IP Library Granted Patent US 9,414,233
Granted Patent B2
US 9,414,233 · App. 14/342,986 · Granted Aug 9, 2016

Method for managing profile of Embedded UICC, and Embedded UICC, Embedded UICC-equipped terminal, provision method, and method for changing MNO using same

Inventors: Jaemin Park (Seoul, KR); Jinhyoung Lee (Seoul, KR)
Assignee: KT Corporation
H04W12/08H04W12/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,414,233
App. No.
14/342,986
Granted
Aug 9, 2016
Kind
B2
Abstract

The present invention provides a method wherein an MNO receives a secret key allocated to a corresponding embedded UICC (eUICC) through SM-SR (secure routing) in an environment where SM is divided and implemented as SM-SR and SM-DP (data preparation), that is, provided is a method wherein the MNO dynamically acquires the secret key (public key or the like) from the corresponding eUICC through the SM-SR and uses the acquired secret key. In addition, the present invention allows the eUICC to receive an encrypted profile from the MNO or the SM and decrypts the encrypted profile using profile access credential information (a secret key corresponding to an eUICC public key) stored in the eUICC to use the decrypted profile, thereby securely transmitting important data such as operation profiles, and blocking external entities such as a device or terminal from accessing the important data.

Claims (20)

1. A method of protecting operating profiles transmitted to an embedded universal integrated circuit card (eUICC) from a mobile network operator (MNO) system and a subscription manager (SM), the method comprising: receiving, by the eUICC, an encrypted profile from an external entity; and decrypting the encrypted profile by using a private key stored in and generated by the eUICC or a terminal equipped with the wherein the encrypted profile is encrypted by using a public key of the eUICC, and the private key is profile access credentials or a secret key corresponding to the public key of the eUICC, wherein the SM includes a subscription manager-data preparation (SM-DP) and a subscription manager-secure routing (SM-SR), the SM-DP encrypts the profile by using the public key of the eUICC, and the SM-SR successively encrypts the profile, which has been encrypted using the public key, by using a separate management key so that the encrypted profile becomes a double ciphered profile, and wherein the encrypted profile is the double ciphered profile, and the eUICC successively decrypts the encrypted profile by using the separate management key and then decrypts the profile, which has been decrypted using the separate management key, by using the private key of the eUICC wherein the private key is dynamically generated at every issuance time.

2. The method of claim 1 , wherein the profile includes at least one information of a provisioning profile for provisioning, an operational profile, MNO credential information or package information comprising MNO credential information, an International Mobile Subscriber Identity (IMSI), the management key such as an UICC OTA key, a GP ISD key, value-added application, and value-added service data.

3. The method of claim 1 , wherein the public key is generated by the eUICC.

4. The method of claim 1 , wherein the eUICC transmits a key generation algorithm, for generating the public key, to the SM.

5. An embedded universal integrated circuit card (eUICC) configured to protect operating profiles transmitted from an external entity including a mobile network operator (MNO) system and a subscription manager (SM), comprising a security module decrypting an encrypted profile downloaded from the external entity by using a private key generated by the eUICC, wherein the profile is a combination of a file structure, data, and an application to be provided to the eUICC wherein the encrypted profile is encrypted by using a public key of the eUICC, and the private key is profile access credentials or a secret key corresponding to the public key of the eUICC, wherein the SM includes a subscription manager-data preparation (SM-DP) and a subscription manager-secure routing (SM-SR), the SM-DP encrypts the profile by using the public key of the eUICC, and the SM-SR successively encrypts the profile, which has been encrypted using the public key, by using a separate management key so that the encrypted profile becomes a double ciphered profile, and wherein the encrypted profile is the double ciphered profile, and the eUICC successively decrypts the encrypted profile by using the separate management key and then decrypts the profile, which has been decrypted using the separate management key, by using the private key of the eUICC wherein the private key is dynamically generated at every issuance time.

6. The embedded universal integrated circuit card of the claim 5 , wherein the private key is profile access credentials uniquely allocated to the eUICC and corresponding to a public key.

7. A terminal equipped with an embedded universal integrated circuit card (eUICC) configured to protect operating profiles transmitted from a mobile network operator (MNO) system and a subscription manager (SM), the terminal comprising an issuance processing module generating and managing profile access credential information for managing a profile received from the MNO or the SM, wherein the issuance processing module generates a public key as profile access credentials for the eUICC autonomously or by using an internal separate security module and responds according to a request of the SM, and wherein the issuance processing module receives the profile information encrypted using the public key from the MNO or the SM, and decrypts the profile encrypted by using a secret key or a private key corresponding to the public key, wherein the secret key and the private key are generated by the eUICC or a terminal equipped with the eUICC wherein the SM includes a subscription manager-data preparation (SM-DP) and a subscription manager-secure routing (SM-SR), the SM-DP encrypts the profile by using the public key of the eUICC, and the SM-SR successively encrypts the profile, which has been encrypted using the public key, by using a separate management key so that the encrypted profile becomes a double ciphered profile, and wherein the encrypted profile is the double ciphered profile, and the eUICC successively decrypts the encrypted profile by using the separate management key and then decrypts the profile, which has been decrypted using the separate management key, by using the private key of the eUICC wherein the private key is dynamically generated at every issuance time.

8. The terminal of claim 7 , wherein the issuance processing module installs the security module according to a request of the SM-SR.

9. The terminal of claim 8 , wherein, when the issuance processing module responds to the SM-SR with the public key of the eUICC, the issuance processing module delivers encryption information of the public key including information about a key generation algorithm and a key length.

10. The terminal of claim 8 , wherein the encrypted profile information is double ciphered information successively encrypted by using both the public key of the eUICC and the separate management key of the eUICC.

11. The terminal of claim 10 , wherein the double ciphered profile information includes electronic signature information generated by using the private key of the SM-DP or the MNO which generates the profile.

12. A method of protecting operating profiles transmitted to an embedded universal integrated circuit cart (eUICC) from a mobile network operator (MNO) system, a subscription manager-data preparation (SM-DP) and a subscription manager-secure routing (SM-SR) constituting a subscription manager (SM), the method comprising:

receiving, by the SM-SR, an eUICC public key from the eUICC, and delivering the eUICC public key to the MNO;

encrypting, by the SM-DP, a profile by using the eUICC public key received from the MNO and delivering a first encrypted profile to the MNO;

requesting, by the MNO to the SM-SR, a second encrypted profile, which is the first encrypted profile encrypted by using a security key generated by the eUICC or a terminal equipped with the eUICC;

delivering, by the MNO or the SM-SR, the second encrypted profile which is double ciphered profile information to the eUICC;

decrypting, by the eUICC, original profile information from the double ciphered profile information by decrypting the double ciphered profile information firstly by using the security key and secondarily by using the private key corresponding to the eUICC public key wherein the private key is dynamically generated at every issuance time;

transmitting, by the eUICC, an activation request including eUICC identification information (eUICCiD) to the MNO; and

identifying, between the MNO and the eUICC, a status and a technical performance of the eUICC.

13. The method of claim 12 , wherein in encrypting, by the SM-DP, the profile by using the eUICC public key received from the MNO, the profile is electronically signed by the SM-DP according to an electronic signature expected by the eUICC.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2019
From: KT CORPORATION
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 050566/0472 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2014
From: PARK, JAE-MIN; LEE, JIN-HYOUNG
To: KT CORPORATION
Reel/Frame 032382/0217 →
Priority Claims (3)
KR 10-2011-0089638 · Sep 5, 2011 · national
KR 10-2011-0096210 · Sep 23, 2011 · national
KR 10-2011-0097900 · Sep 28, 2011 · national
Continuity (1)
Related Publication 20140219447A1 · Aug 7, 2014