Method and apparatus for moving and storing profile outside of embedded universal integrated circuit card (EUICC)
The method of transferring profiles outside the eUICC addresses storage limitations by securing memory based on predicted size, improving profile management efficiency and user convenience.
Patent Information
- Application Number
- PCT/KR2025/009001
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-04-29
- Filing Date
- 2025-06-26
- Publication Date
- 2026-01-02
AI Technical Summary
The limited storage capacity of embedded universal integrated circuit cards (eUICC) in terminals poses a challenge for installing and managing multiple profiles, leading to inefficiencies and increased costs when users run out of space.
A method and device for transferring profiles outside the eUICC by transmitting additional profile information to a profile server, receiving predicted profile size information, and securing eUICC memory accordingly to facilitate profile installation.
Enables efficient management of profiles by allowing them to be moved outside the eUICC, reducing the need for profile deletion and reinstallations, thereby enhancing user convenience and optimizing storage utilization.
Smart Images

Figure KR2025009001_02012026_PF_FP_ABST
Abstract
Description
Method and device for moving and storing profiles outside of an embedded universal integrated circuit card (EUICC)
[0001] The present disclosure relates to a wireless communication system or a mobile communication system. Specifically, it relates to a method and device for transferring communication subscription information from a terminal. The method and device enable profile installation by extracting and transferring a profile previously stored in an eUICC to a location outside the eUICC when installing a profile in a terminal, thereby securing installation space and enabling profile installation.
[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in the sub-6GHz frequency band such as 3.5 gigahertz (3.5GHz), but also in the ultra-high frequency band called millimeter wave (mmWave) such as 28GHz and 39GHz ('Above 6GHz'). In addition, for 6G mobile communication technology, which is called the system after 5G communication (Beyond 5G), implementation in the terahertz (THz) band (for example, 3 THz band at 95GHz) is being considered to achieve a transmission speed that is 50 times faster than 5G mobile communication technology and an ultra-low latency time that is reduced to one-tenth.
[0003] In the early stages of 5G mobile communication technology, the goal is to support services and satisfy performance requirements for enhanced Mobile Broadband (eMBB), Ultra-Reliable Low-Latency Communications (URLLC), and massive Machine-Type Communications (mMTC). These include beamforming and massive MIMO to mitigate path loss of radio waves in ultra-high frequency bands and increase the transmission distance of radio waves, support for various numerologies (such as operation of multiple subcarrier intervals) and dynamic operation of slot formats for efficient use of ultra-high frequency resources, initial access technology to support multi-beam transmission and wideband, definition and operation of BWP (Bidth Part), new channel coding methods such as LDPC (Low Density Parity Check) codes for large-capacity data transmission and Polar Code for reliable transmission of control information, and L2 pre-processing (L2). Standardization has been made for network slicing, which provides dedicated networks specialized for specific services, and pre-processing.
[0004] Currently, discussions are underway to improve and enhance the initial 5G mobile communication technology in consideration of the services that 5G mobile communication technology was intended to support, and physical layer standardization is in progress for technologies such as V2X (Vehicle-to-Everything) to help autonomous vehicles make driving decisions and increase user convenience based on their own location and status information transmitted by vehicles, NR-U (New Radio Unlicensed) for the purpose of system operation that complies with various regulatory requirements in unlicensed bands, NR terminal low power consumption technology (UE Power Saving), Non-Terrestrial Network (NTN), which is direct terminal-satellite communication to secure coverage in areas where communication with terrestrial networks is impossible, and Positioning.
[0005] In addition, standardization of wireless interface architecture / protocols is in progress for technologies such as intelligent factories (Industrial Internet of Things, IIoT) to support new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) that provides nodes for expanding network service areas by integrating wireless backhaul links and access links, Mobility Enhancement technology including Conditional Handover and Dual Active Protocol Stack (DAPS) handover, and 2-step random access (2-step RACH for NR) that simplifies random access procedures. Standardization is also in progress for system architecture / services such as 5G baseline architecture (e.g., Service-based Architecture, Service-based Interface) for grafting Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) that provides services based on the location of the terminal.
[0006] Once these 5G mobile communication systems are commercialized, an explosive increase in connected devices will be connected to the communication network, necessitating enhanced functionality and performance of 5G mobile communication systems and integrated operation of these connected devices. To this end, new research will be conducted on improving 5G performance and reducing complexity, supporting AI services, supporting metaverse services, and drone communications by utilizing eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).
[0007] In addition, the development of these 5G mobile communication systems includes new waveforms to ensure coverage in the terahertz band of 6G mobile communication technology, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), Array Antenna, and Large Scale Antenna, metamaterial-based lenses and antennas to improve the coverage of terahertz band signals, high-dimensional spatial multiplexing technology using Orbital Angular Momentum (OAM), Reconfigurable Intelligent Surface (RIS) technology, as well as full duplex technology to improve the frequency efficiency and system network of 6G mobile communication technology, satellite, AI (Artificial Intelligence) from the design stage and AI-based communication technology that realizes system optimization by internalizing end-to-end AI support functions, and ultra-high-performance communication and computing resources to provide services with complexity that exceeds the limits of terminal computing capabilities. It can serve as a basis for the development of next-generation distributed computing technologies that can be realized by utilizing them.
[0008] An object of the present invention is to provide a method and a terminal for transferring a profile to the outside of an embedded universal integrated circuit card (eUICC) of a terminal.
[0009] According to one embodiment of the present disclosure for solving the above problem, a method performed by a terminal in a wireless communication system is provided. The method may include: transmitting a first message including additionalprofile information to a profile server for profile installation; and, when the additionalprofile information is set to a preset value, receiving a second message including information on the predicted profile size from the profile server; controlling to secure embedded universal integrated circuit card (eUICC) memory based on reception of the second message including information on the predicted profile size; and performing the profile installation based on the securing of the eUICC memory.
[0010] According to another embodiment of the present disclosure, a method performed by a profile server in a wireless communication system is provided. The method may include: receiving a first message including additional profile information from a terminal for profile installation; determining whether the additional profile information is set to a preset value; and transmitting a second message including information about a predicted profile size if the additional profile information is set to a preset value.
[0011] According to another embodiment of the present disclosure, a terminal is provided in a wireless communication system. The terminal may include a transceiver; and a control unit configured to transmit a first message including additionalprofile information to a profile server for profile installation through the transceiver, and, when the additionalprofile information is set to a preset value, receive a second message including information on the predicted profile size from the profile server through the transceiver, and, based on reception of the second message including information on the predicted profile size, control to secure embedded universal integrated circuit card (eUICC) memory, and control to perform profile installation based on the securing of the eUICC memory.
[0012] According to another embodiment of the present disclosure, a profile server is provided in a wireless communication system. The profile server may include a transceiver; and a step of receiving a first message including additional profile information from a terminal for profile installation through the transceiver, and determining whether the additional profile information is set to a preset value; and a control unit controlling transmission of a second message including information on a predicted profile size if the additional profile information is set to a preset value.
[0013] According to one embodiment of the present invention, it is possible to efficiently transfer a profile outside of an eUICC of a terminal.
[0014] The effects that can be obtained from the present disclosure are not limited to the effects mentioned in the various embodiments, and other effects that are not mentioned can be clearly understood by a person having ordinary skill in the art to which the present disclosure belongs from the description below.
[0015] FIG. 1 is a diagram showing the relationship between components for moving a profile according to one embodiment of the present disclosure.
[0016] FIG. 2 is a diagram illustrating a procedure for moving a profile outside an eUICC according to one embodiment of the present disclosure.
[0017] FIG. 3 is another diagram illustrating a procedure for moving a profile outside an eUICC according to another embodiment of the present disclosure.
[0018] FIG. 4 is a diagram illustrating an example of checking eUICC available memory and moving a profile when installing a profile download according to an embodiment of the present disclosure.
[0019] FIG. 5 is a diagram illustrating an example of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
[0020] FIG. 6 is another diagram illustrating another embodiment of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
[0021] FIG. 7 is a diagram illustrating a method for resuming installation of an existing profile after moving a profile within a terminal according to an embodiment of the present disclosure.
[0022] Figure 8 is a diagram illustrating a method for resuming installation of an existing profile after moving the profile within the terminal.
[0023] FIG. 9 is a diagram illustrating a procedure for moving a profile from an eUICC to outside the eUICC according to one embodiment of the present disclosure.
[0024] FIG. 10 is a diagram illustrating a configuration of a terminal according to some embodiments of the present disclosure.
[0025] FIG. 11 is a diagram illustrating a configuration of a server according to some embodiments of the present disclosure.
[0026] FIG. 12a is a diagram illustrating an example of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
[0027] FIG. 12b is a diagram illustrating a specific embodiment of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
[0028] FIG. 13 is a diagram illustrating an embodiment in which a profile server provides a session maintenance time to a terminal according to one embodiment of the present disclosure.
[0029] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.
[0030] In describing the embodiments, descriptions of technical details that are well known in the technical field to which the present disclosure pertains and are not directly related to the present disclosure will be omitted. This is to convey the gist of the present disclosure more clearly without obscuring it by omitting unnecessary explanations.
[0031] For the same reason, some components in the attached drawings are exaggerated, omitted, or schematically depicted. Furthermore, the dimensions of each component do not entirely reflect its actual size. Identical or corresponding components in each drawing are assigned the same reference numbers.
[0032] The advantages and features of the present disclosure, and methods for achieving them, will become clearer with reference to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided solely to ensure that the present disclosure is complete and to fully inform those skilled in the art of the scope of the disclosure, and the present disclosure is defined only by the scope of the claims. Like reference numerals designate like elements throughout the specification.
[0033] At this time, it will be understood that each block of the processing flowchart drawings and combinations of the flowchart drawings can be performed by computer program instructions. These computer program instructions can be installed in a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, so that the instructions executed by the processor of the computer or other programmable data processing equipment create a means for performing the functions described in the flowchart block(s). These computer program instructions can also be stored in a computer-available or computer-readable memory that can direct a computer or other programmable data processing equipment to implement the functions in a specific manner, so that the instructions stored in the computer-available or computer-readable memory can also produce a manufactured item that includes an instruction means for performing the functions described in the flowchart block(s). Since the computer program instructions may be installed on a computer or other programmable data processing device, a series of operational steps may be performed on the computer or other programmable data processing device to create a computer-executable process, and the instructions that cause the computer or other programmable data processing device to perform the steps for performing the functions described in the flowchart block(s) may also provide steps for performing the functions described in the flowchart block(s).
[0034] Additionally, each block may represent a module, segment, or portion of code that contains one or more executable instructions for performing a specific logical function(s). It should also be noted that in some alternative implementation examples, the functions described in the blocks may occur out of order. For example, two blocks depicted in succession may actually be executed substantially concurrently, or the blocks may sometimes be executed in reverse order, depending on their respective functions.
[0035] Here, the term '~ unit' used in the present embodiment means a software or hardware component such as an FPGA or ASIC, and the '~ unit' performs certain roles. However, the '~ unit' is not limited to software or hardware. The '~ unit' may be configured to be on an addressable storage medium and may be configured to play one or more processors. Accordingly, as an example, the '~ unit' includes components such as software components, object-oriented software components, class components, and task components, processes, functions, properties, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and '~ units' may be combined into a smaller number of components and '~ units' or further separated into additional components and '~ units'. Additionally, components and '~parts' may be implemented to regenerate one or more CPUs within a device or secure multimedia card.
[0036] In this disclosure, modifiers such as "first" and "second" that designate terms may be used to distinguish each term from another when describing embodiments. The terms modified by modifiers such as "first" and "second" may refer to different objects. However, the terms modified by modifiers such as "first" and "second" may also refer to the same object. That is, modifiers such as "first" and "second" may be used to refer to the same object from different perspectives. For example, modifiers such as "first" and "second" may be used to distinguish the same object from a functional or operational perspective. For example, "first user" and "second user" may refer to the same user.
[0037] Furthermore, while the present disclosure describes each embodiment using eUICC as an example of a security module, the scope of the present disclosure is not limited to eUICC. For example, it will be apparent to those skilled in the art that the various embodiments described below can be applied substantially identically or similarly to other security media that perform functions substantially identical or similar to eUICC.
[0038] Certain terms used in the following description are provided to aid in understanding the present disclosure, and the use of such specific terms may be changed to other forms without departing from the technical spirit of the present disclosure.
[0039] To meet the increasing demand for wireless data traffic since the commercialization of 4G communication systems, efforts are being made to develop improved 5G or pre-5G communication systems. For this reason, 5G or pre-5G communication systems are also called beyond 4G network (Beyond 4G Network) or post-LTE (Post LTE) systems. To achieve high data rates, 5G communication systems are being considered for implementation in ultra-high frequency (mmWave) bands (e.g., 60 GHz bands). To mitigate path loss and increase transmission range of radio waves in ultra-high frequency bands, beamforming, massive MIMO, full-dimensional MIMO (FD-MIMO), array antennas, analog beamforming, and large-scale antenna technologies are being discussed in 5G communication systems. In addition, to improve the network of the system, technologies such as evolved small cells, advanced small cells, cloud radio access networks (cloud RAN), ultra-dense networks, device-to-device communication (D2D), wireless backhaul, moving networks, cooperative communication, CoMP (Coordinated Multi-Points), and interference cancellation are being developed in 5G communication systems.In addition, advanced coding modulation (ACM) methods such as FQAM (Hybrid FSK and QAM Modulation) and SWSC (Sliding Window Superposition Coding), as well as advanced access technologies such as FBMC (Filter Bank Multi Carrier), NOMA (non-orthogonal multiple access), and SCMA (sparse code multiple access) are being developed in 5G systems.
[0040] Meanwhile, the Internet is evolving from a human-centric network where humans create and consume information to an Internet of Things (IoT) network where information is exchanged and processed between distributed components, such as objects. The Internet of Everything (IoE) is also emerging, combining IoT technologies with big data processing technologies, such as those connected to cloud servers. To implement the IoT, technological elements such as sensing technology, wireless and wired communication and network infrastructure, service interface technology, and security technology are required. Recently, research is being conducted on technologies such as sensor networks, Machine-to-Machine (M2M), and Machine-Type Communication (MTC) for connecting objects. In the IoT environment, intelligent IT (Internet Technology) services can be provided that collect and analyze data generated from connected objects to create new value for human life. IoT can be applied to areas such as smart homes, smart buildings, smart cities, smart or connected cars, smart grids, healthcare, smart appliances, and advanced medical services through the convergence and integration of existing IT (information technology) technologies with various industries.
[0041] Accordingly, various attempts are being made to apply 5G communication systems to IoT networks. For example, technologies such as sensor networks, machine-to-machine (M2M), and machine-type communication (MTC) are being implemented using 5G communication techniques such as beamforming, MIMO, and array antennas. The application of cloud RAN, a big data processing technology described above, can also be considered an example of the convergence of 5G and IoT technologies.
[0042] As described above, the advancement of mobile communication systems has enabled the provision of a variety of services, creating a need for effective solutions to facilitate these services. For example, one or more profiles containing user subscription information can be installed and used on an eSIM chip within a terminal. In cases of insufficient storage space, profiles can be exported from the eSIM chip and then reinstalled on the same or a different eSIM chip.
[0043] According to an embodiment of the present disclosure, a method for exporting a first profile from an eSIM chip in a first terminal in a wireless communication system and then installing it in the same eSIM chip may further include a step of providing, from the terminal to a profile server, information on whether the terminal and the eSIM chip support external storage during the process of installing a new profile, a step of determining whether to send a reply message including additional information on the size of the profile to be installed based on information received from the profile server, a step of checking available memory in the eUICC based on a message received from the profile server in the terminal, a step of performing a determination including a determination as to whether there is a profile that can be moved outside the eUICC, a step of processing a profile move outside the eSIM chip if there is a profile that can be moved, and a step of performing profile installation after performing the profile move.
[0044] According to various embodiments of the present disclosure, if a terminal user runs out of storage space on the eSIM chip during the process of installing a new profile, the terminal user can only delete and reinstall a previously purchased profile. However, the terminal user can move and store the profile outside the eSIM chip and then reinstall it on the eSIM chip when needed. Accordingly, the terminal user can keep the profile he or she purchased and reinstall it on the eSIM chip when needed, thereby reducing the cost incurred when deleting and reinstalling the profile.
[0045] Meanwhile, terminal manufacturers can improve user convenience by solving the problem of limited eSIM chip memory capacity by utilizing storage space outside the eSIM chip.
[0046] "SE (Secure Element)" may refer to a security module consisting of a single chip that can store security information (e.g., mobile network access keys, user identification information such as ID cards / passports, credit card information, encryption keys, etc.) and operate a control module (e.g., network access control module such as USIM, encryption module, key generation module, etc.) that utilizes the stored security information. SE may be used in various electronic devices (e.g., smartphones, tablets, wearable devices, automobiles, IoT devices, etc.) and provide security services (e.g., mobile network access, payment, user authentication, etc.) through security information and control modules.
[0047] SE can be divided into UICC (Universal Integrated Circuit Card), eSE (Embedded Secure Element), SSP (Smart Secure Platform), which is an integrated form of UICC and eSE, and can be further subdivided into removable, fixed (Embedded), and integrated (Integrated) types that are integrated into specific components or SoC (system on chip) depending on the form in which they are connected or installed in electronic devices.
[0048] A "UICC (Universal Integrated Circuit Card)" is a smart card inserted into mobile communication terminals and is also called a UICC card. A UICC may include an access control module for connecting to a mobile communication service provider's network. Examples of access control modules include a Universal Subscriber Identity Module (USIM), a Subscriber Identity Module (SIM), and an IP Multimedia Service Identity Module (ISIM). A UICC containing a USIM is commonly referred to as a USIM card. Similarly, a UICC containing a SIM module is commonly referred to as a SIM card. Meanwhile, the SIM module may be installed during the UICC manufacturing process, or the user may download the desired mobile communication service's SIM module onto the UICC card at any time. Furthermore, multiple SIM modules may be downloaded and installed on a UICC card, and at least one SIM module may be selected and used. Such a UICC card may or may not be fixed to the terminal. In particular, a UICC embedded in a System-On-Chip (SoC) including a communication processor, an application processor, or a single processor structure in which these two processors are integrated is also referred to as an iUICC (Integrated UICC). Typically, eUICC and iUICC may refer to a UICC card that is fixedly used in a terminal and includes a function that allows at least one SIM module to be remotely downloaded to the UICC card and any one of the downloaded SIM modules to be selected. In the present disclosure, a UICC card that includes a function that allows at least one SIM module to be remotely downloaded and the SIM module to be selected is collectively referred to as an eUICC or iUICC.For example, among UICC cards that include functions that allow a SIM module to be downloaded remotely and a SIM module to be selected, a UICC card that is fixed or not fixed to a terminal is collectively referred to as an eUICC or iUICC. In the present disclosure, the term UICC may be used interchangeably with SIM, and the term eUICC may be used interchangeably with eSIM (chip).
[0049] The "eUICC identifier (eUICC ID)" may be a unique identifier of the eUICC embedded in the terminal and may be referred to as EID. In addition, if a provisioning profile is pre-loaded in the eUICC, the eUICC identifier (eUICC ID) may be an identifier of the corresponding provisioning profile (Profile ID of the Provisioning Profile). In addition, in one embodiment of the present disclosure, if the terminal and the eUICC chip are not separated, the eUICC identifier (eUICC ID) may be a terminal ID. In addition, the eUICC identifier (eUICC ID) may refer to a specific secure domain (Secure Domain) of the eUICC chip. The eUICC identifier may also be provided as predetermined information included in an eUICC certificate. In the present disclosure, providing the EID may be a certificate including EID information or the EID information itself.
[0050] "eSE (Embedded Secure Element)" refers to a fixed SE that is fixed to an electronic device and used. An eSE is typically manufactured exclusively for the terminal manufacturer upon request, and may include an operating system and framework. An applet-type service control module can be remotely downloaded and installed on the eSE, and the installed service control module can be used for various security services such as electronic wallets, ticketing, electronic passports, and digital keys. In the present disclosure, a single-chip SE that can be remotely downloaded and installed with a service control module and attached to an electronic device is collectively referred to as an eSE.
[0051] “Profile” may refer to data objects such as applications, file systems, and authentication key values stored within the UICC.
[0052] In the present disclosure, a "profile package" may mean that the contents of a "profile" are packaged in a software form that can be installed in a UICC. A "profile package" may be referred to as a Profile Package TLV. If the profile package is encrypted using encryption parameters, it may be referred to as a Protected Profile Package (PPP) or a Protected Profile Package TLV (PPP TLV). If the profile package is encrypted using encryption parameters that can only be decrypted by a specific eUICC, it may be referred to as a Bound Profile Package (BPP) or a Bound Profile Package TLV (BPP TLV). A Profile Package TLV may be a data set that expresses information that constitutes a profile in the TLV (Tag, Length, Value) format.
[0053] In the present disclosure, a 'profile image' may refer to binary data of a profile package installed in a UICC. The 'profile image' may be referred to as a Profile TLV or a Profile Image TLV. If the profile image is encrypted using encryption parameters, it may be referred to as a PPI or a Protected Profile Image TLV (PPI TLV). If the profile image is encrypted using encryption parameters that can only be decrypted by a specific eUICC, it may be referred to as a BPI or a Bundled Profile Image TLV (BPI TLV). The profile image TLV may be a data set representing information that constitutes a profile in TLV format. It should be noted that in the present disclosure, when it is determined that no special distinction is necessary for the invention, the 'profile image' is expressed as a profile package or a profile. Therefore, in the present disclosure, an 'EPP (Exported Profile Package)' may be a profile image generated from an installed first profile.
[0054] In order not to obscure the logic of the invention, in this disclosure, it can be expressed as EPP without distinction whether it is composed of part or all of the data of Profile 1.
[0055] In the present disclosure, the "state" of a profile may mean one of the states of the profile defined in the SGP.22 specification defined by the GSMA. The "profile identifier" may be referred to as an argument that matches a profile identifier (Profile ID), an Integrated Circuit Card ID (ICCID), a Matching ID, an Event ID, an Activation Code, an Activation Code Token, a Command Code, a Command Code Token, a Signed Command Code, an Unsigned Command Code, an ISD-P, or a Profile Domain (PD). The profile identifier (Profile ID) may represent a unique identifier of each profile. The profile identifier may further include the address of a profile providing server (SM-DP+) that can index the profile. In addition, the profile identifier may further include the signature of the profile providing server (SM-DP+).
[0056] “RSP Server (Remote SIM Provisioning Server)” may be used as a name to refer to a profile (provisioning) server, a profile management server, and / or an activation brokerage server, which will be described later. The RSP server may be expressed as SM-XX (Subscription Manager XX).
[0057] In the present disclosure, a "profile server" may include a function of generating a profile, encrypting a generated profile, generating a profile remote management command, or encrypting a generated profile remote management command. For example, the profile server may be expressed as a Subscription Manager Data Preparation (SM-DP), a Subscription Manager Data Preparation plus (SM-DP+), an off-card entity of a Profile Domain, a profile encryption server, a profile generation server, a profile provider (Profile Provisioner, PP), a profile provider, or a profile provisioning credentials holder (PPC holder).
[0058] In the present disclosure, a “profile management server” may include a function for managing a profile. For example, the profile management server may be expressed as SM-SR (Subscription Manager Secure Routing), SM-SR+ (Subscription Manager Secure Routing Plus), an off-card entity of eUICC Profile Manager or PMC holder (Profile Management Credentials holder), EM (eUICC Manager), or PP (Profile Manager).
[0059] In this disclosure, the profile server may also mean a combination of the functions of a profile management server. Accordingly, in various embodiments of the present disclosure, the operations of the profile server may be performed by the profile management server. Similarly, the operations of the profile management server or SM-SR may be performed by the profile provision server.
[0060] In the present disclosure, the "opening brokerage server" may be expressed as a Subscription Manager Discovery Service (SM-DS), a Discovery Service (DS), a Root SM-DS, or an Alternative SM-DS. The opening brokerage server may receive an event registration request (Register Event Request, Event Register Request) from one or more profile providing servers or opening brokerage servers. In addition, one or more opening brokerage servers may be used in combination, and in this case, the first opening brokerage server may receive an event registration request not only from the profile providing server but also from the second opening brokerage server.
[0061] "Mobile service provider" may refer to a business entity that provides communication services to terminals, and may collectively refer to the business supporting system (BSS), operational supporting system (OSS), point of sale terminal, and other IT systems of the mobile service provider. In addition, in the present disclosure, the mobile service provider is not limited to representing a single specific business entity that provides communication services, but may also be used as a term referring to a group or association (or consortium) of one or more businesses, or an agent representing the group or association. In addition, in the present disclosure, the mobile service provider may be referred to as an operator (or OP or Op.), a mobile network operator (MNO), a mobile virtual network operator (MVNO), a service provider (or SP), a profile owner (PO), a mobile service operator, etc., and each mobile service operator may set or be assigned at least one name and / or object identifier (OID) of the mobile service provider. If the carrier refers to a group or association or agency of one or more businesses, the name or unique identifier of any group or association or agency may be a name or unique identifier shared by all businesses belonging to that group or association or all businesses cooperating with that agency.
[0062] The term "Subscriber" can refer to either the Service Provider who owns the terminal, or the End User who owns the terminal. Typically, a terminal owned by a Service Provider is referred to as an M2M Device, while a terminal owned by a User is referred to as a Consumer Device. In the case of M2M terminals, there may be an End User who does not own the terminal but transfers or leases the terminal from the Service Provider. In this case, the Subscriber and the Service Provider may be different or the same.
[0063] A 'terminal' may be referred to as a mobile station (MS), user equipment (UE), user terminal (UT), wireless terminal, access terminal (AT), terminal, subscriber unit (SU), subscriber station (SS), wireless device, wireless communication device, wireless transmit / receive unit (WTRU), mobile node, mobile, or other terms. Various embodiments of the terminal may include a cellular telephone, a smart phone having a wireless communication function, a personal digital assistant (PDA) having a wireless communication function, a wireless modem, a portable computer having a wireless communication function, a photographing device such as a digital camera having a wireless communication function, a gaming device having a wireless communication function, a music storage and playback home appliance having a wireless communication function, an internet home appliance capable of wireless internet access and browsing, as well as portable units or terminals that integrate combinations of such functions. In addition, the terminal may include, but is not limited to, an M2M (Machine to Machine) terminal, an MTC (Machine Type Communication) terminal / device. In the present disclosure, a terminal may also be referred to as an electronic device.
[0064] In the present disclosure, an electronic device may be equipped with a UICC capable of downloading and installing a profile. If the UICC is not embedded in the electronic device, a UICC physically separated from the electronic device may be inserted into and connected to the electronic device. For example, the UICC may be inserted into the electronic device in the form of a card. The electronic device may include a terminal, and in this case, the terminal may be a terminal including a UICC capable of downloading and installing a profile. The UICC may be embedded in the terminal, or, if the terminal and the UICC are separated, the UICC may be inserted into the terminal and connected to the terminal. A UICC capable of downloading and installing a profile may be referred to, for example, as an eUICC.
[0065] “LPA (Local Profile Assistant)” may refer to software or an application installed in a terminal or electronic device to control a UICC or eUICC in the terminal or electronic device. In the present disclosure, when it is expressed that a terminal transmits a command to an eUICC or a terminal receives a command from an eUICC, the endpoint of the terminal may be interpreted as an LPA. When it is expressed that it is stored in an LPA, it may be interpreted to mean that it is stored in an internal or external memory of the terminal that is accessible from the LPA. For example, it may be applied not only to a fixed or removable memory of a terminal in which an LPA is installed, but also to an external memory connected to the terminal via wired or wireless connection, or to the memory of a cloud server. In this drawing, for example, an explanation is made assuming an internal memory of the terminal. “Event” may be used in the present disclosure for the following purposes. Of course, it is not limited to the following examples.
[0066] An "Event" may be a term that includes a Profile Download, or a Remote Profile Management, or other profile or eUICC management / processing command. An Event may be named a Remote SIM Provisioning Operation (or an RSP Operation) or an Event Record, and each Event may be referred to as data including at least one corresponding Event Identifier (Event ID, EventID) or Matching Identifier (Matching ID, MatchingID), an address (FQDN, IP Address, or URL) of a Profile Provisioning Server (SM-DP+) or a Mobile Activation Server (SM-DS) where the event is stored, a signature of the Profile Provisioning Server (SM-DP+) or the Mobile Activation Server (SM-DS), and a digital certificate of the Profile Provisioning Server (SM-DP+) or the Mobile Activation Server (SM-DS).
[0067] Data corresponding to an event may be referred to as a "command code." Part or all of the procedure utilizing the command code may be referred to as a "command code processing procedure," a "command code procedure," or an "LPA API (Local Profile Assistant Application Programming Interface)." Profile download may be used interchangeably with profile installation.
[0068] Additionally, "Event Type" may be used as a term to indicate whether a particular event is a profile download, remote profile management (e.g., delete, activate, deactivate, replace, update, etc.), or other profile or eUICC management / processing command, and may be named as Operation Type (or OperationType), Operation Class (or OperationClass), Event Request Type, Event Class, Event Request Class, etc. Any event identifier (EventID or MatchingID) may be specified with the path through which the terminal acquired the event identifier (EventID or MatchingID) or its usage purpose (EventID Source or MatchingID Source).
[0069] "Local Profile Management (LPM)" can be named as Profile Local Management, Local Management, Local Management Command, Local Command, Local Profile Management Package (LPM Package), Profile Local Management Package, Local Management Package (LOCAL MANAGEMENT PACKAGE), Local Management Command Package, Local Command Package. LPM can be used to change the status (Enabled, Disabled, Deleted) of a specific profile or to change (update) the contents of a specific profile (e.g., Profile Nickname, Profile Summary Information (Profile Metadata), etc.) through software installed on the terminal. LPM can include one or more local management commands, in which case the target profiles of each local management command can be the same or different for each local management command.
[0070] A "certificate" or digital certificate can refer to a digital certificate used for mutual authentication based on an asymmetric key, which consists of a pair of public keys (PK) and secret keys (SK). Each certificate can include one or more public keys (PK), a public key identifier (PKID) corresponding to each public key, an identifier (Certificate Issuer ID) of the certificate issuer (CI) that issued the certificate, and a digital signature. For example, the certificate issuer can be named a certification issuer, a certificate authority (CA), or a certification authority. For example, in the present disclosure, a public key (PK) and a public key identifier (PKID) may be used to refer to a specific public key or a certificate including the public key, or a portion of the specific public key or a portion of the certificate including the public key, or a computational result (e.g., hash) value of the specific public key or a computational result (e.g., hash) value of the certificate including the public key, or a computational result (e.g., hash) value of a portion of the specific public key or a computational result (e.g., hash) value of a portion of the certificate including the public key, or a storage space where data is stored.
[0071] A "Certificate Chain" or Certificate Hierarchy can indicate the relationship between certificates issued by a "Certificate Issuer" (primary certificate) when those certificates are used to issue other certificates (secondary certificates), or when secondary certificates are used to issue three or more certificates in a chain. For example, the CI certificate used to issue the initial certificate may be named the Root of Certificate, the top-level certificate, the Root CI, the Root CI Certificate, the Root CA, or the Root CA Certificate.
[0072] In the embodiments of the present disclosure below, when it is expressed as “signing and transmitting data” or “transmitting signed data,” it may mean that the transmitting entity digitally signs the data to be transmitted with its own private key to ensure the integrity of the data to be transmitted, for example, the transmitting entity constructs and transmits a message including a signature. For example, the expression that the eUICC transmits a deletion result signed by the eUICC or that the eUICC signs and transmits the deletion result may be interpreted to mean that the eUICC transmits a message including the deletion result data and a signature signed by its own private key. The receiving side can verify the signature included in the message with the corresponding public key (e.g., the public key of the eUICC) to determine whether the data has been tampered with and determine its integrity.
[0073] "ES (External Storage) migration support" can be interpreted as a function that supports the migration storage of profiles installed on an eUICC to outside of the eUICC. ES migration support can be expressed interchangeably with ES support. From the profile server's perspective, ES migration support may refer to a function that provides additional information that the terminal can refer to in order to secure available memory of the eUICC when the profile server determines that the eUICC does not have sufficient memory for installing a profile that the terminal wants to provide. According to one embodiment, the additional information that the terminal can refer to may be the expected installation data size of the corresponding profile that the user wants to download. This profile data size information can be utilized as information for the terminal to perform a deletion or migration procedure of one or more profiles from the eUICC of the terminal. Therefore, in the present invention, a profile server that can provide the corresponding function (providing the expected data size of the corresponding profile that the user wants to download according to one embodiment) should be interpreted as an "ES migration support" profile server.
[0074] Meanwhile, the above ES can also be used as a concept including Extended Storage.
[0075] Terminal information may refer to Device Info defined in SGP.22 as the capability of the terminal. Referring to SGP.22, Device Info may include LpaRspCapability as the capability of LPA for RSP (Remote SIM Provisioning). Therefore, in the drawing described below, terminal information including “ES support” may be interpreted to mean that the terminal or an entity configuring the terminal includes “ES support” information in the capability information of the LPA.
[0076] Meanwhile, as a method of determining whether a profile stored in an eUICC is a profile that can be moved to an eUICC external memory, the term "ES support" of the profile is used in the drawings described below. ES support of a profile may include at least one of an ES movement support (allowance) identifier or a split extraction identifier (for example, when storing security data such as a network key in the eUICC by distinguishing them). Meanwhile, in order not to obscure the point in the drawings described below, an example is given where the profile has explicit identification information, but it may also be possible for the terminal (LPA) and / or the ES-supporting eUICC to regard the profile(s) installed in the ES-supporting eUICC as "ES movement support."
[0077] The insufficient Memory indicator may be an indicator that explicitly indicates insufficient. However, if the estimated Profile Size is returned, the terminal may consider that the estimated Profile Size indicates insufficient memory. For example, in the drawings of the present embodiment, the estimated Profile Size is returned and the insufficient memory is returned separately, but the insufficient memory indicator may be replaced with the estimated Profile Size. Meanwhile, the indicator indicating insufficient may be indicated as one of the data included in the reply message that the profile server returns to the terminal or within the reply message.
[0078] In addition, when describing the present disclosure, if it is determined that a specific description of a related function or configuration may unnecessarily obscure the gist of the present disclosure, the detailed description is omitted.
[0079] In addition, since the present disclosure describes the installation procedure of a profile of the GSMA (GSMA Association) SGP standard, for example, the SGP.22 standard, it can be interpreted with reference thereto. In describing the present disclosure, the named functions, data, and parameter names can be changed in various ways depending on the embodiment.
[0080] FIG. 1 is a diagram showing the relationship between components for moving a profile according to one embodiment of the present disclosure.
[0081] An eUICC (130) may be mounted on a terminal (110), and a profile (not shown) may be installed on the eUICC (130). In addition, an LPA (120) may be installed on the terminal (110). The eUICC (130) may be controlled by the LPA (120). The user (100) may control the eUICC (130) of the terminal (110) through the LPA (120) of the terminal (110). There may be multiple eUICCs (130) mounted on the terminal (110). In the case where there are multiple eUICCs (130), it may be assumed that there are multiple LPAs (120) controlling each eUICC (130). The eUICC (130) may support movement of a profile within the terminal (110).
[0082] The LPA (120) can store profile data in the terminal (110), and in the following drawing, the case of storing in the terminal (110) through the LPA (120) can be used interchangeably as “data stored in the LPA (120)” or “data stored in the terminal (110).” The LPA (120) can support moving the profile to outside the eUICC (130). Here, the case of storing in the terminal (110) through the LPA (120) may mean that the LPA (120) receives profile data from the eUICC (130) and stores it in the memory (not shown) of the terminal (110), or the LPA (120) may request the eUICC (130) to store the profile data externally, causing the eUICC (130) to process the storage in the memory (110) of the terminal and return the processing result to the LPA (120). Therefore, it should be noted that the meaning of “storing in LPA (120)” encompasses both of these cases, and the present invention, which will be described later, can be applied to both of these cases.
[0083] A telecommunications service provider (150) may be connected to a profile server (160). The telecommunications service provider (150) may be configured with one or more service provider servers. For convenience, the drawing illustrates a case where it is configured as a single server. However, depending on the implementation and embodiment, one or more profile servers (SM-DP+) may be included in the server configuration, and one or more opening brokerage servers (SM-DS) that assist in creating a connection between a specific profile server and a terminal may be included in the server configuration. In this way, the configuration of various servers may be simply referred to as a single profile server or SM-DP+ in the following drawing.
[0084] A user (100) may have subscribed to a communication service of a telecommunications service provider (150) and may have installed profile(s) on the eUICC (130) of the terminal (110). In addition, the user (100) may wish to install an additional profile on the eUICC (130) of the terminal (110).
[0085] FIG. 2 is a diagram illustrating a procedure for moving a profile outside an eUICC according to one embodiment of the present disclosure.
[0086] The LPA (205) may request eUICC information from the eUICC (215) to configure and display a user screen. The eUICC (215) may reply to the LPA (205) with eUICC information, including whether "ES (External Storage) migration support" is provided (step 230). The eUICC information may be returned as information included in eUICCInfo2 defined in the GSMA SGP standard. Upon receiving the reply, the LPA (205) may request ES10c.getProfileInfo from the eUICC (215) to receive a List of Profiles, and further check whether the metadata of the profile includes identification information for ES migration support (step 235).
[0087] An example of what is being written can be added to eUICCInfo2 in the form of a data field as follows in ASN.1 format:
[0088] extStorageInfo
[0021] ExtStorageSpecificInfo OPTIONAL, -- reserved for SGP.60
[0089] Alternatively, it could be added as a new bit in EUICCInfo2 EuiccRspCapability, as in the example below.
[0090] extendedStorageSupport (25) -- #SupportedFromV3.XY# support for ExtendedStorage
[0091] LPA (205) can determine whether the ES movement function is enabled by referring to the "ES movement support" identification information of the received eUICC and the "ES movement support" identification information of the profile, or at least the "ES movement support" identification information of the eUICC. (Step 240)
[0092] If the received eUICC information (230) has ES migration support and the profile indicates ES support, the LPA (205) can display profiles that can be moved and saved on the user display screen. If the received eUICC information (230) does not have ES migration support information, or if the eUICC information (230) has ES support information but the profile does not have ES support information, the LPA (205) may not display profiles that can be moved and saved on the user screen and may end the profile migration procedure.
[0093] As mentioned above, whether the profiles support ES may be one of the identification information on whether the corresponding ICCID supports ES and information on separate storage of sensitive data.
[0094] Alternatively, the LPA may consider that the ICCID installed in the ES-supporting eUICC allows “ES support.” For example, if the eUICC information (230) contains ES support information, the LPA (205) may determine that the profiles are movable and display them on the user screen even if the profile does not explicitly contain ES support information. Thereafter, at a specific point in time, the terminal user (200) may select (243) a profile to be moved, and transmit a profile move request from the LPA (205) to the eUICC (215) outside the eUICC. The eUICC (215) that receives the profile move request may generate profile data to be moved outside the eUICC, and reply the generated profile data to the LPA (205). The LPA (205) may store the received data and process the move. (Step 245, described later in FIG. 9)
[0095] Meanwhile, before step 230, a “Move Profile Save” menu may be provided to the terminal user (200), and at this time, the user may select the “Move Profile Save” menu to start the procedure of FIG. 2.
[0096] FIG. 3 is another diagram illustrating a procedure for moving a profile outside an eUICC according to one embodiment of the present disclosure.
[0097] A situation may arise where the terminal determines whether it is necessary to move and store profiles outside the eUICC to secure available memory on the eUICC (step 325). For example, this may be the case when transferring profile(s) from another terminal to the eUICC during a device change process. Alternatively, this may be the case when installing a new profile, as detailed in subsequent drawings.
[0098] If there is insufficient eUICC memory for installing a new profile, the terminal can determine how many profiles must be deleted or moved to allow installation.
[0099] The LPA (305) can request eUICC information from the eUICC (315). The eUICC (315) can check the "ES (External Storage) transfer support" and extCardResource of the eUICC (315) and reply with additional remaining memory information to the LPA (305). The remaining memory information can be included in eUICCInfo2 and returned. For example, this information can be returned as information included in extCardResource. (Step 330)
[0100] The LPA (305) that supports ES (External Storage) movement, which has received the above remaining memory information, can determine whether there is insufficient space to install a profile in the eUICC (315) (step 335). In addition, the LPA (305) can check whether there is an additional profile to be moved.
[0101] For example, LPA (305) can receive metadata information of profiles by requesting ES10c.getProfileInfo to eUICC (315) to receive a List of Profiles. If there is a profile that includes identification information on whether ES movement is supported as the profile metadata, LPA (305) can determine that the profile is a profile that can be moved outside of eUICC (315) (step 345). Whether the profiles support ES can be one of identification information on whether the corresponding ICCID supports ES and information on separate storage of sensitive data. Alternatively, LPA can consider that “ES support” is allowed for an ICCID installed in an ES-supporting eUICC.
[0102] LPA (305) can display profiles that can be moved to external storage on the user display screen by referring to the "ES mobility support" information of the received eUICC and the "ES mobility support" information of the profile or at least the "ES mobility support" identification information of the eUICC. Alternatively, the terminal can determine the activation status of the profile and process all profiles that support mobility within the terminal among the inactive profiles as mobility according to the terminal settings. The terminal can also store the last use time and / or the first installation time among the inactive profiles and determine the order / number of profiles to be moved by referring to the stored information. As described above, the profiles that support mobility within the terminal may be profiles that have ES mobility function support identification information or may be all profiles installed on the ES-supporting eUICC.
[0103] Meanwhile, when a user (300) selects a profile to delete or move, the LPA (305) can additionally determine the activation status of the profile to be deleted. If the status of the profile is Enabled, when deleting or moving the profile, the LPA (305) can check whether the terminal is still able to connect to the network, and can additionally notify the user (300) that after deleting or moving the profile, it is necessary to maintain a network connection (e.g., a Wi-Fi connection) to proceed with the installation of the profile.
[0104] If the eUICC information received in step 330 does not contain ES movement support information, or if the eUICC information contains ES support information but there are no movable profiles, the LPA (305) may not display movable profiles and may terminate the profile movement procedure.
[0105] The LPA (305) can perform a procedure for moving a profile from the eUICC (315) to the terminal. As described later in FIG. 9, a profile move request can be transmitted from the LPA (305) to the eUICC (315). Upon receiving the profile move request, the eUICC (315) can generate profile data to be moved outside the eUICC (315) and reply the generated profile data to the LPA (305). Then, in step 350, the LPA (305) can store the received data and process the move. After processing the profile move storage, the LPA (305) can proceed with the requested operation. This can be, for example, a procedure such as profile installation or device change processing.
[0106] Hereinafter, the processing applied when installing the profile will be described in detail with reference to FIGS. 4 to 9, FIGS. 12a and 12b.
[0107] FIG. 4 is a diagram illustrating an example of checking eUICC available memory and moving a profile when installing a profile download according to an embodiment of the present disclosure.
[0108] FIG. 4 is a drawing for explaining a method applied in the process of a terminal user (400) installing a new profile on a terminal as an example of an operation that requires determining whether to move the profile(s) installed on the eUICC in the aforementioned FIG. 3 to outside the eUICC, according to one embodiment.
[0109] A terminal user (400) may want to download and install a new profile from the profile server (420).
[0110] At this time, the terminal can determine whether there is storage space in the eUICC (415) for installing the profile during the profile installation process. For example, the terminal's LPA (405) can first check the expected data size of the profile to be installed from the profile server.
[0111] During the mutual authentication process for installing a profile, the LPA (405) may transmit information about the terminal and eUICC to the profile server (420). For example, the information may be included in the data of an AuthenticateClient request message for client verification and transmitted. The terminal information may include "ES mobility support," eUICCInfo2 may include "ES mobility support," and the available memory information of the eUICC (415) may be transmitted. Information that can determine the available memory of the eUICC (415) may be included in the extCardResource data and transmitted in byte format. (Step 425)
[0112] If the profile server (420) that received the above information determines that the eSIM chip memory for profile installation is insufficient, it may return an error as response data. For example, the profile server (420) may return an error and an error reason of "insufficientMemory" as a response to AuthenticateClient.
[0113] Meanwhile, the profile server (420) may also respond with insufficientMemory when the "additionalProfile" bit in eUICCInfo2 is set to 0. This can be equally applied to FIGS. 5 to 9, 12a, and 12b described below.
[0114] The terminal LPA (405) that receives the above response may terminate the RSP session for profile installation. In addition, the LPA (405) may notify the user of insufficient storage space and terminate the profile installation procedure, or guide the user to delete the profile(s) and then proceed with installation.
[0115] If it is a profile server that supports ES movement, it may reply with insufficientMemory regardless of whether the "additionalProfile" bit is set to 1 in eUICCInfo2. If it receives at least one of "ES movement support" in the terminal information and "ES movement support" in eUICCInfo2, the profile server (420) may reply with an error and an error reason of "insufficientMemory" in the Response of AuthenticateClient, and may additionally transmit estimated profile size information. (Step 430)
[0116] The same content can be applied to FIGS. 5 to 9, 12a, and 12b described later.
[0117] The terminal LPA (405) that received the above reply may, even if it receives an error in the response from AuthencateClient, terminate the profile installation procedure (Cancel Session) or, without terminating it, perform an operation to secure additional storage space for profile installation in the eSIM chip when additionally receiving the estimated profile size. The operation to secure additional storage space may be a profile transfer or deletion procedure. The terminal may additionally obtain the user's consent to enter the profile transfer or deletion procedure.
[0118] The LPA (405) may additionally check information on previously installed profiles (steps 438 and 439) to determine whether there is a profile that can be moved outside the eSIM chip for the installation of the corresponding profile, and / or to determine the storage space that can be secured through the movement of the profile. For example, the LPA (405) may transmit GetProfileInfo (step 438) to the eUICC (415) and receive information on each profile from the eUICC (415) (step 439). At this time, the LPA (400) may check whether the profile(s) support ES with the information of the metadata of the received profile(s). Whether the profiles support ES may be one of the ES support identification information of the corresponding ICCID and information on the separate storage of sensitive data. Alternatively, the LPA may consider that “ES support” is allowed in the case of an ICCID installed in an ES-supporting eUICC. The LPA may further check the estimatedProfileSize of the received metadata or the number of profiles installed on the eUICC (step 439).
[0119] Based on the collected information, LPA (405) can determine whether space for storing a new profile download can be secured through profile movement. (Step 440) Information that LPA (405) utilizes for determination may be, for example, at least one of the available memory information of the eSIM chip collected from eUICCInfo2 in advance, and / or the estimated profile capacity (estimatedProfileSize) received from the profile server, whether the installed profiles support Ext. Storage received in Step 439, and estimatedProfileSize.
[0120] LPA (405) can terminate the installation if there is no profile among the installed profiles that supports ES movement even if eUICC (415) supports ES movement. (Step 445)
[0121] At the end of the installation (step 445, the same applies to step 435 above), the LPA (405) may request the eUICC (415) to terminate the session for profile installation by sending a CancelSession (CancelSessionReason, transaction Id) message to the eUICC as defined in SGP.22. In addition, the eUICC (415) that received the request may reply to the LPA with eUICC-signed data including the CancelSession Reason, so that the LPA (405) may transmit the data back to the profile server (420). At this time, the Cancel Session Reason may be a session termination (SessionAborted), or a Cancel Session Reason indicating that there is no ES-supported profile, for example, NoProfileWithExtStorageSupport, may be used.
[0122] Meanwhile, the profile server (420) can confirm the received Cancel Session message and terminate the RSP Session. The profile server (420) can provide the telecommunications service provider (not shown) with the reason for the profile installation error.
[0123] If there is a profile that can be moved outside of the eUICC (415), the LPA (405) can perform a profile moving procedure outside of the eUICC (415). (Step 450) This can be performed with or without terminating the session, as shown in FIGS. 7 and 8 described below.
[0124] The profile transfer procedure (step 450) may begin with the terminal user (400) selecting a profile to transfer or transferring a profile according to terminal settings. As described later in FIG. 9, a profile transfer request may be transmitted from the LPA (405) to the eUICC (415). Upon receiving the transfer request, the eUICC (415) may generate profile data to be transferred outside the eUICC and reply with the generated profile data to the LPA (405). The LPA (405) may store the received data and process the transfer. (step 450) After the LPA (405) processes the profile transfer storage, it may proceed with profile installation. (step 455)
[0125] For example, the terminal may process profile movement and continue the profile download procedure while maintaining an RSP session with the profile server (420), or
[0126] Or, after terminating (Cancel) the RSP Session with the profile server (420) and processing the profile transfer, start the profile installation from the beginning and proceed with the profile installation, or
[0127] Alternatively, the RSP Session with the profile server (420) may be resumed, the profile transfer may be processed, and then the profile installation may be resumed to perform subsequent processing.
[0128] Previously, when the terminal processes the profile transfer and continues the profile download procedure while maintaining the RSP Session with the profile server (420), for example, the LPA (405) may transmit an authenticateClient Request back to the profile server (420) to obtain profile metadata as a response to the request, thereby continuing the subsequent procedure.
[0129] FIG. 5 is a diagram illustrating an example of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
[0130] FIG. 5 is a drawing for explaining another method applied in the process of a terminal user (500) installing a new profile on a terminal as an example of an operation that requires determining whether to move the profile(s) installed on the eUICC in the aforementioned FIG. 3 to outside the eUICC, according to one embodiment.
[0131] A terminal user (500) may wish to download and install a new profile from a profile server (520). At this time, during the profile installation process, the terminal may determine whether there is storage space in the eUICC (515) for installing the corresponding profile.
[0132] For example, in the LPA (505) of the terminal, the expected data size of the profile to be installed can be first checked from the profile server.
[0133] During the mutual authentication process for installing a profile, the LPA (505) may transmit information about the terminal and eUICC (515) to the profile server (520). For example, the information may be included in the AuthenticateClient data for client verification and transmitted. The terminal information may include "ES mobility support," eUICCInfo2 may include "ES mobility support," and the available memory information of the eUICC (515) may be transmitted. Information that can determine the available memory of the eUICC (515) may be included in the extCardResource data and transmitted. (Step 525)
[0134] If the profile server (520) that received the above information determines that the memory of the eSIM chip for profile installation is insufficient, if the profile server (520) receives a message without “ES support” information in the terminal information or eUICCInfo2 information, or if the profile server (520) does not understand the ES support identifier, the profile server (520) may reply with an error and insufficientMemory as the error reason.
[0135] For example, the profile server (520) may reply with an error and an error reason of insufficientMemory as a response to AuthenticateClient. The terminal LPA (505) that receives the reply may terminate the RSP session for profile installation (step 535). In addition, the LPA may notify the user of insufficient storage space and terminate the profile installation procedure, or guide the user to delete the profile(s) and then proceed with installation.
[0136] If the profile server supports ES, the profile server (520) can generate and reply with a message response that includes information about the expected profile size. For example, if the server supports ES movement, if the terminal information includes "ES movement support" and eUICCInfo2 includes "ES movement support," the profile server (520) can, instead of sending an error, send a Response Ok from AuthenticateClient and indicate insufficient memory. At this time, information about the estimated profile size may also be included in the reply. (Step 530)
[0137] The Response Ok of the above AuthenticateClient may have a format as shown in Table 1 or Table 2, according to one embodiment.
[0138] AuthenticateClientOk ::= SEQUENCE {transactionId [0] TransactionId,insufficientMemory NULL OPTIONAL, - Not enough space for this Profile downloadestimatedProfileSize
[0033] INTEGER OPTIONAL -- estimated Profile Size to be downloaded,waitingTime INTEGER OPTIONAL, -- estimated time in minutes by when the SM-DP+ maintains the session for this Profile Download.esSessionId [X] OCTET STRING (SIZE(1..16)) OPTIONAL -- the LPA will use this identifier to check to restart session, or continue the remained RSP session}
[0139] AuthenticateClientOkExtStorage ::= SEQUENCE {transactionId [0] TransactionId,smdpSignedX SmdpSignedX, -- Signed informationsmdpSignature [APPLICATION 55] OCTET STRING -- tag '5F37'}SmdpSignedX ::= SEQUENCE { -- #SupportedForExtStorage#transactionId [0] TransactionId, -- The TransactionID generated by the SMDP+insufficientMemory NULL OPTIONAL, - Not enough space for this Profile downloadestimatedProfileSize
[0033] INTEGER OPTIONAL -- estimated Profile Size to be downloadedwaitingTime INTEGER OPTIONAL, -- estimated time in minutes by when the SM-DP+ maintains the session for this Profile Download.esSessionId [X] OCTET STRING (SIZE(1..16)) OPTIONAL -- the LPA will use this identifier to check to restart session, or continue the remained RSP session}
[0140] The terminal LPA (505) that has received the above information may perform an operation to additionally secure storage space for profile installation in the eSIM chip without entering the installation completion stage. The operation may be a profile movement or deletion procedure. The terminal may additionally obtain the user's consent to enter the profile movement or deletion procedure. The LPA (505) may additionally check information on previously installed profiles (steps 538 and 539) to determine whether there is a profile that can be moved outside the eSIM chip for the installation of the corresponding profile and / or to confirm the storage space that can be secured through profile movement. For example, the LPA (505) may transmit GetProfileInfo (step 538) to the eUICC (515) and receive information on each profile from the eUICC (515) (step 539). At this time, the LPA may check whether the profile(s) has an ES movement permission identifier using the information in the metadata of the received profile(s). Additionally, LPA (505) can further check the estimatedProfileSize of the received metadata or the number of profiles installed in the eUICC. (Step 539)
[0141] Based on the collected information, LPA (505) can determine whether space for storing new profile downloads can be secured through profile movement. (Step 540) Information that LPA (505) utilizes for determination may be, for example, at least one of the available memory information of the eSIM chip collected from eUICCInfo2 in advance, and / or the estimated profile capacity (estimatedProfileSize) received from the profile server, whether Ext. Storage of the installed profiles received in step 539, and estimatedProfileSize. Whether the profiles support ES may be one of the ES support identification information of the corresponding ICCID and information on separate storage of sensitive data. Alternatively, in the case of an ICCID installed in an ES-supporting eUICC, “ES support” may be considered to be allowed.
[0142] LPA (505) can terminate the installation if there is no profile among the installed profiles that supports ES movement even if eUICC (515) supports ES movement. (Step 545)
[0143] At the end of the installation (step 545, the same applies to step 535 above), the LPA (505) may request the eUICC (515) to terminate the session for profile installation by sending a CancelSession (CancelSessionReason, transaction Id) message to the eUICC (515) as defined in SGP.22. In addition, the eUICC (515) receiving this may reply to the LPA with eUICC-signed data including the CancelSession Reason, so that the LPA (505) may transmit this back to the profile server. At this time, the Cancel Session Reason may be a session termination (SessionAborted), or a Cancel Session Reason indicating that there is no ES-supported profile, for example, NoProfileWithExtStorageSupport, may be used.
[0144] Meanwhile, the profile server (520) can confirm the received Cancel Session message and terminate the RSP Session. The profile server (520) can provide the telecommunications service provider (not shown) with the reason for the profile installation error.
[0145] If there is a profile that can be moved outside the eUICC (515), the LPA (505) can perform a profile movement procedure outside the eUICC (515). (Step 550) This can be performed with or without terminating the session, as shown in FIGS. 7 and 8 described below.
[0146] The profile transfer procedure (step 550) may begin with the terminal user selecting a profile to transfer or transferring a profile according to terminal settings. As described later in FIG. 9, a profile transfer request may be transmitted from the LPA (505) to the eUICC (515). Upon receiving the transfer request, the eUICC (515) may generate profile data to be transferred outside the eUICC and reply to the LPA (505). The LPA (505) may store the received data to process the transfer. (Step 550) After the LPA (505) processes the profile transfer storage, it may proceed with profile installation. (Step 555)
[0147] For example, the terminal may process profile movement and continue the profile download procedure while maintaining an RSP session with the profile server (520), or
[0148] Or, after terminating (Cancel) the RSP Session with the profile server (520) and processing the profile transfer, start the profile installation from the beginning and proceed with the profile installation, or
[0149] Alternatively, the RSP Session with the profile server (520) may be resumed, the profile transfer may be processed, and then the profile installation may be resumed to perform subsequent processing.
[0150] Previously, when the terminal processes the profile transfer and continues the profile download procedure while maintaining the RSP Session with the profile server (520), for example, the LPA (505) may transmit an authenticateClient Request back to the profile server (520) and obtain profile metadata in response thereto, thereby continuing the subsequent procedure.
[0151] FIG. 6 is a diagram illustrating an example of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
[0152] FIG. 6 is a drawing for explaining another method applied in the process of a terminal user (600) installing a new profile on a terminal as an example of an operation that requires determining whether to move the profile(s) installed on the eUICC in the aforementioned FIG. 3 to outside the eUICC, according to one embodiment.
[0153] A terminal user (600) may wish to download and install a new profile from a profile server (620). At this time, during the profile installation process, the terminal may determine whether there is storage space in the eUICC (615) for installing the profile.
[0154] For example, the LPA (605) of the terminal can first check the expected data size of the profile to be installed from the profile server (620).
[0155] During the mutual authentication process for installing a profile, the LPA (605) may transmit information about the terminal and eUICC (615) to the profile server (620). For example, the information may be transmitted as part of AuthenticateClient data for client verification. The terminal information may include "ES mobility support," eUICCInfo2 may include "ES mobility support," and the available memory information of the eUICC (615) may be transmitted. Information that can determine the available memory of the eUICC (615) may be transmitted as part of extCardResource data. Additionally, estimatedProfileSizeIndicationSupport may be additionally included in eUICCInfo2 and transmitted. (Step 625)
[0156] If the profile server (620) that received the above information determines that the memory of the eSIM chip for profile installation is insufficient, if the profile server (620) receives a message without “ES support” information in the terminal information or eUICCInfo2 information, or if the profile server (620) does not understand the ES support identifier, the profile server (620) may reply with an error and insufficientMemory as the error reason.
[0157] For example, the profile server (620) may reply with an error and an error reason of insufficientMemory as a response to AuthenticateClient. The terminal LPA (605) that receives the response may terminate the RSP session for profile installation (step 635). In addition, the LPA (605) may notify the user of insufficient storage space and terminate the profile installation procedure, or guide the user to delete the profile(s) and then proceed with installation.
[0158] If the profile server (620) supports ES, instead of returning an error, it can return a success response even if insufficientMemory occurs. For example, if the server supports ES movement, if "ES movement support" is included in the terminal information and "ES movement support" is included in eUICCInfo2, the profile server (620) can return a response that further includes whether insufficientMemory is present while transmitting profile metadata with Response Ok of AuthenticateClient.
[0159] According to one embodiment, the Response Ok of the above AuthenticateClient may include the form of Table 3 below.
[0160] AuthenticateClientOk ::= SEQUENCE {transactionId [0] TransactionId,profileMetadata
[0037] StoreMetadataRequest, -- tag 'BF25'smdpSignedY SmdpSignedY, -- Signed informationsmdpSignatureY [APPLICATION 55] OCTET STRING, -- tag '5F37'smdpCertificate Certificate, -- CERT.DPpb.SIGinsufficientMemory NULL OPTIONAL, - Not enough space for this Profile downloadwaitingTime INTEGER OPTIONAL, -- estimated time in minutes by when the SM-DP+ maintains the session for this Profile Download.EsSessionId [X] OCTET STRING (SIZE(1..16)) OPTIONAL -- the LPA will use this identifier to check to restart session, or continue the continued RSP session}
[0161] Previously, in step 625, if the profile server (620) received estimatedProfileSizeSupport from the terminal, the profile server (620) may provide the estimated profile size in the profile metadata. (Step 630)
[0162] In addition, the terminal LPA (605) may perform an operation to determine whether additional storage space for profile installation can be secured in the eSIM chip before performing a procedure to display the metadata of the profile on the user screen and obtain consent for installation.
[0163] The LPA (605) may additionally check information on previously installed profiles (steps 638 and 639) to determine whether there is a profile that can be moved outside the eSIM chip for the installation of the corresponding profile and / or to determine the storage space that can be secured through profile movement. For example, the LPA (605) may transmit GetProfileInfo (step 638) to the eUICC (615) and receive information on each profile from the eUICC (615) (step 639), and the LPA (605) may check whether the profile(s) have an ES movement permission identifier using information in the metadata of the received profile(s). The ES movement permission identifier may be one of identification information on whether ES is supported and information on separate storage of sensitive data. Alternatively, for an ICCID installed on an ES-supporting eUICC, the ICCID's policy may be considered to allow "ES support." The LPA (605) may further check the estimatedProfileSize of the received metadata or the number of profiles installed on the eUICC (step 639).
[0164] Based on the collected information, LPA (605) can determine whether space for storing a new profile download can be secured through profile movement. (Step 640) Information that LPA (605) utilizes for determination may be, for example, at least one of the available memory information of the eSIM chip collected from eUICCInfo2 in advance, and / or the estimated profile capacity (estimatedProfileSize) received from the profile server, whether the installed profiles support ES received in step 639, and estimatedProfileSize.
[0165] Meanwhile, LPA (605) can obtain user consent to proceed with the profile installation (step 643).
[0166] To proceed with profile installation, additional information and consent regarding the possibility of installing previously installed profiles after externally moving / deleting the eSIM chip may be obtained. Step 643 may be performed prior to steps 638 through 640.
[0167] LPA (605) can terminate the installation if there is no profile among the installed profiles that supports ES movement even if eUICC (615) supports ES movement. (Step 645)
[0168] At the end of the installation (step 645, the same applies to step 635 above), the LPA (605) may request the eUICC (615) to terminate the session for profile installation by sending a CancelSession (CancelSessionReason, transaction Id) message to the eUICC (615) as defined in SGP.22. In addition, the eUICC (615) that has received the request may reply to the LPA (605) with eUICC-signed data including the CancelSession Reason. At this time, the LPA (605) may send the reply back to the profile server. At this time, the Cancel Session Reason may be a session termination (SessionAborted), or a Cancel Session Reason indicating that there is no ES-supported profile, for example, NoProfileWithExtStorageSupport, may be used.
[0169] Meanwhile, the profile server (620) can confirm the received Cancel Session message and terminate the RSP Session. The profile server (620) can provide the telecommunications service provider (not shown) with the reason for the profile installation error.
[0170] If there is a profile that can be moved outside the eUICC, the LPA (605) can perform a profile moving procedure outside the eUICC (615). (Step 650) This can be performed with or without terminating the session, as shown in FIGS. 7 and 8 described below.
[0171] As described later in FIG. 9, a profile transfer request can be transmitted from the LPA (605) to the eUICC (615). Upon receiving the request, the eUICC (615) can generate profile data to be transferred outside the eUICC and reply to the LPA (605). The LPA (605) can store the received data and process the transfer. (Step 650) After processing the profile transfer storage, the LPA (605) can proceed with profile installation. (Step 655)
[0172] For example, the terminal may process profile movement and continue the profile download procedure while maintaining an RSP session with the profile server (620), or
[0173] Or, after terminating (Cancel) the RSP Session with the profile server (620) and processing the profile transfer, start the profile installation from the beginning and proceed with the profile installation, or
[0174] Alternatively, the RSP Session with the profile server (620) may be resumed, the profile transfer may be processed, and then the profile installation may be resumed to perform subsequent processing.
[0175] Previously, when the terminal processes the profile transfer and continues the profile download procedure while maintaining the RSP Session with the profile server, the LPA (605) may continue the installation by sending getBoundProfilePackageRequest to the profile server (620).
[0176] The profile server (620) that receives the getBoundProfilePackageRequest implicitly recognizes that available memory has been secured and can create a BoundProfilePakcage and respond.
[0177] FIG. 7 is a diagram illustrating a method for resuming installation of an existing profile after moving a profile within a terminal according to an embodiment of the present disclosure.
[0178] FIG. 7 or FIG. 8 is an example drawing that can be applied after moving the profiles in FIGS. 3 to 6, FIG. 9, FIG. 12a, and FIG. 12b described above to an external location from an eUICC. FIG. 7 describes a procedure for moving an already installed profile to an external location from an eUICC while maintaining an RSP Session, and then proceeding with profile installation.
[0179] As described above in FIGS. 3 to 6, FIG. 9, FIG. 12a, and FIG. 12b, it may be determined at step 730 to move the profile of the eUICC (715) to Ext. Storage due to insufficient available memory.
[0180] After performing the mobile installation for the profile(s) (step 775), the LPA (705) may complete the subsequent profile installation procedure defined in SGP.22 as a subsequent action. An example of the subsequent action upon completion of the installation procedure may be an action of requesting a GetBoundProfilePackage Request to the profile server (720). When the profile server (720) responds with insufficient Memory to the LPA (705) of the terminal and thereafter receives the GetBoundProfilePackage Request, the profile server (720) may determine that available memory has been secured in the terminal and may respond with a ProfilePackage.
[0181] LPA (705) may further perform a procedure (steps 780 to 788) prior to step 790 to explicitly notify the profile server (720) that available eUICC memory information has been secured.
[0182] For example, the LPA (705) may provide the profile server (720) with at least one of the available eUICC memory information and the transaction id as eUICC signed data.
[0183] For example, the eUICC may obtain one or more pieces of information from the information collected by the LPA (705) by including it in the message transmitted in step 780 or from the eUICC (715) by receiving a command from the LPA (705) in step 780, such as the transaction id, which is session identification information, and available eUICC memory information.
[0184] From the LPA (705), the eUICC (715) can request signed data of the eUICC for transmitting available eUICC memory information. (Step 780) At this time, the eUICC (715) can generate data including available eUICC memory information and a transaction id, sign the data, and send it back to the LPA (705) (Step 783). The LPA (705) can receive the response from the eUICC (715) and send it to the profile server (720) (Step 785). The message sent in Step 785 may be a new ES9+ function for securing available memory, or may be an ES9+. AuthenticateClient Request function currently defined in SGP.22.
[0185] The profile server (720) verifies the signature of the received eUICC, determines that it is an RSP session for a previous profile installation through the transaction ID, and additionally verifies and responds with information on the availability of eUICC memory. (Step 788) If the memory for profile installation is larger than the expected profile size, the profile server (720) can respond with a success response (Response Ok). If the memory for profile installation is insufficient, the profile server (720) can respond with an error and terminate the process.
[0186] Upon receiving a success response, LPA (705) can proceed to step 790.
[0187] Meanwhile, the profile server may explicitly provide the terminal with an additional RSP session maintenance time. For example, the profile server may include information on the remaining time for maintaining the RSP session and / or session identification information in the AuthenticateClient response and reply. This may correspond to, for example, one of steps 430, 530, 630, or 1230. Additionally, when considering entry by linking the profile download procedure after ES movement, the profile server may provide the terminal with identification information to determine which profile download operation occurred during the process. This may be the transaction ID of the corresponding session or may be defined as a new ID separately from it.
[0188] In this case, the LPA (705) of the terminal may complete the ES movement procedure within the RSP session maintenance time and enter step 790 of FIG. 7. Alternatively, if the LPA (705) attempts to re-download after the provided time has elapsed, it may determine that the session is invalid and enter a procedure to restart profile download.
[0189] Meanwhile, FIG. 8 is a drawing of a method for resuming installation of an existing profile after moving a profile within a terminal according to another embodiment of the present disclosure.
[0190] FIG. 7 or FIG. 8 is an example drawing that can be applied after the profiles in FIGS. 3 to 6, 12a, and 12b described above are moved outside the eSIM chip. FIG. 8 describes a procedure for terminating an RSP Session, moving the profile outside the eUICC, and then restarting profile installation.
[0191] As described above in FIGS. 3 to 6 and 12, in step 830, the eUICC (815) may decide to move the profile to Ext. Storage due to insufficient available memory. For example, if the user selects to move the profile to ES in FIGS. 3 to 6, the terminal may cancel the existing session and return the CancelSession result to the profile server (820) with eUICC-signed data. For example, the LPA (805) may request the eUICC (815) to terminate the session for profile installation by sending a CancelSession (CancelSessionReason, transaction Id) message to the eUICC (815) as defined in SGP.22. In addition, the eUICC (815) that receives the request may return eUICC-signed data including the CancelSession Reason to the LPA (805). LPA (805) can transmit the above data back to the profile server (820). At this time, the Cancel Session Reason may be a session termination (SessionAborted) or a Cancel Session Reason indicating reconnection after profile transfer. For example, a Cancel Session Reason such as postpone or afterProfileExportToStorage may be defined.
[0192] In the case where a Reason code indicating resumption of installation after moving a profile such as postpone, afterProfileExportToStorage to the terminal is received, the eUICC (815) may store without deleting the encryption keys generated for the installation of the profile, for example, otPK / otSK (a one-time public key and private key pair used as input when creating a session). Meanwhile, the profile server (820) may verify the signature by checking the received Cancel Session message and terminate the RSP Session. In the case where resumption of the profile installation is expected, for example, if an error code such as postpone, afterProfileExportToStorage is received, the profile server (820) may not provide the telecommunications service provider (not shown) with the reason for the profile installation error.
[0193] After terminating the session, the terminal can perform a profile transfer installation procedure as described later in FIG. 9.
[0194] After performing the profile transfer procedure, LPA (805) can proceed with the procedure by starting the profile installation procedure defined in SGP.22 from the beginning for the profile installation procedure on the profile server (820).
[0195] FIG. 9 is a diagram illustrating a procedure for moving a profile from an eUICC to outside the eUICC according to one embodiment of the present disclosure.
[0196] FIG. 9 is a diagram illustrating one embodiment of a procedure for moving a profile from an eUICC to outside the eUICC, which can be commonly applied to the embodiments of FIGS. 3 to 8, FIG. 12a, and FIG. 12b described above.
[0197] The profile migration procedure may be initiated by the terminal user (900) selecting a profile to be migrated (step 935). Alternatively, the procedure may be initiated upon the terminal recognizing the need for profile migration based on terminal settings (e.g., detecting insufficient available memory in the eUICC), obtaining the user's consent, or based on terminal judgment.
[0198] As previously described in FIGS. 3 to 8 or FIGS. 12a and 12b, the profile transfer procedure may be performed as a follow-up operation upon the terminal (905) recognizing (step 915) that the eUICC (910) has insufficient available memory. For example, the terminal LPA (905) may notify the user that a profile deletion or transfer is required and request additional action (step 920).
[0199] LPA (905) may also provide information to determine which profiles are eligible for priority deletion, with some information to assist the user in making a decision to delete a profile. (Step 925) Depending on the embodiment, step 925 may be performed before step 920 and provided as additional information in step 920.
[0200] The terminal may propose profiles for deletion by combining certain information, such as metadata of the profile(s), information obtained from the profile file, usage history of the profile, user setting information for the profile, etc. The information may be at least one of the following: a period of communication service available for the profile, a validity period of the profile itself, whether the terminal user is a communication service provider in the area where the terminal user is located through a PLMN ID, whether the profile is deactivated at the time of performing the operation, information about the last time the profile was activated (enabled) if deactivated, and a usage priority selected by the user.
[0201] If the user selects a profile to be deleted at step 930, the LPA (905) may initiate a profile deletion procedure as defined in SGP.22 and process the profile deletion from the eUICC (910). If the deletion secures available eUICC memory, the LPA (905) may perform subsequent procedures without entering the profile transfer procedure. For example, in the present invention, the profile installation procedure may be resumed or restarted.
[0202] Meanwhile, at step 935, the terminal user (900) may choose to move the profile without deciding to delete the profile.
[0203] When a profile transfer is determined based on the terminal user (900) or the terminal settings, a profile transfer request message may be transmitted from the LPA (905) to the eUICC (910) (step 940). The request may be a new command, such as RequestToExtStorage, for example, and may be transmitted including the ICCID or AID (Application ID) of the profile selected by the user or the terminal as identification information of the profile to be transferred. In addition, the eUICC (910) that received the request may determine whether ES support is possible, including whether “ES support” is allowed by the policy of the corresponding ICCID (step 945). If there is no profile identified by the corresponding ICCID or does not support ES, the eUICC (910) may return an error. The information on whether “ES support” is allowed by the policy of the corresponding ICCID may be one of identification information on whether ES is supported and information on separate storage of sensitive data. Alternatively, an ES-enabled eUICC may consider the ICCID installed on the ES-enabled eUICC to be “ES-enabled” by the ICCID’s policy.
[0204] If the profile supports ES movement, the eUICC (910) can configure data of the corresponding profile to be exported (transmitted externally) (step 950). The data (arbitrarily named ESPPa) may be a data package configured including all or part of the files of the corresponding profile. For example, the file may be configured only with a part excluding sensitive data files such as metadata of the profile or authentication information for network access, and may be configured in the form of binary data. The eUICC (910) may also encrypt the corresponding profile package to be exported externally with an encryption key so that only an eUICC with the same EID can decrypt it.
[0205] The eUICC (910) can reply to the LPA (905) with ESPPa in response to the request. (Step 955) At this time, only ESPPa may be replied, or, together with ESPPa, one or more pieces of decryptable eUICC information, such as EID or ICCID, to identify which profile the data is for, may be replied. The replied eUICC data may also be replied with an eUICC signature included.
[0206] At step 960, LPA (905) can process the movement by storing the received data.
[0207] Additionally, after processing the profile transfer storage, LPA (905) may perform subsequent operations. The subsequent operations may be, according to one embodiment, a profile installation operation.
[0208] If LPA (905) acquires storage space in the eUICC by processing profile movement storage during the profile installation process and performs profile installation again (terminating the existing session and starting from the beginning, or resuming while maintaining the session), LPA may perform the profile installation procedure without obtaining user consent again.
[0209] In the drawings described above, in order not to obscure the logic of the invention, the procedure for receiving and storing profile data by the LPA described in FIG. 9 is described based on this, but it should be noted that the profile transfer operation may be performed in a form in which, when the LPA requests ESPP to the eUICC, the eUICC generates ESPP, transmits it to the terminal memory, and returns the processing result to the LPA.
[0210] Meanwhile, FIG. 10 is a diagram illustrating the configuration of a terminal according to an embodiment of the present disclosure.
[0211] Referring to FIG. 10, the terminal may include a transceiver (1020), a processor (1010), and memory (1030). Additionally, the terminal may further include an eUICC (not shown). The terminals described in this disclosure may correspond to the terminal described in FIG. 10. For example, the terminals described in FIGS. 1 to 9 may include the configuration of the terminal described in FIG. 10.
[0212] However, the configuration of the terminal is not limited to FIG. 10, and may include more or fewer components than those illustrated in FIG. 10. According to some embodiments, the transceiver (1020), processor (1010), memory (1030), and eUICC may be implemented in the form of a single chip. In addition, the processor (1020) may be configured as at least one processor.
[0213] According to various embodiments, the transceiver (1020) may transmit and receive signals, information, data, etc. according to various embodiments of the present disclosure with the transceiver of another terminal or an external server. The transceiver (1020) may be configured with an RF transmitter that up-converts and amplifies the frequency of a transmitted signal, an RF receiver that low-noise amplifies a received signal and down-converts the frequency, etc. However, this is only one embodiment of the transceiver (1020), and the components of the transceiver (1020) are not limited to the RF transmitter and the RF receiver. In addition, the transceiver (1020) may receive a signal through a wireless channel and output it to the processor (1010), and transmit a signal output from the processor (1010) through the wireless channel.
[0214] Meanwhile, the processor (1010) is a component for overall control of the terminal. The processor (1010) can control the overall operation of the terminal according to various embodiments of the present disclosure as described above. The processor (1010) may include the LPA illustrated in FIG. 1 as a control application of the eUICC.
[0215] Meanwhile, the terminal may further include a memory (1030) and may store data such as a basic program, an application program, and setting information for the operation of the terminal. In addition, the memory (1030) may include at least one storage medium among a Flash Memory Type, a Hard Disk Type, a Multimedia Card Micro Type, a card type memory (e.g., an SD or XD memory, etc.), a magnetic memory, a magnetic disk, an optical disk, a Random Access Memory (RAM), a Static Random Access Memory (SRAM), a Read-Only Memory (ROM), a Programmable Read-Only Memory (PROM), and an Electrically Erasable Programmable Read-Only Memory (EEPROM). In addition, the processor (1010) may perform various operations using various programs, contents, data, etc. stored in the memory (1030). The memory (1030) is connected to the LPA as described above in FIG. 1 and can store profile data extracted from the eUICC by the LPA or provide it upon request by the LPA.
[0216] An eUICC (not shown) may include a transceiver, a processor, and a memory. The processor of the eUICC may include an ISD-R application. The ISD-R may exist as a system application of the eUICC (e.g., a part of the OS or a system application existing on the OS). The ISD-R may receive commands from the LPA through the transceiver, interpret the received commands, and perform profile management operations such as profile installation, deletion, and movement on the eUICC. The processor of the eUICC may receive the processing result from the eUICC and return it to the LPA through the transceiver. In addition, the processor of the eUICC may obtain profile status information and profile authority information (including whether movement is supported) from the metadata of the profile, and may generate a deletion processing result message when processing profile deletion. In addition, when processing profile movement, the processor may generate a profile package to be moved, construct a message including the profile package to be moved, and return it to the LPA. In addition, the eUICC may store at least one of the profile's metadata information and some or additional information of the metadata, such as the profile's status information, the profile's expected capacity, whether the profile supports ES movement, whether the eUICC supports ES, and information about the eUICC's residual memory, in the eUICC's memory, and the processor may access the memory to obtain one of the above-described information and use it as predetermined information necessary to perform at least one operation, such as profile movement processing or deletion processing.
[0217] Meanwhile, FIG. 11 is a diagram illustrating the configuration of a server according to one embodiment of the present disclosure.
[0218] Referring to FIG. 11, the server may include a transceiver (1120), a processor (1110), and a memory (1130). The servers described above in the present disclosure may each correspond to the server described in FIG. 11. For example, the servers described in FIGS. 1 to 9 (e.g., a business server, an RSP server, an SM-DP+, or an SM-DS) may each include the configuration of the server described in FIG. 11.
[0219] However, the configuration of the server is not limited to FIG. 11, and may include more or fewer components than those illustrated in FIG. 11. According to some embodiments, the transceiver (1120), the processor (1110), and the memory (1130) may be implemented in the form of a single chip. In addition, the processor (1110) may be configured as at least one processor.
[0220] According to some embodiments, the transceiver (1120) may transmit and receive signals, information, data, etc. according to the terminal and various embodiments of the present disclosure. The transceiver (1120) may be configured with an RF transmitter that up-converts and amplifies the frequency of a transmitted signal, and an RF receiver that low-noise amplifies and frequency-downconverts a received signal. However, this is only one embodiment of the transceiver (1120), and the components of the transceiver (1120) are not limited to the RF transmitter and the RF receiver. In addition, the transceiver (1120) may receive a signal through a wireless channel and output it to the processor (1110), and transmit a signal output from the processor (1110) through the wireless channel.
[0221] Meanwhile, at least one processor (1110) is a component for overall control of the server. The processor (1110) can control the overall operation of the server according to various embodiments of the present disclosure as described above. The at least one processor (1110) may be referred to as a control unit.
[0222] Meanwhile, the server may further include a memory (1130) and may store data such as basic programs for server operation, application programs, and setting information for ES movement support. In addition, the memory (1130) may include at least one storage medium among a Flash Memory Type, a Hard Disk Type, a Multimedia Card Micro Type, a card-type memory (e.g., SD or XD memory, etc.), a magnetic memory, a magnetic disk, an optical disk, a Random Access Memory (RAM), a Static Random Access Memory (SRAM), a Read-Only Memory (ROM), a Programmable Read-Only Memory (PROM), and an Electrically Erasable Programmable Read-Only Memory (EEPROM). In addition, the processor (1110) may perform various operations using various programs, contents, data, etc. stored in the memory.
[0223] The server can perform at least one of the actions mentioned below.
[0224] The server may receive one or more messages for profile installation via the transceiver (1120) and transmit them to the processor (1110), and the processor (1110) may verify the eUICC signature. The server may also perform the role of transmitting the verification results to the business operator.
[0225] Additionally, the server refers to the available memory information received as a message for mutual authentication from the terminal, for example, eUICC information included in AuthenticateClient.
[0226] The expected memory size of the profile to be downloaded for installation can be compared, and by further determining whether at least one of the terminal information (DeviceInfo) and the eUICC information (eUICCInfo2) contains an “ES support” identifier, the message can be configured differently and sent back to the terminal through the transceiver (1120).
[0227] In addition, if the processor (1110) of the server receives an "ES support" identifier from at least one of the terminal information (DeviceInfo) and the eUICC information (eUICCInfo2), and if the reason for the inability to install is insufficient memory (insufficientMemory), it may include in the message that insufficient memory has occurred and reply to the terminal through the transceiver (1120). In addition, the processor (1110) of the server may store session identification information and encryption keys for session creation in the memory (1130) without terminating the corresponding profile installation session.
[0228] The server's transceiver (1120) can receive a profile request message (GetBoundProfilePakcage) from the terminal. If the server receives an "ES support" identifier from at least one of the terminal information (DeviceInfo) and the eUICC information (eUICCInfo2) in the same session and responds to the terminal with insufficient memory (insufficientMemory) as the reason for installation failure, the server may determine that available memory for the profile to be installed has been secured, create a profile package (bound profile package), and respond to the terminal through the transceiver (1120).
[0229] Additionally, the server may perform an operation of signing at least one of the messages transmitted from the profile server with the server's encryption key and transmitting the message including the profile server's signature to the terminal through the transceiver (1120).
[0230] A method according to one embodiment of the present disclosure may include a step of checking the available memory of an eUICC from an eUICC in a terminal; and a step of determining to move to an external space of the eUICC of a profile based on the available memory information of the eUICC obtained from the terminal.
[0231] Additionally, the step of checking the available memory of the eUICC from the eUICC in the terminal may occur during the process of processing the download of the profile, and the terminal may further include a step of resuming and processing the profile download after moving the profile outside the eUICC.
[0232] FIG. 12a and FIG. 12b are diagrams illustrating an embodiment of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
[0233] According to one embodiment, FIG. 12b is a diagram showing a specific embodiment in which the judgment of the profile server (1220) changes according to the AdditionalProfile bit in the embodiment illustrated in FIG. 12a.
[0234] FIGS. 12A and 12B are diagrams illustrating another method applied in the process of a terminal user (1200) installing a new profile on a terminal, as an example of an operation that requires determining whether to move the profile(s) installed on the eUICC in FIG. 3 described above to an external location of the eUICC, according to one embodiment. This example can be applied as a replacement for the mutual authentication process between the terminal and the profile server in FIGS. 4 to 9 described above.
[0235] As previously described in FIGS. 4 to 9, during the mutual authentication process for installing a profile, the LPA (1205) may transmit terminal information (Device Info) and eUICC (1215) information (eUICCInfo2) to the profile server (1220). For example, the data of AuthenticateClient for client verification may include and transmit the terminal information and eUICC (1215) information. At this time, the eUICC information may include and transmit at least the available memory information of the eUICC (1215). Information that can determine the available memory of the eUICC (1215) may be included and transmitted in the extCardResource data. (Step 1225)
[0236] The profile server (1220) that receives the above information may perform at least one of the following procedures. It may determine that the eSIM chip's memory for profile installation is insufficient. Additionally, an identifier indicating whether an AdditionalProfile is present may be included in the eUICC information and transmitted. (Step 1225)
[0237] Specifically, as illustrated in FIG. 12b, the profile server (1220) that received this may perform an Eligibility Check in step 1227. In addition, if the estimated profile installation size of the profile is larger than the received available memory, the profile server (1220) may generate a message including insufficientMemory and information about the estimated profile installation capacity (estimated Profile size) and send it back (step 1230-2). In this embodiment, the profile server (1220) may be a profile server that supports ES migration or supports a specific version (e.g., GSMA SGP.22 V3.2 and later).
[0238] According to one embodiment, as illustrated in FIG. 12b, a profile server (1220) supporting GSMA SGP.22 V3.2 may, if the additionalProfile bit included in EuiccRspCapability is not set to 1, return "eUICC - Insufficient memory" (step 1230-1), and if the EuiccRspCapability bit is set to 1, return "eUICC - Insufficient memory" or may not return eUICC-Insufficient memory and return estimatedProfileSize (step 1230-2). As a condition for returning estimatedProfileSize, the profile server (1220) may additionally determine whether at least one of eUICCInfo2 and / or DeviceInfo includes ES support as additional information, and may provide estimatedProfileSize if the ES support is included. If the profile server (1220) does not support ES movement or is an older version of the function (e.g., older than GSMA SGP.22 V3.2), the profile server may return insufficientMemory as an error and terminate the procedure if the additionalProfile bit is not set to 1 in the received eUICC information or if the estimated installation size of the profile is larger than the available memory regardless of whether the additionalProfile bit is set. (Step 1230-1) The LPA (1250) that receives the insufficientMemory may terminate the RSP session procedure by starting the Cancel Session procedure defined in SGP.22. (Step 1231)
[0239] As described above in FIGS. 4 to 9, the message containing estimatedProfileSize may be returned as a Response from AuthenticateClient. The returned data may be included in either an error message from AuthenticatedClient or a success response message, and estimatedProfileSize may also be transmitted as a single data item included in Profilemetadata (step 1230-2).
[0240] If the profile server (1220) responds with an error message, the profile server (1220) may terminate the RSP session.
[0241] The LPA (1205) that receives the above message can perform an action by entering a section for deleting or moving a profile within the eUICC, and the subsequent action can be performed (step 1235) by referring to the step after receiving the AuthenitcateClient Response in each of the drawings described above, for example, and therefore, the description thereof will be omitted in this drawing.
[0242] Meanwhile, the present invention may be characterized by a step of confirming at least one of eUICC information and terminal information received from a terminal in a profile server; a step of determining whether installation of a profile prepared by an eUICC is possible by referring to the received information; a step of returning an estimated profile size to the terminal; and a step of determining and processing deletion or movement of one or more profiles stored in an eUICC in the terminal based on the estimated profile size received from the profile server.
[0243] FIG. 13 is a diagram illustrating an embodiment in which a profile server provides information on session maintenance to a terminal according to an embodiment of the present disclosure.
[0244] The profile server (1320) may also explicitly provide the terminal with additional information regarding the maintenance of the RSP session. The information regarding the maintenance of the RSP session may be provided together as additional information in the drawings described above. As described above, in step 1325, the profile server (1320) may compare the estimated installation size of the profile to be downloaded with reference to the information of extCardResource received from the LPA (1305) during the mutual authentication process. As a result of the comparison, the profile server (1320) may determine that the available memory for profile installation in the eUICC (1315) is insufficient. If the profile server (1320) determines that the available memory is insufficient, the profile server (1320) may terminate the session or maintain the session without terminating it. For example, in step 1330, the profile server (1320) may maintain the session for a certain period of time without terminating the session and then terminate the session. In step 1335, the profile server (1320) may provide the terminal with information about maintaining the session.
[0245] According to one embodiment, information regarding session maintenance may include at least one of RSP session identification information and RSP session maintenance time information. The RSP session identification information may be the transaction ID of the corresponding session as defined in SGP.22, or may be defined as a new ID to identify a delay in profile installation due to insufficient available eUICC memory. The new ID may be described as an ES session ID, for example. In the description of the present invention, the terms session ID, session identification information, and Es session ID are used.
[0246] The profile server (1320) may transmit to the terminal at least one of RSP session maintenance time information (indicated as waiting time in the drawing above) and RSP session identification information (indicated as ES session Id in the example of the drawing above). An example of the reply message may be a Response of AuthenticateClient. The reply message may be included and returned in one of steps 430, 530, 630, and 1230 above, for example.
[0247] The terminal (LPA (1305)) that received the above reply message may store the corresponding information. In step 1340, the LPA (1305) may delete the existing profile(s) from the eUICC or perform ES movement. In step 1345, the LPA (1305) may use at least one of the RSP session maintenance time and session identification information as information to determine whether the LPA (1305) will continue the existing profile download procedure or restart the profile installation procedure from the beginning.
[0248] At step 1350, LPA (1305) constructs a message and transmits it to the profile server (1320) or eUICC (1315) to perform subsequent actions.
[0249] For example, if the ES movement procedure is completed within the RSP session maintenance time at step 1345, the LPA (1305) may decide to enter a subsequent procedure for profile download (e.g., enter step 790 of FIG. 7), and, at step 1350, may configure a transmission message for profile download installation connected after the Authenticate Response and transmit it to the profile server (1320). Alternatively, if the LPA (1305) determines at step 1345 that the received session maintenance time has been exceeded, at step 1350, may enter a procedure for starting profile download from the beginning (e.g., enter step 870 of FIG. 8), and may perform a procedure for restarting the mutual authentication procedure with the profile server. At step 1355, the profile server (1320) may decide whether to process the terminal request message. The decision on whether to process may be performed including whether session information has expired.
[0250] For example, if the received message contains RSP session identification information transmitted by the profile server to the terminal and the connection is made within the session maintenance time, or if the received message does not contain RSP session identification information transmitted by the profile server to the terminal but the connection is made within the session maintenance time, the profile server (1320) may perform the requested action. The action may be, for example, an action in which the profile server (1320) enters a procedure for generating and downloading a BPP. If the received session identification information cannot be found or has expired, the profile server (1320) may determine to return an error and terminate the procedure.
[0251] In step 1360, the profile server (1320) may construct a response message based on the result of the determination in step 1355 and transmit it to the LPA (1305). The response message may be, for example, a success response and / or BPP, or may include an error reason for an Error and / or session expiration.
[0252] The LPA (1305) that receives the above response message can perform subsequent actions. For example, the LPA (1305) that receives an error message can terminate the relevant procedure. Alternatively, the LPA (1305) that receives a success response message can continue the profile installation procedure defined in SGP.22 to complete the profile installation.
[0253] In the specific embodiments of the present disclosure described above, components included in the disclosure are expressed in the singular or plural form, depending on the specific embodiment presented. However, the singular or plural expressions are selected to suit the presented situation for convenience of explanation, and the present disclosure is not limited to singular or plural components. Components expressed in the plural form may be composed of singular elements, or components expressed in the singular form may be composed of plural elements.
[0254] While the detailed description of this disclosure has described specific embodiments, it should be understood that various modifications are possible without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be limited to the described embodiments, but should be defined not only by the scope of the claims described below, but also by equivalents thereof.
[0255] The various embodiments of the present disclosure and the terminology used therein are not intended to limit the technology described in the present disclosure to a specific embodiment, but should be understood to include various modifications, equivalents, and / or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar components. The singular expression may include plural expressions unless the context clearly indicates otherwise. In the present disclosure, expressions such as “A or B,” “at least one of A and / or B,” “A, B, or C,” or “at least one of A, B, and / or C” may include all possible combinations of the items listed together. Expressions such as “first,” “second,” “first,” or “second” may modify the corresponding components regardless of order or importance, and are only used to distinguish one component from another, but do not limit the corresponding components. When it is said that a component (e.g., a first component) is “(functionally or communicatively) connected” or “connected” to another component (e.g., a second component), said component may be directly connected to said other component, or may be connected via another component (e.g., a third component).
[0256] The term "module" as used herein includes a unit composed of hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integrally formed component, or a minimum unit or portion thereof that performs one or more functions. For example, a module may be composed of an application-specific integrated circuit (ASIC).
[0257] Various embodiments of the present disclosure may be implemented as software (e.g., a program) including instructions stored in a machine-readable storage medium (e.g., an internal memory or an external memory) that can be read by a machine (e.g., a computer). The device is a device capable of calling instructions stored in the storage medium and operating according to the called instructions, and may include a terminal according to various embodiments. When the instructions are executed by a processor, the processor may directly or under the control of the processor perform a function corresponding to the instructions using other components. The instructions may include code generated or executed by a compiler or an interpreter.
[0258] A device-readable storage medium may be provided in the form of a non-transitory storage medium. Here, "non-transitory" means that the storage medium does not contain signals and is tangible, but does not distinguish between whether data is stored semi-permanently or temporarily on the storage medium.
[0259] The methods according to various embodiments disclosed in the present disclosure may be provided as included in a computer program product. The computer program product may be traded between sellers and buyers as a commodity. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or online through an application store (e.g., Play Store™). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily generated in a storage medium such as the memory of a manufacturer's server, an application store's server, or a relay server. Each component (e.g., a module or a program) according to various embodiments may be composed of a single or multiple entities, and some of the aforementioned sub-components may be omitted, or other sub-components may be further included in various embodiments. Alternatively or additionally, some components (e.g., a module or a program) may be integrated into a single entity, which may perform the same or similar functions as those performed by each respective component prior to integration. According to various embodiments, operations performed by a module, program or other component may be executed sequentially, in parallel, iteratively or heuristically, or at least some operations may be executed in a different order, omitted, or other operations may be added.
Claims
1. In a method performed by a terminal in a wireless communication system, A step of sending a first message containing additionalprofile information to a profile server for profile installation; When the additional profile information is set to a preset value, a step of receiving a second message including information about the predicted profile size from the profile server; A step of controlling to secure embedded universal integrated circuit card (eUICC) memory based on reception of a second message including information about the predicted profile size; and A method comprising: performing the profile installation based on securing the eUICC memory; 2. In paragraph 1, The above eUICC memory is secured, A method characterized in that it comprises at least one of moving the above profile or deleting the above profile.
3. In paragraph 1, A method characterized in that it further includes a step of determining whether to maintain or terminate a session with the profile server in order to secure the eUICC memory.
4. In paragraph 1, The first message above is, A method characterized in that it further includes memory information associated with the eUICC.
5. In a method performed by a profile server in a wireless communication system, A step of receiving a first message including additionalprofile information from a terminal for profile installation; A method comprising: a step of checking whether the additionalprofile information is set to a preset value; and a step of transmitting a second message including information about a predicted profile size if the additionalprofile information is set to a preset value.
6. In paragraph 5, The first message further includes memory information associated with the eUICC, A method characterized in that, when the additionalprofile information is set to a preset value, memory information associated with the eUICC and the predicted profile size are compared, and information about the predicted profile size is included in the second message according to the comparison result.
7. In paragraph 5, A step of generating metadata including information about the predicted profile size; further comprising: A method characterized in that the second message including the above metadata is transmitted.
8. In a wireless communication system, at the terminal, Transmitter and receiver; and Transmitting a first message containing additionalprofile information to the profile server through the transceiver for profile installation, When the additional profile information is set to a preset value, a second message including information about the predicted profile size is received from the profile server through the transceiver. Based on the reception of a second message containing information about the predicted profile size, control is provided to secure embedded universal integrated circuit card (eUICC) memory, A terminal including a control unit that controls to perform the profile installation based on the securing of the eUICC memory.
9. In paragraph 8, The above eUICC memory is secured, A terminal characterized by including at least one of moving the above profile or deleting the above profile.
10. In paragraph 8, The above control unit, A terminal characterized in that it controls to decide to maintain or terminate a session with the profile server in order to secure the eUICC memory.
11. In paragraph 8, The first message above is, A terminal characterized in that it further includes memory information associated with the eUICC.
12. In a profile server in a wireless communication system, Transmitter and receiver; and Receive a first message including additional profile information from the terminal through the transceiver for profile installation, A profile server comprising: a step of checking whether the additionalprofile information is set to a preset value; and a control unit for controlling transmission of a second message including information on a predicted profile size if the additionalprofile information is set to a preset value.
13. In paragraph 12, The first message further includes memory information associated with the eUICC, A profile server characterized in that, when the additionalprofile information is set to a preset value, memory information associated with the eUICC and the predicted profile size are compared, and information on the predicted profile size is included in the second message according to the comparison result.
14. In paragraph 12, The above control unit, Control to generate metadata containing information about the predicted profile size, A profile server, characterized in that the second message including the above metadata is transmitted.
Citation Information
Patent Citations
Device changing method and apparatus of wireless communication system
EP3890378A1
A method for informing a mobile network operator server which profile of a profile type should be downloaded from a SM-DP+ to a secure element
EP4301021A1
Customized pin / PUK remote provisioning
US20200280839A1
Profile handling of a communications device
US20200351656A1