Method and device for storing and managing profile in wireless communication system
Patent Information
- Application Number
- PCT/KR2026/002624
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-21
- Filing Date
- 2026-02-12
- Publication Date
- 2026-09-24
Smart Images

Figure KR2026002624_24092026_PF_FP_ABST
Abstract
Description
Method and device for storing and managing profiles in a wireless communication system
[0001] The present disclosure relates to a terminal and a profile server in a wireless communication system. Specifically, the present disclosure relates to a method and apparatus for installing a profile on an embedded universal integrated circuit card (eUICC) in a wireless communication system, and for encrypting, moving, and managing the installed profile to a storage space outside the eUICC.
[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in frequency bands below 6 GHz ('Sub 6 GHz'), such as 3.5 gigahertz (3.5 GHz), but also in ultra-high frequency bands called millimeter waves (mmWave), such as 28 GHz and 39 GHz ('Above 6 GHz'). In addition, for 6G mobile communication technology, which is referred to as a system beyond 5G, implementation in the terahertz band (e.g., the 3 terahertz (3 THz) band at 95 GHz) is being considered to achieve transmission speeds 50 times faster and ultra-low latency reduced to one-tenth compared to 5G mobile communication technology.
[0003] In the early stages of 5G mobile communication technology, aiming to satisfy service support and performance requirements for enhanced Mobile BroadBand (eMBB), Ultra-Reliable Low-Latency Communications (URLLC), and Massive Machine-Type Communications (mMTC), technologies included beamforming and Massive MIMO to mitigate path loss and increase transmission distance in ultra-high frequency bands; support for various numerologies (such as operating multiple subcarrier spacings) and dynamic operation of slot formats for the efficient utilization of ultra-high frequency resources; initial access techniques to support multi-beam transmission and broadband; the definition and operation of Band-Width Parts (BWP); Low Density Parity Check (LDPC) codes for high-volume data transmission; new channel coding methods such as Polar Codes for the reliable transmission of control information; and L2 pre-processing (L2 Standardization has been carried out for pre-processing, network slicing which provides a dedicated network specialized for specific services, and other methods.
[0004] Currently, discussions are underway to improve and enhance the performance of the initial 5G mobile communication technology, taking into account the services that the 5G mobile communication technology was intended to support. Additionally, standardization of the physical layer is in progress for technologies such as V2X (Vehicle-to-Everything), which helps autonomous vehicles make driving decisions and enhance user convenience based on their own location and status information transmitted by the vehicle; NR-U (New Radio Unlicensed), which aims for system operation in unlicensed bands to comply with various regulatory requirements; NR terminal low power consumption technology (UE Power Saving); Non-Terrestrial Network (NTN), which is direct terminal-satellite communication for securing coverage in areas where communication with the terrestrial network is impossible; and positioning.
[0005] In addition, standardization is underway in the field of wireless interface architecture / protocols for technologies such as the Industrial Internet of Things (IIoT) to support new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) which provides nodes to expand network service areas by integrating wireless backhaul links and access links, Mobility Enhancement including Conditional Handover and Dual Active Protocol Stack (DAPS) Handover, and 2-step Random Access (2-step RACH for NR) which simplifies random access procedures. Standardization is also underway in the field of system architecture / services for 5G baseline architectures (e.g., Service based Architecture, Service based Interface) to incorporate Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC), which provides services based on the location of the terminal.
[0006] When such 5G mobile communication systems are commercialized, connected devices, which are increasing explosively, will be connected to communication networks. Accordingly, it is expected that there will be a need to enhance the functionality and performance of 5G mobile communication systems and to integrate the operation of connected devices. To this end, new research is planned to be conducted on 5G performance improvement and complexity reduction, support for AI services, support for metaverse services, and drone communication using eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).
[0007] Furthermore, the advancement of these 5G mobile communication systems encompasses multi-antenna transmission technologies such as new waveforms, Full Dimensional MIMO (FD-MIMO), array antennas, and large-scale antennas to guarantee coverage in the terahertz band of 6G mobile communication technology; metamaterial-based lenses and antennas; high-dimensional spatial multiplexing technology using Orbital Angular Momentum (OAM); and Reconfigurable Intelligent Surface (RIS) technology to improve terahertz band signal coverage; as well as full-duplex technology for enhancing frequency efficiency and system networks in 6G mobile communication technology; AI-based communication technologies that realize system optimization by utilizing satellites and Artificial Intelligence (AI) from the design stage and internalizing end-to-end AI support functions; and the realization of services of complexity exceeding the limits of terminal computing capabilities by utilizing ultra-high-performance communication and computing resources. It could serve as a foundation for the development of next-generation distributed computing technologies.
[0008] One objective of the present disclosure is to provide a method for encrypting, moving, storing, and managing a profile installed in an eUICC in a wireless communication system to a storage space outside the eUICC.
[0009] In addition, one objective of the present disclosure is to provide a method and apparatus for processing an encrypted profile within an eUICC when the profile installed in the eUICC is encrypted and transferred to a storage space outside the eUICC.
[0010] One objective of the present disclosure is to provide a method and apparatus that supports the deletion of a profile that is encrypted, moved, and stored in a storage space outside the eUICC, and transmits the deletion result to a profile server.
[0011] The technical problems to be solved in this disclosure are not limited to those mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art to which this disclosure belongs from the description below.
[0012] The present disclosure, for solving the above-mentioned problems, provides a method performed by a device comprising: confirming a request for an extended storage encrypted profile (ESEP) from a local profile assistant (LPA); generating the ESEP based on the request for the ESEP; storing the ESEP in an external storage; confirming a request from the LPA to delete information related to the ESEP stored in an embedded universal integrated circuit card (eUICC); and deleting information related to the ESEP stored in the eUICC based on the request to delete information related to the ESEP.
[0013] Additionally, the present disclosure provides an apparatus comprising an external storage that stores an extended storage encrypted profile (ESEP) and an embedded universal integrated circuit card (eUICC). The eUICC checks for a request for the extended storage encrypted profile (ESEP) from a local profile assistant (LPA), generates the ESEP based on the request for the ESEP, and after the ESEP is stored in the external storage, checks for a request from the LPA to delete information related to the ESEP stored in the eUICC, and controls the deletion of information related to the ESEP stored in the eUICC based on the request for deletion of information related to the ESEP.
[0014] According to one example of the present disclosure, a method for efficiently storing and managing profiles can be provided.
[0015] According to one example of the present disclosure, by supporting the deletion of a profile that is encrypted, moved, and stored outside the eUICC, it is possible to avoid moving and decrypting the profile into the eUICC for deletion, thereby enabling more efficient management of the profile.
[0016] In addition, according to one example of the present disclosure, there is an effect of managing profiles more securely by deleting the profile within the eUICC after confirming that the encrypted profile has been stored outside the eUICC.
[0017] Accordingly, the present disclosure can provide an apparatus and method capable of effectively providing services in a wireless communication system.
[0018] The effects obtainable from the present disclosure are not limited to those mentioned above, and other unmentioned effects will be clearly understood by those skilled in the art to which the present disclosure belongs from the description below.
[0019] FIG. 1 is a diagram illustrating a method for a terminal to connect to a mobile communication network using a UICC equipped with a fixed profile according to one embodiment of the present disclosure.
[0020] FIG. 2 is a diagram illustrating an example of a connection between a terminal, an activation intermediary server, a profile providing server, and a service provider according to one embodiment of the present disclosure.
[0021] FIG. 3 illustrates a flowchart of a procedure in which a terminal according to one embodiment of the present disclosure generates an encrypted profile for external storage storage from a profile installed on the terminal and stores the encrypted profile in an external storage.
[0022] FIG. 4 illustrates a flowchart of a procedure in which a terminal according to one embodiment of the present disclosure generates an encrypted profile for external storage storage from a profile installed on the terminal and stores the encrypted profile in an external storage.
[0023] FIG. 5 is a block diagram illustrating the functional configuration of a terminal according to one embodiment of the present disclosure.
[0024] FIG. 6 is a block diagram illustrating the functional configuration of a profile server according to one embodiment of the present disclosure.
[0025] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.
[0026] In describing the embodiments, technical details that are well known in the technical field to which this disclosure belongs and are not directly related to this disclosure are omitted. This is intended to convey the essence of this disclosure more clearly without obscuring it by omitting unnecessary explanations.
[0027] For the same reason, some components in the attached drawings have been exaggerated, omitted, or schematically depicted. Additionally, the size of each component does not entirely reflect its actual dimensions. Identical or corresponding components in each drawing have been assigned the same reference numbers.
[0028] The advantages and features of the present disclosure and the methods for achieving them will become clear by referring to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below but may be implemented in various different forms. The embodiments provided are merely to ensure that the disclosure is complete and to fully inform those skilled in the art of the scope of the disclosure, and the disclosure is defined only by the scope of the claims. Throughout the disclosure, the same reference numerals refer to the same components.
[0029] At this point, it will be understood that each block of the process flow diagrams and combinations of the flow diagrams can be executed by computer program instructions. Since these computer program instructions can be loaded into the processor of a general-purpose computer, a computer for special purposes, or other programmable data processing equipment, the instructions executed through the processor of the computer or other programmable data processing equipment create means to perform the functions described in the flow diagram block(s). Since these computer program instructions can also be stored on a computer-available or computer-readable storage medium that can be oriented toward the computer or other programmable data processing equipment to implement the function in a specific way, the instructions stored on the computer-available or computer-readable storage medium can also produce a manufactured item containing means of instruction to perform the function described in the flow diagram block(s). Since computer program instructions can be loaded onto a computer or other programmable data processing equipment, instructions that perform a series of operation steps on the computer or other programmable data processing equipment to create a process executed by the computer can also provide steps for executing the functions described in the flowchart block(s).
[0030] Additionally, each block may represent a module, segment, or part of code containing one or more executable instructions for executing a specified logical function(s). It should also be noted that in some alternative execution examples, the functions mentioned in the blocks may occur out of order. For instance, two blocks described in succession may actually be executed substantially simultaneously, or the blocks may be executed in reverse order according to their corresponding functions.
[0031] In this embodiment, the term "part" refers to a software or hardware component, such as an FPGA or ASIC, and the "part" performs certain roles. However, the meaning of "part" is not limited to software or hardware. The "part" may be configured to reside in an addressable storage medium or configured to operate one or more processors. Accordingly, as an example, the "part" includes components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and "parts" may be combined into a smaller number of components and "parts" or further separated into additional components and "parts." Furthermore, the components and "parts" may be implemented to operate one or more CPUs within a device or secure multimedia card.
[0032] With the advancement of mobile communication systems, it has become possible to provide various services, and thus measures to effectively provide the aforementioned services are required.
[0033] A UICC (Universal Integrated Circuit Card) is a smart card inserted into devices such as mobile communication terminals, and is also referred to as a UICC card. A UICC may include a connection control module for the terminal to connect to a mobile carrier's network. Examples of such connection control modules include the USIM (Universal Subscriber Identity Module), SIM (Subscriber Identity Module), and ISIM (IP Multimedia Service Identity Module). A UICC containing a USIM is commonly referred to as a USIM card. Similarly, a UICC containing a SIM module is commonly referred to as a SIM card.
[0034] Among UICC cards, those fixed to a terminal are called eUICC (embedded UICC). Typically, an eUICC refers to a UICC card that is fixed to a terminal and allows for the remote download and selection of a SIM module. Additionally, the downloaded SIM module information is collectively referred to as an eUICC profile, or more simply, a profile.
[0035] Post-Quantum Cryptography (PQC) is an asymmetric key-based encryption technology utilizing public-private key pairs, designed to replace existing cryptographic systems that are susceptible to decryption by quantum computers and specific algorithms. Consequently, it is attracting attention as a new cryptographic system because it is expected to remain undecipherable within polynomial time by quantum computers, which demonstrate superior performance in integer-based problems. Types of PQC include multivariate-based, code-based, lattice-based, isogeny-based, and hash-based cryptographic algorithms.
[0036] Meanwhile, due to the advancement of quantum computing technology, the risk has increased where malicious attackers can eavesdrop on communications between terminals and profile servers, decrypt encrypted information, and steal user profiles and network security keys. To effectively counter these threats, it is necessary to enhance the security of remote SIM provision operations via eSIM.
[0037] The present disclosure aims to provide a method and apparatus for a terminal in a communication system to select a communication service and connect to a network.
[0038] In addition, the present disclosure aims to provide a method and apparatus for a terminal in a communication system to download, install, and manage a profile online for connecting to a network.
[0039] Specific terms used in the following description are provided to aid in understanding the present disclosure, and the use of such specific terms may be modified in other forms without departing from the technical spirit of the present disclosure.
[0040] In the present disclosure, the UICC (Universal Integrated Circuit Card) is a smart card used by inserting it into a mobile communication terminal or the like, and may also be referred to as a UICC card.
[0041] UICC may refer to a chip that stores personal information such as network access authentication information, phonebooks, and SMS (Short Message Service) of mobile communication subscribers, and enables secure mobile communication by performing subscriber authentication and traffic security key generation when connecting to mobile communication networks such as GSM (Global System for Mobile Communication), WCDMA (Wideband Code Division Multiple Access), LTE (Long Term Evolution) / NR (New Radio).
[0042] The UICC may include communication applications or access control modules for the terminal to connect to a mobile carrier's network. Examples of such communication applications or access control modules may include USIM (Universal Subscriber Identity Module), SIM (Subscriber Identity Module), and ISIM (IP Multimedia Service Identity Module). Additionally, the UICC may provide high-level security functions for the installation of various applications, such as electronic wallets, ticketing, and electronic passports.
[0043] A UICC containing a USIM is commonly referred to as a USIM card. Similarly, a UICC containing a SIM module is commonly referred to as a SIM card.
[0044] In this disclosure, "SIM card," "UICC card," "USIM card," and "UICC including ISIM" may be used interchangeably. For example, the contents of this disclosure may apply equally to SIM cards, USIM cards, ISIM cards, or general UICC cards.
[0045] SIM cards store the personal information of mobile subscribers and enable secure mobile communication by performing subscriber authentication and generating traffic security keys when connecting to a mobile communication network.
[0046] Generally, SIM cards are manufactured as dedicated cards for specific mobile carriers at the request of those carriers. Authentication information for accessing the carrier's network, such as the USIM (Universal Subscriber Identity Module) application, IMSI (International Mobile Subscriber Identity), K value, and OPc value, may be pre-loaded onto the card before shipment. Consequently, the mobile carrier receives the SIM card and provides it to subscribers; subsequently, if necessary, they can utilize technologies such as OTA (Over The Air) to manage the installation, modification, and deletion of applications within the UICC. Subscribers can use the carrier's network and application services by inserting the UICC card into their mobile devices. When replacing devices, the authentication information, mobile phone numbers, and personal phonebooks stored on the UICC card can be transferred and inserted into the new device, allowing them to use the new device as is.
[0047] However, SIM cards present an inconvenience for mobile device users seeking services from other mobile carriers. Users face the inconvenience of having to physically acquire a SIM card to receive services from a mobile carrier. For example, when traveling to another country, users face the inconvenience of having to obtain a local SIM card to receive local mobile services. While roaming services alleviate this inconvenience to some extent, the rates are relatively high, and there is also the issue of being unable to receive service if there is no contract between the carriers.
[0048] Meanwhile, this inconvenience can be largely resolved by remotely downloading and installing a SIM module onto a UICC card. For example, a user can download the SIM module of the mobile communication service they wish to use onto the UICC card at a desired time. Such a UICC card can be used by downloading and installing multiple SIM modules and selecting only one of them. Such a UICC card may or may not be fixed to the terminal. In particular, a UICC that is fixed to the terminal is called an eUICC (embedded UICC); typically, eUICC refers to a UICC card that is fixed to the terminal and allows for the remote downloading and selection of a SIM module. In this disclosure, a UICC card that allows for the remote downloading and selection of a SIM module may be referred to as an eUICC. For example, among UICC cards that allow for the remote downloading and selection of a SIM module, a UICC card that is fixed to the terminal or not fixed may be collectively referred to as an eUICC. Furthermore, the downloaded SIM module information may be collectively referred to as an eUICC profile, or more simply, a profile.
[0049] In the present disclosure, the eUICC may be a security module in the form of a chip embedded in the terminal, rather than a detachable type that can be inserted into and removed from the terminal. Typically, the eUICC may be used by being fixed to the terminal. Meanwhile, the eUICC can download and install a profile using OTA technology. The eUICC may be referred to as a UICC capable of downloading and installing a profile.
[0050] The method of downloading and installing a profile on an eUICC using OTA technology in the present disclosure may also be applied to a detachable UICC that can be inserted into and removed from a terminal. For example, the embodiments of the present disclosure may be applied to a UICC capable of downloading and installing a profile using OTA technology.
[0051] In the present disclosure, "UICC" may be used interchangeably with "SIM", and "eUICC" may be used interchangeably with "embedded SIM (eSIM)".
[0052] In the present disclosure, "Profile" may refer to an application, file system, authentication key value, etc. stored within the UICC packaged in the form of software.
[0053] In the present disclosure, "USIM Profile" may have the same meaning as "profile" or may mean information included in a USIM application within the profile packaged in the form of software.
[0054] In the present disclosure, the operation of enabling a profile by a terminal may mean an operation of changing the state of the profile to an enabled state so that the terminal can receive communication services through the telecommunications carrier that provided the profile. A profile in an enabled state may be expressed as an "enabled profile."
[0055] In the present disclosure, the operation of a terminal disabling a profile may mean changing the state of the profile to a disabled state, thereby configuring the terminal so that it cannot receive communication services through the telecommunications carrier that provided the profile. A profile in a disabled state may be expressed as a "disabled profile."
[0056] In the present disclosure, the operation of a terminal deleting a profile may mean an operation of changing the status of the profile to a deleted state so that the terminal can no longer activate or deactivate the profile. A profile in a deleted state may be expressed as a "deleted profile."
[0057] In the present disclosure, the operation of enabling, disabling, or deleting a profile by a terminal may mean an operation in which, without immediately changing the state of each profile to an enabled, disabled, or deleted state, each profile is first marked as to be enabled, to be disabled, or to be deleted, and then the terminal or the terminal’s UICC changes each profile to an enabled, disabled, or deleted state after performing a specific operation (e.g., the execution of a refresh or reset command). The action of marking a specific profile as a scheduled state (e.g., to be enabled, to be disabled, or to be deleted) is not necessarily limited to marking one scheduled state for a single profile; it is also possible to mark one or more profiles as having the same or different scheduled states, mark one profile as having one or more scheduled states, or mark one or more profiles as having one or more scheduled states.
[0058] Additionally, if the terminal displays one or more scheduled states for any profile, the two scheduled state indications may be combined into one. For example, if any profile is displayed as "to be disabled" and "to be deleted," the profile may be displayed as a combined "to be disabled and deleted" state.
[0059] Additionally, the operation of the terminal displaying a scheduled state for one or more profiles may be performed sequentially or simultaneously. Additionally, the operation of the terminal displaying a scheduled state for one or more profiles and subsequently changing the state of the actual profile may be performed sequentially or simultaneously.
[0060] In the present disclosure, the "profile providing server" may include functions for creating a profile, encrypting a created profile, creating a profile remote management command, or encrypting a created profile remote management command. The profile providing server may be represented as SM-DP (Subscription Manager Data Preparation), SM-DP+ (Subscription Manager Data Preparation plus), off-card entity of Profile Domain, profile encryption server, profile creation server, profile provisioner (PP), profile provider, and PPC (Profile Provisioning Credentials) holder.
[0061] In the present disclosure, the "profile management server" may include a function for managing profiles. The profile management server may be represented as SM-SR (Subscription Manager Secure Routing), SM-SR+ (Subscription Manager Secure Routing Plus), off-card entity of eUICC Profile Manager or PMC (Profile Management Credentials) holder, EM (eUICC Manager), PM (Profile Manager), etc.
[0062] In the present disclosure, the profile providing server may refer to a combination of the functions of a profile management server. Accordingly, in various embodiments of the present disclosure, the operation of the profile providing server may be performed on the profile management server. Likewise, the operation of the profile management server or SM-SR may be performed on the profile providing server.
[0063] In the present disclosure, the "activation intermediary server" may be represented as SM-DS (Subscription Manager Discovery Service), DS (Discovery Service), Root activation intermediary server (Root SM-DS), and Alternative activation intermediary server (Alternative SM-DS). An activation intermediary server may receive an Event Register Request (Event Register Request) from one or more profile providing servers or activation intermediary servers. Additionally, one or more activation intermediary servers may be used in combination, in which case the first activation intermediary server may receive an Event Register Request from a second activation intermediary server as well as a profile providing server.
[0064] In the present disclosure, the profile providing server and the activation brokerage server may be referred to as an 'RSP (Remote SIM Provisioning) server'. The RSP server may be represented as SM-XX (Subscription Manager XX).
[0065] In the present disclosure, the term "terminal" may be referred to as a Mobile Station (MS), User Equipment (UE), User Terminal (UT), wireless terminal, Access Terminal (AT), terminal, Subscriber Unit, Subscriber Station (SS), wireless device, wireless communication device, Wireless Transmit / Receive Unit (WTRU), mobile node, mobile, or other terms. In one embodiment, the terminal may include a cellular telephone, a smartphone having wireless communication capabilities, a Personal Digital Assistant (PDA) having wireless communication capabilities, a wireless modem, a portable computer having wireless communication capabilities, a shooting device such as a digital camera having wireless communication capabilities, a gaming device having wireless communication capabilities, a music storage and playback appliance having wireless communication capabilities, an internet appliance capable of wireless internet access and browsing, as well as portable units or terminals integrating combinations of such capabilities. Additionally, the terminal may include, but is not limited to, M2M (Machine to Machine) terminals and MTC (Machine Type Communication) terminals / devices. In this disclosure, the terminal may also be referred to as an electronic device.
[0066] In the present disclosure, the "electronic device" may have a UICC embedded that can download and install a profile. If the UICC is not embedded in the electronic device, a UICC that is physically separated from the electronic device may be inserted into the electronic device and connected to the electronic device. For example, the UICC may be inserted into the electronic device in the form of a card. The electronic device may include a terminal. In this case, the terminal may be a terminal that includes a UICC that can download and install a profile. The UICC may not only be embedded in the terminal, but if the terminal and the UICC are separated, the UICC may be inserted into the terminal and connected to the terminal. A UICC that can download and install a profile may be referred to, for example, as an eUICC.
[0067] In the present disclosure, a terminal or electronic device may include software or an application installed within the terminal or electronic device to control a UICC or an eUICC. Software or an application installed within the terminal or electronic device to control a UICC or an eUICC may be referred to, for example, as a Local Profile Assistant (LPA).
[0068] In the present disclosure, "profile identifier" may be referred to as an argument matching a profile identifier (Profile ID), ICCID (Integrated Circuit Card ID), Matching ID, Event ID, Activation Code, Activation Code Token, Command Code, Command Code Token, Signed Command Code, Unsigned Command Code, ISD-P (Issuer Security Domain - profile), or Profile Domain (PD). The profile identifier (Profile ID) may represent a unique identifier for each profile. The profile identifier may further include the address of a profile provider server (SM-DP+) capable of indexing the profile. Additionally, the profile identifier may further include the signature of the profile provider server (SM-DP+).
[0069] In the present disclosure, the "eUICC identifier (eUICC ID)" may be a unique identifier of the eUICC embedded in the terminal and may be referred to as an EID (eUICC Identifier). Additionally, if a provisioning profile is pre-loaded on the eUICC, the eUICC identifier (eUICC ID) may be the identifier of the corresponding provisioning profile (Provisioning Profile's Profile ID). Furthermore, in one embodiment of the present disclosure, if the terminal and the eUICC chip are not separated, the eUICC identifier (eUICC ID) may be the terminal ID. Additionally, the eUICC identifier (eUICC ID) may refer to a specific secure domain of the eUICC chip.
[0070] In the present disclosure, "Profile Container" may be referred to as a Profile Domain. A Profile Container may be a Security Domain.
[0071] In the present disclosure, "APDU (application protocol data unit)" may be a message for a terminal to interact with an eUICC. Additionally, APDU may be a message for a PP (Profile Provider) or PM (Profile Manager) to interact with an eUICC.
[0072] In the present disclosure, "Profile Provisioning Credentials (PPC)" may be a means used for mutual authentication, profile encryption, and signing between a profile provisioning server and an eUICC. A PPC may include one or more of a symmetric key, an RSA (Rivest Shamir Adleman) certificate and private key, an ECC (elliptic curved cryptography) certificate and private key, a Root certification authority (CA), and a certificate chain. Additionally, if there are multiple profile provisioning servers, different PPCs may be stored or used in the eUICC for each profile provisioning server.
[0073] In the present disclosure, "PMC (Profile Management Credentials)" may be a means used for mutual authentication, encryption of transmitted data, and signing between a profile management server and an eUICC. A PMC may include one or more of a symmetric key, an RSA certificate and private key, an ECC certificate and private key, a Root CA, and a certificate chain. Additionally, if there are multiple profile management servers, different PMCs may be stored or used in the eUICC for each profile management server.
[0074] In the present disclosure, "AID" may be an Application Identifier. This value may be a distinguisher that separates different applications within the eUICC.
[0075] In the present disclosure, "Event" may be a collective term for Profile Download, Remote Profile Management, or other management / processing commands for profiles or eUICCs. An Event may be named a Remote SIM Provisioning Operation (or RSP Operation) or an Event Record, and each Event may be referred to as data comprising at least one of the following: a corresponding Event Identifier (Event ID, EventID) or Matching Identifier (Matching ID, MatchingID), the address (FQDN, IP Address, or URL) of the Profile Provider Server (SM-DP+) or Activation Broker Server (SM-DS) where the event is stored, the signature of the Profile Provider Server (SM-DP+) or Activation Broker Server (SM-DS), and the digital certificate of the Profile Provider Server (SM-DP+) or Activation Broker Server (SM-DS).
[0076] Data corresponding to an Event may be referred to as a "Command Code." Part or all of the procedure utilizing the Command Code may be referred to as a "Command Code Processing Procedure," a "Command Code Procedure," or an "LPA API (Local Profile Assistant Application Programming Interface)." Profile Download may be used interchangeably with Profile Installation.
[0077] Additionally, "Event Type" may be used as a term indicating whether a specific event is a profile download, remote profile management (e.g., deletion, activation, deactivation, replacement, update, etc.), or other profile or eUICC management / processing commands, and may be named as Operation Type (or OperationType), Operation Class (or OperationClass), Event Request Type, Event Class, Event Request Class, etc. For any event identifier (EventID or MatchingID), the path through which the terminal obtained the event identifier (EventID or MatchingID) or the intended use (EventID Source or MatchingID Source) may be specified.
[0078] In this disclosure, "Profile Package" may be used interchangeably with "profile" or as a term representing a data object of a specific profile, and may be named Profile TLV or Profile Package TLV. If the profile package is encrypted using encryption parameters, it may be named Protected Profile Package (PPP) or Protected Profile Package TLV (PPP TLV). If the profile package is encrypted using encryption parameters that can be decrypted only by a specific eUICC, it may be named Bound Profile Package (BPP) or Bound Profile Package TLV (BPP TLV). A profile package TLV may be a data set representing information constituting a profile in the TLV(Tag, Length, Value) format.
[0079] In the present disclosure, an "extended storage encrypted profile (ESEP)" is data obtained by encrypting a profile installed on an eUICC, and is characterized by being decryptable only on the eUICC and convertable into a usable profile. An extended storage encrypted profile may be generated by the eUICC by a command from software or an application installed within a terminal or electronic device to control the UICC or eUICC, such as a Local Profile Assistant (LPA). Additionally, the generated extended storage encrypted profile may be stored in an encrypted profile external storage by the LPA or the eUICC. Furthermore, an extended storage encrypted profile stored in the encrypted profile external storage may be transmitted to the eUICC by a command from the LPA, decrypted, and converted into a usable profile.
[0080] In the present disclosure, "encrypted profile external storage (Extended Storage)" is a storage that stores encrypted profiles for external storage storage and may exist inside or outside the terminal. The encrypted profile external storage may be defined by various names such as extended storage, external storage, profile external storage, first storage, etc.
[0081] In the present disclosure, the "Extended Storage Protection Function" is a function existing within the eUICC that receives a command from the LPA and performs the function of converting a profile stored in the eUICC into an encrypted profile for external storage, or converting a previously converted encrypted profile for external storage into a usable profile.
[0082] In the present disclosure, "Local Profile Management (LPM)" may be referred to as Profile Local Management, Local Management, Local Management Command, Local Command, Local Profile Management Package, Profile Local Management Package, Local Management Package, Local Management Command Package, or Local Command Package. LPM may be used to change the status (Enabled, Disabled, Deleted) of a specific profile through software installed on a terminal, to change (update) the contents of a specific profile (e.g., Profile Nickname, Profile Metadata, etc.), to create an encrypted profile for external storage, or to convert an encrypted profile for external storage into a usable profile. LPM may include one or more local management commands, in which case the profiles targeted by each local management command may be the same or different for each local management command.
[0083] In the present disclosure, "Remote Profile Management (RPM)" may be referred to as Profile Remote Management, Remote Management, Remote Management Command, Remote Command, Remote Profile Management Package (RPM Package), Profile Remote Management Package, Remote Management Package, Remote Management Command Package, or Remote Command Package. An RPM may be used to change the status (Enabled, Disabled, Deleted) of a specific profile or to update the contents of a specific profile (e.g., Profile Nickname, Profile Metadata, etc.). An RPM may include one or more remote management commands, in which case the profiles targeted by each remote management command may be the same or different for each remote management command.
[0084] In the present disclosure, "Certificate" or "Digital Certificate" may refer to a digital certificate used for asymmetric key-based mutual authentication consisting of a pair of a public key (PK) and a secret key (SK). Each certificate may include one or more public keys (PK), a public key identifier (PKID) corresponding to each public key, a certificate issuer ID of the certificate issuer (CI) that issued the certificate, and a digital signature.
[0085] In addition, the "Certificate Issuer" may be referred to as the Certification Issuer, Certificate Authority (CA), or Certification Authority.
[0086] In the present disclosure, "Public Key (PK)" and "Public Key ID (PKID)" may be used interchangeably with the same meaning to refer to a specific public key or a certificate containing the said public key, or a part of a specific public key or a part of a certificate containing the said public key, or a result of an operation (e.g., hash) of a specific public key or a result of an operation (e.g., hash) of a certificate containing the said public key, or a result of an operation (e.g., hash) of a part of a specific public key or a result of an operation (e.g., hash) of a part of a certificate containing the said public key, or a storage space where data is stored.
[0087] In the present disclosure, when certificates issued by one Certificate Issuer (first certificates) are used to issue other certificates (second certificates), or when second certificates are used to issue third or higher certificates in a linked manner, the correlation of said certificates may be referred to as a Certificate Chain or Certificate Hierarchy, and in this case, the CI certificate used for the initial certificate issuance may be referred to as the Root of Certificate, top certificate, Root CI, Root CI Certificate, Root CA, Root CA Certificate, etc.
[0088] In this disclosure, "mobile operator" may refer to a business entity that provides telecommunication services to a terminal, and may collectively refer to the mobile operator's business supporting system (BSS), operational supporting system (OSS), point of sale terminal, and other IT systems. Furthermore, in this disclosure, "mobile operator" is not limited to representing a single specific business entity that provides telecommunication services, but may also be used as a term referring to a group or association or consortium of one or more business entities, or a representative representing said group or consortium. Additionally, in this disclosure, "mobile operator" may be named as an operator (OP, or Op.), a mobile network operator (MNO), a mobile virtual network operator (MVNO), a service provider (or SP), a profile owner (PO), etc., and each mobile operator may set or be assigned at least one name and / or unique identifier (OID). If a telecommunications business operator refers to a group or association of one or more business entities or an agency, the name or unique identifier of any group or association or agency may be a name or unique identifier shared by all business entities belonging to said group or association or all business entities cooperating with said agency.
[0089] In the present disclosure, "AKA" may represent Authentication and Key agreement and may represent an authentication algorithm for accessing 3GPP and 3GPP2 networks.
[0090] In the present disclosure, "K" may be a cryptographic key value stored in an eUICC used in an AKA authentication algorithm.
[0091] In the present disclosure, "OPC" may be a parameter value that can be stored in an eUICC used in an AKA authentication algorithm.
[0092] In the present disclosure, "NAA" is a Network Access Application, and may be an application such as a USIM or ISIM stored in a UICC for connecting to a network. NAA may be a network access module.
[0093] In this disclosure, the "indicator" may be used to indicate whether any function, setting, or operation is required or not, or to indicate the function, setting, or operation itself. Additionally, in this disclosure, the indicator may be expressed in various forms such as a string, an alphanumeric string, a true / false operator (Boolean - TRUE or FALSE), a bitmap, an array, or a flag, and other expressions having the same meaning may be used in combination.
[0094] Hereinafter, a method and apparatus for installing and managing an eUICC profile according to various embodiments of the present disclosure will be described in detail with reference to FIGS. 1 to 6.
[0095] FIG. 1 illustrates a method for connecting a terminal to a mobile communication network using a UICC equipped with a fixed profile on the terminal according to one embodiment of the present disclosure.
[0096] Referring to FIG. 1, according to one embodiment of the present disclosure, a UICC (120) may be inserted into a terminal (110). For example, the UICC (120) may be detachable, but is not limited thereto. For example, the UICC (120) may be pre-embedded in the terminal (110).
[0097] A fixed profile mounted on the UICC (120) may mean that the 'connection information' that allows access to a specific carrier is fixed. For example, the connection information may be an IMSI that is a subscriber identifier and a K or Ki value that is required to authenticate to the network along with the subscriber identifier.
[0098] According to various embodiments of the present disclosure, a terminal (110) may perform authentication with an authentication processing system of a mobile carrier using a UICC (120). The authentication processing system of a mobile carrier may include a home location register (HLR) or an AuC, but is not limited thereto.
[0099] According to one embodiment, the authentication process of a terminal (110) using a UICC (120) may include an AKA (Authentication and Key Agreement) process.
[0100] According to one embodiment, when the terminal (110) succeeds in authentication, it can use mobile communication services such as telephone or mobile data usage by using the mobile carrier network (130) of the mobile communication system.
[0101] FIG. 2 illustrates an example of a connection between a terminal, an activation intermediary server, a profile providing server, and a service provider according to one embodiment of the present disclosure.
[0102] Referring to FIG. 2, an eUICC (211) may be installed in the terminal (210). A profile may be installed in the eUICC (211). Additionally, an LPA (212) may be installed in the terminal (210). The eUICC (211) may be controlled by the LPA (212). A user (200) can install a profile in the eUICC (211) of each terminal or control the installed profile through the LPA (212).
[0103] According to one embodiment, an Extended Storage (213) may be installed in the terminal (210). In FIG. 2, the Extended Storage (213) is shown as being installed in the terminal (210), but it may exist outside the terminal (210). The Extended Storage (213) may store an encrypted profile for external storage storage. An encrypted profile for external storage storage is data obtained by encrypting and converting all or part of a profile installed in the eUICC (211), and has the characteristic that it can be converted into a profile that can be decrypted and used only in the corresponding eUICC (211). An encrypted profile for external storage storage may be generated by the eUICC (211) by, for example, a command from the LPA (212). Additionally, an encrypted profile for external storage storage stored in the Extended Storage (213) may be transmitted to the eUICC (211) by a command from the LPA (212) to be decrypted and converted into a usable profile.
[0104] According to one embodiment, a profile of a service provider (hereinafter referred to as "communication operator" or "operator", 240) may be installed on a terminal (210). As a result, the user (end user) (200) of the terminal (210) can receive communication services from the operator.
[0105] According to one embodiment, the operator (240) may be connected to the profile server (230). Additionally, the LPA (212) of the terminal (210) may be connected to the profile server (230) and the activation intermediary server (220). In FIG. 2, for convenience of explanation, the profile server (230) and the activation intermediary server (220) are each configured as a single server, but the specific implementation method of the profile server (230) and the activation intermediary server (220) is not limited to the example shown in FIG. 2. For example, depending on the implementation and embodiment, the profile server (230) may be configured with one or more profile servers (SM-DP+), and the activation intermediary server (220) that assists in creating a connection between a specific profile server and a terminal may also be configured with one or more activation intermediary servers (SM-DS). Hereinafter, for convenience of explanation in this disclosure, the term “single profile server” is used; however, it is obvious to those skilled in the art that the profile server mentioned below may include a plurality of server configurations as described above.
[0106] The operation and message exchange procedures of the user (200), operator (240), terminal (210), eUICC (211), LPA (212), profile server (230), and activation intermediary server (220) according to various embodiments of the present disclosure will be described in detail with reference to the drawings to be described later.
[0107] FIG. 3 illustrates a flowchart of a procedure in which a terminal according to one embodiment of the present disclosure generates an encrypted profile for external storage storage (Extended Storage Encrypted Profile, ESEP) from a profile installed on the terminal and stores the encrypted profile in an external storage (Extended Storage).
[0108] The terminal (not shown) described in FIG. 3 may include an eUICC (311), an LPA (312), and an Extended Storage (313), and the Extended Storage (313) may exist outside the terminal. Each component of the terminal and the profile server (330) described in FIG. 3 can be understood in correspondence with each component described in FIG. 2. For example, the terminal (not shown), eUICC (311), LPA (312), Extended Storage (313), and profile server (330) shown in FIG. 3 may correspond to the terminal (210), eUICC (211), LPA (212), Extended Storage (213), and profile server (230) of FIG. 2, respectively. Meanwhile, although the eUICC (311), LPA (312), and Extended Storage (313) are described separately below, this can be described not only by the operation of each component but also by the operation of the terminal including them. The relationship between the terminal and the components constituting the terminal, as described above, can be applied equally to various embodiments of the present disclosure.
[0109] In step 3001, the LPA (312) can check whether a specific profile installed in the eUICC (311) (e.g., a profile selected by a user's request, a first profile) can be converted into an encrypted profile for external storage. Such a checking operation may be performed selectively on a profile-by-profile basis or according to a user request. Additionally, if the LPA (312) has previously checked whether the profile can be converted into an encrypted profile for external storage, the checking operation may not be performed. For example, information regarding whether the profile can be converted into an encrypted profile for external storage, or information for checking this, may be included in the profile metadata of the profile, and the LPA (312) can check whether the profile can be converted into an encrypted profile for external storage based on the information included in the profile metadata. The above checking method is an example and is not limited thereto. Additionally, if the profile is in an enabled state, LPA (312) can disable the profile.
[0110] In step 3003, LPA (312) may request eUICC (311) to convert a profile installed in eUICC (311) into an encrypted profile for external storage and to deliver it to LPA (312). The request for conversion and delivery into an encrypted profile for external storage may be transmitted by LPA (312) to eUICC (311) using an ES10x (ES10b or ES10c) related message. For example, the related message may be an ES10x.CreateESEP or ES10x.GetESEP message, but is not limited thereto. The request for conversion and delivery into an encrypted profile for external storage may include at least one of the following as an argument.
[0111] - Profile identifier (ICCID) of the profile requesting conversion and delivery
[0112] - Indicator for deleting encrypted profile for external storage after conversion and delivery: Instructs the eUICC (311) to delete the converted encrypted profile for external storage after converting the requested profile for conversion and delivery into an encrypted profile for external storage and providing the converted encrypted profile for external storage to the LPA (312).
[0113] In step 3005, eUICC (311) can generate an encrypted profile for external storage based on the profile requested by LPA (312). For example, eUICC (311) can generate at least one of the following.
[0114] - Encrypted profile encryption key for external storage: Can be used to create an encrypted profile for external storage
[0115] - Decryption key for encrypted profile for external storage: This can be used to decrypt, restore, or reinstall the profile in the eUICC (311). It may be the same as the encryption key for the encrypted profile for external storage.
[0116] - Encrypted profile for external storage: Includes at least one of the encrypted profile, a profile identifier, and a hash value using the profile identifier as an input.
[0117] In step 3005, eUICC (311) generates an encrypted profile for external storage based on the profile requested by LPA (312) and may optionally store at least one of the following.
[0118] - Encrypted profile encryption key for external storage
[0119] - Decryption key for encrypted profiles stored in external storage. May be the same as the encryption key for encrypted profiles stored in external storage.
[0120] - Encrypted profile for external storage
[0121] - Profile data not included in encrypted profiles stored in external storage: network authentication key, user sensitive information, carrier sensitive information, etc.
[0122] - Profile identifier (ICCID) of the corresponding profile
[0123] - Hash value with the corresponding profile identifier as input
[0124] - Profile metadata of the corresponding profile
[0125] - Certificate and eUICC private key information used during profile installation: The eUICC certificate and corresponding eUICC private key (SK.EUICC.KA) used during profile installation, and may be the parent certificate information of the eUICC certificate's certificate chain.
[0126] The storage of the above information may also be performed in a later step after step 3005.
[0127] eUICC (311) can optionally change the state of the profile (the profile stored in the eUICC used to create the encrypted profile for external storage) after or during the process of creating the profile for external storage. For example, the state of the changed profile may be transformed or exported.
[0128] Changes to the above information (changes to the profile status, changes to profile status information) may be performed in a later step.
[0129] Additionally, eUICC (311) may optionally generate a notification if the profile metadata has an encrypted profile conversion or extraction notification setting for external storage storage. The generation of the notification may also be performed in another step.
[0130] Additionally, eUICC (311) may optionally delete the profile used to create the encrypted profile for external storage storage. Such deletion may be performed in a later step or may not be performed.
[0131] In step 3007, the eUICC (311) may transmit the encrypted profile for external storage created in step 3005 to the LPA (312). Additionally, if a notification for the profile has been created, the notification may be optionally included in the transmission. The notification may be transmitted via separate signaling in a later step. Additionally, the eUICC (311) may transmit to the LPA (312) and optionally delete the encrypted profile for external storage stored within the eUICC. Furthermore, the deletion operation may be performed when the LPA (312) requests the conversion and transmission of the encrypted profile for external storage, including a deletion indicator after conversion and transmission in step 3003, or it may be performed regardless of the existence of such indicator. The deletion may or may not be performed in a later step.
[0132] In step 3009, LPA (312) can store the encrypted profile for external storage. LPA can store the encrypted profile for external storage in Extended Storage (313).
[0133] In step 3011, the LPA (312) may request the eUICC (311) to delete the encrypted profile for external storage. The request to delete the encrypted profile for external storage may be transmitted by the LPA (312) to the eUICC (311) using an ES10b related message. For example, the related message may be an ES10b.DeleteESEP or ES10b.ConfirmESEP message, but is not limited thereto. The request to delete the encrypted profile for external storage may include at least one of the following as an argument.
[0134] - Profile identifier (ICCID) of the profile requesting deletion
[0135] - Hash value with the corresponding profile identifier as input
[0136] According to one embodiment, in step 3013, the eUICC (311) may delete the encrypted profile for external storage requested by the LPA (312). Additionally, at least one of the following may be optionally stored.
[0137] - Encrypted profile encryption key for external storage
[0138] - Decryption key for encrypted profiles stored in external storage. May be the same as the encryption key for encrypted profiles stored in external storage.
[0139] - Profile data not included in encrypted profiles stored in external storage: network authentication key, user sensitive information, carrier sensitive information, etc.
[0140] - Profile identifier (ICCID) of the corresponding profile
[0141] - Hash value with the corresponding profile identifier as input
[0142] - Profile metadata of the corresponding profile
[0143] - Certificate and eUICC private key information used during profile installation: The eUICC certificate and corresponding eUICC private key (SK.EUICC.KA) used during profile installation, and may be the parent certificate information of the eUICC certificate's certificate chain.
[0144] The storage of the above information may be performed at another stage, and if it has already been performed, it may not be performed.
[0145] Additionally, eUICC (311) may optionally delete the profile used to create the encrypted profile for the deleted external storage.
[0146] eUICC (311) can selectively change the state of the profile after deleting the encrypted profile for external storage, or during the deletion process. For example, the changed state of the profile may be converted or exported.
[0147] Changes to the above information (changes to the state or changes to the state information) may be performed at other stages, and may not be performed if they have already been performed.
[0148] Additionally, eUICC (311) may optionally generate a notification if the profile metadata has an encrypted profile conversion or extraction notification setting for external storage storage. The generation of the notification may be performed in a different step, and may not be performed if it has already been performed.
[0149] Additionally, eUICC (311) may optionally delete the profile used to create the encrypted profile for external storage storage. This deletion may be performed at another stage, and may not be performed if it has already been performed.
[0150] According to one embodiment, in step 3015, the eUICC (311) may transmit the result of deleting the encrypted profile for external storage to the LPA (312). Additionally, if a notification for converting or extracting the encrypted profile for external storage has been generated, the notification may be optionally included and transmitted.
[0151] Steps 3011, 3013, and 3015 of Fig. 3 are optional steps that may not be performed.
[0152] In step 3017, the LPA (312) can request and receive notifications stored in the eUICC (311). If the eUICC (311) also generated a notification for converting or extracting an encrypted profile for external storage in the step illustrated in FIG. 3, the eUICC (311) can provide the notification to the LPA (312). Additionally, the eUICC (311) can optionally delete the encrypted profile for external storage or the profile used to generate the encrypted profile for external storage.
[0153] In step 3019, LPA (312) can forward the notification received from eUICC (311) to the profile server (330).
[0154] FIG. 4 illustrates a flowchart of a procedure in which a terminal according to one embodiment of the present disclosure generates an encrypted profile for external storage storage (Extended Storage Encrypted Profile, ESEP) from a profile installed on the terminal and stores the encrypted profile in an external storage (Extended Storage).
[0155] The terminal (not shown) described in FIG. 4 may include an eUICC (411), an LPA (412), and an Extended Storage (413), and the Extended Storage (413) may exist outside the terminal. Each configuration of the terminal and the profile server (430) described in FIG. 3 can be understood in correspondence with each configuration described in FIG. 2. For example, the terminal (not shown), eUICC (411), LPA (412), Extended Storage (413), and profile server (430) shown in FIG. 4 may correspond to the terminal (210), eUICC (211), LPA (212), Extended Storage (213), and profile server (230) of FIG. 2, respectively.
[0156] In step 4001, the LPA (412) may request the deletion of a profile installed on the eUICC (411). The request for profile deletion may be transmitted by the LPA (412) to the eUICC (411) using an ES10x (ES10b or ES10c) related message. For example, the related message may be an ES10c.DeleteProfile or ES10c.EuiccMemoryReset message, but is not limited thereto. The ES10c.DeleteProfile message may include the profile identifier (ICCID) of the profile requesting deletion.
[0157] In step 4003, the eUICC (411) can delete the profile requested by the LPA (412). After deleting at least one profile, the eUICC (411) can generate a deletion notification according to the notification settings configured in the metadata of the profile. If the profile requested for deletion is an encrypted profile for external storage, the eUICC (411) can generate a notification using the profile metadata of the profile stored in steps 3005 to 3013 of FIG. 3, or the certificate and eUICC secret key information used when installing the profile. The notification may be a profile deletion notification (DeleteNotification). Additionally, if the profile requested for deletion is an encrypted profile for external storage, the eUICC (411) can delete the information stored in steps 3005 to 3013 of FIG. 3 together.
[0158] In step 4005, the eUICC (411) can transmit the profile deletion result to the LPA (412). Additionally, it may optionally transmit the generated notification.
[0159] In step 4007, the LPA (412) may delete the encrypted profile for external storage stored in Extended Storage (413). This step may be performed independently of the steps described in FIG. 4. For example, the LPA (412) may instruct the deletion through information, a message, or an indicator instructing the deletion of the encrypted profile for external storage stored in extended storage (413).
[0160] In step 4009, the LPA (412) can request and receive a notification stored in the eUICC (411). If the eUICC (411) has generated a notification in the step illustrated in FIG. 4, the eUICC (311) can provide the notification to the LPA (312).
[0161] In step 4011, the LPA (412) may transmit the notification received from the eUICC (411) to the profile server (430). Actions regarding the notification may be omitted. FIG. 5 illustrates the functional configuration of a terminal according to an embodiment of the present disclosure.
[0162] Referring to FIG. 5, a terminal according to various embodiments of the present disclosure may include a transceiver (510) and a control unit (or processor) (520). Additionally, the terminal may include a UICC (530). For example, the UICC (530) may be inserted into the terminal, but is not limited thereto. For example, the UICC (530) may include an eUICC embedded in the terminal.
[0163] According to one embodiment, the transmitting and receiving unit (510) can transmit and receive signals, information, data, etc. to and from the profile server.
[0164] According to one embodiment, the processor (520) may include components for overall control of the terminal. The processor (520) may control the overall operation of the terminal according to various embodiments of the present disclosure. For example, the processor (520) may perform operations related to an encrypted profile for external storage according to various embodiments of the present disclosure. For example, the processor (520) may perform operations for generating and managing an encrypted profile for external storage and / or related information, status, etc. In the present disclosure, the processor (520) may be referred to as a control unit. According to one embodiment of the present disclosure, the processor (520) may include at least one processor.
[0165] According to one embodiment of the present disclosure, the UICC (530) can download a profile and install a profile. Additionally, the UICC (530) can manage a profile. For example, the UICC (530) can perform operations related to an encrypted profile for external storage according to various embodiments of the present disclosure. For example, the UICC (530) can perform operations for creating and managing an encrypted profile for external storage and / or related information, status, etc.
[0166] According to one embodiment, the UICC (530) may operate under the control of the processor (520). Alternatively, the UICC (530) may include a processor or controller for installing a profile, or may have an application installed. Part of the application may be installed on the processor (520).
[0167] Although not illustrated in the drawings, a terminal according to an example of the present disclosure may further include a storage unit or memory. According to one embodiment, the storage unit or memory of the terminal may store data such as a basic program, an application program, and setting information for the operation of the terminal. Additionally, the storage unit may include at least one storage medium among a Flash Memory Type, a Hard Disk Type, a Multimedia Card Micro Type, a card type memory (e.g., SD or XD memory, etc.), magnetic memory, a magnetic disk, an optical disk, a Random Access Memory (RAM), a Static Random Access Memory (SRAM), a Read-Only Memory (ROM), a Programmable Read-Only Memory (PROM), and an Electrically Erasable Programmable Read-Only Memory (EEPROM). Additionally, the processor (620) may perform various operations using various programs, content, data, etc. stored in the storage unit.
[0168] FIG. 6 illustrates the functional configuration of a profile server according to one embodiment of the present disclosure.
[0169] Referring to FIG. 6, a profile server according to various embodiments of the present disclosure may include a transmitting and receiving unit (610) and a control unit (or processor) (620).
[0170] According to one embodiment, the transmitting and receiving unit (610) can transmit and receive signals, information, data, etc. with a terminal, an activation intermediary server, or a business operator.
[0171] According to one embodiment, the processor (620) may include components for overall control of the profile server. The processor (620) may control the overall operation of the profile server according to various embodiments of the present disclosure. For example, the processor (620) may perform operations related to an encrypted profile for storage in an external storage according to various embodiments of the present disclosure. In the present disclosure, the processor (620) may be referred to as a control unit. According to one embodiment of the present disclosure, the processor (620) may include at least one processor.
[0172] Although not illustrated in the drawings, a profile server according to one example of the present disclosure may further include a storage unit or memory. The storage unit or memory of the profile server may store data such as a basic program, an application program, and configuration information for the operation of the profile server. Additionally, the storage unit may include at least one storage medium selected from a Flash Memory Type, a Hard Disk Type, a Multimedia Card Micro Type, a card-type memory (e.g., SD or XD memory), magnetic memory, a magnetic disk, an optical disk, a Random Access Memory (RAM), a Static Random Access Memory (SRAM), a Read-Only Memory (ROM), a Programmable Read-Only Memory (PROM), and an Electrically Erasable Programmable Read-Only Memory (EEPROM). Additionally, the processor (620) may perform various operations using various programs, content, data, etc. stored in the storage unit.
[0173] According to one embodiment of the present disclosure, a method is provided to be performed by a terminal of a wireless communication system. The method comprises the steps of: transmitting a first message to a profile server containing functional information related to post-quantum cryptography (PQC) supported by an eSIM (embedded subscriber identity module) of the terminal; and receiving, in response to the first message, a second message from the profile server containing PQC information to be used by the eSIM.
[0174] According to one embodiment of the present disclosure, a method is provided to be performed by a profile server of a wireless communication system. The method comprises the steps of receiving a first message from a terminal containing functional information related to a PQC supported by the eSIM of the terminal, and transmitting a second message to the terminal containing PQC information to be used by the eSIM in response to the first message.
[0175] According to one embodiment of the present disclosure, a terminal of a wireless communication system is provided. The terminal includes a transceiver and at least one processor coupled to the transceiver. The at least one processor controls the transceiver to transmit a first message containing functional information related to a PQC supported by the eSIM of the terminal to a profile server, and controls the transceiver to receive, in response to the first message, a second message containing PQC information to be used by the eSIM from the profile server.
[0176] According to one embodiment of the present disclosure, a profile server of a wireless communication system is provided. The profile server includes a transceiver and at least one processor coupled to the transceiver. The at least one processor controls the transceiver to receive a first message from a terminal containing functional information related to a PQC supported by the eSIM of the terminal, and controls the transceiver to transmit a second message to the terminal containing PQC information to be used by the eSIM in response to the first message.
[0177] According to one embodiment of the present disclosure, when a terminal in a communication system communicates with a profile server using a quantum-resistant encryption method and wants to download a profile, the terminal provides the profile server with a quantum-resistant encryption method and parameters supported by the terminal, and can receive from the profile server a method supported identically by both the terminal and the profile server, and can generate a common session key using the simultaneously supported quantum-resistant encryption method and download and install the profile.
[0178] According to one embodiment of the present disclosure, in a communication system, a profile server receives a quantum-resistant encryption method and parameters supported by the terminal from the terminal, selects a method supported identically by the profile server and the terminal and provides it to the terminal, and generates a common session key using the simultaneously supported quantum-resistant encryption method, encrypts the profile, and transmits it to the terminal.
[0179] In the specific embodiments of the present disclosure described above, the components included in the disclosure are expressed in a singular or plural form according to the specific embodiments presented. However, the singular or plural expression is selected to suit the situation presented for convenience of explanation, and the present disclosure is not limited to singular or plural components; even if a component is expressed in the plural form, it may be composed of a singular form, and even if a component is expressed in the singular form, it may be composed of a plural form.
[0180] Meanwhile, although specific embodiments have been described in the detailed description of the present disclosure, it is understood that various modifications are possible within the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be defined by the claims set forth below as well as equivalents thereof.
[0181] The various embodiments of the present disclosure and the terms used therein are not intended to limit the technology described in the present disclosure to specific embodiments and should be understood to include various modifications, equivalents, and / or substitutions of said embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar components. A singular expression may include a plural expression unless the context clearly indicates otherwise. In the present disclosure, expressions such as "A or B," "at least one of A and / or B," "A, B or C," or "at least one of A, B and / or C" may include all possible combinations of items listed together. Expressions such as "first," "second," "first," or "second" may modify said components regardless of order or importance and are used only to distinguish one component from another and do not limit said components. Where it is stated that a certain (e.g., 1st) component is "(functionally or telecommunicationally) connected" or "connected" to another (e.g., 2nd) component, the certain component may be directly connected to the other component or connected through the other component (e.g., 3rd component).
[0182] As used in this disclosure, the term "module" includes a unit composed of hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be a component formed integrally, or a minimum unit or part thereof that performs one or more functions. For example, a module may be composed of an application-specific integrated circuit (ASIC).
[0183] Various embodiments of the present disclosure may be implemented as software (e.g., a program) containing instructions stored in a machine-readable storage medium (e.g., internal memory or external memory) that is readable by a machine (e.g., a computer). The machine may include a terminal according to various embodiments of the present disclosure, which is a device capable of calling instructions stored from the storage medium and operating according to the called instructions. When an instruction is executed by a processor (e.g., the processor (520) of FIG. 5 or the processor (620) of FIG. 6), the processor may perform a function corresponding to the instruction directly or using other components under the control of the processor. The instruction may include code generated or executed by a compiler or an interpreter.
[0184] A device-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' means only that the storage medium does not contain a signal and is tangible, and does not distinguish whether data is stored semi-permanently or temporarily in the storage medium.
[0185] Methods according to the various embodiments disclosed in this disclosure may be provided as included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or online through an application store (e.g., Play Store™). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created in a storage medium such as the memory of a manufacturer's server, an application store's server, or a relay server.
[0186] Each component (e.g., module or program) according to various embodiments may be composed of a singular or multiple entities, and some of the aforementioned sub-components may be omitted, or other sub-components may be additionally included in various embodiments. Generally or additionally, some components (e.g., module or program) may be integrated into a single entity to perform the functions performed by each of the respective components prior to integration in the same or similar manner. The operations performed by the module, program, or other components according to various embodiments may be executed sequentially, in parallel, iteratively, or heuristically, or at least some operations may be executed in a different order, omitted, or other operations added.
Claims
1. In a method performed by a device, A step to verify a request for an ESEP (extended storage encrypted profile) from the LPA (local profile assistant); A step of generating the ESEP based on a request for the ESEP; A step of storing the above ESEP in an external storage; A step of confirming a request from the above LPA to delete information related to the above ESEP stored in the eUICC (embedded universal integrated circuit card); and A method comprising the step of deleting information related to the ESEP stored in the eUICC based on a request to delete information related to the ESEP.
2. In Paragraph 1, A method in which, after storing the above ESEP in the above external storage, the above LPA transmits the above deletion request to the above eUICC.
3. In Paragraph 1, Information related to the above ESEP is a method corresponding to at least one of the profile used to generate the above ESEP or the encrypted ESEP.
4. In Paragraph 1, A method further comprising the step of storing profile meter data of a profile associated with the ESEP based on a request from the ESEP.
5. In Paragraph 4, A step of confirming a request from the LPA to delete a profile associated with the ESEP stored in the external storage; and A method further comprising the step of accepting a request to delete a profile associated with the ESEP in the above eUICC.
6. In Paragraph 5, A method further comprising the step of deleting profile-related information stored in the eUICC in relation to the creation of the ESEP based on a request to delete a profile related to the ESEP.
7. In Paragraph 5, A step of providing information directing acceptance from the eUICC to the LPA based on a deletion request of a profile associated with the above ESEP; and It further includes the step of deleting the ESEP stored in the external storage based on information directing the acceptance, and A method in which an ESEP stored in the above external storage is deleted from the above external storage without being restored to the above eUICC.
8. In Paragraph 5, A method further comprising the step of generating a profile deletion notification for the deletion of a profile associated with the ESEP based on the profile metadata.
9. In the device, External storage for storing ESEP (extended storage encrypted profile); and It includes an eUICC (embedded universal integrated circuit card), The above eUICC is, Check the request for the above ESEP (extended storage encrypted profile) from the LPA (local profile assistant), and The ESEP is generated based on a request for the ESEP, and After the above ESEP is stored in the external storage, a request from the LPA to delete information related to the above ESEP stored in the eUICC is confirmed, and A device that controls the deletion of information related to the ESEP stored in the eUICC based on a request to delete information related to the ESEP.
10. In Paragraph 9, The information related to the above ESEP is a device corresponding to at least one of the profile used to generate the above ESEP or the encrypted ESEP.
11. In Paragraph 9, the above eUICC is, A device that stores profile meter data of a profile associated with the ESEP based on a request from the ESEP.
12. In the 11th, the above eUICC is, Confirming the deletion request from the above LPA for the profile associated with the above ESEP stored in the above external storage, and A device that accepts a request to delete a profile associated with the ESEP in the above eUICC.
13. In Paragraph 12, the above eUICC is, A device for deleting profile-related information stored in the eUICC in relation to the creation of the ESEP based on a request to delete a profile related to the ESEP.
14. In Paragraph 12, The above eUICC provides information directing acceptance to the above LPA based on a deletion request of a profile associated with the above ESEP, and The above LPA deletes the ESEP stored in the external storage based on the information directing the acceptance, and, A device in which the ESEP stored in the external storage is deleted from the external storage without being restored to the eUICC.
15. In Paragraph 12, the above eUICC is, A device that generates a profile deletion notification for the deletion of a profile associated with the ESEP based on the profile metadata.