Method and device for changing an EUICC terminal
By implementing the server-side profile management method in the mobile communication system, the problem of downloading and installing profiles between terminals is solved, and the security management of profiles and efficient service provision are realized.
Patent Information
- Application Number
- CN202080020825.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-04-19
- Filing Date
- 2020-03-12
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2040-03-12
AI Technical Summary
In mobile communication systems, prior art is difficult to provide services effectively, especially in the development of online download, installation and management of profiles between terminals.
By implementing a method in a wireless communication system, the server receives a request for delivery of a profile from the first terminal, recognizes the possibility of delivery of a profile, and sends an activation code of the second profile to the first terminal. The method further includes receiving relevant policy messages from the service provider, sending request information to the service provider, and receiving and processing a profile download request.
It realizes that the terminal can effectively download and install profiles in the communication system, ensures the security management of the profile and prevents copying, and improves the reliability and efficiency of the service.
Smart Images

Figure CN113557754B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a method and an apparatus for installing and managing eUICC profiles. Background Art
[0002] In order to meet the increasing demand for wireless data traffic since the deployment of 4G communication systems, efforts have been made to develop improved 5G or pre-5G communication systems. Therefore, 5G or pre-5G communication systems are also referred to as "Beyond 4G Networks" or "Post-LTE Systems". The 5G communication system is considered to be implemented in a higher frequency (mmWave) band (e.g., 60 GHz band) in order to achieve higher data rates. In order to reduce the propagation loss of radio waves and increase the transmission distance, beamforming, massive multiple-input multiple-output (MIMO), full-dimensional MIMO (FD-MIMO), array antennas, analog beamforming, and massive antenna technologies are discussed in 5G communication systems. In addition, in 5G communication systems, system network improvement is being developed based on advanced small cells, cloud radio access network (RAN), ultra-dense network, device-to-device (D2D) communication, wireless backhaul, mobile network, cooperative communication, coordinated multi-point (CoMP), receiver-side interference cancellation, etc. In 5G systems, hybrid FSK and QAM modulation (FQAM) as advanced coding modulation (ACM) and sliding window superimposed coding (SWSC) have been developed, as well as filter bank multi-carrier (FBMC), non-orthogonal multiple access (NOMA), and sparse code multiple access (SCMA) as advanced access technologies.
[0003] The Internet, as a human-centered connection network for generating and consuming information, is now evolving into the Internet of Things (IoT), in which distributed entities such as things exchange and process information without human intervention. The Internet of Everything (IoE) has emerged as a combination of IoT technology and big data processing technology connected to a cloud server. Since technical elements such as "sensing technology", "wired / wireless communication and network infrastructure", "service interface technology", and "security technology" are necessary for IoT implementation, sensor networks, machine-to-machine (M2M) communication, machine type communication (MTC), etc. have been recently studied. Such an IoT environment can provide intelligent Internet technology services, which create new value for human life by collecting and analyzing data generated between connected things. Through the convergence and combination of existing information technology (IT) and various industrial applications, IoT can be applied to various fields, including smart home, smart building, smart city, smart car or connected car, smart grid, healthcare, smart home appliances, and advanced medical services.
[0004] In accordance with this, various attempts have been made to apply the 5G communication system to the IoT network. For example, technologies such as sensor networks, machine type communication (MTC), and machine-to-machine (M2M) communication can be implemented through beamforming, MIMO, and array antennas. The application of cloud radio access network (RAN) as the above-mentioned big data processing technology can also be considered an example of the convergence between 5G technology and IoT technology.
[0005] As described above, since various services can be provided with the development of the mobile communication system, it is necessary to have a scheme that can effectively provide such services.
[0006] A "Universal Integrated Circuit Card (UICC)" is a smart card that is used by being inserted into a mobile communication terminal or the like, and is also referred to as a UICC card. The UICC may include an access control module for enabling the terminal to access the network of a mobile operator. Examples of such an access control module include a Universal Subscriber Identity Module (USIM), a Subscriber Identity Module (SIM), an IP Multimedia Service Identity Module (ISIM), etc. A UICC including a USIM is generally referred to as a USIM card. Similarly, a UICC including a SIM is generally referred to as a SIM card.
[0007] A UICC card that is fixed to and used in a terminal is called an embedded UICC (eUICC). Generally, an eUICC refers to a UICC card that is fixed to and used in a terminal, and can remotely download and select a SIM module. In addition, the downloaded SIM module information is generally referred to as an eUICC profile or more simply as a profile. Summary of the Invention
[0008]
Technical Problem
[0009] The present disclosure is for effectively providing services in a mobile communication system.
[0010] According to an embodiment disclosed in the present disclosure, a method and an apparatus for a terminal to select a communication service in a communication system and connect to a network can be provided.
[0011] According to an embodiment disclosed in the present disclosure, a method and an apparatus for a terminal to online download, install, and manage a profile for connecting to a network in a communication system can be provided.
[0012] According to an embodiment disclosed in the present disclosure, a method and an apparatus for a terminal to effectively download a profile installed in another terminal for reconnecting to a network in a communication system can be provided.
[0013]
Problem Solution
[0014] The technical objectives to be achieved in the embodiments of the present disclosure are not limited to the above technical objectives, and those with ordinary knowledge in the field to which the present disclosure pertains can clearly understand other technical objectives not described above from the following description.
[0015] In the present disclosure, a method performed by a server in a wireless communication system includes: receiving a request for delivering a first profile from a first terminal; identifying the possibility of delivering the first profile based on the received request for delivering the first profile; and sending an activation code for a second profile to the first terminal.
[0016] In some examples, the method further includes receiving a message from a service provider for setting a policy related to the request for delivering the first profile from the first terminal.
[0017] In some examples, the method further includes: sending information indicating that a request for delivering the first profile has been received from the first terminal to the service provider; receiving a first message from the service provider, the first message including information to be noted by the user determined based on the delivery policy for the first profile; and sending the first message to the first terminal.
[0018] In some examples, the method further includes: receiving a second message from the user, the second message including information on whether to permit delivering the first profile determined based on the first message; sending a third message to the service provider, the third message including information on whether to permit delivering the first profile based on the second message; and receiving a fourth message related to the second profile.
[0019] In some examples, the method further includes: receiving a request for downloading the second profile from a second terminal; sending a fifth message to the second terminal, the fifth message including information about the second profile and information to be noted by the user; receiving a request from the second terminal for information on whether to permit downloading the second profile and the profile package based on the fifth message; and sending the profile package to the second terminal.
[0020] In another example of the present disclosure, a method of a first terminal in a wireless communication system includes: receiving a request for delivering a first profile from a user; sending a message requesting an activation code to a server based on the request for delivering the first profile; and receiving an activation code for a second profile from the server, where the activation code for the second profile is determined based on the server and the service provider.
[0021] In some examples, the method further includes sending the activation code for the second profile to a second terminal. The activation code is marked as a QR code.
[0022] In some examples, the method further includes disabling the first profile and sending the disabling result to the server.
[0023] In another example of the present disclosure, a server includes: a transceiver capable of sending and receiving at least one signal; and a controller coupled to the transceiver. The controller is configured to: receive a request for delivering a first profile from a first terminal; identify the possibility of delivering the first profile based on the received request for delivering the first profile; and send an activation code of a second profile to the first terminal.
[0024] In another example of the present disclosure, a first terminal includes: a transceiver capable of sending and receiving at least one signal; and a controller coupled to the transceiver. The controller is configured to: receive a request for delivering a first profile from a user; send a message for requesting an activation code to a server based on the request for delivering the first profile; and receive an activation code of a second profile from the server. The activation code of the second profile is determined based on the server and the service provider.
[0025] Furthermore, a terminal for managing a profile for connecting to a network by using an embedded universal integrated circuit card (eUICC) in a wireless communication system according to an embodiment of the present disclosure may include: a transceiver; and at least one processor controlling the terminal to receive a request for delivering a profile from a user, confirm profile delivery information, send a message for requesting an activation code to a profile server, receive an activation code and whether it is necessary to delete the profile from the profile server, delete the profile, send a result of deleting the profile to the profile server, deliver the activation code to another terminal, receive an activation code from the other terminal, send a message for requesting the profile to the profile server by using the activation code, receive a profile package from the profile server, and install the profile package.
[0026] In a wireless communication system according to an embodiment, a profile server for providing a profile for network connection to a terminal may include: a transceiver; and at least one processor controlling the profile server to receive a request message for delivering a profile from a terminal, identify whether the profile is deliverable, generate an activation code based on which the profile or a new profile can be downloaded, set the status of the profile to a non-downloadable state when the delivery of the profile is possible, set the status of the new profile to a downloadable state when the delivery of the profile is impossible, send a message including the activation code and whether it is necessary to delete the profile to the terminal, receive a result of deleting the profile from the terminal, change the status of the profile to a downloadable state, receive a profile download request message from the terminal, identify whether the status of the profile is a downloadable state, send a profile package to the terminal when the status of the profile is a downloadable state, and send an error code when the status of the profile is a non-downloadable state.
[0027]
Advantageous Effects of the Present Invention
[0028] According to an embodiment of the present disclosure, services can be effectively provided in a mobile communication system.
[0029] According to an embodiment of the present disclosure, in a communication system, when a terminal attempts to reinstall a profile installed in the terminal in another terminal, the terminal may have an activation code necessary for the reinstalled profile to be republished by the profile server, or extract the activation code necessary for reinstalling the profile from information stored in the terminal or the profile. If necessary, the profile to be delivered may be deleted first, and the activation code may be passed to another terminal. The other terminal can effectively download and install the profile from the profile server.
[0030] According to an embodiment of the present disclosure, in a communication system, when the profile server receives a request to reinstall a profile installed in a terminal in another terminal, the profile server can prevent the duplication of the profile and securely process the profile download in the following manner: when the profile can be reused, request the terminal to delete the profile by setting the status of the profile to a non-downloadable state; when the profile cannot be reused, prepare another profile by setting the status of another profile to a downloadable state, generate an activation code based on which the prepared profile can be downloaded, and change the status of the profile to a downloadable state if the terminal has deleted the profile. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 is a diagram showing a method by which a terminal according to an embodiment of the present disclosure connects to a mobile communication network by using a universal integrated circuit card (UICC) on which a fixed profile has been installed.
[0032] Figure 2 is a diagram showing the configuration of a system in which a terminal according to an embodiment of the present disclosure manages a profile installed in a first terminal in response to a user input and installs the profile in a second terminal.
[0033] Figure 3A is a diagram showing a process by which a first terminal according to an embodiment of the present disclosure receives an activation code through a profile server and downloads a new profile by passing the activation code to a second terminal.
[0034] Figure 3B is a diagram showing another process by which a first terminal according to an embodiment of the present disclosure receives an activation code through a profile server and downloads a new profile by passing the activation code to a second terminal.
[0035] Figure 4A is a diagram showing a process by which a first terminal according to an embodiment of the present disclosure receives an activation code through a profile server and redownloads the same profile by passing the activation code to a second terminal.
[0036] Figure 4BIt is a diagram showing another process in which a first terminal according to an embodiment of the present disclosure receives an activation code through a profile server and redownloads the same profile by passing the activation code to a second terminal.
[0037] Figure 4C It is a diagram showing yet another process in which a first terminal according to an embodiment of the present disclosure receives an activation code through a profile server and redownloads the same profile by passing the activation code to a second terminal.
[0038] Figure 4D It is a diagram showing yet another process in which a first terminal according to an embodiment of the present disclosure receives an activation code through a profile server and redownloads the same profile by passing the activation code to a second terminal.
[0039] Figure 5 It is a diagram showing a process in which a first terminal according to an embodiment of the present disclosure downloads a new profile by sending an activation code stored in the first terminal to a second terminal.
[0040] Figure 6 It is a diagram showing a process in which a first terminal according to an embodiment of the present disclosure redownloads the same profile by sending an activation code stored in the first terminal to a second terminal.
[0041] Figure 7A It is a flowchart showing an operation process of a first terminal according to an embodiment of the present disclosure.
[0042] Figure 7B It is a flowchart showing an operation process of a second terminal according to an embodiment of the present disclosure.
[0043] Figure 8 It is a flowchart showing an operation process of a profile server according to an embodiment of the present disclosure.
[0044] Figure 9 It is a block diagram showing components of a terminal according to an embodiment of the present disclosure.
[0045] Figure 10 It is a block diagram showing components of a profile server according to an embodiment of the present disclosure. Detailed Description of the Embodiments
[0046] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the accompanying drawings.
[0047] When describing the embodiments, descriptions of technical content that is well known in the art to which the present disclosure pertains and is not directly related to the present disclosure are omitted so as to clearly convey the gist of the present disclosure without obscuring the gist of the present disclosure by omitting unnecessary descriptions.
[0048] For the same reason, in the drawings, some elements are enlarged, omitted or schematically depicted. In addition, the size of each element does not accurately reflect its true size. In the drawings, the same or similar elements are assigned the same reference numerals.
[0049] Advantages and features of the present disclosure, as well as methods for achieving these advantages and features, will become apparent from the embodiments described in detail in conjunction with the drawings. However, the present disclosure is not limited to the disclosed embodiments, but may be implemented in various different forms. The embodiments are provided only to complete the present disclosure and fully notify those with ordinary knowledge in the field to which the present disclosure pertains of the category of the present disclosure. The present disclosure is defined by the category of the claims. Throughout the specification, the same reference numerals denote the same elements.
[0050] In the present disclosure, it will be understood that each block of the flowchart illustration and combinations of blocks in the flowchart illustration can be executed by computer program instructions. These computer program instructions can be installed on a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that the instructions executed by the processor of the computer or other programmable data processing device create a means for performing the functions specified in the flowchart block. These computer program instructions can also be stored in a computer-usable or computer-readable storage medium, which can direct a computer or other programmable data processing device to implement functions in a specific manner, such that the instructions stored in the computer-usable or computer-readable storage medium produce an article of manufacture including an instruction means for implementing the functions specified in the flowchart block. The computer program instructions can also be loaded onto a computer or other programmable data processing device to cause a series of operational steps to be performed on the computer or other programmable data processing device to produce a computer-executed process, such that the instructions executed on the computer or programmable data processing device provide steps for performing the functions described in the flowchart block.
[0051] In addition, each block of the flowchart illustration can represent a module, segment, or portion of code that includes one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative embodiments, the functions recited in the blocks may occur out of order. For example, two blocks shown in succession may in fact be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved.
[0052] As used in this embodiment, the term "unit" refers to a software or hardware component, such as an FPGA or ASIC, and the "unit" performs a specific task. However, the term "~ unit" does not mean that it is limited to software or hardware. The "unit" can be advantageously configured to reside on an addressable storage medium and be configured to operate on one or more processors. Thus, a "unit" can include, for example, components (such as software components, object-oriented software components, class components, and task components), processes, functions, attributes, procedures, subroutines, program code segments, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided in components and "units" can be combined into fewer components and "units", or can be further divided into additional components and "units". In addition, components and "units" can be implemented to operate on one or more CPUs within a device or a secure multimedia card.
[0053] Specific terms used in the embodiments of the present disclosure are provided to assist in understanding the present disclosure. Without departing from the technical spirit of the present disclosure, the use of such specific terms can be changed to another form.
[0054] In the present disclosure, a "Universal Integrated Circuit Card (UICC)" is a smart card used by being inserted into a mobile communication terminal or the like, and is also referred to as a UICC card.
[0055] The UICC refers to a chip in which personal information of a mobile communication subscriber (such as network access authentication information, phone number book, or SMS) is stored, and it enables secure use of mobile communication by generating subscriber authentication and traffic security keys when accessing a mobile communication network (such as GSM, WCDMA, LTE, etc.).
[0056] The UICC can include a communication application or an access control module for enabling a terminal to access a mobile operator's network. Examples of such a communication application or access control module include a Universal Subscriber Identity Module (USIM), a Subscriber Identity Module (SIM), an IP Multimedia Service Identity Module (ISIM), etc. In addition, the UICC can provide more advanced security functions for installing various applications such as an electronic wallet, tickets, or an electronic password.
[0057] A UICC including a USIM is generally referred to as a USIM card. Similarly, a UICC including a SIM module is generally referred to as a SIM card.
[0058] In the present disclosure, "SIM card", "UICC card", "USIM card", and "UICC including ISIM" can be used with the same meaning. That is, the content of the present disclosure can be equally applied to SIM cards, USIM cards, ISIM cards, or common UICC cards.
[0059] The SIM card stores personal information of a mobile communication subscriber and enables secure use of mobile communication by generating user authentication and traffic security keys when accessing a mobile communication network.
[0060] Generally, in response to a request from a specific mobile operator, the SIM card is manufactured as a dedicated card for the corresponding operator and is issued with authentication information (e.g., a Universal Subscriber Identity Module (USIM) application pre-installed on the card, an International Mobile Subscriber Identity (IMSI), a K value, an OPc value, etc.) for the corresponding operator to connect to the network. Thus, the SIM card is provided to the mobile operator and to the subscriber. Thereafter, if necessary, the mobile service provider can perform management of applications within the UICC, such as installation, modification, deletion, etc., by using a technology such as Over-the-Air (OTA). The subscriber can use the application services and the network of the mobile operator by inserting the UICC card into the owned mobile communication terminal, and can use the authentication information, mobile communication phone number, personal phone book, etc. stored in the UICC card in the new terminal without any change by delivering and inserting the UICC card from the existing terminal to the new terminal when changing the terminal.
[0061] However, the SIM card causes inconvenience to mobile communication terminal users when receiving services from another mobile operator. The mobile communication terminal user feels inconvenient because he or she has to physically obtain the SIM card in order to receive services from the mobile service provider. For example, when traveling to another country, the user feels inconvenient because he or she has to obtain a local SIM card in order to receive local mobile communication services. Roaming services solve this inconvenience to some extent, but the problems are that it is relatively expensive and roaming services cannot be provided if there is no contract between communication companies.
[0062] If the SIM module is remotely downloaded and installed in the UICC card, this inconvenience can be greatly solved. That is, the user can download the SIM module to be used at the desired timing to the UICC card. In such a UICC card, a method of downloading and installing multiple SIM modules and only selecting one of the SIM modules can be used. Such a UICC card can be fixed to the terminal or not fixed to the terminal. Specifically, the UICC used by being fixed to the terminal is called an embedded UICC (eUICC). Generally, an eUICC refers to a UICC card that can be used by being fixed to the terminal, can remotely download a SIM module to the UICC card, and can select the downloaded SIM module therein. In the present disclosure, a UICC card that can remotely download a SIM module to it and can select the downloaded SIM module therein is called an eUICC. That is, the UICC card, whether fixed or not fixed to the terminal, in which a SIM module can be remotely downloaded to it and the downloaded SIM module can be selected therein, is generally used as an eUICC. In addition, the downloaded SIM module information is generally used as a term called an eUICC profile or more simply called a profile.
[0063] In the present disclosure, the "embedded UICC (eUICC)" is a security module in the form of a chip inserted into the terminal, rather than a detachable type where the eUICC can be inserted into and removed from the terminal. The profile can be downloaded and installed in the eUICC by using over-the-air (OTA) technology. The eUICC can be named as a UICC in which the profile can be downloaded and installed.
[0064] In the present disclosure, the method of downloading and installing the profile in the eUICC by using OTA technology can also be applied to a detachable type UICC that can be inserted into and removed from the terminal. That is, the embodiments of the present disclosure can be applied to a UICC in which the profile can be downloaded and installed by using OTA technology.
[0065] In the present disclosure, "UICC" can be used interchangeably with "SIM", and "eUICC" can be used interchangeably with "eSIM".
[0066] In the present disclosure, the "profile" can mean applications, file systems, authentication key values, etc. stored in the UICC and encapsulated in software form.
[0067] In the present disclosure, the "USIM profile" can have the same meaning as the "profile", or can mean the information included in the USIM application within the profile encapsulated in software form.
[0068] In the present disclosure, the operation of enabling a profile by a terminal may mean an operation by the terminal to set the status of a profile by changing the status of the profile to an enabled state such that the terminal can receive communication services through a mobile operator providing the corresponding profile. A profile in an enabled state may be denoted as an "enabled profile".
[0069] In the present disclosure, the operation of disabling a profile by a terminal may mean an operation by the terminal to set the status of a profile by changing the status of the profile to a disabled state such that the terminal cannot receive communication services through a mobile operator providing the corresponding profile. A profile in a disabled state may be denoted as a "disabled profile".
[0070] In the present disclosure, the operation of deleting a profile by a terminal may mean an operation by the terminal to set the status of a profile by changing the status of the profile to a deleted state such that the terminal can no longer enable or disable the corresponding profile. A profile in a deleted state may be denoted as a "deleted profile".
[0071] In the present disclosure, the operation of enabling, disabling, or deleting a profile by a terminal may mean the following operation: First, mark the status of each profile as a to-be-enabled state, a to-be-disabled state, or a to-be-deleted state without immediately changing the status of each profile to an enabled state, a disabled state, or a deleted state. Then, perform a specific operation (e.g., execute a refresh or reset command) by the terminal or the UICC of the terminal, and then change the status of each profile to an enabled state, a disabled state, or a deleted state. The operation of marking the status of a specific profile as a pending state (i.e., a to-be-enabled state, a to-be-disabled state, or a to-be-deleted state) is not essentially limited to marking one pending state for one profile. The status of one or more profiles may be marked as the same or different pending states, the status of one profile may be marked as one or more pending states, or the status of one or more profiles may be marked as the same or different one or more pending states.
[0072] In addition, if a terminal marks one or more to-be states for a given profile, the two marked to-be states may be merged into one state. For example, if the status of a given profile is marked as a to-be-disabled state and a to-be-deleted state, the to-be-disabled state and the to-be-deleted state of the corresponding profile may be integrated and marked as a to-be-disabled or to-be-deleted state.
[0073] Furthermore, the operation of marking the status of one or more profiles as pending states by the terminal may be performed sequentially or simultaneously. Furthermore, the operation of marking the status of one or more profiles as pending states by the terminal and then changing the actual status of the profiles may be performed sequentially or simultaneously.
[0074] In the present disclosure, a "profile provisioning server" may include functions for generating a profile, encrypting the generated profile, generating a profile remote management command, or encrypting the generated profile remote management command. The profile provisioning server may be represented as a Subscription Manager Data Preparation (SM-DP), Subscription Manager Data Preparation Plus (SM-DP+), out-of-card entity of a profile domain, profile encryption server, profile generation server, Profile Provisioner (PP), profile provider, or Profile Provisioning Credential (PPC) holder.
[0075] In the present disclosure, a "profile management server" may include functions for managing a profile. The profile management server may be represented as a Subscription Manager Secure Routing (SM-SR), Subscription Manager Secure Routing Plus (SM-SR+), out-of-card entity of an eUICC profile manager, Profile Management Credential (PMC) holder, eUICC Manager (EM), Profile Manager (PP), etc.
[0076] In the present disclosure, the profile provisioning server may represent a combination of the functions of the profile management server. Thus, in various embodiments of the present disclosure, the operations of the profile provisioning server may be performed in the profile management server. Similarly, the operations of the profile management server or SM-SR may be performed in the profile provisioning server.
[0077] In the present disclosure, a "discovery relay server" may be represented as a Subscription Manager Discovery Service (SM-DS), Discovery Service (DS), root discovery relay server (root SM-DS), alternative discovery relay server (alternative SM-DS). The discovery relay server may receive an event registration request (or registration event request) from one or more profile provisioning servers or discovery relay servers. In addition, one or more discovery relay servers may be used in a complex manner. In this case, in addition to the profile provisioning server, the first discovery relay server may also receive an event registration request from the second discovery relay server.
[0078] In the present disclosure, the profile provisioning server and the discovery relay server may be used under the name of a "Remote SIM Provisioning (RSP) server". The RSP server may be represented as Subscription Manager XX (SM-XX).
[0079] In the present disclosure, a "terminal" may be represented as a mobile station (MS), user equipment (UE), user terminal (UT), radio terminal, access terminal (AT), terminal, subscriber unit, subscriber station (SS), wireless device, wireless communication device, wireless transmit / receive unit (WTRU), mobile node, mobile device, or other terms. In an embodiment, the terminal may include a cellular phone, a smart phone having a wireless communication function, a portable digital assistant (PDA) having a wireless communication function, a wireless modem, a portable computer having a wireless communication function, a photographing device such as a digital camera having a wireless communication function, a game device having a wireless communication function, a music storage and playback household appliance having a wireless communication function, an Internet household appliance capable of wireless Internet access and browsing, and may also include a portable unit or terminal integrating a combination of these functions. In addition, the terminal may include a machine-to-machine (M2M) terminal, a machine type communication (MTC) terminal / device, but the present disclosure is not limited thereto. In the present disclosure, the terminal may also be represented as an electronic device.
[0080] In the present disclosure, a UICC in which a profile can be downloaded and installed may be embedded in an "electronic device". If the UICC is not embedded in the electronic device, a UICC physically separated from the electronic device may be inserted into the electronic device and coupled to the electronic device. For example, the UICC may be inserted into the electronic device in the form of a card. The electronic device may include a terminal. In this case, the terminal may be a terminal including a UICC in which a profile can be downloaded and installed. If the UICC can be embedded in the terminal and the terminal and the UICC are separated, the UICC may be inserted into the terminal and may be inserted into the terminal and coupled to the terminal. For example, a UICC in which a profile can be downloaded and installed may be represented as an eUICC.
[0081] In the present disclosure, the terminal or the electronic device may include software or an application installed in the terminal or the electronic device to control the UICC or the eUICC. For example, software or an application installed in the terminal or the electronic device to control the UICC or the eUICC may be represented as a local profile assistant (LPA).
[0082] In the present disclosure, a "profile separator" may be represented as a factor matching a profile ID, an integrated circuit card ID (ICCID), a matching ID, an event ID, an activation code, an activation code token, a command code, a command code token, a signed command code, an unsigned command code, an ISD-P, or a profile domain (PD). The profile ID may indicate a unique ID of each profile. The profile separator may further include an address of a profile provisioning server (SM-DP+) capable of indexing the profile. In addition, the profile separator may further include a signature of the profile provisioning server (SM-DP+).
[0083] In the present disclosure, the "eUICC ID" may be the unique ID of the eUICC embedded in the terminal and may be represented as the EID. Additionally, if a provisioning profile was previously installed on the eUICC, the eUICC ID may be the ID of the corresponding provisioning profile. Further, in an embodiment of the present disclosure, if the terminal and the eUICC chip are not separated, the eUICC ID may be the terminal ID. Additionally, the eUICC ID may represent a specific security domain of the eUICC chip.
[0084] In the present disclosure, the "profile container" may be named the profile domain. The profile container may be a security domain.
[0085] In the present disclosure, the "Application Protocol Data Unit (APDU)" may be a message for enabling the terminal to operate in conjunction with the eUICC. Additionally, the APDU may be a message for enabling the Profile Provider (PP) or the Profile Manager (PM) to operate in conjunction with the eUICC.
[0086] In the present disclosure, the "Profile Provisioning Credential (PPC)" may be a means for mutual authentication, profile encryption, and signature between the profile provisioning server and the eUICC. The PPC may include one or more of a symmetric key, a Rivest Shamir Adleman (RSA) certificate and private key, an Elliptic Curve Cryptography (ECC) certificate and private key, a Root Certification Authority (CA), and a certificate chain. Additionally, if there are multiple profile provisioning servers, different PPCs may be stored or used by the multiple profile provisioning servers in the eUICC.
[0087] In the present disclosure, the "Profile Management Credential (PMC)" may be a means for mutual authentication, transmission data encryption, and signature between the profile management server and the eUICC. The PMC may include one or more of a symmetric key, an RSA certificate and private key, an ECC certificate and private key, a Root CA, and a certificate chain. Additionally, if there are multiple profile management servers, different PMCs may be stored or used by the multiple profile management servers in the eUICC.
[0088] In the present disclosure, the "AID" may be an application identifier. The value may be a separator for distinguishing different applications within the eUICC.
[0089] In the present disclosure, an "event" may be a term that generally represents a profile download, remote profile management, or other management / processing commands for a profile or eUICC. The event may be named a remote SIM provisioning operation, RSP operation, RSP operation, or event record. Each event may be represented as data including at least one of the following items: a corresponding event identifier (Event ID, EventID) or matching identifier (Matching ID, MatchingID), the address (FQDN, IP address, or URL) of the profile provisioning server (SM-DP+) or discovery relay server (SM-DS) storing the corresponding event, the signature of the profile provisioning server (SM-DP+) or discovery relay server (SM-DS), or the digital certificate of the profile provisioning server (SM-DP+) or discovery relay server (SM-DS).
[0090] The data corresponding to the event may be represented as a "command code". Some or the entire process of using the command code may be represented as a "command code processing process" or "command code process" or "local profile assistant application programming interface (LPAAPI)". Profile download may be used interchangeably with profile installation.
[0091] In addition, an "event type" may be used as a term indicating that a specific event is a profile download or remote profile management (e.g., delete, enable, disable, replace, update, etc.) or a profile or eUICC management / processing command, and may be named an operation type (or OperationType), operation class (or OperationClass), event request type, event class, event request class. The path for the terminal to obtain a given event identifier (EventID or MatchingID) or the purpose of use of the corresponding event identifier (EventID source or MatchingID source) may be specified in the corresponding event identifier (EventID or MatchingID).
[0092] In the present disclosure, a "profile package" may be used interchangeably with a profile, or may be used as a term indicating a data object for a specific profile, and may be named a profile TLV or profile package TLV. If the profile package has been encrypted using encryption parameters, the profile package may be named a protected profile package (PPP) or protected profile package TLV (PPP TLV). If the profile package has been encrypted using encryption parameters that can only be decoded by a specific eUICC, the profile package may be named a bound profile package (BPP) or bound profile package TLV (BPP TLV). The profile package TLV may be a data set representing the information constituting the profile in a tag, length, value (TLV) format.
[0093] In the present disclosure, "Local Profile Management (LPM)" may be named as Profile Local Management, Local Management, Local Management Command, Local Command, Local Profile Management Package (LPM Package), Profile Local Management Package, Local Management Package, Local Management Command Package, or Local Command Package. LPM can be used to change the status (enable, disable, delete) of a specific profile and update the content of a specific profile (e.g., the nickname of the profile (profile nickname) or the profile summary information (profile metadata), etc.) through software installed in the terminal, etc. LPM may include one or more local management commands. In this case, for each local management command, the profile (i.e., the subject of each local management command) may be the same or different.
[0094] In the present disclosure, "Remote Profile Management (RPM)" may be named as Profile Remote Management, Remote Management, Remote Management Command, Remote Command, Remote Profile Management Package (RPM Package), Profile Remote Management Package, Remote Management Package, Remote Management Command Package, or Remote Command Package. RPM can be used to change the status (enable, disable, delete) of a specific profile or update the content of a specific profile (e.g., the nickname of the profile (profile nickname) or the profile summary information (profile metadata), etc.). RPM may include one or more remote management commands. In this case, the profile (i.e., the subject of each remote management command) may be the same or different for each remote management command.
[0095] In the present disclosure, "certificate" or "digital certificate" may indicate a digital certificate used for mutual authentication based on an asymmetric key composed of a pair of public key (PK) and secret key (SK). Each certificate may include one or more public keys (PKs), a public key ID (PKID) corresponding to each public key, an identifier of the certificate issuer (CI) that issued the corresponding certificate (certificate issuer ID), and a digital signature.
[0096] In addition, "certificate issuer" may be named as certificate issuer, certificate authority (CA), certificate authority, etc.
[0097] In the present disclosure, "public key (PK)" and "public key ID (PKID)" may be used interchangeably to represent the same meaning of a storage space in which a specific public key or a certificate including the corresponding public key, a part of a specific public key or a part of a certificate including the corresponding public key, a value of an operation result of a specific public key (e.g., a hash value) or a value of an operation result of a certificate including the corresponding public key (e.g., a hash value), or a value of an operation result of a part of a specific public key (e.g., a hash value) or a value of an operation result of a part of a certificate including the corresponding public key (e.g., a hash value), or data is stored.
[0098] In the present disclosure, if a certificate (primary certificate) issued by one certificate issuer is used to issue another certificate (secondary certificate), or the secondary certificate is used to successively issue a third or more certificates, the correlation between the corresponding certificates may be named a certificate chain or a certificate hierarchy. In this case, the CI certificate used to issue the first certificate may be named the root of the certificate, the highest certificate, the root CI, the root CI certificate, the root CA, the root CA certificate, etc.
[0099] In the present disclosure, a "mobile service provider" may indicate a company that provides communication services to a terminal and may generally represent all of a business support system (BSS), an operation support system (OSS), a point of sale (POS) terminal, and other IT systems of the service provider. Further, in the present disclosure, the service provider is not limited to only indicating a specific company that provides communication services and may be used as a term representing a group or association (or consortium) of one or more companies and / or a representative representative of the corresponding group or association. Further, in the present disclosure, the service provider may be named an operator (or OP or Op.), a mobile network operator (MNO), a mobile virtual network operator (MVNO), a service provider (SP), a profile owner (PO), etc. At least one of the name and / or the unique ID (object identifier: OID) of the provider may be set or assigned to each service provider. If the service provider represents a group or association or representative of one or more companies, the name or unique ID of the given group or association or representative may be a name or unique ID shared by all companies belonging to the corresponding group or association and / or all companies collaborating with the corresponding representative.
[0100] In the present disclosure, "AKA" may indicate authentication and key agreement and may indicate an authentication algorithm for accessing 3GPP and 3GPP2 networks.
[0101] In the present disclosure, "K" may be an encryption key value stored in the eUICC used in the AKA authentication algorithm.
[0102] In the present disclosure, "OPc" is a parameter value that may be stored in the eUICC used in the AKA authentication algorithm.
[0103] In the present disclosure, "NAA" is a network access application and may be an application stored in the UICC and used to access a network, such as a USIM or an ISIM. The NAA may be a network access module.
[0104] In the present disclosure, an "indicator" can be used to indicate that a given function, setting, or operation is necessary or not necessary, or can be used to represent the corresponding function, setting, or operation itself. Further, in the present disclosure, the indicator can be represented in various forms, such as a string, an alphanumeric string, an operator indicating true / false (Boolean - true or false), a bitmap, an array, or a flag. Other expressions having the same meaning can be used interchangeably.
[0105] Hereinafter, reference is made to Figures 1 to 10 describe a method and an apparatus for installing and managing an eUICC profile according to the present disclosure.
[0106] Figure 1 is a diagram showing a method by which a terminal according to an embodiment of the present disclosure connects to a mobile communication network by using a universal integrated circuit card (UICC) on which a fixed profile has been installed.
[0107] As Figure 1 shown, the UICC 120 can be inserted into the terminal 110. For example, the UICC 120 can be of a detachable type and can have been previously embedded in the terminal.
[0108] The fixed profile of the UICC on which the fixed profile has been installed means that the "access information" based on which a specific communication company can be accessed has been fixed. For example, the access information can be an IMSI (i.e., a subscriber separator), and a K or Ki value necessary for authenticating the network together with the subscriber separator.
[0109] The terminal 110 according to various embodiments can perform authentication by using the UICC 120 together with an authentication processing system of a mobile operator (e.g., a home location register (HLR) or an AuC). For example, the authentication processing can be an authentication and key agreement (AKA) process. When the authentication is successful, the terminal can use mobile communication services, such as making a call or using mobile data, through the mobile communication company network 130 of the mobile communication system.
[0110] Figure 2 is a diagram showing a configuration of a system in which a terminal according to an embodiment of the present disclosure manages a profile installed in a first terminal and installs the profile in a second terminal in response to a user input.
[0111] As Figure 2As shown, eSIMs 211 and 221 have been installed on terminals 210 and 220 respectively. Profiles (not shown) may have been installed in eSIMs 211 and 221 respectively. In addition, LPAs 212 and 222 may have been installed in terminals 210 and 220 respectively. eSIMs 211 and 221 can be controlled by LPAs 212 and 222 respectively. User 200 can control the profiles installed in respective eSIMs 211 and 221 of the terminals through LPAs 212 and 222 respectively.
[0112] Communication services can be provided to user 200 from a service provider (hereinafter referred to as "service provider") 250. To this end, a profile (not shown) of service provider 250 may have been installed in the first terminal 210. For example, if user 200 has newly purchased a second terminal 220, the user may attempt to install again in the second terminal 220 the profile installed in the first terminal 210.
[0113] Service provider 250 may have been coupled to a first profile server 230 and a second profile server 240. LPA 212 of the first terminal 210 may have been coupled to the first profile server 230. LPA 222 of the second terminal 220 may have been coupled to the second profile server 240. In this case, the first profile server 230 and the second profile server 240 may be the same or different. In addition, if one or more operator servers are included in the configuration, each of the operator servers may have been coupled to each individual profile server, and at least one operator server may have been coupled to the same profile server. In addition, for convenience, Figure 2 Each of profile servers 230 and 240 is shown as being composed of a single server. However, according to embodiments and examples, one or more profile servers (SM-DP+) may be included in the server configuration, and one or more discovery relay servers (SM-DS) that assist in the connection and generation between a specific profile server and a terminal may be included in the server configuration. As described above, it will be noted that in the following drawings, various configurations of the servers may be briefly indicated as a single profile server.
[0114] The detailed operations and message exchange processes of user 200, service provider 250, terminals 210 and 220, eSIMs 211 and 221, LPAs 212 and 222, and profile servers 230 and 240 according to embodiments of the present disclosure will be described in detail with reference to the drawings to be described later.
[0115] Figure 3A is a diagram showing a process in which a first terminal receives an activation code through a profile server and downloads a new profile by passing the activation code to a second terminal according to an embodiment of the present disclosure.
[0116] Reference Figure 2 to obtain Figure 3A the configurations and descriptions of the user 200, the first terminal 210, the second terminal 220, the first profile server 230, the second profile server 240, and the service provider 250 in Figure 2 For example, the user 200, the first terminal 210, the second terminal 220, the first profile server 230, the second profile server 240, and the service provider 250 may respectively correspond to the user 200, the first terminal 210, the second terminal 220, the first profile server 230, the second profile server 240, and the service provider 250 in
[0117] Reference Figure 3A In step 301a, the user 200 may request the delivery of the first profile from the first terminal 210. If necessary, the user 200 may confirm, via the first terminal 210, information about the first profile (profile metadata) and information that the user attempting to deliver the first profile should note. Some or all of the information about the first profile and some or all of the information that the user attempting to deliver the first profile should note may already be stored in the first terminal 210 or the first profile and may subsequently be received from the first profile server 230 in step 307a and from the second profile server 240 in step 313a. For example, the information about the first profile may include the name or logo of the service provider 250, profile policies, etc. For example, the information that the user attempting to deliver the first profile should note may include the remaining number of profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc. If there is no remaining or defined number of profile deliveries allowed by the service provider 250, the first terminal 210 may notify the user that the delivery of the first profile is impossible and terminate the operation, or may further receive, via the service provider 250 or profile servers 230 or 240 by performing steps 303a to 307a, the cost that the user will pay for the profile delivery, etc., and may notify the user of the cost, etc. In addition, at least one address of the profile server that needs to be accessed by the terminal to deliver the profile may already be stored in the first terminal 210 or the first profile. For example, the profile server that needs to be accessed by the terminal to deliver the profile may be the first profile server 230.
[0118] In step 303a, the first terminal 210 may request the delivery of the first profile from the first profile server 230. For example, step 303a may be performed using at least one of an Initiate Authentication message, a terminal Authentication Client message, or a delivery request message and / or by further sending an operation type set to device change or profile delivery. The process of requesting the delivery of the first profile in step 303a may include the step of sending at least the profile ID (ICCID) of the first profile.
[0119] In step 305a, the first profile server 230 and the service provider 250 may check the delivery possibility of the first profile. If the first profile cannot be delivered to another terminal, the first profile server 230 and the service provider 250 may prepare a new second profile. For example, step 305a may be performed using at least one of a download command message, a Confirm Order message, a Remote Provisioning Management (RPM) command message, a Release Order message, or a Handle Notification. In step 305a, if necessary, the profile server 230 and the service provider 250 may also generate or change information about the first profile (profile metadata), information about the second profile (profile metadata), and / or some or all of the information that the user attempting to deliver the first profile should be aware of. For example, the information about the first profile and the information about the second profile may include the name or logo of the operator 250 that has provided each profile, profile policies, etc. For example, the information that the user attempting to deliver the first profile should be aware of may include the remaining number of profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc. In addition, the first profile server 230 and the service provider 250 may also generate an activation code, based on which the prepared second profile can be downloaded. The activation code may at least include the address of the second profile server 240 storing the second profile and an event identifier (MatchingID) connected to the second profile. For convenience, the first profile server 230 and the second profile server 240 have been shown as separate servers in the drawings, but the first profile server 230 may be the same server as the second profile server 240. For a more detailed description of step 305a and another embodiment, reference may be made to Figure 3B 。
[0120] In step 307a, the first profile server 230 may deliver to the first terminal 210 an activation code that is downloadable based on its second profile, and may also provide a notification that the first profile does not need to be deleted. For example, a method of providing a notification that the first profile does not need to be deleted may be performed using a method such as not sending a first Delete Profile flag, not sending a first Reuse Profile flag, sending a first Do Not Delete Profile flag, or sending a new profile usage flag. In addition, in step 307a, if necessary, the first profile server 230 may also notify the first terminal 210 of some or all information about the first profile, all information about the second profile (profile metadata), and / or all information that a user attempting to deliver the first profile should be aware of. For example, information about the first profile or information about the second profile may include the name or logo of the service provider 250 that has provided each profile, profile policies, etc. For example, information that a user attempting to deliver the first profile should be aware of may include the number of remaining profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc. If the first terminal 210 also receives information about the first profile, information about the second profile, and / or information that a user attempting to deliver the first profile should be aware of, the first terminal 210 may output some or all of the information to the user 200 and may receive permission from the user 200.
[0121] In step 309a, the first terminal 210 may display the activation code on the screen by converting the activation code in the form of an image such as a QR code or in the form of a string, and may notify the user that the activation code has been prepared. The QR code may be replaced with barcode information, other encrypted information, etc.
[0122] In step 311a, the user 200 may input the activation code displayed on the screen of the first terminal 210 to the second terminal 220. Various methods may be used to perform the method of inputting the activation code, such as capturing an image (such as a QR code) using a camera or inputting a string via a keyboard. In addition, if the first terminal 210 and the second terminal 220 are connected via short-range communication (e.g., Bluetooth, NFC, WiFi, WiFi Direct, etc.), in step 309a, the first terminal 210 may directly pass the activation code to the second terminal 220 without displaying the activation code on the screen.
[0123] In step 313a, the second terminal 220 may request to download the second profile from the second profile server 240. For example, at least one of an initiation authentication message, a terminal authentication client message, or a delivery request message may be used to perform step 313a. Step 313a may include a process in which the second terminal 220 passes an event identifier (MatchingID) included in the activation code to the second profile server 240. In step 313a, the second terminal 220 may use WiFi or the Internet network sharing function provided by the first terminal 210 for Internet connection.
[0124] In step 315a, the second profile server 240 may pass information about the second profile (profile metadata) and information that a user downloading the second profile should be aware of to the second terminal 220. For example, the information about the second profile may include the name or logo of the service provider 250, a profile policy, etc. For example, the information that a user downloading the second profile should be aware of may include the remaining number of profile deliveries allowed by the service provider 250, the fees that the user will pay for the profile delivery, etc.
[0125] In step 317a, the user 200 may confirm the information about the second profile and the information that a user downloading the second profile should be aware of, and may consent to profile installation. The operation of consenting to profile installation may include selecting "yes / no", entering a password set by the user 200, entering biometric information such as the fingerprint or iris of the user 200, etc.
[0126] In step 319a, the second terminal 220 may notify the second profile server 240 that the user 200 has consented to profile download, and may request a profile package from the second profile server 240.
[0127] In step 321a, the second profile server 240 may pass the profile package of the second profile to the second terminal 220.
[0128] In step 323a, the second terminal 220 may install the second profile by using the profile package of the second profile.
[0129] In step 325a, the first terminal 210 may disable and delete the first profile, and may notify the first profile server 230 of the disablement result and the deletion result. The disablement result and the deletion result of the first profile may at least include the profile ID (ICCID) of the first profile. For example, a handle notification message may be used to perform step 325a. Step 325a may be a separate operation independent of the first profile server 230 not requesting deletion of the first profile in step 307a, and step 325a may be selectively performed if necessary. In addition, for the convenience of this figure, Figure 3AIt is shown that the first terminal 210 notifies the first profile server 230 of the disabling result and the deletion result. However, the disabling result and the deletion result may be transmitted to another profile server (for example, a second profile server 240 or a third profile server not shown in the figure). The disabling result and the deletion result may be transmitted separately. In addition, when the status of the first profile is already a disabled state, the operation of disabling the first profile by the first terminal 210 in step 325a and the operation of the first terminal 210 notifying the first profile server 230 of the disabling result may be omitted.
[0130] Figure 3B is a diagram showing another process in which a first terminal according to an embodiment of the present disclosure receives an activation code through a profile server and downloads a new profile by passing the activation code to a second terminal.
[0131] For Figure 3B the configuration and description of the user 200, the first terminal 210, the second terminal 220, the first profile server 230, the second profile server 240, and the service provider 250 in Figure 2 refer to Figure 2 . For example, the user 200, the first terminal 210, the second terminal 220, the profile server 230, and the service provider 250 may respectively correspond to
[0132] the user 200, the first terminal 210, the second terminal 220, the first profile server 230, and the service provider 250 in Figure 3B Referring to
[0133] In step 303b, user 200 may request delivery of the first profile from the first terminal 210. If necessary, user 200 may confirm information (profile metadata) regarding the first profile via the first terminal 210. Some or all of the information regarding the first profile may already be stored in the first terminal 210 or the first profile. For example, the information regarding the first profile may include the name or logo of the service provider 250, profile policies, etc. In addition, at least one address of the profile server to be accessed by the terminal for delivering the profile may already be stored in the first terminal 210 and the first profile. For example, the profile server to be accessed by the terminal for delivering the profile may be the profile server 230.
[0134] In step 305b, the first terminal 210 may request delivery of the first profile from the profile server 230. For example, step 305b may be performed by using at least one of an initiation authentication message, a terminal authentication client message, or a delivery request message and / or by further sending an operation type set to device change or profile delivery. The process of requesting delivery of the first profile in step 305b may include the step of sending at least the profile ID (ICCID) of the first profile.
[0135] In step 307b, the profile server 230 may notify the service provider 250 that a request for delivery of the first profile has been received from the terminal 210. For example, step 307b may be performed using a handle notification message.
[0136] In step 309b, the service provider 250 may check the delivery policy of the first profile. For the criteria for allowing delivery of the first profile, reference may be made to the communication rate system subscribed to by the user 200, etc. The service provider 250 may provide the user 200 with additional information for delivering the first profile and, if necessary, may identify the need to receive permission from the user 200.
[0137] In step 311b, the service provider 250 may pass some or all of the information that the user attempting to deliver the first profile should be aware of to the profile server 230. For example, the information that the user attempting to deliver the first profile should be aware of may include the remaining number of profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, and so on. In step 311b, when necessary, the profile server 230 and the service provider 250 may also generate or change some or all of the information (profile metadata) about the first profile, all of the information (profile metadata) about the second profile, and / or all of the information that the user attempting to deliver the first profile should be aware of. For example, the information about the first profile or the information about the second profile may include the name or logo of the service provider 250 that has provided each profile, the profile policy, and so on. For example, the information that the user attempting to deliver the first profile should be aware of may include the remaining number of profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, and so on.
[0138] In step 313b, the profile server 230 may pass some or all of the information that the user attempting to deliver the first profile should be aware of to the first terminal 210. The first terminal 210 may show some or all of the received information to the user 200.
[0139] In step 315b, the user 200 may confirm the information for delivering the first profile presented by the service provider 250 and may input user approval to the first terminal 210.
[0140] In step 317b, the first terminal 210 may pass that the user has agreed to the delivery of the first profile to the profile server 230. For example, step 317b may be performed by using at least one of an initiation authentication message, a terminal authentication client message, or a delivery request message and / or by further sending an operation type set to Device Change Confirmed, Transfer Profile Confirmed, or End User Confirmed. The process of passing that the user has agreed to the delivery of the first profile in step 317b may include the step of sending at least the profile ID (ICCID) of the first profile.
[0141] In step 319b, the profile server 230 may notify the service provider 250 that the user has agreed to the delivery of the first profile. For example, step 319b may be performed by using a handle notification message.
[0142] In step 321b, the profile server 230 and the service provider 250 may prepare a new second profile. For example, step 321b may be performed using at least one of a download command message, a confirmation command message, a remote management command (RPM command) message, a release command message, or a handle notification. In addition, the profile server 230 and the service provider 250 may also generate an activation code, and the prepared second profile is downloadable based on the activation code. The activation code may include at least the address of the profile server 230 that stores the second profile and an event identifier (MatchingID) associated with the second profile.
[0143] In step 323b, the profile server 230 may pass the activation code based on which the second profile is downloadable to the first terminal 210, and may also provide a notification that the first profile does not need to be deleted. For example, the method of providing the notification that the first profile does not need to be deleted may be performed using methods such as not sending a first delete profile flag, not sending a first reuse profile flag, sending a first do not delete profile flag, or sending a new profile usage flag.
[0144] In step 325b, the first terminal 210 may display the activation code on the screen by converting the activation code in the form of an image such as a QR code or in the form of a string, and may notify the user that the activation code has been prepared. The QR code may be replaced with barcode information, other encrypted information, etc.
[0145] In step 327b, the user 200 may input the activation code displayed on the screen of the first terminal 210 to the second terminal 220. The method of inputting the activation code may be performed using various methods, such as capturing an image (such as a QR code) using a camera or inputting a string via a keyboard. In addition, if the first terminal 210 and the second terminal 220 are connected via short-range communication (e.g., Bluetooth, NFC, WiFi, WiFi Direct, etc.), in step 327b, the first terminal 210 may directly pass the activation code to the second terminal 220 without displaying the activation code on the screen.
[0146] In step 329b, the second terminal 220 may download the second profile from the profile server 230. For a detailed description of step 329b, refer to Figure 3A the description of step 313a and its subsequent steps in
[0147] Figure 4A is a diagram showing the process by which a first terminal according to an embodiment of the present disclosure receives an activation code through a profile server and redownloads the same profile by passing the activation code to a second terminal.
[0148] For Figure 4AThe configurations and descriptions of the user 200, the first terminal 210, the second terminal 220, the profile server 230, and the service provider 250 in Figure 2 . For example, the user 200, the first terminal 210, the second terminal 220, the profile server 230, and the service provider 250 may respectively correspond to Figure 2 the user 200, the first terminal 210, the second terminal 220, the first profile server 230, and the service provider 250 in
[0149] Refer to Figure 4A . In step 401a, the user 200 may request the delivery of the first profile from the first terminal 210. To this end, the user 200 may confirm, via the first terminal 210, information about the first profile (profile metadata) and information that a user attempting to deliver the first profile should be aware of. The information about the first profile and the information that a user attempting to deliver the first profile should be aware of may already be stored in the first terminal 210 or the first profile. For example, the information about the first profile may include the name or logo of the service provider 250, a profile policy, etc. For example, the information that a user attempting to deliver the first profile should be aware of may include the remaining number of profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc. In addition, at least one address of the profile server to which the terminal should connect to deliver the profile may already be stored in the first terminal 210 or the first profile. For example, the profile server to which the terminal should connect to deliver the profile may be the profile server 230.
[0150] In step 403a, the first terminal 210 may request the delivery of the first profile from the profile server 230. For example, step 403a may be performed by using at least one of an initiation authentication message, a terminal authentication client message, or a delivery request message and / or by further sending an operation type set to device change or profile delivery. The process of requesting the delivery of the first profile in step 403a may include the step of sending at least the profile ID (ICCID) of the first profile.
[0151] In step 405a, the profile server 230 and the carrier 250 can check the delivery possibility of the first profile. If the first profile can be delivered to another terminal, the profile server 230 and the service provider 250 can prepare for the reuse of the first profile. In this case, the status of the prepared first profile can be set to the state where download is not yet possible, so as to prevent the copying of the first profile. For example, at least one of a download command message, a confirmation command message, a remote management command (RPM command) message, a release command message, or a handle notification can be used to execute step 405a. In step 405a, if necessary, the profile server 230 and the service provider 250 can also generate or change some or all of the information (profile metadata) about the first profile and / or all of the information that the user attempting to deliver the first profile should note. For example, the information about the first profile can include the name or logo of the service provider 250, the profile policy, etc. For example, the information that the user attempting to deliver the first profile should note can include the remaining number of profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc. In addition, the profile server 230 and the service provider 250 can also generate an activation code based on which the first profile can be downloaded again. The activation code can at least include the address of the profile server 240 storing the first profile and the event identifier (MatchingID) connected to the first profile. In this figure, for the sake of convenience, the first profile has been shown as being stored in the profile server 230, but the first profile can be stored in a profile server different from the profile server 230. For example, the second profile server 240 in Figure 3A can be used.
[0152] In step 407a, the profile server 230 can pass the activation code based on which the first profile can be downloaded again to the first terminal 210, and can also provide a notice that the first profile needs to be deleted. For example, methods such as sending a first delete profile flag, sending a first reuse profile flag, not sending a first profile do not delete flag, or not sending a new profile usage flag can be used to execute the method of providing a notice that the first profile needs to be deleted. In addition, in step 407a, if necessary, the first profile server 230 can also notify the first terminal 210 of some or all of the information (profile metadata) about the second profile and / or all of the information that the user downloading the second profile should note. When further receiving the information about the second profile and / or the information that the user downloading the second profile should note, the first terminal 210 can output some or all of the information to the user 200 and can receive permission from the user 200.
[0153] In step 409a, the first terminal 210 may disable and delete the first profile in response to a request from the profile server 230, and may notify the profile server 230 of the disable result and the delete result. The disable result and the delete result of the first profile may at least include the profile ID (ICCID) of the first profile. For example, step 409a may be performed using at least one of a DisableProfile message, a Delete Profile message, or a handle notification message. Additionally, for the convenience of this figure, Figure 4A it is shown that the first terminal 210 notifies the profile server 230 of the disable result and the delete result. However, the disable result and the delete result may be passed to another profile server (e.g., a second profile server 240 or a third profile server not shown in the figure). The disable result and the delete result may be passed separately. Additionally, when the status of the first profile is already in the disabled state, the operation of the first terminal 210 disabling the first profile and the operation of the first terminal 210 notifying the profile server 230 of the disable result in step 409a may be omitted.
[0154] In step 411a, the profile server 230 may recognize that the first terminal 210 has deleted the first profile, and may set the status of the first profile prepared in step 405a to the downloadable state. Additionally, the profile server 230 may notify the first terminal 210 that the status of the first profile is the downloadable state.
[0155] In step 413a, the first terminal 210 may display the activation code on the screen by converting the activation code in the form of an image such as a QR code or in the form of a string, and may notify the user that the activation code has been prepared.
[0156] In step 415a, the user 200 may input the activation code displayed on the screen of the first terminal 210 into the second terminal 220. Various methods may be used to perform the method of inputting the activation code, such as capturing an image (such as a QR code) using a camera or inputting a string through a keyboard. Additionally, if the first terminal 210 and the second terminal 220 are connected by short-range communication (e.g., Bluetooth, NFC, WiFi, WiFi Direct, etc.), in step 413a, the first terminal 210 may directly pass the activation code to the second terminal 220 without displaying the activation code on the screen.
[0157] In step 417a, the second terminal 220 may request to download the first profile from the profile server 230. For example, at least one of an initiation authentication message, a terminal authentication client message, or a delivery request message may be used to perform step 417a. Step 417a may include a process in which the second terminal 220 passes an event identifier (MatchingID) included in the activation code to the profile server 230. In step 417a, the second terminal 220 may use the WiFi or the Internet network sharing function provided by the first terminal 210 for Internet connection.
[0158] In step 419a, the profile server 230 may first identify whether the status of the first profile is a downloadable status. If the status of the first profile is a non-downloadable status because the profile server 230 has not recognized through steps 409a to 411a that the first profile has been deleted from the first terminal, the profile server 230 may send an error code as a response and terminate the operation. When the status of the first profile is a downloadable status, the profile server 230 may pass information about the first profile (profile metadata) and information that the user who downloads the first profile should note to the second terminal 220. For example, the information about the first profile may include the name or logo of the carrier 250, a profile policy, etc. For example, the information that the user who downloads the first profile should note may include the remaining number of profile deliveries allowed by the carrier 250, the cost that the user will pay for the profile delivery, etc.
[0159] In step 421a, the user 200 may confirm the information about the first profile and the information that the user who downloads the first profile should note, and may agree to profile installation. The operation of agreeing to profile installation may include selecting "Yes / No", entering a password set by the user 200, an operation of entering biometric information (such as the fingerprint or iris of the user 200, etc.).
[0160] In step 423a, the second terminal 220 may notify the profile server 230 that the user 200 has agreed to profile download, and may request a profile package from the profile server 230.
[0161] In step 425a, the profile server 230 may pass the profile package of the first profile to the second terminal 220.
[0162] In step 427a, the second terminal 220 may install the first profile by using the profile package of the first profile.
[0163] Figure 4B FIG. is a diagram showing another process in which a first terminal according to an embodiment of the present disclosure receives an activation code through a profile server and downloads a new profile by passing the activation code to a second terminal.
[0164] ForFigure 4B The configurations and descriptions of user 200, first terminal 210, second terminal 220, profile server 230, and service provider 250 in Figure 2 are referred to. For example, user 200, first terminal 210, second terminal 220, profile server 230, and operator 250 may respectively correspond to Figure 2 user 200, first terminal 210, second terminal 220, first profile server 230, and operator 250 in
[0165] Refer to Figure 4B . In step 401b, when a request to deliver the first profile is received from terminal 210 or 220, operator 250 may request profile server 230 to notify service provider 250 of the delivery of the first profile. For example, a method such as using a Notification Request On Transfer flag or a Transfer Available Without Notification flag may be used to perform the method of requesting profile server 230 to notify service provider 250 of the delivery of the first profile when a request to deliver the first profile is received.
[0166] In step 403b, user 200 may request the delivery of the first profile from first terminal 210. If necessary, user 200 may confirm information (profile metadata) about the first profile through first terminal 210. Some or all of the information about the first profile may already be stored in first terminal 210 or the first profile. For example, the information about the first profile may include the name or logo of operator 250, profile policies, etc. In addition, at least one address of the profile server to which the terminal should connect to deliver the profile may already be stored in first terminal 210 or the first profile. For example, the profile server to which the terminal should connect to deliver the profile may be profile server 230.
[0167] In step 405b, first terminal 210 may request the delivery of the first profile from profile server 230. For example, step 405b may be performed by using at least one of an initiation authentication message, a terminal authentication client message, or a delivery request message and / or by further sending an operation type set to device change or profile delivery. The process of requesting the delivery of the first profile in step 405b may include the step of sending at least the profile ID (ICCID) of the first profile.
[0168] In step 407b, profile server 230 may notify operator 250 that a request to deliver the first profile has been received from terminal 210. For example, step 407b may be performed by using a handle notification message.
[0169] In step 409b, the service provider 250 may check the delivery policy of the first profile. For the criteria allowing the delivery of the first profile, reference may be made to, for example, a communication rate system subscribed to by the user 200. The service provider 250 may provide the user 200 with additional information for delivering the first profile and, if necessary, determine that permission from the user 200 needs to be received.
[0170] In step 411b, the service provider 250 may pass on to the profile server 230 some or all of the information that a user attempting to deliver the first profile should be aware of, and may also provide a notice that the first profile needs to be deleted first. For example, the information that a user attempting to deliver the first profile should be aware of may include the number of remaining profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc. In step 411b, if necessary, the profile server 230 and the service provider 250 may also generate or change some or all of the information (profile metadata) about the first profile and / or all of the information that a user attempting to deliver the first profile should be aware of. For example, the information about the first profile may include the name or logo of the service provider 250 that has provided the first profile, the profile policy, etc. For example, the information that a user attempting to deliver the first profile should be aware of may include the number of remaining profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc. For example, methods such as sending a first delete profile flag, sending a first reuse profile flag, not sending a No Not Delete Profile flag, or not sending a new profile usage flag may be used to perform the method of providing a notice that the first profile needs to be deleted.
[0171] In step 413b, the profile server 230 may pass on to the first terminal 210 some or all of the information that a user attempting to deliver the first profile should be aware of. The first terminal 210 may show some or all of the received information to the user 200.
[0172] In step 415b, the user 200 may confirm the information presented by the service provider 250 for delivering the first profile and may input user permission to the first terminal 210.
[0173] In step 417b, the first terminal 210 may pass on that the user has agreed to the delivery of the first profile to the profile server 230. For example, step 417b may be performed by using at least one of an initiation authentication message, a terminal authentication client message, or a delivery request message and / or by further sending an operation type set to device change confirmation, delivery profile confirmation, or terminal user confirmation. The process of passing on in step 417b that the user has agreed to the delivery of the first profile may include the step of sending at least the profile ID (ICCID) of the first profile.
[0174] In step 419b, the profile server 230 may notify the operator 250 that the user has consented to the delivery of the first profile. For example, a handle notification message may be used to perform step 419b.
[0175] In step 421b, the profile server 230 and the operator 250 may prepare for the reuse of the first profile. For example, at least one of a download command message, a confirmation command message, a remote management command (RPM command) message, or a handle notification may be used to perform step 421b, and step 421b may be performed by further providing a notification that the first profile needs to be deleted. For example, a method of providing a notification that the first profile needs to be deleted may be performed using methods such as sending a first delete profile flag, sending a first reuse profile flag, not sending a first profile not delete unnecessary (No Not Delete Profile) flag, or not sending a new profile use flag. In addition, the profile server 230 and the operator 250 may also generate an activation code, and the prepared first profile is downloadable based on the activation code. The activation code may at least include the address of the profile server 230 storing the first profile and an event identifier (MatchingID) connected to the first profile.
[0176] In step 423b, the profile server 230 may pass the activation code based on which the first profile is downloadable to the first terminal 210, and may also provide a notification that the first profile needs to be deleted. For example, a method of providing a notification that the first profile needs to be deleted may be performed using methods such as sending a first delete profile flag, sending a first reuse profile flag, not sending a first profile not delete unnecessary (No Not Delete Profile) flag, or not sending a new profile use flag.
[0177] In step 425b, the first terminal 210 may disable and delete the first profile in response to a request from the profile server 230, and may notify the profile server 230 of the disable result and the delete result. The disable result and the delete result of the first profile may at least include the profile ID (ICCID) of the first profile. For example, at least one of a disable profile message, a delete profile message, or a handle notification message may be used to perform step 425b. In addition, for the convenience of this figure, Figure 4B it is shown that the first terminal 210 notifies the profile server 230 of the disable result and the delete result. However, the disable result and the delete result may be passed to another profile server (for example, a second profile server 240 or a third profile server not shown in the figure). The disable result and the delete result may be passed separately. In addition, when the status of the first profile is already in a disabled state, the operation of the first terminal 210 disabling the first profile in step 425b and the operation of the first terminal 210 notifying the profile server 230 of the disable result may be omitted.
[0178] In step 427b, the profile server 230 may notify the service provider 250 that the first profile has been deleted from the first terminal 210. For example, the handle notification message may be used to perform step 427b. Step 427b may include a process of passing at least the ID (ICCID) of the first profile.
[0179] In step 429b, the service provider 250 may request the profile server 230 to change the status of the first profile to an available state. For example, the release command message may be used to perform step 429b.
[0180] In step 431b, the profile server 230 may, in response to a request from the service provider 250, set the status of the first profile prepared in step 421b to a downloadable state. In addition, the profile server 230 may notify the first terminal 210 that the status of the first profile is a downloadable state.
[0181] In step 433b, the first terminal 210 may display the activation code on the screen by converting the activation code in the form of an image such as a QR code or in the form of a string, and may notify the user that the activation code has been prepared. The QR code may be replaced with barcode information, other encrypted information, etc.
[0182] In step 435b, the user 200 may input the activation code displayed on the screen of the first terminal 210 to the second terminal 220. Various methods may be used to perform the method of inputting the activation code, such as capturing an image (such as a QR code) using a camera or inputting a string through a keyboard. In addition, if the first terminal 210 and the second terminal 220 are connected by short-range communication (e.g., Bluetooth, NFC, WiFi, WiFi Direct, etc.), in step 423b, the first terminal 210 may directly transmit the activation code to the second terminal 220 without displaying the activation code on the screen.
[0183] In step 437b, the second terminal 220 may download the first profile from the profile server 230. For a detailed description of step 437b, refer to Figure 4A the description of step 417a and its subsequent steps in
[0184] Figure 4C is a diagram showing another process in which a first terminal according to an embodiment of the present disclosure receives an activation code through a profile server and downloads a new profile by passing the activation code to a second terminal.
[0185] For Figure 4C the configuration and description of the user 200, the first terminal 210, the second terminal 220, the profile server 230, and the service provider 250 in Figure 2For example, user 200, the first terminal 210, the second terminal 220, the profile server 230, and the service provider 250 may respectively correspond to Figure 2 user 200, the first terminal 210, the second terminal 220, the first profile server 230, and the service provider 250 in
[0186] Referring to Figure 4C , in step 401c, when a request to deliver the first profile is received from terminal 210 or 220, the service provider 250 may request the profile server 230 to notify the service provider 250 of the delivery of the first profile. For example, a method such as using a Send Notification Request On Transfer flag or a Transfer Available Without Notification flag may be used to perform the method of requesting the profile server 230 to notify the service provider 250 of the delivery of the first profile when a request to deliver the first profile is received.
[0187] In step 403c, user 200 may request the delivery of the first profile from the first terminal 210. If necessary, user 200 may confirm information (profile metadata) about the first profile through the first terminal 210. Some or all of the information about the first profile may already be stored in the first terminal 210 or the first profile. For example, the information about the first profile may include the name or logo of the service provider 250, the profile policy, etc. In addition, at least one address of the profile server to which the terminal should connect to deliver the profile may already be stored in the first terminal 210 or the first profile. For example, the profile server to which the terminal should connect to deliver the profile may be the profile server 230.
[0188] In step 405c, the first terminal 210 may request the delivery of the first profile from the profile server 230. For example, step 405c may be performed by using at least one of an Initiate Authentication Message, a Terminal Authentication Client Message, or a Delivery Request Message and / or by further sending an operation type set to device change or profile delivery. The process of requesting the delivery of the first profile in step 405c may include the step of sending at least the profile ID (ICCID) of the first profile.
[0189] In step 407c, the profile server 230 may notify the service provider 250 that a request to deliver the first profile has been received from terminal 210. For example, step 407c may be performed by using a Handle Notification Message.
[0190] In step 409c, the service provider 250 may check the delivery policy of the first profile. For the criteria allowing the delivery of the first profile, reference may be made to, for example, the communication rate system subscribed by the user 200. The service provider 250 may provide the user 200 with additional information for delivering the first profile and, if necessary, may identify the need to receive permission from the user 200.
[0191] In step 411c, the service provider 250 may pass some or all of the information that the user attempting to deliver the first profile should be aware of to the profile server 230. For example, the information that the user attempting to deliver the first profile should be aware of may include the remaining number of profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc. In step 411c, if necessary, the profile server 230 and the service provider 250 may further generate or change some or all of the information (profile metadata) about the first profile and / or all of the information that the user attempting to deliver the first profile should be aware of. For example, the information about the first profile may include the name or logo of the service provider 250 that has provided the first profile, the profile policy, etc. For example, the information that the user attempting to deliver the first profile should be aware of may include the remaining number of profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc.
[0192] In step 413c, the profile server 230 may pass some or all of the information that the user attempting to deliver the first profile should be aware of to the first terminal 210. The first terminal 210 may show some or all of the received information to the user 200.
[0193] In step 415c, the user 200 may confirm the information presented by the service provider 250 for delivering the first profile and may input user permission to the first terminal 210.
[0194] In step 417c, the first terminal 210 may pass that the user has agreed to the delivery of the first profile to the profile server 230. For example, step 417c may be performed by using at least one of an initiation authentication message, a terminal authentication client message, or a delivery request message and / or by further sending an operation type set to device change confirmation, delivery profile confirmation, or terminal user confirmation. The process of passing in step 417c that the user has agreed to the delivery of the first profile may include the step of sending at least the profile ID (ICCID) of the first profile.
[0195] In step 419c, the profile server 230 may notify the service provider 250 that the user has permitted the delivery of the first profile. For example, step 419c may be performed using a handle notification message.
[0196] In step 421c, the profile server 230 and the service provider 250 may prepare for the reuse of the first profile. For example, at least one of a download command message, a confirmation command message, a remote management command (RPM command) message, a release command message, or a handle notification may be used to execute step 421c, and step 421c may be executed by further providing a notification that the first profile needs to be deleted. For example, a method of providing a notification that the first profile needs to be deleted may be executed by using methods such as sending a first delete profile flag, sending a first reuse profile flag, not sending a first profile not delete unnecessary (No Not Delete Profile) flag, or not sending a new profile usage flag. In addition, the profile server 230 and the service provider 250 may also generate an activation code, and the prepared first profile is downloadable based on the activation code. The activation code may at least include the address of the profile server 230 storing the first profile and an event identifier (MatchingID) connected to the first profile.
[0197] In step 423c, the profile server 230 may transfer the activation code based on which the first profile is downloadable to the first terminal 210, and may also provide a notification that the first profile needs to be deleted. For example, a method of providing a notification that the first profile needs to be deleted may be executed by using methods such as sending a first delete profile flag, sending a first reuse profile flag, not sending a first profile not delete unnecessary (No Not Delete Profile) flag, or not sending a new profile usage flag.
[0198] In step 425c, the first terminal 210 may disable and delete the first profile in response to a request from the profile server 230, and may notify the profile server 230 of the disable result and the delete result. The disable result and the delete result of the first profile may at least include the profile ID (ICCID) of the first profile. For example, at least one of a disable profile message, a delete profile message, or a handle notification message may be used to execute step 425c. In addition, for the convenience of this figure, Figure 4C it is shown that the first terminal 210 notifies the profile server 230 of the disable result and the delete result. However, the disable result and the delete result may be transferred to another profile server (for example, a second profile server 240 or a third profile server not shown in the figure). The disable result and the delete result may be transferred separately. In addition, when the status of the first profile is already in a disabled state, the operation of the first terminal 210 disabling the first profile in step 425c and the operation of the first terminal 210 notifying the profile server 230 of the disable result may be omitted.
[0199] In step 427c, the profile server 230 may identify that the first terminal 210 has deleted the first profile and may set the status of the first profile prepared in step 421c to a downloadable status. In addition, the profile server 230 may notify the first terminal 210 that the status of the first profile is a downloadable status.
[0200] In step 429c, the profile server 230 may notify the service provider 250 that the first profile has been deleted from the first terminal 210 and that profile delivery is ready. For example, step 427c may be performed using a handle notification message. Step 427c may include at least a process of passing the ID (ICCID) of the first profile.
[0201] In step 433c, the first terminal 210 may display the activation code on the screen by converting the activation code in the form of an image such as a QR code or in the form of a string, and may notify the user that the activation code is ready. The QR code may be replaced with barcode information, other encrypted information, etc.
[0202] In step 435c, the user 200 may input the activation code displayed on the screen of the first terminal 210 into the second terminal 220. Various methods may be used to perform the method of inputting the activation code, such as capturing an image (such as a QR code) using a camera or inputting a string through a keyboard. In addition, if the first terminal 210 and the second terminal 220 are connected by short - range communication (e.g., Bluetooth, NFC, WiFi, WiFi Direct, etc.), in step 423c, the first terminal 210 may directly pass the activation code to the second terminal 220 without displaying the activation code on the screen.
[0203] In step 437c, the second terminal 220 may download the first profile from the profile server 230. For a detailed description of step 437c, refer to Figure 4A the description of step 417a and its subsequent steps in
[0204] Figure 4D FIG. is a diagram showing another process in which a first terminal according to an embodiment of the present disclosure receives an activation code through a profile server and downloads a new profile by passing the activation code to a second terminal.
[0205] For Figure 4D the configuration and description of the user 200, the first terminal 210, the second terminal 220, the first profile server 230, and the service provider 250 in Figure 2 . For example, the user 200, the first terminal 210, the second terminal 220, the profile server 230, and the service provider 250 may respectively correspond to Figure 2User 200, the first terminal 210, the second terminal 220, the first profile server 230, and the service provider 250 in
[0206] Reference Figure 4D , in step 401d, when a request to deliver the first profile is received from terminal 210 or 220, the service provider 250 may request the profile server 230 to notify the service provider 250 of the delivery of the first profile. For example, a method such as using a Notification Request On Transfer flag or a Transfer Available Without Notification flag may be used to perform the method of requesting the profile server 230 to notify the service provider 250 of the delivery of the first profile when a request to deliver the first profile is received.
[0207] In step 403d, user 200 may request the delivery of the first profile from the first terminal 210. If necessary, user 200 may confirm information (profile metadata) about the first profile through the first terminal 210. Some or all of the information about the first profile may already be stored in the first terminal 210 or the first profile. For example, the information about the first profile may include the name or logo of the service provider 250, the profile policy, etc. In addition, at least one address of the profile server to be accessed by the terminal to deliver the profile may already be stored in the first terminal 210 or the first profile. For example, the profile server to be accessed by the terminal to deliver the profile may be the profile server 230.
[0208] In step 405d, the first terminal 210 may request the delivery of the first profile from the profile server 230. For example, step 405d may be performed by using at least one of an initiation authentication message, a terminal authentication client message, or a delivery request message and / or by further sending an operation type set to device change or profile delivery. The process of requesting the delivery of the first profile in step 405d may include the step of sending at least the profile ID (ICCID) of the first profile.
[0209] In step 407d, the profile server 230 may notify the service provider 250 that a request to deliver the first profile has been received from terminal 210. For example, step 407d may be performed using a handle notification message.
[0210] In step 409d, the service provider 250 may check the delivery policy of the first profile. For the criteria for allowing the delivery of the first profile, reference may be made to, for example, a communication rate system subscribed by the user 200. The service provider 250 may provide the user 200 with additional information for delivering the first profile and, if necessary, may identify the need to receive permission from the user 200.
[0211] In step 411d, the service provider 250 may pass some or all of the information that a user attempting to deliver the first profile should be aware of to the profile server 230. For example, the information that a user attempting to deliver the first profile should be aware of may include the number of remaining profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc. In step 411d, if necessary, the profile server 230 and the service provider 250 may also generate or change some or all of the information (profile metadata) about the first profile and / or all of the information that a user attempting to deliver the first profile should be aware of. For example, the information about the first profile may include the name or logo of the operator 250 that has provided the first profile, the profile policy, etc. For example, the information that a user attempting to deliver the first profile should be aware of may include the number of remaining profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc.
[0212] In step 413d, the profile server 230 may pass some or all of the information that a user attempting to deliver the first profile should be aware of to the first terminal 210 and may also provide a notice that the first profile needs to be deleted. For example, a method of providing a notice that the first profile needs to be deleted may be performed by using methods such as sending a first delete profile flag, sending a first reuse profile flag, not sending a first profile not delete unnecessary (No NotDelete Profile) flag, or not sending a new profile use flag. The first terminal 210 may show some or all of the received information to the user 200.
[0213] In step 415d, the user 200 may confirm the information presented by the service provider 250 for delivering the first profile and may input user permission to the first terminal 210.
[0214] In step 417d, the first terminal 210 may disable and delete the first profile in response to a request from the profile server 230 and may notify the profile server 230 of the disable result and the delete result. The disable result and the delete result of the first profile may at least include the profile ID (ICCID) of the first profile. For example, step 417d may be performed by using at least one of a disable profile message, a delete profile message, or a handle notification message. In addition, for the convenience of this figure, Figure 4DIt is shown that the first terminal 210 notifies the profile server 230 of the disabling result and the deletion result. However, the disabling result and the deletion result can be passed to another profile server (for example, a second profile server 240 or a third profile server not shown in the figure). The disabling result and the deletion result can be passed separately. In addition, when the status of the first profile is already in the disabled state, the operation of disabling the first profile by the first terminal 210 in step 417d and the operation of the first terminal 210 notifying the profile server 230 of the disabling result can be omitted. Step 417d may include the process of the first terminal 210 passing that the user has agreed to deliver the first profile to the profile server 230. For example, step 417d can be performed by using at least one of an initiation authentication message, a terminal authentication client message, a delivery request message, or a handle notification message and / or by further sending an operation type set as device change confirmation, delivery profile confirmation, or end user confirmation. The process of passing that the user has agreed to deliver the first profile in step 417d may include at least the step of sending the profile ID (ICCID) of the first profile.
[0215] In step 419d, the profile server 230 may notify the service provider 250 that the user has agreed to the delivery of the first profile. For example, step 419d can be performed by using a handle notification message.
[0216] In step 421d, the profile server 230 and the operator 250 may prepare for the reuse of the first profile. For example, step 421d can be performed by using at least one of a download command message, a confirmation command message, a remote management command (RPM command) message, a release command message, or a handle notification. In addition, the profile server 230 and the service provider 250 may also generate an activation code based on which the prepared first profile for reuse is downloadable. The activation code may at least include the address of the profile server 230 storing the first profile and the event identifier (MatchingID) connected to the first profile.
[0217] In step 423d, the profile server 230 may identify that the first terminal 210 has deleted the first profile and may set the status of the first profile prepared in step 421d to the downloadable state. In addition, the profile server 230 may notify the first terminal 210 that the status of the first profile is the downloadable state by passing the activation code based on which the first profile is downloadable to the first terminal 210.
[0218] In step 425d, the profile server 230 may notify the service provider 250 that the first profile has been deleted from the first terminal 210 and the profile delivery is ready. For example, step 425d can be performed by using a handle notification message. Step 425d may include at least the process of passing the ID (ICCID) of the first profile.
[0219] In step 433d, the first terminal 210 can display the activation code on the screen by converting the activation code in the form of an image such as a QR code or in the form of a string, and can notify the user that the activation code has been prepared. The QR code can be replaced with bar code information, other encrypted information, etc.
[0220] In step 435d, the user 200 can input the activation code displayed on the screen of the first terminal 210 into the second terminal 220. Various methods can be used to perform the method of inputting the activation code, such as capturing an image (such as a QR code) using a camera or inputting a string through a keyboard. In addition, if the first terminal 210 and the second terminal 220 are connected through short-range communication (for example, Bluetooth, NFC, WiFi, WiFi Direct, etc.), in step 423d, the first terminal 210 can directly transfer the activation code to the second terminal 220 without displaying the activation code on the screen.
[0221] In step 437d, the second terminal 220 can download the first profile from the profile server 230. For a detailed description of step 437d, refer to Figure 4A the description of step 417a and its subsequent steps in
[0222] Figure 5 FIG. is a diagram showing a process in which a first terminal according to an embodiment of the present disclosure downloads a new profile by sending an activation code stored in the first terminal to a second terminal.
[0223] For Figure 5 the configuration and description of the user 200, the first terminal 210, the second terminal 220, the profile server 230, and the service provider 250 in Figure 2 . For example, the user 200, the first terminal 210, the second terminal 220, the profile server 230, and the service provider 250 may respectively correspond to Figure 2 the user 200, the first terminal 210, the second terminal 220, the first profile server 230, and the operator 250 in
[0224] Refer to Figure 5, in step 501, user 200 may request the delivery of a first profile from the first terminal 210. To this end, user 200 may confirm, via the first terminal 210, information about the first profile (profile metadata) and information that the user attempting to deliver the first profile should be aware of. The information about the first profile and the information that the user attempting to deliver the first profile should be aware of may already be stored in the first terminal 210 or the first profile. For example, the information about the first profile may include the name or logo of the service provider 250, the profile policy, etc. For example, the information that the user attempting to deliver the first profile should be aware of may include the remaining number of profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc. In addition, the activation code required for the terminal to deliver the first profile and the information indicating that the first profile does not need to be deleted for profile delivery may already be stored in the first terminal 210 or the first profile. For example, the activation code required for the terminal to deliver the first profile may be the activation code used to install the first profile in the first terminal in the past. The information indicating that the first profile does not need to be deleted for profile delivery may be represented using methods such as: the first delete profile flag has not been set, the first reuse profile flag has not been set, the first profile delete unnecessary (No Not Delete Profile) flag has been set, or the new profile use flag has been set, etc.
[0225] In step 503, the first terminal 210 may call the activation code stored in the first terminal 210 or the first profile and required for the terminal to deliver the first profile. The activation code may at least include the address of the profile server 230 that stores the second profile and the event identifier (MatchingID) connected to the second profile.
[0226] In step 505, the first terminal 210 may display the activation code on the screen by converting the activation code in the form of an image such as a QR code or in the form of a string, and may notify the user that the activation code is ready.
[0227] In step 507, user 200 may input the activation code displayed on the screen of the first terminal 210 into the second terminal 220. Various methods may be used to perform the method of inputting the activation code, such as capturing an image (such as a QR code) using a camera or inputting a string via a keyboard. In addition, if the first terminal 210 and the second terminal 220 are connected via short-range communication (e.g., Bluetooth, NFC, WiFi, WiFi Direct, etc.), in step 507, the first terminal 210 may directly pass the activation code to the second terminal 220 without displaying the activation code on the screen.
[0228] In step 509, the second terminal 220 may request to download a second profile from the profile server 230. For example, at least one of an initiation authentication message, a terminal authentication client message, or a delivery request message may be used to perform step 509. Step 509 may include a process in which the second terminal 220 passes an event identifier (MatchingID) included in the activation code to the profile server 230. In step 509, the second terminal 220 may use WiFi for an Internet connection, or may use an Internet network sharing function provided by the first terminal 210.
[0229] In step 511, the profile server 230 may pass information about the second profile (profile metadata) and information that a user who downloads the second profile should be aware of to the second terminal 220. For example, information about the second profile may include the name or logo of the service provider 250, a profile policy, and the like. For example, information that a user who downloads the second profile should be aware of may include the remaining number of profile deliveries allowed by the service provider 250, the fees that the user will pay for profile delivery, and the like.
[0230] In step 513, the user 200 may confirm the information about the second profile and the information that a user who downloads the second profile should be aware of, and may consent to profile installation. The operation of consenting to profile installation may include selecting "Yes / No", an operation in which the user 200 inputs a set password, an operation of inputting biometric information (such as the fingerprint or iris of the user 200), and the like.
[0231] In step 515, the second terminal 220 may notify the profile server 230 that the user 200 has consented to profile download and may request a profile package.
[0232] In step 517, the profile server 230 may pass a profile package of the second profile to the second terminal 220.
[0233] In step 519, the second terminal 220 may install the second profile by using the profile package of the second profile.
[0234] In step 521, the first terminal 210 may disable and delete the first profile, and may notify the profile server 230 of the disable result and the delete result. The disable result and the delete result of the first profile may at least include the profile ID (ICCID) of the first profile. For example, at least one of a disable profile message, a delete profile message, or a handle notification message may be used to perform step 521. Step 521 may be a separate operation independent of the first terminal 210 having checked in step 503 that the first profile does not need to be deleted, and may be selectively performed if necessary. In addition, for the convenience of this figure, Figure 5It shows that the first terminal 210 notifies the profile server 230 of the disabling result and the deletion result. However, the disabling result and the deletion result can be transmitted to another profile server (e.g., Figure 3A the second profile server 240 in or a third profile server not shown in the figure). The disabling result and the deletion result can be transmitted separately. In addition, when the status of the first profile is already a disabled state, the operation of disabling the first profile by the first terminal 210 in step 521 and the operation of the first terminal 210 notifying the profile server 230 of the disabling result can be omitted.
[0235] Figure 6 is a diagram showing the process of the first terminal according to an embodiment of the present disclosure re-downloading the same profile by sending an activation code stored in the first terminal to the second terminal.
[0236] For Figure 6 the configuration and description of the user 200, the first terminal 210, the second terminal 220, the profile server 230, and the service provider 250 in, refer to Figure 2 . For example, the user 200, the first terminal 210, the second terminal 220, the profile server 230, and the service provider 250 can respectively correspond to Figure 2 the user 200, the first terminal 210, the second terminal 220, the first profile server 230, and the service provider 250 in.
[0237] Refer to Figure 6 , in step 601, the user 200 may request the delivery of the first profile from the first terminal 210. To this end, the user 200 may confirm information about the first profile (profile metadata) and information that a user attempting to deliver the first profile should note through the first terminal 210. The information about the first profile and the information that a user attempting to deliver the first profile should note may already be stored in the first terminal 210 or the first profile. For example, the information about the first profile may include the name or logo of the service provider 250, the profile policy, etc. For example, the information that a user attempting to deliver the first profile should note may include the remaining number of profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc. In addition, the activation code required for the terminal to deliver the profile and the information indicating that the first profile needs to be deleted to deliver the first profile may already be stored in the first terminal 210 or the first profile. For example, the activation code required for the terminal to deliver the profile may be the activation code used to install the first profile in the first terminal in the past. Methods such as the first delete profile flag has not been set, the first reuse profile flag has been set, the first profile delete unnecessary (No Not Delete Profile) flag has not been set, or the new profile use flag has not been set can be used to represent the information indicating that the first profile needs to be deleted to deliver the profile.
[0238] In step 603, the first terminal 210 may call an activation code stored in the first terminal 210 or in the first profile and required for the terminal to deliver the first profile. The activation code may at least include the address of the profile server 230 storing the first profile and an event identifier (MatchingID) connected to the first profile. In this case, the status of the first profile stored in the profile server 230 may already be set to a state where download is not yet possible, so as to prevent the first profile from being copied.
[0239] In step 605, the first terminal 210 may disable and delete the first profile, and may notify the profile server 230 of the disablement result and the deletion result. The disablement result and the deletion result of the first profile may at least include the profile ID (ICCID) of the first profile. For example, step 605 may be performed using at least one of a disable profile message, a delete profile message, or a handle notification message. In addition, for the convenience of this figure, Figure 6 it is shown that the first terminal 210 notifies the profile server 230 of the disablement result and the deletion result. However, the disablement result and the deletion result may be passed to another profile server (for example, a second profile server 240 or a third profile server not shown in the figure). The disablement result and the deletion result may be passed separately. In addition, when the status of the first profile is already in a disabled state, the operation of disabling the first profile by the first terminal 210 in step 605 and the operation of the first terminal 210 notifying the profile server 230 of the disablement result may be omitted.
[0240] In step 607, the profile server 230 and the service provider 250 may check the delivery possibility of the first profile. If the first profile is deliverable to another terminal, the profile server 230 and the service provider 250 may prepare for the reuse of the first profile. For example, step 607 may be performed using at least one of a download command message, a confirmation command message, a remote management command (RPM command) message, a release command message, or a handle notification.
[0241] In step 609, the profile server 230 may identify that the first terminal 210 has deleted the first profile, and may set the status of the first profile to a downloadable state. In addition, the profile server 230 may notify the first terminal 210 that the status of the first profile is a downloadable state.
[0242] In step 611, the first terminal 210 may display the activation code on the screen by converting the activation code in the form of an image such as a QR code or in the form of a string, and may notify the user that the activation code has been prepared.
[0243] In step 613, user 200 may input the activation code displayed on the screen of the first terminal 210 into the second terminal 220. Various methods can be used to perform the method of inputting the activation code, such as capturing an image (such as a QR code) using a camera or inputting a string via a keyboard. Additionally, if the first terminal 210 and the second terminal 220 are connected via short-range communication (e.g., Bluetooth, NFC, WiFi, WiFi Direct, etc.), in step 413a, the first terminal 210 may directly pass the activation code to the second terminal 220 without displaying the activation code on the screen.
[0244] In step 615, the second terminal 220 may request to download the first profile from the profile server 230. For example, at least one of an initiation authentication message, a terminal authentication client message, or a delivery request message may be used to perform step 615. Step 615 may include a process of the second terminal 220 passing the event identifier (MatchingID) included in the activation code to the profile server 230. In step 615, the second terminal 220 may use WiFi for an Internet connection, or may use the Internet network sharing function provided by the first terminal 210.
[0245] In step 617, the profile server 230 may first identify whether the status of the first profile is a downloadable status. When the status of the first profile is a non-downloadable status because it has not been recognized through steps 605 to 609 that the first profile has been deleted from the first terminal, the profile server 230 may send an error code as a response and may terminate the operation. When the status of the first profile is a downloadable status, the profile server 230 may deliver information about the first profile (profile metadata) and information that the user downloading the first profile should note to the second terminal 220. For example, the information about the first profile may include the name or logo of the service provider 250, the profile policy, etc. For example, the information that the user downloading the first profile should note may include the remaining number of profile deliveries allowed by the service provider 250, the cost that the user will pay for the profile delivery, etc.
[0246] In step 619, user 200 may confirm the information about the first profile and the information that the user downloading the first profile should note, and may consent to profile installation. The operation of consenting to profile installation may include an operation of selecting "yes / no", inputting a password set by user 200, or inputting biometric information (such as the fingerprint or iris of user 200).
[0247] In step 621, the second terminal 220 may notify the profile server 230 that user 200 has consented to profile download and may request the profile package.
[0248] In step 623, the profile server 230 may deliver the profile package of the first profile to the second terminal 220.
[0249] In step 625, the second terminal 220 may install the first profile by using the profile package of the first profile.
[0250] Figure 7A is a flowchart showing an operation process of a first terminal according to an embodiment of the present disclosure.
[0251] Figure 7B is a flowchart showing an operation process of a second terminal according to an embodiment of the present disclosure.
[0252] Each terminal (the first terminal 210, the second terminal 220, and the terminal described without being assigned a reference numeral) described in the present disclosure may correspond to the first terminal described with reference to Figure 7A or the second terminal described with reference to Figure 7B Each of the first terminal 210 and the second terminal 220 may be an embodiment of the terminal in Figure 7A and Figure 7B The expressions "first" and "second" are only used to indicate that the terminals are physically different terminals.
[0253] With reference to Figure 7A , in step 701, the first terminal may start operating.
[0254] In step 703, the first terminal may receive a request for profile delivery from the user.
[0255] In step 705, the first terminal may identify information about profile delivery. The information about profile delivery may be information indicating whether an activation code necessary for receiving profile delivery from the server must be received or whether an activation code stored in the terminal must be used. If an activation code necessary for receiving profile delivery from the server must be received, the information about profile delivery may further include at least the address of the corresponding server. The first terminal may proceed to step 707. If an activation code stored in the terminal must be used, the information about profile delivery may further include information indicating whether the profile must be deleted first before using the activation code stored in the terminal. The first terminal may proceed to step 709.
[0256] In step 707, the first terminal may receive an activation code by requesting the activation code from the server. The message sent by the server as a response including the activation code may further include information indicating whether the profile must be deleted first before using the activation code.
[0257] In step 709, the first terminal may read the activation code stored in the terminal.
[0258] In step 711, the first terminal can identify whether it is necessary to delete the first profile. For the criteria used to identify whether it is necessary to delete the first profile, reference can be made to the information on profile delivery identified in step 705 and the instructions from the server received in step 707. If it is necessary to delete the first profile, the first terminal can proceed to step 713. If it is not necessary to delete the first profile, the first terminal can proceed to step 715.
[0259] In step 713, the first terminal can delete the first profile and can notify the server of the deletion result.
[0260] In step 715, the first terminal can transfer the activation code received from the server in step 707 or read in step 709 to the second terminal. The following methods can be used to perform the transfer of the activation code to the second terminal: the user takes a picture of the activation code displayed on the screen of the first terminal in the form of an image such as a QR code using the camera of the second terminal, the user inputs the activation code displayed as a string on the screen of the first terminal into the keyboard of the second terminal, or the first terminal and the second terminal are connected via short-range communication such as Bluetooth, NFC, WiFi, or WiFi Direct, and the activation code is transferred in the form of data. Step 715 can correspond to step 753.
[0261] In step 717, the first terminal can terminate the operation.
[0262] Reference Figure 7B , in step 751, the second terminal can start the operation.
[0263] In step 753, the second terminal can receive the activation code from the first terminal. For the method of receiving the activation code, refer to the description in step 715.
[0264] In step 755, the second terminal can request to download a profile from the profile server.
[0265] In step 757, the second terminal can receive a profile from the profile server.
[0266] In step 759, the second terminal can install the profile.
[0267] In step 761, the second terminal can terminate the operation.
[0268] Figure 8 is a flowchart showing the operation process of a profile server according to an embodiment of the present disclosure.
[0269] Each profile server (the first profile server 230, the second profile server 240, and the server described without being assigned a reference numeral) described in the present disclosure can correspond to the reference Figure 8The described profile server. Each of the first profile server 230 and the second profile server 240 can be Figure 8 an embodiment of the server in
[0270] Reference Figure 8 , in step 801, the profile server can start operating.
[0271] In step 803, the profile server can receive a request to deliver the first profile from the terminal. The request to deliver the first profile can include at least the first profile, i.e., the profile ID (ICCID) of the object to be delivered.
[0272] In step 805, the profile server can identify whether the first profile requested by the terminal to be delivered is a deliverable profile. For the method of identifying whether the first profile is a deliverable profile, the profile reuse policy of the operator can be referred to. When the first profile is a deliverable profile, the profile server can proceed to step 807. When the first profile is not a deliverable profile, the profile server can proceed to step 815.
[0273] In step 807, the profile server can prepare for the reuse of the first profile and can prepare the activation code necessary for downloading the first profile. In step 807, the status of the prepared first profile can be set to the non-downloadable state to prevent the copying of the profile. In step 807, the prepared activation code can include at least the address of the profile server and the event identifier (MatchingID) connected to the first profile.
[0274] In step 809, the profile server can send the activation code to the terminal as a response and can also notify the terminal that the first profile needs to be deleted.
[0275] In step 811, the profile server can wait for the terminal to provide a notification of the result of deleting the first profile. In step 811, when the profile server receives the result of deleting the first profile from the terminal, the profile server can proceed to step 813.
[0276] In step 813, the profile server can change the status of the first profile to the downloadable state.
[0277] In step 815, the profile server can prepare the second profile and can prepare the activation code necessary for downloading the second profile. In step 815, the status of the prepared second profile can be immediately set to the downloadable state. In step 815, the prepared activation code can include at least the address of the profile server and the event identifier (matching ID) connected to the second profile.
[0278] In step 817, the profile server may send an activation code to the terminal as a response.
[0279] In step 819, the profile server may receive a profile download request from the terminal. The profile download request may include at least an event identifier connected to the first profile or an event identifier connected to the second profile.
[0280] In step 821, the profile server may identify whether the status of the first profile or the second profile that the terminal has requested to download is a downloadable status. When the status of the first profile or the second profile that the terminal has requested to download is a downloadable status, the profile server may proceed to step 823. When the status of the first profile or the second profile that the terminal has requested to download is not a downloadable status, the profile server may proceed to step 825.
[0281] In step 823, the profile server may send a profile package to the terminal as a response.
[0282] In step 825, the profile server may send an error code indicating that the download of the profile is impossible to the terminal as a response.
[0283] In step 827, the profile server may terminate the operation.
[0284] Figure 9 is a block diagram showing components of a terminal according to an embodiment of the present disclosure.
[0285] Each terminal (the first terminal 210, the second terminal 220, and the terminal described without being assigned a reference numeral) described in the present disclosure may correspond to the first terminal described with reference to Figure 7A or the second terminal described with reference to Figure 7B Each of the first terminal 210 and the second terminal 220 may be an embodiment of the terminal in Figure 7A and Figure 7B The expressions "first" and "second" are only used to indicate that the terminals are physically different terminals.
[0286] As Figure 9 shown, the terminal may include a transceiver 910 and a processor 920. In addition, the terminal may include a UICC 930. For example, the UICC 930 may be inserted into the terminal or may be an eUICC embedded in the terminal.
[0287] The transceiver 910 may send signals, information, data, etc. to the profile server and receive signals, information, data, etc. from the profile server.
[0288] According to an embodiment of the present disclosure, the transceiver 910 may send a message requesting an activation code to the profile server, may receive the activation code and whether it is necessary to delete the profile from the profile server, and may send the result of deleting the profile to the profile server.
[0289] According to an embodiment of the present disclosure, the transceiver 910 may send a message requesting a profile to the profile server by using the activation code, and may receive a profile package.
[0290] The processor 920 is an element that generally controls the terminal. The processor 920 may control the overall operation of the terminal according to various embodiments of the present disclosure. The processor 920 may be named a controller. According to an embodiment of the present disclosure, the processor 920 may include at least one processor.
[0291] According to an embodiment of the present disclosure, the processor 920 may control the terminal to receive a profile delivery request from a user, confirm profile delivery information, send a message requesting an activation code to the profile server, receive the activation code and whether it is necessary to delete the profile from the profile server, delete the profile, send the result of deleting the profile to the profile server, and pass the activation code to another terminal.
[0292] According to an embodiment of the present disclosure, the processor 920 may control the terminal to receive an activation code from another terminal, send a message requesting a profile to the profile server by using the activation code, receive a profile package from the profile server, and install the profile package.
[0293] According to an embodiment of the present disclosure, the UICC 930 may download and install a profile. In addition, the UICC 930 may manage the profile.
[0294] The UICC 930 may operate under the control of the processor 920. Alternatively, the UICC 930 may include a processor or a controller for installing a profile, or an application may already be installed in the UICC 930. A part of the application may already be installed in the processor 920.
[0295] The terminal may further include a storage unit (not shown), and may store data such as a basic program, an application program, or setting information for the operation of the terminal. In addition, the storage unit may include at least one storage medium such as a flash memory type, a hard disk type, a multimedia card micro type, a card type memory (e.g., SD or XD memory), a magnetic memory, a magnetic disk, an optical disk, a random access memory (RAM), a static random access memory (SRAM), a read only memory (ROM), a programmable read only memory (PROM), or an electrically erasable programmable read only memory (EEPROM). In addition, the processor 920 may perform various operations by using various programs, contents, data, etc. stored in the storage unit.
[0296] Figure 10 It is a block diagram showing elements of a profile server according to an embodiment of the present disclosure.
[0297] Each profile server (the first profile server 230, the second profile server 240, and the server described without being assigned a reference numeral) described in the present disclosure may correspond to the profile server described with reference to Figure 8 Each of the first profile server 230 and the second profile server 240 may be an embodiment of the server in Figure 8 The expressions "first" and "second" are only used to indicate that the profile servers are physically different profile servers.
[0298] With reference to Figure 10 , the profile server may include a transceiver 1010 and a processor 1020.
[0299] The transceiver 1010 may send signals, information, data, etc. to a terminal or an operator, and receive signals, information, data, etc. from the terminal or the operator.
[0300] The transceiver 1010 according to an embodiment of the present disclosure may receive a profile delivery request message from a terminal, may send a message including an activation code and whether it is necessary to delete the profile to the terminal, may receive a profile deletion message from the terminal, may receive a profile download request message from the terminal, may send a profile package to the terminal when the status of the profile is a downloadable state, and may send an error code when the status of the profile is a non-downloadable state.
[0301] The processor 1020 is an element for generally controlling the profile server. According to various embodiments of the present disclosure, the processor 1020 may control the overall operation of the profile server. The processor 1020 may be named a controller. According to an embodiment of the present disclosure, the processor 1020 may include at least one processor.
[0302] The processor 1020 according to an embodiment of the present disclosure may control the profile server to receive a profile delivery request message from a terminal, identify whether the profile is deliverable, generate an activation code based on which the profile is downloadable, set the status of the profile to a non-downloadable state when the profile is deliverable, set the status of the profile to a downloadable state when the profile is not deliverable, send a message including the activation code and whether it is necessary to delete the profile to the terminal, receive the result of deleting the profile from the terminal, change the status of the profile to a downloadable state, receive a profile download request message from the terminal, determine whether the status of the profile is a downloadable state, send a profile package to the terminal when the status of the profile is a downloadable state, and send an error code when the status of the profile is a non-downloadable state.
[0303] The profile server may also include a storage unit (not shown) and may store data such as basic programs, application programs, or setting information for the operation of the profile server. In addition, the storage unit may include at least one storage medium among a flash type, a hard disk type, a multimedia card micro type, a card type memory (e.g., SD or XD memory), a magnetic memory, a magnetic disk, an optical disk, a random access memory (RAM), a static random access memory (SRAM), a read only memory (ROM), a programmable read only memory (PROM), or an electrically erasable programmable read only memory (EEPROM). In addition, the processor 1020 may perform various operations by using various programs, contents, data, etc. stored in the storage unit.
[0304] According to an embodiment of the present disclosure, in a wireless communication system, a terminal may receive a request from a user who attempts to install a profile for network connection installed in the terminal in another terminal. In addition, the terminal may request an activation code for downloading a profile from a profile server with reference to profile delivery information stored in the terminal, or may read an activation code stored in the terminal. In addition, the terminal may delete the profile, that is, an object to be delivered, in response to a request from the profile server or with reference to profile delivery information stored in the terminal. In addition, if necessary, the terminal may receive the activation code stored in the terminal from the profile server, or pass the activation code to another terminal through user input. In addition, the terminal may download a profile from the profile server by using the activation code.
[0305] According to an embodiment of the present disclosure, in a wireless communication system, a profile server may generate a profile for enabling a terminal to access a network and an activation code necessary for profile download. In addition, the profile server may identify whether delivery of the profile is possible in response to a profile delivery request received from the terminal, may send an activation code based on which the profile to be delivered can be downloaded and a profile deletion request to the terminal when delivery of the profile is possible, may send an activation code based on which a new profile can be downloaded to the terminal when delivery of the profile is not possible, may receive a deletion result of the profile to be delivered from the terminal, may change the status of the profile to a downloadable state, may receive a profile download request from the terminal, may identify whether the profile is downloadable, and may send the profile to the terminal when the profile is downloadable.
[0306] In the above detailed embodiments of the present disclosure, according to the proposed detailed embodiments, the components included in the present disclosure have been expressed in singular or plural forms. However, for ease of description, the singular or plural expressions have been appropriately selected for the proposed cases, and the present disclosure is not limited to singular or plural components. Although the components have been expressed in plural forms, they may be configured in singular forms. Although the components have been expressed in singular forms, they may be configured in plural forms.
[0307] Although detailed embodiments have been described in the detailed description of the present disclosure, the present disclosure can be modified in various ways without departing from the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the above embodiments, but should be defined not only by the claims, but also by their equivalents.
[0308] The various embodiments and terms used in the embodiments of the present disclosure are not intended to limit the technology described in the present disclosure to a specific embodiment, but should be interpreted to include various changes, equivalents, and / or alternatives of the corresponding embodiments. Regarding the description of the drawings, similar reference numerals may be used for similar elements. Unless otherwise clearly defined in the context, singular expressions may include plural expressions. In the present disclosure, expressions such as "A or B", "at least one of A and / or B", "A, B, or C", or "at least one of A, B, and / or C" may include all possible combinations of the listed items together. Expressions such as "first", "second", "first", or "second" may modify the corresponding elements regardless of their order or importance, and are only used to distinguish one element from another element without limiting the corresponding element. When describing that one (e.g., first) element is "(functionally or communicatively) connected to" another (e.g., second) element or "coupled" to another (e.g., second) element, one element may be directly connected to another element, or may be connected to another element through another element (e.g., a third element).
[0309] The term "module" used in the present disclosure includes a unit configured as hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integrated part, the smallest unit that executes one or more functions, or a part thereof. For example, a module may be configured as an application specific integrated circuit (ASIC).
[0310] The various embodiments of the present disclosure may be implemented as software (e.g., a program) including instructions stored in a machine (e.g., a computer) readable storage medium (e.g., an internal memory or an external memory). A device is a device that can call the stored instructions from the storage medium and can operate in response to the called instructions, and may include terminals (e.g., a first terminal 210, a second terminal 220) according to the various embodiments of the present disclosure. When the instructions are executed by a processor (e.g., the processor 920 in Figure 9 or the processor 1020 in Figure 10 ), the processor can directly or by using other elements under the control of the processor execute functions corresponding to the instructions. The instructions may include code generated or executed by a compiler or an interpreter.
[0311] A machine-readable storage medium may be provided in the form of a non-transitory storage medium. In this case, "non-transitory" only means that the storage medium does not include signals and is tangible, without distinguishing between cases where data is stored semi-permanently or temporarily in the storage medium.
[0312] The methods according to various embodiments disclosed in the present disclosure may be included in a computer program product and provided. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed online in the form of a device-readable storage medium (e.g., a compact disc read-only memory (CD-ROM)) or through an application store (e.g., PlayStore TM ). In the case of online distribution, at least some computer program products may be stored or generated temporarily at least in a storage medium, such as a memory in a manufacturer's server, an application store's server, or a relay server.
[0313] Each element (e.g., a module or a program) according to various embodiments may be composed of a single entity or multiple entities. In various embodiments, some of the above corresponding sub-elements may be omitted, or other sub-elements may be further included. Alternatively or additionally, some elements (e.g., a module or a program) may be integrated into a single entity. The single entity may perform the functions performed by each of the corresponding elements before the corresponding elements are integrated identically or similarly. The operations performed by a module, a program, or other elements according to various embodiments may be executed sequentially, in parallel, repeatedly, or heuristically, or at least some operations may be executed in a different order or may be omitted, or other operations may be added.
Claims
1. A method performed by a server in a wireless communication system, comprising: receiving, from a first terminal, a request message for delivering a first eUICC profile in the first terminal; identifying, based on the received request message for delivering the first eUICC profile, whether the first eUICC profile can be delivered from the first terminal to a second terminal; when the first eUICC profile can be delivered from the first terminal to the second terminal, sending to the first terminal an activation code of the first eUICC profile and a notification for deleting the first eUICC profile; and when the first eUICC profile cannot be delivered from the first terminal to the second terminal, sending to the first terminal an activation code of a second eUICC profile.
2. The method according to claim 1, further comprising: receiving, from a service provider, a message for setting a policy related to the request message for delivering the first eUICC profile in the first terminal, wherein further identifying whether the first eUICC profile can be delivered from the first terminal to the second terminal is performed based on the policy.
3. The method according to claim 1, further comprising: sending to the service provider information indicating that a request message for delivering the first eUICC profile has been received from the first terminal; receiving, from the service provider, a first message, the first message including information to be noted by the user determined based on a delivery policy of the first eUICC profile; and sending the first message to the first terminal.
4. The method according to claim 3, further comprising: receiving, from the user, a second message, the second message including information on whether delivery of the first eUICC profile is permitted based on the first message; sending to the service provider a third message, the third message including information on whether delivery of the first eUICC profile is permitted based on the second message; and receiving a fourth message related to the second eUICC profile.
5. The method according to claim 1, further comprising: receiving, from the second terminal, a request for downloading a second eUICC profile; sending to the second terminal a fifth message, the fifth message including information on the second eUICC profile and information to be noted by the user; receiving, from the second terminal, a request for information on whether downloading of the second eUICC profile and an eUICC profile package is permitted based on the fifth message; and sending the eUICC profile package to the second terminal.
6. A method performed by a first terminal in a wireless communication system, comprising: receiving, from the user, a request for delivering a first eUICC profile in the first terminal; sending, based on the request, a request message for delivering the first eUICC profile in the first terminal to the server; when the first eUICC profile can be delivered from the first terminal to the second terminal, receiving from the server an activation code of the first eUICC profile and a notification for deleting the first eUICC profile; and when the first eUICC profile cannot be delivered from the first terminal to the second terminal, receiving from the server an activation code of the second eUICC profile, Among them, the activation code of the first eUICC profile or the second eUICC profile is determined based on the server and the service provider.
7. The method according to claim 6, further comprising: sending an activation code of the first eUICC profile or the second eUICC profile to a second terminal, wherein the activation code is marked as a QR code.
8. The method according to claim 6, further comprising: deleting the first eUICC profile; and sending the result of the deletion to the server.
9. A server, comprising: a transceiver capable of sending and receiving at least one signal; and a controller coupled to the transceiver, wherein the controller is configured to: receive, from a first terminal, a request message for delivering a first eUICC profile in the first terminal; identify, based on the received request message for delivering the first eUICC profile, whether the first eUICC profile can be delivered from the first terminal to a second terminal; in a case where the first eUICC profile can be delivered from the first terminal to the second terminal, send an activation code of the first eUICC profile and a notification for deleting the first eUICC profile to the first terminal; and in a case where the first eUICC profile cannot be delivered from the first terminal to the second terminal, send an activation code of the second eUICC profile to the first terminal.
10. The server according to claim 9, wherein the controller is further configured to receive, from a service provider, a message for setting a policy related to the request message for delivering the first eUICC profile in the first terminal, and further execute, based on the policy, identifying whether the first eUICC profile can be delivered from the first terminal to the second terminal.
11. The server according to claim 9, wherein the controller is further configured to: send information indicating that a request message for delivering the first eUICC profile has been received from the first terminal to the service provider; receive a first message from the service provider, the first message including information identified based on the delivery policy of the first eUICC profile and requiring user attention; and send the first message to the first terminal.
12. The server according to claim 11, wherein the controller is further configured to: receive a second message from the user, the second message including information on whether to permit delivering the first eUICC profile determined based on the first message; send a third message to the service provider, the third message including information on whether to permit delivering the first eUICC profile based on the second message; and receive a fourth message related to the second eUICC profile.
13. The server according to claim 9, wherein the controller is further configured to: receive a request for downloading a second eUICC profile from the second terminal; send a fifth message to the second terminal, the fifth message including information on the second eUICC profile and information requiring user attention; receive, from the second terminal, a request for information on whether to permit downloading the second eUICC profile and the eUICC profile package based on the fifth message; and send the eUICC profile package to the second terminal.
14. A first terminal, comprising: A transceiver capable of transmitting and receiving at least one signal; and a controller coupled to the transceiver, wherein the controller is configured to: Receive a request from a user for delivering a first eUICC profile in a first terminal; Send a request message for delivering the first eUICC profile in the first terminal to a server based on the request; Receive an activation code for the first eUICC profile and a notification for deleting the first eUICC profile from the server when the first eUICC profile can be delivered from the first terminal to a second terminal; and Receive an activation code for a second eUICC profile from the server when the first eUICC profile cannot be delivered from the first terminal to the second terminal, wherein the activation code for the first eUICC profile or the second eUICC profile is determined based on the server and the service provider.
15. The first terminal according to claim 14, wherein the controller is further configured to: Send the activation code for the first eUICC profile or the second eUICC profile to the second terminal; Delete the first eUICC profile; and Send the result of the deletion to the server, wherein the activation code is marked as a QR code.
Citation Information
Patent Citations
Method for transferring profile and electronic device supporting the same
US20160241537A1
Profile download method and device
WO2018076711A1