Patents by Inventor Ulrich Huber
Ulrich Huber has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 11943837Abstract: A method for managing subscription profiles of a security element, which is provided for use in a mobile end device and on which a profile manager and at least one first subscription profile is loaded, includes: loading a second subscription profile from a subscription management server; checking whether the at least one first loaded subscription profile satisfies a predetermined condition; and putting the at least one first subscription profile out of operation when the at least one first subscription profile satisfies the predetermined condition.Type: GrantFiled: January 29, 2020Date of Patent: March 26, 2024Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBHInventors: Andreas Morawietz, Nils Nitsch, Ulrich Huber, Ulrich Wimbock
-
Patent number: 11716620Abstract: A subscriber identity module (eUICC), comprises profiles for the utilization of a mobile terminal that include at least a first profile and at least a second profile, of which the second profile (Pr1, Pr2) is devised as an active profile. The first profile is designed as a root profile (PrR) which in a normal state of the subscriber identity module is in an inactive state, and which is devised to be activated in response to an authentication command (AUTHENTICATE) received at the subscriber identity module. The authentication command is specially parameterized for the root profile (PrR) with a specific root value of the network parameter (P2) to be activated during a change-over period. The initially active second profile (Pr1, Pr2) is deactivated during the change-over period. After the end of the change-over period, the first profile (PrR) is again deactivated and the second profile (Pr1, Pr2) is again activated.Type: GrantFiled: September 27, 2021Date of Patent: August 1, 2023Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBHInventors: Ulrich Huber, Nils Nitsch
-
Publication number: 20220132297Abstract: A method for managing subscription profiles of a security element, which is provided for use in a mobile end device and on which a profile manager and at least one first subscription profile is loaded, includes: loading a second subscription profile from a subscription management server; checking whether the at least one first loaded subscription profile satisfies a predetermined condition; and putting the at least one first subscription profile out of operation when the at least one first subscription profile satisfies the predetermined condition.Type: ApplicationFiled: January 29, 2020Publication date: April 28, 2022Inventors: Andreas MORAWIETZ, Nils NITSCH, Ulrich HUBER, Ulrich WIMBOCK
-
Publication number: 20220014913Abstract: A subscriber identity module (eUICC), comprises profiles for the utilization of a mobile terminal that include at least a first profile and at least a second profile, of which the second profile (Pr1, Pr2) is devised as an active profile. The first profile is designed as a root profile (PrR) which in a normal state of the subscriber identity module is in an inactive state, and which is devised to be activated in response to an authentication command (AUTHENTICATE) received at the subscriber identity module. The authentication command is specially parameterized for the root profile (PrR) with a specific root value of the network parameter (P2) to be activated during a change-over period. The initially active second profile (Pr1, Pr2) is deactivated during the change-over period. After the end of the change-over period, the first profile (PrR) is again deactivated and the second profile (Pr1, Pr2) is again activated.Type: ApplicationFiled: September 27, 2021Publication date: January 13, 2022Inventors: Ulrich HUBER, Nils NITSCH
-
Patent number: 11202201Abstract: A subscriber identity module (eUICC), comprises profiles for the utilization of a mobile terminal that include at least a first profile and at least a second profile, of which the second profile (Pr1, Pr2) is devised as an active profile. The first profile is designed as a root profile (PrR) which in a normal state of the subscriber identity module is in an inactive state, and which is devised to be activated in response to an authentication command (AUTHENTICATE) received at the subscriber identity module. The authentication command is specially parameterized for the root profile (PrR) with a specific root value of the network parameter (P2) to be activated during a change-over period. The initially active second profile (Pr1, Pr2) is deactivated during the change-over period. After the end of the change-over period, the first profile (PrR) is again deactivated and the second profile (Pr1, Pr2) is again activated.Type: GrantFiled: November 30, 2016Date of Patent: December 14, 2021Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBHInventors: Ulrich Huber, Nils Nitsch
-
Patent number: 10966081Abstract: A system for registering an MSISDN with a device hosting the UICC and in which the UICC is or can be operated includes a UICC provisioning server operated by an UICC different from the MNO. A Local Profile Assistant LPA is installed within the device or the UICC, and enables establishment of secured data sessions between the UICC and the UICC provisioning server. A modem is installed within the device or UICC. The modem enables communication of the device within a mobile network operator MNO mobile network. An MSISDN retrieval logic is associated with the LPA. A logic is constructed to perform a retrieval sequence with the foregoing components and data.Type: GrantFiled: December 20, 2018Date of Patent: March 30, 2021Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBHInventors: Jorgen Hult, Markus Haubner, Nils Nitsch, Waleed Badawy, Ulrich Huber, Anders Kokeritz, Hrushikesh Chidley, Rikard Forselius, Gero Galka
-
Patent number: 10904742Abstract: A method for the communicating of a subscriber identity module, implemented or implementable in an end device, in which at least one profile is adapted for the utilization of the mobile end device in a mobile communication network, vis-à-vis a server, in which method a message from the subscriber identity module is sent to the server. Before the sending of the message, a step of the establishing of a technology is carried out in the subscriber identity module in which there is established, which technology the profile corresponds to, and the sending is carried out compliant with the technology. The communicating can involve the notifying of a profile change effected in the subscriber identity module.Type: GrantFiled: June 24, 2016Date of Patent: January 26, 2021Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBHInventors: Nils Nitsch, Ulrich Huber
-
Publication number: 20210006969Abstract: A system for registering an MSISDN with a device hosting the UICC and in which the UICC is or can be operated includes a UICC provisioning server operated by an UICC different from the MNO. A Local Profile Assistant LPA is installed within the device or the UICC, and enables establishment of secured data sessions between the UICC and the UICC provisioning server. A modem is installed within the device or UICC. The modem enables communication of the device within a mobile network operator MNO mobile network. An MSISDN retrieval logic is associated with the LPA. A logic is constructed to perform a retrieval sequence with the foregoing components and data.Type: ApplicationFiled: December 20, 2018Publication date: January 7, 2021Inventors: Jorgen HULT, Markus HAUBNER, Nils NITSCH, Waleed BADAWY, Ulrich HUBER, Anders KOKERITZ, Hrushikesh CHIDLEY, Rikard FORSELIUS, Gero GALKA
-
Patent number: 10631214Abstract: A method for performing a switch from a first mobile network to a second mobile network by a mobile terminal comprising a secure element includes the following steps: attaching to the first mobile network using a first subscription profile; downloading a second subscription profile from a subscription management server including a command script defining a sequence of commands; attaching to the second mobile network; and executing the sequence of commands defined by the command script.Type: GrantFiled: August 8, 2014Date of Patent: April 21, 2020Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBHInventors: Ulrich Huber, Thomas Larsson
-
Patent number: 10602341Abstract: A loading package is adapted for loading a profile for a subscription into a subscriber identity module. A loading sequence through the implementation of which in the subscriber identity module the profile is set up in the subscriber identity module. A profile loading counter sequence is generated on the basis of a counter reading of a profile loading counter maintained at a data preparation server; is adapted to load into the subscriber identity module a profile loading counter with the generated counter reading; and is loaded into the subscriber identity module before the loading sequence. The profile loading counter sequence is further adapted if no implemented profile loading counter is present in the subscriber identity module, to implement the profile-loading counter in the subscriber identity module with a counter reading which determines an admissible number of times which the loading package may be loaded into the subscriber identity module.Type: GrantFiled: October 6, 2016Date of Patent: March 24, 2020Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBHInventors: Nils Nitsch, Ulrich Huber
-
Patent number: 10231127Abstract: A method of performing a switch from a first mobile network to a second mobile network by a mobile terminal comprising a secure element comprises the steps of: (a) requesting attachment to the first mobile network using a first identification data element, preferably a first IMSI, of a first subscription profile; (b) requesting attachment to the second mobile network using a second identification data element, preferably a second IMSI, of a second subscription profile; and (c) requesting attachment to the first mobile network. The second mobile network or another mobile network uses a confirmation data element, wherein the confirmation data element has the same format as the first and the second identification data element and is configured such that the attachment request is forwarded to a subscription management server in order to inform the subscription management server whether the attachment to the second mobile network was successful.Type: GrantFiled: August 8, 2014Date of Patent: March 12, 2019Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBHInventors: Ulrich Huber, Thomas Larsson
-
Publication number: 20180367992Abstract: A subscriber identity module (eUICC), comprises profiles for the utilization of a mobile terminal that include at least a first profile and at least a second profile, of which the second profile (Pr1, Pr2) is devised as an active profile. The first profile is designed as a root profile (PrR) which in a normal state of the subscriber identity module is in an inactive state, and which is devised to be activated in response to an authentication command (AUTHENTICATE) received at the subscriber identity module. The authentication command is specially parameterized for the root profile (PrR) with a specific root value of the network parameter (P2) to be activated during a change-over period. The initially active second profile (Pr1, Pr2) is deactivated during the change-over period. After the end of the change-over period, the first profile (PrR) is again deactivated and the second profile (Pr1, Pr2) is again activated.Type: ApplicationFiled: November 30, 2016Publication date: December 20, 2018Inventors: Ulrich HUBER, Nils NITSCH
-
Publication number: 20180317083Abstract: A method for the communicating of a subscriber identity module, implemented or implementable in an end device, in which at least one profile is adapted for the utilization of the mobile end device in a mobile communication network, vis-à-vis a server, in which method a message from the subscriber identity module is sent to the server. Before the sending of the message, a step of the establishing of a technology is carried out in the subscriber identity module in which there is established, which technology the profile corresponds to, and the sending is carried out compliant with the technology. The communicating can involve the notifying of a profile change effected in the subscriber identity module.Type: ApplicationFiled: June 24, 2016Publication date: November 1, 2018Inventors: Nils NITSCH, Ulrich HUBER
-
Patent number: 10104517Abstract: A method for loading a profile for a mobile radio subscription from a data preparation server into a subscriber identity module, comprises the steps: (a) providing a profile at the data preparation server; (b) generating a single executable program code module of the profile provided according to (a), which program code module is arranged such that by executing the executable program code module the profile is installed in the subscriber identity module; (c?) loading the single executable program code module into the subscriber identity module. A method for installing a profile in the subscriber identity module, comprises the steps: (d) sending an APDU command from the data preparation server to the subscriber identity module; (e) in reaction to a reception of the APDU command at the subscriber identity module, executing the executable program code module and by executing installing the profile in the subscriber identity module.Type: GrantFiled: March 24, 2016Date of Patent: October 16, 2018Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBHInventors: Nils Nitsch, Ulrich Huber
-
Publication number: 20180288607Abstract: A loading package is adapted for loading a profile for a subscription into a subscriber identity module. A loading sequence through the implementation of which in the subscriber identity module the profile is set up in the subscriber identity module. A profile loading counter sequence is generated on the basis of a counter reading of a profile loading counter maintained at a data preparation server; is adapted to load into the subscriber identity module a profile loading counter with the generated counter reading; and is loaded into the subscriber identity module before the loading sequence. The profile loading counter sequence is further adapted if no implemented profile loading counter is present in the subscriber identity module, to implement the profile-loading counter in the subscriber identity module with a counter reading which determines an admissible number of times which the loading package may be loaded into the subscriber identity module.Type: ApplicationFiled: October 6, 2016Publication date: October 4, 2018Applicant: GIESECKE+DEVRIENT MOBILE SECURITY GMBHInventors: Nils NITSCH, Ulrich HUBER
-
Patent number: 9948641Abstract: A method and a system are provided for providing a subscription profile on a mobile terminal for communication via a mobile communication network. The method comprises the following steps: the logging in of a first mobile terminal with a first subscription profile to a mobile communication network; the downloading of a second subscription profile to the first mobile terminal via the mobile communication network; and the forwarding of the second subscription profile from the first mobile terminal to a second mobile terminal via a communication channel.Type: GrantFiled: September 22, 2015Date of Patent: April 17, 2018Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBHInventors: Carsten Ahrens, Bernd Müller, Jens Dinger, Andreas Morawietz, Ulrich Huber
-
Publication number: 20180063667Abstract: A method for loading a profile for a mobile radio subscription from a data preparation server into a subscriber identity module, comprises the steps: (a) providing a profile at the data preparation server; (b) generating a single executable program code module of the profile provided according to (a), which program code module is arranged such that by executing the executable program code module the profile is installed in the subscriber identity module; (c?) loading the single executable program code module into the subscriber identity module. A method for installing a profile in the subscriber identity module, comprises the steps: (d) sending an APDU command from the data preparation server to the subscriber identity module; (e) in reaction to a reception of the APDU command at the subscriber identity module, executing the executable program code module and by executing installing the profile in the subscriber identity module.Type: ApplicationFiled: March 24, 2016Publication date: March 1, 2018Inventors: Nils NITSCH, Ulrich HUBER
-
Patent number: 9794775Abstract: A method of performing a switch from a first mobile network to a second mobile network by a mobile terminal comprising a secure element includes the steps of: (a) attaching to the first mobile network using a first attachment message containing a first identification data element, preferably a first IMSI, of a first subscription profile; and (b) attaching to the second mobile network by an attachment process including a second attachment message containing a second identification data element, preferably a second IMSI, of a second subscription profile. The second mobile network is configured to monitor at least parts of the attachment process, to determine the second identification data element contained therein and to forward this information to a subscription management server in order to confirm the successful attachment of the secure element to the second mobile network.Type: GrantFiled: August 8, 2014Date of Patent: October 17, 2017Assignee: GIESECKE+DEVRIENT MOBILE SECURITYInventors: Ulrich Huber, Thomas Larsson
-
Publication number: 20170295172Abstract: A method and a system are provided for providing a subscription profile on a mobile terminal for communication via a mobile communication network. The method comprises the following steps: the logging in of a first mobile terminal with a first subscription profile to a mobile communication network; the downloading of a second subscription profile to the first mobile terminal via the mobile communication network; and the forwarding of the second subscription profile from the first mobile terminal to a second mobile terminal via a communication channel.Type: ApplicationFiled: September 22, 2015Publication date: October 12, 2017Applicant: GIESECKE & DEVRIENT GMBHInventors: Carsten AHRENS, Bernd MÜLLER, Jens DINGER, Andreas MORAWIETZ, Ulrich HUBER
-
Patent number: 9451461Abstract: A subscriber identity module for authenticating a subscriber on a communication network includes: a first set of subscriber identity data for authenticating the subscriber; a second set of subscriber identity data for authenticating the subscriber, with the first set of subscriber identity data differing from the second set of subscriber identity data; and a means for managing the first and second sets of subscriber identity data, with the managing being realized by management functions. The subscriber identity module can be extended to a method for managing the subscriber identity module, to a use of the subscriber identity module in a mobile end device, and to a system comprising subscriber end devices and a remote entity.Type: GrantFiled: August 22, 2013Date of Patent: September 20, 2016Assignee: Giesecke & Devrient GmbHInventors: Karl Eglof Hartel, Ulrich Huber, Nils Nitsch