Apparatus, method and computer program product for controlling the usability of an application module by means of security module
Abstract
Es wird für ein Kommunikationsendgerät (10) ein Sicherheitsmodul (1) vorgeschlagen, das eingerichtet ist, ein Telekommunikationsnetz (2) zu authentifizieren. Das Sicherheitsmodul (1) umfasst ein Sperrmodul (12) zum Aufheben der Nutzbarkeit des Applikationsmoduls (11), ein Freigabemodul (13) zum Wiederherstellen der Nutzbarkeit des Applikationsmoduls (11), und ein Steuermodul (14) zum Aktivieren des Freigabemoduls (13) abhängig von empfangenen Daten, die authentifizierbar einem bestimmten Telekommunikationsnetz (2) zuweisbar sind. Das Steuermodul (14) ist eingerichtet, das Sperrmodul (12) abhängig von der Selektion und Benutzung des Applikationsmoduls (11) zu aktivieren. Das Steuermodul (14) ist eingerichtet, das Freigabemodul (13) abhängig vom Empfang von authentifizierbaren Berechtigungsmeldungen oder Authentifizierungsdaten vom Telekommunikationsnetz (2) zu aktivieren. Durch die Freigabe oder Aufhebung der Nutzbarkeit eines Applikationsmoduls (11) abhängig von Daten, die authentifizierbar einem bestimmten Telekommunikationsnetz (2) zuweisbar sind, kann die Nutzung von netzunabhängigen Applikationen an die Nutzung eines bestimmten Telekommunikationsnetzes angebunden werden.

Term
Term ended
Projected expiry passed 23 June 2025, 1.3 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
13 claims: 3 independent, 10 dependent
- c-de-0001Security module (1) is adapted for a communication terminal (10), which security module (1) to authenticate a telecommunications network (2), and that the security module (1) comprises at least one application module usable (11), marked by a locking module (12) for canceling the usability of the application module (11), a release module (13) to restore the usability of the application module (11), and a control module (14) for activating the release module (13) depending on the received data, the authenticated a particular telecommunications network (2) can be assigned.
- c-de-0003Security module (1) according to one of claims 1 or 2, characterized in that the control module (14) is arranged to activate the enable module (13) in response to one of:received authorization message that is authenticated and the specific telecommunications network (2) assignable, and received authentication data to the specific telecommunications network (2) assignable.
- c-de-0004Security module (1) according to one of claims 1 to 3, characterized in that the lock module (12) is arranged to pick up the usability of the application module (11) by one of:Disable, Blocking, Hiding, hibernate, and uninstalling the application module (11), and that the enable module (13) is arranged, the usability of the application module ( 11) recover accordingly by one of: activating, deblocking, listing, waking and install the application module (11).
- c-de-0005Security module (1) according to one of claims 1 to 4, characterized in that it comprises at least an expiration register (15) that is associated with one or more application modules (11), and that the control module (14) is arranged to store in the expiration register (15) updated information from at least one of:number of uses of the application module (11 ), number of selections of the application module (11), number of uses functions of the application module (11), number of sessions through a logical channel of the application module (11), number of resetting cycles of the security module (1) and time.
- c-de-0006Security module (1) according to one of claims 1 to 5, characterized in that it comprises at least an authorization register (16) that is associated with one or more application module (11), and that the control module (14) is arranged to store in the privilege registers (16) information on at least one of:legitimate number uses of the application module (11 ), authorized number selections of the application module (11), authorized number uses of functions of the application module (11), entitled number sessions through a logical channel of the application module (11), authorized number reset cycles of the security module (1) and authorized period.
- c-de-0007Security module (1) according to one of claims 1 to 6, characterized in that it is designed as a device, in particular a chip card, which is removably connectable to the communication terminal (10).
- c-de-0008Security module (1) according to one of claims 1 to 7, characterized in that it is implemented as a computer program product comprising computer program code means for controlling one or more processors of the communication terminal (10).
- c-de-0009Security module (1) according to one of claims 1 to 8, characterized in that it is embodied as a subscriber identity module, and in that it is performed for a mobile, fitted for mobile networks communication terminal (10).
- c-de-0010A computer program product comprising:computer program code means for controlling one or more processors of a security module (1) for a communication terminal (10), which security module (1) is adapted to authenticate a telecommunications network (2), and that the security module (1) at least a usable application module (11 ) comprises, in such a way that the security module (1) performs a lifting of the usability of the application module (11), that the security module (1) performs a restoring the usability of the application module (11), and that the security module (1) restoring the usability of the application module (11) is activated depending on the received data, the authenticatable a particular telecommunications network (2) are assignable ,
- c-de-0011A method for controlling the usability of an application module (11), wherein the application module (11) in a security module (1) for a communication terminal (10) is arranged, and wherein the security module (1) is arranged to authenticate a telecommunications network (2), marked by Picked up the usability of the application module (11) by a locking module (12) of the security module (1), Restoring the usability of the application module (11) by a release module (13) of the security module (1), and Enabling of restoring the viability of by a control module (14) of the security module (1) depending on the received data, the authenticated a particular telecommunications network (2) can be assigned.
- c-de-0013A method according to any one of claims 11 or 12, characterized in that Restoring the utility is activated dependent on one of:received authorization message that authenticated the specific telecommunications network (2) is assignable, and received authentication data to the specific telecommunications network (2) assignable.
Independent claims11
30 paragraphs in 1 section, as filed
Technical field
p0001The present invention relates to a security module and a method for controlling the usability of an application module. The present invention particularly relates to a communication terminal suitable for a security module that is arranged to authenticate a telecommunications network, and comprises the at least one application module usable, and a method for controlling the usability of the application module.
State of the art
p0002Security modules are known in particular for mobile communication terminals, such as mobile phones, in the form of smart cards as a so-called SIM card (Subscriber Identity Module). Such security modules are also increasingly used in communication terminals for fixed networks. In addition to the subscriber identification security modules are used in particular also the authentication of the telecommunications networks. Protocols for an end-to-end network authentication by the security module are described in various standardization writings. The authentication of network access to mobile networks based on 3GPP AKA (3GPP: Third Generation Partnership Project; AKA: Authentication and Key Agreement Protocol) is for example in the technical specifications ETSI TS 133 102 V6.3.0 (2004-12); Universal Mobile Telecommunications System (UMTS); 3G Security; Security Architecture (3GPP TS 33.102 version 6.3.0 Release 6) or ETSI TS 131 102 V6.9.0 (2005-03) Universal Mobile Telecommunications System (UMTS); Characteristics of the USIM Application (3GPP TS 31.102 version 6.9.0 Release 6) defined. The authenticating access to IMS (IP Multimedia Subsystem) on 3GPP AKA is based, for example in the technical specifications ETSI TS 131 103 V6.7.0 (2005-03); Digital Cellular Telecommunications System (Phase 2+); Universal Mobile Telecommunications System (UMTS); Characteristics of the IP Multimedia Services Identity Module (ISIM) application (3GPP TS 31.103 version 6.7.0 Release 6) defined. The authentication of access to public wireless local area networks (Public Wireless Local Area Network, WLAN) based on EAP (Extensible Authentication Protocol), for example, in ETSI TS 102 310 V6.1.0 (2005-02); Smartcards; Extensible Authentication Protocol Support described in the UICC (Release 6). Other authentication mechanisms are in ETSI TS 101 181 V8.8.0 (2001-12); Digital Cellular Telecommunications System (Phase 2+); Security Mechanisms for SIM Application Toolkit; Stage 2 (3GPP TS 03:48 Version 8.8.0 Release 1999) and ETSI TS 123 048 V5.8.0 (2003-12); Digital Cellular Telecommunications System (Phase 2+); Universal Mobile Telecommunications System (UMTS); Security Mechanisms for the (U) SIM Application Toolkit; Stage 2 (3GPP TS 23 048 version 5.8.0 Release 5) for SMS (short messaging services) described. Typically, the security modules also include application modules that are particularly often without mains available. For example, a cryptographic module for decrypting encrypted data to be used without requiring access to an authenticated telecommunication network is necessary. Similarly, an application module for on-line payment are used on the Internet without requiring necessarily the mobile network or the wireless network must be used, which are operated by the issuer of the security module. The security module provides an operator of a telecommunications network, in particular a mobile network or Wi-Fi, which provides a security module with application modules for use in the telecommunication network available to a subscriber, thus no control over whether the subscriber uses network-independent application modules, without using even the telecommunications network of the operator. That is, the security module asks no connection to the use of off-grid applications to the use of the telecommunications network of the operator.
Summary of the Invention
p0003It is an object of the present invention, a suitable security module for a communication terminal and a method for controlling the usability of an application module of the security module to propose, which does not have the disadvantages of the prior art. It is a particular object of the present invention, a security module and a method for controlling the usability of an application module of the security module propose that enable at least some connection to the use of off-grid application modules to the use of a particular telecommunication network.
p0004At this point should be noted, which is meant by the term usability property of an application module to be available (for a user) to use. Similarly, an application module is repealed with usability (for the user) is not available for use because the application module for the user, for example, not visible, selectable, activated or executed.
p0005According to the present invention, the above objects are achieved in particular through the elements of the independent claims. Further advantageous embodiments follow moreover from the dependent claims and the description.
p0006The security module is provided for a communication terminal and at least one application module usable. In addition, the security module is arranged to authenticate a telecommunications network.
p0007The above mentioned objects are particularly achieved by the present invention, that the security module is provided with a locking module for canceling the usability of the application module. Moreover, the security module includes a release module for restoring (respectively producing) the usability of the application module, and a control module for activating the release module (respectively for activating recovering the utility) depending on received data that are authenticated to a particular telecommunications network assignable. The security module comprises for example a plurality of control modules, each associated with an application module. The security module is preferably implemented as a device, in particular a chip card, which is removably connectable to the communication terminal. The skilled artisan will understand that the security module is also executed in a variant as a computer program product comprising computer program code means for controlling one or more processors of the communication terminal. In one embodiment, the security module is designed as a subscriber identity module. The security module is carried out, for example, for a mobile, equipped for mobile networks communication terminal. The fact that the usability of an application module is dependent on data that are authenticated to a particular telecommunications network assignable, released or removed, the use of off-grid applications, it is possible to connect them to the use of a particular telecommunication network. For example, the usability of an application module can be linked to the condition that the user of the communication terminal logs in to the specific telecommunications network and thereby receives authentication data of this telecommunications network. The condition for the utility is preferably extended to telecommunications networks that have a roaming agreement with the particular telecommunications network, ie the usability is therefore tied to the use in telecommunication networks of the home network operator and the roaming partner of the home network operator. The explicit transmission of authenticatable authorization messages respectively authorization data the usability of an application module can be linked to certain conditions of the operator of the telecommunications network, for example, to a certain amount of services that are related by the operator of the telecommunication network by the user.
p0008In different or combined embodiments, the control module is further configured to activate the notch module, depending on the number of uses of the application module, the number of selections of the application module, the number of uses of functions of the application module, the number of created sessions via a logical channel of the application module, the number resetting cycles of the security module and / or the achievement of a period of time. By monitoring various parameters, it is possible to control dynamically and flexibly adapt to different requirements, the usability of an application module.
p0009In different or combined embodiments, the control module is further configured to activate the enable module depending on received authorization messages that are authenticated and the specific telecommunications network assignable, and / or depending on the received authentication data to the specific telecommunications network assignable. The control of the usability of an application module depending on received authentication data has the advantage that the usability can be controlled without any further changes to the network infrastructure alone in the security module.
p0010In different or combined embodiments, the blocking module is configured, the usability of the application module set aside by disabling, blocking, hiding, hibernate and / or uninstalling the application module. The release module is configured accordingly, the usability of the application module recover by activating, deblocking, listing, wakeup and / or install the application module.
p0011In one embodiment, the security module comprises at least an expiration register which is associated with one or more application modules. The control module is configured in decay registers to store current information about the number uses the application module, the number selections of the application module, the number uses of functions of the application module, the number of created sessions through a logical channel of the application module, the number reset cycles of the security module and / or the time period.
p0012In one embodiment, the security module comprises at least one authorization register that is associated with one or more application modules. The control module is configured to store in the authorization register information on the authorized number of uses of the application module, the authorized number of selections of the application module, the authorized number of uses of functions of the application module, the authorized number of sessions through a logical channel of the application module, the authorized number of resetting cycles of the security module and / or the authorized period of time.
p0013In addition to the security module for communication devices and the method for controlling the usability of an application module, the present invention relates also to a computer program product comprising computer program code means for controlling one or more processors of a security module for a communication terminal, which security module is configured to authenticate a telecommunications network, and that the security module at least includes usable application module, the computer program product comprises, in particular a computer-readable medium in which the computer program code means are stored.
Brief Description of Drawings
p0014An embodiment of the present invention by way of example will be described. The example of the embodiment is illustrated by the following attached figures:<ul><li>1 shows a block diagram illustrating schematically a communication terminal with a security module, said security module is designed as a device which is removably connected to the communication terminal.</li><li>Figure 2 shows a block diagram illustrating schematically another example of a communication terminal with a security module, said security module is designed as a computer program product comprising computer program code means for controlling one or more processors of the communication terminal.</li><li>Figure 3 shows a block grams schematically illustrates one possible embodiment of the security module, and related processes.</li><li>Figure 4 shows a block grams schematically illustrates another possible embodiment of the security module, and related processes. </li><li>5 shows a block grams, still schematically illustrates a further possible embodiment of the security module, and the relevant processes.</li><li>Figure 6 shows a block grams schematically illustrates another possible embodiment of the security module, and related processes.</li></ul>
WAYS OF CARRYING OUT OF THE INVENTION
p0015In the figures 1 to 6 corresponding components are designated with the same reference numerals.
p0016In the figures 1 to 6, the reference numeral 1, a security module, which is arranged to authenticate a telecommunications network 2nd An end-to-end authentication in the telecommunications network 2 is, for example, carried out by the security module 1 based on the above-mentioned known authentication mechanisms. The security module 1 comprises a plurality of application modules 11, 11 ', which are the user of the security module 1, or by the runtime environment (Client Execution Environment) or applications of the communication terminal 10 can be used. For application modules 11, 11 'that require user interaction, data from the user, for example via the Dateneingabelemente 101, 101' (keyboard, mouse) input to and acoustically reproduced to the user via the display 102 or. In addition to the useful application modules 11, 11 'comprises the security module 1 further function modules, in particular a locking module 12, an enabling module 13 and a control module 14, as well as an expiration register 15 and an authorization register 16. The locking module 12 is adapted to the usability of one or more application modules 11 , 11 'set aside, that is, the availability and / or authorization to use the relevant application modules 11, 11' to terminate. The release module 13 is set up, the utility of one or more application modules 11, 11 'to restore, ie the availability and / or authorization to use the relevant application modules 11, 11' (again, or possibly for the first time) to prepare and to grant. The control module 14 is set up, the enable module 13, respectively, to restore the utility, and the locking module 12, respectively canceling the utility, depending on the use of one or more application modules 11, 11 ', that is dependent on defined conditions governing the use of application modules 11, 11 'to activate. The function modules are preferably implemented as programmed software modules. The functional modules comprise computer program code for controlling one or more processors, which are located on the device on which the security module 1 is executed. Is shown schematically in Figure 1, the security module 1 is preferably embodied as a device which is removably connected to the communication terminal 10, preferably as a chip card, in particular a subscriber identification module in the form of a SIM card. Is shown schematically in Figure 2, the security module 1 is constructed in a variant as a computer program product that is directly implemented in the communication terminal 10 and controls one or more processors of the communication terminal 10th The skilled person will understand that the functional modules can also be partially or completely performed by hardware. The communication terminal 10 includes at least one communication module for data communication via telecommunication networks 2, 4. The communication terminal 10 is, for example, as a mobile phone, PDA (Personal Data Assistant), laptop or personal computer running. The telecommunication network 2 preferably includes a mobile radio network, for example a GSM network (Global System for Mobile Communication), a UMTS network (Universal Mobile Telephone System), another, eg satellite-based mobile radio system and / or a (public) Wi-Fi. The skilled person will understand that the telecommunications network 2 may also include a fixed network, such as an ISDN (Integrated Services Digital Network) or the Internet. The telecommunication network 4 corresponds technologically example the telecommunication network 2, however, has a different network identification (eg another mobile network code, MNC) and is typically operated by another operator. In the figure 1, the reference numeral 3 refers to an authentication center, which the network side, the end-to-end network authentication supported by the security module. 1 The numeral 5 refers to an authorization control module which need not be implemented in the authentication center 3, s ondern in another network unit of the telecommunication network 2 may be located, for example in an authorization control server. The authorization control module 5 is preferably implemented as a computer program product, the computer program code for controlling includes one or more processors of a network unit of the telecommunication network 2. On the function of the authorization control module 5 will be discussed later.
p0017In the following sections, the operation of the security module 1 will be explained with reference to Figures 3 to sixth In Figures 3 to 6, the reference numerals refer 7, 7 'on the application modules (Client Applications) of the communication terminal 10; numeral 8 refers to the runtime environment (Client Execution Environment) of the communication terminal 10; numeral 9 refers to an event control module (Client Event Handler) of the communication terminal 10; numeral 6 refers to a network gateway; and numeral 17 refers to the runtime environment (Execution Environment) of the security module 1. Figures 3 to 6 give a logic / functional representation again. The data flow and control flow at the application layer between an active application module 11 of the security module 1 and an associated application module 7 of the communication terminal 10 are indicated in the figures 3 to 6 by the step S7. The step S7 'is schematically indicated that events such as the selection of an application (eg, application module 11 of the security module 1), be triggered by application modules 7 of the communication terminal 10th
p0018As illustrated in Figures 3 to 6, data from the authentication center 3 or the authorization control module 5 are in the runtime environment 17 of the security module 1 in step S1 'accepted, routed, for example, in step S1 via the network gateway. 6 The data from the authentication center 3 includes authentication data, which are transmitted in the authentication of the telecommunications network 2 to the security module 1 and display an authentication of the telecommunications network. 2 The data from the authorization control module 5 comprise at least one authorization message that is transmitted from the authorization control module 5 to the security module. 1 The Berechtigungsmedlung be authenticated and may the telecommunication network 2, respectively the authorization control module 5, an associated authorization control server or a trusted service provider to be assigned. The authorization message includes, for example, authorization data with instructions for enabling or restoring the right to use one or more application modules 11, 11 '. The authorization data can also be created implicitly in the security module 1 on the basis of a received authorization message. In the runtime environment 17 of the security module 1 can be received from a trusted time server also factor authenticated timestamp via the telecommunication network 2; 4. In addition, data in the runtime environment 17 of the security module 1 in step S2 'received by the runtime environment 8 of the communication terminal 10, which are passed, for example, in step S2, the event control module 9 of the communication terminal 10th The data from the runtime environment 8 include instructions for the selection and activation of application modules 11, 11 ', for the selection and activation of functions of the application modules 11, 11', and for reset (reset) of the security module. 1
p0019As shown in Figures 3 to 5, the received data by the run-time environment 17 of the security module 1 at step S3 will be forwarded to the control module fourteenth
p0020As shown in the figure 6, the security module 1 in an embodiment a plurality of control modules 14 ', 14 "in which each one of the application modules 11, 11' are assigned. In the embodiment of Figure 6, data from the runtime environment 8, the 'relate, at step S3' the control of the application modules 11, 11 respectively on the respective associated control module 14 ', 14 "passed. In addition, in the embodiment of Figure 6, authorization messages for one or more specific application modules, in step S3 ', respectively to the respective assigned control module 14', 14 passed ".
p0021As shown in Figures 3 and 4, update the control module 14 in step S4, the authorization register 16 on the basis of the received authorization messages or authentication data indicating an authentication of the telecommunications network. 2 enabled Due to the received authorization messages or authentication data, the control module 14, the enable module 13, the usability of one, several or all application modules 11, 11 'releases respectively restores in step S6. The release respectively restore the usability of an application module 11, 11 'is achieved by the release module 13 in that the respective application module 11, 11' is activated, unblocked, awakened, installed or displayed in a list. It may also be a blocking token to be deleted, which is read by the application module 11, 11 '. The authorization register 16 includes authorization conditions for one or more specific application modules 11, 11 'or for all application modules 11, 11' of the security module 1. Eligibility conditions include, for example, one or more application modules 11, 11 ', the authorized number of uses of the application module 11, 11' that legitimate number selections of the application module 11, 11 ', the authorized number of uses of functions of the application module 11, 11', the authorized number of sessions through a logical channel of the application module 11, 11 ', the authorized number of resetting cycles of the security module 1 and / or the authorized period of use of the application module 11, 11 '. Eligibility conditions are set, for example, on the basis of the received recovery instructions or authentication data in the authorization register 16, the authorization conditions are included in the recovery instructions or hidden in the security module 1 is stored.
p0022The release or restoration of usability of an application module due to received authentication data is bound in a variant to additional conditions, prescribe, for example, a certain number of authentications of the telecommunications network 2 within a defined time period.
p0023As shown in Figures 5 and 6, the security module 1 in a variant embodiment, multiple permission registers 16, 16 ', each one of the application modules 11, 11' are assigned. In the embodiment according to Figures 5 and 6, updates the control module 14 (respectively 14 ', 14 ") in step S4', respectively the relevant authorization assigned to registers 16, 16 'on the basis of the received authorization messages or authentication data.
p0024To track changing permissions and nachzuführen, has the security module 1 via one or more expiration register 15, 15 '. Figure 3 illustrates an embodiment in which the security module 1 has an expiration Register 15th Figures 4 to 6 illustrate preferred embodiments in which the security module 1 multiple expiry register 15, 15 ', each having an application module 11, 11' are assigned. In the expiry register 15 15 'details are stored on action taken or still to be carried out activities related to one or more application modules 11, 11'. If the expiration register is 15, 15 set up 'as incrementing register values or number activities (uses) from zero are counted. If the expiration register is 15, 15 set up 'as decrementing register values or number activities (uses), starting from an initial threshold (permission condition) are counted down. The expiry registers 15, 15 'comprises, in particular information on the number uses the application module 11, 11', the number selections of the application module 11, 11 ', the number uses of functions of the application module 11, 11', the number of created sessions through a logical channel the application module 11, 11 ', the number reset cycles of the security module 1 and / or a period of time, for example, the length of time since the granting of the authorization. The skilled person will understand that may correspond to the expiry register 15 15 'the permissions tab 16, 16', wherein the setting of permission register 16 setting an initialization value of the expiry register 15 equals, which is decremented over time or depending on the use.
p0025If the received data is a request concerning one of the application modules 11, 11 'include or a provision requirement of the security module 1, update the control module 14, 14' in step S5, S5 'expiration register in question 15, 15' and checks the authorization for the selection or activation of the respective application module 11, 11 'respectively a function of the respective application module 11, 11'. The review of the authorization is based on the relevant authorization register 16, 16 'and / or the expiry register concerned 15, 15'. When incrementing expiry register 15 15 'is no longer justified if the incremented value (the number uses z. B.) in the authorization register 16, 16 the corresponding maximum permissible value' exceeds or reaches. When decrementing expiry register 15 15 'is no longer justified when the decremented value starting from the original maximum allowable value (z. B. the number selections) from the permissions tab 16, 16' reaches zero. If no authorization exists, an error feedback is generated to the requesting unit, for example. If the authorization expires due to the present request, activates the control module 14, the locking module 12, which 'cancels the usability of one, several or all application modules 11, 11th The lifting of the usability of an application module 11, 11 'is achieved by the locking module 12 in that the respective application module 11, 11' are deactivated, blocked hiberniert, uninstalled or is hidden by removal from a list. It can also be a lock token to be set, will be read by you, and then the application module 11, 11 'which when activated by the application module 11, 11 terminated its activity. Otherwise, if an authorization is present, the respective application module 11, 11 'respectively that function is selected and activated. In an alternative embodiment, the expiry register 15 as indicated in Figure 3, updated by the respective application module 11 in step S8. In the embodiments with multiple expiry registers 15, 15 ', as indicated in Figures 4 to 6, in step S8' expiry register 15 updates that is associated with the respective application module 11, 11 '.
p0026In the security module 1 can set expiration register 15, 15 'and permission registers 16, 16' for application modules 11, 11 'of different telecommunications networks 2 respectively operators are provided.
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both waysCites: the store holds 7 of 8
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| EP2308014A4 | Cited by | European Patent Office (EPO) | – | Search report | – |
| US9852418B2 | Cited by | United States of America | – | Applicant | – |
| US12022290B2 | Cited by | United States of America | – | Applicant | – |
| CN102572408A | Cited by | China | – | Search report | – |
| US11595820B2 | Cited by | United States of America | – | Applicant | – |
| US11521194B2 | Cited by | United States of America | – | Applicant | – |
| EP1271881A1 | Cites | European Patent Office (EPO) | A | Search report | 1-13 |
| EP1271881A1 | Cites | European Patent Office (EPO) | A | Search report | 1-13 |
| US2004123152A1 | Cites | United States of America | X | Search report | 1-13 |
| US6226749B1 | Cites | United States of America | A | Search report | 1-13 |
| US6226749B1 | Cites | United States of America | A | Search report | 1-13 |
| US6550010B1 | Cites | United States of America | A | Search report | 1-13 |
| US6550010B1 | Cites | United States of America | A | Search report | 1-13 |
| WAP FORUM: "WAP-182-ProvArch-20010314-a", WAP STANDARD SPECIFICATION, 14 March 2001 (2001-03-14), pages 1 - 22, XP002253357 | Non-patent | – | – | Search report | – |
| "Wireless Application Protocol, WAP-182-ProvArch-20010314-a, Provisioning Architecture Overview", WIRELESS APPLICATION PROTOCOL (WAP) FORUM, 14 March 2001 (2001-03-14) | Non-patent | – | – | Applicant | – |
5 members in 3 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 05405398 | European Patent Office (EPO) | A | |
| EP20050405398 | – | – | – |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| EP1737181A1This record | European Patent Office (EPO) | A1 | |
| US2006293030A1 | United States of America | A1 | |
| EP1737181B1 | European Patent Office (EPO) | B1 | |
| ES2393568T3 | Spain | T3 | |
| US8509737B2 | United States of America | B2 |
73 legal events, as 10 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Patent ceasedCeasedPL | PL | CH | |
| Expiry of rightR071 | R071 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Transfer of patentPC2A | PC2A | ES | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of representativeR082 | R082 | DE | |
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)REGISTERED BETWEEN 20220526 AND 20220601732E | 732E | GB | |
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04L0029060000R079 | R079 | DE | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapse because of not paying annual feesLapsedMM01 | MM01 | AT | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent lapsedLapsedMM4A | MM4A | IE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Be: lapsedLapsedBERE | BERE | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Invalidated european patentMG4D | MG4D | LT | |
| Discontinued in the netherlands as no translation has been filedVDEP | VDEP | NL | |
| Definitive protectionFG2A | FG2A | ES | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| New agentNV | NV | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Designation fees paidAKX | AKX | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1737181
- Publication, DOCDB
- 1737181
- Publication, EPODOC
- EP1737181
- Application
- 5405398
- Application, DOCDB
- 05405398
- Application, EPODOC
- EP20050405398
Titles3
- German
- Vorrichtung, Verfahren und Computerprogrammprodukt zum Steuern der Nutzbarkeit eines Applikationsmoduls mittels Sicherheitsmodul
- English
- Apparatus, method and computer program product for controlling the usability of an application module by means of security module
- French
- Appareil, méthode et produit logiciel pour contrôler l'utilité d'un module d'application par un module de sécurité
Classification
- CPC, 10
- G07F7/1008
- G06Q20/341
- G06Q20/3576
- H04L63/0853
- H04L63/10
- H04L63/126
- H04M2250/14
- H04W88/02
- H04M1/0254
- H04M1/72409
- IPC, 3
- H04L29 06
- H04M1 725
- H04M1 72409
Designated states2
- Contracting states, 1
- Türkiye
- Extension states, 1
- Yugoslavia, later Serbia and Montenegro (until 2006)