Electronic device for performing subscriber identification module authentication, operation method thereof, and storage medium

The electronic device's processor-driven SIM authentication method with auto-generated PINs and cloud integration addresses secure PIN management and network connectivity issues, enhancing security and user convenience.

WO2026059111A1PCT designated stage Publication Date: 2026-03-19SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-08-07
Publication Date
2026-03-19

AI Technical Summary

Technical Problem

Existing electronic devices face challenges in securely managing subscriber identity module (SIM) authentication processes, particularly in ensuring secure PIN management and network connectivity, which can be compromised by unauthorized access or forgotten PINs.

Method used

The electronic device employs a processor-driven method for SIM authentication that includes displaying a lock screen, obtaining and verifying a PIN, generating and managing PINs using auto-generated PINs, and integrating with a cloud server for backup and restoration, ensuring secure SIM unlock and network connection.

Benefits of technology

This approach enhances SIM authentication security by enabling secure PIN management, automatic PIN generation, and cloud-based backup, thereby reducing unauthorized access and improving user convenience and network connectivity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025011953_19032026_PF_FP_ABST
    Figure KR2025011953_19032026_PF_FP_ABST
Patent Text Reader

Abstract

This electronic device (101) comprises: a communication circuit (210); a display (220); at least one processor (240) including processing circuitry; and memory (230) storing instructions. The instructions, when executed individually or collectively by the at least one processor (240), cause the electronic device (101) to: display a lock screen for user authentication through the display (220) on the basis of the occurrence of an event for subscriber identity module (SIM) authentication; acquire a personal identification number (PIN) for SIM unlock on the basis of the acquisition of user authentication information for unlocking the lock screen; determine whether the acquired PIN corresponds to a stored PIN; and perform the SIM unlock on the basis of determining that the acquired PIN corresponds to the stored PIN.
Need to check novelty before this filing date? Find Prior Art

Description

Electronic device performing subscriber identification module authentication, and method of operation and storage medium thereof

[0001] The present disclosure relates to an electronic device for performing subscriber identity module (SIM) authentication, a method of operation thereof, and a storage medium.

[0002] In a wireless communication system, electronic devices (e.g., user equipment; UE) can connect to a wireless communication network to use voice or data communication services at a designated location or while on the move. An appropriate authentication process may be required to provide communication services to electronic devices. For instance, a universal integrated circuit card (UICC) may be inserted into an electronic device, and authentication between the electronic device and the server of a mobile network operator (MNO) may be performed through a universal subscriber identity module (USIM) installed inside the UICC. The UICC may be referred to as a SIM (subscriber identity module) card in the case of the global system for mobile communications (GSM) method, and a USIM (universal subscriber identity module) card in the case of WCDMA (wideband code division multiple access), LTE (long term evolution), or NR (new radio) methods.

[0003] A portable electronic device may include a storage medium, such as a subscriber identification module card (or user authentication module card) or a memory card. Such storage medium may be embedded in the electronic device itself or configured to be easily replaceable and / or added by the user. For example, the electronic device may include a removable tray in a housing, and the storage medium may be coupled to the electronic device while placed in the tray.

[0004] When a user of an electronic device subscribes to a wireless communication service provided by a telecommunications carrier, the carrier provides the user with a UICC (e.g., a SIM card or USIM card), and the user can insert the provided UICC into their electronic device. Once the UICC is inserted into the electronic device, the USIM application installed within the UICC is executed. Using the International Mobile Subscriber Identity (IMSI) value and the cryptographic key value for authentication stored within the UICC, an appropriate authentication process can be performed with the carrier's server, where the same values ​​are stored. After the appropriate authentication process is completed, the wireless communication service can be utilized.

[0005] The information described above may be provided as related art for the purpose of aiding understanding of the present disclosure. No claim or determination is made as to whether any of the foregoing may be applied as prior art related to the present disclosure.

[0006] According to one aspect of the present disclosure, an electronic device comprises: a communication circuit; a display; at least one processor including processing circuitry; and a memory for storing instructions, wherein when the instructions are executed individually or collectively by the at least one processor, the electronic device causes: to display a lock screen for user authentication through the display based on the occurrence of an event for SIM (subscriber identity module) authentication; to obtain a PIN (personal identification number) for SIM unlock based on the acquisition of user authentication information for unlocking the lock screen; to check whether the acquired PIN corresponds to a stored PIN; and to perform the SIM unlock based on the confirmation that the acquired PIN corresponds to the stored PIN.

[0007] When the above instructions are executed individually or collectively by the at least one processor, the electronic device causes: to display a user interface for obtaining user authentication information through the display based on the confirmation of an event for activating a SIM authentication function using an auto-generated PIN (AGP); to obtain the user authentication information based on input to the user interface for obtaining user authentication information; to obtain identification information of the electronic device and identification information of the SIM based on performing user authentication using the user authentication information; and to obtain a PIN for setting the SIM authentication information based on (i) identification information of the electronic device, (ii) identification information of the SIM, and (iii) random value, and to store the PIN for setting the SIM authentication information.

[0008] When the above instructions are executed individually or collectively by the at least one processor, the electronic device is caused to: acquire identification information of the electronic device and identification information of the SIM based on the acquisition of user authentication information for unlocking the lock screen, (i) identification information of the electronic device, (ii) identification information of the SIM, and (iii) acquire a PIN for unlocking the SIM based on the random value, and establish a connection with a network through the communication circuit based on the fact that the PIN for unlocking the SIM corresponds to the stored PIN.

[0009] When the above instructions are executed individually or collectively by the at least one processor, the electronic device causes: to store the encrypted random value obtained using a key for encrypting the random value or decrypting the encrypted random value in the memory, and, based on obtaining user authentication information for unlocking the lock screen, to obtain a decrypted random value for the encrypted random value using the key, and (i) identification information of the electronic device, (ii) identification information of the SIM, and (iii) to obtain a PIN for SIM unlock based on the decrypted random value.

[0010] When the above instructions are executed individually or collectively by the at least one processor, the electronic device causes: based on the confirmation of an event for activating the SIM authentication function using the PIN, to check whether user authentication information for user authentication is set; based on the confirmation that user authentication information for user authentication is not set, to display a user interface for setting the user authentication information through the display; based on input to the user interface, to acquire the user authentication information; and to store the acquired user authentication information in the memory.

[0011] When the above instructions are executed individually or collectively by the at least one processor, the electronic device causes: to display a user interface for obtaining user authentication information through the display based on the acquisition of an input for displaying the stored PIN; to obtain the user authentication information based on the input to the user interface; and to display a user interface including the stored PIN through the display based on confirming that the acquired user authentication information corresponds to the stored user authentication information.

[0012] When the above instructions are executed individually or collectively by the at least one processor, the electronic device causes: after displaying the user interface including the stored PIN, to obtain an updated PIN using another random value generated from the random value, and to set the updated PIN as the PIN for SIM unlock.

[0013] When the above instructions are executed individually or collectively by the at least one processor, the electronic device causes: to disable a function associated with SIM lock based on confirmation of an event for disabling the SIM authentication function using the AGP—wherein the function associated with SIM unlock is disabled by changing the stored PIN to a set value—while the function associated with SIM lock is disabled, to display a user interface for obtaining user authentication information through the display based on confirmation of an event for enabling the SIM authentication function using a manual PIN based on input to the user interface, to obtain user authentication information based on input to the user interface, to display a user interface for obtaining a manual PIN through the display based on the user authentication information corresponding to the stored user authentication information, and to set the manual PIN obtained based on input to the user interface for obtaining the manual PIN as the PIN for SIM unlock.

[0014] When the above instructions are executed individually or collectively by the at least one processor, the electronic device causes: to display a user interface for obtaining a PIN through the display, to check whether a PIN entered into the user interface corresponds to the stored PIN, and to perform an operation associated with a SIM lock based on the check that a PIN obtained based on the input does not correspond to the stored PIN.

[0015] The identification information of the electronic device includes the IMEI (international mobile equipment identity) of the electronic device, and the identification information of the SIM includes the ICCID (integrated circuit card identifier) ​​of the SIM, and when the instructions are executed individually or collectively by the at least one processor, the electronic device is caused to: obtain a PIN for SIM unlock based on information output from the key derivation function by inputting the IMEI, the ICCID, and the random value into the key derivation function.

[0016] When the above instructions are executed individually or collectively by the at least one processor, the electronic device causes: to start a timer for periodically updating a PIN based on the acquisition of a PIN for SIM unlock, and, based on the elapsement of a time interval corresponding to the timer, to acquire an updated PIN based on another random value generated from the random value, and to set the updated PIN as the PIN for SIM unlock.

[0017] When the above instructions are executed individually or collectively by the at least one processor, they cause the electronic device to: convert the acquired PIN into an encrypted PIN based on the fact that the acquired PIN corresponds to the stored PIN, and transmit the encrypted PIN to a cloud server through the communication circuit.

[0018] The event for the above SIM authentication includes an event in which a SIM is inserted into the electronic device.

[0019] The event for the above SIM authentication includes an event for rebooting the electronic device.

[0020] According to one aspect of the present disclosure, a method of operating an electronic device comprises: displaying a lock screen for user authentication through a display of the electronic device based on the occurrence of an event for SIM (subscriber identity module) authentication; obtaining a PIN (personal identification number) for SIM unlock based on obtaining user authentication information for unlocking the lock screen; checking whether the obtained PIN corresponds to a stored PIN; and performing the SIM unlock based on confirming that the obtained PIN corresponds to the stored PIN.

[0021] The above method comprises: an operation of displaying a user interface for obtaining user authentication information through the display based on the confirmation of an event for activating a SIM authentication function using an auto-generated PIN (AGP); an operation of obtaining the user authentication information based on input to the user interface; an operation of obtaining identification information of the electronic device and identification information of the SIM based on performing user authentication using the user authentication information; an operation of obtaining a PIN for setting SIM authentication information based on (i) identification information of the electronic device, (ii) identification information of the SIM, and (iii) a random value; and an operation of storing the PIN for setting SIM authentication information.

[0022] The operation of obtaining the PIN for SIM unlock based on obtaining user authentication information for unlocking the lock screen is: the operation of obtaining identification information of the electronic device and identification information of the SIM based on obtaining user authentication information for unlocking the lock screen; and further includes the operation of obtaining the PIN for SIM unlock based on (i) identification information of the electronic device, (ii) identification information of the SIM, and (iii) the random value; and the method further includes the operation of establishing a connection with a network through the communication circuit based on the PIN for SIM unlock corresponding to the stored PIN.

[0023] The above method further includes the operation of storing the encrypted random value obtained using a key for encrypting the random value or decrypting the encrypted random value in the memory of the electronic device, and the operation of obtaining a PIN for SIM unlock based on obtaining user authentication information for unlocking the lock screen includes: the operation of obtaining a random value decrypted using the key for the encrypted random value based on obtaining user authentication information for unlocking the lock screen; and the operation of obtaining a PIN for SIM unlock based on (i) identification information of the electronic device, (ii) identification information of the SIM, and (iii) the decrypted random value.

[0024] The above method further comprises: an operation of checking whether user authentication information for user authentication is set based on confirming an event for activating a SIM authentication function using the PIN; an operation of displaying a user interface for setting the user authentication information through the display based on confirming that the user authentication information for user authentication is not set; an operation of obtaining user authentication information based on input to the user interface for setting the user authentication information; and an operation of storing the obtained user authentication information in the memory of the electronic device.

[0025] According to one aspect of the present disclosure, in a non-transient computer-readable storage medium storing computer-executable instructions, the computer-executable instructions, when executed individually or collectively by at least one processor comprising processing circuitry of an electronic device, cause the electronic device to: display a lock screen for user authentication through a display of the electronic device based on the occurrence of an event for SIM (subscriber identity module) authentication; obtain a PIN (personal identification number) for SIM unlock based on the acquisition of user authentication information for unlocking the lock screen; determine whether the acquired PIN corresponds to a stored PIN; and perform the SIM unlock based on the determination that the acquired PIN corresponds to the stored PIN.

[0026] The above and other aspects, features, and advantages of specific embodiments of the present disclosure will become more apparent from the following description written together with the accompanying drawings:

[0027] FIG. 1 is a block diagram of an electronic device in a network environment according to one or more embodiments.

[0028] FIG. 2 is a block diagram of an electronic device according to one embodiment.

[0029] FIG. 3 is a block diagram of a framework of an electronic device according to one embodiment.

[0030] FIG. 4 is a flowchart illustrating a method for performing SIM authentication of an electronic device according to one embodiment.

[0031] FIG. 5a is an illustrative diagram for explaining a method of performing SIM authentication of an electronic device according to one embodiment.

[0032] FIG. 5b is an illustrative diagram for explaining a method of performing SIM authentication of an electronic device according to one embodiment.

[0033] FIG. 6a is an illustrative diagram for explaining a method of setting a SIM PIN of an electronic device according to one embodiment.

[0034] FIG. 6b is an illustrative diagram for explaining a method of setting a SIM PIN of an electronic device according to one embodiment.

[0035] FIG. 7 is a flowchart illustrating a method for setting a PIN of an electronic device according to one embodiment.

[0036] FIG. 8 is an exemplary diagram illustrating a method for activating a SIM authentication function using a PIN of an electronic device according to one embodiment.

[0037] FIG. 9 is a flowchart illustrating a method for providing a stored PIN of an electronic device according to one embodiment.

[0038] FIG. 10 is an illustrative diagram for explaining a method of providing a stored PIN of an electronic device according to one embodiment.

[0039] FIG. 11 is a flowchart illustrating a method for setting a PIN of an electronic device according to one embodiment.

[0040] FIG. 12 is an illustrative diagram for explaining a method of setting a PIN of an electronic device according to one embodiment.

[0041] FIG. 13 is a flowchart illustrating a method for transmitting a PIN of an electronic device to a cloud server according to one embodiment.

[0042] FIG. 14 is an exemplary diagram illustrating a method for enabling a PIN management function through a cloud server of an electronic device according to one embodiment.

[0043] FIG. 15 is an illustrative diagram for explaining a method of backing up or restoring a PIN through a cloud server of an electronic device according to one embodiment.

[0044] FIG. 16 is an illustrative diagram for explaining a method of obtaining a PIN of an electronic device according to one embodiment.

[0045] FIG. 17 is an illustrative diagram for explaining a method of performing SIM authentication of an electronic device according to one embodiment.

[0046] FIG. 18 is an exemplary diagram illustrating a method for performing SIM authentication using information obtained by another electronic device of a user of an electronic device, according to one embodiment.

[0047] Various modifications may be made to the embodiments of the present disclosure, and various types of embodiments may exist. Accordingly, specific embodiments will be illustrated in the drawings and described in detail in the detailed description. However, various embodiments are not intended to limit the scope of the present disclosure to specific embodiments, and should be interpreted as including various modifications, equivalents, and / or alternatives to the embodiments of the present disclosure. Additionally, in connection with the detailed description of the drawings, similar components may be designated by similar reference numbers.

[0048] Additionally, in describing the present disclosure, if it is determined that a specific description of related known functions or features could unnecessarily obscure the essence of the present disclosure, such specific description will be omitted.

[0049] Furthermore, the embodiments described below may be modified in various other forms, and the scope of the technical concept of the present disclosure is not limited to the embodiments described below. Rather, these embodiments are provided to make the present disclosure more sufficient and complete and to fully convey the technical concept of the present disclosure to those skilled in the art.

[0050] Furthermore, the terms used in this disclosure are merely for describing specific embodiments and are not intended to limit the scope of this disclosure. Additionally, singular expressions include plural expressions unless the context clearly indicates otherwise.

[0051] Additionally, in this disclosure, expressions such as “have,” “can have,” “include,” and “can include” indicate the existence of such characteristics (e.g., elements such as numbers, functions, actions, and components) and do not exclude the existence of additional characteristics.

[0052] Additionally, in the present disclosure, expressions such as “A or B”, “at least one of A and B”, “at least one of A or B”, or “one or more of A and / or B” may include all possible combinations of the listed items. For example, “A or B”, “at least one of A and B”, or “at least one of A or B” may refer to all of the following cases: (1) including A, (2) including B, or (3) including A and B.

[0053] Additionally, expressions such as "first," "second," etc. used in this disclosure may describe various elements regardless of order and / or importance. Furthermore, such expressions are intended merely to distinguish one element from another and are not intended to limit said elements.

[0054] Meanwhile, the description in the present disclosure that one element (e.g., a first element) is "(operationally or telecommunicationally) coupled" or "coupled" with another element (e.g., a second element) must be interpreted to include both cases where the one element is directly coupled to the other element and where the one element is coupled to the other element through yet another element (e.g., a third element).

[0055] In contrast, the description that one element (e.g., the first element) is "directly coupled" or "directly connected" to another element (e.g., the second element) can be interpreted to mean that another element (e.g., the third element) does not exist between the first element and the other element.

[0056] Additionally, the expression "configured to" used in this disclosure may, depending on the context, be used interchangeably with other expressions such as "suitable for," "have the capacity to," "designed to," "adapted to," "made to," and "capable to." Meanwhile, the term "configured to" does not necessarily imply that the device is "specifically designed to" in terms of hardware.

[0057] Instead, in some situations, the expression “device configured to do so” may mean that said device “can” perform operations in conjunction with other devices or components. For example, the phrase “processor configured to perform A, B, and C” may mean a dedicated processor (e.g., an embedded processor) that performs said corresponding operations, or a general-purpose processor (e.g., a CPU or an application processor) that can perform said corresponding operations by executing one or more software programs stored in a memory device.

[0058] Additionally, in the embodiments of the present disclosure, a 'module' or 'part' may perform at least one function or operation and may be implemented in hardware or software, or a combination of hardware and software. Additionally, excluding a 'module' or 'part' that needs to be implemented in specific hardware, a plurality of 'modules' or 'parts' may be integrated into at least one module and implemented in at least one processor.

[0059] Meanwhile, various elements and regions in the drawings are schematically depicted. Accordingly, the technical concept of the present disclosure is not limited by the relative sizes or intervals depicted in the accompanying drawings.

[0060] Hereinafter, embodiments of the present disclosure are described in detail with reference to the drawings so that those skilled in the art can easily practice them. However, the present disclosure may be embodied in various different forms and is not limited to the embodiments described herein. In relation to the description of the drawings, the same or similar reference numerals may be used for identical or similar components. Furthermore, in the drawings and related descriptions, descriptions of well-known functions and configurations may be omitted for clarity and brevity.

[0061] FIG. 1 is a block diagram of an electronic device (101) in a network environment (100) according to one embodiment.

[0062] Referring to FIG. 1, in a network environment (100), an electronic device (101) may communicate with an electronic device (102) through a first network (198) (e.g., a short-range wireless communication network) or with at least one of an electronic device (104) or a server (108) through a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with the electronic device (104) through a server (108). According to one embodiment, the electronic device (101) may include a processor (120), memory (130), input module (150), sound output module (155), display module (160), audio module (170), sensor module (176), interface (177), connection terminal (178), haptic module (179), camera module (180), power management module (188), battery (189), communication module (190), subscriber identification module (196), or antenna module (197). In some embodiments, at least one of these components (e.g., connection terminal (178)) may be omitted from the electronic device (101), or one or more other components may be added. In some embodiments, some of these components (e.g., sensor module (176), camera module (180), or antenna module (197)) may be integrated into a single component (e.g., display module (160)).

[0063] The processor (120) can control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) by executing software (e.g., a program (140)), and can perform various data processing or operations. According to one embodiment, as at least part of the data processing or operations, the processor (120) can store commands or data received from other components (e.g., a sensor module (176) or a communication module (190)) in volatile memory (132), process the commands or data stored in volatile memory (132), and store the resulting data in non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or an auxiliary processor (123) that can operate independently or together with it (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor). For example, if the electronic device (101) includes a main processor (121) and an auxiliary processor (123), the auxiliary processor (123) may be configured to use lower power than the main processor (121) or to be specialized for a designated function. The auxiliary processor (123) may be implemented separately from the main processor (121) or as part thereof.

[0064] The auxiliary processor (123) may control at least some of the functions or states associated with at least one component of the electronic device (101) (e.g., display module (160), sensor module (176), or communication module (190)) on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. According to one embodiment, the auxiliary processor (123) (e.g., image signal processor or communication processor) may be implemented as part of another functionally related component (e.g., camera module (180) or communication module (190)). According to one embodiment, the auxiliary processor (123) (e.g., neural network processing unit) may include a hardware structure specialized for processing an artificial intelligence model. The artificial intelligence model may be generated through machine learning. Such learning may be performed, for example, on the electronic device (101) itself where the artificial intelligence model is executed, or through a separate server (e.g., server (108)). The learning algorithm may include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model may include a plurality of artificial neural network layers.An artificial neural network may be a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to the hardware structure, the artificial intelligence model may include a software structure, either additionally or substantially.

[0065] The memory (130) can store various data used by at least one component of the electronic device (101) (e.g., processor (120) or sensor module (176)). The data may include, for example, input data or output data for software (e.g., program (140)) and related commands. The memory (130) may include volatile memory (132) or non-volatile memory (134).

[0066] The program (140) may be stored as software in memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).

[0067] The input module (150) can receive commands or data to be used for a component of the electronic device (101) (e.g., processor (120)) from outside the electronic device (101) (e.g., user). The input module (150) may include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).

[0068] The sound output module (155) can output a sound signal to the outside of the electronic device (101). The sound output module (155) may include, for example, a speaker or a receiver. The speaker may be used for general purposes, such as multimedia playback or recording playback. The receiver may be used to receive incoming calls. According to one embodiment, the receiver may be implemented separately from the speaker or as part thereof.

[0069] The display module (160) can visually provide information to an external (e.g., user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling said device. According to one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of the force generated by said touch.

[0070] The audio module (170) can convert sound into an electrical signal or, conversely, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150) or output sound through the sound output module (155) or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphones) connected directly or wirelessly to the electronic device (101).

[0071] The sensor module (176) can detect the operating state of the electronic device (101) (e.g., power or temperature) or the external environmental state (e.g., user state) and generate an electrical signal or data value corresponding to the detected state. According to one embodiment, the sensor module (176) may include, for example, a gesture sensor, a gyroscope sensor, a barometric pressure sensor, a magnetic sensor, an accelerometer sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biosensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0072] The interface (177) may support one or more specified protocols that can be used for the electronic device (101) to be connected directly or wirelessly to an external electronic device (e.g., electronic device (102)). According to one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.

[0073] The connection terminal (178) may include a connector through which the electronic device (101) can be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0074] The haptic module (179) can convert an electrical signal into a mechanical stimulus (e.g., vibration or movement) or an electrical stimulus that can be perceived by the user through tactile or kinesthetic senses. According to one embodiment, the haptic module (179) may include, for example, a motor, a piezoelectric element, or an electric stimulation device.

[0075] The camera module (180) can capture still images and video. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.

[0076] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented, for example, as at least part of a power management integrated circuit (PMIC).

[0077] The battery (189) can supply power to at least one component of the electronic device (101). According to one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0078] The communication module (190) can support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between an electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may include one or more communication processors that operate independently of the processor (120) (e.g., application processor) and support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., cellular communication module, short-range wireless communication module, or GNSS (global navigation satellite system) communication module) or a wired communication module (194) (e.g., LAN (local area network) communication module, or power line communication module). The corresponding communication module among these communication modules can communicate with an external electronic device (104) through a first network (198) (e.g., a short-range communication network such as Bluetooth, WiFi (wireless fidelity) direct, or IrDA (infrared data association)) or a second network (199) (e.g., a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules may be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can identify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) using subscriber information (e.g., International Mobile Subscriber Identifier (IMSI)) stored in the subscriber identification module (196).

[0079] The wireless communication module (192) can support 5G networks and next-generation communication technologies following 4G networks, for example, new radio access technology. NR access technology can support high-speed transmission of high-capacity data (enhanced mobile broadband (eMBB)), minimization of terminal power and connection of multiple terminals (massive machine type communications (mMTC)), or high reliability and low latency (ultra-reliable and low-latency communications (URLLC)). The wireless communication module (192) can support a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate, for example. The wireless communication module (192) can support various technologies for securing performance in the high-frequency band, such as beamforming, massive MIMO (multiple-input and multiple-output), full-dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large-scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), external electronic device (e.g., electronic device (104)), or network system (e.g., second network (199)). According to one embodiment, the wireless communication module (192) may support a Peak data rate (e.g., 20 Gbps or more) for eMBB realization, loss coverage (e.g., 164 dB or less) for mMTC realization, or U-plane latency (e.g., downlink (DL) and uplink (UL) each 0.5 ms or less, or round trip 1 ms or less) for URLLC realization.

[0080] An antenna module (197) can transmit a signal or power to or from an external source (e.g., an external electronic device). According to one embodiment, the antenna module (197) may include an antenna comprising a radiator made of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). According to one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as a first network (198) or a second network (199), may be selected from the plurality of antennas, for example, by a communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device through the selected at least one antenna. According to some embodiments, in addition to the radiator, other components (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as part of the antenna module (197).

[0081] According to various embodiments, the antenna module (197) may form a mmWave antenna module. According to one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent to a first surface (e.g., bottom surface) of the printed circuit board and capable of supporting a specified high frequency band (e.g., mmWave band), and a plurality of antennas (e.g., array antennas) disposed on or adjacent to a second surface (e.g., top surface or side surface) of the printed circuit board and capable of transmitting or receiving a signal of the specified high frequency band.

[0082] At least some of the above components can be connected to each other via a communication method between peripheral devices (e.g., bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)) and exchange signals (e.g., commands or data) with each other.

[0083] According to one embodiment, commands or data may be transmitted or received between an electronic device (101) and an external electronic device (104) through a server (108) connected to a second network (199). Each of the external electronic devices (102, or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations performed on the electronic device (101) may be performed on one or more of the external electronic devices (102, 104, or 108). For example, if the electronic device (101) needs to perform a function or service automatically or in response to a request from a user or another device, the electronic device (101) may request one or more external electronic devices to perform at least part of the function or service instead of performing the function or service itself or additionally. One or more external electronic devices that receive the above request may execute at least part of the requested function or service, or additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may provide the result as is or additionally processed as at least part of the response to the request. For this purpose, for example, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used. The electronic device (101) may provide ultra-low latency services using, for example, distributed computing or mobile edge computing. In another embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server using machine learning and / or neural networks. According to one embodiment, the external electronic device (104) or the server (108) may be included within a second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.

[0084] FIG. 2 is a block diagram of an electronic device according to one embodiment.

[0085] Referring to FIG. 2, in one embodiment, the electronic device (101) may be the electronic device (101) of FIG. 1.

[0086] In one embodiment, the electronic device (101) may include a communication circuit (210), a display (220), a memory (230), and / or a processor (240).

[0087] In one embodiment, the communication circuit (210) may be included in the communication module (190) of FIG. 1.

[0088] In one embodiment, the display (220) may be included in the display module (160) of FIG. 1. The display (220) may display a user interface associated with settings for SIM card security.

[0089] In one embodiment, the memory (230) may be included in the memory (130) of FIG. 1.

[0090] In one embodiment, the memory (230) may store information for performing an operation to perform SIM (subscriber identity module) authentication. For example, the memory (230) may store instructions for performing an operation to perform SIM authentication when executed by the processor (240).

[0091] In one embodiment, the processor (240) may be included in the processor (120) of FIG. 1.

[0092] In one embodiment, a processor (240) (e.g., a processor including "processing circuitry") can control the overall operation of performing SIM authentication. In one embodiment, the processor (240) may include one or more processors (240) for performing SIM authentication. For example, the processor (240) may correspond to a plurality of processors that perform a plurality of operations by dividing (or individually) or collectively among the processors (240). The operation of the processor (240) performing SIM authentication will be described in detail later with reference to FIGS. 3 through 18.

[0093] Although the electronic device (101) in FIG. 2 is illustrated as including a communication circuit (210), a display (220), a memory (230), and / or a processor (240), it is not limited thereto. For example, the electronic device (101) may further include at least one component, for example, a camera module (180), among one or more components of the electronic device (101) illustrated in FIG. 1. The electronic device (101) may be a portable electronic device capable of receiving a SIM card. For example, the electronic device (101) may be a smartphone, a tablet, a wearable electronic device (e.g., a smart watch or a VST (video see-through) device), and there are no limitations on specific examples. As understood by those skilled in the art, embodiments of the present disclosure are not limited to a single electronic device (101). For example, embodiments may be implemented on a distributed architecture including a plurality of processors. Additionally, embodiments may be implemented such that one or more tasks are divided between the electronic device (101) and a server on the cloud.

[0094] FIG. 3 is a block diagram of a framework of an electronic device according to one embodiment.

[0095] In one embodiment, a framework (301) of an electronic device (e.g., the electronic device (101) of FIG. 2) may include a plurality of modules. The plurality of modules may include, for example, an auto-generated PIN (AGP) module (310), a SIM manager (330), and / or a keystore (350). The framework (301) may be implemented as at least part of an operating system (e.g., the operating system (142) of FIG. 1). In one embodiment, the plurality of modules included in the framework (301) (or framework layer) may be implemented in the form of an application, program, computer code, instructions, routine, process, software, firmware, or a combination of at least two of these that are executable by a processor (e.g., the processor (240) of FIG. 2). For example, when at least one or more of the AGP module (310), SIM manager (330), and / or keystore (350) are executed, the processor may perform an operation corresponding to each. Therefore, the description "a specific module performs an operation" below may be understood as "as the specific module is executed, the processor performs an operation corresponding to the specific module." In one embodiment, at least some of the modules may include a plurality of programs, but are not limited to those described. In one embodiment, the modules and / or units may be implemented as services or applications when executed on an Android operating system, and are not limited thereto.

[0096] In one embodiment, the AGP module (310) may include an AGP key module (311) and an AGP service module (315). In one embodiment, the function provided by the AGP module (310) may be implemented through a menu of a security service such as an auto blocker.

[0097] In one embodiment, the AGP key module (311) may generate a PIN (or AGP) and store the generated PIN. The AGP key module (311) may collect information for generating the PIN. The AGP key module (311) may obtain, for example, identification information of an electronic device (101) and identification information of a SIM (e.g., subscriber identification module (196) of FIG. 1). The AGP key module (311) may generate a random value (or random) and encrypt the generated random value. The AGP key module (311) may store the encrypted random value. In one or more examples, the AGP key module (311) may operate as a random value generator that generates a random value using a key as a seed.

[0098] In one embodiment, the AGP key module (311) may include a terminal (user equipment) information collection unit (312), a random value generation and storage unit (313), and an AGP generation unit (314). The terminal information collection unit (312) may obtain parameters for generating a PIN (e.g., AGP). The parameters for generating a PIN may include identification information of an electronic device (101) and identification information of a SIM. The terminal information collection unit (312) may obtain identification information of an electronic device (101) from a system (e.g., an API (application programming interface) or a system properties menu associated with system properties). The identification information of an electronic device (101) may be, for example, the product serial number or IMEI (international mobile equipment identity) of the electronic device (101). The IMEI may be a 15-digit unique code that identifies a mobile device and may be used for tracking, security, and network identification. However, embodiments are not limited to these configurations and may include any suitable identification information known to those skilled in the art. The terminal information collection unit (312) may obtain identification information of the SIM from the SIM PIN management unit of the SIM. The identification information of the SIM may be the SIM's ICCID (integrated circuit card identifier), but embodiments are not limited to this configuration. The random value generation and storage unit (313) may generate a random value and store the generated random value. The random value generation and storage unit (313) may obtain a key for encrypting or decrypting the random value generated by the key store (350) (e.g., key generator (351)). The random value generation and storage unit (313) may encrypt the random value using the key.The random value generation and storage unit (313) can store the encrypted random value in secure storage (e.g., memory (130) of FIG. 1). The random value generation and storage unit (313) can decrypt the encrypted random value using a key when a PIN is generated by the AGP generation unit (314). The random value generation and storage unit (313) can obtain a random value as a parameter used to generate a PIN for SIM authentication based on the fact that information obtained by the terminal information collection unit (312) may be exposed. A different PIN (e.g., AGP) may be generated each time the random value generation and storage unit (313) generates a random value. Security may be enhanced compared to the case where SIM unlock is performed based on a PIN for unlocking the lock screen or a fixed SIM PIN. The AGP generation unit (314) can bind identification information of the electronic device (101), identification information of the SIM, and the random value. The "operation of binding information" can correspond to the operation of "inputting information to generate a PIN." The AGP generation unit (314) can generate a PIN (e.g., AGP) using a key derivation function such as a PBKDF (password-based key derivation function). The AGP generation unit (314) can provide the generated PIN to the SIM PIN storage unit of the SIM manager (330) so that the generated PIN is stored as the PIN of the SIM.

[0099] In one embodiment, the AGP service module (315) can compare a PIN (e.g., AGP') generated by the AGP key module (311) with a stored PIN (e.g., AGP). The AGP service module (315) can call a user interface corresponding to the comparison result. Based on the comparison result, the AGP service module (315) can back up the PIN to a server (e.g., server (108) of FIG. 1) or restore the PIN from the server. The server may include, for example, a cloud server.

[0100] In one embodiment, the AGP service module (315) may include an AGP management unit (316) and a communication unit (317). The AGP management unit (316) may determine whether SIM PIN authentication is required based on the occurrence of an event for SIM authentication. Events for SIM authentication may include, for example, a reboot event of the electronic device (101), an event in which a SIM is inserted (or attached) to the electronic device (101), or an event in which a SIM is removed from the electronic device (101). However, embodiments are not limited to these events in which SIM authentication may be performed for any known events where SIM authentication is appropriate or suitable. The AGP management unit (316) may determine whether the SIM PIN has been authenticated. The AGP management unit (316) may determine whether the stored PIN has expired based on the validity of the stored PIN or based on whether the stored PIN may be exposed. The AGP management unit (316) can regenerate a PIN based on confirming that the stored PIN (or the validity period of the AGP) has expired. The AGP management unit (316) can provide the regenerated AGP to the SIM through the SIM manager (330) so that the SIM's PIN is replaced by the regenerated AGP. The communication unit (317) can provide a function to back up the generated PIN to a server (or cloud server) or to restore the PIN from the server. For example, the electronic device (101) can restore the PIN stored on the server based on account authentication for the user of the electronic device (101).

[0101] In one embodiment, the AGP generated by the AGP module (310) may be provided through a user interface (e.g., show APG UI). For example, if a user of the electronic device (101) wishes to insert a SIM into another electronic device, a PIN stored in the electronic device (101) (or accessible by the electronic device (101)) may be provided through the user interface. The stored PIN may be provided through the user interface based on user authentication being performed.

[0102] FIG. 4 is a flowchart illustrating a method for performing SIM authentication of an electronic device according to one embodiment.

[0103] In the following embodiments, each operation may be performed sequentially, but is not necessarily performed sequentially. For example, the order of each operation may be changed, and at least two operations may be performed in parallel.

[0104] According to one embodiment, operations 401 to 413 may be understood to be performed in a processor (e.g., processor (240) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 2).

[0105] Referring to FIG. 4, in operation 401, in one embodiment, the electronic device (101) (e.g., processor (240)) may display a lock screen based on the occurrence of an event for SIM authentication. The event for SIM authentication may include, for example, a reboot event of the electronic device (101), an event in which a SIM (e.g., subscriber identification module (196) of FIG. 1) is inserted (or attached) to the electronic device (101), or an event in which a SIM is removed from the electronic device (101), but is not limited thereto. The lock screen may be a protective screen for receiving user authentication information.

[0106] In operation 403, in one embodiment, the electronic device (101) may obtain a PIN based on obtaining user authentication information. The electronic device (101) may obtain user authentication information based on input to a lock screen. The electronic device (101) may perform user authentication based on user authentication information. The electronic device (101) may obtain a PIN based on the completion of user authentication. The electronic device (101) may obtain a PIN for SIM unlock based on identification information of the electronic device (101), identification information of the SIM, and a random value.

[0107] In operation 405, in one embodiment, the electronic device (101) can determine whether the acquired PIN corresponds to a stored PIN. The electronic device (101) can determine whether the PIN (e.g., AGP') acquired based on the occurrence of an event for SIM authentication corresponds to a previously stored PIN (e.g., AGP). The electronic device (101) can compare, for example, an auto-generated PIN (AGP') acquired based on the occurrence of an event for SIM authentication with a previously stored auto-generated PIN (AGP).

[0108] In one embodiment, based on confirming that the acquired PIN corresponds to a stored PIN (Operation 405-Example), in Operation 407, the electronic device (101) may perform SIM unlock. The electronic device (101) may establish a connection with a network, for example. Based on the SIM being unlocked, the electronic device (101) may perform operations that require the establishment of a connection with a carrier's network, such as a call service. The electronic device (101) may also provide a home screen based on the lock screen being unlocked based on user authentication information.

[0109] In one embodiment, the electronic device (101) may integrate an authentication process based on a SIM PIN and an authentication process through a lock screen. To counter SIM swapping attacks, the electronic device (101) may generate a PIN (e.g., AGP) by using a key derivation function, such as a password-based key derivation function (PBKDF), based on the user's terminal information (e.g., IMEI), SIM information (e.g., ICCID), and randomness, and may replace SIM PIN authentication based on sequential input through integration with a lock screen function. The electronic device (101) may perform SIM unlocking based on a PIN comparison operation without receiving SIM PIN and user authentication information sequentially from the user. The user of the electronic device (101) may receive SIM-related services provided by the electronic device (101) in a state where SIM unlocking is completed, based on inputting only information to unlock the lock screen. The electronic device (101) can improve the user experience by performing SIM unlocking without dual authentication.

[0110] In one embodiment, based on confirming that the acquired PIN does not correspond to a stored PIN (operation 405-No), in operation 409, the electronic device (101) may display a user interface for acquiring a PIN. The electronic device (101) may display a user interface for acquiring a manual PIN based on, for example, that SIM unlock cannot be performed using an automatically generated PIN (AGP') acquired based on the occurrence of an event for SIM authentication.

[0111] In operation 411, in one embodiment, the electronic device (101) can determine whether a PIN verified based on an input corresponds to a stored PIN. The electronic device (101) can receive a PIN provided by, for example, another electronic device (e.g., an electronic device operating based on the same user account as the electronic device (101)) or a cloud server. The electronic device (101) can determine whether a PIN corresponding to an input corresponds to a stored PIN.

[0112] In one embodiment, based on confirming that the PIN verified based on the input corresponds to a stored PIN (Operation 411-Yes), in Operation 407, the electronic device (101) may perform SIM unlocking. Based on confirming that the PIN verified based on the input does not correspond to a stored PIN (Operation 411-No), in Operation 413, the electronic device (101) may perform SIM locking. By performing an operation associated with SIM locking when SIM authentication fails, the electronic device (101) can enhance the security of the SIM in the event that a SIM swapping attack is attempted.

[0113] FIGS. 5a and FIGS. 5b are exemplary diagrams for explaining a method of performing SIM authentication of an electronic device according to one embodiment.

[0114] Referring to FIG. 5a, in one embodiment, the electronic device (101) may detect an event for SIM authentication. The electronic device (101) may detect, for example, the occurrence of an event in which a SIM (e.g., the subscriber identification module (196) of FIG. 1) is inserted (511) (or attached) into the electronic device (101). The event for SIM authentication is not limited to the example of FIG. 5a. For example, the event for SIM authentication may be a reboot event of the electronic device (101). In one or more examples, the reboot event may occur when the device is turned on or restarted without being turned off. In one or more examples, the reboot event may occur when the device is turned off and then turned on again. In one or more examples, the reboot event may occur when the device is turned off for a predetermined time and then turned on again. The electronic device (101) can obtain identification information of the electronic device (101) and identification information of the SIM (521) based on confirming an event for SIM authentication. The electronic device (101) can obtain a random value to improve the security of the PIN for performing SIM authentication. The electronic device (101) can store the obtained encrypted random value in advance using a key to encrypt the random value or to decrypt the encrypted random value. The electronic device (101) can obtain a decrypted random value using a key based on confirming an event for SIM authentication. The electronic device (101) can obtain a PIN for SIM unlock based on the identification information of the electronic device (101), the identification information of the SIM, and the decrypted random value. The electronic device (101) can obtain a PIN (e.g., AGP') for SIM unlock based on information (533) output from a key induction function by inputting parameters (531) for generating an AGP, for example.The electronic device (101) can determine (551) whether the acquired PIN corresponds to a stored PIN (e.g., AGP) based on acquiring a PIN for SIM unlocking (541). The electronic device (101) can provide a user interface (560, 570) corresponding to the result of the comparison between the acquired PIN and the stored PIN.

[0115] Referring to FIG. 5b, the electronic device (101) may provide a lock screen (570) if a PIN (e.g., AGP') obtained based on the occurrence of a SIM authentication event corresponds to a stored PIN (e.g., AGP). The electronic device (101) may perform SIM unlocking based on performing only lock screen (570) authentication based on user authentication information. For example, the electronic device (101) may establish a connection with a network based on the PIN for SIM unlocking corresponding to a stored PIN. If a PIN (e.g., AGP') obtained based on the occurrence of a SIM authentication event does not correspond to a stored PIN (e.g., AGP), the electronic device (101) may provide a screen (560) for receiving a SIM PIN. The electronic device (101) may provide a lock screen (570) based on receiving a SIM PIN (561). The electronic device (101) can perform SIM unlocking by sequentially performing SIM PIN authentication and lock screen authentication when AGP-based SIM authentication fails. The PIN required for input in SIM PIN authentication may be a value corresponding to a pre-generated AGP. When AGP-based SIM authentication fails, the security of SIM authentication may be enhanced because input of a value corresponding to an AGP generated based on a random value is required.

[0116] FIGS. 6a and FIGS. 6b are exemplary diagrams for explaining a method of setting a SIM PIN of an electronic device according to one embodiment.

[0117] Referring to FIG. 6a, in one embodiment, an electronic device (101) may display a user interface (610) associated with settings for SIM card security through a display (e.g., the display (220) of FIG. 2). The user interface (610) associated with settings for SIM card security may include a window (611) for security functions such as a SIM lock function, changing the SIM card PIN, USIM personalization, or changing the password. The SIM lock function may be referred to as the "SIM card lock function." The electronic device (101) may detect an event for activating the SIM lock function. The electronic device (101) may detect, for example, a touch event for an object (613) associated with the SIM lock function (e.g., an event in which a user explicitly activates the SIM lock function). Based on detecting the event for activating the SIM lock function (615), the electronic device (101) may provide a user interface (620) for receiving a SIM PIN. The electronic device (101) may display masked numbers or characters on a portion of the user interface (620) in a part area (621) based on input to a keypad (623) included in the user interface (620). The electronic device (101) may check whether the entered SIM PIN corresponds to the initial setting PIN based on a touch event to an approval object (625). The electronic device (101) may display a user interface (630) indicating that the SIM lock function is activated based on confirming (627) that the entered SIM PIN corresponds to the initial setting PIN. The user interface (630) may include an object (631) indicating that the SIM lock function is activated. The electronic device (101) may check a touch event to an object (633) associated with the SIM card PIN change function.The electronic device (101) can display a user interface (640) for receiving a SIM PIN based on confirming (635) an input for an object (633).

[0118] Referring to FIG. 6b, the user interface (640) may include a window (641) requesting input of the current SIM PIN. The electronic device (101) may check whether the SIM PIN identified based on input to the keypad object (623) corresponds to the current SIM PIN. Based on confirming (643) that the input SIM PIN corresponds to the current SIM PIN, the electronic device (101) may display a user interface (650) for receiving input of a new SIM PIN. The user interface (650) may include a window (651) requesting input of the new SIM PIN. The electronic device (101) may obtain (653) the new SIM PIN based on input to the keypad object (623). The electronic device (101) may store the new SIM PIN and display a user interface (660) including a message (661) indicating that the SIM PIN has been successfully changed. In one embodiment, as shown in FIGS. 6a and 6b, when SIM authentication is performed based on an initial set PIN or a PIN changed by the user, SIM PIN authentication and lock screen authentication may be performed sequentially.

[0119] FIG. 7 is a flowchart illustrating a method for setting a PIN of an electronic device according to one embodiment.

[0120] In the following embodiments, each operation may be performed sequentially, but is not necessarily performed sequentially. For example, the order of each operation may be changed, and at least two operations may be performed in parallel.

[0121] According to one embodiment, operations 701 to 717 may be understood to be performed in a processor (e.g., processor (240) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 2).

[0122] Referring to FIG. 7, in operation 701, in one embodiment, an electronic device (101) (e.g., processor (240)) can detect an event for activating a SIM authentication function using an automatically generated PIN (AGP).

[0123] In operation 703, in one embodiment, the electronic device (101) can check whether user authentication information is set. The electronic device (101) can check whether user authentication information is set based on the fact that a SIM authentication function using an auto-generated PIN requires high security. User authentication information may include information for unlocking the lock screen. User authentication information may include, for example, user authentication such as 3P (e.g., PIN, password, or pattern), but is not limited thereto. Setting of user authentication information may be setting of the lock screen (or enabling the lock screen function).

[0124] In one embodiment, based on confirming that user authentication information is set (Operation 703-Example), the electronic device (101) may display a user interface for obtaining user authentication information in Operation 705. In Operation 707, in one embodiment, the electronic device (101) may obtain user authentication information.

[0125] In operation 709, in one embodiment, the electronic device (101) can obtain a PIN. The electronic device (101) can obtain identification information of the electronic device (101) and identification information of the SIM based on performing user authentication using user authentication information. The electronic device (101) can collect information for obtaining an AGP based on confirming that the user authentication information corresponds to the user authentication information stored. The electronic device (101) can obtain a PIN for setting SIM authentication information based on the identification information of the electronic device (101), the identification information of the SIM, and a random value. In operation 711, in one embodiment, the electronic device (101) can store a PIN. The electronic device (101) can store a PIN for setting SIM authentication information.

[0126] In one embodiment, based on confirming that user authentication information is not set (operation 703-No), the electronic device (101) may display a user interface for setting user authentication information in operation 713. In operation 715, in one embodiment, the electronic device (101) may obtain user authentication information. The electronic device (101) may obtain user authentication information based on input to the user interface. In operation 717, in one embodiment, the electronic device (101) may store user authentication information. Based on storing user authentication information, the electronic device (101) may obtain a PIN for AGP-based SIM authentication.

[0127] FIG. 8 is an exemplary diagram illustrating a method for activating a SIM authentication function using a PIN of an electronic device according to one embodiment.

[0128] Referring to FIG. 8, the electronic device (101) may display a user interface (810) including objects (811, 813) associated with an AGP function. The electronic device (101) may display a user interface (820) including a window (821) requesting input of a SIM PIN based on confirming (815) input to an object (811) indicating whether the AGP function is enabled. The electronic device (101) may obtain an AGP based on receiving the current SIM PIN input (821). The electronic device (101) may obtain a PIN (833) for setting SIM authentication information based on inputting information (831) including identification information of the electronic device (101), identification information of the SIM, and a random value. The electronic device (101) can set the acquired AGP as a SIM PIN corresponding to the SIM (e.g., the subscriber identification module (196) of FIG. 1) based on storing the acquired PIN (835). The electronic device (101) can display a user interface (850) including an object (853) indicating that an AGP function (or menu) is activated based on setting SIM authentication information based on the AGP (843). In the user interface (850), the object (851) for setting or changing the SIM card PIN can be dimmed.

[0129] FIG. 9 is a flowchart illustrating a method for providing a stored PIN of an electronic device according to one embodiment.

[0130] In the following embodiments, each operation may be performed sequentially, but is not necessarily performed sequentially. For example, the order of each operation may be changed, and at least two operations may be performed in parallel.

[0131] According to one embodiment, operations 901 to 909 may be understood to be performed in a processor (e.g., processor (240) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 2).

[0132] Referring to FIG. 9, in operation 901, in one embodiment, an electronic device (101) (e.g., a processor (240)) can obtain an input for displaying a stored PIN. For example, if a user of the electronic device (101) wishes to change the device in which the SIM is accepted to a new electronic device, the stored PIN can be checked using the electronic device (101).

[0133] In operation 903, in one embodiment, the electronic device (101) may display a user interface for obtaining user authentication information. The electronic device (101) may determine whether to display an AGP based on the user authentication information in order to reduce the risk that the PIN (e.g., AGP) may be exposed to a third party other than the user.

[0134] In operation 905, in one embodiment, the electronic device (101) can obtain user authentication information. In operation 907, in one embodiment, the electronic device (101) can check whether user authentication is complete. The electronic device (101) can check whether the obtained user authentication information corresponds to the stored user authentication information. In one embodiment, based on confirming that user authentication is not complete (operation 907-No), the electronic device (101) can display a user interface for obtaining user authentication information in operation 903.

[0135] In one embodiment, based on confirming that user authentication is complete (operation 907-e.), the electronic device (101) may display a user interface including a stored PIN in operation 909. The electronic device (101) may display a stored PIN (e.g., AGP) based on confirming that the acquired user authentication information corresponds to the stored user authentication information.

[0136] FIG. 10 is an illustrative diagram for explaining a method of providing a stored PIN of an electronic device according to one embodiment.

[0137] Referring to FIG. 10, an electronic device (101) may display a user interface (1010) including an object (1011) for displaying an AGP. The electronic device (101) may obtain user authentication information (1021) based on verifying (1013) an input to the object (1011). In FIG. 10, it is shown that the user authentication information may be a fingerprint, but it is not limited thereto. The electronic device (101) may verify whether the obtained user authentication information (1021) corresponds to stored user authentication information. The electronic device (101) may display a user interface (1030) including an AGP (or a code representing the AGP) (1031) based on verifying (1023) that the obtained user authentication information (1021) corresponds to stored user authentication information. The user interface (1030) can display a message (1033) indicating that the code representing the AGP may be changed.

[0138] In one embodiment, the electronic device (101) may obtain an updated PIN based on a random value different from a random value corresponding to the stored PIN after displaying a user interface (1030) containing a stored PIN. The electronic device (101) may obtain an updated PIN using a different random value based on the fact that the AGP may be obtained differently depending on the random value for generating the AGP. The electronic device (101) may set the updated PIN as a PIN for SIM unlocking. The electronic device (101) may enhance security by updating the PIN after providing a user interface (1030) containing a stored PIN (or a code representing the AGP) without sequential touches for changing the user's PIN.

[0139] In one embodiment, the electronic device (101) may periodically update the PIN. The electronic device (101) may start a timer for periodically updating the PIN based on obtaining a PIN for SIM unlock. Based on the elapsement of a time interval corresponding to the timer, the electronic device (101) may obtain an updated PIN based on a random value different from the random value corresponding to the stored PIN. The electronic device (101) may set the updated PIN as the PIN for SIM unlock.

[0140] FIG. 11 is a flowchart illustrating a method for setting a PIN of an electronic device according to one embodiment.

[0141] In the following embodiments, each operation may be performed sequentially, but is not necessarily performed sequentially. For example, the order of each operation may be changed, and at least two operations may be performed in parallel.

[0142] According to one embodiment, operations 1101 to 1113 may be understood to be performed in a processor (e.g., processor (240) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 2).

[0143] Referring to FIG. 11, in operation 1101, in one embodiment, an electronic device (101) (e.g., processor (240)) can detect an event for disabling a SIM authentication function using AGP.

[0144] In operation 1103, in one embodiment, the electronic device (101) may disable a function associated with a SIM lock. The electronic device (101) may disable a function associated with a SIM lock by changing a stored PIN to a set value based on checking an event for disabling a SIM authentication function using an auto-generated PIN. The operation of changing a stored PIN to a set value may include an operation of deleting (or discarding) the stored PIN or an operation of changing the stored PIN to a null value. The electronic device (101) may also disable a SIM lock function based on checking an event for disabling a SIM authentication function using AGP.

[0145] In operation 1105, in one embodiment, the electronic device (101) may detect an event for activating the SIM authentication function using a manual PIN. Based on detecting the event for activating the SIM authentication function using a manual PIN while the function associated with the SIM lock is disabled, the electronic device (101) may display a user interface for obtaining user authentication information through a display (e.g., the display (220) of FIG. 2). The electronic device (101) may detect, for example, an event for activating the function associated with the SIM lock. In operation 1107, in one embodiment, the electronic device (101) may perform user authentication. Based on the fact that a high level of security is required for the function associated with the SIM lock, the electronic device (101) may activate the function associated with the SIM lock after performing user authentication. The electronic device (101) may obtain user authentication information. The electronic device (101) may check whether the obtained user authentication information corresponds to the stored user authentication information. The electronic device (101) can confirm that user authentication is completed based on confirming that the acquired user authentication information corresponds to the stored user authentication information.

[0146] In operation 1109, in one embodiment, the electronic device (101) may display a user interface for obtaining a manual PIN. In operation 1111, in one embodiment, the electronic device (101) may obtain a manual PIN based on input to the user interface for obtaining a manual PIN. In operation 1113, in one embodiment, the electronic device (101) may set the manual PIN as a PIN for SIM unlock.

[0147] FIG. 12 is an illustrative diagram for explaining a method of setting a PIN of an electronic device according to one embodiment.

[0148] Referring to FIG. 12, in one embodiment, an electronic device (101) may detect an event for disabling an AGP-based SIM authentication function based on input to a user interface (1210) associated with a setting for SIM card security. The electronic device (101) may disable both the AGP-based SIM authentication function and the SIM lock function based on checking (1213) input to an object (1211) associated with the AGP-based SIM authentication function. The user interface (1220) may include objects (1221, 1223) indicating that both the AGP-based SIM authentication function and the SIM lock function have been disabled. The electronic device (101) may display a user interface (1230) including a window (1231) requesting input of an initial setting PIN based on checking (1225) input to an object (1223) associated with the SIM lock function. The electronic device (101) can activate the SIM lock function based on confirming (1233) that the input PIN corresponds to the set PIN. The user interface (1240) may include an object (1241) indicating that the SIM lock function has been activated.

[0149] FIG. 13 is a flowchart illustrating a method for transmitting a PIN of an electronic device to a cloud server according to one embodiment.

[0150] In the following embodiments, each operation may be performed sequentially, but is not necessarily performed sequentially. For example, the order of each operation may be changed, and at least two operations may be performed in parallel.

[0151] According to one embodiment, operations 1301 to 1313 may be understood to be performed in a processor (e.g., processor (240) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 2).

[0152] Referring to FIG. 13, in operation 1301, in one embodiment, an electronic device (101) (e.g., a processor (240)) may detect an event for SIM authentication. The event for SIM authentication may include, but is not limited to, a reboot event of the electronic device (101), an event in which a SIM is inserted (or attached) to the electronic device (101), or an event in which a SIM is removed from the electronic device (101).

[0153] In operation 1303, in one embodiment, the electronic device (101) may obtain a PIN based on checking an event for SIM authentication. The electronic device (101) may obtain a PIN for SIM unlock based on identification information of the electronic device (101), identification information of the SIM, and a random value. In operation 1305, in one embodiment, the electronic device (101) may check whether the obtained PIN corresponds to a stored PIN. The electronic device (101) may check whether the obtained PIN (e.g., AGP') corresponds to a set PIN (e.g., AGP) based on checking an event for SIM authentication. In one embodiment, based on checking that the obtained PIN does not correspond to a stored PIN (operation 1305-No), in operation 1307, the electronic device may perform a SIM lock. The electronic device (101) may enhance security by performing a SIM lock when AGP-based SIM authentication fails.

[0154] In one embodiment, based on confirming that the acquired PIN corresponds to a stored PIN (Operation 1305-Example), in Operation 1309, the electronic device may perform SIM unlock.

[0155] In operation 1311, in one embodiment, the electronic device (101) can convert the acquired PIN into an encrypted PIN. The electronic device (101) can encrypt the acquired PIN so that the PIN can be transmitted over a network. In operation 1313, in one embodiment, the electronic device (101) can transmit the encrypted PIN to a cloud server. The electronic device (101) can restore the PIN transmitted from another electronic device (or the identification information of the SIM confirmed from the PIN) based on a user account.

[0156] FIG. 14 is an exemplary diagram illustrating a method for enabling a PIN management function through a cloud server of an electronic device according to one embodiment.

[0157] Referring to FIG. 14, the electronic device (101) may display a user interface (1410) including a window (1411) associated with a function to share information with other electronic devices through a cloud server. The electronic device (101) may transmit the acquired AGP (or encrypted AGP) to the cloud server based on an input to an object (1413) indicating whether the backup function of the AGP using the cloud is enabled.

[0158] FIG. 15 is an illustrative diagram for explaining a method of backing up or restoring a PIN through a cloud server of an electronic device according to one embodiment.

[0159] Referring to FIG. 15, the first electronic device (1501) can acquire a first AGP (1513) based on an input parameter (1511) including identification information of the first electronic device (1501), identification information of the SIM, and a first random value. The electronic device (101) can transmit the AGP to a cloud server (1520) (1515) based on the fact that the backup function of the AGP of FIG. 14 is enabled. The electronic device (101) can transmit, for example, an encrypted AGP to the cloud server (1520). The operation of transmitting the encrypted AGP to the cloud server may be referred to as the operation of "performing an E2EE (end-to-end encrypted) key backup." The user of the first electronic device (1501) can insert the SIM into a new electronic device after removing the SIM from the first electronic device (1501). For example, a user's SIM may be inserted into a second electronic device (1530). The second electronic device (1530) may perform SIM authentication based on receiving information (1531) associated with SIM authentication from a cloud server (1520) without manually entering a SIM PIN. The operation of receiving information associated with SIM authentication from the cloud may be referred to as an operation of "performing an end-to-end encrypted key restore."

[0160] In one embodiment, the second electronic device (1530) may receive an encrypted AGP. The second electronic device (1530) may obtain an AGP based on decrypting the encrypted AGP. Based on the obtained AGP, the second electronic device (1530) may obtain identification information of the second electronic device (1530), identification information of the SIM, and a second random value (1533). The second electronic device (1530) may obtain a second AGP (1537) based on an input parameter (1535) including identification information of the second electronic device (1530), identification information of the SIM, and the second random value. The second electronic device (1530) may also receive information set by the cloud server (1520) in addition to the AGP from the cloud server (1520).

[0161] FIG. 16 is an illustrative diagram for explaining a method of obtaining a PIN of an electronic device according to one embodiment.

[0162] Referring to FIG. 16, in one embodiment, the terminal information collection unit (312) may collect identification information of the electronic device (101) and identification information of the SIM (e.g., the subscriber identification module (196) of FIG. 1). The electronic device (101) may perform lock screen authentication based on confirming an event for activating an AGP function. The terminal information collection unit (312) may collect identification information of the electronic device (101) and identification information of the SIM based on performing lock screen authentication.

[0163] The random value generation and storage unit (313) can generate a random value and encrypt the generated random value. The random value generation and storage unit (313) can encrypt the random value using a key provided by the key store (350). The random value generation and storage unit (313) can store the encrypted random value in secure storage.

[0164] The AGP generation unit (314) can bind identification information of an electronic device, identification information of a SIM, and a random value. The AGP generation unit (314) can generate an AGP using PBKDF. The AGP generation unit (314) can transmit the generated AGP to the SIM. The AGP generation unit (314) can set the generated AGP as a SIM PIN corresponding to the SIM.

[0165] FIG. 17 is an illustrative diagram for explaining a method of performing SIM authentication of an electronic device according to one embodiment.

[0166] Referring to FIG. 17, in one embodiment, based on confirming an event for SIM authentication, the random value generation and storage unit (313) can obtain an encrypted random value from secure storage (e.g., memory (130)). The random value generation and storage unit (313) can decrypt the encrypted random value using a key provided by the key store (350).

[0167] The terminal information collection unit (312) can bind identification information of the electronic device (101), identification information of the SIM (e.g., the subscriber identification module (196) of FIG. 1), and a random value. The AGP generation unit (314) can generate an AGP' using PBKDF. The AGP management unit (316) can compare the generated AGP' with a stored AGP. The AGP management unit (316) can complete SIM unlocking based on confirming that the generated AGP' corresponds to the stored AGP. The SIM manager (330) can provide a SIM PIN screen based on the fact that the generated AGP' does not correspond to the stored AGP. The SIM manager (330) can check whether the input value corresponds to the AGP. The SIM manager (330) can complete SIM unlocking based on confirming that the input value corresponds to the AGP. The SIM manager (330) can perform SIM locking based on confirming that the input value does not correspond to AGP.

[0168] FIG. 18 is an exemplary diagram illustrating a method for performing SIM authentication using information obtained by another electronic device of a user of an electronic device, according to one embodiment.

[0169] Referring to FIG. 18, in one embodiment, based on confirming an event for SIM authentication, the random value generation and storage unit (313) can obtain an encrypted random value from secure storage (e.g., memory (130)). The random value generation and storage unit (313) can decrypt the encrypted random value using a key provided by the key store (350).

[0170] The terminal information collection unit (312) can bind identification information of the electronic device (101), identification information of the SIM (e.g., the subscriber identification module (196) of FIG. 1), and a random value. The AGP generation unit (314) can generate an AGP' using PBKDF. The AGP management unit (316) can compare the generated AGP' with a stored AGP. The AGP management unit (316) can complete SIM unlocking based on confirming that the generated AGP' corresponds to the stored AGP. The SIM manager (330) can provide a SIM PIN screen based on the fact that the generated AGP' does not correspond to the stored AGP. In one embodiment, the user of the electronic device (101) can check the AGP value using another electronic device (1501) in which the SIM was previously inserted. For example, the user can obtain the AGP'' from the other electronic device using the show AGP function. The electronic device (101) may receive an AGP from a user. The electronic device (101) may also receive an AGP from another electronic device (1501). The SIM manager (330) may check whether the entered AGP corresponds to AGP. The SIM manager (330) may complete SIM unlocking based on confirming that the AGP corresponds to AGP. The SIM manager (330) may perform SIM locking based on confirming that the AGP does not correspond to AGP.

[0171] An electronic device according to one embodiment (e.g., the electronic device (101) of FIG. 2) may include a communication circuit (e.g., the communication circuit (210) of FIG. 2). The electronic device (101) may include a display (e.g., the display (220) of FIG. 2). The electronic device (101) may include at least one processor (e.g., the processor (240) of FIG. 2) that includes processing circuitry. The electronic device (101) may include a memory (e.g., the memory (230) of FIG. 2) that stores instructions. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause the display (220) to display a lock screen for user authentication based on the occurrence of an event for SIM (subscriber identity module) authentication. When the above instructions are executed individually or collectively by the at least one processor (240), they may cause the electronic device (101) to obtain a personal identification number (PIN) for SIM unlock based on obtaining user authentication information for unlocking the lock screen. When the above instructions are executed individually or collectively by the at least one processor (240), they may cause the electronic device (101) to check whether the obtained PIN corresponds to a stored PIN. When the above instructions are executed individually or collectively by the at least one processor (240), they may cause the electronic device (101) to perform the SIM unlock based on confirming that the obtained PIN corresponds to the stored PIN.

[0172] In one embodiment, when the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to display a user interface for obtaining user authentication information through the display (220) based on confirming an event for activating a SIM authentication function using an auto-generated PIN (AGP). When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to obtain the user authentication information based on input to the user interface. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to obtain identification information of the electronic device (101) and identification information of the SIM based on performing user authentication using the user authentication information. When the above instructions are executed individually or collectively by the at least one processor (240), they may cause the electronic device (101) to obtain a PIN for setting SIM authentication information based on the identification information of the electronic device (101), the identification information of the SIM, and a random value. When the above instructions are executed individually or collectively by the at least one processor (240), they may cause the electronic device (101) to store a PIN for setting SIM authentication information.

[0173] In one embodiment, when the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to obtain identification information of the electronic device (101) and identification information of the SIM based on obtaining user authentication information for unlocking the lock screen. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to obtain a PIN for SIM unlock based on the identification information of the electronic device (101), identification information of the SIM, and the random value. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to establish a connection with a network through the communication circuit (210) based on the PIN for SIM unlock corresponding to the stored PIN.

[0174] In one embodiment, when the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to store an encrypted random value obtained using a key for encrypting the random value or decrypting the encrypted random value in the memory (230). When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to obtain a decrypted random value using the key based on obtaining user authentication information for unlocking the lock screen. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to obtain a PIN for SIM unlock based on the identification information of the electronic device (101), the identification information of the SIM, and the decrypted random value.

[0175] In one embodiment, when the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to check whether user authentication information for user authentication is set based on confirming an event for activating the SIM authentication function using the PIN. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to display a user interface for setting the user authentication information through the display (220) based on confirming that the user authentication information for user authentication is not set. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to obtain user authentication information based on input to the user interface. When the above instructions are executed individually or collectively by the at least one processor (240), they may cause the electronic device (101) to store the acquired user authentication information in the memory (230).

[0176] In one embodiment, when the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause a user interface for obtaining user authentication information to be displayed through the display (220) based on obtaining an input for displaying the stored PIN. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause the user authentication information to be obtained based on an input to the user interface. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause a user interface including the stored PIN to be displayed through the display (220) based on the acquired user authentication information corresponding to the stored user authentication information.

[0177] In one embodiment, when the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to obtain an updated PIN based on a random value different from the random value after displaying a user interface including the stored PIN. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to set the updated PIN as a PIN for SIM unlock.

[0178] In one embodiment, when the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to disable a function associated with a SIM lock by changing the stored PIN to a set value based on confirming an event for disabling a SIM authentication function using an auto-generated PIN. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to display a user interface for obtaining user authentication information through the display (220) based on confirming an event for enabling a SIM authentication function using a manual PIN while the function associated with the SIM lock is disabled. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to obtain the user authentication information based on input to the user interface. When the above instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause the display (220) to display a user interface for obtaining a manual PIN based on the user authentication information stored therein. When the above instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause the manual PIN obtained based on input to the user interface for obtaining the manual PIN to be set as a PIN for SIM unlock.

[0179] In one embodiment, when the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause a user interface for obtaining a PIN to be displayed through the display (220) based on confirming that the obtained PIN does not correspond to the stored PIN. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause a PIN being verified based on input to the user interface to be verified whether the PIN being verified corresponds to the stored PIN. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause an operation associated with a SIM lock to be performed based on confirming that the PIN being verified based on the input does not correspond to the stored PIN.

[0180] In one embodiment, the identification information of the electronic device (101) may include the international mobile equipment identity (IMEI) of the electronic device (101). The identification information of the SIM may include the integrated circuit card identifier (ICCID) of the SIM. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may be caused to obtain a PIN for SIM unlocking based on information output from the key derivation function by inputting the IMEI, the ICCID, and the random value into the key derivation function.

[0181] In one embodiment, when the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause a timer to start for periodically updating a PIN based on obtaining a PIN for SIM unlock. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause an updated PIN based on a random value different from the random value to be obtained based on the elapsed time interval corresponding to the timer. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause the updated PIN to be set as a PIN for SIM unlock.

[0182] In one embodiment, when the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may convert the acquired PIN into an encrypted PIN based on confirming that the acquired PIN corresponds to the stored PIN. When the instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) may cause the encrypted PIN to be transmitted to a cloud server through the communication circuit (210).

[0183] In one embodiment, the event for SIM authentication may include an event in which a SIM is inserted into the electronic device (101).

[0184] In one embodiment, the event for SIM authentication may include a reboot event of the electronic device (101).

[0185] According to one embodiment, a method of operation of an electronic device (101) may include an operation of displaying a lock screen for user authentication through a display (220) of the electronic device (101) based on the occurrence of an event for SIM (subscriber identity module) authentication. The method may include an operation of obtaining a PIN (personal identification number) for SIM unlock based on obtaining user authentication information for unlocking the lock screen. The method may include an operation of checking whether the obtained PIN corresponds to a stored PIN. The method may include an operation of performing SIM unlock based on confirming that the obtained PIN corresponds to the stored PIN.

[0186] In one embodiment, the method may further include an operation of displaying a user interface for obtaining user authentication information through the display (220) based on confirming an event for activating a SIM authentication function using an auto-generated PIN (AGP). The method may further include an operation of obtaining the user authentication information based on input to the user interface. The method may further include an operation of obtaining identification information of the electronic device (101) and identification information of the SIM based on performing user authentication using the user authentication information. The method may further include an operation of obtaining a PIN for setting SIM authentication information based on the identification information of the electronic device (101), the identification information of the SIM, and a random value. The method may further include an operation of storing the PIN for setting SIM authentication information.

[0187] In one embodiment, the operation of obtaining a PIN for SIM unlock based on obtaining user authentication information for unlocking the lock screen may include the operation of obtaining identification information of the electronic device (101) and identification information of the SIM based on obtaining user authentication information for unlocking the lock screen. The operation of obtaining a PIN for SIM unlock based on obtaining user authentication information for unlocking the lock screen may include the operation of obtaining a PIN for SIM unlock based on the identification information of the electronic device (101), the identification information of the SIM, and a random value. The method may further include the operation of establishing a connection with a network through the communication circuit (210) of the electronic device (101) based on the PIN for SIM unlock corresponding to the stored PIN.

[0188] In one embodiment, the method may further include the operation of storing the encrypted random value obtained using a key for encrypting the random value or decrypting the encrypted random value in the memory (230) of the electronic device (101). The operation of obtaining a PIN for SIM unlock based on obtaining user authentication information for unlocking the lock screen may include the operation of obtaining a decrypted random value using the key based on obtaining user authentication information for unlocking the lock screen. The operation of obtaining a PIN for SIM unlock based on obtaining user authentication information for unlocking the lock screen may include the operation of obtaining a PIN for SIM unlock based on identification information of the electronic device (101), identification information of the SIM, and the decrypted random value.

[0189] In one embodiment, the method may further include an operation to check whether user authentication information for user authentication is set based on confirming an event for activating a SIM authentication function using a PIN. The method may further include an operation to display a user interface for setting the user authentication information through the display (220) based on confirming that the user authentication information for user authentication is not set. The method may further include an operation to obtain user authentication information based on input to the user interface. The method may further include an operation to store the obtained user authentication information in the memory (230) of the electronic device (101).

[0190] According to one embodiment, in a non-transient computer-readable storage medium storing computer-executable instructions, the computer-executable instructions, when executed individually or collectively by at least one processor (240) comprising the processing circuitry of the electronic device (101), may cause the electronic device (101) to display a lock screen for user authentication through the display (220) of the electronic device (101) based on the occurrence of an event for SIM (subscriber identity module) authentication. The computer-executable instructions, when executed individually or collectively by at least one processor (240), may cause the electronic device (101) to obtain a PIN (personal identification number) for SIM unlock based on obtaining user authentication information for unlocking the lock screen. The above computer-executable instructions may cause the electronic device (101), when executed individually or collectively by at least one processor (240), to check whether the acquired PIN corresponds to a stored PIN. The above computer-executable instructions may cause the electronic device (101), when executed individually or collectively by at least one processor (240), to perform the SIM unlock based on the confirmation that the acquired PIN corresponds to the stored PIN.

[0191] In addition, the structure of the data used in the embodiments of the present disclosure described above may be recorded on a computer-readable recording medium through various means. The computer-readable recording medium includes storage media such as magnetic storage media (e.g., ROM, floppy disk, hard disk, etc.) and optical reading media (e.g., CD-ROM, DVD, etc.).

[0192] The electronic device according to the various embodiments disclosed in this document may be of various forms. The electronic device may include, for example, a portable communication device (e.g., a smartphone), a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, or a consumer electronics device. The electronic device according to the embodiments of this document is not limited to the devices described above.

[0193] The various embodiments of this document and the terms used therein are not intended to limit the technical features described in this document to specific embodiments, and should be understood to include various modifications, equivalents, or substitutions of said embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of said items unless the relevant context clearly indicates otherwise. In this document, phrases such as "A or B," "at least one of A and B," "at least one of A or B," "A, B or C," "at least one of A, B and C," and "at least one of A, B, or C" may each include any one of the items listed together in the corresponding phrase, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used simply to distinguish said components from other said components and do not limit said components in any other aspect (e.g., importance or order). Where any (e.g., 1st) component is referred to as “coupled” or “connected” to another (e.g., 2nd) component, with or without the terms “functionally” or “communicationly,” it means that said any component may be connected to said other component directly (e.g., via a wire), wirelessly, or through a third component.

[0194] The term “module” as used in the various embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit, for example. A module may be a component formed integrally, or a minimum unit of said component or a part thereof that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0195] Various embodiments of the present document may be implemented as software (e.g., program (140)) comprising one or more instructions stored in a storage medium (e.g., internal memory (136) or external memory (138)) readable by a machine (e.g., electronic device (101)). For example, a processor (e.g., processor (120)) of the machine (e.g., electronic device (101)) may call at least one of the one or more instructions stored in the storage medium and execute it. This enables the machine to be operated to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code that can be executed by an interpreter. The storage medium readable by the machine may be provided in the form of a non-transitory storage medium. Here, 'non-temporary' simply means that the storage medium is a tangible device and does not contain a signal (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently and cases where it is stored temporarily.

[0196] According to one embodiment, the method according to the various embodiments disclosed herein may be provided by being included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or an application store (e.g., Play Store). TM It can be distributed online (e.g., downloaded or uploaded) through ) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created on a device-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.

[0197] According to various embodiments, each component (e.g., module or program) of the components described above may include a singular or multiple entities, and some of the multiple entities may be separated and placed in other components. According to various embodiments, one or more of the components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Generally or additionally, multiple components (e.g., module or program) may be integrated into a single component. In this case, the integrated component may perform one or more functions of each of the multiple components in the same or similar manner as those performed by the corresponding component among the multiple components prior to integration. According to various embodiments, operations performed by the module, program, or other components may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.

Claims

1. In an electronic device (101), Communication circuit (210); Display (220); At least one processor (240) including processing circuitry; and The electronic device (101) includes a memory (230) for storing instructions, and when the instructions are executed individually or collectively by the at least one processor (240), Based on the occurrence of an event for SIM (subscriber identity module) authentication, a lock screen for user authentication is displayed through the display (220), and Based on the acquisition of user authentication information for unlocking the above lock screen, a PIN (personal identification number) for SIM unlock is obtained, and Check whether the above-mentioned acquired PIN corresponds to a stored PIN, and An electronic device (101) that causes the SIM unlock to be performed based on confirming that the above-mentioned acquired PIN corresponds to the above-mentioned stored PIN.

2. In Paragraph 1, When the above instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) is enabled, Based on the confirmation of an event for activating the SIM authentication function using an auto-generated PIN (AGP), a user interface for obtaining the user authentication information is displayed through the display (220). Acquire the user authentication information based on input to a user interface for acquiring the above user authentication information, and Based on performing user authentication using the above user authentication information, identification information of the electronic device (101) and identification information of the SIM are obtained, and (i) identification information of the electronic device (101), (ii) identification information of the SIM, and (iii) based on a random value, obtain a PIN for setting SIM authentication information, and An electronic device (101) that causes to store a PIN for setting the above SIM authentication information.

3. In Paragraph 1 or 2, When the above instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) is enabled, Based on obtaining user authentication information for unlocking the lock screen, identification information of the electronic device (101) and identification information of the SIM are obtained, and (i) identification information of the electronic device (101), (ii) identification information of the SIM, and (iii) based on the random value, obtain a PIN for unlocking the SIM, and An electronic device (101) that causes a connection with a network to be established through the communication circuit (210) based on the fact that the PIN for SIM unlock corresponds to the stored PIN.

4. In any one of paragraphs 1 to 3, When the above instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) is enabled, The encrypted random value obtained using a key for encrypting the random value or decrypting the encrypted random value is stored in the memory (230), and Based on obtaining user authentication information for unlocking the lock screen, a decrypted random value is obtained using the key for the encrypted random value, and (i) identification information of the electronic device (101), (ii) identification information of the SIM, and (iii) an electronic device (101) that causes to obtain a PIN for SIM unlock based on the decoded random value.

5. In any one of paragraphs 1 to 4, When the above instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) is enabled, Based on the confirmation of an event for activating the SIM authentication function using the above PIN, check whether user authentication information for the above user authentication is set, and Based on confirming that user authentication information for the above user authentication is not set, a user interface for setting the user authentication information is displayed through the display (220), and Based on the input to the above user interface, user authentication information is obtained, and An electronic device (101) that causes the acquired user authentication information to be stored in the memory (230).

6. In any one of paragraphs 1 to 5, When the above instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) is enabled, Based on the acquisition of an input for displaying the above-mentioned stored PIN, a user interface for acquiring the above-mentioned user authentication information is displayed through the display (220), and Based on input to the above user interface, the user authentication information is obtained, and An electronic device (101) that causes a user interface including the stored PIN to be displayed through the display (220) based on the fact that the above acquired user authentication information corresponds to the stored user authentication information.

7. In any one of paragraphs 1 through 6, When the above instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) is enabled, After displaying the user interface including the stored PIN, obtain an updated PIN using another random value generated from the random value, and An electronic device (101) that causes the above-mentioned updated PIN to be set as the PIN for SIM unlock.

8. In any one of paragraphs 1 through 7, When the above instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) is enabled, Based on the confirmation of an event for disabling the SIM authentication function using the above AGP, the function associated with SIM lock is disabled—wherein the function associated with SIM unlock is disabled by changing the stored PIN to a set value—, While the function associated with the above SIM lock is disabled, based on the confirmation of an event for activating the above SIM authentication function using a manual PIN, the user interface for obtaining the above user authentication information is displayed through the display (220), and Based on input to the above user interface, the above user authentication information is obtained, and Based on the fact that the above user authentication information corresponds to the stored user authentication information, a user interface for obtaining a manual PIN is displayed through the display (220), and An electronic device (101) that causes a manual PIN obtained based on input to a user interface for obtaining the manual PIN to be set as a PIN for SIM unlock.

9. In any one of paragraphs 1 through 8, When the above instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) is enabled, A user interface for obtaining a PIN is displayed through the above display (220), and Check whether the PIN entered for the above user interface corresponds to the stored PIN, and An electronic device (101) that causes to perform an operation associated with a SIM lock based on confirming that the PIN obtained based on the above input does not correspond to the stored PIN.

10. In any one of paragraphs 1 through 9, The identification information of the electronic device (101) includes the IMEI (international mobile equipment identity) of the electronic device (101), and The identification information of the above SIM includes the ICCID (integrated circuit card identifier) ​​of the above SIM, and The above instructions, when executed individually or collectively by the at least one processor (240), cause the electronic device (101) to obtain a PIN for SIM unlock based on information output from the key induction function by inputting the IMEI, the ICCID, and the random value into the key induction function.

11. In any one of paragraphs 1 through 10, When the above instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) is enabled, Based on the acquisition of a PIN for SIM unlock, a timer for periodically updating the PIN is initiated, and Based on the elapsed time interval corresponding to the above timer, an updated PIN is obtained based on another random value generated from the above random value, and An electronic device (101) that causes the above-mentioned updated PIN to be set as the PIN for SIM unlock.

12. In any one of paragraphs 1 to 11, When the above instructions are executed individually or collectively by the at least one processor (240), the electronic device (101) is enabled, Based on confirming that the above-mentioned acquired PIN corresponds to the above-mentioned stored PIN, the above-mentioned acquired PIN is converted into an encrypted PIN, and An electronic device (101) that causes the encrypted PIN to be transmitted to a cloud server through the communication circuit (210).

13. In any one of paragraphs 1 through 12, The above event for SIM authentication includes an event in which a SIM is inserted into the electronic device (101), the electronic device (101).

14. In the method of operating the electronic device (101), An operation of displaying a lock screen for user authentication through the display (220) of the electronic device (101) based on the occurrence of an event for SIM (subscriber identity module) authentication; An operation to obtain a PIN (personal identification number) for SIM unlock based on obtaining user authentication information for unlocking the above lock screen; An operation to check whether the above-mentioned acquired PIN corresponds to a stored PIN; and An operation to perform SIM unlocking based on confirming that the above-mentioned acquired PIN corresponds to the above-mentioned stored PIN. A method including 15. In a non-transient computer-readable storage medium storing computer-executable instructions, the computer-executable instructions, when executed individually or collectively by at least one processor (240) comprising the processing circuitry of an electronic device (101), the electronic device (101), Based on the occurrence of an event for SIM (subscriber identity module) authentication, a lock screen for user authentication is displayed through the display (220) of the electronic device (101), and Based on the acquisition of user authentication information for unlocking the above lock screen, a PIN (personal identification number) for SIM unlock is obtained, and Check whether the above-mentioned acquired PIN corresponds to a stored PIN, and A storage medium that causes the SIM unlock to be performed based on confirming that the above-mentioned acquired PIN corresponds to the above-mentioned stored PIN.

Citation Information

Patent Citations

  • Personal identification number (PIN) code processing method and apparatus

    EP4358562A1

  • Winding unit

    KR1020230153256A

  • Solar power generating system having a function of seismic isolation

    KR102269570B1

  • Secure storage devices, with physical input device, for secure configuration in a configuration-ready mode

    US20200117777A1

  • Method and apparatus for verifying personal identification number pin code

    US20240064519A1