Abstract:
A tamper resistant device (11; 21) implementing an embedded Universal Integrated Circuit Card (15) comprising at least a security domain (P0) in which at least a telecommunication profile (Pj) is stored, said device (21) comprising a physical interface (18) configured to allow access from a processor (13) configured to operate with at least a mobile telecommunications network to said at least a telecommunication profile (Pj. Said tamper resistant device (21) a further security domain (PS0) storing at least an application profile (Si; PSi) and a further physical interface (17) configured to allow access from an application processor (12) to said at least an application profile (Si; PSi) stored in said further security domain (PSO), said single tamper resistant device (21) being configured to enable accessibility to the at least an application profile (PSi) if corresponding commands (C) are received in signals exchanged on the first interface (17) and to enable accessibility to the telecommunication profile (Pj) if corresponding commands (C) are received in signals exchanged on the second interface (18).
Abstract:
La présente description concerne un procédé de communication, à un module tiers d'un premier dispositif électronique, de premières données (DATA4) échangées entre un premier module du premier dispositif électronique et un deuxième module, le module tiers étant différent du premier module et du deuxième module, le premier dispositif comprenant au moins un élément sécurisé (402) et un routeur (401) transmettant les premières données (DATA4) du premier module au deuxième module, le routeur (401) étant adapté à être mis dans un mode sécurisé dans lequel, lorsque le module tiers demande accès aux premières données (DATA4), un procédé d'authentification est mis en oeuvre pour vérifier si le module tiers est autorisé ou non à avoir accès aux premières données (DATA4).
Abstract:
A method for performing a management of a multi-subscription SIM module (108a), said multi-subscription SIM module (108a) comprising at least one memory (1084a) adapted to store at least a first (P1) and a second (P2) profile associated with a respective first and a second mobile network operator, said memory (1084) comprising a volatile portion (1084R), said operation of storing including installing or updating (1004) profiles (PI, P2) by downloading one or more downloaded profiles (Pd) from a remote host (30a), said management including selecting one or more enabled profiles (Ps) comprising an application to be executed and allocating a partition of the volatile portion (1084R) of the memory to said one or more enabled profile (Ps), specifically, dividing (2005) the area of the volatile memory (1084R) in a partition (OSP) for the operative system, a partition (SPP) for the each of the one or more enabled profiles and a partition for a downloaded profile (DPP), said partition for the enabled profile (SPP) and partition for a downloaded profile (DPP) having the same size, allocating (2010) the partition for the enabled profile (SPP) to the enabled profile (Ps), maintaining the partition for a downloaded profile (DPP) not accessible, during a profile download operation (1004), accessing (2015) only the partition for a downloaded profile (DPP) allocating said partition for a downloaded profile (DPP) to the downloaded profile (Pd), during a profile change operation (1006) swapping (2020) the downloading profile (Pd) from the partition for a downloaded profile (DPP) to one of the partitions for the enabled profile (SPP).
Abstract:
A method for performing a remote management of a multi-subscription SIM module (108a) is disclosed. The multi-subscription SIM module (108a) comprises at least one memory adapted to store a first (P1) and a second (P2) profile associated with a respective first (MNO1) and a second (MNO2) mobile network operator, such that a respective content may be associated with each profile (P1, P2). Specifically, the method comprises receiving a remote management message from a remote host (30a, 30b), wherein the remote management message comprises a remote management command, and a sender address and/or a destination address. Next, the remote management message is processed in order to determine the sender address and/or the destination address and a target profile (P1; P2) of the remote management command is determined as a function of the sender address and/or the destination address. Accordingly, once having determined the target profile, the remote management command may be executed in order to interact with the content of the target profile (P1; P2).