WO2016127435A1 - 一种profile下载和激活方法、集成电路卡及系统 - Google Patents

一种profile下载和激活方法、集成电路卡及系统 Download PDF

Info

Publication number
WO2016127435A1
WO2016127435A1 PCT/CN2015/073118 CN2015073118W WO2016127435A1 WO 2016127435 A1 WO2016127435 A1 WO 2016127435A1 CN 2015073118 W CN2015073118 W CN 2015073118W WO 2016127435 A1 WO2016127435 A1 WO 2016127435A1
Authority
WO
WIPO (PCT)
Prior art keywords
profile
integrated circuit
circuit card
euicc
activated
Prior art date
Application number
PCT/CN2015/073118
Other languages
English (en)
French (fr)
Inventor
高林毅
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to PCT/CN2015/073118 priority Critical patent/WO2016127435A1/zh
Priority to CN201580075336.7A priority patent/CN107211385B/zh
Publication of WO2016127435A1 publication Critical patent/WO2016127435A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/30Security of mobile devices; Security of mobile applications
    • H04W12/35Protecting application or service provisioning, e.g. securing SIM application provisioning
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/40Security arrangements using identity modules
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/61Time-dependent
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W60/00Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • H04W8/20Transfer of user or subscriber data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/02Terminal devices
    • H04W88/06Terminal devices adapted for operation in multiple networks or having at least two operational modes, e.g. multi-mode terminals

Definitions

  • the present invention relates to the field of mobile communications technologies, and in particular, to a profile download and activation method, an integrated circuit card, and a system.
  • a Universal Integrated Circuit Card is a general term for smart cards that define physical and electrical characteristics.
  • the UICC is mainly used to store information such as user information, an authentication key, and a charging policy.
  • the UICC can include multiple logic modules, such as a Subscriber Identity Module (SIM), a Universal Subscriber Identity Module (USIM), and an IP Multimedia Service Identity Module (IPM). ), as well as other non-telecom application modules such as electronic signature authentication, e-wallet.
  • SIM Subscriber Identity Module
  • USIM Universal Subscriber Identity Module
  • IPM IP Multimedia Service Identity Module
  • the logic modules in the UICC may exist separately or multiple simultaneously. Different user terminals may select and use corresponding logic modules according to the type of the wireless access network.
  • the embedded universal integrated circuit card (eUICC) is formed by embedding the UICC into the terminal through encapsulation or soldering.
  • the eUICC is inconvenient to plug and unplug, and cannot be replaced as the UICC.
  • At least one profile is usually installed in the eUICC (Chinese translation can be a profile, a user information set, an attribute parameter set or an attribute data set, etc.), and a profile refers to a collection of file structures, data, and applications, including one or more network accesses.
  • Application and corresponding network access credentials such as International Mobile Subscriber Identity (IMSI) and Key Identity (KI).
  • the prior art has already defined the process of how to download and activate the profile.
  • the process of downloading and activating the profile specified by the prior art only considers a scenario in which only one activation profile is in the eUICC, when allowing multiple activation profiles in the eUICC at the same time.
  • an embodiment of the present invention provides a profile downloading and activating method, a chip, and a system to solve the technical problem of how to download and activate a profile when there are multiple active profiles in the eUICC.
  • an embodiment of the present invention provides a profile downloading method, which is applied to an embedded universal integrated circuit card eUICC installed with an activated first profile and an activated second profile, including: eUICC receiving profile manager PM through The data connection establishment request sent by the profile, the eUICC determines whether the first profile meets the preset condition: if the first profile meets the preset condition, the eUICC uses the first profile to establish a data connection between the eUICC and the PM; The eUICC determines whether the second profile meets the preset condition: if the second profile meets the preset condition, the eUICC uses the second profile to establish a data connection between the eUICC and the PM, and the eUICC downloads a new profile through the data connection. .
  • the eUICC further includes an inactive third profile, where the eUICC further includes: if the second profile does not meet the preset condition, before the eUICC downloads the new profile by using the data connection.
  • the eUICC determines whether the third profile meets the preset condition; if the third profile meets the preset condition, the eUICC activates the third profile, and uses the third profile to establish a data connection between the eUICC and the PM.
  • the number of the first profiles is one, and the number of the second profiles is multiple, the first profile and the second
  • the profile is set with a priority; if the second profile meets the preset condition, the eUICC uses the second profile to establish a data connection between the eUICC and the PM, including: if only one second profile meets the preset condition, the usage meets the preset
  • the second profile of the condition establishes a data connection between the eUICC and the PM; if at least two second profiles meet the preset condition, the eUICC establishes between the eUICC and the PM by using the second profile that meets the preset condition and has the highest priority. Data connection.
  • the preset condition includes any one of the following: A packet data connection has been established and is dedicated to establishing a data connection between the eUICC and the PM.
  • an embodiment of the present invention provides a profile activation method, which is applied to an embedded universal integrated circuit card eUICC installed with two activated profiles and at least one inactive profile, and two activated profiles are set with priority. , including: eUICC receives the profile sent by the profile manager PM The activation request, the profile activation request is used to request activation of the target profile, the target profile is one of the inactive profiles, and the eUICC determines whether the number of currently activated profiles reaches the maximum allowed: if yes, the eUICC deactivates the active profile priority. A lower profile and activate the target profile; if not, the eUICC activates the target profile.
  • the method further includes: eUICC sequentially attaching the currently activated profile to the network according to the priority of the currently activated profile.
  • an embodiment of the present invention provides a profile deactivation method, including: an embedded universal integrated circuit card eUICC receives a profile deactivation request sent by a profile manager PM, and a profile deactivation request is used to request to deactivate a target profile.
  • the target profile is an activated profile in the eUICC, and the eUICC determines whether there are other activated profiles in the eUICC other than the target profile: if yes, the eUICC deactivates the target profile; if not, the eUICC deactivates the target profile, activates the eUICC The standby profile; the eUICC requests the terminal device to restart the eUICC.
  • the standby profile is a preset active profile when the currently activated profile in the eUICC loses the network connection.
  • the method further includes: the eUICC attaching the currently activated profile to the network.
  • an embodiment of the present invention provides a method for maintaining a network connection, where the embedded universal integrated circuit card eUICC is installed with an activated first profile, an activated second profile, and an inactive standby profile.
  • the profile and the second profile are set with a priority, and the eUICC receives the first notification message sent by the terminal device, where the first notification message is used to notify the eUICC that the first profile loses the network connection; the eUICC sends the connection establishment message to the terminal device, and the connection establishment message is sent.
  • the eUICC deactivates the lower priority profile in the first profile and the second profile, and activates the standby profile; the eUICC requests the terminal device to restart the eUICC.
  • the network connection is lost without network coverage or lost data connection to the network.
  • the eUICC before the eUICC sends the connection setup message to the terminal device, the eUICC further includes: the eUICC confirms that the first profile loses the network connection for more than The first threshold; or the eUICC confirms that the number of times the network connection fails to be established using the first profile exceeds a second threshold.
  • an embodiment of the present invention provides an integrated circuit card, in which an activated first profile and an activated second profile are installed, including: a receiving unit, configured to receive a profile manager PM through the first profile.
  • the data connection establishment request is sent;
  • the determining unit is configured to determine whether the first profile meets the preset condition, and when the first profile does not meet the preset condition, determine whether the second profile meets the preset condition;
  • the connection establishing unit is configured to: When the first profile meets the preset condition, the first profile is used to establish a data connection between the integrated circuit card and the PM; when the first profile does not meet the preset condition, and the second profile meets the preset condition, the second profile is established.
  • a data connection between the integrated circuit card and the PM a download unit for downloading a new profile over the data connection.
  • the integrated circuit card is further configured with an inactive third profile
  • the determining unit is further configured to: when the first profile and the second profile do not meet the preset condition Determining whether the third profile meets the preset condition;
  • the connection establishing unit is further configured to: when the first profile and the second profile do not meet the preset condition, and the third profile meets the preset condition, activate the third profile, and use the first The three profile establishes a data connection between the integrated circuit card and the PM.
  • the number of the first profiles is one, and the number of the second profiles is multiple, the first profile and the second The profile is set with a priority;
  • the connection establishing unit is configured to establish a data connection between the integrated circuit card and the PM by using the second profile when the first profile does not meet the preset condition, and the second profile meets the preset condition, including: connecting The establishing unit is configured to establish a data connection between the integrated circuit card and the PM by using the second profile that meets the preset condition when only one second profile meets the preset condition; and when at least two second profiles meet the preset condition, A data connection between the integrated circuit card and the PM is established using a second profile that meets the preset conditions and has the highest priority.
  • the preset condition includes any one of the following: A packet data connection has been established and is dedicated to establishing a data connection between the integrated circuit card and the PM.
  • an embodiment of the present invention provides an integrated circuit card, where an integrated circuit card is installed with two activated profiles and at least one inactive profile, and two activated profiles are set with priorities, including: a receiving unit, Receiving a profile activation request sent by the profile manager PM, the profile activation request is used to request activation of the target profile, and the target profile is one of the inactive profiles; the determining unit is configured to determine whether the number of currently activated profiles reaches the maximum allowed value. ; activate and deactivate the unit to deactivate the activation when the number of currently active profiles reaches the maximum allowed The lower priority profile in the profile, and the target profile is activated; when the number of currently activated profiles does not reach the maximum allowed, the target profile is activated.
  • the integrated circuit card further includes: a network attaching unit, configured to sequentially attach the currently activated profile to the network according to a priority of the currently activated profile.
  • an embodiment of the present invention provides an integrated circuit card, including: a receiving unit, configured to receive a profile deactivation request sent by a profile manager PM, and a profile deactivation request for requesting to deactivate a target profile, where the target profile is An activated profile in the integrated circuit card; a determining unit for determining whether there is another active profile in the integrated circuit card other than the target profile; and an activation and deactivation unit for using the integrated circuit card in addition to the target profile
  • the target profile is deactivated; when there is no other active profile in the integrated circuit card except the target profile, the target profile is activated to activate the standby profile in the integrated circuit card; the sending unit is used to the terminal device Request to restart the IC card.
  • the standby profile is a preset active profile when the currently activated profile in the integrated circuit card loses the network connection.
  • the integrated circuit card further includes: a network attaching unit, configured to attach the currently activated profile to the network.
  • an embodiment of the present invention provides an integrated circuit card, where an activated first profile, an activated second profile, and an inactive standby profile are installed, and the first profile and the second profile are set with priority.
  • a receiving unit configured to receive a first notification message sent by the terminal device, where the first notification message is used to notify the first profile of the integrated circuit card to lose the network connection, and the sending unit is configured to send a connection establishment message to the terminal device, and connect Establishing a message for establishing a network connection by using the second profile; and activating and deactivating the unit, when the second profile loses the network connection, deactivating the lower priority profile in the first profile and the second profile and activating the standby profile;
  • the sending unit is further configured to request the terminal device to restart the integrated circuit card.
  • the network connection is lost without network coverage or loss of data connection with the network.
  • the integrated circuit card further includes a confirmation unit, where the sending unit sends the connection to the terminal device Before the message is confirmed, the time when the first profile loses the network connection exceeds the first threshold, or the number of times the network connection fails to be established using the first profile fails to exceed the second threshold.
  • an embodiment of the present invention provides an integrated circuit card, in which an activated first profile and an activated second profile are installed, including: a receiver, configured to receive a profile manager PM through the first profile. Sending a data connection establishment request, and downloading a new profile through a data connection between the integrated circuit card and the PM; the processor is configured to determine whether the first profile meets a preset condition, and if the first profile meets the preset condition, use The first profile establishes a data connection between the integrated circuit card and the PM; if the first profile does not meet the preset condition, it determines whether the second profile meets the preset condition, and if the second profile meets the preset condition, the second profile is used. Establishing a data connection between the integrated circuit card and the PM; a memory for storing the program code; and a communication bus for connecting the receiver, the processor, and the memory.
  • the integrated circuit card further includes an inactive third profile, where the processor is further configured to: if the first profile and the second profile do not meet the preset condition And determining whether the third profile meets the preset condition; if the third profile meets the preset condition, the third profile is activated, and the third profile is used to establish a data connection between the integrated circuit card and the PM.
  • the number of the first profiles is one, and the number of the second profiles is multiple, the first profile and the second
  • the profile is set with a priority
  • the processor is configured to establish a data connection between the integrated circuit card and the PM by using the second profile if the second profile meets the preset condition
  • the method includes: the processor is configured to: if only one second profile meets the preset condition And establishing a data connection between the integrated circuit card and the PM by using the second profile that meets the preset condition; if at least two second profiles meet the preset condition, using the second condition that meets the preset condition and has the highest priority
  • the profile establishes a data connection between the integrated circuit card and the PM.
  • the preset condition includes any one of the following: A packet data connection has been established and is dedicated to establishing a data connection between the integrated circuit card and the PM.
  • an embodiment of the present invention provides an integrated circuit card, where an integrated circuit card is installed with two activated profiles and at least one inactive profile, and two activated profiles are set with priorities, including: a receiver, Receiving a profile activation request sent by the profile manager PM, the profile activation request is used to request activation of the target profile, the target profile is one of the inactive profiles, and the processor is configured to determine whether the number of currently activated profiles reaches the maximum allowed value. If yes, go Activating a lower priority profile in the activated profile and activating the target profile; if not, activating the target profile; a memory for storing the program code; and a communication bus for connecting the receiver, the processor, and the memory.
  • the processor is further configured to sequentially attach the currently activated profile to the network according to the priority of the currently activated profile.
  • an embodiment of the present invention provides an integrated circuit card, including: a receiver, configured to receive a profile deactivation request sent by a profile manager PM, and a profile deactivation request for requesting to deactivate a target profile, a target profile An activated profile in the integrated circuit card; the processor is configured to determine whether there is another active profile in the integrated circuit card other than the target profile, and if so, to deactivate the target profile; if not, to deactivate the target profile, Activating an alternate profile in the integrated circuit card; a transmitter for requesting the terminal device to restart the integrated circuit card; a memory for storing the program code; and a communication bus for connecting the receiver, the transmitter, the processor, and the memory.
  • the standby profile is a preset active profile when the currently activated profile in the integrated circuit card loses the network connection.
  • the processor is further configured to attach the currently activated profile to the network.
  • an embodiment of the present invention provides an integrated circuit card, where an activated first profile, an activated second profile, and an inactive standby profile are installed, and the first profile and the second profile are configured.
  • the priority includes: a receiver, configured to receive a first notification message sent by the terminal device, where the first notification message is used to notify the first profile of the integrated circuit card to lose the network connection; and the transmitter is configured to send a connection establishment message to the terminal device, The connection setup message is used to establish a network connection by using the second profile, the transmitter is further configured to request the terminal device to restart the integrated circuit card, and the processor is configured to deactivate the first profile and the second if the second profile loses the network connection A profile with a lower priority in the profile and activates an alternate profile; a memory for storing program code; and a communication bus for connecting the receiver, the transmitter, the processor, and the memory.
  • the network connection is lost without network coverage or lost data connection with the network.
  • the processor is further configured to: before the transmitter sends the connection establishment message to the terminal device, confirm the first profile Lost the network connection for longer than the first threshold, or confirm the use of the first profile to rebuild The number of failed network connections exceeded the second threshold.
  • the embodiment of the present invention provides a profile downloading system, including a profile manager PM, and an integrated circuit card provided by the ninth aspect of the present invention and embodiments thereof, wherein the PM further includes: a processor, Selecting a first profile according to whether the two activated profiles in the integrated circuit card meet the preset condition and priority; the transmitter is configured to send a data connection establishment request to the integrated circuit card through the first profile, and the data connection establishment request is used for the request Establish a data connection between the integrated circuit card and the PM.
  • the first profile is a profile that is the only one of the two activated profiles that meets the preset condition; or the first profile is a priority of the two activated profiles. Higher profile.
  • the first profile when there are multiple activated profiles in the integrated circuit card, the first profile is multiple activated The only profile in the profile that meets the preset criteria; or the first profile is the profile with the highest priority among the multiple activated profiles.
  • the technical solution provided by the embodiment of the present invention has the beneficial effects that when the two active profiles are allowed in the eUICC, the eUICC determines whether to use the profile to establish the eUICC according to whether the two activated profiles in the eUICC meet the preset conditions. A data connection between the PM and the PM, and then download a new profile through the data connection. In addition, the eUICC determines whether to activate the target profile according to whether the number of currently activated profiles in the eUICC reaches the maximum allowed value, and if so, activates the active profile with a lower priority and then activates the target profile. This provides a profile download and activation method when two active profiles are allowed in the eUICC at the same time.
  • 1 is an exemplary eUICC logical architecture diagram
  • FIG. 5 is a flowchart of a profile activation method according to Embodiment 2 of the present invention.
  • FIG. 6 is a flowchart of a profile deactivation method according to Embodiment 3 of the present invention.
  • FIG. 7 is a flowchart of a method for maintaining a network connection according to Embodiment 4 of the present invention.
  • FIG. 8 is a schematic diagram of a virtual structure of an integrated circuit card according to Embodiment 5 of the present invention.
  • FIG. 9 is a schematic diagram of a physical structure of an integrated circuit card according to Embodiment 5 of the present invention.
  • FIG. 10 is a schematic structural diagram of a profile download system composed of an integrated circuit card and a PM according to Embodiment 5 of the present invention
  • FIG. 11 is a schematic diagram showing the virtual structure of another integrated circuit card according to Embodiment 6 of the present invention.
  • FIG. 12 is a schematic diagram showing the physical structure of another integrated circuit card according to Embodiment 6 of the present invention.
  • FIG. 13 is a schematic diagram showing the virtual structure of another integrated circuit card according to Embodiment 7 of the present invention.
  • FIG. 14 is a schematic diagram showing the physical structure of another integrated circuit card according to Embodiment 7 of the present invention.
  • FIG. 15 is a schematic diagram showing the virtual structure of another integrated circuit card according to Embodiment 8 of the present invention.
  • FIG. 16 is a schematic diagram showing the physical structure of another integrated circuit card according to Embodiment 8 of the present invention.
  • FIG. 1 is an exemplary eUICC logical architecture diagram, including:
  • the eUICC Controlling Authority Security Domain holds the key and certificate of the eUICC.
  • the primary security domain root (ISS-R) is associated with a subscription management-secure routing unit (SM-SR, not shown) for establishing A secure communication channel with the SM-SR and the creation of a new primary security domain profile (ISS-P).
  • SM-SR subscription management-secure routing unit
  • the primary security domain profile also known as the profile domain, is the space for storing the profile, and the subscription management-data preparation unit (Subscription Manager-Data Preparing unit) is saved outside the eUICC.
  • SM-DP subscribed to by SM-DP (not shown), the key for secure communication, and the credentials used to decrypt and install the profile.
  • Profile two profiles are shown in Figure 1, one for the active profile and one for the inactive profile.
  • Each profile further includes: a file system, a network access application (NAA), a policy rule, other applications, and a Mobile Network Operator Security Domain (MNO-SD).
  • NAA network access application
  • MNO-SD Mobile Network Operator Security Domain
  • the eUICC operating system includes a platform service management unit (Platform Service Manager) and a telecom framework (Telecom Framework).
  • the platform service management unit is used to provide platform management functions and policy rule execution mechanisms.
  • the telecom framework is used to provide a standardized network authorization algorithm to NAA, and can also use a demand parameter configuration algorithm.
  • a terminal may also be referred to as a system, a subscriber unit, a subscriber station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a mobile terminal, a wireless communication device, and a user.
  • the terminal may be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, or a Personal Digital Assistant (PDA).
  • the MNO sends a profile download request to the SM-DP, where the profile download request carries the identifier of the SM-SR (SM-SR Identity, SRID for short), the ID of the target eUICC (EID), and the identification of the integrated circuit card of the profile to be downloaded.
  • SM-SR Identity SRID for short
  • EID eUICC
  • ICCID Integrate Circuit Card Identity
  • the ICCID can uniquely identify the profile
  • the SM-DP is also called a Profile Provisioner (PP), and is used to generate a profile that can be downloaded to the eUICC according to the information provided by the MNO.
  • PP Profile Provisioner
  • S202 The SM-DP identifies the SM-SR currently registered by the eUICC according to the SRID.
  • the SM-SR also known as the Profile Manager (PM)
  • PM is used to establish a secure communication channel to the eUICC and manage profiles in the eUICC, such as activating, deactivating, or deleting profiles.
  • the PM can be located in a server on the network side or as a logical module located in the terminal device.
  • S203 Perform mutual authentication between the SM-DP and the SM-SR.
  • the SM-DP requests an eUICC Information Set (EIS) of the eUICC corresponding to the EID from the SM-SR.
  • EIS eUICC Information Set
  • S205 The SM-SR reads the locally stored EIS.
  • S206 The SM-SR returns an EIS to the SM-DP.
  • S207 The SM-DP checks whether the eUICC is suitable for downloading the profile according to the EIS.
  • the SM-DP requests the SM-SR to create an ISD-P.
  • S210 Perform mutual authentication between the SM-DP and the eUICC.
  • the SM-SR creates an ISD-P in the eUICC, and returns a creation confirmation to the SM-DP.
  • S212 Establish an ISD-P key for protecting profile download and installation between the SM-DP and the eUICC.
  • S213 The SM-DP encrypts the profile to be downloaded by using the ISD-P key set;
  • the SM-DP sends a profile download request to the SM-SR, where the request carries the profile data, the EID, and the application identifier (AID) of the ISD-P in the eUICC.
  • the profile download request is used to request the SM-SR to download the profile to the ISD-P corresponding to the ISD-P AID in the target eUICC;
  • the SM-SR checks the initial condition, for example, whether the SM-SR is responsible for managing the target eUICC, whether the ISD-P corresponding to the ISD-PAID has been created, and the like, and if the check finds an error, returns a failure notification to the SM-DP.
  • S215a The SM-DP returns a failure notification to the MNO;
  • HTTPS is a type of connection between SM-SR and eUICC, and may also have other connection forms, such as short message (SMS);
  • S216 The SM-SR sends the encrypted profile data to the ISD-R in the eUICC.
  • the ISD-R forwards the encrypted profile data to the ISD-P in the eUICC.
  • S218 The ISD-P decrypts the profile data by using an ISD-P key set.
  • the ISD-R returns a data transmission response to the SM-SR.
  • S221 The SM-SR returns a profile download response to the SM-DP.
  • S222 optional step, if the profile download needs to be performed in multiple steps, repeating the steps of S214-S221;
  • S223 The SM-DP sends an indication message that the download and installation is completed to the SM-SR, where the message carries the EID, the ICCID, and the POL2, where POL2 is a policy rule configured in the SM-SR.
  • S224 The SM-SR updates the EIS of the eUICC.
  • S225 The SM-SR confirms that the profile download and installation is completed to the SM-DP.
  • S226 The SM-DP returns a profile download and installation success response to the MNO.
  • FIG. 3 is an exemplary flowchart of an enable, including the following steps:
  • S301 The MNO requests the SM-SR to activate the target profile, where the request carries the EID of the target eUICC and the ICCID of the target profile.
  • the SM-SR checks whether the initial condition is met. If yes, the next step is performed. If the failure notification is returned to the MNO, the process ends.
  • the initial condition may include whether the SM-SR manages the target eUICC, whether the target profile is in a deactivated state, or whether the POL2 allows activation of the target profile, and the like;
  • S303 The SM-SR sends an activation profile request to the eUICC, where the request carries the ISD-P AID of the ISD-P where the target profile is located.
  • S304 The ISD-R in the eUICC executes POL1 of the currently activated profile. If POL1 refuses to activate the target profile, S306 and S306a are performed. If POL1 allows the target profile to be activated, S305 is performed. POL1 is a policy rule stored in a profile currently activated in the eUICC;
  • S305 The eUICC disables the currently activated profile, activates the target profile, and then executes S307;
  • S306a The SM-SR returns a failure result to the MNO, and the process ends.
  • S309 The eUICC performs a notification process. If the eUICC does not successfully send the notification message or does not receive the confirmation message sent by the SM-SR in the notification process, the eUICC will activate the newly activated profile and reactivate the original profile.
  • the scenario is applied to only one active profile in the eUICC.
  • the embodiment of the present invention will download and activate the profile when there are at least two active profiles in the eUICC. Introduction.
  • FIG. 4 is a flowchart of a profile download method according to Embodiment 1 of the present invention, which is applied to an installation.
  • the priority can be set by the PM.
  • the priority of the profile it can be set according to whether the current attached network of the profile is a roaming network. For example, the profile of the attached network for the local network is set to a high priority, and the attached network is roamed.
  • the profile of the network is set to a low priority; or it is set according to the coverage of the currently attached network of the profile. For example, the profile with high coverage of the attached network is set to high priority, and the profile with low coverage of the attached network is set to low. priority.
  • the profile download method shown in FIG. 4 includes:
  • the PP sends a profile download request to the PM, where the request carries an EID, a profile ID to be downloaded, an ID of an MNO that initiates a download request, and the like.
  • the profile ID can be in the form of an ICCID or other identifier that uniquely identifies the profile.
  • S402 The PM selects a profile according to whether the two activated profiles in the eUICC meet the preset condition and priority.
  • the PM After receiving the profile download request sent by the PP, the PM needs to establish a data connection with the eUICC to download the profile to be downloaded to the eUICC.
  • the PM can directly establish a data connection through the activated profile.
  • the PM when there are two active profiles in the eUICC, the PM is based on the eUICC. Whether the two activated profiles meet the preset conditions and priorities select a profile to establish a data connection.
  • the preset condition includes any one of the following: having a configuration attribute, a currently established packet data connection, and a connection for establishing a data connection between the eUICC and the PM. That is, the PM determines whether the profile meets the preset condition, including whether the PM determines whether the profile has the configuration attribute, whether the profile has established a packet data connection, or whether the profile is specified when the user subscribes, and is dedicated to establishing a data connection between the eUICC and the PM. Profile.
  • the profile is divided into a profile with a provisioning attribute and a profile with an operational attribute, or it can be said that the profile has two types, one is A profile (Provisioning Profile, Chinese translation is called a configuration file or an authorization file, hereinafter referred to as a configuration file).
  • a profile Provisioning Profile
  • Chinese translation is called a configuration file or an authorization file, hereinafter referred to as a configuration file.
  • One is a running profile (Chinese translation is called a running file or an executable file, hereinafter referred to as a running file).
  • the profile with the configuration attribute is mainly used to provide the data connection between the eUICC and the PM, and the function with the profile of the running attribute is similar to the UICC, and the terminal can pass the profile with the running attribute. Access all networks allowed by the profile's sign-up. However, it should be noted that a profile can have both configuration and runtime properties.
  • the PM determines whether the two activated profiles meet the preset condition, and if an activated profile meets the preset condition, select the profile that meets the preset condition; if both activated profiles are If the preset conditions are met or none of the preset conditions are met, the profile with the higher priority is selected.
  • the PM selects a profile by:
  • the embodiment of the present invention assumes that the profile selected by the PM is the first profile.
  • S403 The PM sends a data connection establishment request to the eUICC by using the first profile.
  • the data connection establishment request may be sent by a trigger message for requesting establishment of a data connection between the eUICC and the PM.
  • the eUICC needs to confirm whether the profile selected by the PM meets the preset condition.
  • S405a If the eUICC determines that the first profile meets the preset condition, the first profile is used to establish a data connection between the eUICC and the PM.
  • S405b If the eUICC determines that the first profile does not meet the preset condition, determining another activated profile, that is, whether the second profile meets the preset condition;
  • the eUICC selects the second profile by:
  • the data connection is established using the second profile that meets the preset condition
  • the second profile that meets the preset condition and has the highest priority is used to establish a data connection.
  • the eUICC establishes a data connection by using the third profile that meets the preset condition; if at least two third profiles meet the preset condition, the eUICC activates the third profile with the highest priority. And establishing a connection by using the third profile with the highest priority; if the third profile does not meet the preset condition, the eUICC returns an error response to the PM.
  • the eUICC receives the priority setting request sent by the PM, and is used for at least one of: setting a priority of a new profile and updating a priority of a profile other than the new profile.
  • the PM when two active profiles are installed in the eUICC, the PM establishes a data connection according to whether the activated profile meets the preset condition and the priority selection profile and the eUICC, and the eUICC determines whether the activated profile meets the preset condition. And the priority is used to confirm the profile selected by the PM, and when the activated profile does not meet the preset condition and the inactive profile meets the preset condition, the inactive profile is activated and the activated profile is used to establish a data connection, and the data is passed.
  • the connection downloads a new profile, providing a profile download method when two active profiles are installed in the eUICC.
  • FIG. 5 is a flowchart of a profile activation method according to Embodiment 2 of the present invention, which is applied to an eUICC in which two activated profiles and at least one inactive profile are installed, and the activated profile is set with a priority.
  • the method of setting the priority is the same as described in the first embodiment.
  • the profile activation method shown in Figure 5 includes:
  • the request initiator requests the PM to activate the target profile, where the request carries the ID of the target profile and the identifier of the request initiator.
  • the request originator can be an MNO, a user, or a Service Provider (SP).
  • MNO Mobility Management Entity
  • SP Service Provider
  • the PM determines whether the target profile can be activated, for example, the PM determines whether the target profile exists in the eUICC managed by the PM, and the like;
  • This step can be omitted when the PM is a logical unit located in the terminal device.
  • the step of establishing a data connection between the PM and the eUICC in the first embodiment may be performed, which is not described in this embodiment.
  • the PM sends a profile activation request to the eUICC, where the request carries the ID of the target profile, or the ISD-P AID of the ISD-P where the target profile is located, and is used to request to activate the target profile, where the target profile is an inactive one in the eUICC.
  • Profile
  • S505 The eUICC determines whether the number of currently activated profiles reaches the maximum allowed value.
  • the eUICC deactivates the profile with the lowest priority among the activated profiles.
  • S508 The eUICC sequentially attaches the currently activated profile to the network according to the priority of the currently activated profile.
  • the eUICC when two active profiles are allowed to be installed in the eUICC, when receiving the request to activate the target profile, the eUICC determines whether the number of currently activated profiles reaches the maximum allowed value, and if the maximum value is reached, Then, the active profile with lower priority is activated, and the target profile is activated, providing a profile activation method when two active profiles are allowed to be installed in the eUICC.
  • FIG. 6 is a flowchart of a profile deactivation method according to Embodiment 3 of the present invention, including:
  • the request initiator requests the PM to deactivate the target profile, where the request carries the identifier of the target profile and the identifier of the request initiator.
  • the PM determines whether the target profile can be deactivated, for example, the PM determines whether a target profile exists in the eUICC managed by the PM, and the like;
  • This step can be omitted when the PM is a logical unit located in the terminal device.
  • the step of establishing a data connection between the PM and the eUICC in the first embodiment may be performed, which is not described in this embodiment.
  • the PM sends a profile deactivation request to the eUICC, where the request includes an ID of the target profile, and is used to request to deactivate the target profile, where the target profile is an activated profile in the eUICC;
  • the eUICC determines whether there are other activated profiles in the eUICC in addition to the target profile.
  • the alternate profile can be a profile with a Fall Back attribute, usually inactive, and is a pre-configured profile that is activated when all connected network profiles lose network connectivity.
  • the eUICC reactivates the target profile and returns a failure notification to the PM.
  • the eUICC attaches the currently activated profile to the network according to the priority of the currently activated profile.
  • the eUICC when receiving the request to deactivate the target profile, determines whether there is another active profile other than the target profile, and prevents the profile from being activated after the target profile is deactivated. Without other active profiles, eUICC will activate the alternate profile, providing a profile deactivation method.
  • FIG. 7 is a flowchart of a method for maintaining a network connection according to Embodiment 4 of the present invention, which is applied to an eUICC in which a first profile, a second profile, and a standby profile are installed, where both the first profile and the second profile are activated.
  • the method of setting the priority is the same as described in the first embodiment.
  • the method for maintaining a network connection shown in FIG. 7 includes:
  • S701 The terminal device detects that the first profile loses the network connection.
  • losing the network connection includes no network coverage or loss of data connection to the network.
  • the terminal device sends a first notification message to the eUICC, to notify the eUICC that the first profile loses the network connection.
  • the ID of the first profile may be carried in the first notification message.
  • S703 The eUICC sends a connection establishment message to the terminal device, where the second profile is used to establish a data connection with the network.
  • connection setup message may carry the ID of the second profile.
  • the eUICC first confirms that the time when the first profile loses the network connection exceeds the first threshold and/or the number of failed to establish the network connection using the first profile exceeds the second threshold before sending the connection establishment message to the terminal device.
  • This can make the first profile in a certain scenario only temporarily lose the network connection, and can quickly restore the network connection, avoiding the delay and energy consumption caused by the network connection being replaced by the profile.
  • the terminal device sends a second notification message to the eUICC, to notify the eUICC that the second profile loses the data connection with the network.
  • the ID of the second profile may be carried in the second notification message.
  • S705 The eUICC deactivates the lower priority profile in the first profile and the second profile, and activates the standby profile.
  • the eUICC deactivates the profile with the lowest priority.
  • S708 The eUICC sends a notification message to the PM.
  • the eUICC when two active profiles are installed in the eUICC, and the two activated profiles lose network connection, the eUICC deactivates the lower priority profiles of the two activated profiles and activates the standby profile.
  • a method of maintaining a network connection when two activated profiles are installed in an eUICC is provided.
  • the above embodiment describes a method of downloading, activating, deactivating a profile or maintaining a network connection.
  • the following embodiment will introduce an integrated circuit card capable of downloading, activating, deactivating a profile or maintaining a network connection.
  • FIG. 8, FIG. 9, and FIG. 10 are respectively a schematic diagram of a virtual structure of an integrated circuit card according to Embodiment 5 of the present invention, a physical structure diagram of an integrated circuit card, and a profile download system composed of an integrated circuit card and a PM. Schematic.
  • the activated first card and the activated second profile are installed in the integrated circuit card 80 shown in FIG. 8, including:
  • the receiving unit 81 is configured to receive a data connection sent by the profile manager PM through the first profile. Establish a request;
  • the determining unit 82 is configured to determine whether the first profile meets the preset condition, and determine whether the second profile meets the preset condition when the first profile does not meet the preset condition;
  • the connection establishing unit 83 is configured to establish a data connection between the integrated circuit card and the PM by using the first profile when the first profile meets the preset condition; and when the first profile does not meet the preset condition, the second profile meets the preset condition. Establishing a data connection between the integrated circuit card 80 and the PM using the second profile;
  • the download unit 84 is configured to download a new profile through the data connection.
  • the integrated circuit card 80 is further configured with an inactive third profile, and the determining unit 82 is further configured to determine whether the third profile meets the preset condition when the first profile and the second profile do not meet the preset condition. ;
  • connection establishing unit 83 is further configured to: when the first profile and the second profile do not meet the preset condition, activate the third profile when the third profile meets the preset condition, and establish a relationship between the integrated circuit card 80 and the PM by using the third profile. Data connection.
  • connection establishing unit 83 is specifically configured to use when only one second profile meets the preset condition. And establishing, by using the second profile that meets the preset condition, a data connection between the integrated circuit card 80 and the PM; when at least two second profiles meet the preset condition, using the second profile that meets the preset condition and has the highest priority A data connection between the integrated circuit card 80 and the PM is established.
  • the preset condition includes any one of the following: having a configuration attribute, a currently established packet data connection, and a data connection dedicated to establishing an integrated circuit card and the PM.
  • the activated first card and the activated second profile are installed in the integrated circuit card 90 shown in FIG. 9, including:
  • a receiver 91 configured to receive a data connection establishment request sent by the profile manager PM through the first profile, and download a new profile by using a data connection between the integrated circuit card 90 and the PM;
  • the processor 92 is configured to determine whether the first profile meets the preset condition, and if the first profile meets the preset condition, use the first profile to establish a data connection between the integrated circuit card 90 and the PM; if the first profile does not meet the pre-configuration Setting a condition, determining whether the second profile meets the preset condition, and if the second profile meets the preset condition, using the second profile to establish a data connection between the integrated circuit card 90 and the PM;
  • a memory 93 configured to store program code
  • a communication bus 94 is provided for connecting the receiver 91, the processor 92, and the memory 93.
  • the integrated circuit card 90 is further configured with an inactive third profile
  • the processor 92 is further configured to determine whether the third profile meets the preset condition if the first profile and the second profile do not meet the preset condition; If the third profile meets the preset condition, the third profile is activated and a data connection between the integrated circuit card 90 and the PM is established using the third profile.
  • the processor 92 is specifically configured to: if only one second profile meets the preset condition, And establishing a data connection between the integrated circuit card 90 and the PM by using the second profile that meets the preset condition; if at least two second profiles meet the preset condition, using the second condition that meets the preset condition and has the highest priority The profile establishes a data connection between the integrated circuit card 90 and the PM.
  • the preset condition includes any one of the following: having configuration attributes, a currently established packet data connection, and dedicated to establishing a data connection between the integrated circuit card 90 and the PM.
  • a profile download system 100 shown in FIG. 10 includes a PM and an integrated circuit card as shown in FIG. 8 or FIG. 9, wherein the PM 1000 further includes:
  • the processor 1001 is configured to select the first profile according to whether the two activated profiles in the integrated circuit card meet the preset condition and priority;
  • the transmitter 1002 is configured to send, by using the first profile, a data connection establishment request to the integrated circuit card, where the data connection establishment request is used to request to establish a data connection between the integrated circuit card and the PM;
  • the processor 1001 is specifically configured to: determine whether the two activated profiles meet the preset condition, and if only the first profile meets the preset condition, select the first profile; if the first profile and the second profile are consistent with the pre-configuration If the conditions are not met or the preset conditions are not met, select the profile with higher priority.
  • the processor 1001 selects the profile with the highest priority.
  • the integrated circuit card 80 or 90 in accordance with embodiments of the present invention may correspond to the eUICC in the method embodiments of the present invention, and that the above and other operations and/or functions of the various devices in the integrated circuit card 80 or 90 are respectively implemented for The corresponding processes of the respective methods in FIG. 4 are not described herein for the sake of brevity.
  • the integrated circuit card in FIG. 8 and FIG. 9 may also be a terminal.
  • the terminal further includes one installed with at least two activations.
  • Profile of the integrated circuit card the terminal uses the integrated circuit card to determine which profile to use and Data connection between PMs and use this data connection to download a new profile.
  • the PM when two activated profiles are installed in the integrated circuit card, the PM establishes a data connection according to whether the activated profile meets the preset condition and the priority selection profile and the integrated circuit card, and the integrated circuit card is activated according to the Whether the profile meets the preset condition and priority to confirm the profile selected by the PM, and activates the inactive profile and uses the activated profile when the activated profile does not meet the preset condition and the inactive profile meets the preset condition.
  • Establishing a data connection through which to download a new profile provides an integrated circuit card for profile download when two active profiles are installed in the integrated circuit card.
  • FIG. 11 and FIG. 12 are respectively a schematic diagram of a virtual structure of another integrated circuit card and a physical structure of another integrated circuit card according to Embodiment 6 of the present invention, and the integrated circuit cards shown in FIG. 11 or FIG. 12 can be implemented.
  • the profile activation method of the second embodiment is a schematic diagram of a virtual structure of another integrated circuit card and a physical structure of another integrated circuit card according to Embodiment 6 of the present invention, and the integrated circuit cards shown in FIG. 11 or FIG. 12 can be implemented.
  • the integrated circuit card 110 shown in FIG. 11 is installed with two active profiles and at least one inactive profile, and the two activated profiles are set with priorities, including:
  • the receiving unit 111 is configured to receive a profile activation request sent by the profile manager PM, where the profile activation request includes an identifier ID of the target profile, and is used to request to activate the target profile, where the target profile is one of the inactive profiles;
  • the determining unit 112 is configured to determine whether the number of currently activated profiles reaches the maximum allowed value
  • the activation and deactivation unit 113 when the number of currently activated profiles reaches the maximum allowed value, deactivates the lower priority profile in the activated profile, and activates the target profile; the number of currently activated profiles does not reach the allowed At the maximum, the target profile is activated.
  • the integrated circuit card 110 further includes a network attaching unit 114 for sequentially attaching the currently activated profile to the network according to the priority of the currently activated profile.
  • the integrated circuit card 120 shown in FIG. 12 is installed with two active profiles and at least one inactive profile, and the two activated profiles are set with priorities, including:
  • the receiver 121 is configured to receive a profile activation request sent by the profile manager PM, where the profile activation request includes an identifier ID of the target profile, and is used to request to activate the target profile, where the target profile is one of the inactive profiles;
  • the processor 122 is configured to determine whether the number of currently activated profiles reaches the maximum allowed value, and if yes, deactivate the profile with the lower priority in the activated profile, and activate the target profile; No, the target profile is activated.
  • a memory 123 configured to store program code
  • the communication bus 124 is used to connect the receiver 121, the processor 122, and the memory 123.
  • the processor 122 is further configured to sequentially attach the currently activated profile to the network according to the priority of the currently activated profile.
  • the integrated circuit card 110 or 120 in accordance with an embodiment of the present invention may correspond to the eUICC in the method embodiments of the present invention, and that the above and other operations and/or functions of the respective devices in the integrated circuit card 110 or 120 are respectively implemented for The corresponding processes of the respective methods in FIG. 5 are not described herein for the sake of brevity.
  • the integrated circuit card in FIG. 11 and FIG. 12 may also be a terminal.
  • the terminal further includes one installed with at least two activations.
  • the integrated circuit card of the profile determines whether the target profile is activated according to whether the number of profiles currently activated in the integrated circuit card reaches the maximum allowed value.
  • the integrated circuit card when two activated profiles are installed in the integrated circuit card, when the integrated circuit card receives the request to activate the target profile, it determines whether the number of currently activated profiles reaches the maximum allowed value. When the maximum is reached, the lower priority active profile is deactivated and the target profile is activated, providing an integrated circuit card for profile activation when two active profiles are installed in the integrated circuit card.
  • FIG. 13 and FIG. 14 are respectively a schematic diagram of a virtual structure of another integrated circuit card and a physical structure of another integrated circuit card according to Embodiment 7 of the present invention, and the integrated circuit cards shown in FIG. 13 or FIG. 14 can be implemented.
  • the profile deactivation method of the third embodiment is a schematic diagram of a virtual structure of another integrated circuit card and a physical structure of another integrated circuit card according to Embodiment 7 of the present invention, and the integrated circuit cards shown in FIG. 13 or FIG. 14 can be implemented.
  • the profile deactivation method of the third embodiment is respectively a schematic diagram of a virtual structure of another integrated circuit card and a physical structure of another integrated circuit card according to Embodiment 7 of the present invention, and the integrated circuit cards shown in FIG. 13 or FIG. 14 can be implemented.
  • the profile deactivation method of the third embodiment is a schematic diagram of a virtual structure of another integrated circuit card and a physical structure of another integrated circuit card according to Embodiment 7 of the present invention, and the integrated circuit cards shown in
  • the integrated circuit card 130 shown in FIG. 13 includes:
  • the receiving unit 131 is configured to receive a profile deactivation request sent by the profile manager PM, where the profile deactivation request includes an identifier ID of the target profile, and is used to request to deactivate the target profile, where the target profile is an activated profile in the integrated circuit card. ;
  • the determining unit 132 is configured to determine whether there is another activated profile in the integrated circuit card 130 other than the target profile;
  • the activation and deactivation unit 133 is configured to deactivate the target profile when there are other activated profiles in the integrated circuit card 130 in addition to the target profile; when the integrated circuit card is other than the target profile When the medium 130 has no other active profiles, the target profile is activated to activate the standby profile in the integrated circuit card 130;
  • the sending unit 134 is configured to request the terminal device to restart the integrated circuit card 130.
  • the standby profile may be a profile with a Fall Back attribute, which is usually in an inactive state, and is a preset profile that is activated when all connected network profiles lose network connectivity.
  • the integrated circuit card 130 further includes a network attachment unit 135 for attaching the currently activated profile to the network.
  • the integrated circuit card 140 shown in Figure 14 includes:
  • the receiver 141 is configured to receive a profile deactivation request sent by the profile manager PM, where the profile deactivation request includes an identifier ID of the target profile, and is used to request to deactivate the target profile, where the target profile is an activated profile in the integrated circuit card. ;
  • the processor 142 is configured to determine whether there is another activated profile in the integrated circuit card 140 other than the target profile, and if so, deactivate the target profile; if not, deactivate the target profile to activate the standby profile in the integrated circuit card 140. ;
  • a transmitter 143 configured to request the terminal device to restart the integrated circuit card 140
  • a memory 144 configured to store program code
  • a communication bus 145 is provided for connecting the receiver 141, the transmitter 143, the processor 142, and the memory 144.
  • the standby profile may be a profile with a Fall Back attribute, which is usually in an inactive state, and is a preset profile that is activated when all connected network profiles lose network connectivity.
  • the processor 142 is further configured to attach the currently activated profile to the network.
  • the integrated circuit card 130 or 140 in accordance with embodiments of the present invention may correspond to the eUICC in the method embodiments of the present invention, and that the above and other operations and/or functions of the various devices in the integrated circuit card 130 or 140 are implemented separately for The corresponding processes of the respective methods in FIG. 6 are not described herein for the sake of brevity.
  • the integrated circuit card in FIG. 13 and FIG. 14 may also be a terminal.
  • the terminal further includes an integrated circuit card, which is Whether there is another active profile in the integrated circuit card in addition to the target profile to determine whether to deactivate the target profile.
  • the integrated circuit card when receiving the request to deactivate the target profile, determines whether there is another activated profile other than the target profile, and prevents the profile from being activated after the target profile is deactivated. There is no other active profile outside the target profile, the IC card will deactivate the target profile and activate the alternate profile, providing an integrated circuit card for profile deactivation in an integrated circuit card that allows multiple active profiles at the same time.
  • FIG. 15 and FIG. 16 are respectively a schematic diagram of a virtual structure of another integrated circuit card and a physical structure of another integrated circuit card according to Embodiment 8 of the present invention, and the integrated circuit cards shown in FIG. 15 or FIG. 16 can be implemented.
  • the activated circuit card 150 shown in FIG. 15 is equipped with an activated first profile, an activated second profile, and an inactive standby profile.
  • the first profile and the second profile are set with priorities, including:
  • the receiving unit 151 is configured to receive a first notification message sent by the terminal device, where the first notification message is used to notify the first profile of the integrated circuit card to lose the network connection;
  • the sending unit 152 is configured to send a connection establishment message to the terminal device, where the connection establishment message is used to establish a network connection by using the second profile;
  • the activation and deactivation unit 153 is configured to: when the second profile loses the network connection, deactivate the lower priority profile in the first profile and the second profile and activate the standby profile;
  • the sending unit 152 is further configured to request the terminal device to restart the integrated circuit card 150.
  • the network connection is lost for no network coverage or lost data connection to the network.
  • the integrated circuit card 150 further includes an acknowledgment unit 154, configured to confirm, before the sending unit 152 sends the connection establishment message to the terminal device, that the time when the first profile loses the network connection exceeds a first threshold, or confirms that the network is re-established using the first profile. The number of connection failures exceeded the second threshold.
  • the activated circuit card 160 shown in FIG. 16 is provided with an activated first profile, an activated second profile, and an inactive standby profile.
  • the first profile and the second profile are set with priorities, including:
  • the receiver 161 is configured to receive a first notification message sent by the terminal device, where the first notification message is used to notify the first profile of the integrated circuit card to lose the network connection;
  • a transmitter 162 configured to send a connection establishment message to the terminal device, the connection establishment message is used to establish a network connection by using the second profile, and the transmitter is further configured to request the terminal device to restart the integrated circuit card 160;
  • the processor 163 is configured to: if the second profile loses the network connection, deactivate the profile with lower priority in the first profile and the second profile and activate the standby profile;
  • a memory 164 configured to store program code
  • a communication bus 165 is provided for connecting the receiver 161, the transmitter 162, the processor 163, and the memory 164.
  • the network connection is lost for no network coverage or lost data connection to the network.
  • the processor 163 is further configured to: before the transmitter 162 sends the connection establishment message to the terminal device, confirm that the first profile loses the network connection for more than the first threshold, or confirm that the number of failed to establish the network connection using the first profile exceeds Second threshold.
  • the integrated circuit card 150 or 160 in accordance with embodiments of the present invention may correspond to the eUICC in the method embodiments of the present invention, and that the above and other operations and/or functions of the various devices in the integrated circuit card 150 or 160 are respectively implemented for The corresponding processes of the respective methods in FIG. 7 are not described herein again for the sake of brevity.
  • the integrated circuit card in FIG. 15 and FIG. 16 may also be a terminal.
  • the terminal further includes one installed with at least two activations.
  • the integrated circuit card of the profile when the activated profile in the integrated circuit card loses the network connection, the terminal deactivates the active profile with lower priority, activates the standby profile, and establishes a network connection using the alternate profile.
  • the integrated circuit card deactivates the lower priority profiles of the two activated profiles, and Activating the alternate profile provides a way to maintain network connectivity when two active profiles are installed in an integrated circuit card.
  • the processor may be a central processing unit (CPU), and may be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), Field Programmable Gate Array (FPGA) or other programmable logic device, discrete gate or transistor logic device, discrete hardware components, etc.
  • the general purpose processor may be a microprocessor or the processor or any conventional processor or the like.
  • the memory can include read only memory and random access memory, store program code, and provide instructions and data to the processor.
  • the communication bus may include a power bus, a control bus, and a status signal bus in addition to the data bus.
  • the various buses are labeled as communication buses in the figures.
  • each step of the above method can be integrated by the logic of the hardware in the processor.
  • the instructions in the form of a road or software are completed.
  • the steps of the method disclosed in the embodiments of the present invention may be directly implemented as a hardware processor, or may be performed by a combination of hardware and software modules in the processor.
  • the software module can be located in a conventional storage medium such as random access memory, flash memory, read only memory, programmable read only memory or electrically erasable programmable memory, registers, and the like.
  • the storage medium is located in the memory, and the processor reads the information in the memory and combines the hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.
  • a component can be, but is not limited to being, a process running on a processor, a processor, an object, an executable, a thread of execution, a program, and/or a computer.
  • an application running on a computing device and a computing device can be a component.
  • One or more components can reside within a process and/or execution thread, and the components can be located on one computer and/or distributed between two or more computers.
  • these components can execute from various computer readable media having various data structures stored thereon.
  • a component may, for example, be based on signals having one or more data packets (eg, data from two components interacting with another component between the local system, the distributed system, and/or the network, such as the Internet interacting with other systems) Communicate through local and/or remote processes.
  • data packets eg, data from two components interacting with another component between the local system, the distributed system, and/or the network, such as the Internet interacting with other systems
  • the term "article of manufacture” as used in this application encompasses a computer program accessible from any computer-readable device, carrier, or media.
  • the computer readable medium may include, but is not limited to, a magnetic storage device (for example, a hard disk, a floppy disk, or a magnetic tape), and an optical disk (for example, a CD (Compact Disk), a DVD (Digital Versatile Disk). Etc.), smart cards and flash memory devices (eg, EPROM (Erasable Programmable Read-Only Memory), cards, sticks or key drivers, etc.).
  • various storage media described herein can represent one or more devices and/or other machine-readable media for storing information.
  • the term "machine-readable medium” may include, without limitation, a wireless channel and various other mediums capable of storing, containing, and/or carrying instructions and/or data.
  • the disclosed systems, devices, and methods may be implemented in other manners.
  • the device embodiments described above are merely illustrative.
  • the division of the unit is only a logical function division.
  • there may be another division manner for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, or an electrical, mechanical or other form of connection.
  • the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the objectives of the embodiments of the present invention.
  • each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
  • the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
  • the technical solution of the present invention contributes in essence or to the prior art, or all or part of the technical solution may be embodied in the form of a software product stored in a storage medium.
  • a number of instructions are included to cause a computer device (which may be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention.
  • the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like. .

Abstract

一种profile下载和激活方法、集成电路卡及系统。其中profile下载方法包括eUICC根据eUICC中的两个激活的profile是否符合预设条件来判断使用哪个profile建立所述eUICC和PM之间的数据连接,再通过建立的数据连接下载新的profile;profile激活方法包括eUICC根据所述eUICC中当前激活的profile的数量是否达到允许的最大值来判断是否激活目标profile。由此提供了一种当eUICC中允许同时有两个激活的profile时的profile下载和激活方法。

Description

一种profile下载和激活方法、集成电路卡及系统 技术领域
本发明涉及移动通信技术领域,特别涉及一种profile下载和激活方法、集成电路卡及系统。
背景技术
通用集成电路卡(Universal Integrated Circuit Card,简称UICC)是定义了物理特性、电气特性等特性的智能卡的总称。作为用户终端的一个组成部分,UICC主要用于存储用户信息、鉴权密钥、计费策略等信息。UICC可以包括多种逻辑模块,如用户识别模块(Subscriber Identity Module,简称SIM)、通用用户识别模块(Universal Subscriber Identity Module,简称USIM)、IP多媒体业务识别模块(IP Multi Media Service Identity Module,简称ISIM),以及其他如电子签名认证、电子钱包等非电信应用模块。UICC中的逻辑模块可以单独存在,也可以多个同时存在,不同的用户终端可以根据无线接入网络的类型,来选择使用相应的逻辑模块。
嵌入式通用集成电路卡(embedded UICC,简称eUICC)是将UICC通过封装或者焊接等方式嵌入到终端中所形成的,eUICC不方便插拔,也不能像UICC一样随意更换。
eUICC中通常安装有至少一个profile(中文译名可以为轮廓、用户信息集、属性参数集或属性数据集等),profile是指文件结构、数据和应用程序的集合,包括一个或多个网络接入应用及相应的网络接入信任状,如国际移动用户识别码(International Mobile Subscriber Identity,简称IMSI)、个人身份鉴权键(Key Identity,简称KI)。
现有技术已经规定了如何下载和激活profile的流程,但是,现有技术规定的下载和激活profile的流程仅考虑了eUICC中只有一个激活profile的场景,当允许eUICC中同时有多个激活profile时,目前还缺乏相应的方法。因此需要一种方法来解决当eUICC中同时有多个激活profile时如何下载和激活profile的技术问题。
发明内容
为了解决上述技术问题,本发明实施例提供了一种profile下载和激活方法、芯片及系统,以解决当eUICC中同时有多个激活profile时如何下载和激活profile的技术问题。
第一方面,本发明实施例提供了一种profile下载方法,应用于安装有激活的第一profile和激活的第二profile的嵌入式通用集成电路卡eUICC,包括:eUICC接收profile管理器PM通过第一profile发送的数据连接建立请求,eUICC判断第一profile是否符合预设条件:若第一profile符合预设条件,则eUICC使用第一profile建立eUICC和PM之间的数据连接;若第一profile不符合预设条件,则eUICC判断第二profile是否符合预设条件:若第二profile符合预设条件,则eUICC使用第二profile建立eUICC和PM之间的数据连接,eUICC通过数据连接下载新的profile。
结合第一方面,在第一方面的第一种实现方式中,eUICC中还安装有未激活的第三profile,eUICC通过数据连接下载新的profile之前进一步包括:若第二profile不符合预设条件,则eUICC判断第三profile是否符合预设条件;若第三profile符合预设条件,则eUICC激活第三profile,并使用第三profile建立eUICC和PM之间的数据连接。
结合第一方面或第一方面的第一种实现方式,在第一方面的第二种实现方式中,第一profile的数量为一个,第二profile的数量有多个,第一profile和第二profile均设置有优先级;若第二profile符合预设条件,则eUICC使用第二profile建立eUICC和PM之间的数据连接,包括:若只有一个第二profile符合预设条件,则使用符合预设条件的第二profile建立eUICC和PM之间的数据连接;若有至少两个第二profile符合预设条件,则eUICC使用符合预设条件,且优先级最高的第二profile建立eUICC和PM之间的数据连接。
结合第一方面、第一方面的第一种实现方式或第一方面的第二种实现方式,在第一方面第三种实现方式中,预设条件包括以下任意之一:具备配置属性、当前已建立分组数据连接和专用于建立eUICC和PM之间数据连接。
第二方面,本发明实施例提供了一种profile激活方法,应用于安装有两个激活的profile和至少一个未激活的profile的嵌入式通用集成电路卡eUICC,两个激活的profile设置有优先级,包括:eUICC接收profile管理器PM发送的profile 激活请求,profile激活请求用于请求激活目标profile,目标profile为其中一个未激活的profile,eUICC判断当前激活的profile的数量是否达到允许的最大值:若是,则eUICC去激活激活的profile中优先级较低的profile,并且激活目标profile;若否,则eUICC激活目标profile。
结合第二方面,在第二方面第一种实现方式中,进一步包括:eUICC根据当前激活的profile的优先级,将当前激活的profile依次附着到网络。
第三方面,本发明实施例提供了一种profile去激活方法,包括:嵌入式通用集成电路卡eUICC接收profile管理器PM发送的profile去激活请求,profile去激活请求用于请求去激活目标profile,目标profile为eUICC中的一个激活的profile,eUICC判断除了目标profile以外eUICC中是否还有其他激活的profile:若是,则eUICC去激活目标profile;若否,则eUICC去激活目标profile,激活eUICC中的备用profile;eUICC向终端设备请求重新启动eUICC。
结合第三方面,在第三方面的第一种实现方式中,备用profile为eUICC中当前激活的profile都失去网络连接时,预设激活的profile。
结合第三方面或第三方面的第一种实现方式,在第三方面的第二种实现方式中,方法进一步包括:eUICC将当前激活的profile附着到网络。
第四方面,本发明实施例提供了一种保持网络连接的方法,应用于安装有激活的第一profile、激活的第二profile和未激活的备用profile的嵌入式通用集成电路卡eUICC,第一profile和第二profile设置有优先级,包括:eUICC接收终端设备发送的第一通知消息,第一通知消息用于通知eUICC第一profile失去网络连接;eUICC向终端设备发送连接建立消息,连接建立消息用于使用第二profile建立网络连接;若第二profile失去网络连接,eUICC去激活第一profile和第二profile中优先级较低的profile,并激活备用profile;eUICC向终端设备请求重新启动eUICC。
结合第四方面,在第四方面的第一种实现方式中,失去网络连接为没有网络覆盖或失去和网络的数据连接。
结合第四方面或第四方面的第一种实现方式,在第四方面的第二种实现方式中,eUICC向终端设备发送连接建立消息之前进一步包括:eUICC确认第一profile失去网络连接的时间超过第一阈值;或者eUICC确认使用第一profile重新建立网络连接失败的次数超过第二阈值。
第五方面,本发明实施例提供了一种集成电路卡,集成电路卡中安装有激活的第一profile和激活的第二profile,包括:接收单元,用于接收profile管理器PM通过第一profile发送的数据连接建立请求;判断单元,用于判断第一profile是否符合预设条件,以及当第一profile不符合预设条件时,判断第二profile是否符合预设条件;连接建立单元,用于当第一profile符合预设条件时,使用第一profile建立集成电路卡和PM之间的数据连接;当第一profile不符合预设条件,第二profile符合预设条件时,使用第二profile建立集成电路卡和PM之间的数据连接;下载单元,用于通过数据连接下载新的profile。
结合第五方面,在第五方面的第一种实现方式中,集成电路卡中还安装有未激活的第三profile,判断单元还用于当第一profile和第二profile都不符合预设条件时,判断第三profile是否符合预设条件;连接建立单元还用于当第一profile和第二profile都不符合预设条件,第三profile符合预设条件时,激活第三profile,并使用第三profile建立集成电路卡和PM之间的数据连接。
结合第五方面或第五方面的第一种实现方式,在第五方面的第二种实现方式中,第一profile的数量为一个,第二profile的数量有多个,第一profile和第二profile均设置有优先级;连接建立单元用于当第一profile不符合预设条件,第二profile符合预设条件时,使用第二profile建立集成电路卡和PM之间的数据连接,包括:连接建立单元用于当只有一个第二profile符合预设条件时,使用符合预设条件的第二profile建立集成电路卡和PM之间的数据连接;当有至少两个第二profile符合预设条件,使用符合预设条件,且优先级最高的第二profile建立集成电路卡和PM之间的数据连接。
结合第五方面、第五方面的第一种实现方式或第五方面的第二种实现方式,在第五方面第三种实现方式中,预设条件包括以下任意之一:具备配置属性、当前已建立分组数据连接和专用于建立集成电路卡和PM之间数据连接。
第六方面,本发明实施例提供了一种集成电路卡,集成电路卡安装有两个激活的profile和至少一个未激活的profile,两个激活的profile设置有优先级,包括:接收单元,用于接收profile管理器PM发送的profile激活请求,profile激活请求用于请求激活目标profile,目标profile为其中一个未激活的profile;判断单元,用于判断当前激活的profile的数量是否达到允许的最大值;激活和去激活单元,用于当前激活的profile的数量达到允许的最大值时,去激活激活 的profile中优先级较低的profile,并且激活目标profile;当前激活的profile的数量未达到允许的最大值时,激活目标profile。
结合第六方面,在第六方面的第一种实现方式中,集成电路卡进一步包括:网络附着单元,用于根据当前激活的profile的优先级,将当前激活的profile依次附着到网络。
第七方面,本发明实施例提供了一种集成电路卡,包括:接收单元,用于接收profile管理器PM发送的profile去激活请求,profile去激活请求用于请求去激活目标profile,目标profile为集成电路卡中的一个激活的profile;判断单元,用于判断除了目标profile以外集成电路卡中是否还有其他激活的profile;激活和去激活单元,用于当除了目标profile以外集成电路卡中还有其他激活的profile时,去激活目标profile;当除了目标profile以外集成电路卡中没有其他激活的profile时,去激活目标profile,激活集成电路卡中的备用profile;发送单元,用于向终端设备请求重新启动集成电路卡。
结合第七方面,在第七方面的第一种实现方式中,备用profile为集成电路卡中当前激活的profile都失去网络连接时,预设激活的profile。
结合第七方面或第七方面的第一种实现方式,在第七方面的第二种实现方式中,集成电路卡进一步包括:网络附着单元,用于将当前激活的profile附着到网络。
第八方面,本发明实施例提供了一种集成电路卡,集成电路卡中安装有激活的第一profile、激活的第二profile和未激活的备用profile,第一profile和第二profile设置有优先级,包括:接收单元,用于接收终端设备发送的第一通知消息,第一通知消息用于通知集成电路卡第一profile失去网络连接;发送单元,用于向终端设备发送连接建立消息,连接建立消息用于使用第二profile建立网络连接;激活和去激活单元,用于当第二profile失去网络连接时,去激活第一profile和第二profile中优先级较低的profile并激活备用profile;发送单元还用于向终端设备请求重新启动集成电路卡。
结合第八方面,在第八方面的第一种实现方式中,失去网络连接为没有网络覆盖或失去和网络的数据连接。
结合第八方面或第八方面的第一种实现方式,在第八方面的第二种实现方式中,集成电路卡进一步包括确认单元,用于发送单元向终端设备发送连接建 立消息之前确认第一profile失去网络连接的时间超过第一阈值,或者确认使用第一profile重新建立网络连接失败的次数超过第二阈值。
第九方面,本发明实施例提供了一种集成电路卡,集成电路卡中安装有激活的第一profile和激活的第二profile,包括:接收器,用于接收profile管理器PM通过第一profile发送的数据连接建立请求,以及通过集成电路卡和PM之间的数据连接下载新的profile;处理器,用于判断第一profile是否符合预设条件,若第一profile符合预设条件,则使用第一profile建立集成电路卡和PM之间的数据连接;若第一profile不符合预设条件,则判断第二profile是否符合预设条件,若第二profile符合预设条件,则使用第二profile建立集成电路卡和PM之间的数据连接;存储器,用于存储程序代码;通信总线,用于连接接收器、处理器和存储器。
结合第九方面,在第九方面的第一种实现方式中,集成电路卡中还安装有未激活的第三profile,处理器还用于若第一profile和第二profile都不符合预设条件,则判断第三profile是否符合预设条件;若第三profile符合预设条件,则激活第三profile,并使用第三profile建立集成电路卡和PM之间的数据连接。
结合第九方面或第九方面的第一种实现方式,在第九方面的第二种实现方式中,第一profile的数量为一个,第二profile的数量有多个,第一profile和第二profile设置有优先级;处理器用于若第二profile符合预设条件,则使用第二profile建立集成电路卡和PM之间的数据连接,包括:处理器用于若只有一个第二profile符合预设条件,则使用符合预设条件的第二profile建立集成电路卡和PM之间的数据连接;若有至少两个第二profile符合预设条件,则使用符合预设条件,且优先级最高的第二profile建立集成电路卡和PM之间的数据连接。
结合第九方面、第九方面的第一种实现方式或第九方面的第二种实现方式,在第九方面第三种实现方式中,预设条件包括以下任意之一:具备配置属性、当前已建立分组数据连接和专用于建立集成电路卡和PM之间数据连接。
第十方面,本发明实施例提供了一种集成电路卡,集成电路卡安装有两个激活的profile和至少一个未激活的profile,两个激活的profile设置有优先级,包括:接收器,用于接收profile管理器PM发送的profile激活请求,profile激活请求用于请求激活目标profile,目标profile为其中一个未激活的profile;处理器,用于判断当前激活的profile的数量是否达到允许的最大值,若是,则去 激活激活的profile中优先级较低的profile,并且激活目标profile;若否,则激活目标profile;存储器,用于存储程序代码;通信总线,用于连接接收器、处理器和存储器。
结合第十方面,在第十方面的第一种实现方式中,处理器还用于根据当前激活的profile的优先级,将当前激活的profile依次附着到网络。
第十一方面,本发明实施例提供了一种集成电路卡,包括:接收器,用于接收profile管理器PM发送的profile去激活请求,profile去激活请求用于请求去激活目标profile,目标profile为集成电路卡中的一个激活的profile;处理器,用于判断除了目标profile以外集成电路卡中是否还有其他激活的profile,若是,则去激活目标profile;若否,则去激活目标profile,激活集成电路卡中的备用profile;发射器,用于向终端设备请求重新启动集成电路卡;存储器,用于存储程序代码;通信总线,用于连接接收器、发射器、处理器和存储器。
结合第十一方面,在第十一方面的第一种实现方式中,备用profile为集成电路卡中当前激活的profile都失去网络连接时,预设激活的profile。
结合第十一方面或第十一方面的第一种实现方式,在第十一方面的第二种实现方式中,处理器还用于将当前激活的profile附着到网络。
第十二方面,本发明实施例提供了一种集成电路卡,集成电路卡中安装有激活的第一profile、激活的第二profile和未激活的备用profile,第一profile和第二profile设置有优先级,包括:接收器,用于接收终端设备发送的第一通知消息,第一通知消息用于通知集成电路卡第一profile失去网络连接;发射器,用于向终端设备发送连接建立消息,连接建立消息用于使用第二profile建立网络连接,发射器还用于向终端设备请求重新启动集成电路卡;处理器,用于若第二profile失去网络连接,则去激活第一profile和第二profile中优先级较低的profile并激活备用profile;存储器,用于存储程序代码;通信总线,用于连接接收器、发射器、处理器和存储器。
结合第十二方面,在第十二方面的第一种实现方式中,失去网络连接为没有网络覆盖或失去和网络的数据连接。
结合第十二方面或第十二方面的第一种实现方式,在第十二方面的第二种实现方式中,处理器还用于发射器向终端设备发送连接建立消息之前,确认第一profile失去网络连接的时间超过第一阈值,或者确认使用第一profile重新建 立网络连接失败的次数超过第二阈值。
第十三方面,本发明实施例提供了一种profile下载系统,包括profile管理器PM和本发明实施例第九方面及其各实施方式提供的集成电路卡,其中PM进一步包括:处理器,用于根据集成电路卡中两个激活的profile是否符合预设条件和优先级选择第一profile;发射器,用于通过第一profile向集成电路卡发送数据连接建立请求,数据连接建立请求用于请求建立集成电路卡和PM之间的数据连接。
结合第十三方面,在第十三方面的第一种实现方式中,第一profile为两个激活的profile中唯一符合预设条件的profile;或者第一profile为两个激活的profile中优先级较高的profile。
结合第十三方面或第十三方面的第一种实现方式,在第十三方面的第二种实现方式中,当集成电路卡中有多个激活的profile时,第一profile为多个激活的profile中唯一符合预设条件的profile;或者第一profile为多个激活的profile中优先级最高的profile。
本发明实施例提供的技术方案带来的有益效果是:当eUICC中允许同时有两个激活的profile时,eUICC根据eUICC中的两个激活的profile是否符合预设条件来判断使用哪个profile建立eUICC和PM之间的数据连接,再通过该数据连接下载新的profile。另外,eUICC根据eUICC中当前激活的profile的数量是否达到允许的最大值来判断是否激活目标profile,若是则去激活优先级较低的激活profile,再激活目标profile。由此提供了一种当eUICC中允许同时有两个激活的profile时的profile下载和激活方法。
附图说明
为了更清楚地说明本发明实施例中的技术方案,下面将对实施例描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1是一种示例性的eUICC逻辑架构图;
图2是一种示例性的profile的下载和安装流程图;
图3是一种示例性的profile的激活流程图;
图4是本发明实施例一提供的一种profile下载方法的流程图;
图5是本发明实施例二提供的一种profile激活方法的流程图;
图6是本发明实施例三提供的一种profile去激活方法的流程图;
图7是本发明实施例四提供的一种保持网络连接的方法的流程图;
图8是本发明实施例五提供的一种集成电路卡的虚拟结构示意图;
图9是本发明实施例五提供的一种集成电路卡的实体结构示意图;
图10是本发明实施例五提供的一种集成电路卡与PM组成的profile下载系统的结构示意图;
图11是本发明实施例六提供的另一种集成电路卡的虚拟结构示意图;
图12是本发明实施例六提供的另一种集成电路卡的实体结构示意图;
图13是本发明实施例七提供的另一种集成电路卡的虚拟结构示意图;
图14是本发明实施例七提供的另一种集成电路卡的实体结构示意图;
图15是本发明实施例八提供的另一种集成电路卡的虚拟结构示意图;
图16是本发明实施例八提供的另一种集成电路卡的实体结构示意图。
具体实施方式
为使本发明的目的、技术方案和优点更加清楚,下面将结合附图对本发明实施方式作进一步地详细描述。
为了便于理解本发明实施例,首先对eUICC的逻辑架构进行一个简要的说明。图1为一种示例性的eUICC逻辑架构图,包括:
eUICC权限控制安全域(eUICC Controlling Authority Security Domain,简称ECASD),保存有eUICC的密钥和证书;
主安全域根(Issuer Security Domain Root,简称ISD-R),和eUICC外的签约管理-安全路由单元(Subscription Manager-Secure Routing,简称SM-SR,图中未示出)相关联,用于建立和SM-SR之间的安全通信通道,以及创建新的主安全域profile(Issuer Security Domain Profile,简称ISD-P);
主安全域profile(Issuer Security Domain Profile,简称ISD-P),又称为profile域,为用于存放profile的空间,并且保存有和eUICC外的签约管理-数据准备单元(Subscription Manager-Data Preparing,简称SM-DP,图中未示出)进行安全通信的密钥,以及用于解密和安装profile的信任状。
Profile,图1中示出了两个profile,一个为激活的profile,一个为未激活的profile。每个profile又进一步包括:文件系统、网络接入应用(Network Access Application,简称NAA)、策略规则、其他应用和移动网络运营商安全域(Mobile Network Operator Security Domain,简称MNO-SD)。
eUICC操作系统,包括平台服务管理单元(Platform Service Manager)和电信框架(Telecom Framework)。平台服务管理单元用于提供平台管理功能和策略规则执行机制。电信框架用于向NAA提供标准化的网络授权算法,还能够使用需求参数配置算法。
另外,本发明实施例中,终端(Terminal)也可以称为系统、用户单元、用户站、移动站、移动台、远方站、远程终端、移动设备、用户终端、移动终端、无线通信设备、用户代理、用户装置或用户设备(User Equipment,简称UE)。例如,终端可以是蜂窝电话、无绳电话、会话启动协议(Session Initiation Protocol,简称SIP)电话、无线本地环路(Wireless Local Loop,简称WLL)站、个人数字助手(Personal Digital Assistant,简称PDA)、具备无线通信功能的手持设备、计算设备、车载通信模块、智能电表、智能家庭设备或连接到无线调制解调器的其它处理设备。
图2为一种示例性的profile的下载和安装流程图,包括如下步骤:
S201:MNO向SM-DP发送profile下载请求,该profile下载请求中携带SM-SR的标识(SM-SR Identity,简称SRID),目标eUICC的ID(EID)和要下载的profile的集成电路卡识别码(Integrate Circuit Card Identity,简称ICCID),ICCID可以唯一的标识profile;
SM-DP也称为Profile配置器(Profile Provisioner,简称PP),用于根据MNO提供的信息生成可以下载到eUICC的profile;
S202:SM-DP根据SRID识别eUICC当前注册的SM-SR;
SM-SR也称为profile管理器(Profile Manager,简称PM),用于建立到eUICC的安全通信通道,并且管理eUICC中的profile,例如激活、去激活或删除profile。PM可以位于网络侧的服务器中,也可以为位于终端设备中的一个逻辑模块。
S203:SM-DP和SM-SR之间进行双向认证;
S204:SM-DP向SM-SR请求EID对应的eUICC的eUICC信息集(eUICC Information Set,简称EIS);
S205:SM-SR读取本地存储的EIS;
S206:SM-SR向SM-DP返回EIS;
S207:SM-DP根据EIS检查eUICC是否适合下载该profile;
S208:若发现eUICC不适合下载该profile(例如eUICC的存储空间不足,证书不合法等),SM-DP向MNO和SM-SR返回冲突通知;
S209:若确认eUICC适合下载该profile,SM-DP请求SM-SR创建ISD-P。
S210:SM-DP和eUICC之间进行双向认证;
S211:SM-SR在eUICC中创建ISD-P,并向SM-DP返回创建确认;
S212:SM-DP和eUICC之间建立用于保护profile下载和安装的ISD-P密钥;
S213:SM-DP使用ISD-P密钥集加密要下载的profile;
S214:SM-DP向SM-SR发送profile下载请求,该请求中携带要下载的profile数据、EID和eUICC中的ISD-P的应用标识(Application Identifier,简称AID)。该profile下载请求用于请求SM-SR将profile下载到目标eUICC中的ISD-P AID对应的ISD-P中;
S215:SM-SR检查初始条件,例如SM-SR是否负责管理目标eUICC、ISD-PAID对应的ISD-P是否已经创建等,如果检查发现错误,向SM-DP返回失败通知;
S215a:SM-DP向MNO返回失败通知;
S215b:如果当前SM-SR和eUICC没有HTTPS会话连接,则SM-SR触发eUICC建立HTTPS会话。HTTPS是SM-SR和eUICC之间的连接形式的一种,还可以有其他连接形式,例如短消息(SMS);
S216:SM-SR向eUICC中的ISD-R发送加密后的profile数据;
S217:ISD-R将加密后的profile数据转发给eUICC中的ISD-P;
S218:ISD-P使用ISD-P密钥集解密profile数据;
S219:若S218执行成功,ISD-P执行接收到的命令;
S219a:ISD-P向ISD-R返回处理响应;
S220:ISD-R向SM-SR返回数据传输响应;
S221:SM-SR向SM-DP返回profile下载响应;
S222:可选步骤,如果profile下载需要分为多步执行,则重复S214-S221的步骤;
S223:SM-DP将下载安装完成的指示消息发送给SM-SR,该消息中可以携带EID、ICCID和POL2,其中POL2为配置到SM-SR中的策略规则;
S224:SM-SR更新eUICC的EIS;
S225:SM-SR向SM-DP确认profile下载安装完成;
S226:SM-DP向MNO返回profile下载安装成功响应。
图3为一种示例性的profile的激活(enable)流程图,包括如下步骤:
S301:MNO请求SM-SR激活目标profile,该请求中携带目标eUICC的EID和目标profile的ICCID;
S302:SM-SR检查初始条件是否满足,若是则执行下一步骤,若否则向MNO返回失败通知,流程结束。该初始条件可以包括SM-SR是否管理目标eUICC,目标profile是否处于去激活状态,或者POL2是否允许激活目标profile等;
S303:SM-SR向eUICC发送激活profile请求,该请求中携带目标profile所在ISD-P的ISD-P AID;
S304:eUICC中的ISD-R执行当前激活的profile的POL1,若POL1拒绝激活目标profile,则执行S306和S306a,若POL1允许激活目标profile,则执行S305。POL1为存储在eUICC中当前激活的profile中的策略规则;
S305:eUICC去激活(disable)当前激活的profile,激活目标profile,然后执行S307;
S306:eUICC向SM-SR返回执行结果;
S306a:SM-SR向MNO返回失败结果,流程结束;
S307:eUICC向终端设备请求重新启动eUICC;
S308:eUICC使用新激活的profile附着到网络;
S309:eUICC执行通知流程。如果在通知流程中,eUICC没有成功发送通知消息,或者没有接收到SM-SR发送的确认消息,则eUICC会去激活新激活的profile,重新激活原来的profile。
在上述的profile下载和激活流程中,都是应用于eUICC中只有一个激活的profile的场景,接下来本发明实施例将对eUICC中同时有至少两个激活的profile时,如何下载和激活profile进行介绍。
图4为本发明实施例一提供的一种profile下载方法的流程图,应用于安装 有激活的第一profile和激活的第二profile和未激活的第三profile的eUICC,并且eUICC中安装的profile均设置有优先级。优先级可以通过PM来设置,在设置profile的优先级时,可以根据profile当前附着网络是否为漫游网络来设置,例如,将附着网络为本地网络的profile设置为高优先级,将附着网络为漫游网络的profile设置为低优先级;或者根据profile当前附着网络的覆盖情况来设置,例如,将附着网络的覆盖率高的profile设置为高优先级,将附着网络的覆盖率低的profile设置为低优先级。图4所示的profile下载方法包括:
S401:PP向PM发送profile下载请求,该请求中携带EID、要下载的profile ID、发起下载请求的MNO的ID等。profile ID的形式可以是ICCID,也可以是其他能够唯一确定profile的标识;
S402:PM根据eUICC中的两个激活的profile是否符合预设条件和优先级选择一个profile;
PM收到PP发送的profile下载请求后,需要和eUICC之间建立数据连接,以将要下载的profile下载到eUICC。现有技术中因为eUICC中同时只有一个激活的profile,因此PM可以直接通过该激活的profile建立数据连接;本发明实施例中,当eUICC中同时有两个激活的profile时,PM会根据eUICC中的两个激活的profile是否符合预设条件和优先级选择一个profile来建立数据连接。
可选地,预设条件包括以下任意之一:具备配置属性、当前已建立分组数据连接和专用于建立eUICC和PM之间数据连接。也就是说,PM判断profile是否符合预设条件包括PM判断profile是否具备配置属性、profile当前是否已建立分组数据连接或profile是否是用户签约时指定的,专用于建立eUICC和PM之间数据连接的profile。
当预设条件是具备配置属性时,本发明实施中,profile分为具备配置(Provisioning)属性的profile和具备运行(Operational)属性的profile,或者也可以说,profile有两种类型,一种为配置profile(Provisioning Profile,中文译名为配置文件或授权文件,以下统称为配置文件),一种为运行profile(Operational Profile,中文译名为运行文件或执行文件,以下统称为运行文件)。这两种表述方式是等同的。
具备配置属性的profile主要用于提供eUICC和PM之间的数据连接,而具备运行属性的profile的功能和UICC类似,终端可以通过具备运行属性的profile 访问该profile的签约所允许的所有网络。但需要注意的是,一个profile可以同时具备配置属性和运行属性。
可选地,PM在选择profile时,判断两个激活的profile是否符合预设条件,若有一个激活的profile符合预设条件,则选择该符合预设条件的profile;若两个激活的profile都符合预设条件或都不符合预设条件,则选择其中优先级较高的profile。
当eUICC中激活的profile的数量大于两个时,PM通过如下方式选择profile:
判断激活的profile中是否有符合预设条件的profile,若只有一个激活的profile符合预设条件,则选择该符合预设条件的profile;若有超过一个激活的profile符合预设条件或所有激活的profile都不符合预设条件,则选择其中优先级最高的profile。
为易于理解,本发明实施例假设PM选择的profile为第一profile。
S403:PM通过第一profile向eUICC发送数据连接建立请求;
该数据连接建立请求可以通过trigger消息发送,用于请求建立eUICC和PM之间的数据连接。
S404:eUICC判断第一profile是否符合预设条件;
由于eUICC和PM中配置的策略规则可能不同,因此PM选择了建立数据连接的profile以后,eUICC需要确认PM选择的profile是否符合预设条件。
S405a:若eUICC判断第一profile符合预设条件,则使用该第一profile建立eUICC和PM之间的数据连接;
S405b:若eUICC判断第一profile不符合预设条件,则判断另一个激活的profile,即第二profile是否符合预设条件;
S406a:若eUICC判断第二profile符合预设条件,则使用第二profile建立eUICC和PM之间的数据连接;
可选地,在S406a中,当eUICC中有超过两个激活的profile时,例如当第二profile的数量有多个时,eUICC通过如下方式选择第二profile:
若只有一个第二profile符合预设条件,则使用符合预设条件的第二profile建立数据连接;
若有至少两个第二profile符合预设条件,则使用符合预设条件,且优先级最高的第二profile建立数据连接。
S406b:若eUICC判断第二profile不符合预设条件,则判断第三profile是否符合预设条件;
S407a:若第三profile符合预设条件,则激活第三profile,并使用激活后的第三profile建立eUICC和PM之间的数据连接;
S407b:若第三profile不符合预设条件,eUICC向PM返回错误响应;
在S407a和S407b中,可选地,当第三profile的数量有多个时,则:
若只有一个第三profile符合预设条件,则eUICC使用该符合预设条件的第三profile建立数据连接;若有至少两个第三profile符合预设条件,则eUICC激活优先级最高的第三profile并使用该优先级最高的第三profile建立连接;若第三profile都不符合预设条件,则eUICC向PM返回错误响应。
S408:eUICC通过该数据连接下载新的profile;
S409:eUICC接收所述PM发送的优先级设置请求,用于以下至少之一:设置新的profile的优先级和更新新的profile以外的其他profile的优先级。
本发明实施例中,当eUICC中安装有两个激活的profile时,由PM根据激活的profile是否符合预设条件和优先级选择profile和eUICC建立数据连接,eUICC根据激活的profile是否符合预设条件和优先级对PM选择的profile进行确认,并在激活的profile不符合预设条件且未激活的profile符合预设条件时,激活未激活的profile并使用激活后的profile建立数据连接,通过该数据连接下载新的profile,提供了一种当eUICC中安装有两个激活的profile时的profile下载方法。
图5为本发明实施例二提供的一种profile激活方法的流程图,应用于安装有两个激活的profile和至少一个未激活的profile的eUICC,并且激活的profile设置有优先级。设置优先级的方法和实施例一中所述相同。图5所示的profile激活方法包括:
S501:请求发起者(Initiator)请求PM激活目标profile,该请求携带目标profile的ID和请求发起者的标识;
该请求发起者可以为MNO、用户或服务提供商(Service Provider,简称SP)。
S502:PM判断是否能够激活目标profile,例如PM判断其所管理的eUICC中是否存在目标profile等;
当PM为位于终端设备内的逻辑单元时,本步骤可以省略。
可选地,当PM位于网络侧时,还可以执行实施例一中建立PM和eUICC之间数据连接的步骤,本实施例对此不再赘述。
S503:若PM判断能够激活目标profile,则PM和eUICC进行双向认证;
S504:PM向eUICC发送profile激活请求,该请求携带目标profile的ID,或者目标profile所在的ISD-P的ISD-P AID,用于请求激活目标profile,该目标profile为eUICC中的一个未激活的profile;
S505:eUICC判断当前激活的profile的数量是否达到允许的最大值;
S506a:若是,则eUICC去激活激活的profile中优先级较低的profile,并且激活目标profile,若激活失败,则向PM返回失败通知;
可选地,如果eUICC中激活的profile的数量有多个,则eUICC去激活激活的profile中优先级最低的profile。
S506b:若否,则eUICC直接激活目标profile;
S507:eUICC请求终端设备重新启动该eUICC;
S508:eUICC根据当前激活的profile的优先级,将当前激活的profile依次附着到网络。
本发明实施例中,当eUICC中允许安装有两个激活的profile时,eUICC在接收到激活目标profile的请求时,会判断当前激活的profile的数量是否达到允许的最大值,若达到最大值,则去激活优先级较低的激活的profile,并激活目标profile,提供了一种当eUICC中允许安装有两个激活的profile时的profile激活方法。
图6为本发明实施例三提供的一种profile去激活方法的流程图,包括:
S601:请求发起者请求PM去激活目标profile,该请求携带目标profile的标识和请求发起者的标识;
S602:PM判断是否能够去激活目标profile,例如PM判断其所管理的eUICC中是否存在目标profile等;
当PM为位于终端设备内的逻辑单元时,本步骤可以省略。
可选地,当PM位于网络侧时,还可以执行实施例一中建立PM和eUICC之间数据连接的步骤,本实施例对此不再赘述。
S603:若PM判断能够去激活目标profile,则PM和eUICC进行双向认证;
S604:PM向eUICC发送profile去激活请求,该请求包括目标profile的ID,用于请求去激活目标profile,该目标profile为eUICC中的一个激活的profile;
S605:eUICC判断除了目标profile以外该eUICC中是否还有其他激活的profile;
S606a:若是,则eUICC直接去激活目标profile;
S606b:若否,则eUICC去激活目标profile,激活eUICC中的备用profile;
备用profile可以是具备回落(Fall Back)属性的profile,通常处于非激活状态,是预先设定的、当所有连接网络的profile都失去网络连接时激活的profile。
若备用profile激活失败,则eUICC重新激活目标profile,向PM返回失败通知。
S607:eUICC向终端设备请求重新启动该eUICC;
S608:eUICC根据当前激活的profile的优先级,将当前激活的profile附着到网络。
本发明实施例中,eUICC在接收到去激活目标profile的请求时,会判断除目标profile以外是否还有其他激活的profile,防止去激活目标profile后出现无激活的profile的情况,若除目标profile以外没有其他激活的profile,eUICC会激活备用profile,提供了一种profile去激活方法。
图7为本发明实施例四提供的一种保持网络连接的方法的流程图,应用于安装有第一profile、第二profile和备用profile的eUICC,第一profile和第二profile均为激活的、设置有优先级的profile。设置优先级的方法和实施例一中所述相同。图7所示的保持网络连接的方法包括:
S701:终端设备检测到第一profile失去网络连接;
可选地,失去网络连接包括没有网络覆盖或失去和网络的数据连接。
S702:终端设备向eUICC发送第一通知消息,用于通知eUICC第一profile失去网络连接;
第一通知消息中可以携带第一profile的ID。
S703:eUICC向终端设备发送连接建立消息,用于使用第二profile建立和网络的数据连接;
连接建立消息中可以携带第二profile的ID。
可选地,eUICC向终端设备发送连接建立消息之前先确认第一profile失去网络连接的时间超过第一阈值和/或使用第一profile重新建立网络连接失败的次数超过第二阈值。这样可以使得某些场景下第一profile只是暂时性失去网络连接,可以很快恢复网络连接时,避免由于更换profile建立网络连接造成的时延和能耗等问题。
S704:终端设备向eUICC发送第二通知消息,用于通知eUICC第二profile失去和网络的数据连接;
第二通知消息中可以携带第二profile的ID。
S705:eUICC去激活第一profile和第二profile中优先级较低的profile,并激活备用profile;
可选地,当eUICC中激活的profile数量有多个时,eUICC会去激活优先级最低的profile。
S706:eUICC向终端设备请求重新启动eUICC;
S707:eUICC将备用profile附着到网络;
S708:eUICC向PM发送通知消息。
本发明实施例中,当eUICC中安装有两个激活的profile,并且两个激活的profile都失去网络连接时,eUICC去激活两个激活的profile中优先级较低的profile,并激活备用profile,提供了一种当eUICC中安装有两个激活的profile时的保持网络连接的方法。
上述实施例中介绍了下载、激活、去激活profile或保持网络连接的方法,下面的实施例将介绍一种能够下载、激活、去激活profile或保持网络连接的集成电路卡。
图8、图9和图10分别为本发明实施例五提供的一种集成电路卡的虚拟结构示意图、一种集成电路卡的实体结构示意图和一种集成电路卡与PM组成的profile下载系统的结构示意图。
图8所示的集成电路卡80中安装有激活的第一profile和激活的第二profile,包括:
接收单元81,用于接收profile管理器PM通过第一profile发送的数据连接 建立请求;
判断单元82,用于判断第一profile是否符合预设条件,以及当第一profile不符合预设条件时,判断第二profile是否符合预设条件;
连接建立单元83,用于当第一profile符合预设条件时,使用第一profile建立集成电路卡和PM之间的数据连接;当第一profile不符合预设条件,第二profile符合预设条件时,使用第二profile建立集成电路卡80和PM之间的数据连接;
下载单元84,用于通过数据连接下载新的profile。
可选地,集成电路卡80中还安装有未激活的第三profile,判断单元82还用于当第一profile和第二profile都不符合预设条件时,判断第三profile是否符合预设条件;
连接建立单元83还用于当第一profile和第二profile都不符合预设条件,第三profile符合预设条件时,激活第三profile,并使用第三profile建立集成电路卡80和PM之间的数据连接。
可选地,当该集成电路卡中激活的profile的数量有多个时,例如,第二profile的数量有多个时,连接建立单元83具体用于当只有一个第二profile符合预设条件时,使用符合预设条件的第二profile建立集成电路卡80和PM之间的数据连接;当有至少两个第二profile符合预设条件,使用符合预设条件,且优先级最高的第二profile建立集成电路卡80和PM之间的数据连接。
可选地,预设条件包括以下任意之一:具备配置属性、当前已建立分组数据连接和专用于建立集成电路卡和PM之间数据连接。
图9所示的集成电路卡90中安装有激活的第一profile和激活的第二profile,包括:
接收器91,用于接收profile管理器PM通过第一profile发送的数据连接建立请求,以及通过集成电路卡90和PM之间的数据连接下载新的profile;
处理器92,用于判断第一profile是否符合预设条件,若第一profile符合预设条件,则使用第一profile建立集成电路卡90和PM之间的数据连接;若第一profile不符合预设条件,则判断第二profile是否符合预设条件,若第二profile符合预设条件,则使用第二profile建立集成电路卡90和PM之间的数据连接;
存储器93,用于存储程序代码;
通信总线94,用于连接接收器91、处理器92和存储器93。
可选地,集成电路卡90中还安装有未激活的第三profile,处理器92还用于若第一profile和第二profile不符合预设条件,则判断第三profile是否符合预设条件;若第三profile符合预设条件,则激活第三profile,并使用第三profile建立集成电路卡90和PM之间的数据连接。
可选地,当该集成电路卡90中激活的profile的数量有多个时,例如,第二profile的数量有多个时,处理器92具体用于若只有一个第二profile符合预设条件,则使用符合预设条件的第二profile建立集成电路卡90和PM之间的数据连接;若有至少两个第二profile符合预设条件,则使用符合预设条件,且优先级最高的第二profile建立集成电路卡90和PM之间的数据连接。
可选地,预设条件包括以下任意之一:具备配置属性、当前已建立分组数据连接和专用于建立集成电路卡90和PM之间数据连接。
图10所示的一种profile下载系统100包括PM和图8或图9所示的集成电路卡,其中PM1000进一步包括:
处理器1001,用于根据集成电路卡中两个激活的profile是否符合预设条件和优先级选择第一profile;
发射器1002,用于通过第一profile向集成电路卡发送数据连接建立请求,数据连接建立请求用于请求建立集成电路卡和PM之间的数据连接;
可选地,处理器1001具体用于:判断两个激活的profile是否符合预设条件,若只有第一profile符合预设条件,则选择第一profile;若第一profile和第二profile都符合预设条件或都不符合预设条件,则选择其中优先级较高的profile。
当集成电路卡中的激活的profile的数量为多个,例如第二profile的数量有多个时:若只有第一profile符合预设条件,则选择第一profile;若有至少两个激活的profile符合预设条件,或者激活的profile都不符合预设条件时,则处理器1001选择其中优先级最高的profile。
应理解,根据本发明实施例的集成电路卡80或90可对应于本发明方法实施例中的eUICC,并且集成电路卡80或90中的各个器件的上述和其它操作和/或功能分别为了实现图4中的各个方法的相应流程,为了简洁,在此不再赘述。
应理解,本发明实施例中,图8和图9中的集成电路卡也可以是一种终端,除了图8或图9中的所有元件外,该终端还包括一个安装有至少两个激活的profile的集成电路卡,由终端来为该集成电路卡来判断使用哪个profile建立和 PM之间的数据连接,并使用该数据连接下载新的profile。
本发明实施例中,当集成电路卡中安装有两个激活的profile时,由PM根据激活的profile是否符合预设条件和优先级选择profile和集成电路卡建立数据连接,集成电路卡根据激活的profile是否符合预设条件和优先级对PM选择的profile进行确认,并在激活的profile不符合预设条件且未激活的profile符合预设条件时,激活该未激活的profile并使用激活后的profile建立数据连接,通过该数据连接下载新的profile,提供了一种当集成电路卡中安装有两个激活的profile时用于profile下载的集成电路卡。
图11和图12分别为本发明实施例六提供的另一种集成电路卡的虚拟结构示意图和另一种集成电路卡的实体结构示意图,图11或图12所示的集成电路卡均能够实施实施例二的profile激活方法。
图11所示的集成电路卡110安装有两个激活的profile和至少一个未激活的profile,两个激活的profile设置有优先级,包括:
接收单元111,用于接收profile管理器PM发送的profile激活请求,profile激活请求包括目标profile的标识ID,用于请求激活目标profile,目标profile为其中一个未激活的profile;
判断单元112,用于判断当前激活的profile的数量是否达到允许的最大值;
激活和去激活单元113,用于当前激活的profile的数量达到允许的最大值时,去激活激活的profile中优先级较低的profile,并且激活目标profile;当前激活的profile的数量未达到允许的最大值时,激活目标profile。
可选地,集成电路卡110进一步包括网络附着单元114,用于根据当前激活的profile的优先级,将当前激活的profile依次附着到网络。、
图12所示的集成电路卡120安装有两个激活的profile和至少一个未激活的profile,两个激活的profile设置有优先级,包括:
接收器121,用于接收profile管理器PM发送的profile激活请求,profile激活请求包括目标profile的标识ID,用于请求激活目标profile,目标profile为其中一个未激活的profile;
处理器122,用于判断当前激活的profile的数量是否达到允许的最大值,若是,则去激活激活的profile中优先级较低的profile,并且激活目标profile;若 否,则激活目标profile。
存储器123,用于存储程序代码;
通信总线124,用于连接接收器121、处理器122和存储器123。
可选地,处理器122还用于根据当前激活的profile的优先级,将当前激活的profile依次附着到网络。
应理解,根据本发明实施例的集成电路卡110或120可对应于本发明方法实施例中的eUICC,并且集成电路卡110或120中的各个器件的上述和其它操作和/或功能分别为了实现图5中的各个方法的相应流程,为了简洁,在此不再赘述。
应理解,本发明实施例中,图11和图12中的集成电路卡也可以是一种终端,除了图11或图12中的所有元件外,该终端还包括一个安装有至少两个激活的profile的集成电路卡,由终端来根据该集成电路卡中当前激活的profile的数量是否达到允许的最大值,来判断是否激活目标profile。
本发明实施例中,当集成电路卡中安装有两个激活的profile时,集成电路卡在接收到激活目标profile的请求时,会判断当前激活的profile的数量是否达到允许的最大值,若已达到最大值,则会去激活优先级较低的激活的profile,再激活目标profile,提供了一种当集成电路卡中安装有两个激活的profile时用于profile激活的集成电路卡。
图13和图14分别为本发明实施例七提供的另一种集成电路卡的虚拟结构示意图和另一种集成电路卡的实体结构示意图,图13或图14所示的集成电路卡均能够实施实施例三的profile去激活方法。
图13所示的集成电路卡130包括:
接收单元131,用于接收profile管理器PM发送的profile去激活请求,该profile去激活请求包括目标profile的标识ID,用于请求去激活目标profile,目标profile为集成电路卡中的一个激活的profile;
判断单元132,用于判断除了目标profile以外集成电路卡130中是否还有其他激活的profile;
激活和去激活单元133,用于当除了目标profile以外集成电路卡130中还有其他激活的profile时,去激活目标profile;当除了目标profile以外集成电路卡 中130没有其他激活的profile时,去激活目标profile,激活集成电路卡130中的备用profile;
发送单元134,用于向终端设备请求重新启动集成电路卡130。
其中,备用profile可以是具备回落(Fall Back)属性的profile,通常处于非激活状态,是预先设定的、当所有连接网络的profile都失去网络连接时激活的profile。
可选地,集成电路卡130进一步包括网络附着单元135,用于将当前激活的profile附着到网络。
图14所示的集成电路卡140包括:
接收器141,用于接收profile管理器PM发送的profile去激活请求,该profile去激活请求包括目标profile的标识ID,用于请求去激活目标profile,目标profile为集成电路卡中的一个激活的profile;
处理器142,用于判断除了目标profile以外集成电路卡140中是否还有其他激活的profile,若是,则去激活目标profile;若否,则去激活目标profile,激活集成电路卡140中的备用profile;
发射器143,用于向终端设备请求重新启动集成电路卡140;
存储器144,用于存储程序代码;
通信总线145,用于连接接收器141、发射器143、处理器142和存储器144。
其中,备用profile可以是具备回落(Fall Back)属性的profile,通常处于非激活状态,是预先设定的、当所有连接网络的profile都失去网络连接时激活的profile。
可选地,处理器142还用于将当前激活的profile附着到网络。
应理解,根据本发明实施例的集成电路卡130或140可对应于本发明方法实施例中的eUICC,并且集成电路卡130或140中的各个器件的上述和其它操作和/或功能分别为了实现图6中的各个方法的相应流程,为了简洁,在此不再赘述。
应理解,本发明实施例中,图13和图14中的集成电路卡也可以是一种终端,除了图13或图14中的所有元件外,该终端还包括一个集成电路卡,由终端根据该集成电路卡中除了目标profile之外是否还有其他激活的profile,来判断是否去激活目标profile。
本发明实施例中,集成电路卡在接收到去激活目标profile的请求时,会判断除目标profile以外是否还有其他激活的profile,防止去激活目标profile后出现无激活的profile的情况,若除目标profile以外没有其他激活的profile,集成电路卡会去激活目标profile,并激活备用profile,提供了一种集成电路卡中允许同时有多个激活的profile时用于profile去激活的集成电路卡。
图15和图16分别为本发明实施例八提供的另一种集成电路卡的虚拟结构示意图和另一种集成电路卡的实体结构示意图,图15或图16所示的集成电路卡均能够实施实施例四的保持网络连接的方法。
图15所示的集成电路卡150中安装有激活的第一profile、激活的第二profile和未激活的备用profile,第一profile和第二profile设置有优先级,包括:
接收单元151,用于接收终端设备发送的第一通知消息,第一通知消息用于通知集成电路卡第一profile失去网络连接;
发送单元152,用于向终端设备发送连接建立消息,连接建立消息用于使用第二profile建立网络连接;
激活和去激活单元153,用于当第二profile失去网络连接时,去激活第一profile和第二profile中优先级较低的profile并激活备用profile;
发送单元152还用于向终端设备请求重新启动集成电路卡150。
可选地,失去网络连接为没有网络覆盖或失去和网络的数据连接。
可选地,集成电路卡150进一步包括确认单元154,用于发送单元152向终端设备发送连接建立消息之前确认第一profile失去网络连接的时间超过第一阈值,或者确认使用第一profile重新建立网络连接失败的次数超过第二阈值。
图16所示的集成电路卡160中安装有激活的第一profile、激活的第二profile和未激活的备用profile,第一profile和第二profile设置有优先级,包括:
接收器161,用于接收终端设备发送的第一通知消息,第一通知消息用于通知集成电路卡第一profile失去网络连接;
发射器162,用于向终端设备发送连接建立消息,连接建立消息用于使用第二profile建立网络连接,发射器还用于向终端设备请求重新启动集成电路卡160;
处理器163,用于若第二profile失去网络连接,则去激活第一profile和第二profile中优先级较低的profile并激活备用profile;
存储器164,用于存储程序代码;
通信总线165,用于连接接收器161、发射器162、处理器163和存储器164。
可选地,失去网络连接为没有网络覆盖或失去和网络的数据连接。
可选地,处理器163还用于发射器162向终端设备发送连接建立消息之前,确认第一profile失去网络连接的时间超过第一阈值,或者确认使用第一profile重新建立网络连接失败的次数超过第二阈值。
应理解,根据本发明实施例的集成电路卡150或160可对应于本发明方法实施例中的eUICC,并且集成电路卡150或160中的各个器件的上述和其它操作和/或功能分别为了实现图7中的各个方法的相应流程,为了简洁,在此不再赘述。
应理解,本发明实施例中,图15和图16中的集成电路卡也可以是一种终端,除了图15或图16中的所有元件外,该终端还包括一个安装有至少两个激活的profile的集成电路卡,在该集成电路卡中的激活的profile都失去网络连接时,由终端去激活优先级较低的激活的profile,激活备用profile,并使用备用profile建立网络连接。
本发明实施例中,当集成电路卡中安装有两个激活的profile,并且两个激活的profile都失去网络连接时,集成电路卡去激活两个激活的profile中优先级较低的profile,并激活备用profile,提供了一种当集成电路卡中安装有两个激活的profile时的保持网络连接的方法。
应理解,在本发明上述实施例中,处理器可以是中央处理单元(Central Processing Unit,简称CPU),还可以是其他通用处理器、数字信号处理器(DSP)、专用集成电路(ASIC)、现场可编程门阵列(FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。
存储器可以包括只读存储器和随机存取存储器,存储有程序代码,并向处理器提供指令和数据。
通信总线除包括数据总线之外,还可以包括电源总线、控制总线和状态信号总线等。但是为了清楚说明起见,在图中将各种总线都标为通信总线。
在实现过程中,上述方法的各步骤可以通过处理器中的硬件的集成逻辑电 路或者软件形式的指令完成。结合本发明实施例所公开的方法的步骤可以直接体现为硬件处理器执行完成,或者用处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器,处理器读取存储器中的信息,结合其硬件完成上述方法的步骤。为避免重复,这里不再详细描述。
在本说明书中使用的术语“部件”、“模块”、“系统”等用于表示计算机相关的实体、硬件、固件、硬件和软件的组合、软件、或执行中的软件。例如,部件可以是但不限于,在处理器上运行的进程、处理器、对象、可执行文件、执行线程、程序和/或计算机。通过图示,在计算设备上运行的应用和计算设备都可以是部件。一个或多个部件可驻留在进程和/或执行线程中,部件可位于一个计算机上和/或分布在2个或更多个计算机之间。此外,这些部件可从在上面存储有各种数据结构的各种计算机可读介质执行。部件可例如根据具有一个或多个数据分组(例如来自与本地系统、分布式系统和/或网络间的另一部件交互的二个部件的数据,例如通过信号与其它系统交互的互联网)的信号通过本地和/或远程进程来通信。
此外,本发明的各个方面或特征可以实现成方法、装置或使用标准编程和/或工程技术的制品。本申请中使用的术语“制品”涵盖可从任何计算机可读器件、载体或介质访问的计算机程序。例如,计算机可读介质可以包括,但不限于:磁存储器件(例如,硬盘、软盘或磁带等),光盘(例如,CD(Compact Disk,压缩盘)、DVD(Digital Versatile Disk,数字通用盘)等),智能卡和闪存器件(例如,EPROM(Erasable Programmable Read-Only Memory,可擦写可编程只读存储器)、卡、棒或钥匙驱动器等)。另外,本文描述的各种存储介质可代表用于存储信息的一个或多个设备和/或其它机器可读介质。术语“机器可读介质”可包括但不限于,无线信道和能够存储、包含和/或承载指令和/或数据的各种其它介质。
本领域普通技术人员可以意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,能够以电子硬件、计算机软件或者二者的结合来实现,为了清楚地说明硬件和软件的可互换性,在上述说明中已经按照功能一般性地描述了各示例的组成及步骤。这些功能究竟以硬件还是软件方式来执行,取决 于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本发明的范围。
所属领域的技术人员可以清楚地了解到,为了描述的方便和简洁,上述描述的系统、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统、装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另外,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口、装置或单元的间接耦合或通信连接,也可以是电的,机械的或其它的形式连接。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本发明实施例方案的目的。
另外,在本发明各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以是两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本发明的技术方案本质上或者说对现有技术做出贡献的部分,或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本发明各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述,仅为本发明的具体实施方式,但本发明的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本发明揭露的技术范围内,可轻易想到各种等效的修改或替换,这些修改或替换都应涵盖在本发明的保护范围之内。因此,本发明的保护范围应以权利要求的保护范围为准。

Claims (36)

  1. 一种profile下载方法,其特征在于,所述方法应用于安装有激活的第一profile和激活的第二profile的嵌入式通用集成电路卡eUICC,包括:
    所述eUICC接收profile管理器PM通过所述第一profile发送的数据连接建立请求;
    所述eUICC判断所述第一profile是否符合预设条件;
    若所述第一profile符合所述预设条件,则所述eUICC使用所述第一profile建立所述eUICC和所述PM之间的数据连接;
    若所述第一profile不符合所述预设条件,则所述eUICC判断所述第二profile是否符合所述预设条件;
    若所述第二profile符合所述预设条件,则所述eUICC使用所述第二profile建立所述eUICC和所述PM之间的数据连接;
    所述eUICC通过所述数据连接下载新的profile。
  2. 根据权利要求1所述的方法,其特征在于,所述eUICC中还安装有未激活的第三profile,所述eUICC通过所述数据连接下载新的profile之前进一步包括:
    若所述第二profile不符合所述预设条件,则所述eUICC判断所述第三profile是否符合所述预设条件;
    若所述第三profile符合所述预设条件,则所述eUICC激活所述第三profile,并使用所述第三profile建立所述eUICC和所述PM之间的数据连接。
  3. 根据权利要求1或2所述的方法,其特征在于,所述第一profile的数量为一个,所述第二profile的数量有多个,所述第一profile和所述第二profile均设置有优先级;
    所述若所述第二profile符合所述预设条件,则所述eUICC使用所述第二profile建立所述eUICC和所述PM之间的数据连接,包括:
    若只有一个所述第二profile符合所述预设条件,则使用符合所述预设条件的第二profile建立所述eUICC和所述PM之间的数据连接;
    若有至少两个所述第二profile符合所述预设条件,则所述eUICC使用符合所述预设条件,且优先级最高的第二profile建立所述eUICC和所述PM之间的 数据连接。
  4. 根据权利要求1-3任一项所述的方法,其特征在于,所述预设条件包括以下任意之一:
    具备配置属性、当前已建立分组数据连接和专用于建立所述eUICC和所述PM之间数据连接。
  5. 一种profile激活方法,其特征在于,所述方法应用于安装有两个激活的profile和至少一个未激活的profile的嵌入式通用集成电路卡eUICC,所述两个激活的profile设置有优先级,包括:
    所述eUICC接收profile管理器PM发送的profile激活请求,所述profile激活请求用于请求激活目标profile,所述目标profile为其中一个所述未激活的profile;
    所述eUICC判断当前激活的profile的数量是否达到允许的最大值;
    若是,则所述eUICC去激活所述激活的profile中优先级较低的profile,并且激活所述目标profile;
    若否,则所述eUICC激活所述目标profile。
  6. 根据权利要求5所述的方法,其特征在于,所述方法进一步包括:
    所述eUICC根据当前激活的profile的优先级,将当前激活的profile依次附着到网络。
  7. 一种profile去激活方法,其特征在于,包括:
    嵌入式通用集成电路卡eUICC接收profile管理器PM发送的profile去激活请求,所述profile去激活请求用于请求去激活目标profile,所述目标profile为所述eUICC中的一个激活的profile;
    所述eUICC判断除了所述目标profile以外所述eUICC中是否还有其他激活的profile;
    若是,则所述eUICC去激活所述目标profile;
    若否,则所述eUICC去激活所述目标profile,激活所述eUICC中的备用profile;
    所述eUICC向终端设备请求重新启动所述eUICC。
  8. 根据权利要求7所述的方法,其特征在于,所述备用profile为所述eUICC中当前激活的profile都失去网络连接时,预设激活的profile。
  9. 根据权利要求7或8所述的方法,其特征在于,所述方法进一步包括:
    所述eUICC将当前激活的profile附着到网络。
  10. 一种保持网络连接的方法,其特征在于,所述方法应用于安装有激活的第一profile、激活的第二profile和未激活的备用profile的嵌入式通用集成电路卡eUICC,所述第一profile和所述第二profile设置有优先级,包括:
    所述eUICC接收终端设备发送的第一通知消息,所述第一通知消息用于通知所述eUICC所述第一profile失去网络连接;
    所述eUICC向所述终端设备发送连接建立消息,所述连接建立消息用于使用所述第二profile建立网络连接;
    若所述第二profile失去网络连接,所述eUICC去激活所述第一profile和所述第二profile中优先级较低的profile,并激活所述备用profile;
    所述eUICC向所述终端设备请求重新启动所述eUICC。
  11. 根据权利要求10所述的方法,其特征在于,所述失去网络连接为没有网络覆盖或失去和网络的数据连接。
  12. 根据权利要求10或11所述的方法,其特征在于,所述eUICC向所述终端设备发送连接建立消息之前进一步包括:
    所述eUICC确认所述第一profile失去网络连接的时间超过第一阈值;或者
    所述eUICC确认使用所述第一profile重新建立网络连接失败的次数超过第二阈值。
  13. 一种集成电路卡,其特征在于,所述集成电路卡中安装有激活的第一profile和激活的第二profile,包括:
    接收单元,用于接收profile管理器PM通过所述第一profile发送的数据连接建立请求;
    判断单元,用于判断所述第一profile是否符合预设条件,以及当所述第一profile不符合所述预设条件时,判断所述第二profile是否符合所述预设条件;
    连接建立单元,用于当所述第一profile符合所述预设条件时,使用所述第一profile建立所述集成电路卡和所述PM之间的数据连接;当所述第一profile不符合所述预设条件,所述第二profile符合所述预设条件时,使用所述第二profile建立所述集成电路卡和所述PM之间的数据连接;
    下载单元,用于通过所述数据连接下载新的profile。
  14. 根据权利要求13所述的集成电路卡,其特征在于,所述集成电路卡中还安装有未激活的第三profile,所述判断单元还用于当所述第一profile和所述第二profile都不符合所述预设条件时,判断所述第三profile是否符合所述预设条件;
    所述连接建立单元还用于当所述第一profile和所述第二profile都不符合所述预设条件,所述第三profile符合所述预设条件时,激活所述第三profile,并使用所述第三profile建立所述集成电路卡和所述PM之间的数据连接。
  15. 根据权利要求13或14所述的集成电路卡,其特征在于,所述第一profile的数量为一个,所述第二profile的数量有多个,所述第一profile和所述第二profile均设置有优先级;
    所述连接建立单元用于当所述第一profile不符合所述预设条件,所述第二profile符合所述预设条件时,使用所述第二profile建立所述集成电路卡和所述PM之间的数据连接,包括:
    所述连接建立单元用于当只有一个所述第二profile符合所述预设条件时,使用所述符合预设条件的第二profile建立所述集成电路卡和所述PM之间的数据连接;当有至少两个所述第二profile符合所述预设条件,使用符合所述预设条件,且优先级最高的第二profile建立所述集成电路卡和所述PM之间的数据连接。
  16. 根据权利要求13-15任一项所述的集成电路卡,其特征在于,所述预设条件包括以下任意之一:
    具备配置属性、当前已建立分组数据连接和专用于建立所述集成电路卡和所述PM之间数据连接。
  17. 一种集成电路卡,其特征在于,所述集成电路卡安装有两个激活的profile和至少一个未激活的profile,所述两个激活的profile设置有优先级,包括:
    接收单元,用于接收profile管理器PM发送的profile激活请求,所述profile激活请求用于请求激活目标profile,所述目标profile为其中一个所述未激活的profile;
    判断单元,用于判断当前激活的profile的数量是否达到允许的最大值;
    激活和去激活单元,用于当前激活的profile的数量达到允许的最大值时,去激活所述激活的profile中优先级较低的profile,并且激活所述目标profile; 当前激活的profile的数量未达到允许的最大值时,激活所述目标profile。
  18. 根据权利要求17所述的集成电路卡,其特征在于,所述集成电路卡进一步包括:
    网络附着单元,用于根据当前激活的profile的优先级,将当前激活的profile依次附着到网络。
  19. 一种集成电路卡,其特征在于,包括:
    接收单元,用于接收profile管理器PM发送的profile去激活请求,所述profile去激活请求用于请求去激活目标profile,所述目标profile为所述集成电路卡中的一个激活的profile;
    判断单元,用于判断除了所述目标profile以外所述集成电路卡中是否还有其他激活的profile;
    激活和去激活单元,用于当除了所述目标profile以外所述集成电路卡中还有其他激活的profile时,去激活所述目标profile;当除了所述目标profile以外所述集成电路卡中没有其他激活的profile时,去激活所述目标profile,激活所述集成电路卡中的备用profile;
    发送单元,用于向终端设备请求重新启动所述集成电路卡。
  20. 根据权利要求19所述的集成电路卡,其特征在于,所述备用profile为所述集成电路卡中当前激活的profile都失去网络连接时,预设激活的profile。
  21. 根据权利要求19或20所述的集成电路卡,其特征在于,所述集成电路卡进一步包括:
    网络附着单元,用于将当前激活的profile附着到网络。
  22. 一种集成电路卡,其特征在于,所述集成电路卡中安装有激活的第一profile、激活的第二profile和未激活的备用profile,所述第一profile和所述第二profile设置有优先级,包括:
    接收单元,用于接收终端设备发送的第一通知消息,所述第一通知消息用于通知所述集成电路卡所述第一profile失去网络连接;
    发送单元,用于向所述终端设备发送连接建立消息,所述连接建立消息用于使用所述第二profile建立网络连接;
    激活和去激活单元,用于当所述第二profile失去网络连接时,去激活所述第一profile和所述第二profile中优先级较低的profile并激活所述备用profile;
    所述发送单元还用于向所述终端设备请求重新启动所述集成电路卡。
  23. 根据权利要求22所述的集成电路卡,其特征在于,所述失去网络连接为没有网络覆盖或失去和网络的数据连接。
  24. 根据权利要求22或23所述的集成电路卡,其特征在于,所述集成电路卡进一步包括确认单元,用于所述发送单元向所述终端设备发送连接建立消息之前确认所述第一profile失去网络连接的时间超过第一阈值,或者确认使用所述第一profile重新建立网络连接失败的次数超过第二阈值。
  25. 一种集成电路卡,其特征在于,所述集成电路卡中安装有激活的第一profile和激活的第二profile,包括:
    接收器,用于接收profile管理器PM通过所述第一profile发送的数据连接建立请求,以及通过所述集成电路卡和所述PM之间的数据连接下载新的profile;
    处理器,用于判断所述第一profile是否符合预设条件,若所述第一profile符合所述预设条件,则使用所述第一profile建立所述集成电路卡和所述PM之间的数据连接;若所述第一profile不符合所述预设条件,则判断所述第二profile是否符合所述预设条件,若所述第二profile符合所述预设条件,则使用所述第二profile建立所述集成电路卡和所述PM之间的数据连接;
    存储器,用于存储程序代码;
    通信总线,用于连接所述接收器、所述处理器和所述存储器。
  26. 根据权利要求25所述的集成电路卡,其特征在于,所述集成电路卡中还安装有未激活的第三profile,所述处理器还用于若所述第一profile和所述第二profile都不符合所述预设条件,则判断所述第三profile是否符合所述预设条件;若所述第三profile符合所述预设条件,则激活所述第三profile,并使用所述第三profile建立所述集成电路卡和所述PM之间的数据连接。
  27. 根据权利要求25或26所述的集成电路卡,其特征在于,所述第一profile的数量为一个,所述第二profile的数量有多个,所述第一profile和所述第二profile设置有优先级;
    所述处理器用于若所述第二profile符合所述预设条件,则使用所述第二profile建立所述集成电路卡和所述PM之间的数据连接,包括:
    所述处理器用于若只有一个所述第二profile符合所述预设条件,则使用符合所述预设条件的第二profile建立所述集成电路卡和所述PM之间的数据连接; 若有至少两个所述第二profile符合所述预设条件,则使用符合所述预设条件,且优先级最高的第二profile建立所述集成电路卡和所述PM之间的数据连接。
  28. 根据权利要求25-27任一项所述的集成电路卡,其特征在于,所述预设条件包括以下任意之一:
    具备配置属性、当前已建立分组数据连接和专用于建立所述集成电路卡和所述PM之间数据连接。
  29. 一种集成电路卡,其特征在于,所述集成电路卡安装有两个激活的profile和至少一个未激活的profile,所述两个激活的profile设置有优先级,包括:
    接收器,用于接收profile管理器PM发送的profile激活请求,所述profile激活请求用于请求激活目标profile,所述目标profile为其中一个所述未激活的profile;
    处理器,用于判断当前激活的profile的数量是否达到允许的最大值,若是,则去激活所述激活的profile中优先级较低的profile,并且激活所述目标profile;若否,则激活所述目标profile。
    存储器,用于存储程序代码;
    通信总线,用于连接所述接收器、所述处理器和所述存储器。
  30. 根据权利要求29所述的集成电路卡,其特征在于,所述处理器还用于根据当前激活的profile的优先级,将当前激活的profile依次附着到网络。
  31. 一种集成电路卡,其特征在于,包括:
    接收器,用于接收profile管理器PM发送的profile去激活请求,所述profile去激活请求用于请求去激活目标profile,所述目标profile为所述集成电路卡中的一个激活的profile;
    处理器,用于判断除了所述目标profile以外所述集成电路卡中是否还有其他激活的profile,若是,则去激活所述目标profile;若否,则去激活所述目标profile,激活所述集成电路卡中的备用profile;
    发射器,用于向终端设备请求重新启动所述集成电路卡;
    存储器,用于存储程序代码;
    通信总线,用于连接所述接收器、所述发射器、所述处理器和所述存储器。
  32. 根据权利要求31所述的集成电路卡,其特征在于,所述备用profile为所述集成电路卡中当前激活的profile都失去网络连接时,预设激活的profile。
  33. 根据权利要求31或32所述的集成电路卡,其特征在于,所述处理器还用于将当前激活的profile附着到网络。
  34. 一种集成电路卡,其特征在于,所述集成电路卡中安装有激活的第一profile、激活的第二profile和未激活的备用profile,所述第一profile和所述第二profile设置有优先级,包括:
    接收器,用于接收终端设备发送的第一通知消息,所述第一通知消息用于通知所述集成电路卡所述第一profile失去网络连接;
    发射器,用于向所述终端设备发送连接建立消息,所述连接建立消息用于使用所述第二profile建立网络连接,所述发射器还用于向所述终端设备请求重新启动所述集成电路卡;
    处理器,用于若所述第二profile失去网络连接,则去激活所述第一profile和所述第二profile中优先级较低的profile并激活所述备用profile;
    存储器,用于存储程序代码;
    通信总线,用于连接所述接收器、所述发射器、所述处理器和所述存储器。
  35. 根据权利要求34所述的集成电路卡,其特征在于,所述失去网络连接为没有网络覆盖或失去和网络的数据连接。
  36. 根据权利要求34或35所述的集成电路卡,其特征在于,所述处理器还用于所述发射器向所述终端设备发送连接建立消息之前,确认所述第一profile失去网络连接的时间超过第一阈值,或者确认使用所述第一profile重新建立网络连接失败的次数超过第二阈值。
PCT/CN2015/073118 2015-02-15 2015-02-15 一种profile下载和激活方法、集成电路卡及系统 WO2016127435A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2015/073118 WO2016127435A1 (zh) 2015-02-15 2015-02-15 一种profile下载和激活方法、集成电路卡及系统
CN201580075336.7A CN107211385B (zh) 2015-02-15 2015-02-15 一种profile下载和激活方法、集成电路卡及系统

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2015/073118 WO2016127435A1 (zh) 2015-02-15 2015-02-15 一种profile下载和激活方法、集成电路卡及系统

Publications (1)

Publication Number Publication Date
WO2016127435A1 true WO2016127435A1 (zh) 2016-08-18

Family

ID=56615025

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/073118 WO2016127435A1 (zh) 2015-02-15 2015-02-15 一种profile下载和激活方法、集成电路卡及系统

Country Status (2)

Country Link
CN (1) CN107211385B (zh)
WO (1) WO2016127435A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110519350A (zh) * 2019-08-15 2019-11-29 中国联合网络通信集团有限公司 一种终端的调度方法及装置
KR20210005653A (ko) * 2018-04-26 2021-01-14 후아웨이 테크놀러지 컴퍼니 리미티드 단말 애플리케이션 활성화 방법, 장치 및 시스템

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR102394334B1 (ko) * 2017-12-19 2022-05-06 삼성전자주식회사 보안 엘리먼트를 이용하여 통신 서비스를 제공하는 방법 및 이를 위한 전자 장치
CN110809255B (zh) * 2018-08-06 2022-05-24 中兴通讯股份有限公司 一种卡信息激活方法、装置及存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103020511A (zh) * 2011-09-23 2013-04-03 三星Sds株式会社 移动装置管理设备和方法以及管理服务器
US20130283047A1 (en) * 2010-08-05 2013-10-24 Gemalto Sa System and method for securely using multiple subscriber profiles with a security component and a mobile telecommunications device
CN103533634A (zh) * 2013-10-25 2014-01-22 中国联合网络通信集团有限公司 激活配置文件的系统、eUICC及其激活配置文件的方法
CN104185179A (zh) * 2013-05-27 2014-12-03 中国移动通信集团公司 一种用于用户识别卡的控制装置、方法及用户识别卡

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2013027085A1 (en) * 2011-08-22 2013-02-28 Nokia Corporation Multi-sim enabling application and use of euicc in legacy terminals
US9674690B2 (en) * 2012-05-23 2017-06-06 Kt Corporation Method for control and enforcement of policy rule and EUICC

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20130283047A1 (en) * 2010-08-05 2013-10-24 Gemalto Sa System and method for securely using multiple subscriber profiles with a security component and a mobile telecommunications device
CN103020511A (zh) * 2011-09-23 2013-04-03 三星Sds株式会社 移动装置管理设备和方法以及管理服务器
CN104185179A (zh) * 2013-05-27 2014-12-03 中国移动通信集团公司 一种用于用户识别卡的控制装置、方法及用户识别卡
CN103533634A (zh) * 2013-10-25 2014-01-22 中国联合网络通信集团有限公司 激活配置文件的系统、eUICC及其激活配置文件的方法

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
CHANG, JIE: "Research on the Embedded UICC Security Technology in Internet of Things", CHINA INTERNET, no. 1, 31 January 2015 (2015-01-31) *

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20210005653A (ko) * 2018-04-26 2021-01-14 후아웨이 테크놀러지 컴퍼니 리미티드 단말 애플리케이션 활성화 방법, 장치 및 시스템
EP3780900A4 (en) * 2018-04-26 2021-06-09 Huawei Technologies Co., Ltd. TERMINAL, DEVICE AND SYSTEM APPLICATION ACTIVATION PROCESS
JP2021520746A (ja) * 2018-04-26 2021-08-19 華為技術有限公司Huawei Technologies Co.,Ltd. 端末アプリケーション起動方法、装置、およびシステム
KR102478936B1 (ko) 2018-04-26 2022-12-16 후아웨이 테크놀러지 컴퍼니 리미티드 단말 애플리케이션 활성화 방법, 장치 및 시스템
KR20230003620A (ko) * 2018-04-26 2023-01-06 후아웨이 테크놀러지 컴퍼니 리미티드 단말 애플리케이션 활성화 방법, 장치 및 시스템
JP7241770B2 (ja) 2018-04-26 2023-03-17 華為技術有限公司 端末アプリケーション起動方法、装置、およびシステム
KR102571100B1 (ko) 2018-04-26 2023-08-24 후아웨이 테크놀러지 컴퍼니 리미티드 단말 애플리케이션 활성화 방법, 장치 및 시스템
CN110519350A (zh) * 2019-08-15 2019-11-29 中国联合网络通信集团有限公司 一种终端的调度方法及装置
CN110519350B (zh) * 2019-08-15 2023-11-03 中国联合网络通信集团有限公司 一种终端的调度方法及装置

Also Published As

Publication number Publication date
CN107211385A (zh) 2017-09-26
CN107211385B (zh) 2020-06-02

Similar Documents

Publication Publication Date Title
US9462457B2 (en) Subscription transfer method, apparatus, and system
US10141966B2 (en) Update of a trusted name list
US10356606B2 (en) Proxy platform for inter-operator provisioning of eSIM profiles
US20220385445A1 (en) EMBEDDED UNIVERSAL INTEGRATED CIRCUIT CARD (eUICC) PROFILE CONTENT MANAGEMENT
CN107835204B (zh) 配置文件策略规则的安全控制
KR101474096B1 (ko) 가입자 디바이스들의 네트워크 개인화를 위한 방법 및 장치
US20160057725A1 (en) Security method and system for supporting re-subscription or additional subscription restriction policy in mobile communications
US9439069B2 (en) Subscriber identity module provider apparatus for over-the-air provisioning of subscriber identity module containers and methods
US10721616B2 (en) Subscription information download method, related device, and system
KR20160009966A (ko) 프로파일 관리서버의 업데이트 방법 및 장치
CN109417702B (zh) 包括片的通信网络中的接入控制
US11659621B2 (en) Selection of IP version
KR20210138812A (ko) 세션 관리 기능 선택을 위한 방법 및 장치
US11388661B2 (en) Network slice configuration update
US20210051098A1 (en) Method and apparatus for universal integrated circuit card update via dedicated network function
WO2016127435A1 (zh) 一种profile下载和激活方法、集成电路卡及系统
JP2016524393A (ja) 近接サービス許可方法、装置及びシステム
CN111466109A (zh) 用于提供网络接入的方法和订户身份组件
US11706591B2 (en) Methods to enable Wi-Fi onboarding of user equipment by utilizing an eSIM
KR101944647B1 (ko) 데이터 처리 방법, 장치, 단말기, 이동성 관리 엔티티 및 시스템
CN104796852A (zh) 用于终端直连通信的设备发现方法、装置和终端
US20210204118A1 (en) Privacy Key in a Wireless Communication System
CN114189844A (zh) 终端跨区域通信方法、网元设备及存储介质
JP2022525370A (ja) Sm‐srプラットフォームを介してセキュアエレメントのオペレーティングシステムに透過的にパッチを適用する方法
ES2748112T3 (es) Método para cargar credenciales de suscriptor y equipo asociado

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15881597

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15881597

Country of ref document: EP

Kind code of ref document: A1