IP Library Granted Patent US 10,264,023
Granted Patent B2
US 10,264,023 · App. 15/104,761 · Granted Apr 16, 2019

Methods and apparatuses for managing subscriptions on a security element

Inventors: Claus Jarnik (Windach, DE); Monika Eckardt (Mammendorf, DE)
Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
H04L63/20H04L63/06H04L63/08H04L63/0853H04L63/10H04W8/205H04W12/08H04W12/12H04W8/183H04W88/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,264,023
App. No.
15/104,761
Granted
Apr 16, 2019
Kind
B2
Abstract

A method is provided for managing a plurality of subscriptions on a security element of a mobile end device for logging into a respective mobile radio network, and such a security element. The security element has a plurality of memory locations for storing the plurality of subscriptions, wherein the plurality of subscriptions comprises a primary subscription and at least one secondary subscription. In the primary subscription there is deposited a set of rules which determines whether the at least one secondary subscription on the security element can be used.

Claims (46)

1. A method for managing a plurality of subscriptions on a security element of a mobile end device, the method comprising:

providing a security element having a hardware storage device that includes a plurality of memory locations configured to store a plurality of subscriptions, and

storing the plurality of subscriptions in the hardware storage device of the security element, the plurality of subscriptions including a primary subscription and at least a secondary subscription,

each of the plurality of subscriptions respectively including subscription authorization data that provides for communication by the security element of the mobile end device over a respective mobile radio network such that

the primary subscription includes first subscription authorization data that provides for communication by the security element of the mobile end device over a first radio network and

the secondary subscription includes second subscription authorization data that provides for communication by the security element of the mobile end device over a second radio network,

wherein in the primary subscription there is deposited a set of rules which determines whether the secondary subscription on the security element is usable on the security element.

2. The method according to claim 1 , wherein the primary subscription comprises, alongside the subscription authorization data and the set of rules, at least one application and/or at least one data set, wherein the set of rules deposited in the primary subscription further determines whether the at least one application or the at least one data set of the primary subscription is accessible by the secondary subscription.

3. A method for managing a plurality of subscriptions on a security element of a mobile end device, the method comprising:

providing a security element having a hardware storage device that includes a plurality of memory locations configured to store a plurality of subscriptions, and

storing the plurality of subscriptions in the hardware storage device of the security element, the plurality of subscriptions including a primary subscription and at least a secondary subscription,

each of the plurality of subscriptions respectively including subscription authorization data that provides for communication by the security element of the mobile end device over a respective mobile radio network such that

the primary subscription includes first subscription authorization data that provides for communication by the security element of the mobile end device over a first radio network and

the secondary subscription includes second subscription authorization data that provides for communication by the security element of the mobile end device over a second radio network,

wherein the primary subscription has, alongside the subscription authorization data, at least one application and/or at least one data set as well as a set of rules which determines whether the at least one application or the at least one data set of the primary subscription is accessible by the secondary subscription.

4. The method according to claim 1 , wherein alongside the primary subscription no further primary subscription on the security element is usable on the security element, and

wherein the set of rules deposited in the primary subscription determines that only secondary subscriptions from certain network operators on the security element are usable on the security element.

5. The method according to claim 1 , wherein the plurality of subscriptions comprise at least two secondary subscriptions, and the set of rules deposited in the primary subscription determines whether the combination of the at least two secondary subscriptions on the security element are usable on the security element.

6. The method according to claim 1 , wherein alongside the primary subscription at least one further primary subscription on the security element is usable on the security element, and the plurality of subscriptions comprise at least two secondary subscriptions,

wherein the set of rules deposited in the primary subscription only holds for a portion of the at least two secondary subscriptions, and in the further primary subscription there is deposited a set of rules which determines whether a secondary subscription of the other portion of the at least two secondary subscriptions on the security element is usable on the security element.

7. A security element for a mobile end device, the security element comprising:

a hardware storage device having a plurality of memory locations configured to store a plurality of subscriptions,

wherein the storage device has stored thereon the plurality of subscriptions, the plurality of subscriptions including a primary subscription and at least a secondary subscription,

each of the plurality of subscriptions respectively including subscription authorization data that provides for communication by the security element of the mobile end device over a respective mobile radio network such that

the primary subscription includes first subscription authorization data that provides for communication by the security element of the mobile end device over a first radio network, and

the secondary subscription includes second subscription authorization data that provides for communication by the security element of the mobile end device over a second radio network, and

wherein in the primary subscription there is deposited a set of rules which determines whether the secondary subscription on the security element is usable on the security element.

8. The security element according to claim 7 , wherein the primary subscription comprises, alongside the subscription authorization data and the set of rules, at least one application and/or at least one data set, wherein the set of rules deposited in the primary subscription further determines whether the at least one application or the at least one data set of the primary subscription is accessible by the secondary subscription.

9. A security element for a mobile end device, the security element comprising:

a hardware storage device having a plurality of memory locations configured to store a plurality of subscriptions,

wherein the storage device has stored thereon the plurality of subscriptions, the plurality of subscriptions including a primary subscription and at least a secondary subscription,

each of the plurality of subscriptions respectively including subscription authorization data that provides for communication by the security element of the mobile end device over a respective mobile radio network such that

the primary subscription includes first subscription authorization data that provides for communication by the security element of the mobile end device over a first radio network and

the secondary subscription includes second subscription authorization data that provides for communication by the security element of the mobile end device over a second radio network, and

wherein the primary subscription comprises, alongside the subscription authorization data, at least one application and/or at least one data set as well as a set of rules which determines whether the at least one application or the at least one data set of the primary subscription is accessible by the secondary subscription.

10. The security element according to claim 7 , wherein the security element is configured such that alongside the primary subscription no further primary subscription on the security element is usable on the security element, and that the set of rules deposited in the primary subscription determines that only secondary subscriptions from certain network operators on the security element are usable on the security element.

11. The security element according to claim 7 , wherein the security element is configured such that the plurality of subscriptions comprise at least two secondary subscriptions, and the set of rules deposited in the primary subscription determines whether the combination of the at least two secondary subscriptions on the security element is usable on the security element.

12. The security element according to claim 7 , wherein the security element is configured such that alongside the primary subscription at least one further primary subscription on the security element is usable on the security element, and the plurality of subscriptions comprise at least two secondary subscriptions, wherein the set of rules deposited in the primary subscription only holds for a portion of the at least two secondary subscriptions, and in the further primary subscription there is deposited a set of rules which determines whether a secondary subscription of the other portion of the at least two secondary subscriptions on the security element is usable on the security element.

13. The security element according to claim 7 , wherein the security element is a SIM, eUICC/UICC or M2M module.

14. A mobile end device having a security element according to claim 7 .

15. The method according to claim 1 , wherein the security element is a SIM, an eUICC, a UICC, or a M2M module.

16. The method according to claim 1 , wherein the security element includes a processor configured to process data.

17. The method according to claim 16 , wherein the processor is configured to execute a subscription management application that manages subscriptions on the security element.

18. The method according to claim 1 , wherein the security element includes at least one interface for communication with an external device.

19. The method according to claim 1 , wherein the security element is arranged as a firmly integrated component in the mobile end device.

20. The method according to claim 1 , wherein the security element is connected to the mobile end device as a removable hardware module.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2017
From: GIESECKE & DEVRIENT GMBH
To: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Reel/Frame 043230/0485 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2016
From: JARNIK, CLAUS; ECKARDT, MONIKA
To: GIESECKE & DEVRIENT GMBH
Reel/Frame 038920/0648 →
Priority Claims (1)
DE 10 2013 022 029 · Dec 19, 2013 · national
Continuity (1)
Related Publication 20160315966A1 · Oct 27, 2016