A method for managing at least one EUICC Information Set (EIS) of an EUICC and an intermediate buffer proxy.
Patent Information
- Application Number
- JP2024515044
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-10-26
- Filing Date
- 2022-10-06
- Publication Date
- 2026-09-30
- Estimated Expiration
- 2042-10-06
AI Technical Summary
【0031】 図面の簡単な説明 本発明の更なる実施形態及び本発明の利点について、本発明の実施形態の例を単に説明する図面を参照してより詳細に説明する。図面における同じ構成要素に、同じ参照符号を与える。図面は、原寸に正確に比例していると見なされず、特に、図面の個々の要素を、誇張して大きい形又は誇張して単純化した形で示してもよい。
Smart Images

Figure 0007927059000001 
Figure 0007927059000002 
Figure 0007927059000003
Abstract
Description
[Technical Field]
[0001] Technical field of the invention The present invention relates to a method for managing at least one eUICC information set (EIS) in an eUICC, and to an intermediate buffer proxy.
[0002] The use of embedded universal integrated circuit cards (eUICC), also called embedded subscriber identity modules (eSIM), is becoming increasingly popular in the field of consumer and machine-to-machine (M2M) communications. Unlike conventional UICCs or SIMs which exist as removable smart cards transportable between multiple devices, an eUICC is an integrated circuit that is not designed to be removable by a user, that is, it is generally embedded or soldered to other electronic components of a device. An eUICC is generally issued by a manufacturer (EUM), which is often referred to as an original equipment manufacturer (OEM). [Background Art]
[0003] Technical background Conventionally, in order for a telecommunication device to connect to a specific mobile network, it is necessary to insert a SIM card issued by a mobile network operator (MNO) into the device. In this method, to switch a mobile connection to a different MNO, the SIM card for the current MNO is removed from the device and replaced with another SIM card associated with the new MNO. Whenever a connection to a different mobile network is required, the requirement to replace the SIM card is a major drawback, especially in the context of M2M communication. When manufacturing a device, it is very efficient and desirable to install a single SIM card that can then support connection to a user-selected MNO.
[0004] To address this issue, the Global Systems for Mobile Association (GSMA) defines a remote provisioning architecture for embedded SIMs as a guideline for mobile operators. eSIMs, embedded in IoT devices, provide a secure interoperability architecture and facilitate the commercial deployment of systems that enable the remote provisioning of target MNO profiles to eSIMs. The GSMA specifies methods and protocols for MNOs to set up profile information for eSIMs using radio communication channels. This method is called over-the-air (OTA) provisioning. OTA provisioning of entirely new SIM profiles can be used for devices navigating within an operator network.
[0005] In the GSMA SGP.01 document, "Embedded SIM Remote Provisioning Architecture," version 4.0, dated February 23, 2019, the GSMA provides an architectural methodology for provisioning and enrollment management of M2M devices. The document includes a description of eUICC registration in the SM-SR. To achieve this, the eUICC manufacturer submits a registration request to the SM-SR, and after performing the registration, the SM-SR returns a registration confirmation.
[0006] eSIM supports numerous subscriber profiles. These profiles can be added, enabled, disabled, and deleted as needed. The GSMA has standardized an OTA architecture for eSIM profile deployment and switching. Profile deployment and switching comply with the Global Platform Card Standard (v2.2.1) cited herein by reference. The Subscriber Administrator Data Preparation (SM-DP) function is used to create SIM profiles, while the Subscriber Administrator Secure Routing (SM-SR) function is used to communicate with the eUICC to deploy, enable, disable, and delete profiles. Certificate Issuers (CIs) are used for authentication and integrity protection.
[0007] One or more eSIM profiles are set up in the eUICC, each eSIM profile containing a unique International Mobile Subscriber Identification (IMSI) number that authenticates the subscriber to the wireless network operator. Other data stored in the eSIM profile may include operator network information, security authentication information, a list of accessible network services, and / or others. The wireless network operator may transfer the eSIM profile to the user device's eUICC in the form of a consumer device or M2M device via over-the-air (OTA) updates.
[0008] Consumer devices are network-enabled devices that are generally sold to individual consumers. For example, these devices may include smartphones, tablet computers, smartwatches, game consoles, and / or others. M2M devices are network machines that use telecommunications services provided by wireless communication line operators to communicate with other network machines. For example, an M2M monitoring device embedded in a vehicle may automatically transmit vehicle tracking and driving information to a remote assistance device at a management center. In another example, an M2M device in the form of a smart home appliance may automatically transmit diagnostic information to a monitoring device at a service center in the event of a device failure.
[0009] Furthermore, an eUICC may include an eUICC Information Set (EIS). The eUICC Information Set (EIS) represents the eUICC and may include an eUICC identifier, an identifier of the eUICC manufacturer, and further information (e.g., a list of profiles associated with the eUICC). A description and application of the eUICC Information Set (EIS) can be found in the GSMA SGP.02 standard, "Remote Provisioning Architecture for Embedded UICC," version 4.0, February 25, 2019.
[0010] To enable subscription management procedures, eUICC is registered in the Subscriber Administrator Safe Route Designation (SM-SR) database. Registration is performed using EIS. The procedure is defined in the SGP.01 standard.
[0011] For several OEMs, EUMs, or service providers (SPs), it is necessary to determine under what conditions and / or at what time to load the eUICC Information Set (EIS) into the Subscriber Administrator Secure Routing (SM-SR) function. For example, the conditions for loading the eUICC Information Set (EIS) into the Subscriber Administrator Secure Routing (SM-SR) function could be the registered and valid subscription of the eUICC in the Home Position Register (HLR), or the MNO's knowledge of incorporating the eUICC into the device being powered on. Furthermore, the MNO may need to control numerous EUM providers and determine which eUICC Information Sets (EIS) to load into the Subscriber Administrator Secure Routing (SM-SR) function, from whom to load the eUICC Information Sets (EIS) into the Subscriber Administrator Secure Routing (SM-SR) function, and when to load the eUICC Information Sets (EIS) into the Subscriber Administrator Secure Routing (SM-SR) function. Furthermore, it may be necessary to outsource the creation of the ES1 interface between EUM and SM-SR, as defined in the current GSMA SGP.02 standard, to a third-party integration provider. The ES1 interface functions as an interface between two entities that perform the functions of EUM and SM-SR.
[0012] The EIS is loaded using a request-response function as described in the SGP.02 standard. The EUM, acting as the requester, receives and processes the request and finally sends the request message to the SM-SR, which returns a message accordingly. The request function is identified based on the Function Requester Identifier (FRI) and the Function Call Identifier (FCI). For request-response functions, a validity period may be set.
[0013] However, because all communication between the EUM or OEM and the SM-SR function must be synchronized, the current GSMA SGP.02 standard does not allow for the outsourcing of the ES1 interface. Furthermore, the GSMA SGP.02 standard cannot provide any components that would delay the loading of the Subscriber Administrator Secure Routing (SM-SR) function.
[0014] To partially satisfy the aforementioned needs of the OEM, EUM, or SP, the use of a transparent proxy is known from prior art. A transparent proxy intercepts standard application layer communications without requiring any special client configuration. A transparent proxy is a proxy that does not modify requests or responses beyond what is necessary for proxy authentication and identification. The client does not need to be aware of the proxy's presence. A transparent proxy can be placed between the EUM or OEM and the SM-SR function. Although such a transparent proxy can function as a broker between the EUM or OEM and the SM-SR function, it cannot delay the loading of the Subscriber Administrator Secure Routing (SM-SR) function.
[0015] Alternatively, it is known from prior art that a stop-and-go proxy may be implemented to partially meet the aforementioned needs of the OEM, EUM, or SP. While a stop-and-go proxy between the EUM or OEM and the SM-SR function can delay the loading to the Subscriber Administrator Secure Routing (SM-SR) function, it compromises the integrity of the chain between the EUM or OEM and the SM-SR function and poses a risk when duplicating data in the SM-SR function or the EUM or OEM.
[0016] International Publication No. 2020 / 071975A1 discloses a system for registering the eUICC of an autonomous vehicle with legal parties. The system connects the eUICC manufacturer to the autonomous vehicle manufacturer, who is connected to a specialized SM-SR device. The eUICC manufacturer provides the eUICC to the vehicle manufacturer, who then transfers the eUICC to the specialized SM-SR for provisioning. After registering ownership with the legal parties, the specialized SM-SR sends a message to the eUICC manufacturer indicating the change in the status of the eUICC.
[0017] U.S. Patent Application Publication 2019 / 0159016A1 discloses a system for deploying eSIMs, including a subscriber administrator proxy positioned as an intermediate gateway between the target MNO's SM-DP and the current MNO's SM-SR. The subscriber administrator proxy enables the creation, downloading, activation, and deactivation of target MNO profiles for existing subscriptions. [Overview of the Initiative] [Problems that the invention aims to solve]
[0018] Summary of the Invention The problem to be solved by the present invention is to provide the possibility of delaying the loading to the SM-SR function without jeopardizing the integrity of the chain between the EUM or OEM and the SM-SR function.
[0019] The problem is solved by the method for managing at least one eUICC information set (EIS) of eUICC according to claim 1, and by the intermediate buffer proxy according to claim 6. Furthermore, preferred embodiments of the present invention are objects of the dependent claims.
[0020] A method for managing at least one eUICC information set (EIS) of an eUICC according to the present invention is: - A step of generating a first request for registering an eUICC information set (EIS) with an eUICC manufacturer (EUM), wherein the first request includes a first function call identifier (FCI), - transmitting a first request from an eUICC manufacturer (EUM) to an intermediate buffer proxy, - generating a response to the first request within the intermediate buffer proxy, and - transmitting the response to the request to the eUICC manufacturer (EUM), comprising the above steps.
[0021] According to an aspect of the present invention, the method comprises: - after receiving a response to a request to the eUICC manufacturer (EUM) at the eUICC manufacturer (EUM), generating a registration result response within the eUICC manufacturer (EUM), and - transmitting the registration result response to a mobile network operator (MNO), further comprising the above steps.
[0022] According to a further aspect of the present invention, the method comprises: - generating, at the intermediate buffer proxy, a second request for registering an eUICC information set (EIS) based on the first request received at the intermediate buffer proxy, wherein the second request comprises a second functional call identifier (FCI), and - transmitting the second request from the intermediate buffer proxy to a Subscription Manager-Secure Routing (SM-SR) function, further comprising the above steps.
[0023] According to a further aspect of the present invention, the method comprises: - receiving the second request from the intermediate buffer proxy at the Subscription Manager-Secure Routing (SM-SR) function, and - confirming, by the Subscription Manager-Secure Routing (SM-SR) function, that the eUICC information set (EIS) exists in an eUICC information set (EIS) directory stored in the Subscription Manager-Secure Routing (SM-SR) function, further comprising the above steps.
[0024] According to a further aspect of the present invention, the method comprises: - A step of storing the eUICC information set (EIS) in the database of valid eUICC information sets (EIS) present in the Subscriber Administrator Safe Route Designation (SM-SR) function, - The step of generating a response to the second request using the Subscriber Administrator Secure Route Designation (SM-SR) function, - The step of sending the response from the Subscriber Administrator Secure Routing (SM-SR) function to the second request to the intermediate buffer proxy. It also includes.
[0025] Furthermore, the present invention relates to an intermediate buffer proxy configured to receive a first request from an eUICC manufacturer (EUM) for registering an eUICC information set (EIS), wherein the first request includes a first function call identifier (FCI), generate a response to the first request, and send the response to the request to the eUICC manufacturer (EUM).
[0026] According to an aspect of the present invention, the intermediate buffer proxy is further configured to generate a second request to register an eUICC information set (EIS) and to transmit the second request to the Subscriber Administrator Secure Routing (SM-SR) function.
[0027] According to a further aspect of the present invention, the intermediate buffer proxy is further configured to receive a response to a second request from the Subscriber Administrator Secure Routing (SM-SR) function.
[0028] According to a further aspect of the present invention, the intermediate buffer proxy further includes a unique object identifier (OID).
[0029] According to a further aspect of the present invention, the intermediate buffer proxy further includes a function requester identifier (FRI).
[0030] The method and intermediate buffer proxy give the possibility of delaying the loading to the SM-SR function without compromising the integrity of the chain between the EUM or OEM and the SM-SR function.
[0031] Brief explanation of the drawing Further embodiments of the present invention and the advantages of the present invention will be described in more detail with reference to drawings that merely illustrate examples of embodiments of the present invention. The same reference numerals are given to the same components in the drawings. The drawings are not considered to be exactly proportional to the actual size, and in particular, individual elements of the drawings may be shown in an exaggeratedly large or exaggeratedly simplified form. [Brief explanation of the drawing]
[0032] [Figure 1] Examples of methods known from prior art using transparent proxies are shown. [Figure 2] Examples of methods known from prior art using stop-and-go proxies are shown. [Figure 3] An example of a preferred embodiment of the method using an intermediate buffer proxy is shown. [Figure 4] An example of a mobile communication network including an intermediate buffer proxy according to a preferred embodiment is shown. [Modes for carrying out the invention]
[0033] Detailed description of preferred embodiments This application relates to a method for managing at least one eUICC information set (EIS) of an eUICC, and an intermediate buffer proxy 20. eUICCs are generally issued by manufacturers (EUMs), often referred to as original equipment manufacturers (OEMs).
[0034] Traditionally, telecommunications devices require a SIM card issued by a mobile network operator (MNO) to be inserted into the device in order to connect to a specific mobile network. In this system, switching mobile connectivity to a different MNO requires removing the current MNO's SIM card from the device and replacing it with a different SIM card associated with the new MNO. The requirement to swap SIM cards whenever a connection to a different mobile network is needed is a significant drawback, especially in M2M communication scenarios. It would be highly efficient and desirable to manufacture devices with a single SIM card pre-installed, which could then support the user's choice of MNOs.
[0035] To address this issue, the Global Systems for Mobile Association (GSMA) defines a remote provisioning architecture for embedded SIMs as a guideline for mobile operators. eSIMs, embedded in IoT devices, provide a secure interoperability architecture and facilitate the commercial deployment of systems that enable the remote provisioning of target MNO profiles to eSIMs. The GSMA specifies methods and protocols for MNOs to set up profile information for eSIMs using radio communication channels. This method is called over-the-air (OTA) provisioning. OTA provisioning of entirely new SIM profiles can be used for devices navigating within an operator network.
[0036] eSIM supports numerous subscriber profiles. These profiles can be added, enabled, disabled, and deleted as needed. The GSMA has standardized an OTA architecture for eSIM profile deployment and switching. Profile deployment and switching comply with the Global Platform Card Standard (v2.2.1) cited herein by reference. The Subscriber Administrator Data Preparation (SM-DP) function is used to create SIM profiles, while the Subscriber Administrator Secure Routing (SM-SR) function is used to communicate with the eUICC to deploy, enable, disable, and delete profiles. Certificate Issuers (CIs) are used for authentication and integrity protection.
[0037] One or more eSIM profiles may be set up in the eUICC, each eSIM profile containing a unique International Mobile Subscriber Identification (IMSI) number that authenticates the subscriber to the wireless network operator. Other data stored in the eSIM profile may include operator network information, security authentication information, a list of accessible network services, and / or others. The wireless network operator may transfer the eSIM profile to the user device's eUICC in the form of a consumer device or M2M device via over-the-air (OTA) updates.
[0038] Furthermore, an eUICC may include an eUICC Information Set (EIS). The eUICC Information Set (EIS) represents an eUICC and may include an eUICC identifier, an identifier of the eUICC manufacturer, and further information (e.g., a list of profiles associated with the eUICC). The eUICC Information Set (EIS) is defined in the SGP.02 standard.
[0039] For example, the eUICC may have a file system as described in 3GPP TS 11.11 or 3GPP TS 11.14. In the sense of the present invention, the eUICC can be a reduced-size and resource-efficient electronic module having, for example, a control unit (microcontroller) and at least one interface (data interface) for communication with a device. Preferably, this communication is performed via a connection protocol, particularly a protocol conforming to ETSI TS 102 221 or ISO-7816 standards.
[0040] eUICCs can be integrated components within a device, such as hardwired electronic components. These eUICCs are not intended to be removed from the device and, in principle, cannot be easily replaced. Furthermore, such eUICCs can be designed as built-in safety elements and are safe hardware components within the device.
[0041] eUICC can be used for remote monitoring, control, and maintenance of equipment (machinery, plants, and systems). eUICC can also be used for metering units (e.g., electricity meters, water heaters, etc.). For example, eUICC is part of IoT technology.
[0042] In the sense of the present invention, a device is, in principle, a device or device component having means for communicating with a communication network so that it can use the services of the communication network or use the services of a server via a gateway to the communication network. For example, mobile devices (e.g., smartphones, tablet computers, laptop computers, personal digital assistants) may be included under the term. Multimedia devices (e.g., digital image frames, audio devices, televisions, e-book readers) that further have means for communicating with a communication network may also be understood as devices.
[0043] The device can be installed in machines, vending machines, and / or vehicles. When the device is installed in a vehicle, the device typically has an integrated eUICC. The eUICC establishes data connectivity to a server via a communication network through the device, for example, by the device's modem. For example, the device can be used to communicate with a device manufacturer's (EUM) server to handle a control unit, such as an ECU (Electronic Control Unit), for the device's functions. The eUICC can be used to communicate with a server in the background system of a mobile network operator (MNO), for example, a server that loads updates for the eUICC's software, firmware, and / or operating system into the eUICC.
[0044] For example, to use a server or another server's services, or to exchange data, you might set up an eUICC and establish a data connection to a server on a communication network. Establishing such a data connection from an eUICC to a server requires connection parameters (e.g., a unique server address and the data connection protocol to be used). For example, to establish, terminate, and operate a data connection, you might use a card application toolkit (CAT) of subscriber identification modules compliant with ETSI standard TS 102 223.
[0045] A communication network is a technical facility in which the transmission of signals is carried out for the identification and / or authentication of subscribers. A communication network provides specific services (specific voice and data services) and / or enables the use of services from external entities. Preferably, the communication network is a mobile network, which enables communication between devices under the supervision of the communication network. In particular, here the mobile communication network is, for example, a "Global System for Mobile Communications" (GSM) or "General-Purpose Packet Radio Service" (GPRS) as a second-generation example, a "Universal Mobile Telecommunications System" (UMTS) as a third-generation example, a "Long-Term Evolution" (LTE) as a fourth-generation example as a mobile communication network, or a fifth-generation mobile communication network with the currently working name "5G" as a communication network. Communication in the communication network can be carried out via a secure channel (e.g., SCP80, SCP81, or Transport Layer Security TLS) as defined, for example, in the technical standards ETSI TS 102 225 and / or ETSI TS 102 226.
[0046] In the sense of the present invention, a server is an entity spatially separated from the device. A server may be part of a communication network. Alternatively, or further, a server is an external instance (i.e., not an instance of a communication network). Preferably, the server is a device manufacturer's server for handling control units, e.g., electronic control units (ECUs), for the functions of the device. Alternatively, or further, the server is a server for remote management of the eUICC, e.g., a so-called OTA server that loads updates for the eUICC's software, firmware, and / or operating system into the eUICC.
[0047] For example, subscriber identification data stored in the non-volatile memory area of eUICC is data that uniquely identifies a subscriber (person or device) on a communication network. This data includes, for example, a subscriber identifier also known as an International Mobile Subscriber Identifier or IMSI and / or subscriber identification data. An IMSI is a unique subscriber identification file on a mobile communication network. An IMSI consists of a country code MCC (Mobile Country Code), a network code MNC (Mobile Network Code), and a serial number assigned by the network operator. Furthermore, subscriber identification data may include, for example, data that uniquely authenticates a subscriber to the communication network (e.g., authentication algorithm, specific algorithm parameters, cryptographic authentication key Ki, and / or cryptographic radio or OTA key). Furthermore, subscriber identification data may include, for example, data that uniquely authenticates a subscriber to a service (e.g., a unique identifier or signature). The service is, in particular, a voice service or data service of a server that transmits information and / or data over a communication network.
[0048] eUICC may be operationally integrated into the device. Communication between UICC and the device is based on a connection protocol. Furthermore, the device can also be set up to independently establish a data connection to a remote server in order to exchange data with that server, using the services of a remote server.
[0049] Profile management can be performed via OTA communication between servers in the communication network (e.g., subscriber servers compliant with GSMA standard SGP.02, or data provisioning servers SM-DP, SM-DP+), for example, using SMS, CAT_TP, or HTTPS for wireless OTA communication with eUICC. This profile management, which is not part of this specification, includes "create," "load," "enable," "unavailable," "delete," and "update." For further details, refer to the GSMA standard described.
[0050] It is necessary to determine under what conditions and / or at what time the eUICC Information Set (EIS) will be loaded into the Subscriber Administrator Secure Routing (SM-SR) function for several OEMs, EUMs, or service providers (SPs). For example, the conditions for loading the eUICC Information Set (EIS) into the Subscriber Administrator Secure Routing (SM-SR) function may be the registration and active subscription of the eUICC in the Home Location Register (HLR), or the MNO's knowledge of incorporating the eUICC into the device that is about to be powered on. Furthermore, the MNO may need to control numerous EUM providers and determine which eUICC Information Set (EIS) to load into the Subscriber Administrator Secure Routing (SM-SR) function, from whom to load the eUICC Information Set (EIS) into the Subscriber Administrator Secure Routing (SM-SR) function, and when to load the eUICC Information Set (EIS) into the Subscriber Administrator Secure Routing (SM-SR) function. In addition, it may be necessary to outsource the ES1 interface, as defined in the current GSMA SGP.02 standard, to a third-party integration provider. The ES1 interface functions as an interface between two entities that perform the roles of EUM and SM-SR functions.
[0051] However, the current GSMA SGP.02 standard does not allow for this possibility, as all communication between the EUM or OEM and the SM-SR function must be synchronized. Furthermore, the GSMA SGP.02 standard cannot provide any components that would delay the loading of the Subscriber Administrator Secure Routing (SM-SR) function.
[0052] To partially satisfy the aforementioned needs of OEMs, EUMs, or SPs, the use of a transparent proxy is known from the prior art. A known method from the prior art using such a transparent proxy is shown in Figure 1. The transparent proxy intercepts standard application layer communications without requiring any special client configuration. The transparent proxy is a proxy that does not modify requests or responses beyond what is necessary for proxy authentication and identification. The client does not need to be aware of the proxy's presence. The transparent proxy can be placed between the EUM or OEM and the SM-SR function.
[0053] Such a transparent proxy can be a single point of provisioning for EIS data, enabling MNO data, whose destination is an SM-SR function, to be generated by the EUM or OEM and seamlessly passed to the SM-SR function via the BSS of the mobile communications network in a secure and standardized manner. When using a transparent proxy between the EUM or OEM and the SM-SR function, the transparent proxy must use the same Function Requester Identifier (FRI) and Function Call Identifier (FCI) as the EUM or OEM. Optionally, a request validity period can be set.
[0054] The transparent proxy receives all parameters used by the EUM or OEM in the request and passes them to the SM-SR function without modification. The EUM or OEM and the transparent proxy use the ES1 interface as defined by the GSMA SGP.02 standard. The request can be an "ES1.RegiseterEISRequest" as defined by the GSMA SGP.02 standard.
[0055] While such transparent proxies can function as brokers between the EUM or OEM and the SM-SR function, they cannot delay the loading of the Subscriber Administrator Secure Routing (SM-SR) function.
[0056] Alternatively, it is known from the prior art that a stop-and-go proxy may be used to partially meet the aforementioned needs of the OEM, EUM, or SP. A method known from the prior art using such a stop-and-go proxy is shown in Figure 2.
[0057] This method allows different FCIs to be used by the proxy and the EUM or OEM. However, this can break trust in the chain from the EUM or OEM to the SM-SR function. Furthermore, the expiration of the request validity period may cause unknown behavior with respect to the EUM or OEM, the proxy, and / or the SM-SR function. For example, if the retry mechanism starts to activate, an endless loop may occur for a single EIS that may or may not be registered. With this method, if the request "RegisterEIS" is successful, it cannot be notified back to the MNO from the EUM or OEM. Any stop-and-go change on the proxy side or the EUM or OEM side will affect all MNO and all SM-SR functions supported by the EUM or OEM.
[0058] A stop-and-go proxy between the EUM or OEM and the SM-SR function can delay the loading to the Subscriber Administrator Secure Routing (SM-SR) function, but it compromises the integrity of the chain between the EUM or OEM and the SM-SR function and poses a risk when duplicating data in the SM-SR function or the EUM or OEM.
[0059] Figure 3 shows an example of a method according to a preferred embodiment using an intermediate buffer proxy, and Figure 4 shows an example of a mobile communication network including an intermediate buffer proxy according to a preferred embodiment.
[0060] According to this embodiment, a method for managing at least one eUICC information set (EIS) of eUICC is: - Step 110 of generating a first request for registering an eUICC Information Set (EIS) with an eUICC Manufacturer (EUM), wherein the first request includes a first Function Call Identifier (FCI), - Step 120 involves sending a first request from the eUICC manufacturer (EUM) to the intermediate buffer proxy 20, - Step 130 generates a response to the first request within the intermediate buffer proxy (20), - Step 140 to send a response to the request to the eUICC manufacturer (EUM) and Includes.
[0061] The intermediate buffer proxy according to this application is configured to receive a first request from an eUICC manufacturer (EUM), generate a response to the first request, and send the response to the request to the eUICC manufacturer (EUM).
[0062] The method and intermediate buffer proxy 20 according to this embodiment provide the possibility of delaying the loading to the SM-SR function without compromising the integrity of the chain between the EUM or OEM and the SM-SR function.
[0063] In other words, the intermediate buffer proxy 20 simulates the response of the SM-SR function to the EUM or OEM, or responds with a false response to avoid invalidating the request after the request's validity period has ended. Thus, the intermediate buffer proxy 20 functions as an SM-SR to the EUM or OEM.
[0064] The term MNO can be used synonymously with MNO servers that communicate over a mobile network. The term EUM can be used synonymously with EUM servers that communicate over a mobile network. The term SM-SR function can be used synonymously with SM-SR servers that perform SM-SR functions and communicate over a mobile network.
[0065] Before generating (110) and sending (120) the first request, the EUM or OEM may receive input data from the MNO. When sending (120) the first request to the intermediate buffer proxy 20, the EUM may simultaneously send a response file for HLR registration to the MNO. After receiving a response to the request at the EUM, the EUM may send an "ES1 registration result response" to the MNO.
[0066] The intermediate buffer proxy 20 may need to generate a new FCI for communication with the SM-SR function, especially if the FCI originating from the EUM or OEM has been terminated. Data validation can be performed by the intermediate buffer proxy 20 until the request is validated by the SM-SR.
[0067] The intermediate buffer proxy 20 may be identified by a unique object identifier (OID) and may include a unique FRI.
[0068] EIS data operations can be performed on the intermediate buffer proxy 20 instead of, for example, on the EUM or OEM.
[0069] The correlation between the FCI from the EUM or OEM and the FCI used by the intermediate buffer proxy 20 can be tracked by the intermediate buffer proxy 20. This ensures the integrity of end-to-end communication between the EUM or OEM and the intermediate buffer proxy 20.
[0070] The method is, - Step 150: After the eUICC Manufacturer (EUM) receives a response to a request to the eUICC Manufacturer (EUM), the eUICC Manufacturer (EUM) generates a registration result response within the eUICC Manufacturer (EUM), - Step 160 to send the registration result response to the mobile network operator (MNO) and It may also include the following.
[0071] Preferably, the method is - Step 170 of generating a second request in the intermediate buffer proxy 20 to register an eUICC information set (EIS) based on a first request received in the intermediate buffer proxy, wherein the second request includes a second function call identifier (FCI), and - Step 180 sends the second request from the intermediate buffer proxy 20 to the Subscriber Administrator Secure Routing (SM-SR) function. It may also include the following.
[0072] The intermediate buffer proxy 20 may be further configured to generate a second request to register an eUICC information set (EIS) and to send the second request to the Subscriber Administrator Secure Route Designation (SM-SR) function.
[0073] Furthermore, the method is, - Step 190, receiving a second request from the intermediate buffer proxy 20 using the subscriber administrator secure route designation SM-SR function, - Step 200 confirms that the eUICC information set (EIS) exists in the eUICC information set (EIS) directory stored in the subscriber administrator secure route designation (SM-SR) function, and It may also include the following.
[0074] Furthermore, the method is, - Step 210 involves storing the eUICC information set (EIS) in the database of valid eUICC information sets (EIS) present in the Subscriber Administrator Safe Route Designation (SM-SR) function, - Step 220 generates a response to the second request using the Subscriber Administrator Safe Route Designation (SM-SR) function, - Step 230 sends the response from the Subscriber Administrator Secure Routing (SM-SR) function to the Intermediate Buffer Proxy 20 to the second request. It may also include the following.
[0075] The intermediate buffer proxy 20 may be further configured to receive responses to the second request from the Subscriber Administrator Secure Routing (SM-SR) function.
[0076] The intermediate buffer proxy 20 may further include a unique object identifier (OID) and / or a unique function requester identifier (FRI).
[0077] In other words, the intermediate buffer proxy 20 acts as an SM-SR function with respect to the EUM and acts as an EUM with respect to the SM-SR function. The intermediate buffer proxy 20 may send a provisional response to the EUM in response to a request to register a new EIS with the SM-SR function. The provisional response received by the EUM may trigger a registration response in the EUM, which is sent to the MNO for confirmation. Subsequently, a change of destination for the request received by the intermediate buffer proxy 20 for the SM-SR function may be invoked later and may be selected by the MNO, EUM, OEM, or SP.
[0078] Therefore, the intermediate buffer proxy 20 may function as a bridge for confirming and adjusting data exchanged between the EUM or OEM and the SM-SR function.
[0079] The intermediate buffer proxy 20 may send a false response to avoid expiration of the validity period in EUM.
[0080] The intermediate buffer proxy 20 may "impersonate" the EUM, i.e., function as an SM-SR, to respond immediately to the EUM and avoid the expiration of its validity period.
[0081] Within the scope of the present invention, any of the elements described and / or illustrated and / or claimed may be combined in any way.
Claims
1. A method for managing at least one eUICC information set (EIS) of an eUICC, comprising the following sequence of steps: A generating step (110) for generating a first request to register the eUICC information set (EIS) at an eUICC manufacturer (EUM), wherein the first request includes a first function call identifier (FCI), Step (120) of sending the first request from the eUICC manufacturer (EUM) to the intermediate buffer proxy (20), Step (130) of generating a response to the first request within the intermediate buffer proxy (20), Step (140) of sending the response to the request to the eUICC manufacturer (EUM) A method that includes this.
2. The following are the sequential steps: Step (150): After the eUICC manufacturer (EUM) receives the response to the request to the eUICC manufacturer (EUM), the eUICC manufacturer (EUM) generates a registration result response within the eUICC manufacturer (EUM), Step (160) of sending the registration result response to the mobile network operator (MNO) The method according to claim 1, further comprising:
3. The following are the sequential steps: Step (170) of generating a second request in the intermediate buffer proxy (20) to register the eUICC information set (EIS) based on the first request received by the intermediate buffer proxy (20), wherein the second request includes a second function call identifier (FCI), Step (180) of sending the second request from the intermediate buffer proxy (20) to the subscriber administrator secure route assignment (SM-SR) function and The method according to claim 1 or 2, further comprising:
4. The following are the sequential steps: The step (190) of receiving the second request from the intermediate buffer proxy (20) using the subscriber administrator secure routing (SM-SR) function, Step (200) of confirming with the Subscriber Administrator Safe Route Designation (SM-SR) function that the eUICC information set (EIS) exists in the eUICC information set (EIS) directory stored in the Subscriber Administrator Safe Route Designation (SM-SR) function. The method according to claim 3, further comprising:
5. Step (210) of storing the eUICC information set (EIS) in the database of valid eUICC information sets (EIS) present in the subscriber administrator safety route designation (SM-SR) function, The steps (220) include generating a response to the second request using the subscriber administrator security route designation (SM-SR) function, Step (230) of sending the response from the Subscriber Administrator Secure Route Designation (SM-SR) function to the second request to the intermediate buffer proxy (20) The method according to claim 4, further comprising:
6. An intermediate buffer proxy configured to receive a first request from an eUICC manufacturer (EUM) for registering an eUICC information set (EIS), the first request comprising a first function call identifier (FCI), generate a response to the first request, and transmit the response to the request to the eUICC manufacturer (EUM).
7. The intermediate buffer proxy according to claim 6, further configured to generate a second request for registering the eUICC information set (EIS) and to transmit the second request to the Subscriber Administrator Safe Route Designation (SM-SR) function.
8. The intermediate buffer proxy according to claim 7, further configured to receive a response to the second request from the subscriber administrator secure route designation (SM-SR) function.
9. An intermediate buffer proxy according to any one of claims 6 to 8, characterized in that it includes a unique object identifier (OID).
10. An intermediate buffer proxy according to any one of claims 6 to 8, characterized by including a unique function requester identifier (FRI).
11. The intermediate buffer proxy according to claim 7 or 8, characterized in that it is configured to generate a new function call identifier (FCI) for communication with the subscriber administrator secure routing (SM-SR) function.
Citation Information
Patent Citations
How an eUICC embedded in a machine-type communication device triggers the download of a subscription profile
JP2020505879A
Proxy platform for inter-operator provisioning of ESIM profiles
US20190159016A1