in a ticket which is flashed. by the mobile equipment 10, the operator uses the physical identifier ID to secure the installation of the network access operational profile.
- the operator thus controls that the network access profile generated after the first access to the network by means of the initial profile is sent only to the security module 101 whose module identifier which appears in the module's certificate. security coincides with the one he has memorized in association with the original data and entered in the ticket he has generated.
- the network entity 11 requests the mobile equipment 10 during the information request step E25, the physical identifier ID of the security module 101. It sends for this purpose a GET DATA request such as as defined for example by the GlobalPlatform association. It receives the physical identifier of the security module 101 in the response step E27. The network entity 11 then checks that the physical identifier it has received is the same as the identifier ID that it has registered and inserted in the ticket before proceeding to send the access profile during the the step E29 of sending the profile. This provides additional security for the operator. In this way, the operator secures upstream the subsequent installation of the network access profile by inserting in the ticket the physical identifier ID of the security module 101.
- a ticket that includes the initial data IMSI init , K init , the physical identifier ID of the security module 101 and an IP address of a server of the operator that generates and / or makes available Network access profiles that it generates after subscriptions subscription is created.
- the ticket is then read by the mobile equipment 10.
- the local LPA profile manager of the mobile equipment 10 retrieves from the network entity 11 the network access profile via the limited connectivity provided by the initial profile.
- the information requesting steps E25, receiving E26, receiving E27 and receiving E28 are not implemented. This simplifies the process of obtaining a network access profile.
- a mobile device 10 is for example a user equipment such as a mobile terminal, a tablet.
- the mobile device 10 is an M2M device. Note that in this case it does not have a user interface. In this case, it is associated with an M2M equipment fleet manager.
- the mobile equipment 10 conventionally comprises a radio interface arranged to interface with a mobile communication network, a processor, a set of memories (these elements are not represented in FIG. 3) and a security module 101, for example an eUICC card.
- the security module 101 is designed to store and process sensitive data, such as keys and cryptographic algorithms. Such data and algorithms are intended to be used when accessing the mobile network.
- sensitive data such as keys and cryptographic algorithms. Such data and algorithms are intended to be used when accessing the mobile network.
- the interactions between the mobile terminal 10 and the security module 101 are very close and known. For reasons of readability, only the elements which form part of the security module 101 are described below and only appear in FIG.
- the mobile equipment 10 comprises in the security module 101:
- a processing unit or processor 1011 or “CPU” (of the “Central Processing Unit”), intended to load instructions in memory, to execute them, to perform operations;
- the storage memory 1103 is arranged to store a software module for obtaining a mobile network access profile that includes code instructions for implementing the steps of the method for obtaining a profile. network access as described above and which are implemented by the security module 101.
- the storage memory 1013 is also arranged to store in a secure area an IMSI type subscriber identifier and a secret key K.
- the subscriber identifier may be an initial identifier IMSI init and the secret key an initial secret key K init intended to be used only for limited access to the operator's network and intended to obtain an access profile. perennial to the network of this operator. This initial data is intended to be replaced by a perennial identifier and secret key, obtained following a subscription subscription to the operator.
- Mobile equipment 10 also includes:
- a sending module 1014 arranged to send a request for access to the network, said request comprising an initial subscriber identifier IMSI init included in an initial profile.
- the sending module 1014 is arranged to implement the steps E10 and E20 of the methods for obtaining a network access profile described above;
- an authentication module 1015 arranged to implement mutual authentication with the network entity 11 by means of the initial secret key K init associated with the initial identifier IMSI init .
- the authentication module 1015 is arranged to implement the phases P14 and P24 of the methods for obtaining a network access profile as described above; -
- a receiving module 1016 arranged to receive from the network entity 11 a new network access profile, said new access profile comprising a new subscriber identifier and a new secret key.
- the new identifier and the new secret key are arranged to access the network and the associated services of the operator as a client.
- the reception module 1016 is arranged to implement the steps E1 and E30 of the methods for obtaining a network access profile as described above.
- the sending module 1014, the authentication module 1015 and the receiving module 1016 are preferably software modules comprising software instructions for implementing the steps of the methods for obtaining a network access profile. as previously described.
- the invention therefore also relates to:
- the invention is not limited to a user equipment of this type and in another embodiment, the mobile equipment 10 comprises a secure software area arranged to process the sensitive network access data.
- a network device 11, according to an exemplary embodiment will now be described in relation to FIG. 4.
- the network device 11 is arranged to receive from mobile equipment network attachment requests which comprise an initial identifier IMSI init , to implement mutual authentication with the mobile equipment on the basis of the initial identifier IMSIi n i t and a secret key associated K init , to generate a new operational and perennial access profile to the network and associated services for the user of the mobile equipment 11, said new profile comprising a new subscriber identifier and a new secret key, and to send the new profile to the mobile device.
- the network device 11 is formed of one or more computer equipment, such as computers.
- the network device 11 comprises:
- a processing unit or processor 111 intended to load instructions in memory, to execute them, to perform operations
- the storage memory 113 is arranged to store a software module for providing an access profile to a mobile network which comprises code instructions for implementing the steps of the method for obtaining a profile of a mobile network. network access which are implemented by the network device 11;
- access interfaces 114 to databases, such as a partner database comprising initial identifiers and associated initial secret keys and a database of subscriber identifiers and associated secret keys.
- databases such as a partner database comprising initial identifiers and associated initial secret keys and a database of subscriber identifiers and associated secret keys.
- the network device 11 also comprises:
- reception module 115 arranged to receive from a mobile equipment a network access request, said request comprising an initial subscriber identifier IMSI init included in an initial profile.
- the reception module 116 is arranged to implement the steps El i and E21 of the methods for obtaining a mobile network access profile as described above;
- a mutual authentication module 116 arranged to implement mutual authentication with the mobile equipment by means of an initial secret key K init associated with the initial identifier.
- the mutual authentication module 116 is arranged to implement the phases P14 and P24 of the methods for obtaining a mobile network access profile as described above;
- the module 117 for sending a new profile is arranged to implement steps E15 and E29 of the methods for obtaining a mobile network access profile as described above.
- the module 117 for sending a new access profile interfaces with a profile generation module (not shown in FIG. 4), designed to generate the new network subscription profiles.
- the profile generation module provides an interface that can be accessed by the user to provide his subscription data.
- the receiving modules 115, 116 for authentication and 117 for sending a new profile are preferably software modules comprising software instructions for implementing the steps of the methods for obtaining an access profile to a new profile. network as described above and which are implemented by the network device 11.
- the invention therefore also relates to: a computer program comprising instructions for implementing the method for obtaining a network access profile as described above when this program is executed by a processor of the network device 11,
- the invention also relates to a system for distributing access profiles to a telecommunications network comprising:
- At least one mobile device as described above.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Databases & Information Systems (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR1663295A FR3061398A1 (fr) | 2016-12-23 | 2016-12-23 | Procede d'obtention d'un profil d'acces a un reseau de telecommunications |
| PCT/FR2017/053491 WO2018115634A1 (fr) | 2016-12-23 | 2017-12-11 | Procédé d'obtention d'un profil d'accès à un réseau de télécommunications |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3560226A1 true EP3560226A1 (fr) | 2019-10-30 |
Family
ID=58707665
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP17825898.4A Withdrawn EP3560226A1 (fr) | 2016-12-23 | 2017-12-11 | Procédé d'obtention d'un profil d'accès à un réseau de télécommunications |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20210120411A1 (fr) |
| EP (1) | EP3560226A1 (fr) |
| FR (1) | FR3061398A1 (fr) |
| WO (1) | WO2018115634A1 (fr) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115567920A (zh) * | 2021-06-30 | 2023-01-03 | 华为技术有限公司 | 认证的方法和装置 |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013039900A1 (fr) * | 2011-09-16 | 2013-03-21 | Alcatel-Lucent Usa Inc. | Mise à disposition de dispositifs mobiles indépendamment d'un opérateur de réseau |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103609152B (zh) * | 2011-06-23 | 2018-05-25 | 瑞典爱立信有限公司 | 向订户识别模块中预配置网络信息 |
| EP2632196A1 (fr) * | 2012-02-24 | 2013-08-28 | Alcatel Lucent | Personnalisation initiale de carte intelligente |
| KR102138315B1 (ko) * | 2013-05-30 | 2020-07-27 | 삼성전자주식회사 | 프로파일 설치를 위한 방법 및 장치 |
| FR3034611A1 (fr) * | 2015-03-31 | 2016-10-07 | Orange | Methode de configuration d' une carte de type euicc |
| FR3036574A1 (fr) * | 2015-05-21 | 2016-11-25 | Orange | Chargement de profil d'abonnement dans une carte sim embarquee |
-
2016
- 2016-12-23 FR FR1663295A patent/FR3061398A1/fr not_active Withdrawn
-
2017
- 2017-12-11 WO PCT/FR2017/053491 patent/WO2018115634A1/fr not_active Ceased
- 2017-12-11 US US16/472,585 patent/US20210120411A1/en not_active Abandoned
- 2017-12-11 EP EP17825898.4A patent/EP3560226A1/fr not_active Withdrawn
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013039900A1 (fr) * | 2011-09-16 | 2013-03-21 | Alcatel-Lucent Usa Inc. | Mise à disposition de dispositifs mobiles indépendamment d'un opérateur de réseau |
Also Published As
| Publication number | Publication date |
|---|---|
| US20210120411A1 (en) | 2021-04-22 |
| FR3061398A1 (fr) | 2018-06-29 |
| WO2018115634A1 (fr) | 2018-06-28 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11368839B2 (en) | Secure privacy provisioning in 5G networks | |
| US10187784B1 (en) | Systems and methods for transferring SIM profiles between eUICC devices | |
| US8347090B2 (en) | Encryption of identifiers in a communication system | |
| CN103493526B (zh) | Sim锁定 | |
| EP3029968B1 (fr) | Procede de provisionnement d'un profil de souscripteur pour un module securise | |
| KR102231948B1 (ko) | 프로파일 관리서버의 업데이트 방법 및 장치 | |
| JP6442617B2 (ja) | eUICCの遠隔サブスクリプション管理のための方法、及び対応する端末 | |
| EP3656142B1 (fr) | Chargement d'un nouveau profil d'abonnement dans un module embarqué d'identification de souscripteur | |
| CN105122769A (zh) | 用于在安全单元的安全域中创建简档的方法 | |
| US20120115455A1 (en) | Secure bootstrap provisioning of electronic devices in carrier networks | |
| EP3523998A1 (fr) | Procédé d'authentification mutuelle entre un équipement utilisateur et un réseau de communication | |
| US12477326B2 (en) | Method of providing a communication function in a user equipment | |
| EP3456025A1 (fr) | Technique d'authentification d'un dispositif utilisateur | |
| US10028141B2 (en) | Method and system for determining that a SIM and a SIP client are co-located in the same mobile equipment | |
| EP3560226A1 (fr) | Procédé d'obtention d'un profil d'accès à un réseau de télécommunications | |
| EP3806517B1 (fr) | Chargement d'informations de sécurité à accès restreint | |
| CN108616861B (zh) | 一种空中写卡方法及装置 | |
| EP3662692A1 (fr) | Procédé d'obtention d'un profil d'accès à un réseau de communication par un terminal secondaire via un terminal principal | |
| WO2018065711A1 (fr) | Procédé d'enregistrement d'un équipement utilisateur dans un réseau de communication | |
| CN116249095A (zh) | 一种页面显示方法及相关设备 | |
| EP4601342A1 (fr) | Fourniture d'une euicc avec des données de profil d'au moins un profil | |
| US12335719B2 (en) | Method for recovering a profile of a MNO |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20190711 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: ORANGE |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20210419 |
|
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: ORANGE |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20211030 |