SMART CARD PERSONNALIZATION WITH LOCAL GENERATION OF KEYS
First Claim
1. A method for personalizing a smart card coupled with a communication device of a user being a subscriber of a first telecommunication network, a first international identity and a first authentication key being stored in the smart card, the method comprising:
- receiving a first message from an application server connected to the first telecommunication network and a second telecommunication network, the first message comprising a personalization command and an admin code;
interpreting the personalization command to establish a secure session with a personalization server via the application server if the admin code is valid;
negotiating with the personalization server to agree on a second authentication key by exchanging messages that contain values derived from random secrets;
receiving a second message that contains a second international identity from the personalization server (PS); and
replacing the first international identity and the first authentication key with the second international identity and the second authentication key.
1 Assignment
0 Petitions
Accused Products
Abstract
For personalizing a smart card (SC) coupled with a communication device (CD) of a user being a subscriber of a first telecommunication network (TN1) and wishing to become a subscriber of a second telecommunication network (TN2), a first international identity (IMSI—1) and a first authentication key (AK—1) being stored in the smart card (SC), the smart card receives a message (MesP) from an application server (AS) connected to the first telecommunication network and the second telecommunication network, the message (MesN) comprising a personalization command (ComP) and an admin code (ACas), after that the application server has received a request (Req) of subscription change comprising an identifier (1dMNO2) of the second telecommunication network (TN2) and has established a secured session with a personalization server (PS) of the second telecommunication network (TN2) identified by the identifier (1dMNO2), LR2 and interprets the personalization command (ComP) to establish a secure session with the personalization server (PS) via the application server (AS), if the admin code (ACas) is valid. The smart card negotiates with the personalization server to agree on an second authentication key, by exchanging messages containing values derived from random secrets, receives a message (Mes3) containing an second international identity (IMSI—2) from the personalization server (PS), and replaces the first international identity (IMSI—1) and the first authentication key (AK—1) by the second international identity and the second authentication key.
10 Citations
15 Claims
-
1. A method for personalizing a smart card coupled with a communication device of a user being a subscriber of a first telecommunication network, a first international identity and a first authentication key being stored in the smart card, the method comprising:
-
receiving a first message from an application server connected to the first telecommunication network and a second telecommunication network, the first message comprising a personalization command and an admin code; interpreting the personalization command to establish a secure session with a personalization server via the application server if the admin code is valid; negotiating with the personalization server to agree on a second authentication key by exchanging messages that contain values derived from random secrets; receiving a second message that contains a second international identity from the personalization server (PS); and replacing the first international identity and the first authentication key with the second international identity and the second authentication key. - View Dependent Claims (2, 3, 4, 5, 7, 8, 9)
-
-
6. (canceled)
-
10. (canceled)
-
11. A smart card coupled with a communication device of a user being a subscriber of a first telecommunication network, a first international identity and a first authentication key being stored in the smart card, the smart card comprising:
-
means for receiving a first message from an application server connected to the first telecommunication network and a second telecommunication network, the first message comprising a personalization command and an admin code; means for interpreting the personalization command to establish a secure session with a personalization server via the application server if the admin code is valid; means for negotiating with the personalization server to agree on a second authentication key by exchanging messages that contain values derived from random secrets; means for receiving a second message that contains a second international identity from the personalization server (PS); means for replacing the first international identity and the first authentication key with the second international identity and the second authentication key.
-
-
12. An application server for personalizing a smart card coupled with a communication device of a user being a subscriber of a first telecommunication network, a first international identity and a first authentication key being stored in the smart card, the application server being connected to the first telecommunication network and a second telecommunication network, the application server comprising:
-
means for receiving a request of subscription change comprising an identifier of the second telecommunication network; means for establishing a secured session with a personalization server of the second telecommunication network identified by the identifier; and means for sending a first message comprising a personalization command and an admin code in order that the smart card interprets the personalization command to establish a secure session with a personalization server via the application server if the admin code is valid; negotiates with the personalization server to agree on a second authentication key by exchanging messages that contain values derived from random secret; receives a second message that contains a second international identity from the personalization server (PS); and replaces the first international identity and the first authentication key with the second international identity and the second authentication key.
-
-
13. An personalization server for personalizing a smart card coupled with a communication device of a user being a subscriber of a first telecommunication network, a first international identity and a first authentication key being stored in the smart card, the personalization server being connected to a second telecommunication network, the personalization server comprising:
-
means for establishing a secure session with the smart card via an application server connected to the first and second telecommunication networks if an admin code received in a first message sent from the application server to the smart card is valid; means for negotiating with the smart card to agree on a second authentication key by exchanging messages that contain values derived from random secrets; and means for sending a second message that contains a second international identity to the smart card that is able to replace the first international identity and the first authentication key with the second international identity and the second authentication key.
-
-
14. An information medium readable by a data processing device having computer readable instructions encoded therein, said computer readable instructions adapted to be executed in an application server for personalizing a smart card coupled with a communication device of a user being a subscriber of a first telecommunication network, a first international identity and a first authentication key being stored in the smart card, the application server being connected to the first telecommunication network and the second telecommunication network, said computer readable instructions adapted to be executed to implement a method, comprising:
-
receiving a request of subscription change comprising an identifier of the second telecommunication network; establishing a secured session with a personalization server of the second telecommunication network identified by the identifier; and sending a first message comprising a personalization command and an admin code in order that the smart card interprets the personalization command to establish a secure session with a personalization server via the application server if the admin code (ACas) is valid; negotiates with the personalization server to agree on a second authentication key by exchanging messages that contain values derived from random secrets receives a second message that contains a second international identity from the personalization server; and replaces the first international identity and the first authentication key with the second international identity and the second authentication key.
-
-
15. An information medium readable by a data processing device adapted to be executed in a personalization server for personalizing a smart card coupled with a communication device of a user being a subscriber of a first telecommunication network, a first international identity and a first authentication key being stored in the smart card, the personalization server being connected to the second telecommunication network, said computer readable instructions adapted to be executed to implement a method, comprising:
-
establishing a secure session with the smart card via an application server connected to the first and second telecommunication networks if an admin code received in a first message sent from the application server to the smart card is valid; negotiating with the smart card to agree on a second authentication key by exchanging messages that contain values derived from random secrets; and sending a second message that contains a second international identity to the smart card that is able to replace the first international identity and the first authentication key with the second international identity and the second authentication key.
-
Specification