Abstract:
The invention proposes several improvements related to the management of secure elements, like UICCs embedding Sim applications, these secure elements being installed, fixedly or not, in terminals, like for example mobile phones. In some cases, the terminals are constituted by machines that communicate with other machines for M2M (Machine to Machine) applications.
Abstract:
The invention concerns a method for downloading subscriptions in secure elements (10), each secure element (10) cooperating with a telecommunication terminal, the method consisting in: - Preparing, at the level of a Subscriber Manager Data Preparation unit (12) a plurality of subscriptions ready to be loaded on the secure elements (10) on demand, these subscriptions not being linked to any particular secure element (10) a that time; - Securing the subscriptions within a SCP03 script : - linked to a first unique AID as being the identifier of the Security Domain containing data of all subscriptions he would like to manage; - with a first SCP03 keyset as defined in GlobalPlatform SCP03 amendment D; - At the occurrence of a request for downloading one of these subscriptions in one of the secure elements (10), requesting a Subscriber Manager Secure Routing unit (SM-SR) to create a ISD-P in this secure element (10) by using a second AID different from the first unique AID; - Transmitting the second AID from the Subscriber Manager Secure Routing unit (SM-SR) to the Subscriber Manager Data Preparation unit (12); - Executing a key establishment procedure between the Subscriber Manager Data Preparation unit (12) and the ISD-P, identified by the second AID, and set a first private SCP03 keyset with the ISD-P; - Opening a new SCP03 channel between the Subscriber Manager Data Preparation unit (12) and the ISD-P by using the shared private SP03 keyset and a pseudo-random based on the second AID; - Setting the first unique AID on the ISD-P as an additional AID; - Opening a new SCP03 channel between the Subscriber Manager Data Preparation unit (12) and the ISD-P by using the shared private SCP03 keyset and a pseudo-random based on the first unique AID; - Sending from the Subscriber Manager Data Preparation unit (12) the subscription to the secure element (10), including the setting of the first SCP03 keyset; - Executing the subscription in the secure element (10) in order to install it by deciphering the subscription thanks to the first SCP03 keyset and the first unique AID.
Abstract:
The invention concerns a method for downloading subscriptions in secure elements (10), each secure element (10) cooperating with a telecommunication terminal. According to the invention, the method consists in: a- Ciphering at the level of a manufacturer unit of the secure element, the subscriptions with a manufacturer key and a unique first AID; b- Transferring the ciphered subscriptions to a Subscription Manager Data Preparation unit (SM-DP) along with the manufacturer key and the unique first AID; c- At the occurrence of a request for downloading one of these subscriptions in one secure element, generating a second AID by a Subscription Manager Secure Routing unit (SM-SR) in order to be able to address the content of the subscription later on through the second AID. d- Transmitting one ciphered subscription to this secure element (10), along with the manufacturer key and the unique first AID; e- Deciphering in the secure element (10) the subscription with the manufacturer key and the first unique AID and installing the subscription in the secure element (10).
Abstract translation:本发明涉及一种用于在安全元件(10)中下载订阅的方法,每个安全元件(10)与电信终端协作。 根据本发明,该方法包括:a)利用制造商密钥和独特的第一AID在安全元件的制造商单元的级别加密订阅, b-将加密订阅与制造商密钥和唯一的第一个AID一起传输到订阅管理器数据准备单元(SM-DP); c - 在一个安全元素中下载其中一个订阅的请求时,由订阅管理器安全路由单元(SM-SR)生成第二个AID,以便能够稍后通过 第二个AID。 d。将制造商密钥和独特的第一个AID连同一个加密订阅发送到该安全元件(10); e。使用制造商密钥和第一唯一AID在安全元件(10)中解密订阅,并将订阅安装在安全元件(10)中。
Abstract:
The present invention concerns a method for transmitting a Sim application of a first terminal to a second terminal, the Sim application being stored in a secure element included in the first terminal, the access to the Sim application being locked by a Pin code. According to the invention, the method consists in: i - exporting thed Sim application from the first terminal to a distant site, by including the Pin code as well as a remote loading code; ii - ask to the user of the second terminal to enter the remote loading code in the second terminal; iii - in the event the remote loading code entered by the user matches the remote loading code that has been exported, authorizing the installation of the Sim application in a secure element of the second terminal, and otherwise, do not install the Sim application in the secure element of the second terminal.
Abstract:
Metodo para la exportación en un servidor seguro los datos comprendidos en una UICC incluida en un terminal, dicho metodo consistente en: A petición de la exportación, firmar una peticion de exportación realizada por la UICC, siendo transmitida la petición de exportación por el terminal al servidor; Verificar, a nivel del servidor, la solicitud de exportación firmada mediante la comparación de la firma y la identidad de la UICC; Si la verificacion es positiva, envio por parte del servidor de un certificado de exportación firmado a la UICC a traves del terminal; Verificación del certificado de exportacion firmado en la UICC y, en caso positivo, la preparación de un paquete de exportación que contiene los datos, el paquete de exportación esta firmado y cifrado por la UICC; El envio del paquete de exportacion al terminal; y establecer los datos exportados como "inservible" en la UICC; - La transmisión desde el terminal al servidor del paquete de exportación; Recepción del paquete y verificar la firma a nivel del servidor; Firmar un mensaje de acuse de recibo y transmitirlo a la UICC a traves del terminal; - En la UICC, verificar el mensaje de acuse de recibo y, Si se reconoce la firma del servidor, destruir los datos que se han exportado y enviar mensaje de acuse de recibo al servidor a traves del terminal; Verificación de la firma del mensaje de acuse de recibo en el servidor y, Si la firma es reconocida, configurar los datos disponibles para una transferencia.