IP Library Granted Patent US 9,451,459
Granted Patent B2
US 9,451,459 · App. 14/342,961 · Granted Sep 20, 2016

Certification method using an embedded UICC certificate, provisioning and MNO changing methods using the certification method, embedded UICC therefor, MNO system, and recording medium

Inventors: Jinhyoung Lee (Seoul, KR); Yeumin Yoon (Seoul, KR); Sungchul Kim (Seoul, KR)
Assignee: KT Corporation
H04W12/06H04W12/04H04L63/083H04L63/0823H04W4/001H04W4/005
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,451,459
App. No.
14/342,961
Granted
Sep 20, 2016
Kind
B2
Abstract

The present invention relates to a system constituted by a mobile network operator (MNO), a subscription manager (SM), and an embedded UICC (eUICC), wherein the MNO system or the SM stores an eUICC certificate that can verify the identity of the eUICC, transfers the eUICC certificate to the MNO system or the SM in a provisioning or MNO changing process, verifies the identity of a corresponding eUICC using the received eUICC certificate, and encrypts and transfers a profile to the eUICC only if the verification is successful so that the eUICC may be verified during the provisioning or MNO changing processes.

Claims (46)

1. A method of certifying an embedded universal integrated circuit card (eUICC) cooperating with a mobile network operator (MNO) system and a subscription manager (SM), the method comprising:

storing, by the eUICC, an eUICC certificate used for the MNO system or the SM to verify an identity of the eUICC; and

transmitting, by the eUICC, the eUICC certificate to the MNO system or the SM,

wherein the SM comprises a subscription manager-secure routing (SM-SR) and a subscription manager-data preparation (SM-DP), both of which perform an encryption function such that the eUICC certificate is double encrypted upon a condition that both the SM-SR and SM-DP are instructed to perform said encryption.

2. The method of claim 1 , wherein the eUICC certificate includes at least one of information indicating that at least one of hardware, card operating system (OS), and platform of the eUICC is verified, information indicating that the eUICC is verified as an eUICC trustable by the MNO system and the SM, and information indicating that it is verified that MNO services can be installed in the MNO system.

3. The method of claim 1 , wherein the eUICC certificate in included and stored in common information comprising card OS information and card platform information.

4. The method of claim 3 , wherein the common information including the eUICC certificate is included in an eUICC certificate profile.

5. The method of claim 3 , wherein the common information further includes a personal identification number (PIN) of the eUICC.

6. An embedded universal integrated circuit card (eUICC) cooperating with an external entity including a mobile network operator (MNO) system and a subscription manager (SM),

wherein the eUICC stores an eUICC certificate profile including at least one of an eUICC certificate, which is used for the MNO system or the SM to verify an identity of the eUICC, card operating system (OS) information, card platform information, personal identification number (PIN) information,

wherein the eUICC certificate profile transmits the eUICC certificate to the MNO system or the SM, and

wherein the SM comprises a subscription manager-secure routing (SM-SR) and a subscription manager-data preparation (SM-DP), both of which perform an encryption function such that the eUICC certificate profile is double encrypted upon a condition that both the SM-SR and SM-DP are instructed to perform said encryption.

7. The eUICC of claim 6 , wherein the eUICC certificate includes at least one of information indicating that at least one of hardware, card operating system (OS), and platform of the eUICC is verified, information indicating that the eUICC is verified as an eUICC trustable by the MNO system and the SM, and information indicating that it is verified that MNO services can be installed in the MNO system.

8. A method of provisioning an eUICC certificate which is used for a mobile network operator (MNO) system and a subscription manager (SM) to verify an identity of the eUICC by using the eUICC cooperating with an external entity including the MNO system and the SM, the method comprising:

receiving and storing, by the eUICC, the eUICC certificate generated in a manufacturing step of the eUICC;

transmitting, by the eUICC, the eUICC certificate to the MNO system;

verifying, by the MNO system, the identity of the eUICC by using the eUICC certificate; and

encrypting, by the MNO system, its operational profile and transmitting the operational profile to the eUICC,

wherein the SM comprises a subscription manager-secure routing (SM-SR) and a subscription manager-data preparation (SM-DP), both of which perform an encryption function such that the eUICC certificate is double encrypted upon a condition that both the SM-SR and SM-DP are instructed to perform said encryption.

9. The method of claim 8 , wherein the eUICC certificate includes at least one of information indicating that at least one of hardware, card operating system (OS), and platform of the eUICC is verified, information indicating that the eUICC is verified as an eUICC trustable by the MNO system and the SM, and information indicating that it is verified that MNO services can be installed in the MNO system.

10. A method of changing MNO using an eUICC cooperating with an external entity including a mobile network operator (MNO) system and a subscription manager (SM) and including an eUICC certificate which is used for the MNO system and the SM to verify an identity of the eUICC, the method comprising:

receiving and storing, by the eUICC, the eUICC certificate generated in a manufacturing step of the eUICC;

transmitting, by the eUICC, the eUICC certificate to a receiving MNO system;

verifying, by the receiving MNO system, the identity of the eUICC by using the eUICC certificate;

encrypting, by the receiving MNO system, its operational profile and transmitting the operational profile to the eUICC; and

notifying, by the eUICC, a fact that an MNO is changed, to the receiving MNO system and a donor MNO system,

wherein the SM comprises a subscription manager-secure routing (SM-SR) and a subscription manager-data preparation (SM-DP), both of which perform an encryption function such that the eUICC certificate is double encrypted upon a condition that both the SM-SR and SM-DP are instructed to perform said encryption.

11. The method of claim 10 , wherein the eUICC certificate includes at least one of information indicating that at least one of hardware, card operating system (OS), and platform of the eUICC is verified, information indicating that the eUICC is verified as an eUICC trustable by the MNO system and the SM, and information indicating that it is verified that MNO services can be installed in the MNO system.

12. A method of provisioning by using an embedded universal integrated circuit card (eUICC) cooperating with a mobile network operator (MNO) system, a subscription manager-data preparation (SM-DP) and a subscription manager-secure routing (SM-SR) constituting a subscription manager (SM), the method comprising:

receiving and storing, by the eUICC, an eUICC certificate which can verify an identity of the eUICC, from an eUICC manufacturer system or a terminal manufacturer system, in the eUICC;

transmitting an activation request message or an opening request message to the MNO system according to an opening request of a subscriber;

receiving, by the MNO system, the eUICC certificate when the MNO system performs status requests and technical capability control for the eUICC;

transmitting, by the MNO system, the eUICC certificate to the SM-SR when the MNO system collects information related to a terminal from the SM-SR; and

encrypting, by the MNO system, its operational profile and transmitting the operational profile to the eUICC only when the MNO system or the SM-SR verifies the eUICC using the eUICC certificate,

wherein both the SM-SR and the SM-DP perform an encryption function such that the eUICC certificate is double encrypted upon a condition that both the SM-SR and SM-DP are instructed to perform said encryption.

13. The method of claim 12 , wherein the eUICC certificate includes at least one of information indicating that at least one of hardware, card operating system (OS), and platform of the eUICC is verified, information indicating that the eUICC is verified as an eUICC trustable by the MNO system and the SM, and information indicating that it is verified that MNO services can be installed in the MNO system.

14. A method of changing MNO by using an embedded universal integrated circuit card (eUICC) cooperating with a mobile network operator (MNO) system, a subscription manager-data preparation (SM-DP) and a subscription manager-secure routing (SM-SR) constituting a subscription manager (SM), the method comprising:

receiving and storing, by the eUICC, an eUICC certificate which can verify an identity of the eUICC, from an eUICC manufacturer system or a terminal manufacturer system, in the eUICC;

transmitting, by the eUICC, an activation request message or an opening request message to a receiving MNO system according to an MNO change request;

receiving, by the receiving MNO system, the eUICC certificate from the eUICC when the receiving MNO system performs status requests and technical capability control for the eUICC;

transmitting, by the receiving MNO system, the eUICC certificate to the SM-SR when the receiving MNO system collects information related to a terminal from the SM-SR;

performing, by the receiving MNO system, negotiation and transferring right for MNO change with a donor MNO system; and

encrypting, by the receiving MNO system, its operational profile and transmitting the operational profile to the eUICC, only when the receiving MNO system or the SM-SR verifies the eUICC using the eUICC certificate,

wherein both the SM-SR and the SM-DP perform an encryption function such that the eUICC certificate is double encrypted upon a condition that both the SM-SR and SM-DP are instructed to perform said encryption of the eUICC certificate.

15. The method of claim 14 , wherein the eUICC certificate includes at least one of information indicating that at least one of hardware, card operating system (OS), and platform of the eUICC is verified, information indicating that the eUICC is verified as an eUICC trustable by the MNO system and the SM, and information indicating that it is verified that MNO services can be installed in the MNO system.

16. The method of claim 10 , wherein the donor MNO system is a previous system of the eUICC prior to the receiving MNO.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2019
From: KT CORPORATION
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 050566/0472 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2014
From: LEE, JIN-HYOUNG; YOON, YEU-MIN; KIM, SUNG-CHUL
To: KT CORPORATION
Reel/Frame 032357/0836 →
Priority Claims (2)
KR 10-2011-0089841 · Sep 5, 2011 · national
KR 10-2011-0104171 · Oct 12, 2011 · national
Continuity (1)
Related Publication 20140329502A1 · Nov 6, 2014