Method and apparatus for moving profile out of euicc
The method of moving profiles from eUICC to external memory addresses storage limitations in 5G systems by enabling efficient management and reducing costs through external storage utilization.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-10-27
- Publication Date
- 2026-04-30
AI Technical Summary
Existing 5G mobile communication systems face challenges in managing limited storage capacity of embedded universal integrated circuit cards (eUICC) for profiles, leading to inefficiencies in managing user subscription information and increased costs due to deletion and reinstallation of profiles.
A method and apparatus for moving profiles from an eUICC to external memory, allowing terminals to determine and manage profile storage based on eUICC information and profile server data, enabling efficient use of external storage.
Enhances user convenience by allowing profiles to be moved outside the eUICC, reducing costs associated with profile deletion and reinstallation, and addressing limited eSIM chip memory issues.
Smart Images

Figure KR2025017190_30042026_PF_FP_ABST
Abstract
Description
Method and device for moving a profile outside of eUICC
[0001] The present disclosure relates to a wireless communication system or a mobile communication system. Specifically, the present disclosure relates to a method and apparatus for moving a profile from a terminal to outside an embedded universal integrated circuit card (eUICC).
[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in frequency bands below 6 GHz ('Sub 6 GHz'), such as 3.5 gigahertz (3.5 GHz), but also in ultra-high frequency bands called millimeter waves (mmWave), such as 28 GHz and 39 GHz ('Above 6 GHz'). In addition, for 6G mobile communication technology, which is referred to as a system beyond 5G, implementation in the terahertz (THX) band (e.g., the 3 terahertz band at 95 GHz) is being considered to achieve transmission speeds 50 times faster and ultra-low latency reduced to one-tenth compared to 5G mobile communication technology.
[0003] In the early stages of 5G mobile communication technology, aiming to satisfy service support and performance requirements for enhanced Mobile BroadBand (eMBB), Ultra-Reliable Low-Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), technologies such as beamforming and Massive MIMO to mitigate path loss and increase transmission distance in ultra-high frequency bands, support for various numerologies (such as the operation of multiple subcarrier spacings) and dynamic operation of slot formats for the efficient utilization of ultra-high frequency resources, initial access techniques to support multi-beam transmission and broadband, definition and operation of Band-Width Parts (BWP), Low Density Parity Check (LDPC) codes for high-volume data transmission, new channel coding methods such as Polar Codes for the reliable transmission of control information, and L2 pre-processing (L2 Standardization has been carried out for pre-processing, network slicing which provides a dedicated network specialized for specific services, and other methods.
[0004] Currently, discussions are underway to improve and enhance the performance of the initial 5G mobile communication technology, taking into account the services that the 5G mobile communication technology was intended to support. Additionally, standardization of the physical layer is in progress for technologies such as V2X (Vehicle-to-Everything), which helps autonomous vehicles make driving decisions and enhance user convenience based on their own location and status information transmitted by the vehicle; NR-U (New Radio Unlicensed), which aims for system operation in unlicensed bands to comply with various regulatory requirements; NR terminal low power consumption technology (UE Power Saving); Non-Terrestrial Network (NTN), which is direct terminal-satellite communication for securing coverage in areas where communication with the terrestrial network is impossible; and positioning.
[0005] In addition, standardization is underway in the field of wireless interface architecture / protocols for technologies such as the Industrial Internet of Things (IIoT) for supporting new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) which provides nodes for expanding network service areas by integrating wireless backhaul links and access links, Mobility Enhancement including Conditional Handover and Dual Active Protocol Stack (DAPS) Handover, and 2-step Random Access (2-step RACH for NR) which simplifies random access procedures. Standardization is also underway in the field of system architecture / services for 5G baseline architectures (e.g., Service based Architecture, Service based Interface) for incorporating Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC), which provides services based on the location of the terminal.
[0006] When such 5G mobile communication systems are commercialized, connected devices, which are increasing explosively, will be connected to communication networks. Accordingly, it is expected that there will be a need to enhance the functionality and performance of 5G mobile communication systems and to integrate the operation of connected devices. To this end, new research is planned to be conducted on 5G performance improvement and complexity reduction, support for AI services, support for metaverse services, and drone communication using eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).
[0007] Furthermore, the advancement of these 5G mobile communication systems encompasses multi-antenna transmission technologies such as new waveforms to guarantee coverage in the terahertz band of 6G mobile communication technology, Full Dimensional MIMO (FD-MIMO), array antennas, and large-scale antennas; metamaterial-based lenses and antennas to improve terahertz band signal coverage; high-dimensional spatial multiplexing technology using OAM (Orbital Angular Momentum); and Reconfigurable Intelligent Surface (RIS) technology; as well as Full Duplex technology for enhancing frequency efficiency and system networks in 6G mobile communication technology; AI-based communication technologies that realize system optimization by utilizing satellites and AI from the design stage and internalizing end-to-end AI support functions; and the realization of services of complexity exceeding the limits of terminal computing capabilities by utilizing ultra-high-performance communication and computing resources. It could serve as a foundation for the development of next-generation distributed computing technologies.
[0008] The object of the present disclosure is to provide a method and apparatus for moving a profile from an embedded universal integrated circuit card (eUICC) to an external memory of the eUICC in a terminal, wherein the terminal provides information that enables it to determine whether part or all of a specific profile is a profile that can be moved outside the eUICC, and supports moving to the external memory based on the provided information.
[0009] According to one aspect of an embodiment of the present disclosure, a method of operation of a terminal may be characterized by comprising: receiving eUICC information regarding whether the eUICC supports external storage (ES) from an embedded universal integrated circuit card (eUICC); transmitting the eUICC information to a profile server; receiving profile information from the profile server based on the received eUICC information; and determining whether to move part or all of the profile outside the eUICC based on the profile information.
[0010] According to one aspect of an embodiment of the present disclosure, a terminal comprises: at least one transceiver; at least one processor communicably connected to the at least one transceiver; and one or more memories communicably connected to the at least one processor and storing instructions that can be executed individually or in any combination by the at least one processor, wherein the instructions may be characterized in that the terminal: receives eUICC information from an eUICC (embedded universal integrated circuit card) regarding whether the eUICC supports external storage (ES), transmits the eUICC information to a profile server, receives profile information from the profile server based on the received eUICC information, and determines whether to move part or all of the profile outside the eUICC based on the profile information. In one aspect of the present disclosure, a method performed by a terminal is provided, the method comprising the step of receiving information from an eUICC (embedded universal integrated circuit card) regarding whether a profile supports external storage (ES); and may include a step of determining whether to move part or all of the profile outside the eUICC based on information regarding whether the profile supports ES.
[0011] According to one embodiment of the present disclosure, part or all of the profile can be efficiently moved or transmitted outside the terminal's eUICC.
[0012] The effects obtainable in the present disclosure are not limited to those mentioned in the various embodiments, and other unmentioned effects will be clearly understood by those skilled in the art to which the present disclosure pertains from the description below.
[0013] FIG. 1 is a diagram showing the relationship between components for moving a profile according to one embodiment of the present disclosure.
[0014] FIG. 2 is a diagram illustrating the procedure for moving a profile outside of an eUICC according to one embodiment of the present disclosure.
[0015] FIG. 3 is a diagram illustrating a procedure for a profile server to configure profile metadata based on whether ES is supported, according to one embodiment of the present disclosure.
[0016] FIG. 4 is a diagram illustrating a procedure for updating metadata of a profile regarding whether the profile supports ES according to one embodiment of the present disclosure.
[0017] FIG. 5 is a diagram illustrating a procedure for displaying a profile list in a terminal according to one embodiment of the present disclosure.
[0018] FIG. 6 is a diagram illustrating a procedure for determining an ES-supported storage method in an LPA according to one embodiment of the present disclosure.
[0019] FIG. 7 is a diagram illustrating a procedure for moving a profile from an eUICC to outside the eUICC according to one embodiment of the present disclosure.
[0020] FIG. 8 is a drawing illustrating the configuration of a terminal according to some embodiments of the present disclosure.
[0021] FIG. 9 is a drawing illustrating the configuration of a server according to some embodiments of the present disclosure.
[0022] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.
[0023] In describing the embodiments, technical details that are well known in the technical field to which this disclosure belongs and are not directly related to this disclosure are omitted. This is intended to convey the essence of this disclosure more clearly without obscuring it by omitting unnecessary explanations.
[0024] For the same reason, some components in the attached drawings have been exaggerated, omitted, or schematically depicted. Additionally, the size of each component does not entirely reflect its actual dimensions. Identical or corresponding components in each drawing have been assigned the same reference numbers.
[0025] The advantages and features of the present disclosure and the methods for achieving them will become clear by referring to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below but may be implemented in various different forms. The embodiments provided are merely to make the present disclosure complete and to fully inform those skilled in the art of the scope of the disclosure, and the present disclosure is defined only by the scope of the claims. Throughout the specification, the same reference numerals refer to the same components.
[0026] At this time, it will be understood that each block of the process flow diagrams and combinations of the flow diagrams can be executed by computer program instructions. Since these computer program instructions can be loaded into the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, the instructions executed through the processor of the computer or other programmable data processing equipment create means to perform the functions described in the flow diagram block(s). Since these computer program instructions can also be stored in computer-available or computer-readable memory that can be directed toward the computer or other programmable data processing equipment to implement the function in a specific way, the instructions stored in computer-available or computer-readable memory can also produce a manufactured item containing means of instruction to perform the function described in the flow diagram block(s). Since computer program instructions can be loaded onto a computer or other programmable data processing equipment, instructions that perform a series of operation steps on the computer or other programmable data processing equipment to create a process executed by the computer can also provide steps for executing the functions described in the flowchart block(s).
[0027] Additionally, each block may represent a module, segment, or part of code containing one or more executable instructions for executing a specified logical function(s). It should also be noted that in some alternative execution examples, the functions mentioned in the blocks may occur out of order. For instance, two blocks described in succession may actually be executed substantially simultaneously, or the blocks may be executed in reverse order according to their corresponding functions.
[0028] In this embodiment, the term "part" refers to a software or hardware component, such as an FPGA or ASIC, and the "part" performs certain roles. However, the meaning of "part" is not limited to software or hardware. The "part" may be configured to reside in an addressable storage medium or configured to operate one or more processors. Accordingly, as an example, the "part" includes components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and "parts" may be combined into a smaller number of components and "parts" or further separated into additional components and "parts." Furthermore, the components and "parts" may be implemented to operate one or more CPUs within a device or secure multimedia card.
[0029] In the present disclosure, modifiers such as "first," "second," etc., referring to terms may be used to distinguish each term from one another when describing embodiments. The terms modified by the modifiers such as "first," "second," etc., may refer to different objects. However, the terms modified by the modifiers such as "first," "second," etc., may refer to the same object. That is, the modifiers such as "first," "second," etc., may be used to refer to the same object from different perspectives. For example, the modifiers such as "first," "second," etc., may be used to distinguish the same object in terms of function or operation. For example, the first user and the second user may refer to the same user.
[0030] Furthermore, although the present disclosure describes each embodiment using an eUICC as an example of a security module, the scope of the rights of the present disclosure is not limited to the eUICC. For example, it is obvious to those skilled in the art that the various embodiments described below can be applied substantially identically or similarly to other security media that perform functions substantially identical or similar to the eUICC.
[0031] Specific terms used in the following description are provided to aid in understanding the present disclosure, and the use of such specific terms may be modified in other forms without departing from the technical spirit of the present disclosure.
[0032] Efforts are being made to develop improved 5G or pre-5G communication systems to meet the increasing demand for wireless data traffic since the commercialization of 4G communication systems. For this reason, 5G or pre-5G communication systems are referred to as Beyond 4G Network communication systems or Post-LTE systems. To achieve high data transmission rates, the implementation of 5G communication systems in the mmWave band (e.g., the 60 GHz band) is being considered. To mitigate path loss and increase transmission distance in the mmWave band, technologies such as beamforming, massive MIMO, full Dimensional MIMO (FD-MIMO), array antennas, analog beamforming, and large-scale antennas are being discussed for 5G communication systems. In addition, to improve the network of the system, the development of technologies such as advanced small cell, advanced small cell, cloud radio access network (cloud RAN), ultra-dense network, Device to Device communication (D2D), wireless backhaul, moving network, cooperative communication, CoMP (Coordinated Multi-Points), and interference cancellation is taking place in 5G communication systems.In addition, advanced coding modulation (ACM) methods such as FQAM (Hybrid FSK and QAM Modulation) and SWSC (Sliding Window Superposition Coding), as well as advanced access technologies such as FBMC (Filter Bank Multi Carrier), NOMA (non-orthogonal multiple access), and SCMA (sparse code multiple access) are being developed in 5G systems.
[0033] Meanwhile, the Internet is evolving from a human-centered network where humans generate and consume information into an IoT (Internet of Things) network where distributed components, such as objects, exchange and process information. IoE (Internet of Everything) technology, which combines IoT with Big Data processing technologies through connections with cloud servers, is also emerging. To implement IoT, technological elements such as sensing technology, wired and wireless communication and network infrastructure, service interface technology, and security technology are required; consequently, technologies such as sensor networks, Machine-to-Machine (M2M) communication, and Machine-Type Communication (MTC) are currently being researched to facilitate connections between objects. In an IoT environment, intelligent IT services that create new value for human life by collecting and analyzing data generated from connected objects can be provided. Through the convergence and integration of existing IT technologies with various industries, IoT can be applied to fields such as smart homes, smart buildings, smart cities, smart or connected cars, smart grids, healthcare, smart home appliances, and advanced medical services.
[0034] Accordingly, various attempts are being made to apply 5G communication systems to IoT networks. For example, technologies such as sensor networks, Machine to Machine (M2M), and Machine Type Communication (MTC) are being implemented using 5G communication techniques such as beamforming, MIMO, and array antennas. The application of cloud RAN as a big data processing technology, as previously described, can also be considered an example of the convergence of 5G and IoT technologies.
[0035] As described above, as it has become possible to provide various services with the advancement of mobile communication systems, measures to effectively provide these services are required. For example, one or more profiles containing user subscription information may be installed and used on eSIMs (chips) inside the terminal, and if storage space is insufficient, the profile may be exported from the eSIM (chip) and then reinstalled on the same eSIM (chip) or installed on a different eSIM (chip).
[0036] A method according to one embodiment of the present disclosure is a method for exporting a first profile from an eSIM (chip) at a first terminal in a wireless communication system and then (re)installing it on the same eSIM (chip), and may further include the steps of: providing information including whether the terminal and the eSIM (chip) support external storage during the process of installing a new profile to a profile server; determining whether to send additional information including the size of the profile to be installed as a reply message based on the information received from the profile server; performing a step including determining whether there is a profile that can be moved outside the eUICC by checking the memory available in the eUICC based on the message received from the profile server at the terminal; processing the profile movement outside the eSIM (chip) if there is a movable profile; and proceeding with profile installation after performing the profile movement.
[0037] According to various embodiments of the present disclosure, when a terminal user encounters insufficient storage space on the eSIM (chip) during the process of installing a new profile, they were previously only able to delete and reinstall the previously purchased profile. However, they can now move and store the profile outside the eSIM (chip) and reinstall it onto the eSIM (chip) when needed. Accordingly, the terminal user can possess or own the profile they have purchased and reinstall it onto the eSIM (chip) when necessary, thereby reducing the costs incurred when deleting and reinstalling the profile.
[0038] Meanwhile, by utilizing storage space outside the eSIM (chip), terminal manufacturers can resolve the issue of limited eSIM (chip) memory capacity, thereby enhancing user convenience.
[0039] "SE (Secure Element)" may refer to a security module composed of a single chip capable of storing security information (e.g., mobile network access key, user identity verification information such as ID card / passport, credit card information, encryption key, etc.) and operating a control module that utilizes the stored security information (e.g., network access control module such as USIM, encryption module, key generation module, etc.). The SE can be used in various electronic devices (e.g., smartphones, tablets, wearable devices, automobiles, IoT devices, etc.) and can provide security services (e.g., mobile network access, payment, user authentication, etc.) through the security information and the control module.
[0040] SE can be divided into UICC (Universal Integrated Circuit Card), eSE (Embedded Secure Element), and SSP (Smart Secure Platform), which is a form in which UICC and eSE are integrated. Depending on the form in which it is connected to or installed in an electronic device, it can be subdivided into removable, embedded, and integrated types that are integrated into a specific component or SoC (system on chip).
[0041] A "UICC (Universal Integrated Circuit Card)" is a smart card inserted into mobile communication terminals and is also referred to as a UICC card. A UICC may include a connection control module for connecting to a mobile carrier's network. Examples of connection control modules include USIM (Universal Subscriber Identity Module), SIM (Subscriber Identity Module), and ISIM (IP Multimedia Service Identity Module). A UICC containing a USIM is commonly referred to as a USIM card. Similarly, a UICC containing a SIM module is commonly referred to as a SIM card. Meanwhile, the SIM module may be installed during the manufacturing of the UICC, or the SIM module of the mobile communication service the user wishes to use can be downloaded to the UICC card at a time of their choice. Additionally, multiple SIM modules may be downloaded and installed on the UICC card, and at least one of them may be selected and used. Such a UICC card may or may not be fixed to the terminal. In particular, a UICC embedded in a System-On-Chip (SoC) that includes a communication processor, an application processor, or a single processor structure in which these two processors are integrated is also referred to as an iUICC (Integrated UICC). Typically, eUICC and iUICC may refer to a UICC card that is fixedly used in a terminal and includes a function that allows at least one SIM module to be downloaded to the UICC card remotely and one of the downloaded SIM modules to be selected.In this disclosure, a UICC card comprising a function that allows at least one SIM module to be downloaded and selected remotely is collectively referred to as an eUICC or an iUICC. For example, among UICC cards comprising a function that allows a SIM module to be downloaded and selected remotely, a UICC card that is fixed to or not fixed to a terminal is collectively referred to as an eUICC or an iUICC. In this disclosure, the term UICC may be used interchangeably with SIM, and the term eUICC may be used interchangeably with eSIM (chip).
[0042] The "eUICC identifier (eUICC ID)" may be a unique identifier of the eUICC embedded in the terminal and may be referred to as an EID. Additionally, if a provisioning profile is pre-loaded on the eUICC, the eUICC identifier (eUICC ID) may be the identifier of the corresponding provisioning profile (Provisioning Profile's Profile ID). Furthermore, in one embodiment of the present disclosure, if the terminal and the eUICC chip are not separated, the eUICC identifier (eUICC ID) may be the terminal ID. Additionally, the eUICC identifier (eUICC ID) may refer to a specific secure domain of the eUICC (chip). The eUICC identifier may be provided as certain information included within an eUICC certificate. In the present disclosure, the EID provided may be a certificate containing EID information or the EID information itself.
[0043] "eSE (Embedded Secure Element)" may refer to a fixed SE that is fixed to an electronic device. The eSE is typically manufactured exclusively for the manufacturer at the request of the terminal manufacturer and may be manufactured to include an operating system and a framework. A service control module in the form of an applet may be downloaded and installed remotely on the eSE, and the installed service control module may be used for various security service purposes such as electronic wallets, ticketing, electronic passports, and digital keys. In this disclosure, a single-chip SE attached to an electronic device, to which a service control module may be downloaded and installed remotely, is collectively referred to as an eSE.
[0044] "Profile" may refer to data objects such as applications, file systems, and authentication key values stored within the UICC.
[0045] In the present disclosure, "profile package" may refer to the contents of a "profile" packaged in a software form that can be installed within a UICC. A "profile package" may be named a Profile Package TLV. If the profile package is encrypted using encryption parameters, it may be named a Protected Profile Package (PPP) or a Protected Profile Package TLV (PPP TLV). If the profile package is encrypted using encryption parameters that can be decrypted only by a specific eUICC, it may be named a Bound Profile Package (BPP) or a Bound Profile Package TLV (BPP TLV). A Profile Package TLV may be a data set representing information constituting the profile in the TLV(Tag, Length, Value) format.
[0046] In this disclosure, "profile image" may refer to binary data of a profile package installed within a UICC. The "profile image" may be named a Profile TLV or a Profile Image TLV. If the profile image is encrypted using encryption parameters, it may be named a Protected Profile Image (PPI) or a Protected Profile Image TLV (PPI TLV). If the profile image is encrypted using encryption parameters that can be decrypted only by a specific eUICC, it may be named a Bound Profile Image (BPI) or a Bound Profile Image TLV (BPI TLV). A Profile Image TLV may be a data set representing information constituting a profile in TLV format. It should be noted that in this disclosure, where it is determined that no special distinction is necessary, the "profile image" is expressed as a profile package or a profile. Accordingly, in this disclosure, an "EPP (Exported Profile Package)" may be a profile image generated from a first installed profile.
[0047] In this disclosure, to avoid obscuring the point, cases consisting of part or all of the data of a single profile may be collectively represented as EPP without distinction.
[0048] In the present disclosure, the “state” of a profile may mean one of the states of a profile defined in the SGP.22 specification defined by the GSMA. The “profile identifier” may be referred to as an argument matching a profile identifier (Profile ID), ICCID (Integrated Circuit Card ID), Matching ID, Event ID, Activation Code, Activation Code Token, Command Code, Command Code Token, Signed Command Code, Unsigned Command Code, ISD-P, or Profile Domain (PD). The profile identifier (Profile ID) may represent a unique identifier for each profile. The profile identifier may further include the address of a profile provider server (SM-DP+) capable of indexing the profile. Additionally, the profile identifier may further include the signature of the profile provider server (SM-DP+).
[0049] "RSP Server (Remote SIM Provisioning Server)" may be used as a designation for the profile (provision) server and / or profile management server and / or activation intermediary server described below. The RSP Server may be represented as SM-XX (Subscription Manager XX).
[0050] In the present disclosure, the “profile server” may include functions for creating a profile, encrypting a created profile, creating a profile remote management command, or encrypting a created profile remote management command. For example, the profile server may be represented as SM-DP (Subscription Manager Data Preparation), SM-DP+ (Subscription Manager Data Preparation plus), an off-card entity of Profile Domain, a profile encryption server, a profile creation server, a profile provisioner (PP), a profile provider, or a PPC holder (Profile Provisioning Credentials holder).
[0051] In the present disclosure, the “profile management server” may include a function for managing profiles. For example, the profile management server may be represented as SM-SR (Subscription Manager Secure Routing), SM-SR+ (Subscription Manager Secure Routing Plus), an off-card entity of eUICC Profile Manager, a PMC holder (Profile Management Credentials holder), an EM (eUICC Manager), or a PM (Profile Manager).
[0052] In this disclosure, the profile server may refer to a combination of the functions of a profile management server. Accordingly, in various embodiments of this disclosure, the operation of the profile server may be performed on the profile management server. Likewise, the operation of the profile management server or SM-SR may be performed on the profile providing server.
[0053] In the present disclosure, "activation intermediary server" may be represented as SM-DS (Subscription Manager Discovery Service), DS (Discovery Service), Root activation intermediary server (Root SM-DS), and Alternative activation intermediary server (Alternative SM-DS). An activation intermediary server may receive an Event Register Request (or Event Register Request) from one or more profile providing servers or activation intermediary servers. Additionally, one or more activation intermediary servers may be used in combination, in which case the first activation intermediary server may receive an Event Register Request from a profile providing server as well as a second activation intermediary server.
[0054] "Mobile service provider (MSP)" may refer to a business entity that provides telecommunication services to a terminal, and may collectively refer to the business supporting system (BSS), operational supporting system (OSS), point of sale terminal, and other IT systems of the mobile service provider. Furthermore, in this disclosure, the mobile service provider is not limited to representing a single specific business entity providing telecommunication services, but may also be used as a term referring to a group or association or consortium of one or more business entities, or a representative of said group or consortium. Additionally, in this disclosure, the mobile service provider may be named as an operator (or OP or Op.), a mobile network operator (MNO), a mobile virtual network operator (MVNO), a service provider (or SP), a profile owner (PO), a mobile service operator, etc., and each mobile service provider may set or be assigned at least one name and / or unique identifier (object identifier, OID). If a telecommunications business operator refers to a group or association of one or more business entities or an agency, the name or unique identifier of any group or association or agency may be a name or unique identifier shared by all business entities belonging to said group or association or all business entities cooperating with said agency.
[0055] The term "Subscriber" may be used to refer to a Service Provider who owns the terminal or an End User who owns the terminal. Generally, a terminal owned by a Service Provider may be referred to as an M2M Device, while a terminal owned by a User may be referred to as a Consumer Device. In the case of M2M Devices, there may be End Users who do not own the terminal but use it after receiving it through transfer or lease from the Service Provider; in this instance, the Subscriber may be different from or the same as the Service Provider.
[0056] The term "terminal" may be referred to as a mobile station (MS), user equipment (UE), user terminal (UT), wireless terminal, access terminal (AT), terminal, subscriber unit, subscriber station (SS), wireless device, wireless communication device, wireless transmit / receive unit (WTRU), mobile node, mobile, or other terms. Various embodiments of the terminal may include cellular telephones, smartphones with wireless communication capabilities, personal digital assistants (PDAs) with wireless communication capabilities, wireless modems, portable computers with wireless communication capabilities, imaging devices such as digital cameras with wireless communication capabilities, gaming devices with wireless communication capabilities, home appliances for music storage and playback with wireless communication capabilities, home appliances capable of wireless internet access and browsing, as well as portable units or terminals integrating combinations of such functions. Additionally, the terminal may include, but is not limited to, machine-to-machine (M2M) terminals and machine-type communication (MTC) terminals / devices. In the present disclosure, the terminal may be referred to as an electronic device.
[0057] In the present disclosure, an electronic device may have a UICC embedded therein that can be installed by downloading a profile. If the UICC is not embedded in the electronic device, a UICC that is physically separated from the electronic device may be inserted into the electronic device and connected to the electronic device. For example, the UICC may be inserted into the electronic device in the form of a card. The electronic device may include a terminal, wherein the terminal may be a terminal that includes a UICC that can be installed by downloading a profile. The UICC may not only be embedded in the terminal, but if the terminal and the UICC are separated, the UICC may be inserted into the terminal and connected to the terminal. A UICC that can be installed by downloading a profile may be referred to, for example, as an eUICC.
[0058] "LPA (Local Profile Assistant)" may refer to software or applications installed within a terminal or electronic device to control a UICC or eUICC on the terminal or electronic device. In the present disclosure, when it is expressed that a terminal transmits a command to an eUICC or that a terminal receives a command from an eUICC, the terminal's endpoint may be interpreted as an LPA. When it is expressed as being stored in an LPA, it may be interpreted to mean that it is stored in an internal or external memory of the terminal accessible by the LPA. For example, this may apply to memory fixed or removable to the terminal where the LPA is installed, as well as external memory connected to the terminal via wired or wireless means, and memory of a cloud server. Although the present disclosure describes the case by assuming, for example, the terminal's internal memory, the present disclosure may also apply to the terminal's external memory. "Event" may be used for the following purposes in the present disclosure. Of course, it is not limited to the examples below.
[0059] "Event" may be a term including Profile Download, Remote Profile Management, or other management / processing commands for profiles or eUICC. An Event may be named a Remote SIM Provisioning Operation (or RSP Operation or RSP Operation) or an Event Record, and each Event may be referred to as data comprising at least one of the following: a corresponding Event Identifier (Event ID, EventID) or Matching Identifier (Matching ID, MatchingID), the address of the Profile Provider Server (SM-DP+) or Activation Broker Server (SM-DS) where the event is stored (e.g., Fully Qualified Domain Name (FQDN), Internet Protocol Address (IP), or Uniform Resource Locator (URL)), the signature of the Profile Provider Server (SM-DP+) or Activation Broker Server (SM-DS), and a digital certificate of the Profile Provider Server (SM-DP+) or Activation Broker Server (SM-DS).
[0060] Data corresponding to an Event may be referred to as a "Command Code." Part or all of the procedure utilizing the Command Code may be referred to as a "Command Code Processing Procedure," a "Command Code Procedure," or an "LPA API (Local Profile Assistant Application Programming Interface)." Profile Download may be used interchangeably with Profile Installation.
[0061] Additionally, "Event Type" may be used as a term indicating whether a specific event is a profile download, remote profile management (e.g., deletion, activation, deactivation, replacement, update, etc.), or other profile or eUICC management / processing commands, and may be named as Operation Type (or OperationType), Operation Class (or OperationClass), Event Request Type, Event Class, Event Request Class, etc. For any event identifier (EventID or MatchingID), the path through which the terminal obtained the event identifier (EventID or MatchingID) or the intended use (EventID Source or MatchingID Source) may be specified.
[0062] "Local Profile Management (LPM)" may be referred to as Profile Local Management, Local Management, Local Management Command, Local Command, Local Profile Management Package, Profile Local Management Package, Local Management Package, Local Management Command Package, or Local Command Package. LPM may be used to change the status of a specific profile (e.g., Enabled, Disabled, Deleted) or to update the contents of a specific profile (e.g., Profile Nickname, Profile Metadata, etc.) through software installed on the terminal. LPM may include one or more Local Management Commands; in this case, the profiles targeted by each Local Management Command may be the same or different for each Local Management Command.
[0063] A "Certificate" or "Digital Certificate" may represent a digital certificate used for asymmetric key-based mutual authentication consisting of a pair of a public key (PK) and a secret key (SK). Each certificate may include one or more public keys (PKs), a public key identifier (PKID) corresponding to each public key, a certificate issuer ID (Certificate Issuer ID) of the certificate issuer (CI) that issued the certificate, and a digital signature. For example, the certificate issuer may be referred to as a certification issuer, a certificate authority (CA), or a certification authority. For example, in the present disclosure, a public key (PK) and a public key identifier (PKID) may be used to refer to a specific public key or a certificate containing the public key, or a part of a specific public key or a part of a certificate containing the public key, or a result of an operation (e.g., hash) of a specific public key or a result of an operation (e.g., hash) of a certificate containing the public key, or a result of an operation (e.g., hash) of a part of a specific public key or a result of an operation (e.g., hash) of a part of a certificate containing the public key, or a storage space where data is stored.
[0064] A "Certificate Chain" or "Certificate Hierarchy" can represent the correlation between certificates when certificates issued by a "Certificate Issuer" (primary certificates) are used to issue other certificates (secondary certificates), or when secondary certificates are used to issue tertiary or higher certificates in a linked manner. For example, the CI certificate used for the initial certificate issuance may be named the Root of Certificate, the top-level certificate, the Root CI, the Root CI Certificate, the Root CA, or the Root CA Certificate.
[0065] In the embodiments of the present disclosure below, when the expressions "transmit data by signing" or "transmit signed data" are used, it may mean that the transmitting entity digitally signs the data to be transmitted using its private key to ensure the integrity of the data to be transmitted, for example, that the transmitting entity constructs and transmits a message containing the signature. For example, the expressions "transmit deletion results signed by eUICC" or "transmit deletion results by signing" may be interpreted to mean that the eUICC transmits a message containing deletion result data and a signature in which the deletion result data is signed using its private key. The receiving side can determine whether the data has been tampered with and determine its integrity by verifying it with a public key (e.g., the eUICC's public key) corresponding to the signature included in the message.
[0066] In this disclosure, "External Storage (ES) support or Extended Storage (ES) support" may be interpreted as a function that supports the movement and / or storage of profiles installed on an eUICC outside of the eUICC. ES support may be referred to by terms such as ES movement support and ES memory support. ES support may be interpreted as a function (e.g., eUICC ES support) or permission (e.g., profile ES support) that allows the entire or (partial) of a bound profile package installed on an eUICC to be split, extracted, and stored outside of the eUICC, and then retrieved and used by an eUICC having the same eUICC ID. In this disclosure, extracting a profile may be used interchangeably with moving a profile. For example, "profile extraction" may be used interchangeably with "profile moving."
[0067] A profile package may be a bundle of profile data that occupies one ISD-P (Issuer Security Domain Profile, defined in SGP.22) in eUICC.
[0068] In the present disclosure, split save support may be referred to by terms such as SplitSave and SplitSaveList. Split save may mean a function that allows at least one file of a profile package to be split and saved in the eUICC.
[0069] From the perspective of eUICC, split storage may mean splitting and storing at least one file of a profile package within the eUICC, and providing the ability to store data externally. By explicitly providing a split storage list, the eUICC can indicate which files to store without extracting them externally. If the GSMA defines a list of files that are not recommended for extraction outside the eUICC, the eUICC may refer to that list of files by indicating only the split storage identifier.
[0070] The 'partial storage' of profile metadata may be interpreted to mean that some information of the profile must be left in the eUICC. For example, if a list capable of identifying data (which may be referred to as a file list in this disclosure) is provided as partial storage information, it may be interpreted as the minimum file list that the profile must leave in the eUICC.
[0071] In addition, since this disclosure describes the installation procedure of a profile of the GSMA (GSM Association) SGP standard, for example, SGP.22, this disclosure may be interpreted by referring to the GSMA SGP standard. In describing this disclosure, named functions, data, and parameter names may be changed in various ways depending on the embodiment.
[0072] For example, in the present disclosure, eUICC information may include eUICCInfo1 and eUICCInfo2 as defined in the SGP.22 specification. In the present disclosure, eUICCInfo1 may be referred to as the first eUICC information, and eUICCInfo2 may be referred to as the second eUICC information. For example, eUICCInfo1 may be a subset of eUICCInfo2 and may include information transmitted to a Remote SIM Provisioning (RSP) server prior to authentication. For example, eUICCInfo2 may include the entire eUICC information and may include information disclosed to the RSP server after authentication.
[0073] The present disclosure relates to a wireless communication system or a mobile communication system. Specifically, the present disclosure relates to a method and apparatus for moving communication subscription information in a terminal, and more specifically, to a method and apparatus that, when installing a profile in a terminal, secures installation space and enables the installation of a profile by moving a profile stored in an eUICC to outside the eUICC.
[0074] FIG. 1 is a diagram showing the relationship between components for moving a profile according to one embodiment of the present disclosure.
[0075] FIG. 1 is solely for the purpose of facilitating understanding of the present disclosure and is not limited to the examples of FIG. 1. Some of the configurations illustrated in FIG. 1 may be omitted, and additional configurations may be included in addition to those illustrated in FIG. 1.
[0076] The terminal (110) is equipped with an eUICC (130), and a profile (not shown) may be installed on the eUICC (130). Additionally, an LPA (120) may be installed on the terminal (110). The eUICC (130) may be controlled by the LPA (120). The user (100) can control the eUICC (130) of the terminal (110) through the LPA (120) of the terminal (110). There may be multiple eUICCs (130) installed on the terminal (110). If there are multiple eUICCs (130), multiple LPAs (120) controlling each eUICC (130) may be assumed. The eUICC (130) can support movement of the profile within the terminal (110).
[0077] The LPA (120) can support moving the profile outside the eUICC (130). Here, the case of storing the profile in the terminal (110) via the LPA (120) may be a case where the LPA (120) receives profile data from the eUICC (130) and the LPA (120) stores it in the memory (140) of the terminal (110) (referred to as the "first storage method" in this disclosure), or a case where the LPA (120) requests the eUICC (130) to store the profile data externally, and the eUICC (130) processes the storage of the profile data in the memory (140) of the terminal and returns the processing result to the LPA (120) (referred to as the "second storage method" in this disclosure). Therefore, it should be noted that the meaning of "storing in the terminal" encompasses both of these cases, and the present disclosure may be applicable to both of these cases. Meanwhile, in cases where these two distinctions are necessary, the ES-supported storage method can be described by distinguishing it into a "first storage method" and a "second storage method." In the present disclosure, "ES-supported storage method" may refer to a method of moving and / or storing part or all of a profile externally for ES support.
[0078] The memory (140) may be a data storage space of the terminal and may include a fixed type of memory and / or a removable memory in the form of a card or chip. In the case of the first storage method, the LPA (120) supports an interface with the memory (140), and in the case of the second storage method, the eUICC (130) supports an interface with the memory (140).
[0079] A telecommunications operator (150) may be connected to a profile server (160). The telecommunications operator (150) may be composed of one or more operator servers. In the example of FIG. 1, a case configured as a single server is illustrated for convenience, but depending on the implementation and embodiment, one or more profile servers (SM-DP+) may be included in the server configuration, and one or more activation intermediary servers (SM-DS) that assist in creating a connection between a specific profile server and a terminal may be included in the server configuration. Such various server configurations may be briefly represented in the present disclosure and drawings as a single profile server or SM-DP+.
[0080] The user (100) may have subscribed to the communication service of the telecommunications carrier (150) and installed profile(s) on the eUICC (130) of the terminal (110). Additionally, the user (100) may want to install additional profiles on the eUICC (130) of the terminal (110).
[0081] FIG. 2 is a diagram illustrating the procedure for moving a profile outside of an eUICC according to one embodiment of the present disclosure.
[0082] FIG. 2 is solely for the purpose of facilitating understanding of the present disclosure and is not intended to limit the present disclosure. Some of the entities and / or operations illustrated in FIG. 2 may be omitted, and additional entities and / or operations not illustrated in FIG. 2 may be included.
[0083] LPA (205) may request eUICC information from eUICC (215) (not shown). For example, LPA (205) may request eUICC information from eUICC (215) to configure and display a user screen. eUICC (215) may reply to LPA (205) with eUICC information including whether "ES (External Storage) support" (or identification information regarding ES support) (230). For example, the eUICC information may be replied as information included in eUICCInfo2 defined in the GSMA SGP standard.
[0084] Meanwhile, the LPA (205) may provide eUICC information (e.g., eUICCInfo2) to a profile server (not shown) as described in detail below in FIG. 3, and may provide the profile server to compose metadata of the profile by referring to the received eUICC information (e.g., eUICCInfo2) and reply to the LPA (205) of the terminal, and may provide the LPA (205) of the terminal to store the metadata of the profile in the eUICC (215). This may occur before requesting profile information (e.g., calling or executing the ES10c.getProfilesInfo function).
[0085] At a later time, the LPA (205) may request profile information from the eUICC (215) (e.g., by calling or executing the ES10c.getProfilesInfo function defined in the GSMA SGP specification) to receive a list of profiles and check whether there is identification information regarding ES support in the metadata of the profiles (235). For example, the list of profiles may include at least one of an ICCID, profile size, and identification information regarding ES support for each profile installed in the eUICC (215).
[0086] Operations 230 and 235 may be performed sequentially or at a time interval. As mentioned above, the process may be performed such that the LPA performs operation 230 with specific information required during the process of downloading a profile to download and install the profile and its metadata in the eUICC, and then at a specific time, the 235 operation is performed so that the LPA receives information about one or more profiles installed in the eUICC from the eUICC.
[0087] For example, in 230 and / or 235, eUICC information (e.g., eUICCInfo2) may include at least one of ExtStorageSpecificInfo or extendedStorageSupport. In this disclosure, ExtStorageSpecificInfo and extendedStorageSupport may be collectively referred to as "ES support" identification information. For example, ExtStorageSpecificInfo may be included in eUICCInfo2 in ASN.1 format as a data field as follows.
[0088]
[0089] For example, extendedStorageSupport can be included as new bit information for the eUICC RSP capability information (e.g., EuiccRspCapability) of EUICCInfo2, as shown in the example below.
[0090]
[0091] For example, ExtStorageSpecificInfo may further include at least one of information regarding whether split storage is supported (e.g., splitSaveSupport) and file identifier information (e.g., fileIdentifier), as shown in Table 1 associated with FIG. 3.
[0092]
[0093] LPA (205) can determine whether to provide a move function based on at least one of the "ES support" identification information of the received eUICC and the "ES support" identification information of the profile (240). If the profile is indicated as ES support, LPA (205) can display it as a moveable profile on the user display screen. If there is no ES support information in the received eUICC information (230) or if there is no ES support information in the profile, LPA (205) can terminate the procedure for moving profiles without displaying moveable profiles on the user screen.
[0094] At a specific point in time thereafter, a "Save Profile Move" menu may be provided to the terminal user (200), and if an input (243) selecting the profile to move is received from the terminal user (200), the LPA (205) may transmit a profile move request to the eUICC (215) to move the profile outside the eUICC. Upon receiving the profile move request, the eUICC (215) may generate profile data to move outside the eUICC and send the generated profile data back to the LPA (205). The LPA (205) may process the move by storing the received data (245, described later in FIG. 7).
[0095] FIG. 3 is a diagram illustrating a procedure for a profile server to configure profile metadata based on whether ES is supported, according to one embodiment of the present disclosure.
[0096] FIG. 3 is solely for the purpose of facilitating understanding of the present disclosure and is not intended to limit the present disclosure. Some of the entities and / or actions illustrated in FIG. 3 may be omitted, and additional entities and / or actions not illustrated in FIG. 3 may be included.
[0097] Mutual authentication can be performed between the eUICC (310) and the profile server (315), and mutual authentication can be performed during the process of downloading and installing the profile. The example in FIG. 3 focuses on the metadata configuration considering ES support and includes a description of the general mutual authentication procedure, but for a detailed description, the GSMA SGP.22 specification may be referenced and the entire GSMA SGP.22 specification is included as a reference.
[0098] In the process of performing mutual authentication, prior to operation 320, the terminal's LPA (305) may first request eUICC challenge information and eUICCInfo1, which constitutes part of the eUICC information, from the eUICC (310), and receive eUICC challenge information and eUICCInfo1 from the eUICC (310). In the present disclosure, eUICC challenge information may refer to a random (Nonce) value generated by the eUICC to authenticate a profile server (e.g., SM-DP+), and may be referred to as eUICCCChallenge in the present disclosure.
[0099] LPA (305) can construct a message containing the information and send it to the profile server (320). An example of a message may include an InitiateAuthenticationRequest (or InitiateAuthentication).
[0100] A profile server (315) that receives a message (320) can determine the signature verification algorithm and signature generation algorithm to be used by the profile server and eUICC in the corresponding RSP session based on the data included in eUICCInfo1, and can generate server challenge information. In the present disclosure, server challenge information may refer to a random (Nonce) value generated by the profile server to authenticate the eUICC, and may be referred to as serverChallenge in the present disclosure.
[0101] The profile server (315) may compose data including at least the received eUICCCchaenge and serverChallenge, and then reply with the data and signature signed with the profile server's private key via a message (330). An example of a message (330) may include an AuthenticateResponse.
[0102] LPA (305) may send a message to eUICC (310) to request eUICC to perform server authentication (335). If server authentication is successful, eUICC (310) may reply by generating eUICC-signed data (and / or eUICC signature), including additional data, if there is additional data sent by LPA (e.g., CtxParams1 containing terminal performance information) (345). An example of a message (335) may include ES10b.AuthenticateServer. For example, the message (335) may include at least one of data signed (e.g., dpSignedData) (with the profile server's private key), a signature (e.g., DP+Signature), and additional data (e.g., CtxParams1 containing terminal performance information).
[0103] The eUICC (310) that receives the message (335) can authenticate the profile server by verifying the data (e.g., dpSignedData) signed (with the private key) of the profile server received from the LPA (305) and comparing and / or verifying whether the eUICCCChallenge value included in the verified data is the same as the eUICCChallenge sent before 320 (340).
[0104] When the profile server (315) is authenticated, the eUICC (310) can generate data containing eUICCInfo2 as eUICC information, sign the data with the eUICC's private key (340), and send it back to the LPA (305) (345). At this time, eUICCInfo2 may include information on whether the eUICC (310) supports ES, and if information on whether it supports ES is included, additional information on whether it supports split storage of the profile may be included. Information on whether it supports split storage of the profile may be, for example, an identifier for whether it supports split storage, or information on one of the lists of files to be split and stored. Split storage may indicate a function in which the eUICC can split at least one file of the profile package and store it in the eUICC. For example, split storage may indicate that a bundle of critical data predefined by at least one of the GSMA, 3GPP, Global Platform, TCA, GSMA, and ETSI is split from a profile and stored in an eUICC (for example, splitSaveRuleSupport in Table 2). The eUICC may comprehensively indicate support for split storage by providing a list of files to be split. When the LPA (305) receives eUICC signed data (e.g., eUICCSignedData) and / or an eUICC signature containing eUICCInfo2 from the eUICC (310) (345), the LPA (305) may transmit the eUICC signed data (e.g., eUICCSignedData) and / or the eUICC signature to a profile server via a message (350). For example, one example of a message (350) may include an AuthenticateClient.
[0105] For example, eUICCInfo2 of 345 and / or 350 may include at least one of the information exemplified in [Table 1] or [Table 2].
[0106]
[0107]
[0108] In the example of [Table 1], ExtStorageSpecificInfo indicates whether ES is supported, and if at least one of the following is included: information on whether split storage is supported (e.g., SplitSaveSupport) or file identifier information (e.g., fileIdentifier), it may mean that eUICC provides (additionally) a function to split some items of the profile, store them in eUICC, and extract them outside the terminal.
[0109] In the example of [Table 2], ExtStorageSpecificInfo indicates whether ES is supported, and if at least one of the following is included: information on whether split storage is supported (e.g., SplitSaveSupport) or information on split storage rules (e.g., splitSaveRuleSupport), it may mean that eUICC provides (additionally) a function to split some items of the profile, store them in eUICC, and extract them outside the terminal.
[0110] If information regarding split save support (e.g., SplitSaveSupport) is not included in the ES support identification information (e.g., ExtStorageSpecificInfo), eUICC may provide a default profile extraction method. For example, the default profile extraction method may be to send the entire profile package externally, or it may be split save support. As previously described, file identifier information (e.g., fileIdentifier) may be a list of files to be split and may include an identifier for at least one file.
[0111] A profile server (315) that receives a message (350) can authenticate the eUICC by verifying the signature of the received eUICC and checking through signature verification whether the received data (eUICC signed) (e.g., eUICCSignedData) contains the serverChallenge value previously generated and transmitted by the profile server (355). If authentication is successful, the profile server can check the eUICCInfo2 included in the received data and configure the metadata of the profile (355). For example, the profile server (315) can configure metadata including whether ES is configured based on at least one of the following: information regarding whether the eUICC supports ES and splitting supports received via eUICCInfo2, and profile configuration information regarding the carrier's ES support. The carrier's profile configuration information may be information that the profile server (315) requests from the carrier at the time it receives the message and receives from the carrier, or information that the profile server has previously obtained from the carrier and stores. The determination for configuring the metadata may include at least one of the following (355).
[0112] 1. If there is no ES support instruction in eUICCInfo2,
[0113] Metadata does not include ES support identification information
[0114] 2. eUICCInfo2 contains ES support instructions but lacks split support information,
[0115] If there is a requirement for split support settings in the carrier's profile settings information,
[0116] Metadata does not include ES support identification information
[0117] 3. eUICCInfo2 has ES support instructions but lacks split support information,
[0118] If there is no requirement for split support settings in the carrier's profile settings,
[0119] Includes ES support identification information in metadata
[0120] 4. eUICCInfo2 contains ES support instructions and split support information,
[0121] If there is a requirement for split support settings in the carrier's profile settings information,
[0122] Includes ES support identification information in the metadata, and includes segmentation support.
[0123] 5. eUICCInfo2 contains ES support instructions and split support information,
[0124] If there is no requirement for split support settings in the carrier's profile settings,
[0125] Include ES support identification information in the metadata.
[0126] If the partition support information received from the eUICC includes a file list, the profile server can further check whether there is a partition storage list required by the carrier. If there is a partition storage list required by the carrier, it can determine whether the partition storage file list received from the eUICC includes all the partition storage lists required by the carrier. If the partition storage file list received from the eUICC includes all the partition storage lists required by the carrier, the profile server can determine that the profile is ES-supportable.
[0127] Meanwhile, although not detailed in this drawing, the splitting support information of the eUICC may not include a file list. If the splitting support information received from the eUICC does not include a file list, the profile server may operate in one of the following ways.
[0128] If the profile server has a partitioned storage list requested by the telecommunications carrier, it can compose metadata including the partitioned storage list requested by the telecommunications carrier and send a reply. As previously explained, the partitioned storage list requested by the telecommunications carrier can be verified as information received by the profile server by requesting it from the telecommunications carrier at the time of receiving the message, or it can be verified during the process of setting metadata by storing the profile setting information for ES support from the telecommunications carrier in advance. The profile server can compose metadata including the corresponding file list. It can send or reply to the LPA (305) with a message containing the configured profile metadata.
[0129] If the profile server does not have a partitioned storage list requested by the telecommunications operator, the profile server may configure metadata including at least whether ES is supported, and may send or reply to the LPA (305) a message containing the configured profile metadata.
[0130] The profile server (315) may send or reply to the LPA (305) a message containing profile metadata configured according to the prior judgment (360). An example of information regarding ES support included in the profile metadata (360) may include [Table 3] or [Table 4]. In the example of Table 3 or Table 4, ExternalStorageConfiguration represents information regarding ES support.
[0131]
[0132]
[0133] In the example of Table 3 or Table 4, if the splitSaveRequired item is not present, the entire profile package may be allowed to be extracted to the terminal (or out of the eUICC). In the example of Table 3 or Table 4, if the splitSaveRequired item is present, it may be used as information indicating that a specific file item cannot be extracted to the terminal (or out of the eUICC). In the present disclosure, splitSaveRequired may indicate whether the carrier requires that a portion of the profile package be left in the eUICC or whether the carrier allows split storage, and may be referred to as split storage requirement information.
[0134] In addition to or separately from splitSaveRequired, information regarding ES support (e.g., ExternalStorageConfiguration) may include a list of files that are stored in eUICC without being extracted externally. For example, even if there is no explicit data for splitSaveRequired, it may be determined that splitSaveRequired is required if a file identifier is added to the metadata.
[0135] If the split storage file list received from the eUICC does not include at least one item among the split storage lists required by the telecommunications carrier, the profile server determines that the profile does not support ES and may configure metadata without including ES support identification information or without ES support identification information.
[0136] LPA (305) can proceed with the profile download and installation procedure defined in SGP.22 (365). For example, in 365, LPA (305) can proceed with the profile download and installation procedure defined in SGP.22 after obtaining user consent regarding whether to install the profile by providing profile metadata to the user.
[0137] FIG. 4 is a diagram illustrating a procedure for updating metadata of a profile regarding whether the profile supports ES according to one embodiment of the present disclosure.
[0138] FIG. 4 is solely for the purpose of facilitating understanding of the present disclosure and is not intended to limit the present disclosure. Some of the entities and / or operations illustrated in FIG. 4 may be omitted, and additional entities and / or operations not illustrated in FIG. 4 may be included.
[0139] During the process of installing the profile, the metadata of the profile may be configured and installed without ES support identification information (422), and 422 may include the procedure exemplified in FIG. 3.
[0140] Subsequently, at a specific time, the telecommunications operator (420) may send an update request for the metadata of the profile to the eUICC (410) (425). For example, the update request may use an ES6 interface defined in SGP.22, and an example of the update request may include a message such as UpdateMetadataRequest. The update request (e.g., UpdateMetadataRequest) may include at least one of the following: an ICCID (used as the ID of the profile requesting the update), ES support identification information, and information regarding whether split storage support is required. The information regarding whether split storage support is required may refer to at least one of the following: a list requesting split storage to the eUICC, and split storage request information.
[0141] The eUICC (410) that receives the update request can determine whether it is possible to update metadata related to whether it supports ES and / or whether it supports splitting (430). For example, the eUICC (410) can determine whether it supports the update request received from 425 based on the eUICC's capability, and if the eUICC determines that it does not satisfy the update conditions, it can send an error (e.g., CommandError) to the carrier (420) (435).
[0142] Cases where eUICC determines that the update conditions are not satisfied may include at least one of the following.
[0143] 1. In the case where ES support is specified in the received request (425), but the eUICC does not support ES
[0144] 2. When split storage is specified in the received request (425), but the eUICC does not support split storage
[0145] 3. In the case where the received request (425) includes a split storage list as information regarding split storage support, but the eUICC cannot split the received list and store it in the eUICC when extracting the profile externally
[0146] If eUICC (410) determines that the update conditions are satisfied, eUICC (410) may reply (440) with a success response (e.g., Response OK) and update (445) the information received (in 425) in the metadata of the profile identified by the ICCID. The 445 operation may be performed before the 440 operation.
[0147] Cases in which eUICC determines that the update conditions are satisfied may include at least one of the following.
[0148] 1. When the received request (425) directs ES support (without a split storage request), and the eUICC supports ES
[0149] 2. When the received request (425) indicates ES support and a split storage request, and the eUICC supports ES and also supports split storage
[0150] 3. If a list is included as information regarding the split storage request of the request (425) received in 2, and the eUICC can extract the profile externally by excluding the list,
[0151] If the terminal and the eUICC support LPA Alert, the eUICC may additionally update metadata and notify the LPA that the metadata has been updated (450). An example of a case where the terminal and the eUICC support LPA Alert may include a case where the terminal's LPA sets an alert support bit (e.g., pendingOperationAlertingSupport bit) in LPA RSP capability information (e.g., LpaRspCapability) and transmits it to the eUICC to notify the support of the LPA Alert function, and the eUICC that receives this supports LPA Alert. If the terminal and the eUICC support LPA alerting, the eUICC can transmit LPA alerting data (e.g., ES10c.LpaAlerting) defined in SGP.22 to the terminal's LPA in a message sent by the eUICC to the terminal (e.g., Application Update as a Proactive Command) when a metadata update of a specific ICCID occurs. The LPA (405) can detect a metadata update of a specific profile by referring to at least one of the ICCID and tag list information (e.g., tagList) of the updated metadata (in 445) in the LPA alerting data included in the received message (455). Additionally, depending on the settings of the LPA, further actions may be performed. An example of an additional action may include requesting information of the profile having the corresponding ICCID from the eUICC (410) and obtaining or storing metadata information included in the message that the eUICC (410) replies to the LPA (405).
[0152] FIG. 5 is a diagram illustrating a procedure for displaying a profile list in a terminal according to one embodiment of the present disclosure.
[0153] FIG. 5 is solely for the purpose of facilitating understanding of the present disclosure and is not intended to limit the present disclosure. Some of the operations illustrated in FIG. 5 may be omitted, and additional operations not illustrated in FIG. 5 may be included.
[0154] One or more profiles may be installed in the eUICC of the terminal (500).
[0155] The terminal can display profile information to the terminal user from the terminal's LPA, receive user input, and perform an action corresponding to the user input.
[0156] In the case of an LPA that has decided to support ES, it can perform the 510 operation and subsequent additional operations (505).
[0157] In order for the terminal's LPA to display profile information, the LPA may request information about the profile from the eUICC and receive response data. For example, the LPA may receive profile information by performing operation 235 of FIG. 2. As an example, ES10c.getProfilesInfo defined in the GSMA SGP standard may include ProfileInfoListRequest, and the eUICC may reply to the LPA with information on one or more profiles (e.g., a list of profiles). The LPA may obtain information on a specific profile identified by an ICCID or AID (Application ID) using ProfileInfoListRequest, or request one or more profiles having the same profile class (e.g., Test Profile, Operational Profile). Additionally, it may request values by limiting the data having a specific tag among them.
[0158] If there is one or more profiles in the eUICC, the eUICC checks the metadata of the profile(s) and can reply with the information of the profile(s) as profile information (e.g., ProfileInfo) via a message. For example, if ES support is indicated in the metadata of the profile as a result of FIG. 3 and / or FIG. 4, ES support may be indicated in the information of the profile that the eUICC replies to the LPA. The LPA that receives the profile information can determine whether the profile is allowed to be moved to a terminal storage space outside the eUICC by referring to the information (510).
[0159] If ES support is indicated in the profile information and received (510), the LPA may determine that the profile is a profile that is allowed to be moved to the terminal memory and notify the terminal user through the terminal's User Interface (UI) (515). If there is no indication of ES support in the profile information (510), the LPA may determine that the profile is a profile that is not allowed to be moved to the terminal's memory, and thus provide a method to prevent the terminal user from selecting the profile for external eUICC movement. For example, at least one of the methods such as not displaying the profile on the external move list selection screen or disabling selection may be used (520). An example of the form in which ES support is indicated in the profile information is that externalStorageConfiguration may be included in the data previously received as metadata, as shown in [Table 5]. Or, as another example, at least externalStorageSupport or extendedStorageSupport may be indicated.
[0160]
[0161] Meanwhile, if the LPA is not configured to support ES support or is configured not to support it (505), the LPA may terminate the procedure regardless of whether the profile responds to ES support (525). The determination of the LPA's ES support storage method will be described later in FIG. 6.
[0162] FIG. 6 is a diagram illustrating a procedure for determining an ES-supported storage method in an LPA according to one embodiment of the present disclosure.
[0163] FIG. 6 is solely for the purpose of facilitating understanding of the present disclosure and is not intended to limit the present disclosure. Some of the operations illustrated in FIG. 6 may be omitted, and additional operations not illustrated in FIG. 6 may be included.
[0164] As described with reference to FIG. 1, profile data extracted from the eUICC can be stored in the memory of the terminal through an LPA or an interface to which the eUICC is connected. In the present disclosure, where it is necessary to distinguish the entity responsible for the storage process, ES support is described using the terms "first storage method" and "second storage method." "First storage method" refers to a method in which the LPA receives profile data from the eUICC and transmits it to the terminal memory, and may be used interchangeably with "LPA method" in the present disclosure. "Second storage method" refers to a method in which the eUICC transmits profile data to the terminal's external memory connected to the eUICC without the LPA receiving the profile data from the eUICC, and may be used interchangeably with "eUICC method" in the present disclosure.
[0165] If the storage subject of the ES is predetermined in the terminal (605), the LPA can perform subsequent operations using the predetermined supported storage method (610). An example of the subsequent operation may include the operation exemplified in FIG. 5.
[0166] If the ES-supported storage method to be used by the LPA is not predetermined in the terminal (605), the LPA can check the ES-supported storage method supported by the eUICC and perform a procedure to determine the ES-supported storage method to be used among the ES-supported storage methods supported by the eUICC (612).
[0167] An example of a method for an LPA to check the ES-supported storage method of an eUICC may include checking the information of eUICCInfo2 received by the LPA as reply information to an eUICC information request (e.g., GetEuiccInfo) that the LPA sends to the eUICC (612). If the LPA supports at least one of the ES-supported storage methods received from the eUICC (615), the LPA may set the method to one of the at least one method and process subsequent operations (620). If the eUICC supports two or more storage methods (e.g., both the first storage method and the second storage method are supported), the eUICC may list and provide the supported storage methods according to priority, and the LPA that receives this may determine the method that the LPA can support by referring to the priority provided by the eUICC (620).
[0168] The LPA may explicitly inform the eUICC of the determined ES-supported storage method by sending the determined ES-supported storage method to the eUICC as a message. Alternatively, the LPA may not explicitly inform the eUICC of the determined ES-supported storage method. For example, if the eUICC informs the LPA of two or more ES-supported storage methods, the eUICC may assume the method with the highest priority.
[0169] If the LPA does not support the ES-supported storage method received from the eUICC (615), the LPA can determine that ES is not supported (625) and terminate the procedure (630).
[0170] FIG. 7 is a diagram illustrating a procedure for moving a profile from eUICC to outside of eUICC according to one embodiment of the present disclosure.
[0171] FIG. 7 is solely for the purpose of facilitating understanding of the present disclosure and is not intended to limit the present disclosure. Some of the entities and / or operations illustrated in FIG. 7 may be omitted, and additional entities and / or operations not illustrated in FIG. 7 may be included.
[0172] The example of FIG. 7 may be an action performed at a specific point in time after profile download and installation (720) is performed, and LPA (705) may perform an action (725) to display a list of ES-supported profiles to the user (700) through the user screen. For example, 720 of FIG. 7 may include the action described with reference to FIG. 3, and 725 of FIG. 7 may include the action described with reference to FIG. 5.
[0173] The profile transfer procedure may be initiated when the terminal user (700) receives input (730) selecting the profile to transfer. Alternatively, if the terminal recognizes that a profile transfer is necessary according to the terminal settings (e.g., detection of insufficient available memory in the eUICC), the profile transfer procedure may be initiated by obtaining the user's consent or based on the terminal's judgment.
[0174] When a profile move is determined based on the selection input of the terminal user (700) or the settings of the terminal, the LPA (705) may transmit a (profile move) request (or profile move request message) to the eUICC (715) (735). For example, the request (735) may be a new command such as RequestToExtStorage and may include the ICCID or AID (Application ID) of the profile selected by the user or terminal as identification information of the profile to be moved. If the eUICC does not support the profile move, the eUICC may return an error and terminate the procedure.
[0175] The eUICC (715) that supports profile movement and receives the above request can determine whether to support ES by determining whether at least one of the following conditions is satisfied (740).
[0176] 1. Whether a profile identified by the corresponding ICCID or AID exists
[0177] 2. Whether ES movement is allowed as profile information
[0178] 3. Whether the status of the profile to be moved above is disabled
[0179] eUICC (715) may return an error (745) and terminate the procedure if at least one of the above conditions is not satisfied. Meanwhile, if eUICC (710) returns an error (745) when the profile state requesting the move is active, LPA (705) may request a change of the profile state to an inactive state, and after eUICC (710) performs profile deactivation, LPA (705) may perform 735 again.
[0180] eUICC (715) may determine that the profile is moveable. For example, if there is a profile identified by an ICCID or AID (received from 735) and ES moveable is allowed according to the information of the profile, eUICC (715) may determine that the profile is moveable.
[0181] eUICC (715) can configure the data of a profile to be exported (or transmitted externally) (750). For convenience of explanation, the data of the profile to be exported (or transmitted externally) by the eUICC in this disclosure is referred to as an External Storage Profile Package (ESPP). For example, an ESPP may be a data package configured to include all or part of the files of the profile. The profile package may be composed of only a portion of the files excluding sensitive data files, and may be composed in the form of binary data.
[0182] If the profile contains split storage request information, eUICC (715) can check the information in the profile to see if a list that does not allow extraction required by eUICC has been provided.
[0183] If a list of profile information that does not allow extraction is provided, eUICC (715) can create a data package excluding that list (750).
[0184] If the profile does not include split storage requirement information, the eUICC (715) may package the entire profile or create a data package consisting of only some files according to the split storage information set in the eUICC (715). The split storage information set in the eUICC (715) may be information identifying files or bundles of files that must be kept without being extracted outside the eUICC. For example, files that must be kept without being extracted outside the eUICC may be sensitive data files, such as authentication information for network access.
[0185] eUICC (715) may also encrypt the corresponding profile package (ESPP) being exported externally with an encryption key so that it can only be decrypted by an eUICC with the same EID (eUICC identifier).
[0186] eUICC(715) can operate in the first storage method or the second storage method.
[0187] When the eUICC (715) operates in the first storage method, the eUICC (715) may reply to the LPA (705) with an ESPP in response to the request (735) (755). For example, the eUICC (715) may reply with only the ESPP, or it may reply with at least one of the following: an EID, which can identify which profile the data is for, along with the ESPP and decryptable eUICC information. For example, the eUICC (715) may reply with an eUICC signature along with the eUICC data being replied. The LPA (705) may store the received data in memory (710) (760).
[0188] When the eUICC (715) operates in a second storage mode, the eUICC (715) can transmit the ESPP to memory (710) (765) and return the processing result to the LPA (705) (770). For example, in 765, the eUICC (715) may transmit only the ESPP to memory (710), or it may transmit to memory (710) at least one of the information such as EID and ICCID to identify which profile the data is for, along with the ESPP, as decryptable eUICC information. For example, the eUICC (715) may transmit to memory (710) the eUICC signature along with the transmitted eUICC data. The 765 operation may be performed after the 770 operation is performed.
[0189] After LPA (705) receives a success response for moving the profile (755 or 770), it may proceed with the profile download and installation operations.
[0190] FIG. 8 is a drawing illustrating the configuration of a terminal according to one embodiment of the present disclosure.
[0191] Referring to FIG. 8, the terminal may include a transceiver (820), a processor (810), and a memory (830). Additionally, the terminal may further include an eUICC (not shown). The terminals described above in the present disclosure may correspond to the terminal described in FIG. 8.
[0192] However, the configuration of the terminal is not limited to FIG. 8 and may include more or fewer components than those shown in FIG. 8. According to some embodiments, the transceiver (820), processor (810), memory (830), and eUICC may be implemented in the form of a single chip. Additionally, the processor (820) may be configured as at least one processor.
[0193] A method according to one embodiment of the present disclosure may include: receiving information from an eUICC at a terminal regarding whether the profile supports ES; and determining at the terminal whether to move part or all of the profile outside the eUICC based on the information regarding whether the profile supports ES.
[0194] According to various embodiments, the transceiver (820) may transmit and receive signals, information, data, etc. according to various embodiments of the present disclosure with the transceiver of another terminal or an external server. The transceiver (820) may be composed of an RF transmitter that up-converts and amplifies the frequency of a transmitted signal, and an RF receiver that low-noise amplifies a received signal and down-converts the frequency. However, this is merely one embodiment of the transceiver (820), and the components of the transceiver (820) are not limited to an RF transmitter and an RF receiver. Additionally, the transceiver (820) may receive a signal through a wireless channel and output it to a processor (810), and transmit the signal output from the processor (810) through a wireless channel.
[0195] Meanwhile, the processor (810) is a component for controlling the terminal overall. The processor (810) can control the overall operation of the terminal according to various embodiments of the present disclosure as described above. The processor (810) may include the LPA shown in FIG. 1 as a control application of the eUICC.
[0196] Meanwhile, the terminal may further include memory (830) and may store data such as basic programs, application programs, and setting information for the operation of the terminal. Additionally, the memory (830) may include at least one storage medium among Flash Memory Type, Hard Disk Type, Multimedia Card Micro Type, card type memory (e.g., SD or XD memory, etc.), magnetic memory, magnetic disk, optical disk, RAM (Random Access Memory), SRAM (Static Random Access Memory), ROM (Read-Only Memory), PROM (Programmable Read-Only Memory), and EEPROM (Electrically Erasable Programmable Read-Only Memory). Additionally, the memory may include chip or card-type memory such as an eUICC or embedded Secure Element installed in the terminal, in addition to the eUICC on which the profile to be extracted is installed.
[0197] Additionally, the processor (810) can perform various operations using various programs, content, data, etc. stored in the memory (830). As previously described in FIG. 1, the memory (830) is connected to the LPA and can store profile data extracted by the LPA from the eUICC or provide it when requested by the LPA.
[0198] The eUICC (not shown) may include a transceiver, a processor, and memory. The processor of the eUICC may include an ISD-R application. The ISD-R may exist as a system application of the eUICC (e.g., as part of the OS or as a system application existing on top of the OS). The ISD-R receives commands received from the LPA through the transceiver and interprets the received commands to perform profile management operations on the eUICC, such as installing, deleting, or moving profiles.
[0199] The eUICC processor can perform at least one of the operations mentioned below.
[0200] The processor of the eUICC can perform the role of receiving the processing result from the eUICC and sending it back to the LPA through the transmission and reception unit. In addition, the processor of the eUICC can obtain the profile status information and profile authorization information (at least one of whether movement is supported and whether partition storage is supported) from the profile metadata and store them in memory (830), and when receiving information about the profile status from the LPA, it can obtain it and send it back to the LPA.
[0201] In addition, the eUICC processor can distinguish between profile data that must be left in the eUICC and profile data that is allowed to be moved.
[0202] In addition, the eUICC processor can generate a profile package to move and configure a message including the profile package to move.
[0203] In addition, the eUICC processor may determine whether to transfer the file package to be moved to the memory inside the terminal connected to the LPA or eUICC by referring to the settings for the memory storage entity when ES is supported.
[0204] In addition, the eUICC may store at least one of the profile status information, profile estimated capacity, profile ES support status, profile partition storage request status, partition storage request list, eUICC ES support status, and eUICC ES support setting information as metadata information of the profile and part or additional information of the metadata in the memory of the eUICC, and the processor may access the memory and obtain one of the above-described information and use it as a predetermined information necessary to perform at least one operation such as profile movement processing or deletion processing.
[0205] FIG. 9 is a drawing illustrating the configuration of a server according to one embodiment of the present disclosure.
[0206] Referring to FIG. 9, the server may include a transceiver (920), a processor (910), and a memory (930). The servers described above in the present disclosure may each correspond to the server described in FIG. 9. For example, the servers described above in FIG. 1, FIG. 3, and FIG. 4 (e.g., operator server, RSP server, SM-DP+, or SM-DS) may each include the configuration of the server described in FIG. 9.
[0207] However, the configuration of the server is not limited to FIG. 9 and may include more or fewer components than those shown in FIG. 9. According to some embodiments, the transceiver (920), the processor (910), and the memory (930) may be implemented in the form of a single chip. Additionally, the processor (910) may be configured as at least one processor.
[0208] According to some embodiments, the transceiver (920) can transmit and receive signals, information, data, etc., according to various embodiments of the present disclosure with the terminal. The transceiver (920) may be composed of an RF transmitter that up-converts and amplifies the frequency of a transmitted signal, and an RF receiver that low-noise amplifies a received signal and down-converts the frequency. However, this is merely one embodiment of the transceiver (920), and the components of the transceiver (920) are not limited to an RF transmitter and an RF receiver. Additionally, the transceiver (920) can receive a signal through a wireless channel and output it to a processor (910), and transmit the signal output from the processor (910) through a wireless channel.
[0209] Meanwhile, at least one processor (910) is a component for controlling the server overall. The processor (910) can control the overall operation of the server according to various embodiments of the present disclosure as described above. The at least one processor (910) may be referred to as a control unit.
[0210] Meanwhile, the server may further include memory (930) and may store data such as basic programs for the operation of the server, application programs, and configuration information for ES support. Additionally, the memory (930) may include at least one storage medium among Flash Memory Type, Hard Disk Type, Multimedia Card Micro Type, Card Type Memory (e.g., SD or XD memory, etc.), Magnetic Memory, Magnetic Disk, Optical Disk, RAM (Random Access Memory), SRAM (Static Random Access Memory), ROM (Read-Only Memory), PROM (Programmable Read-Only Memory), and EEPROM (Electrically Erasable Programmable Read-Only Memory). Additionally, the processor (910) may perform various operations using various programs, content, data, etc. stored in the memory.
[0211] The server may perform at least one of the actions mentioned below.
[0212] The server receives one or more messages for profile installation through the transmitting and receiving unit (920) and transmits them to the processor (910), and the processor (910) can verify the eUICC signature. The server can perform the role of delivering the verification results to the operator.
[0213] Additionally, the processor (910) of the server can check whether there is an "ES support" identifier in the eUICC information (e.g., eUICCInfo2) as eUICC information included in the message received from the terminal for mutual authentication, for example, AuthenticateClient. The processor (910) can additionally check whether information regarding the partition storage request for ES support is included, and can determine the metadata configuration by referring to the configuration information for ES support set in the profile server or applied to the corresponding profile of the telecommunications carrier, and can send the configured profile metadata back to the terminal through the transmission / reception unit (920).
[0214] Additionally, the server processor (910) may store session identification information and encryption keys for session creation in memory (930). Additionally, the server may perform the operation of signing at least one of the messages transmitted by the profile server with the server's encryption key and transmitting it to the terminal through the transmission / reception unit (920) as a message containing the profile server's signature.
[0215] Additionally, the server (e.g., a carrier server or a profile server in the previously described embodiment) receives one or more messages for updating the metadata of the profile from the carrier through the transmitting and receiving unit (920), and the processor (910) of the server can process the received update data by transmitting it to the memory (930) of the server to update the metadata of the profile in the memory (930).
[0216] Additionally, the server processor (910) can construct and transmit a metadata update request message for the corresponding profile to the terminal through the server's transmission and reception unit, receive a processing result from the terminal, and provide the processing result to the communication operator of the corresponding profile.
[0217] In the specific embodiments of the present disclosure described above, the components included in the disclosure are expressed in a singular or plural form according to the specific embodiments presented. However, the singular or plural expression is selected to suit the situation presented for convenience of explanation, and the present disclosure is not limited to singular or plural components; even if a component is expressed in the plural form, it may be composed of a singular form, and even if a component is expressed in the singular form, it may be composed of a plural form.
[0218] Meanwhile, although specific embodiments have been described in the detailed description of the present disclosure, it is understood that various modifications are possible within the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be defined by the claims set forth below as well as equivalents thereof.
[0219] The various embodiments of the present disclosure and the terms used therein are not intended to limit the technology described in the present disclosure to specific embodiments and should be understood to include various modifications, equivalents, and / or substitutions of said embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar components. A singular expression may include a plural expression unless the context clearly indicates otherwise. In the present disclosure, expressions such as "A or B," "at least one of A and / or B," "A, B or C," or "at least one of A, B and / or C" may include all possible combinations of items listed together. Expressions such as "first," "second," "first," or "second" may modify said components regardless of order or importance and are used only to distinguish one component from another and do not limit said components. When it is mentioned that a certain (e.g., 1st) component is "(functionally or telecommunicationally) connected" or "connected" to another (e.g., 2nd) component, said certain component may be directly connected to said other component or connected through another component (e.g., 3rd component).
[0220] As used in this disclosure, the term "module" includes a unit composed of hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be a component formed integrally, or a minimum unit or part thereof that performs one or more functions. For example, a module may be composed of an application-specific integrated circuit (ASIC).
[0221] Various embodiments of the present disclosure may be implemented as software (e.g., a program) comprising instructions stored in a machine-readable storage medium (e.g., internal memory or external memory) that is readable by a machine (e.g., a computer). The machine may include a terminal according to various embodiments, which is a device capable of calling instructions stored from the storage medium and operating according to the called instructions. When the instructions are executed by a processor, the processor may perform a function corresponding to the instructions directly or by using other components under the control of the processor. The instructions may include code generated or executed by a compiler or an interpreter.
[0222] A device-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' means merely that the storage medium does not contain a signal and is tangible, without distinguishing whether data is stored semi-permanently or temporarily on the storage medium.
[0223] Methods according to the various embodiments disclosed herein may be provided as included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed online in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or through an application store (e.g., Play Store™). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created in a storage medium such as the memory of a manufacturer's server, an application store's server, or a relay server. Each component (e.g., a module or program) according to the various embodiments may be composed of a singular or multiple entities, and some of the aforementioned sub-components may be omitted, or other sub-components may be further included in the various embodiments. Generally or additionally, some components (e.g., a module or program) may be integrated into a single entity to perform the same or similar functions as those performed by each of the respective components prior to integration. Operations performed by a module, program, or other component according to various embodiments may be executed sequentially, in parallel, iteratively, or heuristically, or at least some operations may be executed in a different order, omitted, or other operations may be added.
Claims
In a method performed by a terminal of a wireless communication system, A step of receiving eUICC information from an eUICC (embedded universal integrated circuit card) regarding whether the eUICC supports external storage (ES); A step of transmitting the above eUICC information to a profile server; A step of receiving profile information from the profile server based on the received eUICC information; and A method comprising the step of determining whether to move part or all of the profile outside the eUICC based on the profile information. In paragraph 1, A method characterized in that the step of receiving the above profile information is performed when the profile server allows the download of the above profile based on the eUICC information. In paragraph 1, A method characterized by the above-mentioned determining step including, based on information regarding whether the profile supports ES included in the profile information, determining whether the profile is displayed as a profile that can be moved outside the eUICC. In paragraph 1, A method characterized in that the above eUICC information includes an identifier indicating whether the above eUICC supports ES. In paragraph 4, A method characterized in that the above eUICC information further includes information regarding whether split storage is supported for storing a portion of the profile in the eUICC. In paragraph 1, A method characterized in that the above profile information further includes setting information indicating whether the above profile supports ES. In paragraph 6, A method characterized in that the above profile information further includes partition storage request information requiring that a part of the above profile be left in the eUICC. In paragraph 1, A step of requesting the movement of the above profile to the eUICC; and A method further comprising the step of receiving an External Storage Profile Package (ESPP) from the above eUICC, wherein, if the profile information includes partition storage request information, the file identified by the partition storage request information is excluded. In a terminal of a wireless communication system, At least one transmitting and receiving unit; At least one processor connected to communicate with the above-mentioned at least one transmitting and receiving unit; and It includes one or more memories that are communicatably connected to the at least one processor and store instructions that can be executed individually or in any combination by the at least one processor. The above commands are the above terminal: Receive eUICC information regarding whether the eUICC supports external storage (ES) from the eUICC (embedded universal integrated circuit card), and The above eUICC information is transmitted to the profile server, and From the above profile server, based on the received eUICC information, profile information is received, and A terminal that determines whether to move part or all of the profile outside the eUICC based on the above profile information. In Paragraph 9, A terminal that allows the above commands to be executed when the receiving of the above profile information is performed when the profile server allows the download of the above profile based on the eUICC information. In Paragraph 9, A terminal, wherein the above commands include determining whether to display the profile as a profile that can be moved outside the eUICC, based on information regarding whether the profile supports ES included in the profile information. In Paragraph 9, A terminal characterized in that the above eUICC information includes an identifier indicating whether the eUICC supports ES. In Paragraph 12, A terminal characterized in that the above eUICC information further includes information regarding whether split storage is supported, which stores a portion of the above profile in the eUICC. In paragraph 1, A terminal characterized in that the above profile information further includes setting information indicating whether the above profile supports ES and split storage request information requiring that a part of the above profile be left in the eUICC. In paragraph 1, The above commands are the above terminal: Request the movement of the above profile to the above eUICC, and A terminal that receives an External Storage Profile Package (ESPP) from the above eUICC, wherein, if the profile information includes partition storage request information, the file identified by the partition storage request information is excluded.