Method and device for processing terminal and server for providing profile movement
The method and device enable efficient remote management and transfer of UICC profiles, addressing the inconvenience of physical SIM card acquisition and roaming by allowing seamless profile installation and reinstallation across terminals using OTA technology.
Patent Information
- Application Number
- PCT/KR2025/001201
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-30
- Filing Date
- 2025-01-22
- Publication Date
- 2025-08-07
AI Technical Summary
Existing mobile communication systems face challenges in efficiently managing and transferring UICC profiles, particularly eUICC profiles, across different terminals, leading to inconvenience when users need to access services from multiple carriers or switch devices, as physical SIM card acquisition and roaming can be cumbersome and expensive.
A method and device for a terminal to request and manage UICC profiles, including eUICC profiles, through a profile server, enabling remote downloading, installation, and management of profiles, allowing seamless transfer and reinstallation across terminals using Over-The-Air (OTA) technology.
Facilitates convenient and cost-effective access to multiple carrier services by allowing users to remotely download and select SIM modules, reducing the need for physical SIM cards and minimizing costs associated with roaming.
Smart Images

Figure KR2025001201_07082025_PF_FP_ABST
Abstract
Description
Processing method and device of terminal and server for providing profile transfer
[0001] The present invention relates to a method and device for installing and managing an embedded universal integrated circuit card (eUICC) profile.
[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in the sub-6GHz frequency band such as 3.5 gigahertz (3.5GHz), but also in the ultra-high frequency band called millimeter wave (mmWave) such as 28GHz and 39GHz ('Above 6GHz'). In addition, for 6G mobile communication technology, which is called the system after 5G communication (Beyond 5G), implementation in the terahertz band (for example, the 3 terahertz (3THz) band at 95GHz) is being considered to achieve a transmission speed that is 50 times faster than 5G mobile communication technology and an ultra-low latency time that is reduced to one-tenth.
[0003] In the early stages of 5G mobile communication technology, the goal is to support services and satisfy performance requirements for enhanced Mobile Broadband (eMBB), Ultra-Reliable Low-Latency Communications (URLLC), and massive Machine-Type Communications (mMTC). These include beamforming and massive MIMO to mitigate path loss of radio waves in ultra-high frequency bands and increase the transmission distance of radio waves, support for various numerologies (such as operation of multiple subcarrier intervals) and dynamic operation of slot formats for efficient use of ultra-high frequency resources, initial access technology to support multi-beam transmission and wideband, definition and operation of BWP (Bidth Part), new channel coding methods such as LDPC (Low Density Parity Check) codes for large-capacity data transmission and Polar Code for reliable transmission of control information, and L2 pre-processing (L2). Standardization has been made for network slicing, which provides dedicated networks specialized for specific services, and pre-processing.
[0004] Currently, discussions are underway to improve and enhance the initial 5G mobile communication technology in consideration of the services that 5G mobile communication technology was intended to support, and physical layer standardization is in progress for technologies such as V2X (Vehicle-to-Everything) to help autonomous vehicles make driving decisions and increase user convenience based on their own location and status information transmitted by vehicles, NR-U (New Radio Unlicensed) for the purpose of system operation that complies with various regulatory requirements in unlicensed bands, NR terminal low power consumption technology (UE Power Saving), Non-Terrestrial Network (NTN), which is direct terminal-satellite communication to secure coverage in areas where communication with terrestrial networks is impossible, and Positioning.
[0005] In addition, standardization of wireless interface architecture / protocols is in progress for technologies such as intelligent factories (Industrial Internet of Things, IIoT) to support new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) that provides nodes for expanding network service areas by integrating wireless backhaul links and access links, Mobility Enhancement technology including Conditional Handover and Dual Active Protocol Stack (DAPS) handover, and 2-step random access (2-step RACH for NR) that simplifies random access procedures. Standardization is also in progress for system architecture / services such as 5G baseline architecture (e.g., Service-based Architecture, Service-based Interface) for grafting Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) that provides services based on the location of the terminal.
[0006] Once these 5G mobile communication systems are commercialized, an explosive increase in connected devices will be connected to the communication network, necessitating enhanced functionality and performance of 5G mobile communication systems and integrated operation of these connected devices. To this end, new research will be conducted on improving 5G performance and reducing complexity, supporting AI services, supporting metaverse services, and drone communications by utilizing eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).
[0007] In addition, the development of these 5G mobile communication systems includes new waveforms to ensure coverage in the terahertz band of 6G mobile communication technology, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), Array Antenna, and Large Scale Antenna, metamaterial-based lenses and antennas to improve the coverage of terahertz band signals, high-dimensional spatial multiplexing technology using Orbital Angular Momentum (OAM), Reconfigurable Intelligent Surface (RIS) technology, as well as full duplex technology to improve the frequency efficiency and system network of 6G mobile communication technology, satellite, AI (Artificial Intelligence) from the design stage and AI-based communication technology that realizes system optimization by internalizing end-to-end AI support functions, and ultra-high-performance communication and computing resources to provide services with complexity that exceeds the limits of terminal computing capabilities. It can serve as a basis for the development of next-generation distributed computing technologies that can be realized by utilizing them.
[0008] Meanwhile, as mobile communication systems have developed and become capable of providing a variety of services, there is a growing need for methods to effectively provide these services.
[0009] The purpose of the present invention is to effectively provide a service in a mobile communication system.
[0010] According to one embodiment disclosed in the present invention, an object is to provide a method and device for a terminal in a communication system to select a communication service and connect to a network.
[0011] According to one embodiment disclosed in the present invention, a method and device for downloading, installing and managing a profile for a terminal to connect to a network online in a communication system are provided.
[0012] According to one embodiment disclosed in the present invention, an object is to provide a method and device for efficiently re-downloading a profile installed by a terminal to connect to a network in a communication system to the same or another terminal.
[0013] According to one embodiment disclosed in the present invention, it is an object of the present invention to provide a method and device for requesting and receiving an activation code from a profile server so that a terminal in a communication system can efficiently re-download a profile installed by the terminal to connect to a network to the same or another terminal.
[0014] The technical problems to be achieved in the present invention are not limited to the technical problems mentioned above, and other technical problems not mentioned can be clearly understood by a person having ordinary skill in the technical field to which the present invention belongs from the description below.
[0015] In order to solve the above problem, according to one embodiment of the present disclosure, a method performed by a terminal in a wireless communication system may include the steps of transmitting a request message including a request for confirmation as to whether an activation code for re-downloading of a first profile installed in the terminal can be obtained to a profile server, and receiving, from the profile server, a response message including information indicating whether an activation code for re-downloading of a profile installed in the terminal can be obtained as a response to the request message.
[0016] Meanwhile, according to another embodiment of the present disclosure, a method performed by a profile server in a wireless communication system may include the steps of receiving, from a terminal, a request message including a request for confirmation as to whether an activation code for re-downloading a first profile installed in the terminal can be obtained, and transmitting, to the terminal, as a response to the request message, a response message including information indicating whether an activation code for re-downloading a profile installed in the terminal can be obtained.
[0017] Meanwhile, according to another embodiment of the present disclosure, in a wireless communication system, a terminal may include a control unit that transmits a request message including a request for confirmation of whether an activation code for re-downloading of a first profile installed in the terminal can be obtained to a profile server through the transceiver and the transceiver, and receives a response message including information indicating whether an activation code for re-downloading of a profile installed in the terminal can be obtained from the profile server as a response to the request message.
[0018] Meanwhile, according to another embodiment of the present disclosure, in a wireless communication system, a profile server may include a control unit that receives, through the transceiver unit, a request message including a request for confirmation of whether an activation code for re-downloading of a first profile installed in the terminal can be obtained from the transceiver unit and a terminal, and transmits, to the terminal, a response message including information indicating whether an activation code for re-downloading of a profile installed in the terminal can be obtained as a response to the request message.
[0019] According to an embodiment of the present invention, a service can be effectively provided in a mobile communication system.
[0020] According to one embodiment of the present invention, in a communication system, when a terminal wishes to reinstall a profile installed on the terminal on the same or another terminal, the terminal may request and receive confirmation from the profile server whether an activation code required for reinstalling the profile can be issued.
[0021] According to one embodiment of the present invention, in a communication system, when a profile server receives a request from a terminal to check whether an activation code required for reinstalling a profile installed in the terminal can be issued from the profile server to the same or another terminal, the profile server can transmit to the terminal whether an activation code for reinstalling the profile can be issued.
[0022] The effects that can be obtained from the present invention are not limited to the effects mentioned above, and other effects not mentioned can be clearly understood by a person having ordinary skill in the art to which the present disclosure pertains from the description below.
[0023] FIG. 1 is a diagram illustrating a method for connecting a terminal to a mobile communication network using a UICC (Universal Integrated Circuit Card) equipped with a fixed profile according to one embodiment of the present disclosure.
[0024] FIG. 2 is a diagram illustrating a configuration of a system in which a terminal manages a profile installed in a first terminal and installs a profile in a second terminal according to a user's input according to an embodiment of the present disclosure.
[0025] FIG. 3 is a diagram illustrating an example of a procedure between a first terminal and a server for checking whether the first terminal and the profile server provide a function (Activation Code Retrieval) for requesting and obtaining an activation code from a profile server for re-downloading a profile installed on the first terminal to the first terminal or the second terminal according to one embodiment of the present disclosure.
[0026] FIG. 4 is a diagram illustrating an example of a procedure between a first terminal, a second terminal, and a profile server for checking whether a specific profile installed on a first terminal (410) according to one embodiment of the present disclosure can be re-downloaded to the first terminal or the second terminal through a profile server (430).
[0027] FIG. 5 is a diagram illustrating an example of a procedure between a first terminal, a second terminal, and a profile server for checking whether a specific profile installed on a first terminal (410) according to one embodiment of the present disclosure can be re-downloaded to the first terminal or the second terminal through a profile server (430).
[0028] FIG. 6 is a block diagram illustrating components of a terminal according to an embodiment of the present disclosure.
[0029] FIG. 7 is a block diagram illustrating components of a profile server according to one embodiment of the present disclosure.
[0030] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.
[0031] In describing the embodiments, descriptions of technical details that are well known in the technical field to which the present disclosure pertains and are not directly related to the present disclosure will be omitted. This is to more clearly convey the gist of the present disclosure without obscuring it by omitting unnecessary explanations.
[0032] For the same reason, some components in the attached drawings are exaggerated, omitted, or schematically depicted. Furthermore, the dimensions of each component do not entirely reflect its actual size. Identical or corresponding components in each drawing are assigned the same reference numbers.
[0033] The advantages and features of the present disclosure, and methods for achieving them, will become clearer with reference to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided only to ensure that the disclosure is complete and to fully inform those skilled in the art of the scope of the disclosure, and the present disclosure is defined only by the scope of the claims. Like reference numerals designate like elements throughout the disclosure.
[0034] At this time, it will be understood that each block of the processing flowchart drawings and combinations of the flowchart drawings can be performed by computer program instructions. These computer program instructions can be installed in a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, so that the instructions executed by the processor of the computer or other programmable data processing equipment create a means for performing the functions described in the flowchart block(s). These computer program instructions can also be stored in a computer-available or computer-readable storage medium that can direct a computer or other programmable data processing equipment to implement the function in a specific manner, so that the instructions stored in the computer-available or computer-readable storage medium can also produce a manufactured item that includes an instruction means for performing the functions described in the flowchart block(s). Since the computer program instructions may be installed on a computer or other programmable data processing device, a series of operational steps may be performed on the computer or other programmable data processing device to create a computer-executable process, and the instructions that cause the computer or other programmable data processing device to perform the steps for performing the functions described in the flowchart block(s) may also provide steps for performing the functions described in the flowchart block(s).
[0035] Additionally, each block may represent a module, segment, or portion of code that contains one or more executable instructions for performing a specific logical function(s). It should also be noted that in some alternative implementation examples, the functions described in the blocks may occur out of order. For example, two blocks depicted in succession may actually be executed substantially concurrently, or the blocks may sometimes be executed in reverse order, depending on their respective functions.
[0036] Here, the term '~ unit' used in the present embodiment means a software or hardware component such as an FPGA or ASIC, and the '~ unit' performs certain roles. However, the '~ unit' is not limited to software or hardware. The '~ unit' may be configured to be on an addressable storage medium and may be configured to play one or more processors. Accordingly, as an example, the '~ unit' includes components such as software components, object-oriented software components, class components, and task components, processes, functions, properties, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and '~ units' may be combined into a smaller number of components and '~ units' or further separated into additional components and '~ units'. Additionally, components and '~parts' may be implemented to regenerate one or more CPUs within a device or secure multimedia card.
[0037] Certain terms used in the following description are provided to aid in understanding the present disclosure, and the use of such specific terms may be changed to other forms without departing from the technical spirit of the present disclosure.
[0038] A UICC (Universal Integrated Circuit Card) is a smart card inserted into mobile terminals and other devices, also known as a UICC card. A UICC may include an access control module that allows the terminal to connect to a mobile carrier's network. Examples of such access control modules include the Universal Subscriber Identity Module (USIM), the Subscriber Identity Module (SIM), and the IP Multimedia Service Identity Module (ISIM). A UICC containing a USIM is commonly referred to as a USIM card. Similarly, a UICC containing a SIM module is commonly referred to as a SIM card.
[0039] Among UICC cards, a UICC that is fixed to a terminal and used is called an eUICC (embedded UICC). Typically, an eUICC refers to a UICC card that is fixed to a terminal and allows remote download and selection of SIM modules. Furthermore, the downloaded SIM module information is collectively referred to as an eUICC profile, or more simply, a profile.
[0040] In this disclosure, a UICC (Universal Integrated Circuit Card) is a smart card inserted into a mobile communication terminal, etc. and is also called a UICC card.
[0041] UICC is a chip that stores personal information such as network access authentication information, phone book, and SMS of mobile subscribers, and performs subscriber authentication and traffic security key generation when connecting to mobile networks such as GSM, WCDMA, and LTE, thereby enabling secure use of mobile communications.
[0042] A UICC may include communication applications or access control modules for a terminal to access a mobile carrier's network. Examples of such communication applications or access control modules include the Universal Subscriber Identity Module (USIM), the Subscriber Identity Module (SIM), and the IP Multimedia Service Identity Module (ISIM). Furthermore, the UICC can provide high-level security functions for various application programs, such as e-wallets, ticketing, and e-passports.
[0043] A UICC containing a USIM is commonly referred to as a USIM card. Similarly, a UICC containing a SIM module is commonly referred to as a SIM card.
[0044] In the present disclosure, the terms "SIM card," "UICC card," "USIM card," and "UICC including ISIM" may be used with the same or similar meanings. For example, the contents of the present disclosure may be equally applicable to a SIM card, a USIM card, an ISIM card, or a general UICC card.
[0045] SIM cards store the personal information of mobile subscribers and perform subscriber authentication and traffic security key generation when connecting to mobile networks, enabling secure mobile communication use.
[0046] Typically, SIM cards are manufactured as dedicated cards for a specific mobile carrier at the request of that carrier, and authentication information for accessing that carrier's network, such as the USIM (Universal Subscriber Identity Module) application and IMSI (International Mobile Subscriber Identity), K value, and OPc value, are pre-loaded onto the card before shipment. Therefore, the mobile carrier receives the SIM card and provides it to the subscriber, and afterward, if necessary, management such as installation, modification, and deletion of applications in the UICC can be performed using technologies such as OTA (Over The Air). Subscribers can use the mobile carrier's network and application services by inserting the UICC card into their mobile terminals, and when replacing their terminals, they can use the authentication information, mobile phone number, and personal phone book stored in the UICC card in the new terminal by moving the UICC card from the old terminal to the new terminal.
[0047] However, SIM cards present inconveniences for mobile device users when accessing services from other carriers. Users must physically obtain a SIM card to access services from other carriers, which can be inconvenient. For example, when traveling to another country, obtaining a local SIM card can be inconvenient. While roaming services can alleviate some of this inconvenience, they are relatively expensive and can also be unavailable if a contract with another carrier is not in place.
[0048] Meanwhile, remotely downloading and installing a SIM module onto a UICC card can significantly resolve these inconveniences. For example, a user can download a SIM module for a desired mobile communication service onto the UICC card at a desired time. Such a UICC card can also be used by downloading and installing multiple SIM modules and selecting only one of them. Such a UICC card may or may not be fixed to a terminal. In particular, a UICC fixed to a terminal is called an eUICC (embedded UICC). Typically, an eUICC refers to a UICC card that is fixed to a terminal and allows remote download and selection of a SIM module. In the present disclosure, a UICC card that allows remote download and selection of a SIM module is referred to as an eUICC. For example, among UICC cards that allow remote download and selection of a SIM module, whether fixed or not fixed to a terminal, the term eUICC is used collectively. Furthermore, the downloaded SIM module information is collectively referred to as an eUICC profile, or more simply, a profile.
[0049] In this disclosure, an eUICC (embedded UICC) is a security module in the form of a chip embedded in a terminal, rather than a removable one that can be inserted and removed from the terminal. The eUICC can be used by being fixed to the terminal. Meanwhile, the eUICC can download and install profiles using OTA (Over The Air) technology. The eUICC can be referred to as a UICC capable of profile download and installation.
[0050] The method of downloading and installing a profile using OTA technology on an eUICC in the present disclosure can also be applied to a removable UICC that can be inserted and removed from a terminal. For example, the embodiments of the present disclosure can be applied to a UICC that can download and install a profile using OTA technology.
[0051] In this disclosure, “UICC” may be used interchangeably with “SIM”, and “eUICC” may be used interchangeably with “eSIM”.
[0052] In this disclosure, “profile” may mean an application, file system, authentication key value, etc. stored in a UICC packaged in software form.
[0053] In this disclosure, “USIM Profile” may have the same meaning as “profile” or may mean information included in a USIM application within a profile packaged in software form.
[0054] In the present disclosure, the action of a terminal activating a profile may refer to an action of changing the status of the profile to enabled, thereby enabling the terminal to receive communication services through the telecommunications service provider that provided the profile. A profile in an enabled state may be expressed as an "enabled profile."
[0055] In the present disclosure, the action of a terminal disabling a profile may refer to an action of changing the status of the profile to disabled, thereby preventing the terminal from receiving communication services through the telecommunications service provider that provided the profile. A disabled profile may be expressed as a "disabled profile."
[0056] In the present disclosure, the action of a terminal deleting a profile may mean an action of changing the status of the profile to a deleted status, thereby preventing the terminal from activating or deactivating the profile any longer. A profile in a deleted status may be expressed as a "deleted profile."
[0057] In the present disclosure, the operation of the terminal activating, disabling, or deleting a profile may mean an operation of not immediately changing the status of each profile to an enabled state, a disabled state, or a deleted state, but only marking each profile as to be enabled, to be disabled, or to be deleted, and then changing each profile to an enabled state, a disabled state, or a deleted state after the terminal or the UICC of the terminal performs a specific operation (e.g., performing a REFRESH or RESET command). The act of marking a particular profile as being in a scheduled state (e.g., to be enabled, to be disabled, or to be deleted) is not necessarily limited to marking a single scheduled state for a single profile, but may also mark one or more profiles as being in the same or different scheduled states, mark one profile as being in more than one scheduled state, or mark one or more profiles as being in more than one scheduled state, which may be the same or different.
[0058] Additionally, if a terminal indicates more than one scheduled status for a given profile, the two scheduled status indications may be combined into one. For example, if a given profile is marked as "to be disabled" and "to be deleted," the profile may be combined into "to be disabled and deleted."
[0059] Additionally, the terminal's actions of indicating a scheduled status for one or more profiles may be performed sequentially or simultaneously. Furthermore, the terminal's actions of indicating a scheduled status for one or more profiles and then changing the status of the actual profiles may be performed sequentially or simultaneously.
[0060] In the present disclosure, a "profile provision server" may include a function of generating a profile, encrypting a generated profile, generating a profile remote management command, or encrypting a generated profile remote management command. The profile provision server may be expressed as SM-DP (Subscription Manager Data Preparation), SM-DP+ (Subscription Manager Data Preparation plus), an off-card entity of Profile Domain, a profile encryption server, a profile generation server, a profile provider (Profile Provisioner, PP), a profile provider, and a PPC holder (Profile Provisioning Credentials holder).
[0061] In the present disclosure, a "profile management server" may include a function for managing a profile. The profile management server may be expressed as SM-SR (Subscription Manager Secure Routing), SM-SR+ (Subscription Manager Secure Routing Plus), an off-card entity of eUICC Profile Manager or PMC holder (Profile Management Credentials holder), EM (eUICC Manager), PP (Profile Manager), etc.
[0062] In the present disclosure, the "profile provision server" may also refer to a combination of the functions of a profile management server. Accordingly, in various embodiments of the present disclosure, the operations of the profile provision server may be performed by the profile management server. Similarly, the operations of the profile management server or SM-SR may also be performed by the profile provision server.
[0063] In the present disclosure, the "opening brokerage server" may be expressed as a Subscription Manager Discovery Service (SM-DS), a Discovery Service (DS), a Root SM-DS, or an Alternative SM-DS. The opening brokerage server may receive an event registration request (Register Event Request, Event Register Request) from one or more profile providing servers or opening brokerage servers. In addition, one or more opening brokerage servers may be used in combination, and in this case, the first opening brokerage server may receive an event registration request not only from the profile providing server but also from the second opening brokerage server.
[0064] In this disclosure, the profile provision server and the subscription brokerage server may be referred to as the 'RSP (Remote SIM Provisioning) server.' The RSP server may be expressed as SM-XX (Subscription Manager XX).
[0065] In the present disclosure, a 'terminal' may be referred to as a mobile station (MS), a user equipment (UE), a user terminal (UT), a wireless terminal, an access terminal (AT), a terminal, a subscriber unit (SS), a subscriber station (SS), a wireless device, a wireless communication device, a wireless transmit / receive unit (WTRU), a mobile node, a mobile, or other terms. In one embodiment, a terminal may include a cellular telephone, a smart phone having a wireless communication function, a personal digital assistant (PDA) having a wireless communication function, a wireless modem, a portable computer having a wireless communication function, a photographing device such as a digital camera having a wireless communication function, a gaming device having a wireless communication function, a music storage and playback home appliance having a wireless communication function, an internet home appliance capable of wireless internet access and browsing, as well as portable units or terminals integrating combinations of such functions. In addition, a terminal may include, but is not limited to, a machine-to-machine (M2M) terminal, a machine-type communication (MTC) terminal / device. In the present disclosure, a terminal may also be referred to as an electronic device.
[0066] In the present disclosure, an "electronic device" may include a built-in UICC capable of downloading and installing a profile. If the UICC is not built into the electronic device, a UICC that is physically separate from the electronic device may be inserted into and connected to the electronic device. For example, a UICC in the form of a card may be inserted into the electronic device. The electronic device may include a terminal. In this case, the terminal may be a terminal including a UICC capable of downloading and installing a profile. The UICC may be built into the terminal, or, if the terminal and the UICC are separate, the UICC may be inserted into the terminal and connected to the terminal. A UICC capable of downloading and installing a profile may be referred to, for example, as an eUICC.
[0067] In the present disclosure, a terminal or electronic device may include software or an application installed within the terminal or electronic device to control the UICC or eUICC. The software or application installed within the terminal or electronic device to control the UICC or eUICC may be referred to, for example, as a Local Profile Assistant (LPA).
[0068] In the present disclosure, a "profile identifier" may be referred to as a profile identifier (Profile ID), an Integrated Circuit Card ID (ICCID), a Matching ID, an Event ID, an Activation Code, an Activation Code Token, a Command Code, a Command Code Token, a Signed Command Code, an Unsigned Command Code, an ISD-P, or an argument matching a Profile Domain (PD). The Profile ID may represent a unique identifier of each profile. The Profile identifier may further include an address of a Profile Providing Server (SM-DP+) capable of indexing the profile. In addition, the Profile identifier may further include a signature of the Profile Providing Server (SM-DP+).
[0069] In the present disclosure, the "eUICC identifier (eUICC ID)" may be a unique identifier of an eUICC embedded in a terminal and may be referred to as EID. In addition, if a provisioning profile is pre-loaded in the eUICC, the eUICC identifier (eUICC ID) may be an identifier of the provisioning profile (Profile ID of the Provisioning Profile). In addition, in one embodiment of the present disclosure, if the terminal and the eUICC chip are not separated, the eUICC identifier (eUICC ID) may be a terminal ID. In addition, the eUICC identifier (eUICC ID) may also refer to a specific secure domain (Secure Domain) of the eUICC chip.
[0070] In this disclosure, a "Profile Container" may be referred to as a Profile Domain. A Profile Container may be a Security Domain.
[0071] In the present disclosure, an "APDU (application protocol data unit)" may be a message for a terminal to interface with an eUICC. Additionally, the APDU may be a message for a PP (Profile Provider) or PM (Profile Manager) to interface with an eUICC.
[0072] In the present disclosure, "Profile Provisioning Credentials (PPC)" may be a means used for mutual authentication between a profile provisioning server and an eUICC, and for profile encryption and signing. The PPC may include one or more of a symmetric key, a Rivest Shamir Adleman (RSA) certificate and private key, an elliptic curved cryptography (ECC) certificate and private key, a root certification authority (CA), and a certificate chain. In addition, when there are multiple profile provisioning servers, different PPCs may be stored or used in the eUICC for each of the multiple profile provisioning servers.
[0073] In the present disclosure, "PMC (Profile Management Credentials)" may be a means used for mutual authentication, data encryption, and signing between a profile management server and an eUICC. A PMC may include one or more of a symmetric key, an RSA certificate and private key, an ECC certificate and private key, a root CA, and a certificate chain. Furthermore, in cases where there are multiple profile management servers, different PMCs may be stored or used in the eUICC for each of the multiple profile management servers.
[0074] In the present disclosure, "AID" may be an application identifier. This value may be a identifier that distinguishes different applications within an eUICC.
[0075] In the present disclosure, an "event" may be a general term for a profile download, remote profile management, or other profile or eUICC management / processing commands. An event may be named a remote SIM provisioning operation (or RSP operation) or an event record, and each event may be referred to as data including at least one corresponding event identifier (Event Identifier, Event ID, EventID) or matching identifier (Matching Identifier, Matching ID, MatchingID), an address (FQDN, IP Address, or URL) of a profile provisioning server (SM-DP+) or a subscription brokerage server (SM-DS) where the event is stored, a signature of the profile provisioning server (SM-DP+) or subscription brokerage server (SM-DS), and a digital certificate of the profile provisioning server (SM-DP+) or subscription brokerage server (SM-DS).
[0076] Data corresponding to an event may be referred to as a "command code." Part or all of the procedure utilizing the command code may be referred to as a "command code processing procedure," a "command code procedure," or an "LPA API (Local Profile Assistant Application Programming Interface)." Profile download may be used interchangeably with profile installation.
[0077] Additionally, "Event Type" may be used as a term to indicate whether a particular event is a profile download, remote profile management (e.g., delete, activate, deactivate, replace, update, etc.), or other profile or eUICC management / processing command, and may be named as Operation Type (or OperationType), Operation Class (or OperationClass), Event Request Type, Event Class, Event Request Class, etc. Any event identifier (EventID or MatchingID) may be specified with the path through which the terminal acquired the event identifier (EventID or MatchingID) or its usage purpose (EventID Source or MatchingID Source).
[0078] In the present disclosure, the term "Profile Package" may be used interchangeably with the term "Profile" or may be used as a term indicating a data object of a specific profile, and may be named a Profile TLV or a Profile Package TLV. If the Profile Package is encrypted using encryption parameters, it may be named a Protected Profile Package (PPP) or a Protected Profile Package TLV (PPP TLV). If the Profile Package is encrypted using encryption parameters that can be decrypted only by a specific eUICC, it may be named a Bound Profile Package (BPP) or a Bound Profile Package TLV (BPP TLV). The Profile Package TLV may be a data set that expresses information that constitutes a profile in the TLV (Tag, Length, Value) format.
[0079] In the present disclosure, "Local Profile Management (LPM)" may be named as Profile Local Management, Local Management, Local Management Command, Local Command, Local Profile Management Package (LPM Package), Profile Local Management Package, Local Management Package (LOCAL MANAGEMENT PACKAGE), Local Management Command Package, and Local Command Package. LPM may be used to change the status (Enabled, Disabled, Deleted) of a specific profile or to change (update) the contents of a specific profile (e.g., Profile Nickname, Profile Summary Information (Profile Metadata), etc.) through software installed on a terminal. LPM may include one or more local management commands, and when LPM includes one or more local management commands, the profiles targeted by each local management command may be the same or different for each local management command.
[0080] In the present disclosure, "Remote Profile Management (RPM)" may be named as Profile Remote Management, Remote Management, Remote Management Command, Remote Command, Remote Profile Management Package (RPM Package), Profile Remote Management Package, Remote Management Command Package, Remote Command Package. RPM may be used to change the status (Enabled, Disabled, Deleted) of a specific profile, or to change (update) the contents of a specific profile (e.g., Profile Nickname, Profile Metadata, etc.). RPM may include one or more remote management commands, in which case the target profiles of each remote management command may be the same or different for each remote management command.
[0081] In the present disclosure, a "certificate" or "digital certificate" may refer to a digital certificate used for mutual authentication based on an asymmetric key, which is composed of a pair of a public key (PK) and a secret key (SK). Each certificate may include one or more public keys (PK), a public key identifier (PKID) corresponding to each public key, an identifier (Certificate Issuer ID) of a certificate issuer (CI) that issued the certificate, and a digital signature.
[0082] Additionally, the "Certificate Issuer" may be referred to as a "Certification Issuer," a "Certificate Authority (CA)," or a "Certification Authority."
[0083] In the present disclosure, "public key (PK)" and "public key identifier (PKID)" may be used interchangeably with the same meaning to refer to a specific public key or a certificate including the public key, or a part of the specific public key or a part of the certificate including the public key, or a computation result (e.g., hash) value of the specific public key or a computation result (e.g., hash) value of the certificate including the public key, or a computation result (e.g., hash) value of a part of the specific public key or a part of the certificate including the public key, or a storage space where data is stored.
[0084] In the present disclosure, when certificates (primary certificates) issued by one certificate issuer are used to issue other certificates (secondary certificates) or secondary certificates are used to issue three or more certificates in a linked manner, the correlation of the certificates may be named a certificate chain or certificate hierarchy, and in this case, the CI certificate used to issue the first certificate may be named a root of certificate, a top-level certificate, a root CI, a root CI certificate, a root CA, a root CA certificate, etc.
[0085] In the present disclosure, a "mobile operator" may refer to a business entity that provides communication services to terminals, and may collectively refer to a business supporting system (BSS), an operational supporting system (OSS), a point of sale terminal, and other IT systems of the mobile operator. In addition, the mobile operator in the present disclosure is not limited to representing a single specific business entity that provides communication services, but may also be used as a term referring to a group or association (or consortium) of one or more businesses, or an agent representing the group or association. In addition, the mobile operator in the present disclosure may be referred to as an operator (OP, or Op.), a mobile network operator (MNO), a mobile virtual network operator (MVNO), a service provider (or SP), a profile owner (PO), etc., and each mobile operator may set or be assigned at least one name and / or object identifier (OID) of the mobile operator. If the carrier refers to a group or association or agency of one or more businesses, the name or unique identifier of any group or association or agency may be a name or unique identifier shared by all businesses belonging to that group or association or all businesses cooperating with that agency.
[0086] In this disclosure, “AKA” may represent Authentication and Key Agreement, and may represent an authentication algorithm for accessing 3GPP and 3GPP2 networks.
[0087] In the present disclosure, “K” may be an encryption key value stored in an eUICC used in the AKA authentication algorithm.
[0088] In the present disclosure, “OPc” may be a parameter value that can be stored in an eUICC used in an AKA authentication algorithm.
[0089] In this disclosure, "NAA" refers to a network access application, which may be an application such as a USIM or ISIM stored in a UICC for accessing a network. The NAA may be a network access module.
[0090] In the present disclosure, an "indicator" may be used to express whether or not a certain function, setting, or operation is required, or may also be used to express the function, setting, or operation itself. In addition, in the present disclosure, an indicator may be expressed in various forms, such as a string or alphanumeric string, a boolean operator indicating true / false (TRUE or FALSE), a bitmap, an array, a flag, etc., and other expressions having the same meaning may be used interchangeably.
[0091] Hereinafter, a method and device for installing and managing an eUICC profile of the present disclosure will be specifically described with reference to FIGS. 1 to 12.
[0092] FIG. 1 is a diagram illustrating a method for connecting a terminal to a mobile communication network using a UICC equipped with a fixed profile according to one embodiment of the present disclosure.
[0093] As illustrated in Fig. 1, the UICC (120) can be inserted into the terminal (110). For example, the UICC (120) may be removable or may be pre-built into the terminal.
[0094] A fixed profile on a UICC means that the "connection information" required to connect to a specific carrier is fixed. For example, the connection information could be the IMSI (subscriber identification number) and the K or Ki value required for network authentication, along with the subscriber identification number.
[0095] According to various embodiments, a terminal (110) can perform authentication with a mobile communication service provider's authentication processing system (e.g., HLR (home location register) or AuC) using a UICC (120). For example, the authentication process may be an AKA (Authentication and Key Agreement) process. If authentication is successful, the terminal can use mobile communication services such as phone calls or mobile data usage by using the mobile communication service provider's network (130) of the mobile communication system.
[0096] Meanwhile, FIG. 2 is a diagram illustrating a configuration of a system in which a terminal according to one embodiment of the present disclosure manages a profile installed in a first terminal and installs a profile in a second terminal according to a user's input.
[0097] As illustrated in FIG. 2, each terminal (210, 220) is equipped with an eSIM (211, 221), and a profile (not shown) may be installed in the eSIM (211, 221). In addition, an LPA (212, 222) may be installed in each terminal (210, 220). The eSIM (211, 221) may be controlled by the LPA (212, 222). The user (200) may control the profile installed in the eSIM (211, 221) of each terminal (210, 220) through the LPA (212, 222).
[0098] A user (200) may receive communication services from a service provider (hereinafter referred to as a "telecommunications service provider" or "operator", 250). To provide the communication services, a profile (not shown) of the operator (250) may be installed on the first terminal (210). For example, if the user (200) newly purchases a second terminal (220), the user (200) may attempt to reinstall the profile installed on the first terminal (210) on the second terminal (220).
[0099] The business operator (250) may be connected to a first profile server (230) and a second profile server (240). The LPA (212) of the first terminal (210) may be connected to the first profile server (230). The LPA (222) of the second terminal (220) may be connected to the second profile server (240). At this time, the first profile server (230) and the second profile server (240) may be the same or different. In addition, when one or more business servers are included in the configuration, each business server may be connected to a separate profile server, or at least one business server may be connected to the same profile server. In addition, for convenience, FIG. 2 illustrates a case where each of the profile servers (230, 240) is configured as a single server, but one or more profile servers (SM-DP+) may be included in the server configuration depending on the implementation and embodiment. It should be noted that the configuration of various servers in this way can be simply represented as a single profile server in the drawing below.
[0100] The detailed operations and message exchange procedures of a user (200), a business operator (250), a terminal (210, 220), an eSIM (211, 221), an LPA (212, 222), and a profile server (230, 240) according to an embodiment of the present disclosure will be examined in detail with reference to the drawings described below.
[0101] FIG. 3 is a diagram illustrating an example of a procedure between a first terminal and a server for checking whether the first terminal and the profile server provide a function (Activation Code Retrieval) for requesting and obtaining an activation code from a profile server for re-downloading a profile installed on the first terminal to the first terminal or the second terminal according to one embodiment of the present disclosure.
[0102] According to one embodiment of the present disclosure, the first terminal (310) illustrated in FIG. 3 may provide information on whether the installed profile supports a function (Activation Code Retrieval) for requesting and obtaining an activation code for profile re-download from the profile server (330). The diagram also illustrates a procedure for providing information to the first terminal (310) on whether the profile server (330) supports a function (Activation Code Retrieval) for processing a request for an activation code for profile re-download and providing the activation code.
[0103] The configuration and description of the first terminal (310), profile server (330), and business operator (not shown) in FIG. 3 will refer to the contents of FIG. 2 described above. For example, the first terminal (310) and profile server (330) illustrated in FIG. 3 may correspond to the first terminal (210) and first profile server (230) illustrated in FIG. 2, respectively.
[0104] Referring to FIG. 3, in step 3001, the first terminal (310) can determine the address of a profile server from which to request an activation code for re-downloading a specific profile installed on the terminal. The address of the profile server can be determined by at least one of the following methods, and the number of profile server addresses determined by the first terminal (310) can be one or more.
[0105] - Address of the profile server used when a specific profile is downloaded to the first terminal (310)
[0106] - The notification address (NotificationAddress) to which notifications set in the notification configuration information (NotificationConfigurationInfo) of a specific profile will be delivered. This address may be the address to which deletion notifications will be delivered when a profile deletion event occurs.
[0107] - Profile server address obtained through a server operated by the first terminal (310) manufacturer or an external organization
[0108] - In addition, the storage space in the first terminal (310), the LPA (not shown), the eSIM (not shown), and the profile server address stored in the profile (not shown) installed in the first terminal (310)
[0109] In addition, if the address of the profile server that requests an activation code for re-downloading a specific profile installed in the first terminal (310) cannot be determined in step 3001, the first terminal (310) can selectively set the status of the profile to not be re-downloaded. The re-download not-available status can be set in the storage space within the first terminal (310), the LPA (not shown), the eSIM (not shown), or the profile (not shown) installed in the first terminal (310). In addition, the re-download menu of the corresponding profile may not be shown on the display or User Interface of the terminal (310), or the profile may be expressed as not accessible so that the user (not shown) cannot select the re-download menu of the corresponding profile.
[0110] In step 3003, the first terminal (310) can start a mutual authentication process with the profile server (330). The mutual authentication start request can be requested from the first terminal (310) to the profile server (330) using the ES9+.InitiateAuthentication function. The mutual authentication start request can optionally include at least one of information (euiccInfo1) of an eSIM (not shown) installed in the first terminal (310), information (lpaRspCapability) of an LPA (not shown), or an indicator (Activation Code Retrieval support) indicating whether the LPA (not shown) supports a function (Activation Code Retrieval) of requesting and obtaining an activation code for profile re-download. An indicator indicating whether the LPA (not shown) of the first terminal (310) supports the function of requesting and obtaining an activation code for profile re-download (Activation Code Retrieval) may be included in the information (lpaRspCapability) of the LPA (not shown) or may be included in the mutual authentication start request independently from the information (lpaRspCapability) of the LPA (not shown). In step 3005, the profile server (330) may transmit a mutual authentication start response corresponding to the mutual authentication start request of the first terminal (310) to the first terminal (310). The mutual authentication start response may be an ES9+.InitiateAuthentication response.The mutual authentication start response may include at least one of TransactionId, information of the profile server (330) (serverRspCapability or sessionContext), or an indicator (Activation Code Retrieval support) indicating whether the profile server (330) processes a request for an activation code for profile re-download, provides an activation code, and supports the function (Activation Code Retrieval). The indicator (Activation Code Retrieval support) indicating whether the profile server (330) processes a request for an activation code for profile re-download, provides an activation code, and supports the function (Activation Code Retrieval) may be included in the information of the profile server (330) (serverRspCapability or sessionContext) or may be independently included in the mutual authentication start response. In addition, the information may include a signature generated by the profile server (330), a profile server (330) digital certificate capable of verifying the signature, and a corresponding certificate chain.
[0111] In step 3005, the first terminal (310) that received the mutual authentication start response from the profile server (330) may selectively repeat step 3003 for the address of another profile server determined in step 3001 or stop the process if the profile server (330) processes the request for an activation code for profile re-download and provides the activation code and does not support the function (Activation Code Retrieval).
[0112] In addition, if the first terminal (310) processes a request for an activation code for profile re-download for the addresses of at least one or all of the profile servers determined in step 3001, provides the activation code, and does not support the function (Activation Code Retrieval), the first terminal (310) can selectively set the status of the corresponding profile to not be re-downloaded. The setting of the not-re-downloaded status can be set in the storage space within the first terminal (310), the LPA (not shown), the eSIM (not shown), or the profile (not shown) installed in the first terminal (310). In addition, the re-download menu of the corresponding profile may not be shown on the display or User Interface of the first terminal (310), or may be expressed as not being accessible so that the user (not shown) cannot select the re-download menu of the corresponding profile.
[0113] FIG. 4 is a diagram illustrating an embodiment of the operation of a procedure between a first terminal, a second terminal, and a profile server to check whether a specific profile installed on a first terminal (410) according to one embodiment of the present disclosure can be re-downloaded to the first terminal or the second terminal through a profile server (430).
[0114] The configuration and description of the first terminal (410), the second terminal (420), and the profile server (430) in FIG. 4 will refer to the contents of FIG. 2 described above. For example, the first terminal (410), the second terminal (420), and the profile server (430) may correspond to the first terminal (210), the second terminal (220), and the first profile server (230) of FIG. 2, respectively.
[0115] Referring to FIG. 4, in step 4001, the first terminal (410) can determine the address of a profile server from which to request an activation code for re-downloading a specific profile installed on the terminal. Step 4001 may refer to step 3001 of FIG. 3.
[0116] Referring to FIG. 4, in step 4003, the first terminal (410) may initiate a mutual authentication process with the profile server (430). The mutual authentication initiation request may be requested from the first terminal (410) to the profile server (430) using the ES9+.InitiateAuthentication function. Step 4003 may refer to step 3003 of FIG. 3.
[0117] In step 4005, the profile server (430) may transmit a mutual authentication initiation response corresponding to the mutual authentication initiation request of the first terminal (410) to the first terminal (410). The mutual authentication initiation response may be an ES9+.InitiateAuthentication response. Step 4005 may refer to step 3005 of FIG. 3.
[0118] At step 4007, the first terminal (410) may request the profile server (430) to request an activation code for re-downloading the first profile installed in the terminal and to confirm whether acquisition thereof is possible. The request for confirmation may use the ES9+.AuthenticateClient function. The request for confirmation may include at least one of an instruction requesting confirmation of whether acquisition thereof is possible and an instruction requesting confirmation of whether acquisition thereof is possible (Activation Code Retrieval Eligibility Check or Availability check, ACRcheck, useMatchingIdForAcrEligiblityCheck, etc.) and a profile identifier (ICCID1) of the first profile. In addition, the request may optionally include an eUICC identifier (EID2) installed in the second terminal (420) or a TAC (Type allocation Code, TAC2) of the second terminal (420). The above verification request may be included in the ctxParams1, ctxParamsForCommonAuthentication or matchingId data object, and the values may include a signature of an eSIM (not shown) installed in the first terminal (410), a digital certificate of the eSIM (not shown) capable of verifying the signature, and a corresponding certificate chain. In addition, the verification request may optionally include an indicator requesting confirmation of whether an activation code for re-downloading the first profile and acquisition are possible (Activation Code Retrieval Eligibility Check or Availability check, ACRcheck, etc.), or an indicator indicating that the matchingId data object is used for an activation code issuance processing request (useMatchingIdForAcr).
[0119] In step 4009, if the profile server (430) is unable to process the request for an activation code for re-downloading the first profile installed on the terminal transmitted by the first terminal (410) and the request for confirmation of whether acquisition is possible, the profile server (430) may reply to the first terminal (410) with an error and the reason for the error. The case where the confirmation request cannot be processed may fall under at least one of the following, but is not limited thereto.
[0120] - If the signature or certificate verification of the eSIM included in the request in step 4007 fails.
[0121] - If you are unable to interpret the request to request and obtain an activation code for re-downloading the first profile.
[0122] - If the request for activation code for profile re-download is processed and the activation code is provided and the function (Activation Code Retrieval) is not supported.
[0123] - If you are unable to request or obtain an activation code for re-downloading the first profile
[0124] If the above error is received, the first terminal (410) may optionally perform step 4011. According to one embodiment, the first terminal (410) may optionally repeat the process from step 4001 for the address of another profile server determined in step 4001, or may stop the process. In addition, if an error is received for the address of at least one or all of the profile servers determined in step 4001, the first terminal (410) may set the status of the first profile to be unavailable for re-download. The unavailable for re-download status setting may be set in the storage space within the first terminal (410), the LPA (not shown), the eSIM (not shown), or the profile (not shown) installed in the first terminal (410). In addition, the re-download menu of the corresponding profile may not be displayed on the display or User Interface of the first terminal (410), or the profile may be expressed as inaccessible so that the user (not shown) cannot select the re-download menu of the corresponding profile.
[0125] At step 4013, the profile server (430) may transmit a response to the first terminal (410) regarding the request for an activation code for re-downloading the first profile of the first terminal and the request for confirmation of whether acquisition is possible. The confirmation request response may be an ES9+.AuthenticateClient response. The confirmation request response may include at least one of the following pieces of information.
[0126] - First Profile Identifier (ICCID)
[0127] - An identifier indicating whether it is possible to process an activation code request for re-downloading the first profile and provide an activation code.
[0128] - An identifier indicating whether information of a second terminal (420) to which the profile is to be re-downloaded is required for processing an activation code request for re-downloading the first profile and providing the activation code. According to one embodiment, information of the second terminal (420) may optionally include at least one of an eUICC identifier installed in the terminal and a TAC (Type allocation Code) of the terminal.
[0129] - Request an activation code for re-downloading the first profile and check availability of the activation code, or at least one other profile server address from which the activation code can be requested.
[0130] - Information on whether an activation code can be requested and obtained for re-downloading at least one profile installed on the first terminal (410), excluding the first profile.
[0131] - Business (not shown) message
[0132] The above information included in the confirmation request response may be included in the Profile metadata or may be included in the confirmation request response independently.
[0133] Additionally, some of the information included in the confirmation request response may be included in the ActivationCodeRetrievalInfo data object for requesting and obtaining an activation code for re-downloading the first profile, and may be included in the confirmation request response independently of the data object. Additionally, the ActivationCodeRetrievalInfo data object for requesting and obtaining an activation code for re-downloading the first profile may be included in the Profile metadata, and may be included in the confirmation request response independently of the profile metadata.
[0134] If the above confirmation request response is received, the first terminal (410) can optionally perform step 4015.
[0135] If the profile server (430) responds that it can process a request for an activation code for re-downloading the first profile and provide the activation code, the first terminal (410) can set the status of the first profile to be re-downloadable at step 4015. The re-downloadable status can be set in the storage space within the first terminal (410), the LPA (not shown), the eSIM (not shown) installed in the first terminal (410), or the profile (not shown). In addition, the re-download menu of the corresponding profile can be shown on the display or User Interface of the first terminal (410), or the profile can be expressed as accessible so that the user (not shown) can select the re-download menu of the corresponding profile.
[0136] If the request for an activation code for re-downloading the first profile is responded as impossible and the provision of the activation code is impossible, the first terminal (410) may selectively repeat the process from step 4001 for the address of another profile server responded by the profile server (430) in step 4013 or the address of another profile server determined in step 4001, or may stop the process. In addition, if the function of processing a request for an activation code for re-downloading the first profile and providing the activation code (Activation Code Retrieval) for the addresses of at least one or all of the profile servers is not supported, the first terminal (410) may set the status of the first profile as impossible to re-download. The setting of the impossible to re-download status may be set in the storage space within the first terminal (410), the LPA (not shown), the eSIM (not shown), or the profile (not shown) installed in the first terminal (410). In addition, the re-download menu of the corresponding profile may not be displayed on the display or User Interface of the first terminal (410), or may be expressed as inaccessible so that the user (not shown) cannot select the re-download menu of the corresponding profile.
[0137] FIG. 5 is a diagram illustrating an example of a procedure between a first terminal, a second terminal, and a profile server for checking whether a specific profile installed on a first terminal (510) according to one embodiment of the present disclosure can be re-downloaded to the first terminal or the second terminal through a profile server (530).
[0138] The configuration and description of the first terminal (510), the second terminal (520), and the profile server (530) in FIG. 5 will refer to the contents of FIG. 2 described above. For example, the first terminal (510), the second terminal (520), and the profile server (530) may correspond to the first terminal (210), the second terminal (220), and the first profile server (230) of FIG. 2, respectively.
[0139] Referring to FIG. 5, in step 5001, the first terminal (510) can determine the address of a profile server from which to request an activation code for re-downloading a specific profile installed on the terminal. Step 5001 may refer to step 3001 of FIG. 3.
[0140] Referring to FIG. 5, in step 5003, the first terminal (510) may initiate a mutual authentication process with the profile server (530). The mutual authentication initiation request may be requested from the first terminal (510) to the profile server (530) using the ES9+.InitiateAuthentication function. Step 5003 may refer to step 3003 of FIG. 3.
[0141] In step 5005, the profile server (530) may transmit a mutual authentication initiation response corresponding to the mutual authentication initiation request of the first terminal (510) to the first terminal (510). The mutual authentication initiation response may be an ES9+.InitiateAuthentication response. Step 5005 may refer to step 3005 of FIG. 3.
[0142] In step 5007, the first terminal (510) may request the profile server (530) to confirm whether it is possible to request and obtain an activation code for re-downloading the first profile installed in the first terminal (510). The confirmation request may use the ES9+.AuthenticateClient function. The confirmation request may include at least one of an activation code request indicator for re-downloading the first profile (Activation Code Retrieval or ACR) and a profile identifier (ICCID1) of the first profile. Optionally, the request may include an eUICC identifier (EID2) installed in the second terminal (520) to which the profile will be transferred or a TAC (Type allocation Code, TAC2) of the second terminal (520). The above verification request may be included in the ctxParams1, ctxParamsForCommonAuthentication or matchingId data object, and the values may include a signature of an eSIM (not shown) installed in the first terminal (510), a digital certificate of the eSIM (not shown) capable of verifying the signature, and a corresponding certificate chain. In addition, the verification request may optionally include an indicator (Activation Code Retrieval Eligibility Check or Availability check, ACRcheck, useMatchingIdForAcr, useMatchingIdForAcrEligiblityCheck, etc.) for requesting and confirming whether an activation code for re-downloading the first profile can be obtained, or an indicator (useMatchingIdForAcr) for indicating that the matchingId data object is used for a request for processing an activation code issuance.
[0143] In step 5009, if the profile server (530) is unable to process the request for an activation code for re-downloading the first profile installed on the terminal transmitted by the first terminal (510) and the request for confirmation of whether acquisition is possible, the profile server (530) may reply to the first terminal (510) with an error and the reason for the error. Step 5009 may refer to step 4009 of FIG. 4.
[0144] If the above error is received, the first terminal (510) may optionally perform step 5011. Step 5011 may refer to step 4011 of FIG. 4.
[0145] In step 5013, the profile server (530) may transmit a response to the first terminal (510) regarding the request for an activation code for re-downloading the first profile of the first terminal and the request for confirmation of whether acquisition is possible. The confirmation request response may be an ES9+.AuthenticateClient response. Step 5013 may refer to step 4013 of FIG. 4.
[0146] If the above confirmation request response is received, the first terminal (510) may optionally perform step 5015. Step 5015 may refer to step 4015 of FIG. 4.
[0147] FIG. 6 is a block diagram illustrating components of a terminal according to an embodiment of the present disclosure.
[0148] Each of the terminals described in this disclosure (e.g., the first terminal and the second terminal) may correspond to the first terminal or the second terminal described in FIG. 2. The first terminal and the second terminal may be embodiments of the terminals of FIG. 2, and the expressions "first" and "second" are used only to indicate that each terminal is physically different from the other.
[0149] As illustrated in FIG. 6, the terminal may include a transceiver unit (610) and a control unit (processor) (620). In addition, the terminal may include a UICC (630). For example, the UICC (630) may be inserted into the terminal or may be an eUICC built into the terminal.
[0150] The transmitter and receiver (610) can transmit and receive signals, information, data, etc. to and from the profile server.
[0151] A transmitter / receiver (610) according to one embodiment of the present disclosure can transmit a message requesting a profile server to check whether an activation code can be issued for reinstalling a profile, and receive information on whether an activation code can be issued and additional information from the profile server.
[0152] Meanwhile, the processor (620) is a component for overall control of the terminal. The processor (620) can control the overall operation of the terminal according to various embodiments of the present disclosure. The processor (620) may be referred to as a control unit. According to one embodiment of the present disclosure, the processor (620) may include at least one processor.
[0153] A processor (620) according to one embodiment of the present disclosure can control a terminal to check the address of a profile server to which a request for confirmation of whether an activation code for reinstalling a profile can be issued is to be sent, send a message requesting the profile server to check whether an activation code for reinstalling a profile can be issued, and receive from the profile server whether an activation code for reinstalling a profile can be issued.
[0154] A UICC (630) according to one embodiment of the present disclosure can download and install profiles. In addition, the UICC (630) can manage profiles.
[0155] The UICC (630) may operate under the control of the processor (620). Alternatively, the UICC (630) may include a processor or controller for installing a profile, or may have an application installed. A portion of the application may be installed on the processor (620).
[0156] Meanwhile, the terminal may further include a storage unit (not shown) and may store data such as basic programs, application programs, and setting information for the operation of the terminal. In addition, the storage unit may include at least one storage medium among a Flash Memory Type, a Hard Disk Type, a Multimedia Card Micro Type, a memory of a card type (e.g., an SD or XD memory, etc.), a magnetic memory, a magnetic disk, an optical disk, a Random Access Memory (RAM), a Static Random Access Memory (SRAM), a Read-Only Memory (ROM), a Programmable Read-Only Memory (PROM), and an Electrically Erasable Programmable Read-Only Memory (EEPROM). In addition, the processor (620) may perform various operations using various programs, contents, data, etc. stored in the storage unit.
[0157] FIG. 7 is a block diagram illustrating components of a profile server according to one embodiment of the present disclosure.
[0158] Each of the profile servers described in the present disclosure (e.g., the first profile server and the second profile server) may correspond to the profile server described in FIG. 2. The first profile server and the second profile server may be embodiments of the servers of FIG. 2, and the expressions "first" and "second" are only used to indicate that each profile server is a physically different profile server.
[0159] Referring to FIG. 7, the profile server may include a transmitter / receiver unit (710) and a control unit (processor) (720).
[0160] The transmitter / receiver (710) can transmit and receive signals, information, data, etc. to and from the terminal.
[0161] A transceiver (710) according to one embodiment of the present disclosure may receive a message requesting confirmation of whether an activation code for profile reinstallation can be issued from a terminal, and transmit information on whether an activation code can be issued and additional information to the terminal.
[0162] Meanwhile, the processor (720) is a component for overall control of the profile server. The processor (720) may control the overall operation of the profile server according to various embodiments of the present disclosure. The processor (720) may be referred to as a control unit. According to one embodiment of the present disclosure, the processor (720) may include at least one processor.
[0163] A processor (720) according to one embodiment of the present disclosure may receive a message requesting confirmation of whether an activation code for profile reinstallation can be issued from a terminal, and control a profile server to transmit the information on whether an activation code can be issued and additional information to the terminal.
[0164] Meanwhile, the profile server may further include a storage unit (not shown) and may store data such as basic programs, applications, and setting information for the operation of the profile server. In addition, the storage unit may include at least one storage medium among a Flash Memory Type, a Hard Disk Type, a Multimedia Card Micro Type, a memory of a card type (e.g., an SD or XD memory, etc.), a magnetic memory, a magnetic disk, an optical disk, a Random Access Memory (RAM), a Static Random Access Memory (SRAM), a Read-Only Memory (ROM), a Programmable Read-Only Memory (PROM), and an Electrically Erasable Programmable Read-Only Memory (EEPROM). In addition, the processor (720) may perform various operations using various programs, contents, data, etc. stored in the storage unit.
[0165] In the specific embodiments of the present disclosure described above, components included in the disclosure are expressed in the singular or plural form, depending on the specific embodiment presented. However, the singular or plural expressions are selected to suit the presented situation for convenience of explanation, and the present disclosure is not limited to singular or plural components. Components expressed in the plural form may be composed of singular elements, or components expressed in the singular form may be composed of plural elements.
[0166] While the detailed description of this disclosure has described specific embodiments, it should be understood that various modifications are possible without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be limited to the described embodiments, but should be defined not only by the scope of the claims described below, but also by equivalents thereof.
[0167] The various embodiments of the present disclosure and the terminology used therein are not intended to limit the technology described in the present disclosure to a specific embodiment, but should be understood to include various modifications, equivalents, and / or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar components. The singular expression may include plural expressions unless the context clearly indicates otherwise. In the present disclosure, expressions such as “A or B,” “at least one of A and / or B,” “A, B, or C,” or “at least one of A, B, and / or C” may include all possible combinations of the items listed together. Expressions such as “first,” “second,” “first,” or “second” may modify the corresponding components regardless of order or importance, and are only used to distinguish one component from another, but do not limit the corresponding components. When it is said that a component (e.g., a first component) is “(functionally or communicatively) connected” or “connected” to another component (e.g., a second component), the component may be directly connected to the other component, or may be connected through another component (e.g., a third component).
[0168] The term "module" as used herein includes a unit composed of hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integrally formed component, or a minimum unit or portion thereof that performs one or more functions. For example, a module may be composed of an application-specific integrated circuit (ASIC).
[0169] Various embodiments of the present disclosure may be implemented as software (e.g., a program) including instructions stored in a machine-readable storage medium (e.g., an internal memory or an external memory) that can be read by a machine (e.g., a computer). The device is a device that can call instructions stored from the storage medium and operate according to the called instructions, and may include a terminal (e.g., a first terminal (210), a second terminal (220)) according to various embodiments of the present disclosure. When an instruction is executed by a processor (e.g., a processor (620) of FIG. 6 or a processor (720) of FIG. 10), the processor may directly, or under the control of the processor, perform a function corresponding to the instruction by using other components. The instruction may include code generated or executed by a compiler or an interpreter.
[0170] A device-readable storage medium may be provided in the form of a non-transitory storage medium. Here, "non-transitory" simply means that the storage medium does not contain signals and is tangible, but does not distinguish between whether data is stored semi-permanently or temporarily on the storage medium.
[0171] The methods according to various embodiments disclosed in the present disclosure may be provided as a computer program product. The computer program product may be traded as a commodity between sellers and buyers. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or online through an application store (e.g., Play Store™). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily generated in a storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.
[0172] Each component (e.g., a module or a program) according to various embodiments may be composed of one or more entities, and some of the aforementioned sub-components may be omitted, or other sub-components may be further included in various embodiments. Alternatively or additionally, some components (e.g., a module or a program) may be integrated into a single entity, which may perform the same or similar functions as those performed by each of the respective components prior to integration. Operations performed by a module, program, or other component according to various embodiments may be executed sequentially, in parallel, iteratively, or heuristically, or at least some operations may be executed in a different order, omitted, or other operations may be added.
Claims
1. In a method performed by a terminal in a wireless communication system, A step of transmitting a request message to a profile server, the request message including a request for confirmation of whether an activation code for re-downloading the first profile installed on the terminal can be obtained; and A method comprising: receiving, from the profile server, a response message including information indicating whether an activation code for re-downloading the profile installed on the terminal can be obtained as a response to the request message; 2. In paragraph 1, The above request is, An instruction indicating that the request requests confirmation of availability of an activation code for re-downloading the first profile and includes at least one profile identifier of the first profile, A method characterized in that the request further comprises an indicator indicating that the request is used for processing an activation code issuance request.
3. In paragraph 1, The information included in the above response message is: A method characterized by being included in profile metadata.
4. In paragraph 1, A method characterized in that it further comprises a step of transmitting a request message to the profile server, the request message including an indicator indicating whether the local profile assistant (LPA) of the terminal supports a function of requesting and obtaining an activation code for profile re-download, during a mutual authentication process between the terminal and the profile server.
5. In a method performed by a profile server in a wireless communication system, A step of receiving a request message from a terminal, the request message including a request for confirmation of whether an activation code for re-downloading the first profile installed on the terminal can be obtained; and A method comprising: a step of transmitting a response message including information indicating whether an activation code for re-downloading a profile installed on the terminal can be obtained as a response to the request message; 6. In paragraph 5, The above request is, An instruction indicating that the request requests confirmation of availability of an activation code for re-downloading the first profile and includes at least one profile identifier of the first profile, Further comprising an indicator indicating that the above request is to be used for processing an activation code issuance request, The information included in the above response message is: A method characterized by being included in profile metadata.
7. In paragraph 5, A method characterized in that it further comprises the step of receiving a request message from the terminal, which includes an indicator indicating whether the local profile assistant (LPA) of the terminal supports a function of requesting and obtaining an activation code for profile re-download, during a mutual authentication process between the terminal and the profile server.
8. In a wireless communication system, at the terminal, Transmitter and receiver; and Transmitting a request message including a request for confirmation of whether an activation code for re-downloading the first profile installed on the terminal can be obtained to the profile server through the transceiver; A terminal including a control unit that controls receiving, from the profile server, a response message including information indicating whether an activation code for re-downloading the profile installed on the terminal can be obtained as a response to the request message.
9. In paragraph 8, The above request is, An instruction indicating that the request requests confirmation of availability of an activation code for re-downloading the first profile and includes at least one profile identifier of the first profile, A terminal characterized in that the above request further includes an indicator indicating that the request is used for processing an activation code issuance request.
10. In paragraph 8, The information included in the above response message is: A terminal characterized by being included in profile metadata.
11. In paragraph 8, A terminal characterized in that it further comprises a step of transmitting a request message to the profile server, the request message including an indicator indicating whether the local profile assistant (LPA) of the terminal supports a function of requesting and obtaining an activation code for profile re-download, during a mutual authentication process between the terminal and the profile server.
12. In a profile server in a wireless communication system, Transmitter and receiver; and Receive a request message from the terminal through the transceiver, including a request for confirmation of whether an activation code for re-downloading the first profile installed on the terminal can be obtained; A profile server comprising a control unit that controls, as a response to the request message, to transmit a response message including information indicating whether an activation code for re-downloading a profile installed on the terminal can be obtained.
13. In paragraph 12, The above request is, An instruction indicating that the request requests confirmation of availability of an activation code for re-downloading the first profile and includes at least one profile identifier of the first profile, A profile server characterized in that the request further includes an indicator indicating that the request is used for processing an activation code issuance request.
14. In paragraph 12, The information included in the above response message is: A profile server characterized by being included in profile metadata.
15. In paragraph 12, The above control unit, A profile server characterized in that, during a mutual authentication process between the terminal and the profile server, a request message including an indicator indicating whether the local profile assistant (LPA) of the terminal supports a function of requesting and obtaining an activation code for profile re-download is received from the terminal.
Citation Information
Patent Citations
Method and apparatus for download of profile in a wireless communication system
KR1020170035242A
Method and apparatus for providing a profile remotely in a communication system
KR1020170041597A
Method and apparatus for providing a profile
KR1020170074752A
Method and apparatus for providing profile
KR1020180004119A
eSIM PROFILE MANAGEMENT FOR WIRELESS DEVICES
US20240007848A1