Method and device by which esim device and profile server negotiate post-quantum cryptography algorithm in wireless communication system
Post-Quantum Cryptography algorithms secure remote SIM provisioning via eUICC cards against quantum threats, ensuring robust communication security for eSIM operations.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- SAMSUNG ELECTRONICS CO LTD
- Filing Date
- 2026-01-26
- Publication Date
- 2026-07-30
AI Technical Summary
The increasing threat of quantum computing poses a risk to the security of remote SIM provision operations via eSIM, as malicious attackers can decrypt encrypted information and steal user profiles and network security keys, necessitating enhanced security measures.
Implementing Post-Quantum Cryptography (PQC) algorithms, such as multivariate-based, code-based, lattice-based, isogeny-based, and hash-based cryptographic systems, to secure remote SIM provisioning through eUICC cards, ensuring communication security against quantum attacks.
Enhances the security of remote SIM operations by making them resistant to quantum decryption, protecting user profiles and network security keys from unauthorized access.
Smart Images

Figure KR2026001467_30072026_PF_FP_ABST
Abstract
Description
Method and apparatus for an ESIM device and a profile server to negotiate a quantum-resistant cryptographic algorithm in a wireless communication system
[0001] The present disclosure relates to a terminal and a profile server in a wireless communication system. Specifically, the present disclosure relates to a method and apparatus for installing and managing an eUICC (embedded universal integrated circuit card) profile in a wireless communication system.
[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in frequency bands below 6 GHz ('Sub 6 GHz'), such as 3.5 gigahertz (3.5 GHz), but also in ultra-high frequency bands called millimeter waves (mmWave), such as 28 GHz and 39 GHz ('Above 6 GHz'). In addition, for 6G mobile communication technology, which is referred to as a system beyond 5G, implementation in the terahertz band (e.g., the 3 terahertz (3 THz) band at 95 GHz) is being considered to achieve transmission speeds 50 times faster and ultra-low latency reduced to one-tenth compared to 5G mobile communication technology.
[0003] In the early stages of 5G mobile communication technology, aiming to satisfy service support and performance requirements for enhanced Mobile BroadBand (eMBB), Ultra-Reliable Low-Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), technologies such as beamforming and Massive MIMO to mitigate path loss and increase transmission distance in ultra-high frequency bands, support for various numerologies (such as the operation of multiple subcarrier spacings) and dynamic operation of slot formats for the efficient utilization of ultra-high frequency resources, initial access techniques to support multi-beam transmission and broadband, definition and operation of Band-Width Parts (BWP), Low Density Parity Check (LDPC) codes for high-volume data transmission, new channel coding methods such as Polar Codes for the reliable transmission of control information, and L2 pre-processing (L2 Standardization has been carried out for pre-processing, network slicing which provides a dedicated network specialized for specific services, and other methods.
[0004] Currently, discussions are underway to improve and enhance the performance of the initial 5G mobile communication technology, taking into account the services that the 5G mobile communication technology was intended to support. Additionally, standardization of the physical layer is in progress for technologies such as V2X (Vehicle-to-Everything), which helps autonomous vehicles make driving decisions and enhance user convenience based on their own location and status information transmitted by the vehicle; NR-U (New Radio Unlicensed), which aims for system operation in unlicensed bands to comply with various regulatory requirements; NR terminal low power consumption technology (UE Power Saving); Non-Terrestrial Network (NTN), which is direct terminal-satellite communication for securing coverage in areas where communication with the terrestrial network is impossible; and positioning.
[0005] In addition, standardization is underway in the field of wireless interface architecture / protocols for technologies such as the Industrial Internet of Things (IIoT) for supporting new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) which provides nodes for expanding network service areas by integrating wireless backhaul links and access links, Mobility Enhancement including Conditional Handover and Dual Active Protocol Stack (DAPS) Handover, and 2-step Random Access (2-step RACH for NR) which simplifies random access procedures. Standardization is also underway in the field of system architecture / services for 5G baseline architectures (e.g., Service based Architecture, Service based Interface) for incorporating Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC), which provides services based on the location of the terminal.
[0006] When such 5G mobile communication systems are commercialized, connected devices, which are increasing explosively, will be connected to communication networks. Accordingly, it is expected that there will be a need to enhance the functionality and performance of 5G mobile communication systems and to integrate the operation of connected devices. To this end, new research is planned to be conducted on 5G performance improvement and complexity reduction, support for AI services, support for metaverse services, and drone communication using eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).
[0007] Furthermore, the advancement of these 5G mobile communication systems encompasses multi-antenna transmission technologies such as new waveforms to guarantee coverage in the terahertz band of 6G mobile communication technology, Full Dimensional MIMO (FD-MIMO), array antennas, and large-scale antennas; metamaterial-based lenses and antennas to improve terahertz band signal coverage; high-dimensional spatial multiplexing technology using OAM (Orbital Angular Momentum); and Reconfigurable Intelligent Surface (RIS) technology; as well as Full Duplex technology for enhancing frequency efficiency and system networks in 6G mobile communication technology; AI-based communication technologies that realize system optimization by utilizing satellites and AI from the design stage and internalizing end-to-end AI support functions; and the realization of services of complexity exceeding the limits of terminal computing capabilities by utilizing ultra-high-performance communication and computing resources. It could serve as a foundation for the development of next-generation distributed computing technologies.
[0008] The present disclosure may provide an apparatus and a method capable of effectively providing services in a mobile communication (or wireless communication) system.
[0009] The technical problems to be solved in this disclosure are not limited to those mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art to which this disclosure belongs from the description below.
[0010] A method performed by a terminal (user equipment) according to one embodiment of the present disclosure may include: establishing a transport layer security (TLS) connection with a profile server; transmitting to the profile server, via an authentication start request message, first eUICC information including first key setting algorithm information supported by the eUICC (embedded universal integrated circuit card) of the terminal, for initiating mutual authentication between the terminal and the profile server; receiving from the profile server an authentication start response message including information on at least one key setting algorithm selected within the first key setting algorithm information; transmitting to the profile server, via a client verification request message, second eUICC information including the eUICC signature of the terminal and second key setting algorithm information supported by the eUICC of the terminal; and receiving from the profile server a response based on a verification result regarding whether the first key setting algorithm information within the first eUICC information and the second key setting algorithm information within the second eUICC information match.
[0011] A method performed by a profile server according to one embodiment of the present disclosure may include: establishing a transport layer security (TLS) connection with a terminal (user equipment); receiving from the terminal, via an authentication start request message for initiating mutual authentication between the terminal and the profile server, first eUICC information including first key setting algorithm information supported by the terminal's eUICC (embedded universal integrated circuit card); transmitting to the terminal an authentication start response message including information on at least one key setting algorithm selected within the first key setting algorithm information; receiving from the terminal, via a client verification request message, second eUICC information including the terminal's eUICC signature and second key setting algorithm information supported by the terminal's eUICC; and transmitting to the terminal a response based on a verification result regarding whether the first key setting algorithm information within the first eUICC information and the second key setting algorithm information within the second eUICC information match.
[0012] A terminal (user equipment) according to one embodiment of the present disclosure comprises at least one transceiver, at least one processor communicatively coupled to the at least one transceiver, and at least one memory communicatively coupled to the at least one processor for storing instructions, wherein the instructions are executed individually or in any combination by the at least one processor, and the terminal establishes a transport layer security (TLS) connection with a profile server, transmits to the profile server, via an authentication start request message for initiating mutual authentication between the terminal and the profile server, first eUICC information including first key setting algorithm information supported by the eUICC (embedded universal integrated circuit card) of the terminal, and receives from the profile server an authentication start response message including information on at least one key setting algorithm selected within the first key setting algorithm information, and transmits to the profile server an eUICC signature of the terminal and second key setting algorithm information supported by the eUICC of the terminal The second eUICC information can be transmitted via a client verification request message, and a response can be received from the profile server regarding the verification result of whether the first key setting algorithm information in the first eUICC information and the second key setting algorithm information in the second eUICC information match.
[0013] A profile server according to one embodiment of the present disclosure comprises at least one transceiver, at least one processor communicatively coupled to the at least one transceiver, and at least one memory communicatively coupled to the at least one processor for storing instructions, wherein the instructions are executed individually or in any combination by the at least one processor, and the profile server establishes a transport layer security (TLS) connection with a terminal (user equipment), receives from the terminal, through an authentication start request message for initiating mutual authentication between the terminal and the profile server, first eUICC information including first key setting algorithm information supported by the terminal's eUICC (embedded universal integrated circuit card), and transmits to the terminal an authentication start response message including information on at least one key setting algorithm selected within the first key setting algorithm information, and receives from the terminal a second key setting algorithm including the terminal's eUICC signature and second key setting algorithm information supported by the terminal's eUICC. eUICC information can be received via a client verification request message, and the terminal can be configured to transmit a response based on the verification result regarding whether the first key setting algorithm information within the first eUICC information and the second key setting algorithm information within the second eUICC information match.
[0014] The present disclosure can provide an apparatus and a method capable of effectively providing services in a wireless communication system.
[0015] The effects obtainable from the present disclosure are not limited to those mentioned above, and other unmentioned effects will be clearly understood by those skilled in the art to which the present disclosure belongs from the description below.
[0016] FIG. 1 illustrates a method for a terminal to connect to a mobile communication network using a UICC equipped with a fixed profile according to one embodiment of the present disclosure.
[0017] FIG. 2 illustrates an example of a connection between a terminal, an activation intermediary server, a profile providing server, and a service provider according to one embodiment of the present disclosure.
[0018] FIG. 3 illustrates a flowchart of a procedure for a terminal to perform function negotiation with a profile server to download a profile according to one embodiment of the present disclosure.
[0019] FIG. 4 illustrates a flowchart of a procedure for a terminal to perform function negotiation with a profile server to download a profile according to one embodiment of the present disclosure.
[0020] FIG. 5 illustrates a flowchart of a procedure for a terminal to perform function negotiation with a profile server to download a profile according to one embodiment of the present disclosure.
[0021] FIG. 6 illustrates the functional configuration of a terminal according to one embodiment of the present disclosure.
[0022] FIG. 7 illustrates the functional configuration of a profile server according to one embodiment of the present disclosure.
[0023] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.
[0024] In describing the embodiments, technical details that are well known in the technical field to which this disclosure belongs and are not directly related to this disclosure are omitted. This is intended to convey the essence of this disclosure more clearly without obscuring it by omitting unnecessary explanations.
[0025] For the same reason, some components in the attached drawings have been exaggerated, omitted, or schematically depicted. Additionally, the size of each component does not entirely reflect its actual dimensions. Identical or corresponding components in each drawing have been assigned the same reference numbers.
[0026] The advantages and features of the present disclosure and the methods for achieving them will become clear by referring to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below but may be implemented in various different forms. The embodiments provided are merely to ensure that the disclosure is complete and to fully inform those skilled in the art of the scope of the disclosure, and the disclosure is defined only by the scope of the claims. Throughout the disclosure, the same reference numerals refer to the same components.
[0027] At this point, it will be understood that each block of the process flow diagrams and combinations of the flow diagrams can be executed by computer program instructions. Since these computer program instructions can be loaded into the processor of a general-purpose computer, a computer for special purposes, or other programmable data processing equipment, the instructions executed through the processor of the computer or other programmable data processing equipment create means to perform the functions described in the flow diagram block(s). Since these computer program instructions can also be stored on a computer-available or computer-readable storage medium that can be oriented toward the computer or other programmable data processing equipment to implement the function in a specific way, the instructions stored on the computer-available or computer-readable storage medium can also produce a manufactured item containing means of instruction to perform the function described in the flow diagram block(s). Since computer program instructions can be loaded onto a computer or other programmable data processing equipment, instructions that perform a series of operation steps on the computer or other programmable data processing equipment to create a process executed by the computer can also provide steps for executing the functions described in the flowchart block(s).
[0028] Additionally, each block may represent a module, segment, or part of code containing one or more executable instructions for executing a specified logical function(s). It should also be noted that in some alternative execution examples, the functions mentioned in the blocks may occur out of order. For instance, two blocks described in succession may actually be executed substantially simultaneously, or the blocks may be executed in reverse order according to their corresponding functions.
[0029] In this embodiment, the term "part" refers to a software or hardware component, such as an FPGA or ASIC, and the "part" performs certain roles. However, the meaning of "part" is not limited to software or hardware. The "part" may be configured to reside in an addressable storage medium or configured to operate one or more processors. Accordingly, as an example, the "part" includes components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and "parts" may be combined into a smaller number of components and "parts" or further separated into additional components and "parts." Furthermore, the components and "parts" may be implemented to operate one or more CPUs within a device or secure multimedia card.
[0030] With the advancement of mobile communication systems, it has become possible to provide various services, and thus measures to effectively provide the aforementioned services are required.
[0031] A UICC (Universal Integrated Circuit Card) is a smart card inserted into devices such as mobile communication terminals, and is also referred to as a UICC card. A UICC may include a connection control module for the terminal to connect to a mobile carrier's network. Examples of such connection control modules include the USIM (Universal Subscriber Identity Module), SIM (Subscriber Identity Module), and ISIM (IP Multimedia Service Identity Module). A UICC containing a USIM is commonly referred to as a USIM card. Similarly, a UICC containing a SIM module is commonly referred to as a SIM card.
[0032] Among UICC cards, those fixed to a terminal are called eUICC (embedded UICC). Typically, an eUICC refers to a UICC card that is fixed to a terminal and allows for the remote download and selection of a SIM module. Additionally, the downloaded SIM module information is collectively referred to as an eUICC profile, or more simply, a profile.
[0033] Post-Quantum Cryptography (PQC) is an asymmetric key-based encryption technology utilizing public-private key pairs, designed to replace existing cryptographic systems that are susceptible to decryption by quantum computers and specific algorithms. Consequently, it is attracting attention as a new cryptographic system because it is expected to remain undecipherable within polynomial time by quantum computers, which demonstrate superior performance in integer-based problems. Types of PQC include multivariate-based, code-based, lattice-based, isogeny-based, and hash-based cryptographic algorithms.
[0034] Due to advancements in quantum computing technology, the risk has increased where malicious attackers can eavesdrop on communications between terminals and profile servers, decrypt encrypted information, and steal user profiles and network security keys. To effectively counter these threats, it is necessary to enhance the security of remote SIM provision operations via eSIM.
[0035] The present disclosure aims to provide a method and apparatus for a terminal in a communication system to select a communication service and connect to a network.
[0036] In addition, the present disclosure aims to provide a method and apparatus for a terminal in a communication system to download, install, and manage a profile online for connecting to a network.
[0037] Specific terms used in the following description are provided to aid in understanding the present disclosure, and the use of such specific terms may be modified in other forms without departing from the technical spirit of the present disclosure.
[0038] In the present disclosure, the UICC (Universal Integrated Circuit Card) is a smart card used by inserting it into a mobile communication terminal, etc., and may also be referred to as a UICC card.
[0039] UICC may refer to a chip that stores personal information such as network access authentication information, phonebooks, and SMS (Short Message Service) of mobile communication subscribers, and enables secure mobile communication by performing subscriber authentication and traffic security key generation when connecting to mobile communication networks such as GSM (Global System for Mobile Communication), WCDMA (Wideband Code Division Multiple Access), LTE (Long Term Evolution) / NR (New Radio).
[0040] The UICC may include communication applications or access control modules for the terminal to connect to a mobile carrier's network. Examples of such communication applications or access control modules may include USIM (Universal Subscriber Identity Module), SIM (Subscriber Identity Module), and ISIM (IP Multimedia Service Identity Module). Additionally, the UICC may provide high-level security functions for the installation of various applications, such as electronic wallets, ticketing, and electronic passports.
[0041] A UICC containing a USIM is commonly referred to as a USIM card. Similarly, a UICC containing a SIM module is commonly referred to as a SIM card.
[0042] In this disclosure, "SIM card," "UICC card," "USIM card," and "UICC including ISIM" may be used interchangeably. For example, the contents of this disclosure may apply equally to SIM cards, USIM cards, ISIM cards, or general UICC cards.
[0043] SIM cards store the personal information of mobile subscribers and enable secure mobile communication by performing subscriber authentication and generating traffic security keys when connecting to a mobile communication network.
[0044] Generally, SIM cards are manufactured as dedicated cards for specific mobile carriers at the request of those carriers. Authentication information for accessing the carrier's network, such as the USIM (Universal Subscriber Identity Module) application, IMSI (International Mobile Subscriber Identity), K value, and OPc value, may be pre-loaded onto the card before shipment. Consequently, the mobile carrier receives the SIM card and provides it to subscribers; subsequently, if necessary, they can utilize technologies such as OTA (Over The Air) to manage the installation, modification, and deletion of applications within the UICC. Subscribers can use the carrier's network and application services by inserting the UICC card into their mobile devices. Furthermore, when replacing devices, the authentication information, mobile phone numbers, and personal contact lists stored on the UICC card can be transferred from the old device to the new one, allowing the new device to use the same information.
[0045] However, SIM cards present an inconvenience for mobile device users seeking services from other mobile carriers. Users face the inconvenience of having to physically acquire a SIM card to receive services from a mobile carrier. For example, when traveling to another country, users face the inconvenience of having to obtain a local SIM card to receive local mobile services. While roaming services alleviate this inconvenience to some extent, the rates are relatively high, and there is also the issue of being unable to receive service if there is no contract between the carriers.
[0046] Meanwhile, this inconvenience can be largely resolved by remotely downloading and installing a SIM module onto a UICC card. For example, a user can download the SIM module of the mobile communication service they wish to use onto the UICC card at a desired time. Such a UICC card can be used by downloading and installing multiple SIM modules and selecting only one of them. Such a UICC card may or may not be fixed to the terminal. In particular, a UICC that is fixed to the terminal is called an eUICC (embedded UICC); typically, eUICC refers to a UICC card that is fixed to the terminal and allows for the remote downloading and selection of a SIM module. In this disclosure, a UICC card that allows for the remote downloading and selection of a SIM module may be referred to as an eUICC. For example, among UICC cards that allow for the remote downloading and selection of a SIM module, a UICC card that is fixed to the terminal or not fixed may be collectively referred to as an eUICC. Furthermore, the downloaded SIM module information may be collectively referred to as an eUICC profile, or more simply, a profile.
[0047] In the present disclosure, the eUICC may be a security module in the form of a chip embedded in the terminal, rather than a detachable type that can be inserted into and removed from the terminal. Typically, the eUICC may be used by being fixed to the terminal. Meanwhile, the eUICC can download and install a profile using OTA technology. The eUICC may be referred to as a UICC capable of downloading and installing a profile.
[0048] The method of downloading and installing a profile on an eUICC using OTA technology in the present disclosure may also be applied to a detachable UICC that can be inserted into and removed from a terminal. For example, the embodiments of the present disclosure may be applied to a UICC capable of downloading and installing a profile using OTA technology.
[0049] In the present disclosure, "UICC" may be used interchangeably with "SIM", and "eUICC" may be used interchangeably with "embedded SIM (eSIM)".
[0050] In the present disclosure, "Profile" may refer to an application, file system, authentication key value, etc. stored within the UICC packaged in the form of software.
[0051] In the present disclosure, "USIM Profile" may have the same meaning as "profile" or may mean information included in a USIM application within the profile packaged in the form of software.
[0052] In the present disclosure, the operation of enabling a profile by a terminal may mean an operation of changing the state of the profile to an enabled state so that the terminal can receive communication services through the telecommunications carrier that provided the profile. A profile in an enabled state may be expressed as an "enabled profile."
[0053] In the present disclosure, the operation of a terminal disabling a profile may mean an operation of changing the state of the profile to a disabled state so that the terminal cannot receive communication services through the telecommunications carrier that provided the profile. A profile in a disabled state may be expressed as a "disabled profile."
[0054] In the present disclosure, the operation of a terminal deleting a profile may mean an operation of changing the status of the profile to a deleted state so that the terminal can no longer activate or deactivate the profile. A profile in a deleted state may be expressed as a "deleted profile."
[0055] In the present disclosure, the operation of enabling, disabling, or deleting a profile by a terminal may mean an operation in which, without immediately changing the state of each profile to an enabled, disabled, or deleted state, each profile is first marked as to be enabled, to be disabled, or to be deleted, and then the terminal or the terminal’s UICC changes each profile to an enabled, disabled, or deleted state after performing a specific operation (e.g., the execution of a refresh or reset command). The action of marking a specific profile as a scheduled state (e.g., to be enabled, to be disabled, or to be deleted) is not necessarily limited to marking one scheduled state for a single profile; it is also possible to mark one or more profiles as having the same or different scheduled states, mark one profile as having one or more scheduled states, or mark one or more profiles as having one or more scheduled states.
[0056] Additionally, if the terminal displays one or more scheduled states for any profile, the two scheduled state indications may be combined into one. For example, if any profile is displayed as "to be disabled" and "to be deleted," the profile may be displayed as a combined "to be disabled and deleted" state.
[0057] Additionally, the operation of the terminal displaying a scheduled state for one or more profiles may be performed sequentially or simultaneously. Additionally, the operation of the terminal displaying a scheduled state for one or more profiles and subsequently changing the state of the actual profile may be performed sequentially or simultaneously.
[0058] In the present disclosure, the "profile providing server" may include functions for creating a profile, encrypting a created profile, creating a profile remote management command, or encrypting a created profile remote management command. The profile providing server may be represented as SM-DP (Subscription Manager Data Preparation), SM-DP+ (Subscription Manager Data Preparation plus), off-card entity of Profile Domain, profile encryption server, profile creation server, profile provisioner (PP), profile provider, and PPC (Profile Provisioning Credentials) holder.
[0059] In the present disclosure, the “profile management server” may include a function for managing profiles. The profile management server may be represented as SM-SR (Subscription Manager Secure Routing), SM-SR+ (Subscription Manager Secure Routing Plus), off-card entity of eUICC Profile Manager or PMC (Profile Management Credentials) holder, EM (eUICC Manager), PM (Profile Manager), etc.
[0060] In the present disclosure, the profile providing server may refer to a combination of the functions of a profile management server. Accordingly, in various embodiments of the present disclosure, the operation of the profile providing server may be performed on the profile management server. Likewise, the operation of the profile management server or SM-SR may be performed on the profile providing server.
[0061] In the present disclosure, the "activation intermediary server" may be represented as SM-DS (Subscription Manager Discovery Service), DS (Discovery Service), Root activation intermediary server (Root SM-DS), and Alternative activation intermediary server (Alternative SM-DS). An activation intermediary server may receive an Event Register Request (Event Register Request) from one or more profile providing servers or activation intermediary servers. Additionally, one or more activation intermediary servers may be used in combination, in which case the first activation intermediary server may receive an Event Register Request from a second activation intermediary server as well as a profile providing server.
[0062] In the present disclosure, the profile providing server and the activation brokerage server may be referred to as the 'RSP (Remote SIM Provisioning) server'. The RSP server may be represented as SM-XX (Subscription Manager XX).
[0063] In the present disclosure, the term "terminal" may be referred to as a Mobile Station (MS), User Equipment (UE), User Terminal (UT), wireless terminal, access terminal (AT), terminal, Subscriber Unit, Subscriber Station (SS), wireless device, wireless communication device, Wireless Transmit / Receive Unit (WTRU), mobile node, mobile, or other terms. In one embodiment, the terminal may include a cellular telephone, a smartphone having wireless communication capabilities, a personal handheld terminal (PDA) having wireless communication capabilities, a wireless modem, a portable computer having wireless communication capabilities, a shooting device such as a digital camera having wireless communication capabilities, a gaming device having wireless communication capabilities, a music storage and playback appliance having wireless communication capabilities, an internet appliance capable of wireless internet access and browsing, as well as portable units or terminals integrating combinations of such capabilities. Additionally, the terminal may include, but is not limited to, M2M (Machine to Machine) terminals and MTC (Machine Type Communication) terminals / devices. In this disclosure, the terminal may also be referred to as an electronic device.
[0064] In the present disclosure, the "electronic device" may have an embedded UICC that can be installed by downloading a profile. If the UICC is not embedded in the electronic device, a UICC that is physically separated from the electronic device may be inserted into the electronic device and connected to the electronic device. For example, the UICC may be inserted into the electronic device in the form of a card. The electronic device may include a terminal. In this case, the terminal may be a terminal that includes a UICC that can be installed by downloading a profile. Not only may the UICC be embedded in the terminal, but if the terminal and the UICC are separated, the UICC may be inserted into the terminal and connected to the terminal. A UICC that can be installed by downloading a profile may be referred to, for example, as an eUICC.
[0065] In the present disclosure, a terminal or electronic device may include software or an application installed within the terminal or electronic device to control a UICC or an eUICC. Software or an application installed within the terminal or electronic device to control a UICC or an eUICC may be referred to, for example, as a Local Profile Assistant (LPA).
[0066] In the present disclosure, "profile identifier" may be referred to as an argument matching a profile identifier (Profile ID), ICCID (Integrated Circuit Card ID), Matching ID, Event ID, Activation Code, Activation Code Token, Command Code, Command Code Token, Signed Command Code, Unsigned Command Code, ISD-P, or Profile Domain (PD). The profile identifier (Profile ID) may represent a unique identifier for each profile. The profile identifier may further include the address of a profile provider server (SM-DP+) capable of indexing profiles. Additionally, the profile identifier may further include the signature of the profile provider server (SM-DP+).
[0067] In the present disclosure, the "eUICC identifier (eUICC ID)" may be a unique identifier of the eUICC embedded in the terminal and may be referred to as an EID. Additionally, if a provisioning profile is pre-loaded on the eUICC, the eUICC identifier (eUICC ID) may be the identifier of the corresponding provisioning profile (Provisioning Profile's Profile ID). Furthermore, in one embodiment of the present disclosure, if the terminal and the eUICC chip are not separated, the eUICC identifier (eUICC ID) may be the terminal ID. Additionally, the eUICC identifier (eUICC ID) may refer to a specific secure domain of the eUICC chip.
[0068] In the present disclosure, "Profile Container" may be referred to as a Profile Domain. A Profile Container may be a Security Domain.
[0069] In the present disclosure, "APDU (application protocol data unit)" may be a message for a terminal to interact with an eUICC. Additionally, APDU may be a message for a PP (Profile Provider) or PM (Profile Manager) to interact with an eUICC.
[0070] In the present disclosure, "PPC (Profile Provisioning Credentials)" may be a means used for mutual authentication, profile encryption, and signing between a profile provisioning server and an eUICC. A PPC may include one or more of a symmetric key, an RSA (Rivest Shamir Adleman) certificate and private key, an ECC (elliptic curved cryptography) certificate and private key, a root certification authority (CA), and a certificate chain. Additionally, if there are multiple profile provisioning servers, different PPCs may be stored or used in the eUICC for each profile provisioning server.
[0071] In the present disclosure, "PMC (Profile Management Credentials)" may be a means used for mutual authentication, encryption of transmitted data, and signing between a profile management server and an eUICC. A PMC may include one or more of a symmetric key, an RSA certificate and private key, an ECC certificate and private key, a Root CA, and a certificate chain. Additionally, if there are multiple profile management servers, different PMCs may be stored or used in the eUICC for each profile management server.
[0072] In the present disclosure, "AID" may be an Application Identifier. This value may be a distinguisher that separates different applications within the eUICC.
[0073] In the present disclosure, "Event" may be a collective term for Profile Download, Remote Profile Management, or other management / processing commands for profiles or eUICCs. An Event may be named a Remote SIM Provisioning Operation (or RSP Operation) or an Event Record, and each Event may be referred to as data comprising at least one of the following: a corresponding Event Identifier (Event ID, EventID) or Matching Identifier (Matching ID, MatchingID), the address (FQDN, IP Address, or URL) of the Profile Provider Server (SM-DP+) or Activation Broker Server (SM-DS) where the event is stored, the signature of the Profile Provider Server (SM-DP+) or Activation Broker Server (SM-DS), and the digital certificate of the Profile Provider Server (SM-DP+) or Activation Broker Server (SM-DS).
[0074] Data corresponding to an Event may be referred to as a "Command Code." Part or all of the procedure utilizing the Command Code may be referred to as a "Command Code Processing Procedure," a "Command Code Procedure," or an "LPA API (Local Profile Assistant Application Programming Interface)." Profile Download may be used interchangeably with Profile Installation.
[0075] Additionally, "Event Type" may be used as a term indicating whether a specific event is a profile download, remote profile management (e.g., deletion, activation, deactivation, replacement, update, etc.), or other profile or eUICC management / processing commands, and may be named as Operation Type (or OperationType), Operation Class (or OperationClass), Event Request Type, Event Class, Event Request Class, etc. For any event identifier (EventID or MatchingID), the path through which the terminal obtained the event identifier (EventID or MatchingID) or the intended use (EventID Source or MatchingID Source) may be specified.
[0076] In this disclosure, "Profile Package" may be used interchangeably with "profile" or as a term representing a data object of a specific profile, and may be named Profile TLV or Profile Package TLV. If the profile package is encrypted using encryption parameters, it may be named Protected Profile Package (PPP) or Protected Profile Package TLV (PPP TLV). If the profile package is encrypted using encryption parameters that can be decrypted only by a specific eUICC, it may be named Bound Profile Package (BPP) or Bound Profile Package TLV (BPP TLV). A profile package TLV may be a data set representing information constituting a profile in the TLV(Tag, Length, Value) format.
[0077] In the present disclosure, "Local Profile Management (LPM)" may be referred to as Profile Local Management, Local Management, Local Management Command, Local Command, Local Profile Management Package, Profile Local Management Package, Local Management Package, Local Management Command Package, or Local Command Package. LPM may be used to change the status (Enabled, Disabled, Deleted) of a specific profile or to update the contents of a specific profile (e.g., Profile Nickname, Profile Metadata, etc.) through software installed on a terminal. LPM may include one or more local management commands, in which case the profiles targeted by each local management command may be the same or different for each local management command.
[0078] In the present disclosure, "Remote Profile Management (RPM)" may be referred to as Profile Remote Management, Remote Management, Remote Management Command, Remote Command, Remote Profile Management Package (RPM Package), Profile Remote Management Package, Remote Management Package, Remote Management Command Package, or Remote Command Package. An RPM may be used to change the status (Enabled, Disabled, Deleted) of a specific profile or to update the contents of a specific profile (e.g., Profile Nickname, Profile Metadata, etc.). An RPM may include one or more remote management commands, in which case the profiles targeted by each remote management command may be the same or different for each remote management command.
[0079] In the present disclosure, "Certificate" or "Digital Certificate" may refer to a digital certificate used for asymmetric key-based mutual authentication consisting of a pair of a public key (PK) and a secret key (SK). Each certificate may include one or more public keys (PK), a public key identifier (PKID) corresponding to each public key, a certificate issuer ID of the certificate issuer (CI) that issued the certificate, and a digital signature.
[0080] In addition, the "Certificate Issuer" may be referred to as the Certification Issuer, Certificate Authority (CA), or Certification Authority.
[0081] In the present disclosure, "Public Key (PK)" and "Public Key ID (PKID)" may be used interchangeably with the same meaning to refer to a specific public key or a certificate containing the said public key, or a part of a specific public key or a part of a certificate containing the said public key, or a result of an operation (e.g., hash) of a specific public key or a result of an operation (e.g., hash) of a certificate containing the said public key, or a result of an operation (e.g., hash) of a part of a specific public key or a result of an operation (e.g., hash) of a part of a certificate containing the said public key, or a storage space where data is stored.
[0082] In the present disclosure, when certificates issued by one Certificate Issuer (first certificates) are used to issue other certificates (second certificates), or when second certificates are used to issue third or higher certificates in a linked manner, the correlation of said certificates may be referred to as a Certificate Chain or Certificate Hierarchy, and in this case, the CI certificate used for the initial certificate issuance may be referred to as the Root of Certificate, top certificate, Root CI, Root CI Certificate, Root CA, Root CA Certificate, etc.
[0083] In this disclosure, "mobile operator" may refer to a business entity that provides telecommunication services to a terminal, and may collectively refer to the mobile operator's business supporting system (BSS), operational supporting system (OSS), point of sale terminal, and other IT systems. Furthermore, in this disclosure, "mobile operator" is not limited to representing a single specific business entity that provides telecommunication services, but may also be used as a term referring to a group or association or consortium of one or more business entities, or a representative representing said group or consortium. Additionally, in this disclosure, "mobile operator" may be named as an operator (OP, or Op.), a mobile network operator (MNO), a mobile virtual network operator (MVNO), a service provider (or SP), a profile owner (PO), etc., and each mobile operator may set or be assigned at least one name and / or unique identifier (OID). If a telecommunications business operator refers to a group or association of one or more business entities or an agency, the name or unique identifier of any group or association or agency may be a name or unique identifier shared by all business entities belonging to said group or association or all business entities cooperating with said agency.
[0084] In the present disclosure, "AKA" may represent Authentication and Key agreement and may represent an authentication algorithm for accessing 3GPP and 3GPP2 networks.
[0085] In the present disclosure, "K" may be a cryptographic key value stored in an eUICC used in an AKA authentication algorithm.
[0086] In the present disclosure, "OPC" may be a parameter value that can be stored in an eUICC used in an AKA authentication algorithm.
[0087] In the present disclosure, "NAA" is a Network Access Application, and may be an application such as a USIM or ISIM stored in a UICC for connecting to a network. NAA may be a network access module.
[0088] In this disclosure, the "indicator" may be used to indicate whether any function, setting, or operation is required or not, or to indicate the function, setting, or operation itself. Additionally, in this disclosure, the indicator may be expressed in various forms such as a string, an alphanumeric string, an operator indicating true or false (e.g., oolean - TRUE or FALSE), a bitmap, an array, or a flag, and other expressions having the same meaning may be used in combination.
[0089] Hereinafter, a method and apparatus for installing and managing an eUICC profile according to various embodiments of the present disclosure will be described in detail with reference to FIGS. 1 to 8.
[0090] FIG. 1 illustrates a method for connecting a terminal to a mobile communication network using a UICC equipped with a fixed profile on the terminal according to one embodiment of the present disclosure.
[0091] Referring to FIG. 1, a UICC (120) according to one embodiment may be inserted into a terminal (110). For example, the UICC (120) may be detachable, but is not limited thereto. For example, the UICC (120) may be pre-embedded in the terminal (110).
[0092] A fixed profile loaded in the UICC (120) may mean that the 'connection information' that allows access to a specific carrier is fixed. For example, the connection information may be an IMSI that is a subscriber identifier and a K or Ki value that is required to authenticate to the network along with the subscriber identifier.
[0093] According to various embodiments of the present disclosure, the terminal (110) may perform authentication with the authentication processing system of a mobile carrier using the UICC (120). The authentication processing system of the mobile carrier may include a home location register (HLR) or an AuC, but is not limited thereto.
[0094] According to one embodiment, the authentication process of a terminal (110) using a UICC (120) may include an AKA (Authentication and Key Agreement) process.
[0095] According to one embodiment, when the terminal (110) succeeds in authentication, it can use mobile communication services such as telephone or mobile data usage by using the mobile carrier network (130) of the mobile communication system.
[0096] FIG. 2 illustrates an example of a connection between a terminal, an activation intermediary server, a profile providing server, and a service provider according to one embodiment of the present disclosure.
[0097] Referring to FIG. 2, an eUICC (211) may be installed in the terminal (210). A profile may be installed in the eUICC (211). Additionally, an LPA (212) may be installed in the terminal (210). The eUICC (211) may be controlled by the LPA (212). A user (200) can install a profile in the eUICC (211) of each terminal or control the installed profile through the LPA (212).
[0098] According to one embodiment, a profile of a carrier (240) may be installed on a terminal (210). As a result, the user (end user) (200) of the terminal (210) may receive communication services from a service provider (hereinafter referred to as "communication carrier" or "carrier", 240).
[0099] According to one embodiment, the operator (240) may be connected to the profile server (230). Additionally, the LPA (212) of the terminal (210) may be connected to the profile server (230) and the activation intermediary server (220). In FIG. 2, for convenience of explanation, the profile server (230) and the activation intermediary server (220) are each configured as a single server, but the specific implementation method of the profile server (230) and the activation intermediary server (220) is not limited to the example illustrated in FIG. 2. For example, depending on the implementation and embodiment, one or more profile servers (SM-DP+) may be included in the server configuration, and one or more activation intermediary servers (SM-DS) that assist in creating a connection between a specific profile server and a terminal may be included in the server configuration. With this in mind, various server configurations may be referred to as a “single profile server” in the present disclosure below.
[0100] The operation and message exchange procedures of the user (200), operator (240), terminal (210), eUICC (211), LPA (212), profile server (230), and activation intermediary server (220) according to various embodiments of the present disclosure will be described in detail with reference to the drawings to be described later.
[0101] FIG. 3 illustrates a flowchart of a procedure for a terminal to perform function negotiation with a profile server to download a profile according to one embodiment of the present disclosure.
[0102] In FIG. 3, a procedure is illustrated in which a terminal (310) performs a mutual authentication process with a profile server (330) and provides at least one post-quantum cryptography (PQC) function support information supported by the terminal (310) to the profile server (330), and the profile server (330) compares the post-quantum cryptography support functions provided by the terminal (310) and, if there is a post-quantum cryptography related function that is commonly supported by the terminal (310) and itself, selects at least one and sends a reply to the terminal (310). Additionally, FIG. 3 illustrates a procedure in which a terminal (310) transmits information on the quantum-resistant encryption function it supports to a profile server (330) and an eUICC signature generated from the eUICC (not shown) of the terminal (310) to the profile server (330), compares the information on the quantum-resistant encryption function support received from the terminal (310), and the profile server (330) sends the comparison result back to the terminal (310).
[0103] The configuration of the terminal (310) and the profile server (330) in FIG. 3 can be understood in correspondence with the configuration of the profile server (330) described with reference to FIG. 2. For example, the terminal (310) and the profile server (330) shown in FIG. 3 may correspond to the terminal (210) and the profile server (230) of FIG. 2, respectively.
[0104] According to one embodiment, in step 3001, the LPA of the terminal (310) can establish a TLS (Transport Layer Security) connection with the profile server (330) that must be connected to for the transfer of the profile.
[0105] According to one embodiment, in step 3003, the terminal (310) may initiate a mutual authentication process with the profile server (330). Here, the mutual authentication may include certificate-based mutual authentication in which the eUICC (not shown) of the terminal (310) and the profile server (430) authenticate each other using an asymmetric key consisting of a pair of a public key (PK) and a secret key (SK). A request to initiate mutual authentication may be made by the terminal (310) to the profile server (330) using an ES9+.InitiateAuthentication message. The request to initiate mutual authentication may optionally include at least one of the information of the eUICC (euiccInfo1) or the information of the LPA (lpaRspCapability) installed on the terminal (310).
[0106] According to one embodiment, a mutual authentication start request may include at least one Post Quantum Cryptography (PQC) function support information supported by an eUICC installed in a terminal (310). For example, the Post Quantum Cryptography function support information may include at least one of an eUICC Post Quantum Cryptography support indicator (euiccPqcSupport) indicating that the eUICC provides a Post Quantum Cryptography function, or a Post Quantum Cryptography algorithm information (supportedPqcAlgo) supported by the eUICC.
[0107] According to one embodiment, the eUICC quantum-resistant encryption support indicator may include an eUICC quantum-resistant encryption key establishment support indicator (euiccPqcKeyEstablishmentSupport or pqcKeyEstablishmentSupport) indicating that it supports a key establishment function using quantum-resistant encryption. Additionally, the quantum-resistant encryption algorithm information supported by the eUICC may include quantum-resistant encryption key establishment algorithm information supported by the eUICC (supportedKeyEstablishmentMethods, supportedPqcKeyEstablishmentMethods, PqcKeyEstablishmentMethods, KeyEstablishmentMethods, PQCSupportedAlgo, supportedPqcAlgo, or supportedPqcKeyEstablishmentAlgo). Information on quantum-resistant cryptographic algorithms supported by eUICC or information on quantum-resistant cryptographic key setting algorithms supported by eUICC may indicate one or more quantum-resistant cryptographic algorithms supported by eUICC (e.g., ML-KEM, ML-DSA, Crystal-Kyber, Crystal-Dilithium, FALCON, SPHINCS+, etc.).
[0108] In one embodiment, the quantum-resistant cryptographic algorithm supported by eUICC may include a key exchange method or a key establishment algorithm that utilizes quantum-resistant cryptography. Additionally, the quantum-resistant cryptographic algorithm supported by eUICC may include a key encapsulation mechanism (KEM) and a key agreement protocol. For example, the key encapsulation mechanism may include at least one of a Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM 512, ML-KEM 768, ML-KEM 1024) or a Ctystal-Kyber algorithm.
[0109] In one embodiment, a quantum-resistant encryption algorithm supported by eUICC or a quantum-resistant encryption key setting encryption algorithm supported by eUICC may be represented in the form of an object identifier (OID) or a bit string that designates the algorithm.
[0110] In one embodiment, at least one of the eUICC quantum-resistant encryption support indicator or the quantum-resistant encryption algorithm information supported by the eUICC may be included in the first information (euiccInfo1) of the eUICC (not shown) installed in the terminal (310) or the information (lpaRspCapability) of the LPA and transmitted to the profile server (330). The eUICC quantum-resistant encryption support indicator may include an eUICC quantum-resistant encryption key establishment support indicator (euiccPqcKeyEstablishmentSupport or pqcKeyEstablishmentSupport) indicating that it supports a key establishment function using quantum-resistant encryption. Additionally, the quantum-resistant encryption algorithm information supported by the eUICC may include quantum-resistant encryption key establishment algorithm information supported by the eUICC (supportedKeyEstablishmentMethods, supportedPqcKeyEstablishmentMethods, PqcKeyEstablishmentMethods, KeyEstablishmentMethods, supportedPqcAlgo or supportedPqcKeyEstablishmentAlgo).
[0111] For example, an eUICC quantum-resistant cryptographic support indicator may be included in eUICC capability support information (euiccRspCapability), and the eUICC capability support information may be included in eUICC first information (euiccInfo1) or second information (euiccInfo2). Additionally, if the eUICC capability support information is included in eUICC first information, an indicator indicating this by the profile server (330) may be included in the eUICC capability support information.
[0112] According to one embodiment, in step 3005, the profile server (330) may review the mutual authentication start request of the terminal (310). Additionally, the profile server (330) may generate a mutual authentication start response corresponding to the mutual authentication start request of the terminal (310) and deliver it to the terminal (310).
[0113] According to one embodiment, in the process of the profile server (330) reviewing a mutual authentication start request and generating a response corresponding to the mutual authentication start request, if at least one of the eUICC quantum-resistant encryption support indicator, eUICC quantum-resistant encryption key setting support indicator, or quantum-resistant encryption algorithm information supported by the eUICC, or quantum-resistant encryption key setting algorithm information supported by the eUICC exists within the mutual authentication start request transmitted by the terminal (310), the profile server (330) may review whether it supports at least one of the quantum-resistant encryption methods supported by the eUICC. Additionally, the profile server (330) may select at least one of the common quantum-resistant encryption algorithms it supports among the quantum-resistant encryption algorithms supported by the eUICC. The selected quantum-resistant encryption algorithm may be a quantum-resistant encryption key setting algorithm.
[0114] According to one embodiment, a profile server may generate a data object comprising at least one of a selected quantum-resistant cryptographic algorithm (selectedPqcAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID) or a selected quantum-resistant cryptographic key establishment algorithm (selectedPqcKeyEstablishmentAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID). For example, the selected quantum-resistant cryptographic algorithm or the quantum-resistant cryptographic key establishment algorithm may be included in the serverSigned1 data object transmitted by the profile server to the terminal. Alternatively, the selected quantum-resistant cryptographic algorithm or the quantum-resistant cryptographic key establishment algorithm may be included in the sessionContext data object. Additionally, for example, the selected quantum-resistant cryptographic algorithm or the selected quantum-resistant cryptographic key establishment algorithm may be represented in the form of an object identifier (OID) or a bit string referring to the algorithm.
[0115] In one embodiment, the profile server (330) may transmit a mutual authentication start response to the terminal (310). The mutual authentication start response may be an ES9+.InitiateAuthentication response. The mutual authentication start response may include at least one of the selected quantum-resistant cryptographic algorithms (selectedPqcAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID) or selected quantum-resistant cryptographic key establishment algorithms (selectedPqcKeyEstablishmentAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID). For example, the selected quantum-resistant cryptographic algorithm or quantum-resistant cryptographic key establishment algorithm may be included in the serverSigned1 data object transmitted by the profile server to the terminal, or in the sessionContext data object. Additionally, the response may include at least one of the signature (serverSignature1) of the profile server (330) generated based on serverSigned1, the digital certificate of the profile server (330) capable of verifying it, and the certificate chain thereof.
[0116] According to one embodiment, in step 3007, the terminal (310) that received the mutual authentication start response can verify the mutual authentication start response transmitted by the profile server (330). The LPA of the terminal (310) can verify the information included in the response transmitted by the profile server (330) through the eUICC installed in the terminal. In the verification, the ES10b.AuthenticateServer message may be used. For example, the eUICC of the terminal (310) can verify the digital certificate and certificate chain of the profile server (330) and verify the signature (serverSignature1) of the profile server.
[0117] According to one embodiment, the eUICC of the terminal (310) can verify whether the terminal (310) or the eUICC of the terminal (310) supports at least one of the quantum-resistant encryption algorithms indicated by the selected quantum-resistant encryption algorithm (selectedPqcAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID) or the selected quantum-resistant encryption key establishment algorithm (selectedPqcKeyEstablishmentAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID) transmitted by the profile server (330).
[0118] According to one embodiment, if there is no quantum-resistant encryption algorithm supported by the terminal (310) among the quantum-resistant encryption algorithms indicated by the selected quantum-resistant encryption algorithm (selectedPqcAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID) or the selected quantum-resistant encryption key establishment algorithm (selectedPqcKeyEstablishmentAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID) transmitted by the profile server (330), the eUICC of the terminal (310) may reply an error to the LPA of the terminal (310).
[0119] According to one embodiment, if there is an algorithm supported by the terminal (310) among the quantum-resistant encryption algorithms indicated by the selected quantum-resistant encryption algorithm (selectedPqcAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID) or the selected quantum-resistant encryption key setting algorithm (selectedPqcKeyEstablishmentAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID) transmitted by the profile server (330), the eUICC of the terminal (310) may store or set the selected quantum-resistant encryption algorithm or quantum-resistant encryption key setting algorithm that is commonly supported by the terminal's eUICC and the profile server. For example, the terminal's eUICC may store at least one commonly supported quantum-resistant encryption algorithm or quantum-resistant encryption key setting algorithm selected in the session information (RSP session) currently in progress with the profile server (330).
[0120] According to one embodiment, in step 3007, the eUICC of the terminal (310) may generate a data object containing at least one Post Quantum Cryptography (PQC) function support information supported by the eUICC installed in the terminal (310) that was transmitted to the profile server (330) in step 3003. For example, the data object may be included in the second information (euiccInfo2) of the eUICC installed in the terminal (310). Additionally, the data object may be included in the euiccSigned1 data object generated by the eUICC.
[0121] In one embodiment, the terminal (310) or the eUICC of the terminal (310) can generate the signature of the eUICC (euiccSignature1) based on a data object containing at least one Post Quantum Cryptography (PQC) function support information supported by the eUICC, or an euiccSinged1 data object.
[0122] In one embodiment, the eUICC of the terminal (310) may reply to the LPA of the terminal (310) with a data object containing support information for at least one Post Quantum Cryptography (PQC) function supported by the eUICC, or an euiccSigned1 data object and the signature (euiccSignature1) of the eUICC. For example, referring to FIG. 3, the terminal (310) may send an ES10b.AuthenticateServer response as a reply to the profile server (330).
[0123] According to one embodiment, in step 3009, the terminal (310) may transmit a client verification request to the profile server (330). The client verification request may include an ES9+.AuthenticateClient request message.
[0124] According to one embodiment, a client verification request may include a data object containing at least one Post Quantum Cryptography (PQC) function support information supported by the installed eUICC. For example, the data object may be included in the second information (euiccInfo2) of the eUICC installed on the terminal (310), or in the euiccSigned1 data object generated by the eUICC. Additionally, the client verification request may include at least one of the signature (euiccSignature1) of the eUICC installed on the terminal (310), the digital certificate of the eUICC capable of verifying it, and the certificate chain thereof. Additionally, for example, the terminal (310) may transmit to the profile server (330) an eUICC Post Quantum Cryptography support indicator included in the eUICC function support information (euiccRspCapability). The eUICC function support information may be included in the eUICC second information (euiccInfo2). In addition, if eUICC function support information is also included in eUICC first information, an indicator that directs the profile server (330) to this may be included in the eUICC function support information.
[0125] According to one embodiment, at step 3011, the profile server (330) can verify whether the support information for at least one Post Quantum Cryptography (PQC) function supported by eUICC transmitted by the terminal (310) at step 3003 matches the support information for at least one Post Quantum Cryptography (PQC) function supported by eUICC transmitted by the terminal (310) at step 3009. For example, the profile server (330) can perform verification regarding whether the information matches if the eUICC Post Quantum Cryptography support indicator in the ES9+.AuthenticateClient request message transmitted by the terminal (310) indicates that the function is supported or if such indicator exists. If the support information for at least one Post Quantum Cryptography (PQC) function supported by the eUICC transmitted by the terminal (310) in steps 3003 and 3009 does not match, the profile server (330) may reply to the terminal (310) with an error due to the mismatch. If the support information for at least one Post Quantum Cryptography (PQC) function supported by the eUICC transmitted by the terminal (310) in steps 3003 and 3009 matches, the profile server (330) may perform subsequent processes using the information provided by the terminal (310) and reply to the terminal (310) with a client verification response. For example, the client verification response may be an ES9+.AuthenticateClientResponse.
[0126] FIG. 4 illustrates a flowchart of a procedure for a terminal to perform function negotiation with a profile server to download a profile according to one embodiment of the present disclosure.
[0127] The flowchart of FIG. 4 may be related to a procedure in which a terminal (410) performs a mutual authentication process with a profile server (430) and provides at least one post-quantum cryptography (PQC) function support information supported by the profile server (430) to the terminal (430), and a procedure in which the terminal (410) compares the post-quantum cryptography support functions provided by the profile server (430) and, if there is a post-quantum cryptography related function that is commonly supported by the profile server (430) and itself, selects at least one of the post-quantum cryptography related functions and sends it back to the profile server (430).
[0128] The configuration and description of the terminal (410) and profile server (430) in FIG. 4 can be understood by referring to FIG. 2. For example, the terminal (410) and profile server (430) shown in FIG. 4 may correspond to the terminal (210) and profile server (230) of FIG. 2, respectively.
[0129] According to one embodiment, in step 4001, the LPA of the terminal (410) can establish a TLS (Transport Layer Security) connection with the profile server (430) that must be connected to for the transfer of the profile.
[0130] According to one embodiment, in step 4003, the terminal (410) can initiate a mutual authentication process with the profile server (430). At this time, the mutual authentication process may include a certificate-based mutual authentication process in which the eUICC of the terminal (410) and the profile server (430) authenticate each other using an asymmetric key consisting of a pair of a public key (PK) and a secret key (SK). The terminal (410) can request the profile server (430) to initiate mutual authentication by transmitting an ES9+.InitiateAuthentication request message to the profile server (430).
[0131] According to one embodiment, in step 4005, the profile server (430) may review a mutual authentication start request from the terminal (410), generate a mutual authentication start response corresponding to the mutual authentication start request, and transmit it to the terminal (410). The mutual authentication start response may be an ES9+.InitiateAuthentication response. The mutual authentication start response may include quantum-resistant cryptographic function support information supported by the profile server (430). For example, the quantum-resistant cryptographic function support information may include at least one of a quantum-resistant cryptographic support indicator (PqcSupport) indicating that the profile server (430) provides a quantum-resistant cryptographic function, or quantum-resistant cryptographic algorithm information (supportedPqcAlgo) supported by the profile server. The quantum-resistant cryptographic support indicator may be a quantum-resistant cryptographic key establishment support indicator (smdpPqcKeyEstablishmentSupport or pqcKeyEstablishmentSupport) indicating that a key establishment function using quantum-resistant cryptography is supported. Additionally, the quantum-resistant cryptographic algorithm information supported by the profile server (430) may be the quantum-resistant cryptographic key establishment algorithm information supported by the profile server (430) (supportedKeyEstablishmentMethods, supportedPqcKeyEstablishmentMethods, PqcKeyEstablishmentMethods, KeyEstablishmentMethods, PQCSupportedAlgo, supportedPqcAlgo, or supportedPqcKeyEstablishmentAlgo).The quantum-resistant encryption algorithm information supported by the profile server (430) or the quantum-resistant encryption key setting algorithm information supported by the profile server (430) may indicate one or more quantum-resistant encryption algorithms supported by the profile server (430) (e.g., ML-KEM, ML-DSA, Crystal-Kyber, Crystal-Dilithium, FALCON, SPHINCS+, etc.).
[0132] In one embodiment, the quantum-resistant encryption algorithm supported by the profile server (430) may include a key exchange method or a key establishment algorithm that utilizes quantum-resistant cryptography. The quantum-resistant encryption algorithm supported by the profile server (430) may include a key encapsulation mechanism (KEM) or a key agreement protocol. For example, the key encapsulation mechanism may include at least one of a Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM 512, ML-KEM 768, ML-KEM 1024) or a Ctystal-Kyber algorithm.
[0133] In one embodiment, the quantum-resistant encryption algorithm supported by the profile server (430) or the quantum-resistant encryption key setting encryption algorithm supported by the profile server may be expressed in the form of an object identifier (OID) or a bit string that designates the algorithm.
[0134] In one embodiment, at least one of the quantum-resistant encryption algorithm information supported by the quantum-resistant encryption support indicator or profile server may be included in the serverSigned1 data object transmitted by the profile server (430) to the terminal (410). Alternatively, at least one of the quantum-resistant encryption algorithm information supported by the quantum-resistant encryption support indicator or profile server may be included in the sessionContext data object or serverRspCapability. Additionally, the mutual authentication start response may include at least one of the signature (serverSignature1) of the profile server (430) generated based on serverSigned1 and a digital certificate of the profile server (430) or a certificate chain capable of verifying it.
[0135] In step 4007, the terminal (410) that has received the mutual authentication start response can authenticate the mutual authentication start response transmitted by the profile server (430). The LPA of the terminal (410) can authenticate the information contained in the response transmitted by the profile server (430) through the eUICC installed on the terminal. Authentication can be performed using the ES10b.AuthenticateServer message. For example, the eUICC of the terminal (410) can authenticate the digital certificate of the profile server (430) and the certificate chain thereof, and authenticate the signature (serverSignature1) of the profile server.
[0136] According to one embodiment, if at least one of the quantum-resistant encryption support indicators or quantum-resistant encryption key setting support indicators of the profile server (430), or quantum-resistant encryption algorithm information or quantum-resistant encryption key setting algorithm information supported by the profile server (430), exists, the eUICC of the terminal (410) may examine whether it supports at least one of the quantum-resistant encryption methods supported by the profile server (430). Additionally, the eUICC of the terminal (410) may select at least one common quantum-resistant encryption algorithm that it supports among the quantum-resistant encryption algorithms supported by the profile server. At this time, the selected quantum-resistant encryption algorithm may be a quantum-resistant encryption key setting algorithm.
[0137] According to one embodiment, if there is an algorithm supported by the eUICC of the terminal (410), the eUICC of the terminal (410) may store or set a selected quantum-resistant cryptographic algorithm or quantum-resistant cryptographic key setting algorithm that is commonly supported by the eUICC of the terminal and the profile server. For example, the eUICC of the terminal may store at least one commonly supported quantum-resistant cryptographic algorithm or quantum-resistant cryptographic key setting algorithm associated with the current profile server (430) and the ongoing session information (RSP session).
[0138] In one embodiment, the eUICC of the terminal (410) may generate a data object comprising at least one of a selected quantum-resistant cryptographic algorithm or a quantum-resistant cryptographic key setting algorithm. For example, the selected quantum-resistant cryptographic algorithm or the quantum-resistant cryptographic key setting algorithm may be included in the euiccSigned1 data object transmitted to the terminal by the profile server. Additionally, for example, the selected quantum-resistant cryptographic algorithm or the selected quantum-resistant cryptographic key setting algorithm may be represented in the form of an object identifier (OID) or a bit string referring to the algorithm.
[0139] In one embodiment, the eUICC of the terminal (410) can generate the signature of the eUICC (euiccSignature1) based on a data object including at least one of a selected quantum-resistant cryptographic algorithm or a quantum-resistant cryptographic key setting algorithm, or an euiccSinged1 data object.
[0140] In one embodiment, the eUICC of the terminal (410) may reply to the LPA of the terminal (410) with a data object including at least one of the selected quantum-resistant cryptographic algorithm or quantum-resistant cryptographic key setting algorithm, an euiccSinged1 data object, and the signature (euiccSignature1) of the eUICC. For example, the reply of the terminal (410) may be an ES10b.AuthenticateServer response.
[0141] According to one embodiment, in step 4009, the terminal (410) may transmit a client verification request to the profile server (430). The terminal (410) may use an ES9+.AuthenticateClient request message as the client verification request. The client verification request may include a data object comprising at least one of a selected quantum-resistant cryptographic algorithm or a quantum-resistant cryptographic key setting algorithm. For example, the data object may be included in the second information (euiccInfo2) of the eUICC installed on the terminal (410), or may be included in the euiccSigned1 data object generated by the eUICC. Additionally, the client verification request may include at least one of the signature (euiccSignature1) of the eUICC installed on the terminal (410), the digital certificate of the eUICC capable of verifying it, and the certificate chain thereof.
[0142] According to one embodiment, in step 4011, the profile server (430) can verify whether the profile server (430) supports at least one of the quantum-resistant encryption algorithms indicated by the selected quantum-resistant encryption algorithm or quantum-resistant encryption key setting algorithm transmitted by the terminal (410).
[0143] According to one embodiment, if the profile server (430) does not support at least one of the quantum-resistant encryption algorithms indicated by the selected quantum-resistant encryption algorithm or quantum-resistant encryption key setting algorithm transmitted by the terminal (410), the profile server (430) may reply an error to the terminal (410).
[0144] If the profile server (430) supports at least one of the quantum-resistant encryption algorithms indicated by the selected quantum-resistant encryption algorithm or quantum-resistant encryption key setting algorithm transmitted by the terminal (410), the profile server (430) may store or set the selected quantum-resistant encryption algorithm or quantum-resistant encryption key setting algorithm that is commonly supported. For example, the profile server (430) may store at least one commonly supported quantum-resistant encryption algorithm or quantum-resistant encryption key setting algorithm associated with the session information (RSP session) currently in progress with the terminal (410).
[0145] According to one embodiment, the profile server (430) can perform subsequent processes using information provided by the terminal (410) and send a client verification response to the terminal (410). For example, the profile server (430) may use ES9+.AuthenticateClient Response as the client verification response.
[0146] FIG. 5 illustrates a flowchart of a procedure for a terminal to perform function negotiation with a profile server to download a profile according to one embodiment of the present disclosure.
[0147] The flowchart of FIG. 5 may be related to a procedure in which a terminal (510) performs a mutual authentication process with a profile server (530) and provides at least one post-quantum cryptography (PQC) function support information supported by the profile server (530) to the terminal (530), and in which the terminal (510) compares the post-quantum cryptography support functions provided by the profile server (530) and, if there is a post-quantum cryptography function that is commonly supported by the profile server (530) and itself, selects at least one of the post-quantum cryptography functions and sends it back to the profile server (430).
[0148] The configuration and description of the terminal (510) and profile server (530) in FIG. 5 can be understood by referring to FIG. 2. For example, the terminal (510) and profile server (530) shown in FIG. 5 may correspond to the terminal (210) and profile server (230) of FIG. 2, respectively.
[0149] According to one embodiment, in step 5001, the LPA of the terminal (510) can establish a TLS (Transport Layer Security) connection with the profile server (530) that must be connected to for the transfer of the profile.
[0150] According to one embodiment, in step 5003, the terminal (510) may initiate a mutual authentication process with the profile server (530). At this time, the mutual authentication process may include a certificate-based mutual authentication process in which the eUICC of the terminal (510) and the profile server (530) authenticate each other using an asymmetric key consisting of a pair of a public key (PK) and a secret key (SK). The terminal (510) may request the profile server (530) to initiate mutual authentication by transmitting an ES9+.InitiateAuthentication message to the profile server (530).
[0151] According to one embodiment, in step 5005, the profile server (530) may review a mutual authentication start request from the terminal (510), generate a mutual authentication start response corresponding to the mutual authentication start request, and transmit it to the terminal (510). The mutual authentication start response may be an ES9+.InitiateAuthentication response. The mutual authentication start response may include quantum-resistant cryptographic function support information supported by the profile server (530). For example, the quantum-resistant cryptographic function support information may include a quantum-resistant cryptographic support indicator (PqcSupport) indicating that the profile server (530) provides a quantum-resistant cryptographic function. The quantum-resistant cryptographic support indicator may be a quantum-resistant cryptographic key establishment support indicator (smdpPqcKeyEstablishmentSupport or pqcKeyEstablishmentSupport) indicating that it supports a key establishment function using quantum-resistant cryptography.
[0152] In one embodiment, the quantum-resistant cryptography support indicator may be included in the serverSigned1 data object transmitted by the profile server to the terminal, or may be included in the sessionContext data object or serverRspCapability. Additionally, the mutual authentication start response may include at least one of the signature (serverSignature1) of the profile server (530) generated based on serverSigned1, the digital certificate of the profile server (530) capable of verifying the signature of the profile server (530), and the certificate chain thereof.
[0153] According to one embodiment, in step 5007, the terminal (510) that receives the mutual authentication start response can authenticate the mutual authentication start response transmitted by the profile server (530). The LPA of the terminal (510) can authenticate the information included in the response transmitted by the profile server (530) through the eUICC installed on the terminal. The authentication can be performed using the ES10b.AuthenticateServer message. For example, the eUICC of the terminal (510) can authenticate the digital certificate of the profile server (530) and the certificate chain thereof, and authenticate the signature (serverSignature1) of the profile server.
[0154] According to one embodiment, the eUICC of the terminal (510) may generate a data object containing at least one Post Quantum Cryptography (PQC) function support information supported by the eUICC. For example, the Post Quantum Cryptography function support information may include at least one of an eUICC Post Quantum Cryptography support indicator (euiccPqcSupport) indicating that the eUICC provides a Post Quantum Cryptography function, or a Post Quantum Cryptography algorithm information supported by the eUICC (supportedPqcAlgo). The eUICC Post Quantum Cryptography support indicator may be an eUICC Post Quantum Cryptography key establishment support indicator (euiccPqcKeyEstablishmentSupport or pqcKeyEstablishmentSupport) indicating that the eUICC supports a key establishment function using Post Quantum Cryptography. In addition, the quantum-resistant cryptographic algorithm information supported by the eUICC may be quantum-resistant cryptographic key establishment algorithm information supported by the eUICC (supportedKeyEstablishmentMethods, supportedPqcKeyEstablishmentMethods, PqcKeyEstablishmentMethods, KeyEstablishmentMethods, PQCSupportedAlgo, supportedPqcAlgo, or supportedPqcKeyEstablishmentAlgo). The quantum-resistant cryptographic algorithm information supported by the eUICC or the quantum-resistant cryptographic key establishment algorithm information supported by the eUICC may indicate one or more quantum-resistant cryptographic algorithms supported by the eUICC (e.g., ML-KEM, ML-DSA, Crystal-Kyber, Crystal-Dilithium, FALCON, SPHINCS+, etc.).
[0155] In one embodiment, the quantum-resistant cryptographic algorithm supported by eUICC may include a key exchange method or a key establishment algorithm that uses quantum-resistant cryptography, and may include a key encapsulation mechanism (KEM) and a key agreement protocol. For example, the key encapsulation mechanism may include at least one of a Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM 512, ML-KEM 768, ML-KEM 1024) and a Ctystal-Kyber algorithm.
[0156] In one embodiment, the quantum-resistant encryption algorithm supported by the eUICC or the quantum-resistant encryption key setting encryption algorithm supported by the eUICC may be expressed in the form of an object identifier (OID) or a bit string that designates the supported algorithm.
[0157] In one embodiment, at least one of the eUICC quantum-resistant encryption support indicator or the quantum-resistant encryption algorithm information supported by the eUICC may be included in the second information (euiccInfo2) of the eUICC installed in the terminal (410). Additionally, at least one of the eUICC quantum-resistant encryption support indicator or the quantum-resistant encryption algorithm information supported by the eUICC may be included in the euiccSigned1 data object generated by the eUICC. The eUICC quantum-resistant encryption support indicator may be an eUICC quantum-resistant encryption key establishment support indicator (euiccPqcKeyEstablishmentSupport or pqcKeyEstablishmentSupport) indicating that it supports a key establishment function using quantum-resistant encryption. In addition, the quantum-resistant cryptographic algorithm information supported by the above eUICC may be quantum-resistant cryptographic key establishment algorithm information supported by the eUICC (supportedKeyEstablishmentMethods, supportedPqcKeyEstablishmentMethods, PqcKeyEstablishmentMethods, KeyEstablishmentMethods, PQCSupportedAlgo, supportedPqcAlgo, or supportedPqcKeyEstablishmentAlgo).
[0158] In one embodiment, the terminal (510) or the eUICC of the terminal (510) can generate the signature of the eUICC (euiccSignature1) based on a data object containing at least one Post Quantum Cryptography (PQC) function support information supported by the eUICC of the terminal (510) or an euiccSinged1 data object.
[0159] In one embodiment, the eUICC of the terminal (510) may reply to the LPA of the terminal (310) with a data object containing support information for at least one Post Quantum Cryptography (PQC) function supported by the eUICC, or an euiccSigned1 data object and the signature (euiccSignature1) of the eUICC. For example, the reply of the terminal (510) may be an ES10b.AuthenticateServer response.
[0160] According to one embodiment, in step 5009, the terminal (510) may transmit a client verification request to the profile server (530). The client verification request may utilize an ES9+.AuthenticateClient request message. The client verification request may include a data object containing information supporting at least one Post Quantum Cryptography (PQC) function supported by the eUICC, or at least one of the euiccSigned1 data object and the signature (euiccSignature1) of the eUICC. Additionally, it may include at least one of the digital certificate of the eUICC and the certificate chain capable of verifying the signature (euiccSignature1) of the eUICC.
[0161] According to one embodiment, in step 5011, the profile server (530) may review whether the information on quantum-resistant cryptographic algorithms supported by the eUICC transmitted by the terminal (510) or the information on quantum-resistant cryptographic key setting algorithms supported by the eUICC supports at least one of the two. Additionally, the profile server (530) may select at least one common quantum-resistant cryptographic algorithm supported by the profile server (530) among the quantum-resistant cryptographic algorithms supported by the eUICC. The selected quantum-resistant cryptographic algorithm may be a quantum-resistant cryptographic key setting algorithm.
[0162] In one embodiment, the profile server (530) may generate a data object comprising at least one of a selected quantum-resistant cryptographic algorithm (selectedPqcAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID) or a selected quantum-resistant cryptographic key establishment algorithm (selectedPqcKeyEstablishmentAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID). For example, the selected quantum-resistant cryptographic algorithm or the quantum-resistant cryptographic key establishment algorithm may be included in the serverSigned2 data object transmitted by the profile server (530) to the terminal (510). Additionally, for example, the selected quantum-resistant cryptographic algorithm or the selected quantum-resistant cryptographic key establishment algorithm may be represented in the form of an object identifier (OID) or a bit string referring to the algorithm.
[0163] In one embodiment, the profile server (530) may transmit a client verification response to the terminal (510). The client verification response may include at least one selected quantum-resistant cryptographic algorithm (selectedPqcAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID) or a selected quantum-resistant cryptographic key establishment algorithm (selectedPqcKeyEstablishmentAlgo, selectedPqcKeyEstablishmentId, selectedKeyEstablishmentAlgo, selectedKeyEstablishmentId, or KeyEstablishmentID). For example, the selected quantum-resistant cryptographic algorithm or the quantum-resistant cryptographic key establishment algorithm may be included in the serverSigned2 data object transmitted by the profile server (530) to the terminal (510). Additionally, the response may include at least one of the signature (serverSignature2) of the profile server (530) generated based on serverSigned2, a digital certificate of the profile server (530) capable of verifying the signature, and the certificate chain thereof.
[0164] FIG. 6 illustrates the functional configuration of a terminal according to one embodiment of the present disclosure.
[0165] Referring to FIG. 6, a terminal according to various embodiments of the present disclosure may include a transceiver (610) and a control unit (or processor) (620). Additionally, the terminal may include a UICC (630). For example, the UICC (630) may be inserted into the terminal, but is not limited thereto. For example, the UICC (630) may include an eUICC embedded in the terminal.
[0166] According to one embodiment, the transmitting and receiving unit (610) can transmit and receive signals, information, data, etc. to and from the profile server.
[0167] According to one embodiment, the processor (620) may include components for overall control of the terminal. The processor (620) may control the overall operation of the terminal according to various embodiments of the present disclosure. In the present disclosure, the processor (620) may be referred to as a control unit. According to one embodiment of the present disclosure, the processor (620) may include at least one processor.
[0168] According to one embodiment of the present disclosure, at least one processor can control the transceiver to transmit a first message containing functional information related to a PQC supported by the eSIM of the terminal to a profile server, and control the transceiver to receive a second message containing PQC information to be used by the eSIM from the profile server in response to the first message.
[0169] According to one embodiment of the present disclosure, the UICC (630) can download a profile and install a profile. Additionally, the UICC (630) can manage a profile.
[0170] According to one embodiment, the UICC (630) may operate under the control of the processor (620). Alternatively, the UICC (630) may include a processor or controller for installing a profile, or may have an application installed. Part of the application may be installed on the processor (620).
[0171] According to one embodiment, the terminal may further include a storage unit or memory. According to one embodiment, the storage unit or memory of the terminal may store data such as a basic program, an application program, and setting information for the operation of the terminal. Additionally, the storage unit may include at least one storage medium among a Flash Memory Type, a Hard Disk Type, a Multimedia Card Micro Type, a card type memory (e.g., SD or XD memory, etc.), magnetic memory, a magnetic disk, an optical disk, a Random Access Memory (RAM), a Static Random Access Memory (SRAM), a Read-Only Memory (ROM), a Programmable Read-Only Memory (PROM), and an Electrically Erasable Programmable Read-Only Memory (EEPROM). Additionally, the processor (620) may perform various operations using various programs, content, data, etc. stored in the storage unit.
[0172] FIG. 7 illustrates the functional configuration of a profile server according to one embodiment of the present disclosure.
[0173] Referring to FIG. 7, a profile server according to various embodiments of the present disclosure may include a transmitting and receiving unit (710) and a control unit (or processor) (720).
[0174] According to one embodiment, the transmitting and receiving unit (710) can transmit and receive signals, information, data, etc. with a terminal, an activation intermediary server, or a business operator.
[0175] According to one embodiment, the processor (720) may include components for overall control of the profile server. The processor (720) may control the overall operation of the profile server according to various embodiments of the present disclosure. In the present disclosure, the processor (720) may be referred to as a control unit. According to one embodiment of the present disclosure, the processor (720) may include at least one processor.
[0176] According to one embodiment of the present disclosure, at least one processor controls the transceiver to receive a first message from a terminal containing functional information related to a PQC supported by the terminal's eSIM, and can control the transceiver to transmit a second message to the terminal containing PQC information to be used by the eSIM in response to the first message.
[0177] According to one embodiment, the profile server may further include a storage unit or memory. The storage unit or memory of the profile server may store data such as a basic program, an application program, and configuration information for the operation of the profile server. Additionally, the storage unit may include at least one storage medium among a Flash Memory Type, a Hard Disk Type, a Multimedia Card Micro Type, a card-type memory (e.g., SD or XD memory, etc.), magnetic memory, a magnetic disk, an optical disk, a Random Access Memory (RAM), a Static Random Access Memory (SRAM), a Read-Only Memory (ROM), a Programmable Read-Only Memory (PROM), and an Electrically Erasable Programmable Read-Only Memory (EEPROM). Additionally, the processor (720) may perform various operations using various programs, content, data, etc. stored in the storage unit.
[0178] According to one embodiment of the present disclosure, a method is provided to be performed by a terminal of a wireless communication system. The method comprises the steps of: transmitting a first message to a profile server containing functional information related to post-quantum cryptography (PQC) supported by an eSIM (embedded subscriber identity module) of the terminal; and receiving, in response to the first message, a second message from the profile server containing PQC information to be used by the eSIM.
[0179] According to one embodiment of the present disclosure, a method is provided to be performed by a profile server of a wireless communication system. The method comprises the steps of receiving a first message from a terminal containing functional information related to a PQC supported by the eSIM of the terminal, and transmitting a second message to the terminal containing PQC information to be used by the eSIM in response to the first message.
[0180] According to one embodiment of the present disclosure, a terminal of a wireless communication system is provided. The terminal includes a transceiver and at least one processor coupled to the transceiver. The at least one processor controls the transceiver to transmit a first message containing functional information related to a PQC supported by the eSIM of the terminal to a profile server, and controls the transceiver to receive, in response to the first message, a second message containing PQC information to be used by the eSIM from the profile server.
[0181] According to one embodiment of the present disclosure, a profile server of a wireless communication system is provided. The profile server includes a transceiver and at least one processor coupled to the transceiver. The at least one processor controls the transceiver to receive a first message from a terminal containing functional information related to a PQC supported by the eSIM of the terminal, and controls the transceiver to transmit a second message to the terminal containing PQC information to be used by the eSIM in response to the first message.
[0182] According to one embodiment of the present disclosure, when a terminal in a communication system communicates with a profile server using a quantum-resistant encryption method and wants to download a profile, the terminal provides the profile server with a quantum-resistant encryption method and parameters supported by the terminal, and can receive from the profile server a method supported identically by both the terminal and the profile server, and can generate a common session key using the simultaneously supported quantum-resistant encryption method and download and install the profile.
[0183] According to one embodiment of the present disclosure, in a communication system, a profile server receives a quantum-resistant encryption method and parameters supported by the terminal from the terminal, selects a method supported identically by the profile server and the terminal and provides it to the terminal, and generates a common session key using the simultaneously supported quantum-resistant encryption method, encrypts the profile, and transmits it to the terminal.
[0184] In the specific embodiments of the present disclosure described above, the components included in the disclosure are expressed in a singular or plural form according to the specific embodiments presented. However, the singular or plural expression is selected to suit the situation presented for convenience of explanation, and the present disclosure is not limited to singular or plural components; even if a component is expressed in the plural form, it may be composed of a singular form, and even if a component is expressed in the singular form, it may be composed of a plural form.
[0185] Meanwhile, although specific embodiments have been described in the detailed description of the present disclosure, it is understood that various modifications are possible within the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be defined by the claims set forth below as well as equivalents thereof.
[0186] The various embodiments of the present disclosure and the terms used therein are not intended to limit the technology described in the present disclosure to specific embodiments and should be understood to include various modifications, equivalents, and / or substitutions of said embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar components. A singular expression may include a plural expression unless the context clearly indicates otherwise. In the present disclosure, expressions such as "A or B," "at least one of A and / or B," "A, B or C," or "at least one of A, B and / or C" may include all possible combinations of items listed together. Expressions such as "first," "second," "first," or "second" may modify said components regardless of order or importance and are used only to distinguish one component from another and do not limit said components. Where it is stated that a certain (e.g., 1st) component is "(functionally or telecommunicationally) connected" or "connected" to another (e.g., 2nd) component, the certain component may be directly connected to the other component or connected through the other component (e.g., 3rd component).
[0187] As used in this disclosure, the term "module" includes a unit composed of hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be a component formed integrally, or a minimum unit or part thereof that performs one or more functions. For example, a module may be composed of an application-specific integrated circuit (ASIC).
[0188] Various embodiments of the present disclosure may be implemented as software (e.g., a program) containing instructions stored in a machine-readable storage medium (e.g., internal memory or external memory) that is readable by a machine (e.g., a computer). The machine may include a terminal according to various embodiments of the present disclosure, which is a device capable of calling instructions stored from the storage medium and operating according to the called instructions. When an instruction is executed by a processor (e.g., the processor (620) of FIG. 6 or the processor (720) of FIG. 7), the processor may perform a function corresponding to the instruction directly or using other components under the control of the processor. The instruction may include code generated or executed by a compiler or an interpreter.
[0189] A device-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' means merely that the storage medium does not contain a signal and is tangible, without distinguishing whether data is stored semi-permanently or temporarily on the storage medium.
[0190] Methods according to the various embodiments disclosed in this disclosure may be provided as included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or online through an application store (e.g., Play Store™). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created in a storage medium such as the memory of a manufacturer's server, an application store's server, or a relay server.
[0191] Each component (e.g., module or program) according to various embodiments may be composed of a singular or multiple entities, and some of the aforementioned sub-components may be omitted, or other sub-components may be additionally included in various embodiments. Generally or additionally, some components (e.g., module or program) may be integrated into a single entity to perform the functions performed by each of the respective components prior to integration in the same or similar manner. The operations performed by the module, program, or other components according to various embodiments may be executed sequentially, in parallel, iteratively, or heuristically, or at least some operations may be executed in a different order, omitted, or other operations added.
Claims
1. A method performed by a terminal (user equipment) in a wireless communication system, wherein the method comprises: Step of establishing a TLS (transport layer security) connection with a profile server; A step of transmitting to the profile server, via an authentication start request message for initiating mutual authentication between the terminal and the profile server, first eUICC information including first key setting algorithm information supported by the eUICC (embedded universal integrated circuit card) of the terminal; A step of receiving an authentication start response message from the profile server, the message including information about at least one key setting algorithm selected within the first key setting algorithm information; A step of transmitting to the profile server, via a client verification request message, second eUICC information including the eUICC signature of the terminal and second key setting algorithm information supported by the eUICC of the terminal; and A method comprising the step of receiving, from the profile server, a response according to a verification result regarding whether the first key setting algorithm information in the first eUICC information and the second key setting algorithm information in the second eUICC information match.
2. In Paragraph 1, The first key setting algorithm information and the second key setting algorithm information include information regarding a key encapsulation mechanism (KEM) for post-quantum cryptography (PQC) functions supported by the eUICC, and A method in which information regarding the above KEM is indicated based on an OID (object identifier) corresponding to at least one ML (Module-Lattice-based)-KEM.
3. In Paragraph 1, A method in which, if the first key setting algorithm information in the first eUICC information and the second key setting algorithm information in the second eUICC information are different, the response includes an error message indicating a verification failure.
4. In Paragraph 3, A method in which the above error message includes information indicating the cause of the above verification failure.
5. In Paragraph 1, A method in which the above client verification request message further includes an eUICC certificate chain for the above eUICC signature.
6. A method performed by a profile server in a wireless communication system, wherein the method comprises: A step of establishing a TLS (transport layer security) connection with the terminal (user equipment); A step of receiving, from the terminal, first eUICC information including first key setting algorithm information supported by the eUICC (embedded universal integrated circuit card) of the terminal, through an authentication start request message for initiating mutual authentication between the terminal and the profile server; A step of transmitting to the terminal an authentication start response message containing information about at least one key setting algorithm selected within the first key setting algorithm information; A step of receiving, from the terminal, second eUICC information including the eUICC signature of the terminal and second key setting algorithm information supported by the eUICC of the terminal through a client verification request message; and A method comprising the step of transmitting to the terminal a response according to a verification result regarding whether the first key setting algorithm information in the first eUICC information and the second key setting algorithm information in the second eUICC information match.
7. In Paragraph 6, The first key setting algorithm information and the second key setting algorithm information include information regarding a key encapsulation mechanism (KEM) for post-quantum cryptography (PQC) functions supported by the eUICC, and A method in which information regarding the above KEM is indicated based on an OID (object identifier) corresponding to at least one ML (Module-Lattice-based)-KEM.
8. In Paragraph 6, A method in which, if the first key setting algorithm information in the first eUICC information and the second key setting algorithm information in the second eUICC information are different, the response includes an error message indicating a verification failure.
9. In Paragraph 8, A method in which the above error message includes information indicating the cause of the above verification failure.
10. In Paragraph 6, A method in which the above client verification request message further includes an eUICC certificate chain for the above eUICC signature.
11. In a wireless communication system, regarding a terminal (user equipment): At least one transceiver; At least one processor communicatively coupled to the above at least one transceiver; and It includes at least one memory that is communicationally coupled to the above at least one processor and stores instructions, and The above instructions are executed individually or in any combination by the above at least one processor, so that the terminal: Establish a TLS (transport layer security) connection with the profile server, and Transmitting to the profile server above first eUICC information including first key setting algorithm information supported by the eUICC (embedded universal integrated circuit card) of the terminal through an authentication start request message for initiating mutual authentication between the terminal and the profile server, and Receive an authentication start response message from the profile server that includes information on at least one key setting algorithm selected within the first key setting algorithm information, and Transmitting to the profile server above, through a client verification request message, second eUICC information including the eUICC signature of the terminal and second key setting algorithm information supported by the eUICC of the terminal, and A terminal that receives, from the profile server, a response according to the verification result regarding whether the first key setting algorithm information in the first eUICC information and the second key setting algorithm information in the second eUICC information match.
12. In Paragraph 11, The first key setting algorithm information and the second key setting algorithm information include information regarding a key encapsulation mechanism (KEM) for post-quantum cryptography (PQC) functions supported by the eUICC, and A terminal in which information regarding the above KEM is indicated based on an OID (object identifier) corresponding to at least one ML (Module-Lattice-based)-KEM.
13. In Paragraph 11, A terminal in which, if the first key setting algorithm information in the first eUICC information and the second key setting algorithm information in the second eUICC information are different, the response includes an error message indicating a verification failure.
14. In Paragraph 13, A terminal in which the above error message includes information indicating the cause of the above verification failure.
15. Regarding a profile server in a wireless communication system: At least one transceiver; At least one processor communicatively coupled to the above at least one transceiver; and It includes at least one memory that is communicationally coupled to the above at least one processor and stores instructions, and The above instructions are executed individually or in any combination by the above at least one processor, and the profile server: Establish a TLS (transport layer security) connection with the terminal (user equipment), and From the above terminal, first eUICC information including first key setting algorithm information supported by the eUICC (embedded universal integrated circuit card) of the terminal is received through an authentication start request message for initiating mutual authentication between the terminal and the profile server, and Transmit an authentication start response message to the terminal that includes information on at least one key setting algorithm selected within the first key setting algorithm information, and From the above terminal, receiving second eUICC information including the eUICC signature of the terminal and second key setting algorithm information supported by the eUICC of the terminal through a client verification request message, and A profile server that transmits to the terminal a response based on a verification result regarding whether the first key setting algorithm information in the first eUICC information and the second key setting algorithm information in the second eUICC information match.