Method and apparatus for managing bundles of smart secure platform

The method and apparatus for managing bundles in mobile communication systems address the challenge of service provision by implementing a bundle policy-based installation and consent confirmation, improving the management of bundles in 5G and IoT networks.

KR102996216B1Active Publication Date: 2026-07-27SAMSUNG ELECTRONICS CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2024-12-19
Publication Date
2026-07-27

AI Technical Summary

Technical Problem

Existing mobile communication systems face challenges in effectively providing services due to the lack of efficient management of bundles in terminals, particularly in the context of 5G and IoT networks, where user intent and subscriber consent are not adequately addressed.

Method used

A method and apparatus for managing bundles in mobile communication systems involving a bundle policy-based installation, local and remote management, and user consent confirmation using a bundle management server and control units in terminals and servers.

Benefits of technology

Enables effective service provision in mobile communication systems by ensuring user intent and subscriber consent are considered, enhancing the management of bundles in terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 112024141520339-PAT00006_ABST
    Figure 112024141520339-PAT00006_ABST
Patent Text Reader

Abstract

The present disclosure discloses a method of operation of a terminal, comprising: a step of installing a bundle according to a bundle policy set based on functional information of each of the terminal, a bundle management server, and a service provider; a step of confirming a user intent according to the bundle policy when performing local management of the installed bundle; and a step of confirming a subscriber intent and user consent according to the bundle policy when performing remote management of the installed bundle.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present disclosure relates to a method and apparatus for managing bundles of SSPs in a mobile communication system. Background Technology

[0002] Efforts are being made to develop improved 5G or pre-5G communication systems to meet the increasing demand for wireless data traffic since the commercialization of 4G communication systems. For this reason, 5G or pre-5G communication systems are referred to as systems beyond the 4G network or systems following the LTE system. To achieve high data transmission rates, the implementation of 5G communication systems in the mmWave band (e.g., the 60 GHz band) is being considered. To mitigate path loss and increase transmission distance in the mmWave band, technologies such as beamforming, massive MIMO, full-dimensional MIMO (FD-MIMO), array antennas, analog beamforming, and large-scale antennas are being discussed for 5G communication systems. In addition, to improve the network of the system, the development of technologies such as advanced small cell, advanced small cell, cloud radio access network (cloud RAN), ultra-dense network, Device to Device communication (D2D), wireless backhaul, moving network, cooperative communication, Coordinated Multi-Points (CoMP), and interference cancellation is underway in 5G communication systems.In addition, advanced coding modulation (ACM) methods such as FQAM (Hybrid FSK and QAM Modulation) and SWSC (Sliding Window Superposition Coding), as well as advanced access technologies such as FBMC (Filter Bank Multi Carrier), NOMA (non-orthogonal multiple access), and SCMA (sparse code multiple access) are being developed in 5G systems.

[0003] Meanwhile, the Internet is evolving from a human-centered network where humans generate and consume information into an IoT (Internet of Things) network where distributed components, such as objects, exchange and process information. IoE (Internet of Everything) technology, which combines IoT with Big Data processing technologies through connections with cloud servers, is also emerging. To implement IoT, technological elements such as sensing technology, wired and wireless communication and network infrastructure, service interface technology, and security technology are required; consequently, technologies such as sensor networks, Machine-to-Machine (M2M) communication, and Machine-Type Communication (MTC) are currently being researched to facilitate the connection of objects. In an IoT environment, intelligent IT services that create new value for human life by collecting and analyzing data generated from connected objects can be provided. Through the convergence and integration of existing IT technologies with various industries, IoT can be applied to fields such as smart homes, smart buildings, smart cities, smart or connected cars, smart grids, healthcare, smart home appliances, and advanced medical services.

[0004] Accordingly, various attempts are being made to apply 5G communication systems to IoT networks. For example, technologies such as sensor networks, Machine to Machine (M2M), and Machine Type Communication (MTC) are being implemented using 5G communication techniques such as beamforming, MIMO, and array antennas. The application of cloud RAN as a big data processing technology, as previously described, can also be considered an example of the convergence of 5G and IoT technologies. As described above and with the advancement of mobile communication systems, it has become possible to provide a variety of services, and therefore, measures to effectively provide these services are required. The problem to be solved

[0005] The disclosed embodiment provides a device and method capable of effectively providing services in a mobile communication system. means of solving the problem

[0006] According to some embodiments of the present disclosure, a method may be provided comprising: a step of installing a bundle according to a bundle policy set based on functional information of each of a terminal, a bundle management server, and a service provider; a step of confirming a user intent according to the bundle policy when performing local management of the installed bundle; and a step of confirming a subscriber intent and user consent according to the bundle policy when performing remote management of the installed bundle.

[0007] Additionally, according to some embodiments of the present disclosure, a terminal may be provided comprising: a transmitting and receiving unit; and a control unit that receives from a bundle management server a bundle including part or all of a bundle policy set based on functional information of a bundle management server and a service provider, installs the received bundle, confirms a user intent according to the bundle policy when performing local management of the installed bundle, and confirms subscriber intent and confirms user consent according to the bundle policy when performing remote management of the installed bundle.

[0008] Additionally, according to some embodiments of the present disclosure, a bundle management server may be provided, comprising: a transmitting and receiving unit; and a control unit that generates a bundle including part or all of a bundle policy set based on functional information of a terminal and a service provider, transmits the bundle to a terminal, receives a request for remote management of the bundle in accordance with a request from a subscriber, and controls the server to confirm the subscriber's intention in accordance with the bundle policy when performing the remote management of the bundle.

[0009] The technical problems to be solved in this disclosure are not limited to those mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art to which this disclosure belongs from the description below. Effects of the invention

[0010] According to an embodiment of the present disclosure, a service can be effectively provided in a mobile communication system. Brief explanation of the drawing

[0011] FIG. 1 is a drawing illustrating a method for connecting a terminal to a mobile communication network using an SSP equipped with a telecom bundle equipped with a profile according to some embodiments of the present disclosure. FIG. 2 shows a conceptual diagram of the internal structure of an SSP according to some embodiments of the present disclosure. FIG. 3 is a diagram showing an example of a certificate hierarchy (or certificate chain) of certificates issued by a certificate issuer (CI) according to some embodiments of the present disclosure, and an example of the configuration of a public key included in each certificate and a digital signature of the certificate issuer (CI). FIG. 4 is a drawing illustrating examples of internal and external components of a terminal for a terminal to download and install a bundle as an SSP according to some embodiments of the present disclosure. FIG. 5 is a diagram illustrating an example of a general procedure in which a subscriber subscribes to a service through a service provider and prepares a bundle on a bundle management server according to some embodiments of the present disclosure. FIG. 6 is a diagram illustrating an example of a method in which a terminal configuration according to some embodiments of the present disclosure and a service provider, a bundle management server, and a user interact with each other. FIG. 7 is a diagram illustrating an example of a general procedure in which a terminal performs bundle local management according to some embodiments of the present disclosure. FIG. 8 is a diagram illustrating an example of a general procedure in which a terminal performs bundle remote management according to some embodiments of the present disclosure. FIG. 9 is a drawing illustrating an example of setting a bundle policy according to some embodiments of the present disclosure. FIG. 10 is a drawing illustrating an example of a procedure in which a terminal performs bundle local management according to some embodiments of the present disclosure. FIG. 11 is a drawing illustrating another example of a procedure in which a terminal performs bundle local management according to some embodiments of the present disclosure. FIG. 12 is a diagram illustrating an example of a procedure in which a terminal performs bundle local management and remote management according to some embodiments of the present disclosure. FIG. 13 is a drawing illustrating another example of a procedure in which a terminal according to some embodiment of the present disclosure performs bundle local management and remote management. FIG. 14a is a diagram illustrating an example of a procedure in which a terminal, a bundle management server, and a service provider set a bundle policy according to some embodiments of the present disclosure. FIG. 14b is a drawing illustrating an example of another procedure in which a terminal, a bundle management server, and a service provider set a bundle policy according to some embodiments of the present disclosure. FIG. 15 is a drawing illustrating the configuration of a terminal according to some embodiments of the present disclosure. FIG. 16 is a drawing illustrating the components of a bundle management server according to one embodiment of the present invention. Specific details for implementing the invention

[0012] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.

[0013] In describing the embodiments, technical details that are well known in the technical field to which this disclosure belongs and are not directly related to this disclosure are omitted. This is intended to convey the essence of this disclosure more clearly without obscuring it by omitting unnecessary explanations.

[0014] For the same reason, some components in the attached drawings have been exaggerated, omitted, or schematically depicted. Additionally, the size of each component does not entirely reflect its actual dimensions. Identical or corresponding components in each drawing have been assigned the same reference numbers.

[0015] The advantages and features of the present disclosure and the methods for achieving them will become clear by referring to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below but may be implemented in various different forms. The embodiments provided are merely to make the present disclosure complete and to fully inform those skilled in the art of the scope of the disclosure, and the present disclosure is defined only by the scope of the claims. Throughout the specification, the same reference numerals refer to the same components.

[0016] At this time, it will be understood that each block of the process flow diagrams and combinations of the flow diagrams can be executed by computer program instructions. Since these computer program instructions can be loaded into the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, the instructions executed through the processor of the computer or other programmable data processing equipment create means to perform the functions described in the flow diagram block(s). Since these computer program instructions can also be stored in computer-available or computer-readable memory that can be directed toward the computer or other programmable data processing equipment to implement the function in a specific way, the instructions stored in computer-available or computer-readable memory can also produce a manufactured item containing means of instruction to perform the function described in the flow diagram block(s). Since computer program instructions can be loaded onto a computer or other programmable data processing equipment, instructions that perform a series of operation steps on the computer or other programmable data processing equipment to create a process executed by the computer can also provide steps for executing the functions described in the flowchart block(s).

[0017] Additionally, each block may represent a module, segment, or part of code containing one or more executable instructions for executing a specified logical function(s). It should also be noted that in some alternative execution examples, the functions mentioned in the blocks may occur out of order. For instance, two blocks described in succession may actually be executed substantially simultaneously, or the blocks may be executed in reverse order according to their corresponding functions.

[0018] In this embodiment, the term "part" refers to a software or hardware component, such as an FPGA or ASIC, and the "part" performs certain roles. However, the meaning of "part" is not limited to software or hardware. The "part" may be configured to reside in an addressable storage medium or configured to operate one or more processors. Accordingly, as an example, the "part" includes components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and "parts" may be combined into a smaller number of components and "parts" or further separated into additional components and "parts." Furthermore, the components and "parts" may be implemented to operate one or more CPUs within a device or secure multimedia card.

[0019] Specific terms used in the following description are provided to aid in understanding the present disclosure, and the use of such specific terms may be modified in other forms without departing from the technical spirit of the present disclosure.

[0020] A Secure Element (SE) refers to a security module composed of a single chip capable of storing security information (e.g., mobile network access keys, user identity verification information such as ID cards / passports, credit card information, encryption keys, etc.) and operating a control module that utilizes the stored security information (e.g., network access control modules such as USIMs, encryption modules, key generation modules, etc.). The SE can be used in various electronic devices (e.g., smartphones, tablets, wearable devices, automobiles, IoT devices, etc.) and can provide security services (e.g., mobile network access, payment, user authentication, etc.) through the security information and the control module.

[0021] SE can be divided into UICC (Universal Integrated Circuit Card), eSE (Embedded Secure Element), and SSP (Smart Secure Platform), which is a form in which UICC and eSE are integrated. Depending on the form in which it is connected to or installed in an electronic device, it can be subdivided into removable, embedded, and integrated types that are integrated into a specific component or SoC (system on chip).

[0022] A UICC (Universal Integrated Circuit Card) is a smart card inserted into mobile communication terminals and is also referred to as a UICC card. A UICC may include a connection control module for connecting to a mobile carrier's network. Examples of connection control modules include USIM (Universal Subscriber Identity Module), SIM (Subscriber Identity Module), and ISIM (IP Multimedia Service Identity Module). A UICC containing a USIM is commonly referred to as a USIM card. Similarly, a UICC containing a SIM module is commonly referred to as a SIM card. Meanwhile, the SIM module is either installed during the manufacturing of the UICC or allows the user to download the SIM module of the mobile communication service they wish to use onto the UICC card at a time of their choosing. A UICC card can also download and install multiple SIM modules, and select at least one of them for use. Such a UICC card may or may not be fixed to the terminal. A UICC that is fixed to a terminal is called an eUICC (embedded UICC), and a UICC embedded in a System-On-Chip (SoC) that includes a communication processor, an application processor, or a single processor structure in which these two processors are integrated is called an iUICC (Integrated UICC). Typically, eUICC and iUICC refer to UICC cards that are fixed to a terminal and allow a SIM module to be downloaded and selected remotely. In this disclosure, a UICC card that allows a SIM module to be downloaded and selected remotely is collectively referred to as an eUICC or an iUICC.In other words, among UICC cards that allow for the remote download and selection of a SIM module, UICC cards that are fixed to the terminal or not are collectively referred to as eUICC or iUICC. Additionally, the downloaded SIM module information is collectively referred to as eUICC profile, iUICC profile, or simply profile.

[0023] An eSE (Embedded Secure Element) refers to a fixed SE used by being fixed to an electronic device. Typically, an eSE is manufactured exclusively for a manufacturer at the request of the terminal manufacturer and may be manufactured to include an operating system and a framework. An eSE can be used for various security service purposes, such as electronic wallets, ticketing, electronic passports, and digital keys, by remotely downloading and installing a service control module in the form of an applet. In this disclosure, a single-chip type SE attached to an electronic device capable of remotely downloading and installing a service control module is collectively referred to as an eSE.

[0024] A Smart Secure Platform (SSP) is capable of integrating and supporting the functions of UICC and eSE on a single chip, and can be classified into removable (rSSP), embedded (eSSP), and integrated (iSSP) types embedded in the SoC. An SSP may consist of a primary platform (PP) and at least one secondary platform bundle (SPB) operating on the PP. The primary platform may include at least one of a hardware platform and a low-level operating system (LLOS), and the secondary platform bundle may include at least one of a high-level operating system (HLOS) and an application running on the HLOS. The secondary platform bundle is also referred to as an SPB or a bundle. The bundle can access resources such as the PP's central processing unit and memory through the Primary Platform Interface (PPI) provided by the PP, and thereby operate on the PP. The bundle may be equipped with communication applications such as SIM (Subscriber Identification Module), USIM (Universal SIM), and ISIM (IP Multimedia SIM), and may also be equipped with various application applications such as electronic wallets, ticketing, electronic passports, and digital keys. In this disclosure, the SSP may also be referred to as a smart security medium.

[0025] Depending on the bundles downloaded and installed remotely, the SSP may be used for the UICC or eSE purposes described above, and multiple bundles may be installed on a single SSP and operated simultaneously to encompass the uses of both UICC and eSE. That is, when a bundle containing a profile is in operation, the SSP may be used for the UICC purpose to connect to a mobile carrier's network. The said UICC bundle can operate by remotely downloading and selecting at least one profile into the bundle, such as the aforementioned eUICC or iUICC. Additionally, when a bundle containing a service control module equipped with an application capable of providing services such as electronic wallets, ticketing, electronic passports, or digital keys on the SSP is in operation, the SSP may be used for the aforementioned eSE purpose. Multiple service control modules may be integrated into a single bundle for installation and operation, or they may be installed and operated as independent bundles.

[0026] In the present disclosure, the SSP is a chip-type security module capable of integrating and supporting the functions of UICC and eSE on a single chip, and can be classified into removable (rSSP), embedded (eSSP), and integrated (iSSP) types embedded in the SoC. The SSP can download and install a bundle from an external bundle management server (Secondary Platform Bundle Manager, SPB Manager) using Over The Air (OTA) technology.

[0027] The method of downloading and installing a bundle using OTA technology on an SSP in the present disclosure can be equally applied to a removable SSP (rSSP) that can be inserted into and removed from a terminal, a fixed SSP (eSSP) installed in a terminal, and an integrated SSP (iSSP) included within an SoC installed in a terminal.

[0028] In the present disclosure, the term UICC may be used interchangeably with SIM, and the term eUICC may be used interchangeably with eSIM.

[0029] In the present disclosure, a Secondary Platform Bundle (SPB) is run on the Primary Platform (PP) of an SSP using the resources of the PP. For example, a UICC Bundle may refer to a package of applications, file systems, authentication key values, etc. stored within an existing UICC, and an operating system (HLOS) on which they operate, in the form of software.

[0030] In the present disclosure, USIM Profile (USIM Profile) may have the same meaning as Profile or may refer to information included in a USIM application within a Profile packaged in the form of software.

[0031] In the present disclosure, the operation of a terminal or an external server enabling a bundle may mean an operation of changing the state of the corresponding profile to an enabled state so that the terminal can receive the services provided by the bundle (e.g., communication services, credit card payment services, user authentication services, etc. through a telecommunications carrier). A bundle in an enabled state may be referred to as an "enabled bundle." A bundle in an enabled state may be stored in an encrypted state in storage space inside or outside the SSP.

[0032] In the present disclosure, an activated bundle may be changed to an active state based on external inputs (e.g., user input, push, request from an application within the terminal, authentication request from a carrier, PP management message, etc.) or internal operations (e.g., timer, polling). An active bundle may mean that it is loaded from storage space inside or outside the SSP into the active memory inside the SSP, processes security information using a security control unit (Secure CPU) inside the SSP, and provides security services to the terminal.

[0033] In the present disclosure, the operation of a terminal or an external server disabling a bundle may mean an operation of changing the state of the bundle to a disabled state so that the terminal cannot receive the services provided by the bundle. A profile in a disabled state may be referred to as a "disabled Bundle." A bundle in an enabled state may be stored in an encrypted state in storage space inside or outside the SSP.

[0034] In the present disclosure, the operation of a terminal or external server deleting a bundle may mean an operation of changing the state of the bundle to a deleted state so that the terminal or external server can no longer activate or deactivate the bundle. A bundle in a deleted state may be referred to as a "deleted bundle."

[0035] In the present disclosure, a bundle management server may include functions for creating a bundle, encrypting a created bundle, creating a bundle remote management command, or encrypting a created bundle remote management command at the request of a Service Provider or another bundle management server. A bundle management server providing such functions may be represented as at least one of an SPB Manager (Secondary Platform Bundle Manager), RBM (Remote Bundle Manager), IDS (Image Delivery Server), SM-DP (Subscription Manager Data Preparation), SM-DP+ (Subscription Manager Data Preparation plus), an administrator bundle server, a Managing SM-DP+ (Managing Subscription Manager Data Preparation plus), a bundle encryption server, a bundle creation server, a Bundle Provisioner (BP), a Bundle Provider, and a BPC holder (Bundle Provisioning Credentials holder).

[0036] In the present disclosure, the bundle management server may perform the role of managing the settings of keys and certificates for downloading, installing, or updating bundles from an SSP and for remotely managing the status of bundles. The bundle management server providing the above functions may be represented as at least one of SPBM (Secondary Platform Bundle Manager), RBM (Remote Bundle Manager), IDS (Image Delivery Server), SM-SR (Subscription Manager Secure Routing), SM-SR+ (Subscription Manager Secure Routing Plus), off-card entity of eUICC Profile Manager or PMC holder (Profile Management Credentials holder), and EM (eUICC Manager).

[0037] In the present disclosure, the activation intermediary server may be represented as at least one of SPBM (Secondary Platform Bundle Manager), RBM (Remote Bundle Manager), SPBDS (Secondary Platform Bundle Discovery Server), BDS (Bundle Discovery Server), SM-DS (Subscription Manager Discovery Service), DS (Discovery Service), Root Activation Intermediary Server (Root SM-DS), and Alternative Activation Intermediary Server (Alternative SM-DS). The activation intermediary server may receive an Event Register Request (Event Register Request) from one or more Bundle Management Servers or Activation Intermediary Servers. Additionally, one or more Activation Intermediary Servers may be used in combination; in this case, the first Activation Intermediary Server may receive an Event Register Request from the Bundle Management Server as well as the second Activation Intermediary Server. In the present disclosure, the functions of the Activation Intermediary Server may be integrated into the Bundle Management Server.

[0038] In the present disclosure, the term "bundle management server" may collectively refer to a combination of functions that generate, encrypt, and transmit bundle or bundle remote management commands, and functions that manage SSP configuration and installed bundles. Additionally, the term "bundle management server" may collectively refer to a combination of functions that include the activation brokerage server. Accordingly, in the various embodiments of the present disclosure below, the operation of the bundle management server and the activation brokerage server may be performed on a single bundle management server. Furthermore, each function may be divided and performed on multiple separate bundle management servers. Additionally, in the specification of the present disclosure, the bundle management server or the activation brokerage server may be referred to as a bundle server. The bundle server may be one of the bundle management server and the activation brokerage server, or it may be a device that includes both the bundle management server and the activation brokerage server.

[0039] In the present disclosure, the bundle management server and the activation brokerage server may be collectively referred to as SPBM or RBM. Additionally, the bundle server may be referred to as the bundle management server.

[0040] As used in this disclosure, the term "terminal" may refer to a mobile station (MS), user equipment (UE), user terminal (UT), wireless terminal, access terminal (AT), terminal, subscriber unit, subscriber station (SS), wireless device, wireless communication device, wireless transmit / receive unit (WTRU), mobile node, or mobile, and the terminal may be referred to by other terms. Various embodiments of the terminal may include a cellular telephone, a smartphone having wireless communication capabilities, a personal digital assistant (PDA) having wireless communication capabilities, a wireless modem, a portable computer having wireless communication capabilities, a shooting device such as a digital camera having wireless communication capabilities, a gaming device having wireless communication capabilities, a music storage and playback appliance having wireless communication capabilities, an internet appliance capable of wireless internet access and browsing, as well as portable units or terminals integrating combinations of such capabilities. Additionally, the terminal may include, but is not limited to, a Machine-to-Machine (M2M) terminal and a Machine-Type Communication (MTC) terminal / device. In the present disclosure, the terminal may be referred to as an electronic device.

[0041] In the present disclosure, an electronic device may have an SSP embedded therein that can be installed by downloading a bundle. If the SSP is not embedded in the electronic device, the SSP, which is physically separated from the electronic device, may be inserted into the electronic device and connected to the electronic device. For example, the SSP may be inserted into the electronic device in the form of a card. For example, the electronic device may include a terminal, wherein the terminal may be a terminal that includes an SSP that can be installed by downloading a bundle. The SSP may not only be embedded in the terminal, but if the terminal and the SSP are separated, the SSP may be inserted into the terminal and connected to the terminal.

[0042] In the present disclosure, a terminal or electronic device may include software or an application installed within the terminal or electronic device to control an SSP. The software or application may be referred to, for example, as a Local Bundle Assistant (LBA) or a Local Bundle Manager (LBM).

[0043] In the present disclosure, the bundle identifier may be referred to as an argument matching the bundle identifier (SPB ID), bundle family identifier (SPB Family ID), bundle matching ID, and event identifier (Event ID). The bundle identifier (SPB ID) may represent a unique identifier for each bundle. The bundle family identifier may represent an identifier distinguishing the type of bundle (e.g., a telecom bundle for mobile carrier network access). The bundle identifier may be used as a value that can index bundles in a bundle management server. In the present disclosure, the SSP identifier (SSP ID) may be a unique identifier of an SSP embedded in a terminal and may be referred to as SSPID. Additionally, as in the embodiments of the present disclosure, the SSP identifier may be a terminal ID when the terminal and the SSP chip are not separated. Furthermore, the SSP identifier may refer to a specific bundle identifier (SPB ID) within the SSP. More specifically, an SSP identifier may refer to the bundle identifier of a managed bundle or loader (SPBL, Secondary Platform Bundle Loader) that manages the installation, activation, deactivation, and deletion of other bundles in the SSP. An SSP may have multiple SSP identifiers, and multiple SSP identifiers may be values ​​derived from a single unique SSP identifier.

[0044] In the present disclosure, a loader (SPBL, Secondary Platform Bundle Loader) may refer to a management bundle that manages the installation, activation, deactivation, and deletion of other bundles in an SSP. An LBA of a terminal or a remote server may install, activate, deactivate, or delete a specific bundle through the loader. In the present disclosure, the loader may also be referred to as an SSP. Additionally, in the present disclosure, the loader may also be referred to as an LBA.

[0045] In the present disclosure, Bundle Provisioning Credentials (BPCs) may be a means used for mutual authentication, bundle encryption, and signing between a bundle management server and an SSP. A BPC may include one or more of a symmetric key, an RSA (Rivest Shamir Adleman) certificate and private key, an ECC (elliptic curved cryptography) certificate and private key, a root certification authority (CA), and a certificate chain. Additionally, if there are multiple profile management servers, different BPCs may be stored or used in the SSP for each profile management server.

[0046] In the present disclosure, Profile Management Credentials (PMCs) may be a means used for mutual authentication, encryption of transmitted data, and signing between a profile management server and an eUICC. A PMC may include one or more of a symmetric key, an RSA certificate and private key, an ECC certificate and private key, a Root CA, and a certificate chain. Additionally, if there are multiple profile management servers, different PMCs may be stored or used in the eUICC for each profile management server.

[0047] In this disclosure, "Event" may be a collective term for "Bundle Download," "Remote Bundle Management," or other management / processing commands for a bundle or SSP. An "Event" may be named "Remote Bundle Provisioning Operation" (or "RBP Operation") or "Event Record." Each "Event" may be referred to by its corresponding "Event Identifier" (Event ID) or "Matching Identifier" (Matching ID), and may also be referred to as data containing at least one address (FQDN, IP Address, or URL) of the bundle management server or activation intermediary server where the event is stored, or each server identifier. "Bundle Download" may be used interchangeably with "Bundle Installation." Additionally, Event Type can be used as a term to indicate whether a specific event is a bundle download, remote bundle management (e.g., deletion, activation, deactivation, replacement, update, etc.), or other bundle or SSP management / processing commands, and may be named Operation Type (or OperationType), Operation Class (or OperationClass), Event Request Type, Event Class, Event Request Class, etc.

[0048] In the present disclosure, "Bundle Image" (or "Image") may be used interchangeably with "Bundle" or as a term representing a specific data object of a bundle, and may be named "Bundle TLV" or "Bundle Image TLV". If the Bundle Image is encrypted using encryption parameters, the Bundle Image may be named "Protected Bundle Image" (PBI) or "Protected Bundle Image TLV" (PBI TLV). If the Bundle Image is encrypted using encryption parameters that can be decrypted only by a specific SSP, it may be named "Bound Bundle Image" (BBI) or "Bound Bundle Image TLV" (BBI TLV). The Bundle Image TLV may be a data set representing information that constitutes a profile in the TLV(Tag, Length, Value) format.

[0049] In the present disclosure, Local Bundle Management (LBM) may be referred to as Bundle Local Management, Local Management, Local Management Command, Local Command, Local Bundle Management Package, Bundle Local Management Package, Local Management Package, Local Management Command Package, or Local Command Package. LBM may be used to install any bundle, change the status (Enabled, Disabled, Deleted) of a specific bundle, or update the contents of a specific bundle (e.g., Bundle Nickname, Bundle Metadata, etc.) through software installed on a terminal. LBM may include one or more Local Management Commands, in which case the bundles targeted by each Local Management Command may be the same or different for each Local Management Command.

[0050] In the present disclosure, Remote Bundle Management (RBM) may be referred to as Bundle Remote Management, Remote Management, Remote Management Command, Remote Command, Remote Bundle Management Package, Bundle Remote Management Package, Remote Management Package, Remote Management Command Package, or Remote Command Package. RBM may be used to install any bundle, change the status (Enabled, Disabled, Deleted) of a specific bundle, or update the contents of a specific bundle (e.g., Bundle Nickname, Bundle Metadata, etc.). RBM may include one or more remote management commands, and the bundles targeted by each remote management command may be the same or different for each remote management command.

[0051] In the present disclosure, the term "target bundle" may be used to refer to a bundle that is the target of a local or remote management command.

[0052] In the present disclosure, "Bundle Rule" may be used as a term referring to information that a terminal must verify when performing local or remote management on a target bundle. Additionally, "Bundle Rule" may be used interchangeably with terms such as "Bundle Policy," "Rule," and "Policy."

[0053] In the present disclosure, the term "Subscriber" may be used to refer to a Service Provider who owns the terminal or an End User who owns the terminal. Generally, the former may be referred to as an M2M Device, and the latter as a Consumer Device. In the case of an M2M Device, there may be an End User who does not own the terminal but uses the terminal transferred to or leased from the Service Provider; in this case, the End User may be different from or the same as the Service Provider.

[0054] In the present disclosure, "Subscriber intent" may be used as a general term for the intent of a subscriber to manage a bundle locally or remotely. Additionally, in the case of local management, "Subscriber intent" may refer to "End User intent," and in the case of remote management, "Subscriber intent" may refer to "Service Provider intent."

[0055] In the present disclosure, "End User consent" may be used as a term referring to whether a user consents to the performance of local or remote management.

[0056] In the present disclosure, a certificate or digital certificate may represent a digital certificate used for asymmetric key-based mutual authentication consisting of a pair of a public key (PK) and a secret key (SK). Each certificate may include one or more public keys (PKs), a public key identifier (PKID) corresponding to each public key, a certificate issuer ID of the certificate issuer (CI) that issued the certificate, and a digital signature. Additionally, the certificate issuer may be referred to as a certification issuer, a certificate authority (CA), a certification authority, etc. In the present disclosure, Public Key (PK) and Public Key ID (PKID) may be used interchangeably with the same meaning to refer to a specific public key or a certificate containing the said public key, or a part of a specific public key or a part of a certificate containing the said public key, or a result of an operation (e.g., hash) of a specific public key or a result of an operation (e.g., hash) of a certificate containing the said public key, or a result of an operation (e.g., hash) of a part of a specific public key or a result of an operation (e.g., hash) of a part of a certificate containing the said public key, or a storage space where data is stored.

[0057] In the present disclosure, when certificates issued by one Certificate Issuer (first certificates) are used to issue other certificates (second certificates), or when second certificates are used to issue third or higher certificates in a linked manner, the correlation of said certificates may be referred to as a Certificate Chain or Certificate Hierarchy, and in this case, the CI certificate used for the initial certificate issuance may be referred to as the Root of Certificate, top certificate, Root CI, Root CI Certificate, Root CA, Root CA Certificate, etc.

[0058] In this disclosure, a Service Provider may represent a business entity that requests the creation of a bundle by issuing a requirement to a bundle management server and provides services to a terminal through the bundle. For example, a Service Provider may represent a Mobile Operator that provides network access services through a bundle equipped with a communication application, and may collectively refer to the Mobile Operator's Business Supporting System (BSS), Operational Supporting System (OSS), Point of Sale Terminal, and other IT systems. Furthermore, in this disclosure, the Service Provider is not limited to representing a single specific business entity but may be used as a term referring to a group or association or consortium of one or more business entities, or an agency representing said group or consortium. Additionally, in the present disclosure, a service provider may be referred to as an operator (or OP or Op.), a bundle owner (BO), an image owner (IO), etc., and each service provider may have at least one name and / or unique identifier (Object Identifier, OID) set or assigned. If a service provider refers to a group or association or agency of one or more business entities, the name or unique identifier of any group or association or agency may be a name or unique identifier shared by all business entities belonging to said group or association or all business entities cooperating with said agency.

[0059] In the present disclosure, AKA may represent Authentication and Key agreement and may represent an authentication algorithm for accessing 3GPP and 3GPP2 networks.

[0060] In the present disclosure, K (or K value) may be a cryptographic key value stored in an eUICC used in an AKA authentication algorithm.

[0061] In the present disclosure, OPc may be a parameter value that can be stored in an eUICC used in an AKA authentication algorithm.

[0062] In the present disclosure, NAA is a Network Access Application, and may be an application such as a USIM or ISIM stored in a UICC for connecting to a network. NAA may be a network access module.

[0063] In the present disclosure, a telecom bundle may be a bundle equipped with at least one NAA or a function to download and install at least one NAA remotely. In the present disclosure, a telecom bundle may include a telecom bundle identifier designating the same.

[0064] Furthermore, in describing the present disclosure, if it is determined that a detailed description of related known functions or configurations could unnecessarily obscure the essence of the present disclosure, such detailed description is omitted.

[0065] The following describes various embodiments of a method and device for installing and managing bundles online via a remote server.

[0066] An embodiment of the present disclosure may provide a device and a method for remotely installing a control module on a security module installed in an electronic device, and providing security services (e.g., mobile communication network access, payment, user authentication, digital key, etc.) through security information stored in the security module and the control module.

[0067] FIG. 1 is a diagram illustrating a method for connecting a mobile communication network of a terminal using an SSP equipped with a telecom bundle having a profile according to some embodiments of the present disclosure, and the operation of various types of bundles.

[0068] As illustrated in FIG. 1, the SSP (120) may be embedded in the SoC (130) of the terminal (110). In this case, the SoC (130) may be a communication processor, an application processor, or a processor that integrates both of these processors. Additionally, the SSP (120) may be a detachable type (122) in the form of an independent chip that is not integrated into the SoC, or an embedded type (124) that is pre-embedded in the terminal (110).

[0069] A bundle equipped with a profile implies that it contains 'connection information' capable of connecting to a specific carrier. For example, the connection information may be the International Mobile Subscriber Identity (IMSI), which is a subscriber identifier, and K or Ki values ​​required to authenticate to the network along with the subscriber identifier.

[0070] The terminal (110) can perform authentication with the mobile carrier's authentication processing system (e.g., HLR (home location register) or AuC (Authentication Center)) using at least one of the telecom bundles (140, 150) installed in the SSP (120). For example, the authentication process may be an AKA (Authentication and Key Agreement) process. If the terminal (110) succeeds in authentication, it can use mobile communication services, such as telephone or mobile data usage, by using the mobile carrier network (160) of the mobile communication system. Each of the telecom bundles (140, 150) can store different authentication information, and the terminal can use the mobile communication network by operating the two bundles simultaneously or in time-sharing mode according to the settings.

[0071] Additionally, the terminal (110) can use a payment bundle (170) installed in the SSP (120) to make online payments through the terminal app or offline payments through an external credit card PoS (Point of Sale) device, and can authenticate the identity of the terminal owner using an electronic ID bundle (180).

[0072] FIG. 2 shows a conceptual diagram of the internal structure of an SSP (210) according to some embodiments of the present disclosure. Since the SSP (210) can correspond to the SSP (120), descriptions that overlap with FIG. 1 are omitted.

[0073] In FIG. 2, the SSP (210) may consist of one Primary Platform (PP) (220) and at least one Secondary Platform Bundle (SPB) (230, 240) running on it. The Primary Platform (220) may include hardware (not disclosed) and at least one Low Level Operating System (LLOS) (222). The Secondary Platform Bundle (230) may include a High-Level Operating System (HLOS) (232) and at least one application (234) running on it. Each Secondary Platform Bundle (230, 240) may access resources such as the central processing unit and memory of the Primary Platform (220) using the Primary Platform Interface (PPI) (250) and run on the SSP (210) through this.

[0074] FIG. 3 is a diagram showing an example of a certificate hierarchy (or certificate chain) of certificates issued by a certificate issuer (CI) according to some embodiments of the present disclosure, and an example of the configuration of a public key included in each certificate and a digital signature of the certificate issuer (CI).

[0075] Referring to FIG. 3, a Certificate Issuer (CI) generates a Certificate Issuer Public Key (CI Public Key) and a Certificate Issuer Secret Key (CI Secret Key) to use, and generates a Certificate Issuer Certificate (CI Certificate, 311) by including the CI Public Key (313) among them in its own certificate, and can attach a Digital Signature (CI Signature, 315) generated using its own Secret Key to its own certificate.

[0076] Additionally, referring to FIG. 3, the CI certificate (311) can be used to issue (391) the certificate (331) of Object 1. Object 1 may be, for example, a bundle management server (SPBM). Object 1 generates a public key and a private key to use, and generates the Object 1 certificate (331) by including the Object 1 public key (333) among them in its own certificate, and requests the certificate issuer to obtain the certificate issuer's digital signature (CI Digital Signature, 335) using the certificate issuer's private key. At this time, the Object 1 certificate (331) may include the certificate issuer's identifier (337) corresponding to the CI public key (313) that must be used to verify the certificate issuer's signature (335) included in the certificate. The certificate issuer's identifier (337) may include at least one of the CI public key identifier (CI Public Key ID) and the CI identifier (CI ID, CI Object ID, Object Universally Unique Identifier, Object UUID).

[0077] Additionally, referring to FIG. 3, the CI certificate (311) can be used to issue (393) the certificate (351) of Object 2. Object 2 may be, for example, an SSP Maker. Object 2 generates a public key and a private key to use, and generates the Object 2 certificate (351) by including the Object 2 public key (353) among them in its own certificate, and requests the certificate issuer to obtain the certificate issuer's digital signature (CI Digital Signature, 355) using the certificate issuer's private key. At this time, the Object 2 certificate (351) may include the certificate issuer's identifier (337) corresponding to the CI public key (313) that must be used to verify the certificate issuer's signature (355) included in the certificate. The certificate issuer's identifier may include at least one of the CI public key identifier (CI Public Key ID) and the CI identifier (CI ID, CI Object ID, Object Universally Unique Identifier, Object UUID). The certificate issuer signatures (335 and 355) included in the above object 1 certificate (331) and object 2 certificate (351) may be different values, but the certificate issuer public key identifier (337) is the same value.

[0078] Additionally, referring to FIG. 3, the object 2 certificate (351) can be used to issue (395) the object 3 certificate (371). Object 3 may be, for example, an SSP manufactured by an SSP Maker or a secondary platform bundle loader installed inside the SSP. Object 3 generates a public key and a private key to use, and generates an object 3 certificate (371) by including the object 3 public key (373) among them in its own certificate, and requests Object 2 to obtain the object 3 digital signature (375) using Object 2's private key, that is, the certificate issuer's private key. At this time, the object 3 certificate (371) may include an issuer identifier (377) corresponding to the object 2 public key (353) that must be used to verify the object 3 signature (375) included in the certificate. The issuer identifier (377) may include at least one of the issuer's public key identifier (Public Key ID) and issuer identifier (Object ID, Object Universally Unique Identifier, Object UUID).

[0079] In the example of FIG. 3, the Object 1 certificate (331), Object 2 certificate (351), and Object 3 certificate (371) shown can all have the same CI certificate (311) as the root of certificate. Therefore, Object 1, Object 2, and Object 3 may require the CI certificate (311) or the CI public key (313) included therein to authenticate each other. More specifically, in the example of FIG. 3, for Object 1 and Object 2 to authenticate each other using digital certificates and signatures, Object 1 may need Object 2's signature (355), Object 2's certificate (351), and CI public key (313), and Object 2 may need Object 1's signature (335), Object 1's certificate (331), and CI public key (313). Additionally, in the embodiment of FIG. 3, for Object 1 and Object 3 to authenticate each other using digital certificates and signatures, Object 1 may need Object 3's signature (375), Object 3's certificate (371), Object 2's certificate (351), and CI public key (313), and Object 3 may need Object 1's signature (335), Object 1's certificate (331), and CI public key (313). At this time, regarding the object 3 certificate (371), the object 2 certificate (351) may be named as a certificate sub-issuer (Sub Certificate Issuer, Sub CI, or Sub Certificate Authority, Sub CA).

[0080] FIG. 4 is a drawing illustrating examples of internal and external components of a terminal (410) for downloading and installing a bundle to an SSP (430) according to some embodiments of the present disclosure.

[0081] In FIG. 4, the terminal (410) may be a terminal equipped with an SSP (430) and an LBA (412) installed to control the SSP (430). The SSP (430) may be embedded in the terminal (410) or may be detachable. The SSP (430) may include a primary platform (431), a secondary platform bundle loader (SPBL) (433), and one or more secondary platform bundles (435, 437, or 439). Additionally, the secondary platform bundles (435, 437, or 439) may not be installed inside the SSP (430) at the time of shipment of the terminal, but may be downloaded and installed remotely after shipment.

[0082] Also, referring to FIG. 4, each bundle may have a different bundle family identifier (441 or 442). The SSP (430) or SPBL (433) may manage certificate information to be used when downloading and installing bundles assigned different family identifiers. At this time, the certificate information managed by each family identifier may exist on a certificate hierarchy issued by different Certificate Issuers (CIs). When downloading and installing a bundle from a bundle management server (451 or 453), the SSP (430) or SPBL (433) may select the certificate information set in the bundle family identifier (441 or 442) assigned to the bundle and transmit that information to the bundle management server (451 or 453). The above certificate information may be the certificate or public key of the certificate issuer of the relevant certificate hierarchy, and may be an identifier corresponding to the relevant certificate and public key (e.g., CI ID, CI Object ID, Object Universally Unique Identifier, Object UUID, CI Public Key ID).

[0083] FIG. 5 is a diagram illustrating an example of a general procedure in which a subscriber (530) subscribes to a service through a service provider (540) and prepares a bundle in a bundle management server (550) according to some embodiments of the present disclosure.

[0084] In FIG. 5, the terminal (500) may be a terminal equipped with an SSP (510) and an LBA (520) installed to control the SSP (510). Additionally, although not shown in the drawing, a bundle requested by a service provider (540) may be created and waiting at the bundle management server (550), and the service provider (540) may possess at least one of the bundle identifier (SPB ID), bundle family identifier (SPB Family ID), and the address (SPBM Addr) of the bundle management server (550).

[0085] Referring to FIG. 5, in step 5001, a subscriber (530) can select and subscribe to a service provided by a service provider (540) (e.g., data service through a mobile communication network). At this time, the subscriber (530) can selectively transmit to the service provider (540) the SSP (510) identifier (SSP ID) of the terminal (500) to install the bundle in order to use the service provided by the service provider (540). In step 5003, the service provider (540) and the bundle management server (550) can perform a bundle download preparation procedure. In step 5003, the service provider (540) can selectively transmit to the bundle management server (550) the SSP (510) identifier (SSP ID) to which the bundle will be installed, and can transmit to the bundle management server (550) at least one of a specific bundle identifier (SPB ID) and a bundle family identifier (SPB Family ID) that can provide the service selected by the subscriber among the bundles prepared on the server. In step 5003, the bundle management server (550) may select one of the bundles having a specific bundle identifier or a bundle family identifier that has been transmitted, and may transmit the identifier of the selected bundle to the service provider (540). The service provider (540) or the bundle management server (550) may generate a new Bundle Matching ID that can distinguish the selected bundle. Additionally, the bundle providing server (550) may manage the selected bundle by linking it with the transmitted SSP identifier (SSP ID). In step 5003, the bundle management server (550) may transmit a bundle management server address (SPBM Addr) that can download the selected bundle, and the bundle management server address may be its own address or another bundle management server address where the prepared bundle is stored, or it may be the address of another bundle management server that can store and obtain download information (server address, etc.) of the prepared bundle.

[0086] Referring to FIG. 5, in step 5005, the service provider (540) can transmit prepared bundle download information to the subscriber (530). The bundle download information may optionally transmit at least one of the bundle management server address (SPBM Addr) where the bundle is prepared, the bundle matching ID of the prepared bundle, and the bundle family identifier (SPB Family ID) of the prepared bundle.

[0087] Referring to FIG. 5, bundle download information may be transmitted to the LBA (520) in step 5006. The bundle download information may be at least one of the address of the bundle management server (SPBM Addr) to which the LBA (520) connects, the bundle separator of the bundle prepared in step 5003 described above, and the bundle family identifier (SPBM Family ID) of the prepared bundle. The bundle separator may include at least one of the bundle Matching ID or bundle Event ID generated in step 5003. The bundle separator may include the bundle family identifier of the prepared bundle. The bundle Event ID may include at least one of the bundle Matching ID of the bundle prepared in step 5003 and the address of the bundle management server. The bundle download information may be entered by the subscriber (530) into the LBA (520) (e.g., QR code scanning, direct text input, etc.). Additionally, bundle download information may be input into the LBA (520) by a subscriber (530) or a service provider (540) using a push input through an information providing server (not shown). Additionally, the LBA (520) may receive bundle download information by connecting to an information providing server (not shown) that is pre-configured in the terminal (500).

[0088] FIG. 6 is a diagram illustrating an example of a method in which a terminal (600) according to some embodiment of the present disclosure and a service provider (630), a bundle management server (640), and a user (650) interact with each other.

[0089] Referring to FIG. 6, the terminal (600) may include at least one LBA (610) and at least one SSP (620).

[0090] As in operations 6001 to 6003, the user (650) can issue commands to the SSP (620) through the LBA (610) within the terminal (600). Additionally, the LBA (610) can issue commands directly to the SSP (620) through operation 6003 without input from the user (650). The present disclosure may refer to bundle management operations (6001, 6003) by the user (650) or the terminal (600) as Local Management.

[0091] In operation 6005, the service provider (630) may request remote management of the bundle from the bundle management server (640). In operation 6007, the bundle management server (640) may issue a remote management command to the SSP (620) through the LBA (610). The present disclosure may refer to the bundle management operations (6005, 6007) by the service provider (630) as remote management.

[0092] In operation 6009, the SSP (620) can check the bundle policy to process the received local or remote management command. Additionally, the LBA (610) or the bundle management server (640) may check the bundle policy. A more detailed method for checking the bundle policy will be described later with reference to the drawings.

[0093] FIG. 7 is a drawing illustrating an example of a general procedure in which a terminal (700) performs bundle local management according to some embodiments of the present disclosure.

[0094] In FIG. 7, the description of the configuration of the terminal (700), LBA (710), SSP (720), service provider (730), bundle management server (740), and user (750) will be omitted if it overlaps with the descriptions in FIG. 1 to 6.

[0095] Referring to FIG. 7, in operation 7001, the user (750) may express an End User Intent to initiate a specific local management operation on the LBA (710). Operation 7001 may utilize a general user interface through which the user interacts with the terminal. For example, the user (750) may input a specific operation (such as QR code scanning) into the LBA (710) or select a specific menu of the LBA (710). If the terminal (700) performs a local management operation that does not require an End User Intent according to the bundle policy, operation 7001 may be omitted.

[0096] In operation 7003, the LBA (710) may request local management from the SSP (720). If the local management operation requires an End User Intent according to the bundle policy, the 7003 operation may be a request reflecting the End User Intent of the 7001 operation. If the local management operation does not require an End User Intent according to the bundle policy, the LBA (710) may perform the 7003 operation directly without the 7001 operation.

[0097] In operation 7005, the SSP (720) can check the bundle policy of the target bundle to perform local management. Additionally, in operation 7005, the LBA (710) and / or the bundle management server (740) may check the bundle policy. For example, in the case of a local management operation to install a bundle, the SSP (720) may receive the Bundle Metadata and / or part of the bundle policy of the bundle to be installed from the bundle management server (740) via the LBA (710). As another example, the SSP (720) may receive all or part of the bundle policy from the LBA (710) in addition to the bundle policy it stores itself. For the detailed operation of the SSP (720) checking the bundle policy, the description of the drawings to be described later will be referenced. If the LBA (710) performs local management alone without an End User Intent, and the Bundle Policy check reveals that the local management requires an End User Intent, the SSP (720) can terminate the local management by performing the 7015 operation. Additionally, if the local management is performed on a bundle for which local management is not permitted under the Bundle Policy, the SSP (720) can terminate the local management by performing the 7015 operation.

[0098] If, as a result of checking the bundle policy, End User Intent Confirmation is required for local management, the SSP (720) may request End User Intent Confirmation from the LBA (710) in operation 7007. In operation 7009, the LBA (710) may receive End User Intent Confirmation from the user (750). The implementation of operation 7009 may utilize various other means provided by the terminal (700), such as displaying a screen asking for a simple "Yes / No," receiving input of a Personal Identification Number (PIN code, etc.) pre-configured by the user (750) or the service provider (740), or receiving input of biometric information such as the user's (750) fingerprint or iris. The End User Intent Confirmation means to be used in operation 7009 may be configured in the bundle policy. In operation 7011, the LBA (710) may transmit the End User Intent Confirmation result (acceptance or rejection) to the SSP (720). If the bundle policy checks determine that user intent verification is not required for the local management, actions 7007 through 7011 may be omitted. If the user intent verification determines that the user rejects the local management or does not respond within a certain period of time, the SSP (720) may perform action 7015 to terminate the local management. If user intent verification is not required or if the user intent verification determines that the user accepts the local management, the SSP (720) may perform action 7013.

[0099] In operation 7013, the SSP (720) can perform local management. Operation 7013 may further include an LBA (710) and / or a bundle management server (740). For example, in the case of a local management operation to install a bundle, the SSP (720) can receive and install a bundle from the bundle management server (740) via the LBA (710).

[0100] In operation 7015, the SSP (720) can notify the LBA (710) of the result (success or failure) of the local management.

[0101] In operation 7017, LBA (710) may notify the user (750) of the result of the local management (success or failure). If there is no need to notify the user of the result of the local management, operation 7017 may be omitted.

[0102] Referring to FIG. 7, when the terminal (700) performs local management of a bundle, it determines whether an End User Intent and End User Intent Confirmation are required according to the bundle's policy, and accordingly, it may accept / execute or reject the local management command.

[0103] FIG. 8 is a diagram illustrating an example of a general procedure in which a terminal (800) performs bundle remote management according to some embodiments of the present disclosure.

[0104] In FIG. 8, the description of the configuration of the terminal (800), LBA (810), SSP (820), service provider (830), bundle management server (840), and user (850) will be omitted if it overlaps with the descriptions in FIG. 1 to 6.

[0105] Referring to FIG. 8, in operation 8001, the service provider (830) can request remote management of the bundle from the bundle management server (840).

[0106] In operation 8003, the bundle management server (840) may request remote management of a specific bundle from the SSP (820) via the LBA (810). The request for remote bundle management may further include all or part of the bundle remote management command and information required to perform the bundle remote management (e.g., the identifier or family identifier of the target bundle to be remotely managed, the type of remote management command such as enable / disable / delete, etc.). All or part of the bundle remote management command or information required to perform the bundle remote management may be transmitted in operation 8003 or in operation 8015.

[0107] In operation 8005, the SSP (820) can check the bundle policy of the target bundle to perform remote management. Additionally, in operation 8005, the LBA (810) and / or the bundle management server (840) may check the bundle policy. For example, in the case of a remote management operation to install a bundle, the SSP (820) may receive the summary information (Bundle Metadata) and / or part of the bundle policy of the bundle to be installed from the bundle management server (840) via the LBA (810). As another example, the SSP (820) may receive all or part of the bundle policy from the LBA (810) or the bundle management server (840) in addition to the bundle policy it stores itself. For a detailed operation of the SSP (820) checking the bundle policy, please refer to the description of the drawings to be described later. If remote management is performed on a bundle for which remote management is not permitted under the bundle policy, the SSP (820) can terminate the remote management by performing the 8017 operation.

[0108] If, as a result of verifying the bundle policy, Subscriber Intent Verification is required for remote management, the SSP (820) can verify the subscriber intent in operation 8007. Operation 8007 may also be performed by a terminal (800), a service provider (830), and / or a bundle management server (840). The implementation of the 8007 operation may utilize various other means provided by the terminal (800), the bundle management server (840), and the service provider (830), such as verifying the digital signature and certificate of the service provider (830) for arbitrary data (e.g., a remote management request message of the 8001 operation, or any string generated by the bundle management server (840) or the SSP (820), or verifying a secret key (credential key) provided by the service provider (830) within the bundle installed in the bundle management server (840), LBA (810), SSP (820), and / or the terminal (800). The means for verifying subscriber intent to be used in the 8007 operation may be set in the bundle policy, and if not set in the bundle policy, any means agreed upon or selected by the terminal (800), the bundle management server (840), or the service provider (830) may be utilized. If the bundle policy checks determine that subscriber intent verification is not required for the remote management, operation 8007 may be omitted. If subscriber intent verification fails, the SSP (820) may perform operation 8017 to terminate the remote management. If subscriber intent verification is not required or if subscriber intent verification is successful, the SSP (820) may perform operation 8009. Meanwhile, although FIG. 8 depicts operation 8007 as being performed before operations 8009 through 8013, it should be noted that depending on the implementation, operation 8007 may be performed after operations 8009 through 8013.Additionally, the 8007 operation may be performed in conjunction with the 8003 operation, the 8005 operation, or the 8015 operation. For example, if the digital signature of the service provider (830) needs to be verified as a means of verifying subscriber intent in the 8007 operation, the 8007 operation may be substituted by verifying the digital signature generated by the service provider for the bundle policy verification of the 8005 operation, the bundle remote management request of the 8003 operation, or the bundle remote management command of the 8015 operation.

[0109] If, as a result of verifying the bundle policy, End User Consent is required for remote management, the SSP (820) may request End User Consent from the LBA (810) in operation 8009. In operation 8011, the LBA (810) may obtain End User Consent from the user (850). The implementation of operation 8011 may utilize various other means provided by the terminal (800), such as displaying a screen asking for a simple "Yes / No," receiving input of a Personal Identification Number (PIN code, etc.) pre-set by the user or service provider, or receiving input of biometric information such as the user's fingerprint or iris. The means for verifying End User Consent to be used in operation 8011 may be set in the bundle policy, and if not set in the bundle policy, any means agreed upon or selected by the terminal (800), the bundle management server (840), or the service provider (830) may be utilized. In operation 8013, the LBA (810) may transmit the result of user consent verification (consent or refusal) to the SSP (820). If the result of checking the bundle policy indicates that user consent verification is not required for the remote management, operations 8009 through 8013 may be omitted. If the result of checking user intent indicates that the user does not consent to the remote management or the user does not respond within a certain period of time, the SSP (820) may perform operation 8017 to terminate the remote management. If user consent is not required or the result of checking user consent indicates that the user consents to the remote management, the SSP (820) may perform operation 8015.

[0110] In the 8015 operation, the SSP (820) can perform remote management. The 8015 operation may further include an LBA (810) and / or a bundle management server (840). For example, in the case of a remote management operation to install a bundle, the SSP (820) can receive and install a bundle from the bundle management server (840) via the LBA (810).

[0111] In operation 8017, the SSP (820) can notify the LBA (810) of the result (success or failure) of the remote management.

[0112] In operation 8019, LBA (810) may notify the user (850) of the result of the remote management operation (success or failure). If there is no need to notify the user of the result of the remote management operation, operation 8019 may be omitted.

[0113] In operation 8021, the LBA (810) can notify the bundle management server (840) of the result (success or failure) of the remote management.

[0114] In operation 8023, the bundle management server (840) can notify the service provider (830) of the result (success or failure) of the remote management.

[0115] Referring to FIG. 8, when the terminal (800) performs remote management of the bundle, it determines whether Subscriber Intent Verification and End User Consent are required according to the bundle's policy, and accordingly, accepts / executes or rejects the remote management command.

[0116] FIG. 9 is a drawing illustrating an example of setting a bundle policy according to some embodiments of the present disclosure.

[0117] Referring to FIG. 9, the bundle policy (910) can be expressed as a series of parameters. Although the bundle policy (910) in FIG. 9 is expressed in the form of a table for convenience of explanation, it does not necessarily have to be in the form of a table and may be composed of a list of parameters. In addition, it should be noted that the setting values ​​of each parameter shown in FIG. 9 are merely examples of the bundle policy for convenience of explanation, and the actual setting values ​​may differ for each bundle.

[0118] The bundle policy (910) may include an identifier (911) that distinguishes each bundle. The bundle identifier (911) may represent the name or bundle identifier of each bundle as a string or sequence of numbers. Additionally, although not shown in FIG. 9, the bundle identifier (911) may further include a family identifier (FID) of each bundle.

[0119] The bundle policy (910) may include a “Visible to End User” indicator (913) indicating whether each bundle is allowed to be displayed to the user. If the bundle is allowed to be displayed to the user, the LBA screen (not shown) may display the bundle to the user, and the indicator (913) may be represented by a string, number sequence, and / or boolean indicating “Yes”. If the bundle is not allowed to be displayed to the user, the LBA screen (not shown) may not display the bundle to the user, and the indicator (913) may be represented by a string, number sequence, and / or boolean indicating “No”.

[0120] The bundle policy (910) may include the types of local or remote management commands received by each bundle ("Command" list, 915). Each remote management command may be represented by a string or sequence of numbers representing the command. In FIG. 9, the local or remote management commands are depicted as five types: "Install," "Enable," "Disable," "Delete," and "Update." However, the types of local or remote management commands that the command types (915) may include are not limited to these and may be extended to various bundle management commands in addition to those described above. Furthermore, while FIG. 9 depicts local or remote management commands as being displayed separately, it is also possible to display one or more local or remote management commands as a group. For example, it is possible to distinguish between commands corresponding to bundle installation and other commands by dividing them into two categories, "Install" and "Etc. or Others," or it is also possible to represent all commands as a single category without distinction by using "All Commands."

[0121] The bundle policy (910) may include a local management configuration ("Local Management" configuration, 917) that indicates detailed settings for local management of the corresponding command according to the classification of the command type (915).

[0122] More specifically, the local management setting (917) may further include an indicator ("Allowed" indicator, 917a) indicating whether each local management command is allowed. If the bundle's local management command is allowed, the indicator (917a) may be represented as a string, number sequence, or boolean indicating "Yes". If the bundle's local management command is not allowed, the indicator (917a) may be represented as a string, number sequence, or boolean indicating "No".

[0123] Additionally, the local management setting (917) may further include an "End User Intent" indicator (917b) indicating whether the execution of each local management command necessarily requires an End User Intent. If the local management command of the bundle must be initiated by the End User, the indicator (917b) may be expressed as a string, number sequence, and / or boolean indicating "Required". If the local management command of the bundle does not necessarily need to be initiated by the user and the terminal can initiate it on its own, the indicator (917b) may be expressed as a string, number sequence, and / or boolean indicating "Not Required". If the local management command of the bundle is not allowed according to the setting of the local management command allow indicator (917a), the indicator (917b) may be expressed as a string, number sequence, or boolean indicating “Not Applicable, N / A”.

[0124] Additionally, the local management setting (917) may further include an indicator ("End User Intent Confirmation" indicator, 917c) indicating whether the execution of each local management command necessarily requires End User Intent Confirmation. If End User Intent Confirmation is required to execute the bundle's local management command, the indicator (917c) may be expressed as a string, number sequence, and / or boolean indicating "Required," and the means of End User Intent Confirmation may be described in more detail as needed. For example, the user may be asked a "Yes / No" question ("Yes or No" in 917c), biometric information such as the user's fingerprint or iris may be entered ("Fingerprint" in 917c), a designated Personal Identification Number (PIN) may be entered ("PIN" in 917c), or various other confirmation means may be utilized. If user intent verification is indicated as "Required" but the means are not specified, or if the terminal cannot use the indicated means for user intent verification, the terminal may arbitrarily select one of the available verification means. If user intent verification is not required for the execution of the bundle's local management command, the indicator (917c) may be expressed as a string, number sequence, and / or boolean indicating "Not Required." If the bundle's local management command is not allowed according to the setting of the local management command allowance indicator (917a), the indicator (917c) may be expressed as a string, number sequence, or boolean indicating "Not Applicable (N / A)."

[0125] The bundle policy (910) may include a remote management configuration ("Remote Management" configuration, 919) that indicates detailed settings for remote management of the corresponding command according to the classification of the command type (915).

[0126] More specifically, the remote management setting (919) may further include an "Allowed" indicator (919a) indicating whether each remote management command is allowed. If the bundle's remote management command is allowed, the indicator (919a) may be represented as a string, number sequence, or boolean indicating "Yes". If the bundle's remote management command is not allowed, the indicator (919a) may be represented as a string, number sequence, or boolean indicating "No".

[0127] Additionally, the remote management setting (919) may further include an "End User Consent" indicator (919b) indicating whether the execution of each remote management command requires End User Consent. If the remote management command of the bundle requires End User Consent, the indicator (919b) may be expressed as a string, number sequence, and / or boolean indicating "Required," and the means of confirming user intent may be indicated in more detail as needed. For example, in a form similar to the example in 917c, the user may be asked a question of "Accept / Reject" ("Accept or Reject" in 919b), biometric information such as the user's fingerprint or iris may be entered ("Fingerprint" in 919b), a designated personal identification number may be entered ("PIN" in 919b), or various other confirmation means may be utilized. If user consent is indicated as "Required" but the means are not specified, or if the terminal cannot use the indicated means of user consent verification, the terminal may arbitrarily select one of the available verification means. If the bundle's remote management command does not require user consent, the indicator (919b) may be expressed as a string, number sequence, and / or boolean indicating "Not Required." If the bundle's remote management command is not allowed according to the setting of the remote management command allow indicator (919a), the indicator (919b) may be expressed as a string, number sequence, or boolean indicating "Not Applicable (N / A)."

[0128] Additionally, the remote management setting (919) may further include a “Subscriber Intent Verification” indicator (919c) indicating whether the execution of each remote management command necessarily requires Subscriber Intent Confirmation. If Subscriber Intent Confirmation is required to execute the remote management command of the bundle, the indicator (919c) may be expressed as a string, a sequence of numbers, and / or a boolean indicating “Required,” and the means of Subscriber Intent Confirmation may be described in more detail as needed. For example, security information such as the subscriber’s secret key may be verified (“Credential Key”) in 919c, a digital signature using the subscriber’s digital certificate may be verified (“Signed Token”) in 919c, or various other verification means may be utilized. If subscriber intent verification is indicated as "Required" but the means are not specified, or if the terminal and / or bundle management server cannot use the indicated means for verifying subscriber intent, the terminal and / or bundle management server may arbitrarily select one of the available verification means. If subscriber intent verification is not required for the execution of the bundle's remote management command, the indicator (919c) may be expressed as a string, number sequence, and / or boolean indicating "Not Required." If the bundle's remote management command is not allowed according to the setting of the remote management command allowance indicator (919a), the indicator (919c) may be expressed as a string, number sequence, or boolean indicating "Not Applicable (N / A)."

[0129] FIG. 10 is a drawing illustrating an example of a procedure in which a terminal (1020) performs bundle local management according to some embodiment of the present disclosure.

[0130] Referring to FIG. 10, a first bundle (1011) may be installed in a terminal (1020). An embodiment of the present disclosure assumes that the first bundle (1011) is currently disabled. The first bundle (1011) may further include a bundle policy (1010). All or part of the bundle policy (1010) may be included not only within the bundle but also in the terminal (1020), LBA (not shown), and / or bundle management server (not shown).

[0131] Since the first bundle (1011) is configured (1013) to be displayed to the user, the first bundle (1011) may be displayed on the terminal's LBA setting screen (1020a) during operation 1021. During operation 1023, the user may attempt to locally activate the first bundle (1011).

[0132] Since the local management setting (1017) of the first bundle (1011) does not require End User Intent Confirmation during the activation operation, the first bundle (1011) can be indicated as activated on the terminal's LBA setting screen (1020b) in the 1025 operation without additional user input after the 1023 operation. In the 1027 operation, the user can attempt to locally deactivate the first bundle (1011).

[0133] Since the local management setting (1017) of the first bundle (1011) does not require End User Intent Confirmation during the deactivation operation, the first bundle can be displayed as deactivated on the terminal's LBA setting screen (1020c) in the 1029 operation without additional user input after the 1025 operation. In the 1031 operation, the user can attempt to locally delete the first bundle (1011).

[0134] Since the local management setting (1017) of the first bundle requires End User Intent Confirmation for the input of a Personal Identification Number (PIN) during the deletion operation, the terminal's LBA setting screen (1020d) may require the user to input a Personal Identification Number during the 1033 operation. During the 1035 operation, the user may input a Personal Identification Number. Of course, the operation of confirming the user's Personal Identification Number during the 1035 operation may be replaced with an operation requiring confirmation such as biometric information like the user's fingerprint / iris or "Yes / No" depending on the setting of the bundle policy (1010).

[0135] If the personal identification number entered by the user in operation 1035 is valid, the terminal can delete the first bundle (1011). Afterward, if there are no bundles remaining on the terminal, the terminal's LBA setting screen (1020e) may not display any bundles.

[0136] FIG. 11 is a drawing illustrating another example of a procedure in which a terminal (1120) performs bundle local management according to some embodiment of the present disclosure.

[0137] Referring to FIG. 11, a second bundle (1111) providing communication services may be installed in the terminal (1120). An embodiment of the present disclosure assumes that the second bundle (1111) is currently disabled. The second bundle (1111) may further include a bundle policy (1110). All or part of the bundle policy (1110) may be included not only within the bundle but also in the terminal (1120), LBA (not shown), and / or bundle management server (1130).

[0138] Since the second bundle (1111) is configured (1113) so that it cannot be displayed to the user, the second bundle (1111) may be hidden from the terminal's LBA setting screen (1120a) during operation 1121. Since the local management setting (1117) of the second bundle (1111) allows the terminal (1120) to locally activate or locally deactivate the second bundle (1111) without user intent, the terminal can locally activate the second bundle (1111) without any input from the user during operation 1123.

[0139] Since the local management setting (1117) of the second bundle (1111) does not require End User Intent Confirmation during the activation operation, the second bundle (1111) may be activated in a hidden state on the terminal's LBA setting screen (1120b) during the 1125 operation without additional user input after the 1123 operation. During the 1127 operation, the terminal (1120) may receive and install the third bundle (11110) from the bundle management server (1130) using the communication service provided by the second bundle (1111). Since the local management setting (1117) of the third bundle does not require End User Intent Confirmation during the bundle installation operation, the installed third bundle may be displayed on the terminal's LBA setting screen (1120b) during the 1129 operation without additional user input after the 1127 operation. In operation 1131, the terminal (1120) can locally disable the second bundle (1111).

[0140] Since the local management setting (1117) of the second bundle (1111) does not require End User Intent Confirmation during the deactivation operation, the second bundle may be disabled in a hidden state on the terminal's LBA setting screen (1120c) during the 1133 operation without additional user input after the 1131 operation.

[0141] FIG. 12 is a diagram illustrating an example of a procedure in which a terminal (1220) according to some embodiment of the present disclosure performs bundle local management and remote management.

[0142] Referring to FIG. 12, a fourth bundle (1211) may be installed in the terminal (1220). An embodiment of the present disclosure assumes that the fourth bundle (1211) is currently enabled. The fourth bundle (1211) may further include a bundle policy (1210). All or part of the bundle policy (1210) may be included not only within the bundle but also in the terminal (1220), LBA (not shown), and / or bundle management server (1230).

[0143] The fourth bundle (1211) may be displayed to the user (1213), but since it is set so that local management is not allowed (1217), the fourth bundle (1211) is displayed on the terminal's LBA setting screen (1220a) in operation 1221, and actions such as deactivation / deletion may be restricted so that the user cannot select them.

[0144] In operation 1223, the service provider (1240) may request the bundle management server (1230) to remotely disable the fourth bundle (1211). In operation 1225, the bundle management server (1230) may request the terminal (1220) to remotely disable the fourth bundle (1211). Since the remote management setting (1219) of the fourth bundle (1211) does not require End User Consent and Subscriber Intent Verification during the disable operation, the fourth bundle (1211) may be displayed as disabled on the terminal's LBA setting screen (1220b) in operation 1227 without any additional action by the bundle management server (1230) or the user after operation 1225.

[0145] In operation 1229, the service provider (1240) may request the bundle management server (1230) to remotely delete the fourth bundle (1211). Since the remote management setting (1219) of the fourth bundle (1211) requires Subscriber Intent Verification to verify the Credential Key during remote deletion, operation 1229 may further include a first key that the bundle management server must verify and / or a second key that the terminal must verify for the remote deletion of the bundle.

[0146] In operation 1231, the bundle management server (1230) can verify the subscriber intent by checking the first key provided by the service provider (1240). If the first key is valid, in operation 1233, the bundle management server (1230) can request the terminal (1220) to remotely delete the fourth bundle (1211). Since the remote management setting (1219) of the fourth bundle (1211) requires subscriber intent verification to verify the credential key during remote deletion, operation 1233 may further include a second key that the terminal must verify for the remote deletion of the bundle. Although FIG. 12 is illustrated as the second key being provided by the service provider (1240), the second key may be generated by the bundle management server (1230) as needed.

[0147] In operation 1235, the terminal (1220) can verify the Subscriber Intent by checking the second key provided by the bundle management server (1230). If the second key is valid, since the remote management setting (1219) of the fourth bundle (1211) requires End User Consent during the remote deletion operation, the terminal's LBA setting screen (1220c) in operation 1237 may request user consent such as "Accept / Reject". Of course, the operation requesting user consent for "Accept / Reject" in operation 1237 can be replaced with an operation requesting verification such as the user's personal identification number or biometric information such as fingerprints or iris scans, depending on the setting of the bundle policy (1210).

[0148] Of course, the operations of verifying the first key and the second key in operations 1231 and 1235, respectively, can be replaced with operations of verifying a digital signature and / or a signed token containing a digital signature, depending on the settings of the bundle policy (1210). Furthermore, subscriber intent verification does not necessarily need to be performed at both the bundle management server (1230) and the terminal (1220), and only one of the verification procedures may be performed as needed. Additionally, operations 1231 and 1235 may include one or more additional message exchanges. For example, if the service provider (1240) does not transmit the first key and / or the second key when a remote deletion request for the fourth bundle (1211) is made in operation 1231, the bundle management server (1230) may request and receive the first key and / or the second key from the service provider (1240) for Subscriber Intent Verification in accordance with the remote management setting (1219). Similarly, if the bundle management server (1230) does not transmit the first key and / or the second key when a remote deletion request for the fourth bundle (1211) is made in operation 1233, the terminal (1220) may request and receive the first key and / or the second key from the bundle management server (1230) for Subscriber Intent Verification in accordance with the remote management setting (1219).

[0149] In operation 1239, the user may agree to the remote deletion of the fourth bundle (1211). Subsequently, the terminal (1220) may remotely delete the fourth bundle (1211). Subsequently, if there are no bundles remaining on the terminal, the terminal's LBA setting screen (1220d) may not display any bundles.

[0150] FIG. 13 is a drawing illustrating another example of a procedure in which a terminal (1320) according to some embodiment of the present disclosure performs bundle local management and remote management.

[0151] Referring to FIG. 13, a fifth bundle (1311) may be installed in the terminal (1320). An embodiment of the present disclosure assumes that the fifth bundle (1311) is currently enabled. The fifth bundle (1311) may further include a bundle policy (1310). All or part of the bundle policy (1310) may be included not only within the bundle but also in the terminal (1320), LBA (not shown), and / or bundle management server (1330).

[0152] The fifth bundle may be displayed to the user (1313) and may be configured to allow only activation and deactivation during local management (1317). In this case, the fifth bundle (1311) is displayed on the LBA setting screen (1320a) of the terminal (1320) in operation 1321, and unlike FIG. 12 which restricts the user from local management operations that are not allowed, it may be displayed as if not only deactivation operations but also deletion operations that are not allowed are allowed to the user. For exception handling regarding this, refer to the description of operation 1339.

[0153] In operation 1323, the service provider (1340) may request the bundle management server (1330) to remotely disable the fifth bundle (1311). In operation 1325, the bundle management server (1330) may request the terminal (1320) to remotely disable the fifth bundle (1311). Since the remote management setting (1319) of the fifth bundle (1311) does not require End User Consent and Subscriber Intent Verification during the remote disable operation, the fifth bundle may be displayed as disabled on the terminal's LBA setting screen (1320b) in operation 1327 without any additional action by the bundle management server (1330) or the user after operation 1325.

[0154] In operation 1329, the service provider (1340) may request the bundle management server (1330) to remotely delete the fifth bundle (1311). In operation 1331, the bundle management server (1330) may request the terminal (1320) to remotely delete the fifth bundle (1311). Since the remote management setting (1319) of the fifth bundle (1311) does not allow the remote deletion operation, the terminal may refuse the remote deletion of the fifth bundle (1311) in operation 1333. Additionally, although FIG. 13 illustrates the terminal (1320) performing the refusal of the remote management command, it should be noted that if the bundle management server (1330) is aware of the bundle policy and the status of the bundle, the bundle management server (1330) may refuse the remote management command request in operation 1329. If the bundle management server (1330) rejects the remote management command, it goes without saying that there is no need to perform the 1333 operation unnecessarily.

[0155] Since the remote deletion of the 5th bundle (1311) was denied, the 5th bundle (1311) may still be displayed as disabled on the terminal's LBA settings screen (1320c) during operation 1335. During operation 1337, the user may attempt to delete the 5th bundle (1311) locally.

[0156] Since the local management setting (1317) of the 5th bundle (1311) does not allow local deletion, the terminal's LBA setting screen (1320d) in operation 1339 can indicate to the user that deletion of the 5th bundle (1311) is not allowed.

[0157] In the 1329, 1333, or 1339 operations of FIG. 13, the operation in which the bundle management server (1330) or terminal (1320) rejects the local or remote management command of the bundle is described as a case where the local or remote management command of the bundle policy (1310) is not permitted; however, it should be noted that the operation of rejecting the local or remote management command of the bundle can be performed in the same way even if the End User Confirmation, End User Consent, and / or Subscriber Intent Verification fails as a result of verification of the bundle policy (1310). For example, even if the key verification of the 1231 or 1235 operations of FIG. 12 fails, the remote management command can be rejected as in the 1333 or 1335 operations of FIG. 13. As another example, in the case where the user's personal identification number verification fails in operation 1033 of Fig. 10, the local management command can be rejected as in operation 1339.

[0158] In the above embodiments, the bundle policy is depicted as information stored in each bundle, but all or part of the bundle policy may be stored in a terminal (more specifically, an SSP, a loader, or an LBA, etc.) as needed. For example, among the bundle policies, the means for End User Intent Confirmation and End User Consent may be stored in the LBA, the means for local management and remote management command permission and Subscriber Intent Verification may be stored in the SSP, and the remaining bundle policies may be stored in the bundle. When all or part of a bundle policy is stored in both the terminal and the bundle, if the bundle policy stored in the terminal and the bundle policy stored in the bundle are different from each other, the terminal may reject the installation of the bundle, accept the installation but prioritize the bundle policy stored in the terminal over the bundle policy stored in the bundle when applying the bundle policy, or accept the installation but prioritize the bundle policy stored in the bundle over the bundle policy stored in the terminal when applying the bundle policy.

[0159] Furthermore, when means for End User Intent Confirmation, End User Consent, or Subscriber Intent Verification are specified within a bundle policy, such means may not necessarily be input methods supported by the terminal, bundle management server, and / or service provider. For example, a bundle policy may exist that requires fingerprint input for End User Consent for a terminal without a fingerprint reader. As another example, a bundle policy may exist that requires a digital certificate and a digital signature for Subscriber Intent Verification for a service provider without a digital certificate. In such cases where the functions of the terminal, bundle management server, and / or service provider conflict with the requirements of the bundle policy, the terminal or bundle management server may reject the execution of the bundle policy, consider it an unconditional success, or use other means to substitute the execution of the bundle policy. For example, in an example such as the above terminal, the terminal may replace fingerprint input with Personal Identification Number (PIN) code input, or the bundle management server may replace digital signatures with security information (Credential Key). In addition, to prevent cases where the functions of the terminal, bundle management server, and / or service provider conflict with the bundle policy, the functional details of the terminal, bundle management server, and / or service provider may be referenced when setting the bundle policy. For example, as part of the operation of installing an arbitrary bundle, the terminal, bundle management server, and service provider may negotiate and identify each other's functions in advance and set the bundle policy to use means that each supports. Refer to the description in FIGS. 14a and 14b for such an example.

[0160] FIG. 14a is a diagram illustrating an example of a procedure in which a terminal (1420), a service provider (1430), and a bundle management server (1440) set a bundle policy through function negotiation according to some embodiments of the present disclosure.

[0161] Referring to FIG. 14a, in operation 14001, the user (1450) can subscribe to the service of the service provider (1430).

[0162] In operation 14003, the service provider (1430) and the bundle management server (1440) can generate information for downloading any bundle.

[0163] In operation 14005, the service provider (1430) can reply to the user (1450) with information for downloading the bundle.

[0164] In operation 14007, the user (1450) can enter bundle download information into the LBA (1410).

[0165] In operation 14009, the bundle management server (1440) and the service provider (1430) may perform digital certificate and function negotiation. More specifically, in operation 14009, the bundle management server (1440) and the service provider (1430) may exchange information on a digital certificate (CI Certificate) to be used in the bundle download and installation process, and exchange means of verification that can be used for End User Intent Confirmation, End User Consent, and Subscriber Intent Verification. Operation 14009 may be performed immediately after operation 14003 or integrated with operation 14003 as needed.

[0166] In operation 14011, the LBA (1410) and SSP (1420) within the terminal (1400) can perform digital certificate and function negotiation with the bundle management server (1440). More specifically, in operation 14011, the terminal (1400) and the bundle management server (1440) can exchange information on a digital certificate (CI Certificate) to be used in the bundle download and installation procedure, and exchange verification means that can be used for End User Intent Confirmation, End User Consent, and Subscriber Intent Verification. Operation 14011 does not necessarily need to be performed separately from operation 14009, and operations 14009 and 14011 may be performed together as needed.

[0167] In operation 14013, the terminal (1400), the bundle management server (1440), and the service provider (1450) may prepare a bundle policy. All or part of the bundle policy may be stored in the bundle, stored in the LBA (1410), stored in the SSP (1420), or stored in the bundle management server (1440). Operation 14013 does not necessarily have to be performed after operation 14011, and part of operation 14013 may be performed immediately after operation 14009 or integrated with operation 14009 as needed. For example, it is possible to set the remote management policy among the bundle policies after the function negotiation between the bundle management server (1440) and the service provider (1430), and to set the local management policy among the bundle policies after the function negotiation between the terminal (1400) and the bundle management server (1440).

[0168] In operation 14015, the terminal (1400), bundle management server (1440), and service provider (1450) can start downloading the bundle.

[0169] FIG. 14b is a drawing illustrating an example of another procedure in which a terminal (1420), a bundle management server (1430), and a service provider (1440) set a bundle policy through function negotiation according to some embodiments of the present disclosure.

[0170] Referring to FIG. 14b, in operation 14101, the user (1450) can subscribe to the service of the service provider (1430). In operation 14101, the user (1450), although not shown in the drawing, can obtain functional information of the terminal (1400) from the terminal and transmit the functional information of the terminal (1400) to the service provider (1430) simultaneously with the service subscription. The functional information of the terminal (1400) may further include information regarding a verification means that the terminal can use for End User Intent Confirmation, End User Consent, and Subscriber Intent Verification. Additionally, while FIG. 14b illustrates that the user directly transmits the functional information of the terminal (1400) to the service provider (1430), it is also possible for the terminal (1400) to directly transmit the functional information of the terminal (1400) to the service provider (1430) or the bundle management server (1440). For example, when a user (1450) uses the terminal (1400) to access the service provider (1430) or the bundle management server (1440) and subscribes to the service of the service provider (1430), the terminal (1400) may transmit the functional information of the terminal (1400) to the service provider (1430) or the bundle management server (1440) as part of the service subscription process.

[0171] In operation 14103, the bundle management server (1440) and the service provider (1430) may perform digital certificate and function negotiation. More specifically, in operation 14103, the bundle management server (1440) and the service provider (1430) may exchange information on a digital certificate (CI Certificate) to be used in the bundle download and installation procedure, and exchange verification means that can be used for End User Intent Confirmation, End User Consent, and Subscriber Intent Verification. Operation 14103 may further include terminal function information received from the user (1450) in operation 14101. Operation 14103 may be performed in conjunction with operation 14105 as needed.

[0172] In operation 14105, the terminal (1400), the bundle management server (1440), and the service provider (1450) can prepare a bundle policy. All or part of the bundle policy may be stored in the bundle, stored in the LBA (1410), stored in the SSP (1420), or stored in the bundle management server (1440).

[0173] In operation 14107, the service provider (1430) and the bundle management server (1440) may generate information for downloading any bundle. Operation 14107 may be performed before operation 14105 or integrated with operation 14105 as needed.

[0174] In operation 14109, the service provider (1430) can reply to the user (1450) with information for downloading the bundle.

[0175] In operation 14111, the user (1450) can enter bundle download information into the LBA (1410).

[0176] In operation 14113, the LBA (1410) and SSP (1420) within the terminal (1400) can perform digital certificate and function negotiation with the bundle management server (1440). More specifically, in operation 14113, the terminal (1400) and the bundle management server (1440) can exchange digital certificate (CI Certificate) information to be used in the bundle download and installation procedure, and exchange verification means that can be used for End User Intent Confirmation, End User Consent, and Subscriber Intent Verification. If necessary, all or part of operation 14113 may be performed in conjunction with operation 14101 or operation 14103.

[0177] In operation 14115, the terminal (1400), bundle management server (1440), and service provider (1450) can start downloading the bundle.

[0178] According to an embodiment of the present disclosure, a terminal and a bundle management server may set a bundle policy in accordance with their functions. Additionally, when performing local or remote management of a predetermined bundle, they may verify the consent or permission of a user and / or service subscriber in accordance with the bundle policy, and accept or reject the local or remote management.

[0179] FIG. 15 is a drawing illustrating the configuration of a terminal (1500) according to some embodiment of the present disclosure.

[0180] As illustrated in FIG. 15, the terminal may include a transceiver (1510) and at least one processor (1520). Additionally, the terminal may include an SSP (1530). For example, the rSSP (1530) may be inserted into the terminal and may be an eSSP or iSSP embedded in the terminal. At least one processor (1520) may be referred to as a control unit.

[0181] However, the configuration of the terminal is not limited to FIG. 15 and may include more or fewer components than those shown in FIG. 15. According to some embodiments, the transceiver (1510), at least one processor (1520), and memory (not shown) may be implemented in the form of a single chip. Additionally, if an SSP (1530) is embedded, it may be implemented in the form of a single chip including the SSP (1530).

[0182] According to some embodiments, the transceiver (1510) may transmit and receive signals, information, data, etc. according to various embodiments of the present disclosure with a bundle management server. The transceiver (1510) may be composed of an RF transmitter that up-converts and amplifies the frequency of a transmitted signal, and an RF receiver that low-noise amplifies a received signal and down-converts the frequency. However, this is merely one embodiment of the transceiver (1510), and the components of the transceiver (1510) are not limited to an RF transmitter and an RF receiver. Additionally, the transceiver (1510) may receive a signal through a wireless channel and output it to at least one processor (1520), and transmit the signal output from at least one processor (1520) through a wireless channel.

[0183] According to some embodiments, the transmitting and receiving unit (1510) may receive at least a message related to bundle installation from a bundle management server, or receive a message including a request for bundle remote management. Additionally, the transmitting and receiving unit (1510) may transmit bundle installation results or bundle remote management results.

[0184] Meanwhile, at least one processor (1520) is a component for controlling the terminal overall. The processor (1520) can control the overall operation of the terminal according to various embodiments of the present disclosure as described above.

[0185] According to some embodiments, the processor (1520) can determine whether the SSP (1530) can process the received bundle package or bundle remote management command by comparing it with the bundle policy, input the bundle package or bundle remote management command to the SSP (1530), install or manage the bundle in the SSP (1530), and generate a bundle installation result or a remote management result.

[0186] Additionally, according to one embodiment, one or more processors (1520) can determine whether an SSP (1530) can process a bundle local management command received from a user by comparing it with a bundle policy, input the bundle local management command to the SSP (1530), install or manage the bundle in the SSP (1530), and generate a local management result.

[0187] Additionally, according to some embodiments, one or more processors (1520) can control a transceiver (1510) to receive a bundle or a bundle remote management command from a profile server, install a bundle or process a bundle remote management command, and transmit a bundle installation result or a remote management result to a bundle management server.

[0188] According to various embodiments, the SSP (1530) can download and install bundles. Additionally, the SSP (1530) can manage bundles and bundle policies.

[0189] Additionally, according to some embodiments, the SSP (1530) may operate under the control of the processor (1520). Alternatively, the SSP (1530) may include a processor or controller for installing bundles, or may have an application installed. Part of the application may be installed on the processor (1520).

[0190] Meanwhile, the terminal may further include memory (not shown) and may store data such as basic programs, application programs, and setting information for the operation of the terminal. In addition, the memory may include at least one storage medium among Flash Memory Type, Hard Disk Type, Multimedia Card Micro Type, Card Type Memory (e.g., SD or XD memory, etc.), Magnetic Memory, Magnetic Disk, Optical Disk, Random Access Memory (RAM), Static Random Access Memory (SRAM), Read-Only Memory (ROM), Programmable Read-Only Memory (PROM), and Electrically Erasable Programmable Read-Only Memory (EEPROM). In addition, the processor (1520) may perform various operations using various programs, content, data, etc. stored in the memory.

[0191] FIG. 16 is a drawing illustrating the components of a bundle management server (1600) according to one embodiment of the present invention.

[0192] According to some embodiments, the bundle management server (1600) may include a transceiver (1610) and at least one processor (1620). However, the configuration of the bundle management server (1600) is not limited to FIG. 16 and may include more or fewer components than those shown in FIG. 16. According to some embodiments, the transceiver (1610), at least one processor (1620), and memory (not shown) may be implemented in the form of a single chip.

[0193] According to some embodiments, the transceiver (1610) may transmit and receive signals, information, data, etc. according to various embodiments of the present invention to and from the terminal (1500). For example, the transceiver (1610) may transmit and / or receive bundle information or information related to bundle remote management to and from the terminal.

[0194] The transceiver (1610) may be composed of an RF transmitter that up-converts and amplifies the frequency of a transmitted signal, and an RF receiver that low-noise amplifies a received signal and down-converts the frequency. However, this is merely one embodiment of the transceiver (1610), and the components of the transceiver (1610) are not limited to an RF transmitter and an RF receiver. Additionally, the transceiver (1610) may receive a signal through a wireless channel and output it to at least one processor (1620), and transmit the signal output from at least one processor (1620) through a wireless channel.

[0195] According to one embodiment, the transmitting and receiving unit (1610) can receive a bundle download request message or a bundle remote management request message from the terminal (1500).

[0196] Additionally, a bundle download request message or a bundle remote management request message according to one embodiment may include information about a terminal (1500) and / or an SSP (1530), and may further include all or part of bundle information or bundle policy information.

[0197] For example, a transmitting and receiving unit (1610) according to one embodiment can transmit a bundle installation package or a bundle remote management command to a terminal (1500).

[0198] In addition, a bundle installation package or a bundle remote management command according to one embodiment may further include all or part of bundle information or bundle policy information.

[0199] Meanwhile, at least one processor (1620) is a component for controlling the bundle management server (1600) overall. The processor (1620) can control the overall operation of the bundle management server (1600) according to an embodiment of the present disclosure as described above.

[0200] For example, at least one processor (1620) according to one embodiment may determine a bundle policy based on information about the terminal (1500) and / or SSP (1530) received from the terminal (1500), and control the transceiver (1620) to transmit a bundle installation package or a bundle remote management command to the terminal (1500) based on the bundle policy.

[0201] Meanwhile, the bundle management server (1600) may further include memory (not shown) and may store data such as basic programs, application programs, and configuration information for the operation of the profile providing server (1600). In addition, the memory may include at least one storage medium among Flash Memory Type, Hard Disk Type, Multimedia Card Micro Type, Card Type Memory (e.g., SD or XD memory, etc.), Magnetic Memory, Magnetic Disk, Optical Disk, RAM (Random Access Memory), SRAM (Static Random Access Memory), ROM (Read-Only Memory), PROM (Programmable Read-Only Memory), and EEPROM (Electrically Erasable Programmable Read-Only Memory). In addition, the processor (1620) may perform various operations using various programs, content, data, etc. stored in the memory.

[0202] In the specific embodiments of the present disclosure described above, the components included in the disclosure are expressed in a singular or plural form according to the specific embodiments presented. However, the singular or plural expression is selected to suit the situation presented for convenience of explanation, and the present disclosure is not limited to singular or plural components; even if a component is expressed in the plural form, it may be composed of a singular form, and even if a component is expressed in the singular form, it may be composed of a plural form.

[0203] Meanwhile, although specific embodiments have been described in the detailed description of the present disclosure, it is understood that various modifications are possible within the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be defined by the claims set forth below as well as equivalents thereof.

[0204] The various embodiments of the present disclosure and the terms used therein are not intended to limit the technology described in the present disclosure to specific embodiments and should be understood to include various modifications, equivalents, and / or substitutions of such embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar components. A singular expression may include a plural expression unless the context clearly indicates otherwise. In the present disclosure, expressions such as "A or B," "at least one of A and / or B," "A, B or C," or "at least one of A, B and / or C" may include all possible combinations of items listed together. Expressions such as "first," "second," "first," or "second" may modify the components, regardless of order or importance, and are used only to distinguish one component from another and do not limit the components. Where it is stated that a certain (e.g., first) component is "(functionally or telecommunicationally) connected" or "connected" to another (e.g., second) component, said certain component may be directly connected to said other component or connected through another component (e.g., third component).

[0205] As used in this disclosure, the term "module" includes a unit composed of hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be a component formed integrally, or a minimum unit or part thereof that performs one or more functions. For example, a module may be composed of an application-specific integrated circuit (ASIC).

[0206] Various embodiments of the present disclosure may be implemented as software (e.g., a program) containing instructions stored in a machine-readable storage medium (e.g., internal memory or external memory) that is readable by a machine (e.g., a computer). The machine may include a terminal (250) according to various embodiments, which is a device capable of calling instructions stored from the storage medium and operating according to the called instructions. When the instructions are executed by a processor (e.g., the processor (1520) of FIG. 15), the processor may perform a function corresponding to the instructions directly or using other components under the control of the processor. The instructions may include code generated or executed by a compiler or an interpreter.

[0207] A device-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' means merely that the storage medium does not contain a signal and is tangible, without distinguishing whether data is stored semi-permanently or temporarily on the storage medium.

[0208] Methods according to the various embodiments disclosed herein may be provided as included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed online in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or through an application store (e.g., Play Store™). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created in a storage medium such as the memory of a manufacturer's server, an application store's server, or a relay server. Each component (e.g., a module or program) according to the various embodiments may be composed of a singular or multiple entities, and some of the aforementioned sub-components may be omitted, or other sub-components may be further included in the various embodiments. Generally or additionally, some components (e.g., a module or program) may be integrated into a single entity to perform the same or similar functions as those performed by each of the respective components prior to integration. Operations performed by a module, program, or other component according to various embodiments may be executed sequentially, in parallel, iteratively, or heuristically, or at least some operations may be executed in a different order, omitted, or other operations may be added.

Claims

Claim 1 A method for operating a terminal in a wireless communication system, comprising: a step of identifying whether user consent is required to perform remote management of at least one Secondary Platform Bundle (SPB); a step of identifying user consent for remote management of said at least one SPB by performing a user consent verification operation based on the identification that user consent is required; and a step of performing remote management of said at least one SPB based on the user consent for remote management of said at least one SPB. Claim 2 A method according to claim 1, wherein the step of identifying user consent for remote management of at least one SPB by performing the user consent verification operation comprises: a step of outputting a screen for user consent verification; and a step of identifying a user input indicating whether user consent for remote management of at least one SPB. Claim 3 A method according to claim 1, wherein the step of identifying user consent for remote management of at least one SPB by performing the user consent verification operation comprises identifying user consent for remote management of at least one SPB based on at least one of user biometric information input or user identification information input. Claim 4 A method according to claim 1, wherein the remote management of the at least one SPB comprises at least one of the installation of the at least one SPB, the activation of the at least one SPB, the deactivation of the at least one SPB, or the deletion of the at least one SPB. Claim 5 A method according to claim 1, further comprising the step of transmitting the result of remote management of at least one SPB to a receiving end associated with at least one SPB. Claim 6 A method according to claim 1, further comprising the step of receiving a remote management command for the at least one SPB from a bundle management server associated with the at least one SPB. Claim 7 A method according to claim 1, wherein the download of at least one SPB is initiated remotely by a bundle management server associated with at least one SPB. Claim 8 An electronic device comprising: a transceiver; and at least one processor connected to the transceiver in a wireless communication system, wherein the at least one processor identifies whether user consent is required to perform remote management of at least one Secondary Platform Bundle (SPB), identifies user consent for remote management of the at least one SPB by performing a user consent verification operation based on identifying that user consent is required, and performs remote management of the at least one SPB based on user consent for remote management of the at least one SPB. Claim 9 In paragraph 8, the electronic device wherein at least one processor outputs a screen for confirming user consent and identifies a user input indicating whether the user consents to the remote management of at least one SPB. Claim 10 In claim 8, the electronic device wherein the at least one processor identifies user consent for remote management of the at least one SPB based on at least one of user biometric information input or user identification information input. Claim 11 An electronic device according to claim 8, wherein the remote management of the at least one SPB comprises at least one of the installation of the at least one SPB, the activation of the at least one SPB, the deactivation of the at least one SPB, or the deletion of the at least one SPB. Claim 12 In paragraph 8, the electronic device wherein the at least one processor transmits the result of remote management of the at least one SPB to a receiving end associated with the at least one SPB. Claim 13 In paragraph 8, the electronic device wherein the at least one processor receives a remote management command for the at least one SPB from a bundle management server associated with the at least one SPB. Claim 14 An electronic device, wherein the download of at least one SPB is initiated remotely by a bundle management server associated with at least one SPB in paragraph 8.