US2014365769A9PendingUtilityA9

Method and arrangement for provisioning and managing a device

Assignee: TELEFONKATIEBOLAGET L M ERICKSSON PUBLPriority: Oct 28, 2008Filed: Dec 12, 2012Published: Dec 11, 2014
Est. expiryOct 28, 2028(~2.3 yrs left)· nominal 20-yr term from priority
H04L 63/08H04L 9/12H04L 2463/061H04L 9/0825H04W 12/04H04L 9/0869H04W 4/70H04W 4/50H04W 4/60H04L 2209/805H04W 12/35H04L 9/0891
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method, arrangement, and provisioning server in a Selected Home Operator (SHO) network for downloading a new Downloadable Universal Subscriber Identity Module (DLUSIM) to a communication device when the communication device changes from a first operator network to the SHO network. A manager of the communication device registers with the SHO network and transfers K Auth to the SHO network. The communication device then receives a bootstrapping message instructing the device to connect to the provisioning server. The bootstrapping message includes an address of the provisioning server and an authentication nonce. The SHO network validates the communication device when the communication device attempts to connect to the provisioning server. The SHO network then generates the new DLUSIM and encrypts the new DLUSIM with K Provision . The provisioning server then downloads the new DLUSIM as an encrypted blob to the communication device.

Claims

exact text as granted — not AI-modified
1 - 17 . (canceled) 
     
     
         18 . A method of downloading a new Downloadable Universal Subscriber Identity Module (DLUSIM) to a communication device while changing the communication device from a first operator network to a second operator network, said method comprising the steps of:
 a manager of the communication device registering with the second operator network, wherein the registering step includes transferring K Auth  to the second operator network;   receiving by the communication device, a bootstrapping message instructing the device to connect to a provisioning service of the new operator network, wherein the bootstrapping message includes an address of the provisioning service of the new operator network and an authentication nonce;   validating the communication device by the new operator network when the communication device attempts to connect to the provisioning service;   the second operator network generating a new DLUSIM and encrypting the DLUSIM with K Provision ;   downloading the DLUSIM as an encrypted blob to the communication device from an Open Mobile Alliance Device Management (OMA DM) provisioning server in the second operator network; and   the communication device attaching to the second operator network utilizing the new DLUSIM.   
     
     
         19 . The method as recited in  claim 18 , wherein the step of receiving a bootstrapping message by the communication device includes receiving the bootstrapping message from an entity selected from the manager of the device, the second operator network, and the first operator network. 
     
     
         20 . The method as recited in  claim 18 , wherein the encrypted blob includes a password parameter based on K Auth . 
     
     
         21 . The method as recited in  claim 18 , wherein the step of downloading the DLUSIM as an encrypted blob includes the second operator network utilizing K Auth  as an integrity protection key to protect the encrypted blob. 
     
     
         22 . The method as recited in  claim 18 , wherein the OMA DM provisioning server is not located in the second operator network, and the method further comprises the steps of:
 the second operator applying K Auth  and confidentiality protection to the encrypted DLUSIM; and   passing the protected encrypted DLUSIM to the OMA DM provisioning server.   
     
     
         23 . An arrangement for downloading a new Downloadable Universal Subscriber Identity Module (DLUSIM) to a communication device when the communication device changes from a first operator network to a Selected Home Operator (SHO) network, the arrangement comprising:
 an Open Mobile Alliance Device Management (OMA DM) provisioning server,   a Platform Validation Authority (PVA);   a Home Subscriber Server/Authentication Center (HSS/AuC); and   a registration unit configured to receive from a manager of the communication device, a subscription registration including K Auth , and to cause a bootstrapping message to be sent to the communication device, the bootstrapping message instructing the communication device to connect to the provisioning server, wherein the bootstrapping message includes an address of the provisioning server and an authentication nonce;   wherein the provisioning server is configured to:
 receive a connection attempt from the communication device; 
 communicate with the PVA to validate the communication device upon receiving the connection attempt from the communication device; 
 upon successful validation of the communication device, communicate with the HSS/AuC to generating the new DLUSIM and to encrypt the new DLUSIM with K Provision ; and 
 download the new DLUSIM as an encrypted blob to the communication device, for subsequent attachment of the communication device to the SHO network utilizing the new DLUSIM. 
   
     
     
         24 . The arrangement as recited in  claim 23 , wherein the bootstrapping message is sent to the communication device from one of:
 the manager of the device;   the SHO network; and   the first operator network.   
     
     
         25 . The arrangement as recited in  claim 23 , wherein the encrypted blob includes a password parameter based on K Auth . 
     
     
         26 . The arrangement as recited in  claim 23 , wherein the provisioning server is configured to utilize K Auth  as an integrity protection key to protect the encrypted blob while downloading the DLUSIM to the communication device. 
     
     
         27 . The arrangement as recited in  claim 23 , wherein the provisioning server is not located in the SHO network, and the SHO network is configured to:
 apply K Auth  and confidentiality protection to the encrypted DLUSIM, and pass the protected encrypted DLUSIM to the provisioning server for downloading to the communication device.   
     
     
         28 . An Open Mobile Alliance Device Management (OMA DM) provisioning server in a Selected Home Operator (SHO) network for downloading a new Downloadable Universal. Subscriber Identity Module (DLUSIM) to a communication device when the communication device changes from a first operator network to the SHO network, wherein the SHO network is in communication with a Platform Validation Authority (PVA) and includes a Home Subscriber Server/Authentication Center (HSS/AuC) and a registration unit configured to receive from a manager of the communication device, a subscription registration including K Auth , and to cause a bootstrapping message to be sent to the communication device, the bootstrapping message instructing the communication device to connect to the provisioning server, wherein the bootstrapping message includes an address of the provisioning server and an authentication nonce, wherein the provisioning server includes a processor coupled to a non-transitory memory that stores computer program instructions, wherein when the processor executes the computer program instructions, the provisioning server is caused to:
 receive a connection attempt from the communication device;   communicate with the PVA to validate the communication device upon receiving the connection attempt from the communication device;   upon successful validation of the communication device, communicate with the HSS/AuC to generating the new DLUSIM and to encrypt the new DLUSIM with K Provision , and   download the new DLUSIM as an encrypted blob to the communication device, for subsequent attachment of the communication device to the SHO network utilizing the new DLUSIM.   
     
     
         29 . The provisioning server as recited in  claim 28 , wherein the encrypted blob includes a password parameter based on K Auth , 
     
     
         30 . The provisioning server as recited in  claim 28 , wherein the provisioning server is configured to utilize K Auth  as an integrity protection key to protect the encrypted blob while downloading the DLUSIM to the communication device.

Join the waitlist — get patent alerts

Track US2014365769A9 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.