IP Library Granted Patent US 10,484,370
Granted Patent B2
US 10,484,370 · App. 15/549,565 · Granted Nov 19, 2019

Method for operating a security element

Inventor: Ulrich Wimböck (Tutzing, DE)
Assignee: GIESECK+DEVRIENT MOBILE SECURITY GMBH
H04L63/0853G06F21/575H04L63/102H04L63/20H04L67/12H04L67/125H04L67/306H04W4/50H04W8/183H04W12/00405H04W12/08H04W88/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,484,370
App. No.
15/549,565
Granted
Nov 19, 2019
Kind
B2
Abstract

A method for operating a security element of a mobile terminal with a memory unit includes using a first subscription profile with a first operating system for the security element, and a second subscription profile with a second operating system for the security element. The method involves operating the security element with the first operating system to communicate with the first subscription profile via a first mobile communication network; switching from the first operating system to the second operating system of the security element through a boot loader in the memory unit loading and executing the second operating system following a reboot of the security element; and operating the security element with the second operating system, to be able to communicate with the second subscription profile via a second mobile communication network. A corresponding security element and a corresponding mobile terminal are provided.

Claims (47)

1. A method for operating a security element of a mobile terminal with a memory unit, in which there are present a first subscription profile with a first operating system for the security element and a second subscription profile with a second operating system for the security element, wherein the method includes the following steps of:

operating the security element with the first operating system, in order to be able to communicate with the first subscription profile via a first mobile communication network;

switching from the first operating system to the second operating system of the security element through a boot loader in the memory unit loading and executing the second operating system following a reboot of the security element; and

operating the security element with the second operating system, in order to be able to communicate with the second subscription profile via a second mobile communication network;

wherein the switching includes:

receiving a message from a background system by the security element operated with the first operating system, with the information content that a switch is to be effected from the first operating system to the second operating system of the security element;

forwarding the message to the boot loader; and

extracting the information content of the message from the message by the boot loader, so that the settings of the boot loader are changed such that the second operating system of the security element is loaded and executed following a reboot of the security element,

wherein the settings of the boot loader are changed by placing in the boot loader a marker which defines that the second operating system of the security element is loaded and executed following a reboot of the security element; and/or

receiving an input from a user by the security element operated with the first operating system, with the information content that a switch is to be effected from the first operating system to the second operating system of the security element;

forwarding the input to the boot loader; and

extracting the information content of the input from the input by the boot loader, so that the settings of the boot loader are changed such that the second operating system of the security element is loaded and executed following a reboot of the security element,

wherein the settings of the boot loader are changed by placing in the boot loader a marker which defines that the second operating system of the security element is loaded and executed following a reboot of the security element; and/or

receiving a message from a background system by the security element operated with the first operating system, with the information content that a switch is to be effected from the first operating system to the second operating system of the security element;

extracting the information content of the message from the message by the security element operated with the first operating system; and

forwarding the information content of the message to the boot loader, so that the settings of the boot loader are changed such that the second operating system of the security element is loaded and executed following a reboot of the security element,

wherein the settings of the boot loader are changed by placing in the boot loader a marker which defines that the second operating system of the security element is loaded and executed following a reboot of the security element.

2. The method according to claim 1 , wherein the communication between the security element operated with the first operating system and the boot loader is effected via a suitably configured program library or programming interface or API (“application programming interface”).

3. A security element for a mobile terminal with a memory unit, in which there are present a first subscription profile with a first operating system for the security element and a second subscription profile with a second operating system for the security element, wherein the security element is configured to:

be operated with the first operating system, in order to be able to communicate with the first subscription profile via a first mobile communication network;

switch from the first operating system to the second operating system of the security element through a boot loader in the memory unit loading and executing the second operating system following a reboot of the security element;

be operated with the second operating system, in order to be able to communicate with the second subscription profile via a second mobile communication network;

wherein the switch includes:

receiving a message from a background system by the first operating system, with the information content that a switch is to be effected from the first operating system to the second operating system of the security element;

forwarding the message to the boot loader; and

extracting the information content of the message from the message by the boot loader, so that the settings of the boot loader are changed such that the second operating system of the security element is loaded and executed following a reboot of the security element,

wherein the settings of the boot loader are changed by placing in the boot loader a marker which defines that the second operating system of the security element is loaded and executed following a reboot of the security element; and/or

receiving a message from a background system by the first operating system, with the information content that a switch is to be effected from the first operating system to the second operating system of the security element;

extracting the information content of the message from the message by the first operating system; and

forwarding the information content of the message to the boot loader, so that the settings of the boot loader are changed such that the second operating system of the security element is loaded and executed following a reboot of the security element,

wherein the security element is configured to change the settings of the boot loader by placing in the boot loader a marker which defines that the second operating system of the security element is loaded and executed following a reboot of the security element.

4. The security element according to claim 3 , wherein the security element is configured such that the communication between the first operating system and the boot loader is effected via a suitably configured program library or programming interface or API (“application programming interface”).

5. A mobile terminal comprising:

a security element, the security element comprising:

a memory unit, in which there are present a first subscription profile with a first operating system for the security element and a second subscription profile with a second operating system for the security element, wherein the security element is configured to:

be operated with the first operating system, in order to be able to communicate with the first subscription profile via a first mobile communication network;

switch from the first operating system to the second operating system of the security element through a boot loader in the memory unit loading and executing the second operating system following a reboot of the security element; and

be operated with the second operating system, in order to be able to communicate with the second subscription profile via a second mobile communication network;

wherein the switch includes:

receiving a message from a background system by the first operating system, with the information content that a switch is to be effected from the first operating system to the second operating system of the security element;

forwarding the message to the boot loader; and

extracting the information content of the message from the message by the boot loader, so that the settings of the boot loader are changed such that the second operating system of the security element is loaded and executed following a reboot of the security element,

wherein the settings of the boot loader are changed by placing in the boot loader a marker which defines that the second operating system of the security element is loaded and executed following a reboot of the security element; and/or

receiving a message from a background system by the first operating system, with the information content that a switch is to be effected from the first operating system to the second operating system of the security element;

extracting the information content of the message from the message by the first operating system; and

forwarding the information content of the message to the boot loader, so that the settings of the boot loader are changed such that the second operating system of the security element is loaded and executed following a reboot of the security element,

wherein the security element is configured to change the settings of the boot loader by placing in the boot loader a marker which defines that the second operating system of the security element is loaded and executed following a reboot of the security element.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2017
From: WIMBÖCK, ULRICH
To: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Reel/Frame 043483/0479 →
Priority Claims (1)
DE 10 2015 001 900 · Feb 9, 2015 · national
Continuity (1)
Related Publication 20180241744A1 · Aug 23, 2018
Cited By (1)
US 12,278,823