WO2026005508A1 - Embedded universal integrated circuit card (euicc) 외부로 프로파일을 이동 및 저장하기 위한 방법 및 장치 - Google Patents

Embedded universal integrated circuit card (euicc) 외부로 프로파일을 이동 및 저장하기 위한 방법 및 장치

Info

Publication number
WO2026005508A1
WO2026005508A1 PCT/KR2025/009001 KR2025009001W WO2026005508A1 WO 2026005508 A1 WO2026005508 A1 WO 2026005508A1 KR 2025009001 W KR2025009001 W KR 2025009001W WO 2026005508 A1 WO2026005508 A1 WO 2026005508A1
Authority
WO
WIPO (PCT)
Prior art keywords
profile
euicc
information
terminal
server
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/KR2025/009001
Other languages
English (en)
French (fr)
Inventor
강수정
윤강진
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Samsung Electronics Co Ltd
Original Assignee
Samsung Electronics Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from KR1020250033994A external-priority patent/KR20260001068A/ko
Priority claimed from KR1020250056560A external-priority patent/KR20260001076A/ko
Application filed by Samsung Electronics Co Ltd filed Critical Samsung Electronics Co Ltd
Publication of WO2026005508A1 publication Critical patent/WO2026005508A1/ko
Pending legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • H04W8/20Transfer of user or subscriber data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/02Terminal devices

Definitions

  • the present disclosure relates to a wireless communication system or a mobile communication system. Specifically, it relates to a method and device for transferring communication subscription information from a terminal.
  • the method and device enable profile installation by extracting and transferring a profile previously stored in an eUICC to a location outside the eUICC when installing a profile in a terminal, thereby securing installation space and enabling profile installation.
  • 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in the sub-6GHz frequency band such as 3.5 gigahertz (3.5GHz), but also in the ultra-high frequency band called millimeter wave (mmWave) such as 28GHz and 39GHz ('Above 6GHz').
  • mmWave millimeter wave
  • mmWave millimeter wave
  • mmWave millimeter wave
  • 'Above 6GHz' millimeter wave
  • 6G mobile communication technology which is called the system after 5G communication (Beyond 5G)
  • THz terahertz
  • eMBB enhanced Mobile Broadband
  • URLLC Ultra-Reliable Low-Latency Communications
  • mMTC massive Machine-Type Communications
  • beamforming and massive MIMO to mitigate path loss of radio waves in ultra-high frequency bands and increase the transmission distance of radio waves
  • numerologies such as operation of multiple subcarrier intervals
  • dynamic operation of slot formats for efficient use of ultra-high frequency resources
  • initial access technology to support multi-beam transmission and wideband
  • definition and operation of BWP Bitth Part
  • new channel coding methods such as LDPC (Low Density Parity Check) codes for large-capacity data transmission and Polar Code for reliable transmission of control information
  • L2 pre-processing L2 pre-processing
  • V2X Vehicle-to-Everything
  • NR-U New Radio Unlicensed
  • UE Power Saving NR terminal low power consumption technology
  • NTN Non-Terrestrial Network
  • wireless interface architecture/protocols for technologies such as intelligent factories (Industrial Internet of Things, IIoT) to support new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) that provides nodes for expanding network service areas by integrating wireless backhaul links and access links, Mobility Enhancement technology including Conditional Handover and Dual Active Protocol Stack (DAPS) handover, and 2-step random access (2-step RACH for NR) that simplifies random access procedures is also in progress, and standardization of system architecture/services for 5G baseline architecture (e.g., Service-based Architecture, Service-based Interface) for grafting Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) that provides services based on the location of the terminal is also in progress.
  • 5G baseline architecture e.g., Service-based Architecture, Service-based Interface
  • NFV Network Functions Virtualization
  • SDN Software-Defined Networking
  • MEC Mobile Edge Computing
  • the development of these 5G mobile communication systems includes new waveforms to ensure coverage in the terahertz band of 6G mobile communication technology, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), Array Antenna, and Large Scale Antenna, metamaterial-based lenses and antennas to improve the coverage of terahertz band signals, high-dimensional spatial multiplexing technology using Orbital Angular Momentum (OAM), Reconfigurable Intelligent Surface (RIS) technology, as well as full duplex technology to improve the frequency efficiency and system network of 6G mobile communication technology, satellite, AI (Artificial Intelligence) from the design stage and AI-based communication technology that realizes system optimization by internalizing end-to-end AI support functions, and ultra-high-performance communication and computing resources to provide services with complexity that exceeds the limits of terminal computing capabilities. It can serve as a basis for the development of next-generation distributed computing technologies that can be realized by utilizing them.
  • FD-MIMO Full Dimensional MIMO
  • Array Antenna and
  • An object of the present invention is to provide a method and a terminal for transferring a profile to the outside of an embedded universal integrated circuit card (eUICC) of a terminal.
  • eUICC embedded universal integrated circuit card
  • a method performed by a terminal in a wireless communication system may include: transmitting a first message including additionalprofile information to a profile server for profile installation; and, when the additionalprofile information is set to a preset value, receiving a second message including information on the predicted profile size from the profile server; controlling to secure embedded universal integrated circuit card (eUICC) memory based on reception of the second message including information on the predicted profile size; and performing the profile installation based on the securing of the eUICC memory.
  • eUICC embedded universal integrated circuit card
  • a method performed by a profile server in a wireless communication system may include: receiving a first message including additional profile information from a terminal for profile installation; determining whether the additional profile information is set to a preset value; and transmitting a second message including information about a predicted profile size if the additional profile information is set to a preset value.
  • a terminal in a wireless communication system.
  • the terminal may include a transceiver; and a control unit configured to transmit a first message including additionalprofile information to a profile server for profile installation through the transceiver, and, when the additionalprofile information is set to a preset value, receive a second message including information on the predicted profile size from the profile server through the transceiver, and, based on reception of the second message including information on the predicted profile size, control to secure embedded universal integrated circuit card (eUICC) memory, and control to perform profile installation based on the securing of the eUICC memory.
  • eUICC embedded universal integrated circuit card
  • a profile server in a wireless communication system.
  • the profile server may include a transceiver; and a step of receiving a first message including additional profile information from a terminal for profile installation through the transceiver, and determining whether the additional profile information is set to a preset value; and a control unit controlling transmission of a second message including information on a predicted profile size if the additional profile information is set to a preset value.
  • FIG. 1 is a diagram showing the relationship between components for moving a profile according to one embodiment of the present disclosure.
  • FIG. 2 is a diagram illustrating a procedure for moving a profile outside an eUICC according to one embodiment of the present disclosure.
  • FIG. 3 is another diagram illustrating a procedure for moving a profile outside an eUICC according to another embodiment of the present disclosure.
  • FIG. 4 is a diagram illustrating an example of checking eUICC available memory and moving a profile when installing a profile download according to an embodiment of the present disclosure.
  • FIG. 5 is a diagram illustrating an example of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
  • FIG. 6 is another diagram illustrating another embodiment of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
  • FIG. 7 is a diagram illustrating a method for resuming installation of an existing profile after moving a profile within a terminal according to an embodiment of the present disclosure.
  • Figure 8 is a diagram illustrating a method for resuming installation of an existing profile after moving the profile within the terminal.
  • FIG. 9 is a diagram illustrating a procedure for moving a profile from an eUICC to outside the eUICC according to one embodiment of the present disclosure.
  • FIG. 10 is a diagram illustrating a configuration of a terminal according to some embodiments of the present disclosure.
  • FIG. 11 is a diagram illustrating a configuration of a server according to some embodiments of the present disclosure.
  • FIG. 12a is a diagram illustrating an example of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
  • FIG. 12b is a diagram illustrating a specific embodiment of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
  • FIG. 13 is a diagram illustrating an embodiment in which a profile server provides a session maintenance time to a terminal according to one embodiment of the present disclosure.
  • each block of the processing flowchart drawings and combinations of the flowchart drawings can be performed by computer program instructions.
  • These computer program instructions can be installed in a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, so that the instructions executed by the processor of the computer or other programmable data processing equipment create a means for performing the functions described in the flowchart block(s).
  • These computer program instructions can also be stored in a computer-available or computer-readable memory that can direct a computer or other programmable data processing equipment to implement the functions in a specific manner, so that the instructions stored in the computer-available or computer-readable memory can also produce a manufactured item that includes an instruction means for performing the functions described in the flowchart block(s).
  • the computer program instructions may be installed on a computer or other programmable data processing device, a series of operational steps may be performed on the computer or other programmable data processing device to create a computer-executable process, and the instructions that cause the computer or other programmable data processing device to perform the steps for performing the functions described in the flowchart block(s) may also provide steps for performing the functions described in the flowchart block(s).
  • each block may represent a module, segment, or portion of code that contains one or more executable instructions for performing a specific logical function(s).
  • the functions described in the blocks may occur out of order. For example, two blocks depicted in succession may actually be executed substantially concurrently, or the blocks may sometimes be executed in reverse order, depending on their respective functions.
  • the term ' ⁇ unit' used in the present embodiment means a software or hardware component such as an FPGA or ASIC, and the ' ⁇ unit' performs certain roles.
  • the ' ⁇ unit' is not limited to software or hardware.
  • the ' ⁇ unit' may be configured to be on an addressable storage medium and may be configured to play one or more processors.
  • the ' ⁇ unit' includes components such as software components, object-oriented software components, class components, and task components, processes, functions, properties, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables.
  • components and ' ⁇ units' may be combined into a smaller number of components and ' ⁇ units' or further separated into additional components and ' ⁇ units'. Additionally, components and ' ⁇ parts' may be implemented to regenerate one or more CPUs within a device or secure multimedia card.
  • modifiers such as “first” and “second” that designate terms may be used to distinguish each term from another when describing embodiments.
  • the terms modified by modifiers such as “first” and “second” may refer to different objects.
  • the terms modified by modifiers such as “first” and “second” may also refer to the same object. That is, modifiers such as “first” and “second” may be used to refer to the same object from different perspectives.
  • modifiers such as “first” and “second” may be used to distinguish the same object from a functional or operational perspective.
  • “first user” and “second user” may refer to the same user.
  • 5G or pre-5G communication systems are also called beyond 4G network (Beyond 4G Network) or post-LTE (Post LTE) systems.
  • 4G network Beyond 4G Network
  • Post LTE Post LTE
  • 5G communication systems are being considered for implementation in ultra-high frequency (mmWave) bands (e.g., 60 GHz bands).
  • mmWave ultra-high frequency bands
  • FD-MIMO full-dimensional MIMO
  • array antennas analog beamforming, and large-scale antenna technologies are being discussed in 5G communication systems.
  • ACM advanced coding modulation
  • FQAM Hybrid FSK and QAM Modulation
  • SWSC Small Cell Superposition Coding
  • FBMC Filter Bank Multi Carrier
  • NOMA non-orthogonal multiple access
  • SCMA parse code multiple access
  • IoT Internet of Things
  • IoE Internet of Everything
  • sensing technology wireless and wired communication and network infrastructure
  • service interface technology service interface technology
  • MTC Machine-Type Communication
  • IoT intelligent IT services can be provided that collect and analyze data generated from connected objects to create new value in human life.
  • IoT can be applied to areas such as smart homes, smart buildings, smart cities, smart or connected cars, smart grids, healthcare, smart appliances, and advanced medical services through the convergence and integration of existing IT (information technology) technologies with various industries.
  • 5G communication systems to IoT networks.
  • technologies such as sensor networks, machine-to-machine (M2M), and machine-type communication (MTC) are being implemented using 5G communication techniques such as beamforming, MIMO, and array antennas.
  • 5G communication techniques such as beamforming, MIMO, and array antennas.
  • cloud RAN a big data processing technology described above, can also be considered an example of the convergence of 5G and IoT technologies.
  • one or more profiles containing user subscription information can be installed and used on an eSIM chip within a terminal.
  • profiles can be exported from the eSIM chip and then reinstalled on the same or a different eSIM chip.
  • a method for exporting a first profile from an eSIM chip in a first terminal in a wireless communication system and then installing it in the same eSIM chip may further include a step of providing, from the terminal to a profile server, information on whether the terminal and the eSIM chip support external storage during the process of installing a new profile, a step of determining whether to send a reply message including additional information on the size of the profile to be installed based on information received from the profile server, a step of checking available memory in the eUICC based on a message received from the profile server in the terminal, a step of performing a determination including a determination as to whether there is a profile that can be moved outside the eUICC, a step of processing a profile move outside the eSIM chip if there is a profile that can be moved, and a step of performing profile installation after performing the profile move.
  • the terminal user can only delete and reinstall a previously purchased profile.
  • the terminal user can move and store the profile outside the eSIM chip and then reinstall it on the eSIM chip when needed. Accordingly, the terminal user can keep the profile he or she purchased and reinstall it on the eSIM chip when needed, thereby reducing the cost incurred when deleting and reinstalling the profile.
  • terminal manufacturers can improve user convenience by solving the problem of limited eSIM chip memory capacity by utilizing storage space outside the eSIM chip.
  • SE Secure Element
  • SE may refer to a security module consisting of a single chip that can store security information (e.g., mobile network access keys, user identification information such as ID cards/passports, credit card information, encryption keys, etc.) and operate a control module (e.g., network access control module such as USIM, encryption module, key generation module, etc.) that utilizes the stored security information.
  • security information e.g., mobile network access keys, user identification information such as ID cards/passports, credit card information, encryption keys, etc.
  • control module e.g., network access control module such as USIM, encryption module, key generation module, etc.
  • SE may be used in various electronic devices (e.g., smartphones, tablets, wearable devices, automobiles, IoT devices, etc.) and provide security services (e.g., mobile network access, payment, user authentication, etc.) through security information and control modules.
  • UICC Universal Integrated Circuit Card
  • eSE Embedded Secure Element
  • SSP Smart Secure Platform
  • UICC Universal Integrated Circuit Card
  • eSE embedded Secure Element
  • SSP Smart Secure Platform
  • UICC Universal Integrated Circuit Card
  • eSE embedded Secure Element
  • SSP Smart Secure Platform
  • a "UICC (Universal Integrated Circuit Card)" is a smart card inserted into mobile communication terminals and is also called a UICC card.
  • a UICC may include an access control module for connecting to a mobile communication service provider's network. Examples of access control modules include a Universal Subscriber Identity Module (USIM), a Subscriber Identity Module (SIM), and an IP Multimedia Service Identity Module (ISIM).
  • USIM Universal Subscriber Identity Module
  • SIM Subscriber Identity Module
  • ISIM IP Multimedia Service Identity Module
  • a UICC containing a USIM is commonly referred to as a USIM card.
  • a UICC containing a SIM module is commonly referred to as a SIM card. Meanwhile, the SIM module may be installed during the UICC manufacturing process, or the user may download the desired mobile communication service's SIM module onto the UICC card at any time.
  • SIM modules may be downloaded and installed on a UICC card, and at least one SIM module may be selected and used.
  • a UICC card may or may not be fixed to the terminal.
  • a UICC built into a System-On-Chip (SoC) including a communication processor, an application processor, or a single processor structure integrating these two processors of a terminal is also referred to as an iUICC (Integrated UICC).
  • SoC System-On-Chip
  • iUICC Integrated UICC
  • eUICC and iUICC may refer to a UICC card that is fixedly used in a terminal and includes a function that allows at least one SIM module to be downloaded remotely to the UICC card and allows any one of the downloaded SIM modules to be selected.
  • a UICC card that includes a function that allows at least one SIM module to be downloaded remotely and the SIM module to be selected is collectively referred to as an eUICC or iUICC.
  • eUICC or iUICC a UICC card that is or is not fixed to a terminal.
  • UICC may be used interchangeably with SIM
  • eUICC may be used interchangeably with eSIM (chip).
  • the "eUICC identifier (eUICC ID)" may be a unique identifier of the eUICC embedded in the terminal and may be referred to as EID.
  • the eUICC identifier (eUICC ID) may be an identifier of the corresponding provisioning profile (Profile ID of the Provisioning Profile).
  • the eUICC identifier (eUICC ID) may be a terminal ID.
  • the eUICC identifier (eUICC ID) may refer to a specific secure domain (Secure Domain) of the eUICC chip.
  • the eUICC identifier may also be provided as predetermined information included in an eUICC certificate. In the present disclosure, providing the EID may be a certificate including EID information or the EID information itself.
  • eSE embedded Secure Element
  • An eSE is typically manufactured exclusively for the terminal manufacturer upon request, and may include an operating system and framework.
  • An applet-type service control module can be remotely downloaded and installed on the eSE, and the installed service control module can be used for various security services such as electronic wallets, ticketing, electronic passports, and digital keys.
  • a single-chip SE that can be remotely downloaded and installed with a service control module and attached to an electronic device is collectively referred to as an eSE.
  • Profile may refer to data objects such as applications, file systems, and authentication key values stored within the UICC.
  • a “profile package” may mean that the contents of a “profile” are packaged in a software form that can be installed in a UICC.
  • a “profile package” may be referred to as a Profile Package TLV. If the profile package is encrypted using encryption parameters, it may be referred to as a Protected Profile Package (PPP) or a Protected Profile Package TLV (PPP TLV). If the profile package is encrypted using encryption parameters that can only be decrypted by a specific eUICC, it may be referred to as a Bound Profile Package (BPP) or a Bound Profile Package TLV (BPP TLV).
  • a Profile Package TLV may be a data set that expresses information that constitutes a profile in the TLV (Tag, Length, Value) format.
  • a 'profile image' may refer to binary data of a profile package installed in a UICC.
  • the 'profile image' may be referred to as a Profile TLV or a Profile Image TLV.
  • the profile image is encrypted using encryption parameters, it may be referred to as a PPI or a Protected Profile Image TLV (PPI TLV).
  • PPI TLV Protected Profile Image TLV
  • BPI TLV Bundled Profile Image TLV
  • the profile image TLV may be a data set representing information that constitutes a profile in TLV format.
  • an 'profile image' is expressed as a profile package or a profile. Therefore, in the present disclosure, an 'EPP (Exported Profile Package)' may be a profile image generated from an installed first profile.
  • the "state" of a profile may mean one of the states of the profile defined in the SGP.22 specification defined by the GSMA.
  • the "profile identifier” may be referred to as an argument that matches a profile identifier (Profile ID), an Integrated Circuit Card ID (ICCID), a Matching ID, an Event ID, an Activation Code, an Activation Code Token, a Command Code, a Command Code Token, a Signed Command Code, an Unsigned Command Code, an ISD-P, or a Profile Domain (PD).
  • the profile identifier (Profile ID) may represent a unique identifier of each profile.
  • the profile identifier may further include the address of a profile providing server (SM-DP+) that can index the profile.
  • the profile identifier may further include the signature of the profile providing server (SM-DP+).
  • RSP Server Remote SIM Provisioning Server
  • SM-XX Subscription Manager XX
  • a “profile server” may include a function of generating a profile, encrypting a generated profile, generating a profile remote management command, or encrypting a generated profile remote management command.
  • the profile server may be expressed as a Subscription Manager Data Preparation (SM-DP), a Subscription Manager Data Preparation plus (SM-DP+), an off-card entity of a Profile Domain, a profile encryption server, a profile generation server, a profile provider (Profile Provisioner, PP), a profile provider, or a profile provisioning credentials holder (PPC holder).
  • SM-DP Subscription Manager Data Preparation
  • SM-DP+ Subscription Manager Data Preparation plus
  • PPC holder profile provisioning credentials holder
  • a “profile management server” may include a function for managing a profile.
  • the profile management server may be expressed as SM-SR (Subscription Manager Secure Routing), SM-SR+ (Subscription Manager Secure Routing Plus), an off-card entity of eUICC Profile Manager or PMC holder (Profile Management Credentials holder), EM (eUICC Manager), or PP (Profile Manager).
  • SM-SR Subscription Manager Secure Routing
  • SM-SR+ Subscribescription Manager Secure Routing Plus
  • PMC holder Profile Management Credentials holder
  • EM eUICC Manager
  • PP Profile Manager
  • the profile server may also mean a combination of the functions of a profile management server. Accordingly, in various embodiments of the present disclosure, the operations of the profile server may be performed by the profile management server. Similarly, the operations of the profile management server or SM-SR may be performed by the profile provision server.
  • the "opening brokerage server” may be expressed as a Subscription Manager Discovery Service (SM-DS), a Discovery Service (DS), a root opening brokerage server (Root SM-DS), or an alternative opening brokerage server (Alternative SM-DS).
  • the opening brokerage server may receive an event registration request (Register Event Request, Event Register Request) from one or more profile providing servers or opening brokerage servers.
  • one or more opening brokerage servers may be used in combination, and in this case, the first opening brokerage server may receive an event registration request not only from the profile providing server but also from the second opening brokerage server.
  • Mobile service provider may refer to a business entity that provides communication services to terminals, and may collectively refer to the business supporting system (BSS), operational supporting system (OSS), point of sale terminal, and other IT systems of the mobile service provider.
  • BSS business supporting system
  • OSS operational supporting system
  • point of sale terminal point of sale terminal
  • other IT systems of the mobile service provider.
  • the mobile service provider is not limited to representing a single specific business entity that provides communication services, but may also be used as a term referring to a group or association (or consortium) of one or more businesses, or an agent representing the group or association.
  • the mobile service provider may be referred to as an operator (or OP or Op.), a mobile network operator (MNO), a mobile virtual network operator (MVNO), a service provider (or SP), a profile owner (PO), a mobile service operator, etc., and each mobile service operator may set or be assigned at least one name and/or object identifier (OID) of the mobile service provider.
  • OID object identifier
  • the carrier refers to a group or association or agency of one or more businesses
  • the name or unique identifier of any group or association or agency may be a name or unique identifier shared by all businesses belonging to that group or association or all businesses cooperating with that agency.
  • the term "Subscriber” can refer to either the Service Provider who owns the terminal, or the End User who owns the terminal.
  • a terminal owned by a Service Provider is referred to as an M2M Device, while a terminal owned by a User is referred to as a Consumer Device.
  • M2M terminals there may be an End User who does not own the terminal but transfers or leases the terminal from the Service Provider.
  • the Subscriber and the Service Provider may be different or the same.
  • a 'terminal' may be referred to as a mobile station (MS), user equipment (UE), user terminal (UT), wireless terminal, access terminal (AT), terminal, subscriber unit (SU), subscriber station (SS), wireless device, wireless communication device, wireless transmit/receive unit (WTRU), mobile node, mobile, or other terms.
  • MS mobile station
  • UE user equipment
  • UT user terminal
  • AT access terminal
  • SU subscriber unit
  • SS subscriber station
  • wireless device wireless communication device
  • WTRU wireless transmit/receive unit
  • mobile node mobile, or other terms.
  • the terminal may include a cellular telephone, a smart phone having a wireless communication function, a personal digital assistant (PDA) having a wireless communication function, a wireless modem, a portable computer having a wireless communication function, a photographing device such as a digital camera having a wireless communication function, a gaming device having a wireless communication function, a music storage and playback home appliance having a wireless communication function, an internet home appliance capable of wireless internet access and browsing, as well as portable units or terminals that integrate combinations of such functions.
  • the terminal may include, but is not limited to, an M2M (Machine to Machine) terminal, an MTC (Machine Type Communication) terminal/device.
  • a terminal may also be referred to as an electronic device.
  • an electronic device may be equipped with a UICC capable of downloading and installing a profile. If the UICC is not embedded in the electronic device, a UICC physically separated from the electronic device may be inserted into and connected to the electronic device.
  • the UICC may be inserted into the electronic device in the form of a card.
  • the electronic device may include a terminal, and in this case, the terminal may be a terminal including a UICC capable of downloading and installing a profile.
  • the UICC may be embedded in the terminal, or, if the terminal and the UICC are separated, the UICC may be inserted into the terminal and connected to the terminal.
  • a UICC capable of downloading and installing a profile may be referred to, for example, as an eUICC.
  • LPA Local Profile Assistant
  • a terminal transmits a command to an eUICC or a terminal receives a command from an eUICC the endpoint of the terminal may be interpreted as an LPA.
  • LPA Low Profile Assistant
  • Event may be used in the present disclosure for the following purposes. Of course, it is not limited to the following examples.
  • Event may be a term that includes a Profile Download, or a Remote Profile Management, or other profile or eUICC management/processing command.
  • An Event may be named a Remote SIM Provisioning Operation (or an RSP Operation) or an Event Record, and each Event may be referred to as data including at least one corresponding Event Identifier (Event ID, EventID) or Matching Identifier (Matching ID, MatchingID), an address (FQDN, IP Address, or URL) of a Profile Provisioning Server (SM-DP+) or a Mobile Activation Server (SM-DS) where the event is stored, a signature of the Profile Provisioning Server (SM-DP+) or the Mobile Activation Server (SM-DS), and a digital certificate of the Profile Provisioning Server (SM-DP+) or the Mobile Activation Server (SM-DS).
  • Command code Data corresponding to an event may be referred to as a "command code.”
  • Part or all of the procedure utilizing the command code may be referred to as a "command code processing procedure,” a "command code procedure,” or an "LPA API (Local Profile Assistant Application Programming Interface).”
  • Profile download may be used interchangeably with profile installation.
  • Event Type may be used as a term to indicate whether a particular event is a profile download, remote profile management (e.g., delete, activate, deactivate, replace, update, etc.), or other profile or eUICC management/processing command, and may be named as Operation Type (or OperationType), Operation Class (or OperationClass), Event Request Type, Event Class, Event Request Class, etc. Any event identifier (EventID or MatchingID) may be specified with the path through which the terminal acquired the event identifier (EventID or MatchingID) or its usage purpose (EventID Source or MatchingID Source).
  • LPM Local Profile Management
  • LPM can be named as Profile Local Management, Local Management, Local Management Command, Local Command, Local Profile Management Package (LPM Package), Profile Local Management Package, Local Management Package (LOCAL MANAGEMENT PACKAGE), Local Management Command Package, Local Command Package.
  • LPM can be used to change the status (Enabled, Disabled, Deleted) of a specific profile or to change (update) the contents of a specific profile (e.g., Profile Nickname, Profile Summary Information (Profile Metadata), etc.) through software installed on the terminal.
  • LPM can include one or more local management commands, in which case the target profiles of each local management command can be the same or different for each local management command.
  • a “certificate” or digital certificate can refer to a digital certificate used for mutual authentication based on an asymmetric key, which consists of a pair of public keys (PK) and secret keys (SK).
  • Each certificate can include one or more public keys (PK), a public key identifier (PKID) corresponding to each public key, an identifier (Certificate Issuer ID) of the certificate issuer (CI) that issued the certificate, and a digital signature.
  • the certificate issuer can be named a certification issuer, a certificate authority (CA), or a certification authority.
  • a public key (PK) and a public key identifier (PKID) may be used to refer to a specific public key or a certificate including the public key, or a portion of the specific public key or a portion of the certificate including the public key, or a computational result (e.g., hash) value of the specific public key or a computational result (e.g., hash) value of the certificate including the public key, or a computational result (e.g., hash) value of a portion of the specific public key or a computational result (e.g., hash) value of a portion of the certificate including the public key, or a storage space where data is stored.
  • a "Certificate Chain” or Certificate Hierarchy can indicate the relationship between certificates issued by a "Certificate Issuer" (primary certificate) when those certificates are used to issue other certificates (secondary certificates), or when secondary certificates are used to issue three or more certificates in a chain.
  • the CI certificate used to issue the initial certificate may be named the Root of Certificate, the top-level certificate, the Root CI, the Root CI Certificate, the Root CA, or the Root CA Certificate.
  • the transmitting entity when it is expressed as “signing and transmitting data” or “transmitting signed data,” it may mean that the transmitting entity digitally signs the data to be transmitted with its own private key to ensure the integrity of the data to be transmitted, for example, the transmitting entity constructs and transmits a message including a signature.
  • the expression that the eUICC transmits a deletion result signed by the eUICC or that the eUICC signs and transmits the deletion result may be interpreted to mean that the eUICC transmits a message including the deletion result data and a signature signed by its own private key.
  • the receiving side can verify the signature included in the message with the corresponding public key (e.g., the public key of the eUICC) to determine whether the data has been tampered with and determine its integrity.
  • ES (External Storage) migration support can be interpreted as a function that supports the migration storage of profiles installed on an eUICC to outside of the eUICC.
  • ES migration support can be expressed interchangeably with ES support.
  • ES migration support may refer to a function that provides additional information that the terminal can refer to in order to secure available memory of the eUICC when the profile server determines that the eUICC does not have sufficient memory for installing a profile that the terminal wants to provide.
  • the additional information that the terminal can refer to may be the expected installation data size of the corresponding profile that the user wants to download.
  • This profile data size information can be utilized as information for the terminal to perform a deletion or migration procedure of one or more profiles from the eUICC of the terminal. Therefore, in the present invention, a profile server that can provide the corresponding function (providing the expected data size of the corresponding profile that the user wants to download according to one embodiment) should be interpreted as an "ES migration support" profile server.
  • the above ES can also be used as a concept including Extended Storage.
  • Terminal information may refer to Device Info defined in SGP.22 as the capability of the terminal.
  • Device Info may include LpaRspCapability as the capability of LPA for RSP (Remote SIM Provisioning). Therefore, in the drawing described below, terminal information including “ES support” may be interpreted to mean that the terminal or an entity configuring the terminal includes “ES support” information in the capability information of the LPA.
  • ES support of a profile may include at least one of an ES movement support (allowance) identifier or a split extraction identifier (for example, when storing security data such as a network key in the eUICC by distinguishing them).
  • ES movement support allowance
  • split extraction identifier for example, when storing security data such as a network key in the eUICC by distinguishing them.
  • the insufficient Memory indicator may be an indicator that explicitly indicates insufficient. However, if the estimated Profile Size is returned, the terminal may consider that the estimated Profile Size indicates insufficient memory. For example, in the drawings of the present embodiment, the estimated Profile Size is returned and the insufficient memory is returned separately, but the insufficient memory indicator may be replaced with the estimated Profile Size. Meanwhile, the indicator indicating insufficient may be indicated as one of the data included in the reply message that the profile server returns to the terminal or within the reply message.
  • FIG. 1 is a diagram showing the relationship between components for moving a profile according to one embodiment of the present disclosure.
  • An eUICC (130) may be mounted on a terminal (110), and a profile (not shown) may be installed on the eUICC (130).
  • an LPA (120) may be installed on the terminal (110).
  • the eUICC (130) may be controlled by the LPA (120).
  • the user (100) may control the eUICC (130) of the terminal (110) through the LPA (120) of the terminal (110).
  • the eUICC (130) may support movement of a profile within the terminal (110).
  • the LPA (120) can store profile data in the terminal (110), and in the following drawing, the case of storing in the terminal (110) through the LPA (120) can be used interchangeably as “data stored in the LPA (120)” or “data stored in the terminal (110).”
  • the LPA (120) can support moving the profile to outside the eUICC (130).
  • the case of storing in the terminal (110) through the LPA (120) may mean that the LPA (120) receives profile data from the eUICC (130) and stores it in the memory (not shown) of the terminal (110), or the LPA (120) may request the eUICC (130) to store the profile data externally, causing the eUICC (130) to process the storage in the memory (110) of the terminal and return the processing result to the LPA (120). Therefore, it should be noted that the meaning of “storing in LPA (120)” encompasses both of these cases, and the present invention, which will be described later, can be applied to both of these cases.
  • a telecommunications service provider (150) may be connected to a profile server (160).
  • the telecommunications service provider (150) may be configured with one or more service provider servers.
  • the drawing illustrates a case where it is configured as a single server.
  • one or more profile servers (SM-DP+) may be included in the server configuration
  • one or more opening brokerage servers (SM-DS) that assist in creating a connection between a specific profile server and a terminal may be included in the server configuration.
  • SM-DP+ profile servers
  • SM-DS opening brokerage servers
  • the configuration of various servers may be simply referred to as a single profile server or SM-DP+ in the following drawing.
  • a user (100) may have subscribed to a communication service of a telecommunications service provider (150) and may have installed profile(s) on the eUICC (130) of the terminal (110). In addition, the user (100) may wish to install an additional profile on the eUICC (130) of the terminal (110).
  • FIG. 2 is a diagram illustrating a procedure for moving a profile outside an eUICC according to one embodiment of the present disclosure.
  • the LPA (205) may request eUICC information from the eUICC (215) to configure and display a user screen.
  • the eUICC (215) may reply to the LPA (205) with eUICC information, including whether "ES (External Storage) migration support" is provided (step 230).
  • the eUICC information may be returned as information included in eUICCInfo2 defined in the GSMA SGP standard.
  • the LPA (205) may request ES10c.getProfileInfo from the eUICC (215) to receive a List of Profiles, thereby further checking whether the metadata of the profile includes identification information for ES migration support (step 235).
  • LPA (205) can determine whether the ES movement function is enabled by referring to the "ES movement support" identification information of the received eUICC and the "ES movement support” identification information of the profile, or at least the "ES movement support” identification information of the eUICC. (Step 240)
  • the LPA (205) can display profiles that can be moved and saved on the user display screen. If the received eUICC information (230) does not have ES migration support information, or if the eUICC information (230) has ES support information but the profile does not have ES support information, the LPA (205) may not display profiles that can be moved and saved on the user screen and may end the profile migration procedure.
  • whether the profiles support ES may be one of the identification information on whether the corresponding ICCID supports ES and information on separate storage of sensitive data.
  • the LPA may consider that the ICCID installed in the ES-supporting eUICC allows “ES support.” For example, if the eUICC information (230) contains ES support information, the LPA (205) may determine that the profiles are movable and display them on the user screen even if the profile does not explicitly contain ES support information. Thereafter, at a specific point in time, the terminal user (200) may select (243) a profile to be moved, and transmit a profile move request from the LPA (205) to the eUICC (215) outside the eUICC. The eUICC (215) that receives the profile move request may generate profile data to be moved outside the eUICC, and reply the generated profile data to the LPA (205). The LPA (205) may store the received data and process the move. (Step 245, described later in FIG. 9)
  • a “Move Profile Save” menu may be provided to the terminal user (200), and at this time, the user may select the “Move Profile Save” menu to start the procedure of FIG. 2.
  • FIG. 3 is another diagram illustrating a procedure for moving a profile outside an eUICC according to one embodiment of the present disclosure.
  • a situation may arise where the terminal determines whether it is necessary to move and store profiles outside the eUICC to secure available memory on the eUICC (step 325). For example, this may be the case when transferring profile(s) from another terminal to the eUICC during a device change process. Alternatively, this may be the case when installing a new profile, as detailed in subsequent drawings.
  • the terminal can determine how many profiles must be deleted or moved to allow installation.
  • the LPA (305) can request eUICC information from the eUICC (315).
  • the eUICC (315) can check the "ES (External Storage) transfer support" and extCardResource of the eUICC (315) and reply with additional remaining memory information to the LPA (305).
  • the remaining memory information can be included in eUICCInfo2 and returned. For example, this information can be returned as information included in extCardResource.
  • the LPA (305) that supports ES (External Storage) movement which has received the above remaining memory information, can determine whether there is insufficient space to install a profile in the eUICC (315) (step 335). In addition, the LPA (305) can check whether there is an additional profile to be moved.
  • LPA (305) can receive metadata information of profiles by requesting ES10c.getProfileInfo to eUICC (315) to receive a List of Profiles. If there is a profile that includes identification information on whether ES movement is supported as the profile metadata, LPA (305) can determine that the profile is a profile that can be moved outside of eUICC (315) (step 345). Whether the profiles support ES can be one of identification information on whether the corresponding ICCID supports ES and information on separate storage of sensitive data. Alternatively, LPA can consider that “ES support” is allowed for an ICCID installed in an ES-supporting eUICC.
  • LPA (305) can display profiles that can be moved to external storage on the user display screen by referring to the "ES mobility support" information of the received eUICC and the "ES mobility support” information of the profile or at least the "ES mobility support” identification information of the eUICC.
  • the terminal can determine the activation status of the profile and process all profiles that support mobility within the terminal among the inactive profiles as mobility according to the terminal settings.
  • the terminal can also store the last use time and/or the first installation time among the inactive profiles and determine the order/number of profiles to be moved by referring to the stored information.
  • the profiles that support mobility within the terminal may be profiles that have ES mobility function support identification information or may be all profiles installed on the ES-supporting eUICC.
  • the LPA (305) can additionally determine the activation status of the profile to be deleted. If the status of the profile is Enabled, when deleting or moving the profile, the LPA (305) can check whether the terminal is still able to connect to the network, and can additionally notify the user (300) that after deleting or moving the profile, it is necessary to maintain a network connection (e.g., a Wi-Fi connection) to proceed with the installation of the profile.
  • a network connection e.g., a Wi-Fi connection
  • the LPA (305) may terminate the profile movement procedure without indicating any movable profiles.
  • the LPA (305) can perform a procedure for moving a profile from the eUICC (315) to the terminal. As described later in FIG. 9, a profile move request can be transmitted from the LPA (305) to the eUICC (315). Upon receiving the profile move request, the eUICC (315) can generate profile data to be moved outside the eUICC (315) and reply the generated profile data to the LPA (305). Then, in step 350, the LPA (305) can store the received data and process the move. After processing the profile move storage, the LPA (305) can proceed with the requested operation. This can be, for example, a procedure such as profile installation or device change processing.
  • FIGS. 4 to 9, FIGS. 12a and 12b the processing applied when installing the profile will be described in detail with reference to FIGS. 4 to 9, FIGS. 12a and 12b.
  • FIG. 4 is a diagram illustrating an example of checking eUICC available memory and moving a profile when installing a profile download according to an embodiment of the present disclosure.
  • FIG. 4 is a drawing for explaining a method applied in the process of a terminal user (400) installing a new profile on a terminal as an example of an operation that requires determining whether to move the profile(s) installed on the eUICC in the aforementioned FIG. 3 to outside the eUICC, according to one embodiment.
  • a terminal user (400) may want to download and install a new profile from the profile server (420).
  • the terminal can determine whether there is storage space in the eUICC (415) for installing the profile during the profile installation process. For example, the terminal's LPA (405) can first check the expected data size of the profile to be installed from the profile server.
  • the LPA (405) may transmit information about the terminal and eUICC to the profile server (420).
  • the information may be included in the data of an AuthenticateClient request message for client verification and transmitted.
  • the terminal information may include "ES mobility support," eUICCInfo2 may include "ES mobility support,” and the available memory information of the eUICC (415) may be transmitted.
  • Information that can determine the available memory of the eUICC (415) may be included in the extCardResource data and transmitted in byte format.
  • the profile server (420) that received the above information determines that the eSIM chip memory for profile installation is insufficient, it may return an error as response data. For example, the profile server (420) may return an error and an error reason of "insufficientMemory" as a response to AuthenticateClient.
  • the profile server (420) may also respond with insufficientMemory when the "additionalProfile" bit in eUICCInfo2 is set to 0. This can be equally applied to FIGS. 5 to 9, 12a, and 12b described below.
  • the terminal LPA (405) that receives the above response may terminate the RSP session for profile installation.
  • the LPA (405) may notify the user of insufficient storage space and terminate the profile installation procedure, or guide the user to delete the profile(s) and then proceed with installation.
  • the profile server may reply with insufficientMemory regardless of whether the "additionalProfile" bit is set to 1 in eUICCInfo2. If it receives at least one of "ES movement support” in the terminal information and "ES movement support” in eUICCInfo2, the profile server (420) may reply with an error and an error reason of "insufficientMemory" in the Response of AuthenticateClient, and may additionally transmit estimated profile size information. (Step 430)
  • the terminal LPA (405) that received the above reply may, even if it receives an error in the response from AuthencateClient, terminate the profile installation procedure (Cancel Session) or, without terminating it, perform an operation to secure additional storage space for profile installation in the eSIM chip when additionally receiving the estimated profile size.
  • the operation to secure additional storage space may be a profile transfer or deletion procedure.
  • the terminal may additionally obtain the user's consent to enter the profile transfer or deletion procedure.
  • the LPA (405) may additionally check information on previously installed profiles (steps 438 and 439) to determine whether there is a profile that can be moved outside the eSIM chip for the installation of the corresponding profile, and/or to determine the storage space that can be secured through the movement of the profile. For example, the LPA (405) may transmit GetProfileInfo (step 438) to the eUICC (415) and receive information on each profile from the eUICC (415) (step 439). At this time, the LPA (400) may check whether the profile(s) support ES with the information of the metadata of the received profile(s). Whether the profiles support ES may be one of the ES support identification information of the corresponding ICCID and information on the separate storage of sensitive data.
  • the LPA may consider that “ES support” is allowed in the case of an ICCID installed in an ES-supporting eUICC.
  • the LPA may further check the estimatedProfileSize of the received metadata or the number of profiles installed on the eUICC (step 439).
  • LPA (405) can determine whether space for storing a new profile download can be secured through profile movement.
  • Information that LPA (405) utilizes for determination may be, for example, at least one of the available memory information of the eSIM chip collected from eUICCInfo2 in advance, and/or the estimated profile capacity (estimatedProfileSize) received from the profile server, whether the installed profiles support Ext. Storage received in Step 439, and estimatedProfileSize.
  • LPA (405) can terminate the installation if there is no profile among the installed profiles that supports ES movement even if eUICC (415) supports ES movement. (Step 445)
  • the LPA (405) may request the eUICC (415) to terminate the session for profile installation by sending a CancelSession (CancelSessionReason, transaction Id) message to the eUICC as defined in SGP.22.
  • the eUICC (415) that received the request may reply to the LPA with eUICC-signed data including the CancelSession Reason, so that the LPA (405) may transmit the data back to the profile server (420).
  • the Cancel Session Reason may be a session termination (SessionAborted), or a Cancel Session Reason indicating that there is no ES-supported profile, for example, NoProfileWithExtStorageSupport, may be used.
  • the profile server (420) can confirm the received Cancel Session message and terminate the RSP Session.
  • the profile server (420) can provide the telecommunications service provider (not shown) with the reason for the profile installation error.
  • the LPA (405) can perform a profile moving procedure outside of the eUICC (415).
  • Step 450 This can be performed with or without terminating the session, as shown in FIGS. 7 and 8 described below.
  • the profile transfer procedure may begin with the terminal user (400) selecting a profile to transfer or transferring a profile according to terminal settings. As described later in FIG. 9, a profile transfer request may be transmitted from the LPA (405) to the eUICC (415). Upon receiving the transfer request, the eUICC (415) may generate profile data to be transferred outside the eUICC and reply with the generated profile data to the LPA (405). The LPA (405) may store the received data and process the transfer. (step 450) After the LPA (405) processes the profile transfer storage, it may proceed with profile installation. (step 455)
  • the terminal may process profile movement and continue the profile download procedure while maintaining an RSP session with the profile server (420), or
  • the RSP Session with the profile server (420) may be resumed, the profile transfer may be processed, and then the profile installation may be resumed to perform subsequent processing.
  • the LPA (405) may transmit an authenticateClient Request back to the profile server (420) to obtain profile metadata as a response to the request, thereby continuing the subsequent procedure.
  • FIG. 5 is a diagram illustrating an example of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
  • FIG. 5 is a drawing for explaining another method applied in the process of a terminal user (500) installing a new profile on a terminal as an example of an operation that requires determining whether to move the profile(s) installed on the eUICC in the aforementioned FIG. 3 to outside the eUICC, according to one embodiment.
  • a terminal user (500) may wish to download and install a new profile from a profile server (520). At this time, during the profile installation process, the terminal may determine whether there is storage space in the eUICC (515) for installing the corresponding profile.
  • the expected data size of the profile to be installed can be first checked from the profile server.
  • the LPA (505) may transmit information about the terminal and eUICC (515) to the profile server (520).
  • the information may be included in the AuthenticateClient data for client verification and transmitted.
  • the terminal information may include "ES mobility support," eUICCInfo2 may include "ES mobility support,” and the available memory information of the eUICC (515) may be transmitted.
  • Information that can determine the available memory of the eUICC (515) may be included in the extCardResource data and transmitted.
  • the profile server (520) that received the above information determines that the memory of the eSIM chip for profile installation is insufficient, if the profile server (520) receives a message without “ES support” information in the terminal information or eUICCInfo2 information, or if the profile server (520) does not understand the ES support identifier, the profile server (520) may reply with an error and insufficientMemory as the error reason.
  • the profile server (520) may reply with an error and an error reason of insufficientMemory as a response to AuthenticateClient.
  • the terminal LPA (505) that receives the reply may terminate the RSP session for profile installation (step 535).
  • the LPA may notify the user of insufficient storage space and terminate the profile installation procedure, or guide the user to delete the profile(s) and then proceed with installation.
  • the profile server (520) can generate and reply with a message response that includes information about the expected profile size. For example, if the server supports ES movement, if the terminal information includes "ES movement support" and eUICCInfo2 includes "ES movement support," the profile server (520) can, instead of sending an error, send a Response Ok from AuthenticateClient and indicate insufficient memory. At this time, information about the estimated profile size may also be included in the reply. (Step 530)
  • the Response Ok of the above AuthenticateClient may include a format as shown in Table 1 or Table 2, according to one embodiment.
  • AuthenticateClientOk SEQUENCE ⁇ transactionId [0] TransactionId; insufficientMemory NULL OPTIONAL, - Not enough space for this Profile download estimatedProfileSize [33] INTEGER OPTIONAL -- estimated Profile Size to be downloaded, waitingTime INTEGER OPTIONAL, -- estimated time in minutes by when the SM-DP+ maintains the session for this Profile Download.
  • esSessionId [X] OCTET STRING (SIZE(1..16)) OPTIONAL -- the LPA will use this identifier to check to restart session, or continue the RSP session ⁇
  • AuthenticateClientOkExtStorage SEQUENCE ⁇ transactionId [0] TransactionId; smdpSignedX SmdpSignedX, -- Signed information smdpSignature [APPLICATION 55]
  • OCTET STRING -- tag '5F37' ⁇ SmdpSignedX SEQUENCE ⁇ -- #SupportedForExtStorage# transactionId [0] TransactionId, -- The TransactionID generated by the SMDP+ insufficientMemory NULL OPTIONAL, - Not enough space for this Profile download estimatedProfileSize [33] INTEGER OPTIONAL -- estimated Profile Size to be downloaded waitingTime INTEGER OPTIONAL, -- estimated time in minutes by when the SM-DP+ maintains the session for this Profile Download.
  • esSessionId [X] OCTET STRING (SIZE(1..16)) OPTIONAL -- the LPA will use this identifier to check to restart session, or continue the
  • the terminal LPA (505) that has received the above information may perform an operation to additionally secure storage space for profile installation in the eSIM chip without entering the installation completion stage.
  • the operation may be a profile movement or deletion procedure.
  • the terminal may additionally obtain the user's consent.
  • the LPA (505) may additionally check information on previously installed profiles (steps 538 and 539) to determine whether there is a profile that can be moved outside the eSIM chip for the corresponding profile installation and/or to confirm the storage space that can be secured through profile movement.
  • the LPA (505) may transmit GetProfileInfo (step 538) to the eUICC (515) and receive information on each profile from the eUICC (515) (step 539).
  • the LPA may check whether the profile(s) has an ES movement permission identifier using the information in the metadata of the received profile(s). Additionally, LPA (505) can further check the estimatedProfileSize of the received metadata or the number of profiles installed in the eUICC. (Step 539)
  • LPA (505) can determine whether space for storing new profile downloads can be secured through profile movement.
  • Information that LPA (505) utilizes for determination may be, for example, at least one of the available memory information of the eSIM chip collected from eUICCInfo2 in advance, and/or the estimated profile capacity (estimatedProfileSize) received from the profile server, whether Ext. Storage of the installed profiles received in Step 539, and estimatedProfileSize.
  • the profiles support ES may be one of the ES support identification information of the corresponding ICCID and information on separate storage of sensitive data. Alternatively, in the case of an ICCID installed in an ES-supporting eUICC, “ES support” may be considered to be allowed.
  • LPA (505) can terminate the installation if there is no profile among the installed profiles that supports ES movement even if eUICC (515) supports ES movement. (Step 545)
  • the LPA (505) may request the eUICC (515) to terminate the session for profile installation by sending a CancelSession (CancelSessionReason, transaction Id) message to the eUICC (515) as defined in SGP.22.
  • the eUICC (515) receiving this may reply to the LPA with eUICC-signed data including the CancelSession Reason, so that the LPA (505) may transmit this back to the profile server.
  • the Cancel Session Reason may be a session termination (SessionAborted), or a Cancel Session Reason indicating that there is no ES-supported profile, for example, NoProfileWithExtStorageSupport, may be used.
  • the profile server (520) can confirm the received Cancel Session message and terminate the RSP Session.
  • the profile server (520) can provide the telecommunications service provider (not shown) with the reason for the profile installation error.
  • the LPA (505) can perform a profile movement procedure outside the eUICC (515). (Step 550) This can be performed with or without terminating the session, as shown in FIGS. 7 and 8 described below.
  • the profile transfer procedure may begin with the terminal user selecting a profile to transfer or transferring a profile according to terminal settings. As described later in FIG. 9, a profile transfer request may be transmitted from the LPA (505) to the eUICC (515). Upon receiving the transfer request, the eUICC (515) may generate profile data to be transferred outside the eUICC and reply to the LPA (505). The LPA (505) may store the received data to process the transfer. (Step 550) After the LPA (505) processes the profile transfer storage, it may proceed with profile installation. (Step 555)
  • the terminal may process profile movement and continue the profile download procedure while maintaining an RSP session with the profile server (520), or
  • the RSP Session with the profile server (520) may be resumed, the profile transfer may be processed, and then the profile installation may be resumed to perform subsequent processing.
  • the LPA (505) may transmit an authenticateClient Request back to the profile server (520) and obtain profile metadata in response thereto, thereby continuing the subsequent procedure.
  • FIG. 6 is a diagram illustrating an example of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
  • FIG. 6 is a drawing for explaining another method applied in the process of a terminal user (600) installing a new profile on a terminal as an example of an operation that requires determining whether to move the profile(s) installed on the eUICC in the aforementioned FIG. 3 to outside the eUICC, according to one embodiment.
  • a terminal user (600) may wish to download and install a new profile from a profile server (620). At this time, during the profile installation process, the terminal may determine whether there is storage space in the eUICC (615) for installing the profile.
  • the LPA (605) of the terminal can first check the expected data size of the profile to be installed from the profile server (620).
  • the LPA (605) may transmit information about the terminal and eUICC (615) to the profile server (620).
  • the information may be included in AuthenticateClient data for client verification and transmitted.
  • the terminal information may include "ES mobility support," eUICCInfo2 may include "ES mobility support,” and eUICC (615) available memory information may be transmitted.
  • Information that can determine the available memory of the eUICC (615) may be included in extCardResource data and transmitted.
  • estimatedProfileSizeIndicationSupport may be additionally included in eUICCInfo2 and transmitted.
  • the profile server (620) that received the above information determines that the memory of the eSIM chip for profile installation is insufficient, if the profile server (620) receives a message without “ES support” information in the terminal information or eUICCInfo2 information, or if the profile server (620) does not understand the ES support identifier, the profile server (620) may reply with an error and insufficientMemory as the error reason.
  • the profile server (620) may reply with an error and an error reason of insufficientMemory as a response to AuthenticateClient.
  • the terminal LPA (605) that receives the response may terminate the RSP session for profile installation (step 635).
  • the LPA (605) may notify the user of insufficient storage space and terminate the profile installation procedure, or guide the user to delete the profile(s) and then proceed with installation.
  • the profile server (620) supports ES, instead of returning an error, it can return a success response even if insufficientMemory occurs. For example, if the server supports ES movement, if "ES movement support" is included in the terminal information and "ES movement support" is included in eUICCInfo2, the profile server (620) can return a response that further includes whether insufficientMemory is present while transmitting profile metadata with Response Ok of AuthenticateClient.
  • the Response Ok of the above AuthenticateClient may include the form of Table 3 below.
  • AuthenticateClientOk SEQUENCE ⁇ transactionId [0] TransactionId; profileMetadata [37] StoreMetadataRequest, -- tag 'BF25' smdpSignedY SmdpSignedY, -- Signed information smdpSignatureY [APPLICATION 55] OCTET STRING, -- tag '5F37' smdpCertificate Certificate, -- CERT.DPpb.SIG insufficientMemory NULL OPTIONAL, - Not enough space for this Profile download waitingTime INTEGER OPTIONAL, -- estimated time in minutes by when the SM-DP+ maintains the session for this Profile Download. EsSessionId [X] OCTET STRING (SIZE(1..16)) OPTIONAL -- the LPA will use this identifier to check to restart session, or continue the RSP session remained ⁇
  • the profile server (620) may provide the estimated profile size in the profile metadata. (Step 630)
  • the terminal LPA may perform an operation to determine whether additional storage space for profile installation can be secured in the eSIM chip before performing a procedure to display the metadata of the profile on the user screen and obtain consent for installation.
  • the LPA (605) may additionally check information on previously installed profiles (steps 638 and 639) to determine whether there is a profile that can be moved outside the eSIM chip for the installation of the corresponding profile and/or to determine the storage space that can be secured through profile movement. For example, the LPA (605) may transmit GetProfileInfo (step 638) to the eUICC (615) and receive information on each profile from the eUICC (615) (step 639), and the LPA (605) may check whether the profile(s) have an ES movement permission identifier using information in the metadata of the received profile(s).
  • the ES movement permission identifier may be one of identification information on whether ES is supported and information on separate storage of sensitive data.
  • the ICCID's policy may be considered to allow "ES support.”
  • the LPA (605) may further check the estimatedProfileSize of the received metadata or the number of profiles installed on the eUICC (step 639).
  • LPA (605) can determine whether space for storing a new profile download can be secured through profile movement.
  • Information that LPA (605) utilizes for determination may be, for example, at least one of the available memory information of the eSIM chip collected from eUICCInfo2 in advance, and/or the estimated profile capacity (estimatedProfileSize) received from the profile server, whether the installed profiles support ES received in step 639, and estimatedProfileSize.
  • LPA (605) can obtain user consent to proceed with the profile installation (step 643).
  • Step 643 may be performed prior to steps 638 through 640.
  • LPA (605) can terminate the installation if there is no profile among the installed profiles that supports ES movement even if eUICC (615) supports ES movement. (Step 645)
  • the LPA (605) may request the eUICC (615) to terminate the session for profile installation by sending a CancelSession (CancelSessionReason, transaction Id) message to the eUICC (615) as defined in SGP.22.
  • the eUICC (615) that has received the request may reply to the LPA (605) with eUICC-signed data including the CancelSession Reason.
  • the LPA (605) may send the reply back to the profile server.
  • the Cancel Session Reason may be a session termination (SessionAborted), or a Cancel Session Reason indicating that there is no ES-supported profile, for example, NoProfileWithExtStorageSupport, may be used.
  • the profile server (620) can confirm the received Cancel Session message and terminate the RSP Session.
  • the profile server (620) can provide the telecommunications service provider (not shown) with the reason for the profile installation error.
  • the LPA (605) can perform a profile moving procedure outside the eUICC (615).
  • Step 650 This can be performed with or without terminating the session, as shown in FIGS. 7 and 8 described below.
  • a profile transfer request can be transmitted from the LPA (605) to the eUICC (615).
  • the eUICC (615) can generate profile data to be transferred outside the eUICC and reply to the LPA (605).
  • the LPA (605) can store the received data and process the transfer.
  • Step 650 After processing the profile transfer storage, the LPA (605) can proceed with profile installation.
  • the terminal may process profile movement and continue the profile download procedure while maintaining an RSP session with the profile server (620), or
  • the RSP Session with the profile server (620) may be resumed, the profile transfer may be processed, and then the profile installation may be resumed to perform subsequent processing.
  • the LPA may continue the installation by sending getBoundProfilePackageRequest to the profile server (620).
  • the profile server (620) that receives the getBoundProfilePackageRequest implicitly recognizes that available memory has been secured and can create a BoundProfilePakcage and respond.
  • FIG. 7 is a diagram illustrating a method for resuming installation of an existing profile after moving a profile within a terminal according to an embodiment of the present disclosure.
  • FIG. 7 or FIG. 8 is an example drawing that can be applied after moving the profiles in FIGS. 3 to 6, FIG. 9, FIG. 12a, and FIG. 12b described above to an external location from an eUICC.
  • FIG. 7 describes a procedure for moving an already installed profile to an external location from an eUICC while maintaining an RSP Session, and then proceeding with profile installation.
  • step 730 it may be determined at step 730 to move the profile of the eUICC (715) to Ext. Storage due to insufficient available memory.
  • the LPA (705) may complete the subsequent profile installation procedure defined in SGP.22 as a subsequent action.
  • An example of the subsequent action upon completion of the installation procedure may be an action of requesting a GetBoundProfilePackage Request to the profile server (720).
  • the profile server (720) may determine that available memory has been secured in the terminal and may respond with a ProfilePackage.
  • LPA (705) may further perform a procedure (steps 780 to 788) prior to step 790 to explicitly notify the profile server (720) that available eUICC memory information has been secured.
  • the LPA (705) may provide the profile server (720) with at least one of the available eUICC memory information and the transaction id as eUICC signed data.
  • the eUICC may obtain one or more pieces of information from the information collected by the LPA (705) by including it in the message transmitted in step 780 or from the eUICC (715) by receiving a command from the LPA (705) in step 780, such as the transaction id, which is session identification information, and available eUICC memory information.
  • the transaction id which is session identification information
  • available eUICC memory information such as the transaction id, which is session identification information, and available eUICC memory information.
  • the eUICC (715) can request signed data of the eUICC for transmitting available eUICC memory information. (Step 780) At this time, the eUICC (715) can generate data including available eUICC memory information and a transaction id, sign the data, and send a reply to the LPA (705) (Step 783).
  • the LPA (705) can receive the reply from the eUICC (715) and send it to the profile server (720) (Step 785).
  • the message sent in Step 785 may be a new ES9+ function for securing available memory, or may be an ES9+.
  • AuthenticateClient Request function currently defined in SGP.22.
  • the profile server (720) verifies the signature of the received eUICC, determines that it is an RSP session for a previous profile installation through the transaction ID, and additionally verifies and responds with information on the availability of eUICC memory. (Step 788) If the memory for profile installation is larger than the expected profile size, the profile server (720) can respond with a success response (Response Ok). If the memory for profile installation is insufficient, the profile server (720) can respond with an error and terminate the process.
  • LPA (705) can proceed to step 790.
  • the profile server may explicitly provide the terminal with an additional RSP session maintenance time.
  • the profile server may include information on the remaining time for maintaining the RSP session and/or session identification information in the AuthenticateClient response and reply. This may correspond to, for example, one of steps 430, 530, 630, or 1230.
  • the profile server may provide the terminal with identification information to determine which profile download operation occurred during the process. This may be the transaction ID of the corresponding session or may be defined as a new ID separately from it.
  • the LPA (705) of the terminal may complete the ES movement procedure within the RSP session maintenance time and enter step 790 of FIG. 7.
  • the LPA (705) attempts to re-download after the provided time has elapsed, it may determine that the session is invalid and enter a procedure to restart profile download.
  • FIG. 8 is a drawing of a method for resuming installation of an existing profile after moving a profile within a terminal according to another embodiment of the present disclosure.
  • FIG. 7 or FIG. 8 is an example drawing that can be applied after the profiles in FIGS. 3 to 6, 12a, and 12b described above are moved outside the eSIM chip.
  • FIG. 8 describes a procedure for terminating an RSP Session, moving the profile outside the eUICC, and then restarting profile installation.
  • the eUICC (815) may decide to move the profile to Ext. Storage due to insufficient available memory. For example, if the user selects to move the profile to ES in FIGS. 3 to 6, the terminal may cancel the existing session and return the CancelSession result to the profile server (820) with eUICC-signed data.
  • the LPA (805) may request the eUICC (815) to terminate the session for profile installation by sending a CancelSession (CancelSessionReason, transaction Id) message to the eUICC (815) as defined in SGP.22.
  • the eUICC (815) that receives the request may return eUICC-signed data including the CancelSession Reason to the LPA (805).
  • LPA (805) can transmit the above data back to the profile server (820).
  • the Cancel Session Reason may be a session termination (SessionAborted) or a Cancel Session Reason indicating reconnection after profile transfer.
  • a Cancel Session Reason such as postpone or afterProfileExportToStorage may be defined.
  • the eUICC (815) may store without deleting the encryption keys generated for the installation of the profile, for example, otPK/otSK (a one-time public key and private key pair used as input when creating a session). Meanwhile, the profile server (820) may verify the signature by checking the received Cancel Session message and terminate the RSP Session.
  • the profile server (820) may not provide the telecommunications service provider (not shown) with the reason for the profile installation error.
  • the terminal After terminating the session, the terminal can perform a profile transfer installation procedure as described later in FIG. 9.
  • LPA (805) can proceed with the procedure by starting the profile installation procedure defined in SGP.22 from the beginning for the profile installation procedure on the profile server (820).
  • FIG. 9 is a diagram illustrating a procedure for moving a profile from an eUICC to outside the eUICC according to one embodiment of the present disclosure.
  • FIG. 9 is a diagram illustrating one embodiment of a procedure for moving a profile from an eUICC to outside the eUICC, which can be commonly applied to the embodiments of FIGS. 3 to 8, FIG. 12a, and FIG. 12b described above.
  • the profile migration procedure may be initiated by the terminal user (900) selecting a profile to be migrated (step 935). Alternatively, the procedure may be initiated upon the terminal recognizing the need for profile migration based on terminal settings (e.g., detecting insufficient available memory in the eUICC), obtaining the user's consent, or based on terminal judgment.
  • the profile transfer procedure may be performed as a follow-up operation upon the terminal (905) recognizing (step 915) that the eUICC (910) has insufficient available memory.
  • the terminal LPA (905) may notify the user that a profile deletion or transfer is required and request additional action (step 920).
  • LPA (905) may also provide information to determine which profiles are eligible for priority deletion, with some information to assist the user in making a decision to delete a profile.
  • Step 925 may be performed before step 920 and provided as additional information in step 920.
  • the terminal may propose profiles for deletion by combining certain information, such as metadata of the profile(s), information obtained from the profile file, usage history of the profile, user setting information for the profile, etc.
  • the information may be at least one of the following: a period of communication service available for the profile, a validity period of the profile itself, whether the terminal user is a communication service provider in the area where the terminal user is located through a PLMN ID, whether the profile is deactivated at the time of performing the operation, information about the last time the profile was activated (enabled) if deactivated, and a usage priority selected by the user.
  • the LPA (905) may initiate a profile deletion procedure as defined in SGP.22 and process the profile deletion from the eUICC (910). If the deletion secures available eUICC memory, the LPA (905) may perform subsequent procedures without entering the profile transfer procedure. For example, in the present invention, the profile installation procedure may be resumed or restarted.
  • the terminal user (900) may choose to move the profile without deciding to delete the profile.
  • a profile transfer request message may be transmitted from the LPA (905) to the eUICC (910) (step 940).
  • the request may be a new command, such as RequestToExtStorage, for example, and may be transmitted including the ICCID or AID (Application ID) of the profile selected by the user or the terminal as identification information of the profile to be transferred.
  • the eUICC (910) that received the request may determine whether ES support is possible, including whether “ES support” is allowed by the policy of the corresponding ICCID (step 945). If there is no profile identified by the corresponding ICCID or does not support ES, the eUICC (910) may return an error.
  • the information on whether “ES support” is allowed by the policy of the corresponding ICCID may be one of identification information on whether ES is supported and information on separate storage of sensitive data.
  • an ES-enabled eUICC may consider the ICCID installed on the ES-enabled eUICC to be “ES-enabled” by the ICCID’s policy.
  • the eUICC (910) can configure data of the corresponding profile to be exported (transmitted externally) (step 950).
  • the data (arbitrarily named ESPPa) may be a data package configured including all or part of the files of the corresponding profile.
  • the file may be configured only with a part excluding sensitive data files such as metadata of the profile or authentication information for network access, and may be configured in the form of binary data.
  • the eUICC (910) may also encrypt the corresponding profile package to be exported externally with an encryption key so that only an eUICC with the same EID can decrypt it.
  • the eUICC (910) can reply to the LPA (905) with ESPPa in response to the request. (Step 955) At this time, only ESPPa may be replied, or, together with ESPPa, one or more pieces of decryptable eUICC information, such as EID or ICCID, to identify which profile the data is for, may be replied. The replied eUICC data may also be replied with an eUICC signature included.
  • LPA (905) can process the movement by storing the received data.
  • LPA may perform subsequent operations.
  • the subsequent operations may be, in one embodiment, a profile installation operation.
  • LPA (905) acquires storage space in the eUICC by processing profile movement storage during the profile installation process and performs profile installation again (terminating the existing session and starting from the beginning, or resuming while maintaining the session), LPA may perform the profile installation procedure without obtaining user consent again.
  • the procedure for receiving and storing profile data by the LPA described in FIG. 9 is described based on this, but it should be noted that the profile transfer operation may be performed in a form in which, when the LPA requests ESPP to the eUICC, the eUICC generates ESPP, transmits it to the terminal memory, and returns the processing result to the LPA.
  • FIG. 10 is a diagram illustrating the configuration of a terminal according to an embodiment of the present disclosure.
  • the terminal may include a transceiver (1020), a processor (1010), and memory (1030). Additionally, the terminal may further include an eUICC (not shown).
  • the terminals described in this disclosure may correspond to the terminal described in FIG. 10.
  • the terminals described in FIGS. 1 to 9 may include the configuration of the terminal described in FIG. 10.
  • the configuration of the terminal is not limited to FIG. 10, and may include more or fewer components than those illustrated in FIG. 10.
  • the transceiver (1020), processor (1010), memory (1030), and eUICC may be implemented in the form of a single chip.
  • the processor (1020) may be configured as at least one processor.
  • the transceiver (1020) may transmit and receive signals, information, data, etc. according to various embodiments of the present disclosure with the transceiver of another terminal or an external server.
  • the transceiver (1020) may be configured with an RF transmitter that up-converts and amplifies the frequency of a transmitted signal, an RF receiver that low-noise amplifies a received signal and down-converts the frequency, etc.
  • this is only one embodiment of the transceiver (1020), and the components of the transceiver (1020) are not limited to the RF transmitter and the RF receiver.
  • the transceiver (1020) may receive a signal through a wireless channel and output it to the processor (1010), and transmit a signal output from the processor (1010) through the wireless channel.
  • the processor (1010) is a component for overall control of the terminal.
  • the processor (1010) can control the overall operation of the terminal according to various embodiments of the present disclosure as described above.
  • the processor (1010) may include the LPA illustrated in FIG. 1 as a control application of the eUICC.
  • the terminal may further include a memory (1030) and may store data such as a basic program, an application program, and setting information for the operation of the terminal.
  • the memory (1030) may include at least one storage medium among a Flash Memory Type, a Hard Disk Type, a Multimedia Card Micro Type, a card type memory (e.g., an SD or XD memory, etc.), a magnetic memory, a magnetic disk, an optical disk, a Random Access Memory (RAM), a Static Random Access Memory (SRAM), a Read-Only Memory (ROM), a Programmable Read-Only Memory (PROM), and an Electrically Erasable Programmable Read-Only Memory (EEPROM).
  • the processor (1010) may perform various operations using various programs, contents, data, etc. stored in the memory (1030).
  • the memory (1030) is connected to the LPA as described above in FIG. 1 and can store profile data extracted from the eUICC by the LPA or provide it upon request by the LPA.
  • An eUICC may include a transceiver, a processor, and a memory.
  • the processor of the eUICC may include an ISD-R application.
  • the ISD-R may exist as a system application of the eUICC (e.g., a part of the OS or a system application existing on the OS).
  • the ISD-R may receive commands from the LPA through the transceiver, interpret the received commands, and perform profile management operations such as profile installation, deletion, and movement on the eUICC.
  • the processor of the eUICC may receive the processing result from the eUICC and return it to the LPA through the transceiver.
  • the processor of the eUICC may obtain profile status information and profile authority information (including whether movement is supported) from the metadata of the profile, and may generate a deletion processing result message when processing profile deletion.
  • the processor may generate a profile package to be moved, construct a message including the profile package to be moved, and return it to the LPA.
  • the eUICC may store at least one of the profile's metadata information and some or additional information of the metadata, such as the profile's status information, the profile's expected capacity, whether the profile supports ES movement, whether the eUICC supports ES, and information about the eUICC's residual memory, in the eUICC's memory, and the processor may access the memory to obtain one of the above-described information and use it as predetermined information necessary to perform at least one operation, such as profile movement processing or deletion processing.
  • the processor may access the memory to obtain one of the above-described information and use it as predetermined information necessary to perform at least one operation, such as profile movement processing or deletion processing.
  • FIG. 11 is a diagram illustrating the configuration of a server according to one embodiment of the present disclosure.
  • the server may include a transceiver (1120), a processor (1110), and a memory (1130).
  • the servers described above in the present disclosure may each correspond to the server described in FIG. 11.
  • the servers described in FIGS. 1 to 9 e.g., a business server, an RSP server, an SM-DP+, or an SM-DS
  • the configuration of the server is not limited to FIG. 11, and may include more or fewer components than those illustrated in FIG. 11.
  • the transceiver (1120), the processor (1110), and the memory (1130) may be implemented in the form of a single chip.
  • the processor (1110) may be configured as at least one processor.
  • the transceiver (1120) may transmit and receive signals, information, data, etc. according to the terminal and various embodiments of the present disclosure.
  • the transceiver (1120) may be configured with an RF transmitter that up-converts and amplifies the frequency of a transmitted signal, and an RF receiver that low-noise amplifies and frequency-downconverts a received signal.
  • this is only one embodiment of the transceiver (1120), and the components of the transceiver (1120) are not limited to the RF transmitter and the RF receiver.
  • the transceiver (1120) may receive a signal through a wireless channel and output it to the processor (1110), and transmit a signal output from the processor (1110) through the wireless channel.
  • At least one processor (1110) is a component for overall control of the server.
  • the processor (1110) can control the overall operation of the server according to various embodiments of the present disclosure as described above.
  • the at least one processor (1110) may be referred to as a control unit.
  • the server may further include a memory (1130) and may store data such as basic programs for server operation, application programs, and setting information for ES movement support.
  • the memory (1130) may include at least one storage medium among a Flash Memory Type, a Hard Disk Type, a Multimedia Card Micro Type, a card-type memory (e.g., SD or XD memory, etc.), a magnetic memory, a magnetic disk, an optical disk, a Random Access Memory (RAM), a Static Random Access Memory (SRAM), a Read-Only Memory (ROM), a Programmable Read-Only Memory (PROM), and an Electrically Erasable Programmable Read-Only Memory (EEPROM).
  • the processor (1110) may perform various operations using various programs, contents, data, etc. stored in the memory.
  • the server can perform at least one of the actions mentioned below.
  • the server may receive one or more messages for profile installation via the transceiver (1120) and transmit them to the processor (1110), and the processor (1110) may verify the eUICC signature.
  • the server may also perform the role of transmitting the verification results to the business operator.
  • the server refers to the available memory information received as a message for mutual authentication from the terminal, for example, eUICC information included in AuthenticateClient.
  • the expected memory size of the profile to be downloaded for installation can be compared, and by further determining whether at least one of the terminal information (DeviceInfo) and the eUICC information (eUICCInfo2) contains an “ES support” identifier, the message can be configured differently and sent back to the terminal through the transceiver (1120).
  • the processor (1110) of the server receives an "ES support" identifier from at least one of the terminal information (DeviceInfo) and the eUICC information (eUICCInfo2), and if the reason for the inability to install is insufficient memory (insufficientMemory), it may include in the message that insufficient memory has occurred and reply to the terminal through the transceiver (1120).
  • the processor (1110) of the server may store session identification information and encryption keys for session creation in the memory (1130) without terminating the corresponding profile installation session.
  • the server's transceiver (1120) can receive a profile request message (GetBoundProfilePakcage) from the terminal. If the server receives an "ES support" identifier from at least one of the terminal information (DeviceInfo) and the eUICC information (eUICCInfo2) in the same session and responds to the terminal with insufficient memory (insufficientMemory) as the reason for installation failure, the server may determine that available memory for the profile to be installed has been secured, create a profile package (bound profile package), and respond to the terminal through the transceiver (1120).
  • the server may perform an operation of signing at least one of the messages transmitted from the profile server with the server's encryption key and transmitting the message including the profile server's signature to the terminal through the transceiver (1120).
  • a method may include a step of checking the available memory of an eUICC from an eUICC in a terminal; and a step of determining to move to an external space of the eUICC of a profile based on the available memory information of the eUICC obtained from the terminal.
  • the step of checking the available memory of the eUICC from the eUICC in the terminal may occur during the process of processing the download of the profile, and the terminal may further include a step of resuming and processing the profile download after moving the profile outside the eUICC.
  • FIG. 12a and FIG. 12b are diagrams illustrating an embodiment of checking available memory of an eUICC and moving a profile from an eUICC when installing a profile download according to another embodiment of the present disclosure.
  • FIG. 12b is a diagram showing a specific embodiment in which the judgment of the profile server (1220) changes according to the AdditionalProfile bit in the embodiment illustrated in FIG. 12a.
  • FIGS. 12A and 12B are diagrams illustrating another method applied in the process of a terminal user (1200) installing a new profile on a terminal, as an example of an operation that requires determining whether to move the profile(s) installed on the eUICC in FIG. 3 described above to an external location of the eUICC, according to one embodiment.
  • This example can be applied as a replacement for the mutual authentication process between the terminal and the profile server in FIGS. 4 to 9 described above.
  • the LPA (1205) may transmit terminal information (Device Info) and eUICC (1215) information (eUICCInfo2) to the profile server (1220).
  • the data of AuthenticateClient for client verification may include and transmit the terminal information and eUICC (1215) information.
  • the eUICC information may include and transmit at least the available memory information of the eUICC (1215).
  • Information that can determine the available memory of the eUICC (1215) may be included and transmitted in the extCardResource data.
  • the profile server (1220) that receives the above information may perform at least one of the following procedures. It may determine that the eSIM chip's memory for profile installation is insufficient. Additionally, an identifier indicating whether an AdditionalProfile is present may be included in the eUICC information and transmitted. (Step 1225)
  • the profile server (1220) that received this may perform an Eligibility Check in step 1227.
  • the profile server (1220) may generate a message including insufficientMemory and information about the estimated profile installation capacity (estimated Profile size) and send it back (step 1230-2).
  • the profile server (1220) may be a profile server that supports ES migration or supports a specific version (e.g., GSMA SGP.22 V3.2 and later).
  • a profile server (1220) supporting GSMA SGP.22 V3.2 may, if the additionalProfile bit included in EuiccRspCapability is not set to 1, return "eUICC - Insufficient memory” (step 1230-1), and if the EuiccRspCapability bit is set to 1, return "eUICC - Insufficient memory” or may not return eUICC-Insufficient memory and return estimatedProfileSize (step 1230-2).
  • the profile server (1220) may additionally determine whether at least one of eUICCInfo2 and/or DeviceInfo includes ES support as additional information, and may provide estimatedProfileSize if the ES support is included.
  • the profile server (1220) may return insufficientMemory as an error and terminate the procedure if the additionalProfile bit is not set to 1 in the received eUICC information or if the estimated installation size of the profile is larger than the available memory regardless of whether the additionalProfile bit is set.
  • the LPA (1250) that receives the insufficientMemory may terminate the RSP session procedure by starting the Cancel Session procedure defined in SGP.22. (Step 1231)
  • the message containing estimatedProfileSize may be returned as a Response from AuthenticateClient.
  • the returned data may be included in either an error message from AuthenticatedClient or a success response message, and estimatedProfileSize may also be transmitted as a single data item included in Profilemetadata (step 1230-2).
  • the profile server (1220) may terminate the RSP session.
  • the LPA (1205) that receives the above message can perform an action by entering a section for deleting or moving a profile within the eUICC, and the subsequent action can be performed (step 1235) by referring to the step after receiving the AuthenitcateClient Response in each of the drawings described above, for example, and therefore, the description thereof will be omitted in this drawing.
  • the present invention may be characterized by a step of confirming at least one of eUICC information and terminal information received from a terminal in a profile server; a step of determining whether installation of a profile prepared by an eUICC is possible by referring to the received information; a step of returning an estimated profile size to the terminal; and a step of determining and processing deletion or movement of one or more profiles stored in an eUICC in the terminal based on the estimated profile size received from the profile server.
  • FIG. 13 is a diagram illustrating an embodiment in which a profile server provides information on session maintenance to a terminal according to an embodiment of the present disclosure.
  • the profile server (1320) may also explicitly provide the terminal with additional information regarding the maintenance of the RSP session.
  • the information regarding the maintenance of the RSP session may be provided together as additional information in the drawings described above.
  • the profile server (1320) may compare the estimated installation size of the profile to be downloaded with reference to the information of extCardResource received from the LPA (1305) during the mutual authentication process. As a result of the comparison, the profile server (1320) may determine that the available memory for profile installation in the eUICC (1315) is insufficient. If the profile server (1320) determines that the available memory is insufficient, the profile server (1320) may terminate the session or maintain the session without terminating it. For example, in step 1330, the profile server (1320) may maintain the session for a certain period of time without terminating the session and then terminate the session. In step 1335, the profile server (1320) may provide the terminal with information about maintaining the session.
  • information regarding session maintenance may include at least one of RSP session identification information and RSP session maintenance time information.
  • the RSP session identification information may be the transaction ID of the corresponding session as defined in SGP.22, or may be defined as a new ID to identify a delay in profile installation due to insufficient available eUICC memory.
  • the new ID may be described as an ES session ID, for example.
  • the terms session ID, session identification information, and Es session ID are used.
  • the profile server (1320) may transmit to the terminal at least one of RSP session maintenance time information (indicated as waiting time in the drawing above) and RSP session identification information (indicated as ES session Id in the example of the drawing above).
  • An example of the reply message may be a Response of AuthenticateClient.
  • the reply message may be included and returned in one of steps 430, 530, 630, and 1230 above, for example.
  • the terminal (LPA (1305)) that received the above reply message may store the corresponding information.
  • the LPA (1305) may delete the existing profile(s) from the eUICC or perform ES movement.
  • the LPA (1305) may use at least one of the RSP session maintenance time and session identification information as information to determine whether the LPA (1305) will continue the existing profile download procedure or restart the profile installation procedure from the beginning.
  • LPA constructs a message and transmits it to the profile server (1320) or eUICC (1315) to perform subsequent actions.
  • the LPA (1305) may decide to enter a subsequent procedure for profile download (e.g., enter step 790 of FIG. 7), and, at step 1350, may configure a transmission message for profile download installation connected after the Authenticate Response and transmit it to the profile server (1320).
  • the LPA (1305) determines at step 1345 that the received session maintenance time has been exceeded, at step 1350, may enter a procedure for starting profile download from the beginning (e.g., enter step 870 of FIG. 8), and may perform a procedure for restarting the mutual authentication procedure with the profile server.
  • the profile server (1320) may decide whether to process the terminal request message. The decision on whether to process may be performed including whether session information has expired.
  • the profile server (1320) may perform the requested action.
  • the action may be, for example, an action in which the profile server (1320) enters a procedure for generating and downloading a BPP. If the received session identification information cannot be found or has expired, the profile server (1320) may determine to return an error and terminate the procedure.
  • the profile server (1320) may construct a response message based on the result of the determination in step 1355 and transmit it to the LPA (1305).
  • the response message may be, for example, a success response and/or BPP, or may include an error reason for an Error and/or session expiration.
  • the LPA (1305) that receives the above response message can perform subsequent actions. For example, the LPA (1305) that receives an error message can terminate the relevant procedure. Alternatively, the LPA (1305) that receives a success response message can continue the profile installation procedure defined in SGP.22 to complete the profile installation.
  • Expressions such as “first,” “second,” “first,” or “second” may modify the corresponding components regardless of order or importance, and are only used to distinguish one component from another, but do not limit the corresponding components.
  • a component e.g., a first component
  • another component e.g., a second component
  • the component may be directly connected to the other component, or may be connected via another component (e.g., a third component).
  • module includes a unit composed of hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit.
  • a module may be an integrally formed component, or a minimum unit or portion thereof that performs one or more functions.
  • a module may be composed of an application-specific integrated circuit (ASIC).
  • ASIC application-specific integrated circuit
  • Various embodiments of the present disclosure may be implemented as software (e.g., a program) including instructions stored in a machine-readable storage medium (e.g., an internal memory or an external memory) that can be read by a machine (e.g., a computer).
  • the device is a device capable of calling instructions stored in the storage medium and performing operations according to the called instructions, and may include a terminal according to various embodiments.
  • the processor may directly, or under the control of the processor, perform a function corresponding to the instructions using other components.
  • the instructions may include code generated or executed by a compiler or an interpreter.
  • a device-readable storage medium may be provided in the form of a non-transitory storage medium.
  • “non-transitory” simply means that the storage medium does not contain signals and is tangible, but does not distinguish between whether data is stored semi-permanently or temporarily on the storage medium.
  • the methods according to various embodiments disclosed in the present disclosure may be provided as included in a computer program product.
  • the computer program product may be traded between sellers and buyers as a commodity.
  • the computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or online through an application store (e.g., Play StoreTM).
  • an application store e.g., Play StoreTM
  • at least a portion of the computer program product may be temporarily stored or temporarily generated in a storage medium such as the memory of a manufacturer's server, an application store's server, or a relay server.
  • Each component may be composed of a single or multiple entities, and some of the aforementioned sub-components may be omitted, or other sub-components may be further included in various embodiments.
  • some components e.g., a module or a program
  • operations performed by a module, program or other component may be executed sequentially, in parallel, iteratively or heuristically, or at least some operations may be executed in a different order, omitted, or other operations may be added.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Databases & Information Systems (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

본 개시는 보다 높은 데이터 전송률을 지원하기 위한 5G 또는 6G 통신 시스템에 관련된 것이다. 예를 들면, 본 개시의 일 실시 예에 따르면, 프로파일을 단말의 eUICC 외부로 효율적으로 이동 전송할 수 있게 된다

Description

EMBEDDED UNIVERSAL INTEGRATED CIRCUIT CARD (EUICC) 외부로 프로파일을 이동 및 저장하기 위한 방법 및 장치
본 개시는 무선 통신 시스템 또는 이동 통신 시스템에 대한 것이다. 구체적으로, 단말에서 통신 가입 정보를 이동하는 방법 및 장치에 관한 것으로, 단말에서 프로파일 설치 시, eUICC에 기존에 저장되어 있던 프로파일을 eUICC 외부로 추출 이동함으로써 설치 공간을 확보하고 프로파일을 설치할 수 있도록 제공하는 방법 및 장치에 관한 것이다.
5G 이동통신 기술은 빠른 전송 속도와 새로운 서비스가 가능하도록 넓은 주파수 대역을 정의하고 있으며, 3.5 기가헤르츠(3.5GHz) 등 6GHz 이하 주파수('Sub 6GHz') 대역은 물론 28GHz와 39GHz 등 밀리미터파(㎜Wave)로 불리는 초고주파 대역('Above 6GHz')에서도 구현이 가능하다. 또한, 5G 통신 이후(Beyond 5G)의 시스템이라 불리어지는 6G 이동통신 기술의 경우, 5G 이동통신 기술 대비 50배 빨라진 전송 속도와 10분의 1로 줄어든 초저(Ultra Low) 지연시간을 달성하기 위해 테라헤르츠(Terahertz, THz) 대역(예를 들어, 95GHz에서 3 테라헤르츠 대역과 같은)에서의 구현이 고려되고 있다.
5G 이동통신 기술의 초기에는, 초광대역 서비스(enhanced Mobile BroadBand, eMBB), 고신뢰/초저지연 통신(Ultra-Reliable Low-Latency Communications, URLLC), 대규모 기계식 통신 (massive Machine-Type Communications, mMTC)에 대한 서비스 지원과 성능 요구사항 만족을 목표로, 초고주파 대역에서의 전파의 경로손실 완화 및 전파의 전달 거리를 증가시키기 위한 빔포밍(Beamforming) 및 거대 배열 다중 입출력(Massive MIMO), 초고주파수 자원의 효율적 활용을 위한 다양한 뉴머롤로지 지원(복수 개의 서브캐리어 간격 운용 등)와 슬롯 포맷에 대한 동적 운영, 다중 빔 전송 및 광대역을 지원하기 위한 초기 접속 기술, BWP(Band-Width Part)의 정의 및 운영, 대용량 데이터 전송을 위한 LDPC(Low Density Parity Check) 부호와 제어 정보의 신뢰성 높은 전송을 위한 폴라 코드(Polar Code)와 같은 새로운 채널 코딩 방법, L2 선-처리(L2 pre-processing), 특정 서비스에 특화된 전용 네트워크를 제공하는 네트워크 슬라이싱(Network Slicing) 등에 대한 표준화가 진행되었다.
현재, 5G 이동통신 기술이 지원하고자 했던 서비스들을 고려하여 초기의 5G 이동통신 기술 개선(improvement) 및 성능 향상(enhancement)을 위한 논의가 진행 중에 있으며, 차량이 전송하는 자신의 위치 및 상태 정보에 기반하여 자율주행 차량의 주행 판단을 돕고 사용자의 편의를 증대하기 위한 V2X(Vehicle-to-Everything), 비면허 대역에서 각종 규제 상 요구사항들에 부합하는 시스템 동작을 목적으로 하는 NR-U(New Radio Unlicensed), NR 단말 저전력 소모 기술(UE Power Saving), 지상 망과의 통신이 불가능한 지역에서 커버리지 확보를 위한 단말-위성 직접 통신인 비 지상 네트워크(Non-Terrestrial Network, NTN), 위치 측위(Positioning) 등의 기술에 대한 물리계층 표준화가 진행 중이다.
뿐만 아니라, 타 산업과의 연계 및 융합을 통한 새로운 서비스 지원을 위한 지능형 공장 (Industrial Internet of Things, IIoT), 무선 백홀 링크와 액세스 링크를 통합 지원하여 네트워크 서비스 지역 확장을 위한 노드를 제공하는 IAB(Integrated Access and Backhaul), 조건부 핸드오버(Conditional Handover) 및 DAPS(Dual Active Protocol Stack) 핸드오버를 포함하는 이동성 향상 기술(Mobility Enhancement), 랜덤액세스 절차를 간소화하는 2 단계 랜덤액세스(2-step RACH for NR) 등의 기술에 대한 무선 인터페이스 아키텍쳐/프로토콜 분야의 표준화 역시 진행 중에 있으며, 네트워크 기능 가상화(Network Functions Virtualization, NFV) 및 소프트웨어 정의 네트워킹(Software-Defined Networking, SDN) 기술의 접목을 위한 5G 베이스라인 아키텍쳐(예를 들어, Service based Architecture, Service based Interface), 단말의 위치에 기반하여 서비스를 제공받는 모바일 엣지 컴퓨팅(Mobile Edge Computing, MEC) 등에 대한 시스템 아키텍쳐/서비스 분야의 표준화도 진행 중이다.
이와 같은 5G 이동통신 시스템이 상용화되면, 폭발적인 증가 추세에 있는 커넥티드 기기들이 통신 네트워크에 연결될 것이며, 이에 따라 5G 이동통신 시스템의 기능 및 성능 강화와 커넥티드 기기들의 통합 운용이 필요할 것으로 예상된다. 이를 위해, 증강현실(Augmented Reality, AR), 가상현실(Virtual Reality, VR), 혼합 현실(Mixed Reality, MR) 등을 효율적으로 지원하기 위한 확장 현실(eXtended Reality, XR), 인공지능(Artificial Intelligence, AI) 및 머신러닝(Machine Learning, ML)을 활용한 5G 성능 개선 및 복잡도 감소, AI 서비스 지원, 메타버스 서비스 지원, 드론 통신 등에 대한 새로운 연구가 진행될 예정이다.
또한, 이러한 5G 이동통신 시스템의 발전은 6G 이동통신 기술의 테라헤르츠 대역에서의 커버리지 보장을 위한 신규 파형(Waveform), 전차원 다중입출력(Full Dimensional MIMO, FD-MIMO), 어레이 안테나(Array Antenna), 대규모 안테나(Large Scale Antenna)와 같은 다중 안테나 전송 기술, 테라헤르츠 대역 신호의 커버리지를 개선하기 위해 메타물질(Metamaterial) 기반 렌즈 및 안테나, OAM(Orbital Angular Momentum)을 이용한 고차원 공간 다중화 기술, RIS(Reconfigurable Intelligent Surface) 기술 뿐만 아니라, 6G 이동통신 기술의 주파수 효율 향상 및 시스템 네트워크 개선을 위한 전이중화(Full Duplex) 기술, 위성(Satellite), AI(Artificial Intelligence)를 설계 단계에서부터 활용하고 종단간(End-to-End) AI 지원 기능을 내재화하여 시스템 최적화를 실현하는 AI 기반 통신 기술, 단말 연산 능력의 한계를 넘어서는 복잡도의 서비스를 초고성능 통신과 컴퓨팅 자원을 활용하여 실현하는 차세대 분산 컴퓨팅 기술 등의 개발에 기반이 될 수 있을 것이다.
본 발명의 목적은 프로파일을 단말의 embedded universal integrated circuit card (eUICC) 외부로 이동 전송하기 위한 방법 및 단말을 제공하는 것을 목적으로 한다.
상기와 같은 문제점을 해결하기 위한 본 개시의 일 실시 예에 따르면, 무선 통신 시스템에서 단말에 의해 수행되는 방법이 제공된다. 상기 방법은 프로파일 설치를 위해 프로파일 서버로 additionalprofile 정보를 포함하는 제1 메시지를 전송하는 단계; 및 상기 additionalprofile 정보가 기설정된 값으로 설정된 경우, 상기 프로파일 서버로부터 상기 예측된 프로파일 사이즈에 대한 정보를 포함하는 제2 메시지를 수신하는 단계; 상기 예측된 프로파일 사이즈에 대한 정보를 포함하는 제 2 메시지의 수신에 기반하여, embedded universal integrated circuit card (eUICC) 메모리를 확보하도록 제어하는 단계; 및 상기 eUICC 메모리 확보에 기반하여 상기 프로파일 설치를 수행하는 단계; 를 포함할 수 있다.
본 개시의 다른 실시 예에 따르면, 무선 통신 시스템에서 프로파일 서버에 의해 수행되는 방법이 제공된다. 상기 방법은 프로파일 설치를 위해 단말로부터 additionalprofile 정보를 포함하는 제1 메시지를 수신하는 단계; 상기 additionalprofile 정보가 기설정된 값으로 설정되었는지 여부를 확인하는 단계; 및 상기 additionalprofile 정보가 기설정된 값으로 설정된 경우, 예측된 프로파일 사이즈에 대한 정보를 포함하는 제2 메시지를 전송하는 단계; 를 포함할 수 있다.
본 개시의 다른 실시 예에 따르면, 무선 통신 시스템에 단말이 제공된다. 상기 단말은 송수신부; 및 프로파일 설치를 위해 프로파일 서버로 additionalprofile 정보를 포함하는 제1 메시지를 상기 송수신부를 통해 전송하고, 상기 additionalprofile 정보가 기설정된 값으로 설정된 경우, 상기 프로파일 서버로부터 상기 예측된 프로파일 사이즈에 대한 정보를 포함하는 제2 메시지를 상기 송수신부를 통해 수신하며, 상기 예측된 프로파일 사이즈에 대한 정보를 포함하는 제 2 메시지의 수신에 기반하여, embedded universal integrated circuit card (eUICC) 메모리를 확보하도록 제어하고, 상기 eUICC 메모리 확보에 기반하여 상기 프로파일 설치를 수행하도록 제어하는 제어부; 를 포함할 수 있다.
본 개시의 다른 실시 예에 따르면, 무선 통신 시스템에서 프로파일 서버가 제공된다. 상기 프로파일 서버는 송수신부; 및 프로파일 설치를 위해 단말로부터 additionalprofile 정보를 포함하는 제1 메시지를 상기 송수신부를 통해 수신하고, 상기 additionalprofile 정보가 기설정된 값으로 설정되었는지 여부를 확인하는 단계; 및 상기 additionalprofile 정보가 기설정된 값으로 설정된 경우, 예측된 프로파일 사이즈에 대한 정보를 포함하는 제2 메시지를 전송하도록 제어하는 제어부; 를 포함할 수 있다.
본 발명의 일 실시 예에 따르면, 프로파일을 단말의 eUICC 외부로 효율적으로 이동 전송할 수 있게 된다.
본 개시에서 얻을 수 있는 효과는 다양한 실시 예들에서 언급한 효과들로 제한되지 않으며, 언급하지 않은 또 다른 효과들은 아래의 기재로부터 본 개시가 속하는 기술 분야에서 통상의 지식을 가진 자에게 명확하게 이해될 수 있을 것이다.
도 1은 본 개시의 일 실시 예에 따른 프로파일을 이동하기 위한 구성 요소 간의 관계를 나타내는 도면이다.
도 2은 본 개시의 일 실시 예에 따른 eUICC 외부로 프로파일을 이동하는 절차를 나타내는 도면이다.
도 3은 본 개시의 다른 실시 예에 따른 eUICC 외부로 프로파일을 이동하는 절차를 나타내는 다른 도면이다.
도 4은 본 개시의 일 실시 예에 따른 프로파일 다운로드 설치 시 eUICC 가용 메모리 확인 및 프로파일을 이동하는 실시 예를 나타내는 도면이다.
도 5는 본 개시의 다른 실시 예에 따른 프로파일 다운로드 설치 시 eUICC 가용 메모리 확인 및 eUICC에서 프로파일을 이동하는 실시 예를 나타내는 도면이다.
도 6는 본 개시의 다른 실시 예에 따른 프로파일 다운로드 설치 시 eUICC 가용 메모리 확인 및 eUICC에서 프로파일 이동하는 실시 예를 나타내는 다른 도면이다.
도 7은 본 개시의 일 실시 예에 따른 프로파일의 단말 내 이동 후 기존 프로파일 설치를 재개하는 방법에 대한 도면이다.
도 8은 프로파일의 단말 내 이동 후 기존 프로파일 설치를 재개하는 방법에 대한 도면이다.
도 9는 본 개시의 일 실시 예에 따라 eUICC에서 프로파일을 eUICC 외부로 이동하는 절차를 나타내는 도면이다.
도 10은 본 개시의 일부 실시 예에 따른 단말의 구성을 도시하는 도면이다.
도 11은 본 개시의 일부 실시 예에 따른 서버의 구성을 도시하는 도면이다.
도 12a는 본 개시의 다른 실시 예에 따른 프로파일 다운로드 설치 시 eUICC 가용 메모리 확인 및 eUICC에서 프로파일을 이동하는 실시 예를 나타내는 도면이다.
도 12b는 본 개시의 다른 실시 예에 따른 프로파일 다운로드 설치 시 eUICC 가용 메모리 확인 및 eUICC에서 프로파일을 이동하는 구체적인 실시 예를 나타내는 도면이다.
도 13은 본 개시의 일 실시 예에 따라 프로파일 서버가 단말에 세션 유지 시간을 제공하여 주는 실시 예를 나타내는 도면이다.
이하에서는 본 개시의 실시 예를 첨부된 도면을 참조하여 상세하게 설명한다.
실시 예를 설명함에 있어서 본 개시가 속하는 기술 분야에 익히 알려져 있고 본 개시와 직접적으로 관련이 없는 기술 내용에 대해서는 설명을 생략한다. 이는 불필요한 설명을 생략함으로써 본 개시의 요지를 흐리지 않고 더욱 명확히 전달하기 위함이다.
마찬가지 이유로 첨부 도면에 있어서 일부 구성요소는 과장되거나 생략되거나 개략적으로 도시되었다. 또한, 각 구성요소의 크기는 실제 크기를 전적으로 반영하는 것이 아니다. 각 도면에서 동일한 또는 대응하는 구성요소에는 동일한 참조 번호를 부여하였다.
본 개시의 이점 및 특징, 그리고 그것들을 달성하는 방법은 첨부되는 도면과 함께 상세하게 후술되어 있는 실시 예들을 참조하면 명확해질 것이다. 그러나 본 개시는 이하에서 개시되는 실시 예들에 한정되는 것이 아니라 서로 다른 다양한 형태로 구현될 수 있으며, 단지 본 실시 예들은 본 개시가 완전하도록 하고, 본 개시가 속하는 기술분야에서 통상의 지식을 가진 자에게 개시의 범주를 완전하게 알려주기 위해 제공되는 것이며, 본 개시는 청구항의 범주에 의해 정의될 뿐이다. 명세서 전체에 걸쳐 동일 참조 부호는 동일 구성 요소를 지칭한다.
이 때, 처리 흐름도 도면들의 각 블록과 흐름도 도면들의 조합들은 컴퓨터 프로그램 인스트럭션들에 의해 수행될 수 있음을 이해할 수 있을 것이다. 이들 컴퓨터 프로그램 인스트럭션들은 범용 컴퓨터, 특수용 컴퓨터 또는 기타 프로그램 가능한 데이터 프로세싱 장비의 프로세서에 탑재될 수 있으므로, 컴퓨터 또는 기타 프로그램 가능한 데이터 프로세싱 장비의 프로세서를 통해 수행되는 그 인스트럭션들이 흐름도 블록(들)에서 설명된 기능들을 수행하는 수단을 생성한다. 이들 컴퓨터 프로그램 인스트럭션들은 특정 방식으로 기능을 구현하기 위해 컴퓨터 또는 기타 프로그램 가능한 데이터 프로세싱 장비를 지향할 수 있는 컴퓨터 이용 가능 또는 컴퓨터 판독 가능 메모리에 저장되는 것도 가능하므로, 그 컴퓨터 이용가능 또는 컴퓨터 판독 가능 메모리에 저장된 인스트럭션들은 흐름도 블록(들)에서 설명된 기능을 수행하는 인스트럭션 수단을 내포하는 제조 품목을 생산하는 것도 가능하다. 컴퓨터 프로그램 인스트럭션들은 컴퓨터 또는 기타 프로그램 가능한 데이터 프로세싱 장비 상에 탑재되는 것도 가능하므로, 컴퓨터 또는 기타 프로그램 가능한 데이터 프로세싱 장비 상에서 일련의 동작 단계들이 수행되어 컴퓨터로 실행되는 프로세스를 생성해서 컴퓨터 또는 기타 프로그램 가능한 데이터 프로세싱 장비를 수행하는 인스트럭션들은 흐름도 블록(들)에서 설명된 기능들을 실행하기 위한 단계들을 제공하는 것도 가능하다.
또한, 각 블록은 특정된 논리적 기능(들)을 실행하기 위한 하나 이상의 실행 가능한 인스트럭션들을 포함하는 모듈, 세그먼트 또는 코드의 일부를 나타낼 수 있다. 또, 몇 가지 대체 실행 예들에서는 블록들에서 언급된 기능들이 순서를 벗어나서 발생하는 것도 가능함을 주목해야 한다. 예컨대, 잇달아 도시되어 있는 두 개의 블록들은 사실 실질적으로 동시에 수행되는 것도 가능하고 또는 그 블록들이 때때로 해당하는 기능에 따라 역순으로 수행되는 것도 가능하다.
이 때, 본 실시 예에서 사용되는 '~부'라는 용어는 소프트웨어 또는 FPGA 또는 ASIC과 같은 하드웨어 구성요소를 의미하며, '~부'는 어떤 역할들을 수행한다. 그렇지만 '~부'는 소프트웨어 또는 하드웨어에 한정되는 의미는 아니다. '~부'는 어드레싱할 수 있는 저장 매체에 있도록 구성될 수도 있고 하나 또는 그 이상의 프로세서들을 재생시키도록 구성될 수도 있다. 따라서, 일 예로서 '~부'는 소프트웨어 구성요소들, 객체지향 소프트웨어 구성요소들, 클래스 구성요소들 및 태스크 구성요소들과 같은 구성요소들과, 프로세스들, 함수들, 속성들, 프로시저들, 서브루틴들, 프로그램 코드의 세그먼트들, 드라이버들, 펌웨어, 마이크로코드, 회로, 데이터, 데이터베이스, 데이터 구조들, 테이블들, 어레이들, 및 변수들을 포함한다. 구성요소들과 '~부'들 안에서 제공되는 기능은 더 작은 수의 구성요소들 및 '~부'들로 결합되거나 추가적인 구성요소들과 '~부'들로 더 분리될 수 있다. 뿐만 아니라, 구성요소들 및 '~부'들은 디바이스 또는 보안 멀티미디어카드 내의 하나 또는 그 이상의 CPU들을 재생시키도록 구현될 수도 있다.
본 개시에서, 용어를 지칭하는 제 1, 제 2 등의 수식어는, 실시예를 설명하는 데에 있어서 각 용어들을 서로 구분하기 위하여 사용될 수 있다. 제 1, 제 2 등의 수식어가 수식하는 용어는 서로 상이한 대상을 지칭할 수 있다. 그러나, 제 1, 제 2 등의 수식어가 수식하는 용어는 동일한 대상을 지칭할 수도 있다. 즉, 제 1, 제 2 등의 수식어는 동일한 대상을 서로 다른 관점에서 지칭하기 위하여 사용될 수도 있다. 예를 들면, 제 1, 제 2 등의 수식어는 동일한 대상을 기능적 측면 또는 동작의 측면에서 구분하기 위하여 사용될 수도 있다. 예를 들면, 제 1 사용자 및 제 2 사용자는 동일한 사용자를 지칭할 수도 있다.
또한, 본 개시에서는 eUICC를 보안 모듈의 일 예로 들어 각 실시예들을 설명하지만, 본 개시의 권리범위가 eUICC에 의한 것으로 제한되지는 않는다. 예를 들면, eUICC와 실질적으로 동일 또는 유사한 기능을 수행하는 다른 보안 매체에도, 이하 설명할 다양한 실시예들이 실질적으로 동일 또는 유사하게 적용될 수 있음은 해당 기술분야의 통상의 기술자들에게 자명하다.
이하의 설명에서 사용되는 특정 용어들은 본 개시의 이해를 돕기 위해서 제공된 것이며, 이러한 특정 용어의 사용은 본 개시의 기술적 사상을 벗어나지 않는 범위에서 다른 형태로 변경될 수 있다.
4G 통신 시스템 상용화 이후 증가 추세에 있는 무선 데이터 트래픽 수요를 충족시키기 위해, 개선된 5G 통신 시스템 또는 pre-5G 통신 시스템을 개발하기 위한 노력이 이루어지고 있다. 이러한 이유로, 5G 통신 시스템 또는 pre-5G 통신 시스템은 4G 네트워크 이후 (Beyond 4G Network) 통신 시스템 또는 LTE 시스템 이후 (Post LTE) 시스템이라 불리어지고 있다. 높은 데이터 전송률을 달성하기 위해, 5G 통신 시스템은 초고주파(mmWave) 대역 (예를 들어, 60기가(60GHz) 대역과 같은)에서의 구현이 고려되고 있다. 초고주파 대역에서의 전파의 경로손실 완화 및 전파의 전달 거리를 증가시키기 위해, 5G 통신 시스템에서는 빔포밍(beamforming), 거대 배열 다중 입출력(massive MIMO), 전차원 다중입출력(Full Dimensional MIMO: FD-MIMO), 어레이 안테나(array antenna), 아날로그 빔형성(analog beam-forming), 및 대규모 안테나 (large scale antenna) 기술들이 논의되고 있다. 또한 시스템의 네트워크 개선을 위해, 5G 통신 시스템에서는 진화된 소형 셀, 개선된 소형 셀 (advanced small cell), 클라우드 무선 액세스 네트워크 (cloud radio access network: cloud RAN), 초고밀도 네트워크 (ultra-dense network), 기기 간 통신 (Device to Device communication: D2D), 무선 백홀 (wireless backhaul), 이동 네트워크 (moving network), 협력 통신 (cooperative communication), CoMP (Coordinated Multi-Points), 및 수신 간섭제거 (interference cancellation) 등의 기술 개발이 이루어지고 있다. 이 밖에도, 5G 시스템에서는 진보된 코딩 변조(Advanced Coding Modulation: ACM) 방식인 FQAM (Hybrid FSK and QAM Modulation) 및 SWSC (Sliding Window Superposition Coding)과, 진보된 접속 기술인 FBMC(Filter Bank Multi Carrier), NOMA(non-orthogonal multiple access), 및SCMA(sparse code multiple access) 등이 개발되고 있다.
한편, 인터넷은 인간이 정보를 생성하고 소비하는 인간 중심의 연결 망에서, 사물 등 분산된 구성 요소들 간에 정보를 주고 받아 처리하는 IoT(Internet of Things, 사물인터넷) 망으로 진화하고 있다. 클라우드 서버 등과의 연결을 통한 빅데이터(Big data) 처리 기술 등이 IoT 기술에 결합된 IoE (Internet of Everything) 기술도 대두되고 있다. IoT를 구현하기 위해서, 센싱 기술, 유무선 통신 및 네트워크 인프라, 서비스 인터페이스 기술, 및 보안 기술과 같은 기술 요소 들이 요구되어, 최근에는 사물 간의 연결을 위한 센서 네트워크(sensor network), 사물 통신(Machine to Machine, M2M), MTC(Machine Type Communication)등의 기술이 연구되고 있다. IoT 환경에서는 연결된 사물들에서 생성된 데이터를 수집, 분석하여 인간의 삶에 새로운 가치를 창출하는 지능형 IT(Internet Technology) 서비스가 제공될 수 있다. IoT는 기존의 IT(information technology)기술과 다양한 산업 간의 융합 및 복합을 통하여 스마트홈, 스마트 빌딩, 스마트 시티, 스마트 카 혹은 커넥티드 카, 스마트 그리드, 헬스 케어, 스마트 가전, 첨단의료서비스 등의 분야에 응용될 수 있다.
이에, 5G 통신 시스템을 IoT 망에 적용하기 위한 다양한 시도들이 이루어지고 있다. 예를 들어, 센서 네트워크(sensor network), 사물 통신(Machine to Machine, M2M), MTC(Machine Type Communication)등의 기술이 5G 통신 기술이 빔 포밍, MIMO, 및 어레이 안테나 등의 기법에 의해 구현되고 있는 것이다. 앞서 설명한 빅데이터 처리 기술로써 클라우드 무선 액세스 네트워크(cloud RAN)가 적용되는 것도 5G 기술과 IoT 기술 융합의 일 예라고 할 수 있을 것이다.
상술한 것과 같이 이동통신 시스템의 발전에 따라 다양한 서비스를 제공할 수 있게 됨으로써, 이러한 서비스들을 효과적으로 제공하기 위한 방안이 요구되고 있다. 예를 들면, 사용자 가입 정보를 포함하는 프로파일이 1개 이상 단말 내부의 eSIM칩에 설치되어 사용될 수 있고, 저장 공간이 부족한 경우 eSIM칩에서 프로파일을 내보내기 했다가 동일 eSIM칩으로 재설치 또는 다른 eSIM칩에 설치를 제공할 수도 있다.
본 개시의 일 실시 예에 따른 방법은, 무선 통신 시스템에서 제 1 단말에서 제 1 프로파일을 eSIM칩에서 내보내기 하였다가, 동일한 eSIM칩에 설치할 수 있도록 하는 방법으로, 신규 프로파일을 설치하는 과정에서 단말에서 프로파일 서버로 단말과 eSIM칩의 외부 저장에 대한 지원 여부를 포함해 제공하는 단계, 프로파일 서버에서 수신된 정보에 기반하여 회신 메시지로 설치할 프로파일 사이즈 정보를 더 포함해 보내줄 지를 판단하는 단계, 단말에서 프로파일 서버로부터 수신된 메시지에 기반하여 eUICC에 가용한 메모리를 확인하는 단계로 eUICC 외부로 이동 가능한 프로파일이 있는지에 대한 판단을 포함해 수행하는 단계, 이동 가능한 프로파일이 있는 경우, eSIM칩 외부로 프로파일 이동을 처리하는 단계, 프로파일 이동을 수행 후에 프로파일 설치를 진행하는 단계를 더 포함해 수행될 수 있다.
본 개시의 다양한 실시 예에 따르면, 단말 사용자는 신규 프로파일 설치를 하는 과정에서 eSIM칩의 저장 공간이 부족한 경우 기존 구매한 프로파일을 삭제 후 재 설치만이 가능하였으나, eSIM칩 외부로 프로파일을 이동 저장해 두었다가 필요한 시점에 eSIM칩으로 재설치 하여 사용할 수 있다. 이에 따라, 단말 사용자는 본인이 구매한 프로파일을 소장하고 필요한 시점에 eSIM칩에 재 설치하여 사용할 수 있어, 프로파일 삭제 후 재 설치 시 발생하는 비용도 절감할 수 있다.
한편, 단말 제조사는 eSIM칩 외부의 저장공간을 활용함으로써, 제한적인 eSIM칩 메모리 용량 문제를 해소할 수 있어 사용자의 편의를 증진할 수 있다.
"SE(Secure Element)"는 보안 정보(예: 이동통신망 접속 키, 신분증/여권 등의 사용자 신원확인 정보, 신용카드 정보, 암호화 키 등)를 저장하고, 저장된 보안 정보를 이용하는 제어 모듈(예: USIM 등의 망 접속 제어 모듈, 암호화 모듈, 키 생성 모듈 등)을 탑재하고 운영할 수 있는 단일 칩으로 구성된 보안 모듈을 의미할 수 있다. SE는 다양한 전자 장치(예: 스마트폰, 태블릿, 웨어러블 장치, 자동차, IoT 장치 등)에 사용될 수 있으며, 보안 정보와 제어 모듈을 통해 보안 서비스(예: 이통통신 망 접속, 결제, 사용자 인증 등)를 제공할 수 있다.
SE는 UICC(Universal Integrated Circuit Card), eSE (Embedded Secure Element), UICC와 eSE가 통합된 형태인 SSP(Smart Secure Platform)등으로 나뉠 수 있으며, 전자 장치에 연결 또는 설치되는 형태에 따라 탈착식(Removable), 고정식(Embedded), 그리고 특정 소자 또는 SoC(system on chip)에 통합되는 통합식(Integrated)으로 세분화될 수 있다.
"UICC(Universal Integrated Circuit Card)"는 이동 통신 단말기 등에 삽입하여 사용하는 스마트카드(smart card)이고 UICC 카드라고도 부른다. UICC에는 이동통신사업자의 망에 접속하기 위한 접속 제어 모듈이 포함될 수 있다. 접속 제어 모듈의 예로는 USIM(Universal Subscriber Identity Module), SIM(Subscriber Identity Module), ISIM(IP Multimedia Service Identity Module) 등이 있다. USIM이 포함된 UICC를 통상 USIM 카드라고 부르기도 한다. 마찬가지로 SIM 모듈이 포함된 UICC를 통상적으로 SIM카드라고 부르기도 한다. 한편, SIM 모듈은 UICC 제조시 탑재되거나 사용자가 원하는 시점에 사용하고자 하는 이동통신 서비스의 SIM 모듈을 UICC 카드에 다운로드 받을 수 있다. 또한, UICC 카드에는 복수개의 SIM 모듈이 다운로드 되어서 설치될 수 있고, 그 중의 적어도 한 개의 SIM 모듈이 선택되어 사용될 수 있다. 이러한 UICC 카드는 단말에 고정되거나 고정되지 않을 수 있다. 특히, 단말의 통신 프로세서(Communication Processor), 어플리케이션 프로세서(Application Processor) 또는 이 두 프로세서가 통합된 단일 프로세서 구조를 포함하는 System-On-Chip(SoC)에 내장된 UICC를 iUICC(Integrated UICC)라고 칭하기도 한다. 통상적으로 eUICC와 iUICC는, 단말에 고정되어 사용되고, 원격으로 적어도 하나의 SIM 모듈이 UICC 카드에 다운로드되고 다운로드된 SIM 모듈 중 어느 하나의 SIM 모듈이 선택될 수 있도록 하는 기능을 포함하는 UICC 카드를 의미할 수 있다. 본 개시에서 원격으로 적어도 하나의 SIM 모듈이 다운로드되고 SIM 모듈이 선택될 수 있도록 하는 기능을 포함하는 UICC 카드를 eUICC 또는 iUICC로 통칭한다. 예를 들어, 원격으로 SIM 모듈이 다운로드되고 SIM 모듈이 선택될 수 있도록 하는 기능을 포함하는 UICC 카드 중 단말에 고정하거나 고정하지 않는 UICC 카드를 통칭하여 eUICC 또는 iUICC로 지칭한다. 본 개시에서 용어 UICC는 SIM과 혼용될 수 있고, 용어 eUICC는 eSIM(칩)과 혼용될 수 있다.
"eUICC 식별자(eUICC ID)"는, 단말에 내장된 eUICC의 고유 식별자일 수 있고, EID로 지칭될 수 있다. 또한, eUICC에 프로비저닝 프로파일 (Provisioning Profile)이 미리 탑재되어 있는 경우, eUICC 식별자(eUICC ID)는 해당 프로비저닝 프로파일의 식별자 (Provisioning Profile의 Profile ID)일 수 있다. 또한, 본 개시의 일 실시예에서, 단말과 eUICC 칩이 분리되지 않을 경우, eUICC 식별자(eUICC ID)는 단말 ID일 수 있다. 또한, eUICC 식별자(eUICC ID)는 eUICC칩의 특정 보안 도메인 (Secure Domain)을 지칭할 수도 있다. eUICC 식별자는 eUICC 인증서 안에 포함된 소정의 정보로서 제공될 수도 있다. 본 개시에서 EID를 제공하는 것은 EID 정보를 포함하는 인증서 또는 EID 정보 자체일 수 있다.
"eSE(Embedded Secure Element)"는 전자 장치에 고정하여 사용하는 고정식 SE를 의미한다. eSE는 통상적으로 단말 제조사의 요청에 의해 제조사 전용으로 제조되며, 운영체제와 프레임워크를 포함하여 제조될 수 있다. eSE에는 원격으로 애플릿 형태의 서비스 제어 모듈이 다운로드되어서 설치될 수 있고, 설치된 서비스 제어 모듈은 전자지갑, 티켓팅, 전자여권, 디지털키 등과 같은 다양한 보안 서비스 용도로 사용될 수 있다. 본 개시에서는 원격으로 서비스 제어 모듈이 다운로드되어서 설치될 수 있고, 전자 장치에 부착된 단일 칩 형태의 SE를 eSE로 통칭한다.
"프로파일(Profile)"은 UICC내에 저장되는 어플리케이션, 파일시스템, 인증키 값 등의 데이터 객체(date object)를 의미할 수 있다.
본 개시에서 "프로파일 패키지"란 "프로파일"의 내용이 UICC 내에 설치될 수 있는 소프트웨어 형태로 패키징된 것을 의미할 수 있다. “프로파일 패키지(profile package)”는 프로파일 패키지 TLV (Profile Package TLV)로 명명될 수 있다. 프로파일 패키지가 암호화 파라미터를 이용해 암호화된 경우 보호된 프로파일 패키지(Protected Profile Package, PPP) 또는 보호된 프로파일 패키지 TLV (PPP TLV)로 명명될 수 있다. 프로파일 패키지가 특정 eUICC에 의해서만 복호화 가능한 암호화 파라미터를 이용해 암호화된 경우 묶인 프로파일 패키지(Bound Profile Package, BPP) 또는 묶인 프로파일 패키지 TLV (BPP TLV)로 명명될 수 있다. 프로파일 패키지 TLV는 TLV (Tag, Length, Value) 형식으로 프로파일을 구성하는 정보를 표현하는 데이터 세트 (set) 일 수 있다.
본 개시에서 '프로파일 이미지'란 UICC 내에 설치되어 있는 프로파일 패키지의 바이너리 데이터를 의미할 수 있다. '프로파일 이미지'는 Profile TLV 또는 프로파일 이미지 TLV로 명명될 수 있다. 프로파일 이미지가 암호화 파라미터를 이용해 암호화된 경우, PPI 또는 보호된 프로파일 이미지 TLV (PPI TLV)로 명명될 수 있다. 프로파일 이미지가 특정 eUICC에 의해서만 복호화 가능한 암호화 파라미터를 이용해 암호화된 경우, BPI 또는 묶인 프로파일 이미지 TLV (BPI TLV)로 명명될 수 있다. 프로파일 이미지 TLV는 TLV 형식으로 프로파일을 구성하는 정보를 표현하는 데이터 세트 (set) 일 수 있다. 본 개시에서 발명을 위해 특별한 구분이 필요하지 않는다고 판단되는 경우, '프로파일 이미지'는 프로파일 패키지 또는 프로파일로 표현하고 있음에 유의해야 한다. 따라서, 본 개시에서 'EPP(Exported Profile Package)'는 설치된 제 1 프로파일로부터 생성된 프로파일 이미지일 수도 있다.
본 개시에서는 발명의 논지를 흐리지 않기 위해 프로파일 1의 일부 또는 전체 데이터로 구성되는 경우를 구분하지 않고 EPP로 일괄 표현될 수 있다.
본 개시에서 프로파일의 "상태"는 GSMA에 정의된 SGP.22 규격에 정의된 프로파일의 상태 중 하나를 의미할 수 있다. "프로파일 구분자"는 프로파일 식별자 (Profile ID), ICCID (Integrated Circuit Card ID), Matching ID, 이벤트 식별자 (Event ID), 활성화 코드(Activation Code), 활성화 코드 토큰(Activation Code Token), 명령 코드(Command Code), 명령 코드 토큰(Command Code Token), 서명된 명령 코드(Signed Command Code), 서명되지 않은 명령 코드(Unsigned Command Code), ISD-P 또는 프로파일 도메인(Profile Domain, PD)과 매칭되는 인자로 지칭될 수 있다. 프로파일 식별자(Profile ID)는 각 프로파일의 고유 식별자를 나타낼 수 있다. 프로파일 구분자는 프로파일을 색인할 수 있는 프로파일 제공서버(SM-DP+)의 주소를 더 포함할 수 있다. 또한 프로파일 구분자는 프로파일 제공서버(SM-DP+)의 서명을 더 포함할 수 있다.
“RSP 서버(Remote SIM Provisioning Server)”는 후술될 프로파일 (제공) 서버 및/또는 프로파일 관리 서버 및/또는 개통중개서버를 지칭하는 명칭으로 사용될 수 있다. RSP 서버는 SM-XX (Subscription Manager XX)로 표현될 수 있다.
본 개시에서 "프로파일 서버"는 프로파일을 생성하거나, 생성된 프로파일을 암호화 하거나, 프로파일 원격관리 명령어를 생성하거나, 생성된 프로파일 원격관리 명령어를 암호화하는 기능을 포함할 수 있다. 예를 들어, 프로파일 서버는 SM-DP (Subscription Manager Data Preparation), SM-DP+ (Subscription Manager Data Preparation plus), off-card entity of Profile Domain, 프로파일 암호화 서버, 프로파일 생성서버, 프로파일 제공자 (Profile Provisioner, PP), 프로파일 공급자 (Profile Provider), 또는 PPC holder (Profile Provisioning Credentials holder) 로 표현될 수 있다.
본 개시에서 “프로파일 관리서버"는 프로파일을 관리하는 기능을 포함할 수 있다. 예를 들어, 프로파일 관리 서버는 SM-SR (Subscription Manager Secure Routing), SM-SR+ (Subscription Manager Secure Routing Plus), off-card entity of eUICC Profile Manager 또는 PMC holder (Profile Management Credentials holder), EM (eUICC Manager), 또는 PP (Profile Manager)로 표현될 수 있다.
본 개시에서 프로파일 서버는 프로파일 관리서버의 기능을 합친 것을 의미할 수도 있다. 따라서, 본 개시의 다양한 일 실시예에서, 프로파일 서버의 동작은 프로파일 관리서버에서 수행될 수도 있다. 마찬가지로, 프로파일 관리서버 또는 SM-SR의 동작은 프로파일 제공서버에서 수행될 수도 있다.
본 개시에서 "개통중개서버"는 SM-DS (Subscription Manager Discovery Service), DS (Discovery Service), 근원 개통 중개서버(Root SM-DS), 대체 개통 중개서버(Alternative SM-DS)로 표현될 수 있다. 개통중개서버는 하나 이상의 프로파일 제공서버 내지 개통중개서버로부터 이벤트 등록 요청(Register Event Request, Event Register Request)을 수신할 수 있다. 또한, 하나 이상의 개통중개서버가 복합적으로 사용될 수 있으며, 이 경우, 제 1 개통중개서버는 프로파일 제공서버 뿐만 아니라 제 2 개통중개서버로부터 이벤트 등록 요청을 수신할 수도 있다.
"통신사업자 (mobile service provider)"는 단말에 통신서비스를 제공하는 사업체를 나타낼 수 있으며, 통신사업자의 사업지원시스템 (business supporting system: BSS), 운영지원시스템 (operational supporting system: OSS), POS 단말 (point of sale terminal), 그리고 기타 IT 시스템을 모두 통칭할 수 있다. 또한 본 개시에서 통신사업자는 통신서비스를 제공하는 특정 사업체를 하나만 표현하는데 한정되지 않고, 하나 이상의 사업체의 그룹 또는 연합체 (association 또는 consortium) 내지 해당 그룹 또는 연합체를 대표하는 대행사 (representative)를 지칭하는 용어로 사용될 수도 있다. 또한 본 개시에서 통신사업자는 사업자 (operator 또는 OP 또는 Op.), 모바일 네트워크 운영자 (mobile network operator, MNO), 모바일 가상 네트워크 운영자 (mobile virtual network operator, MVNO), 서비스 제공자 (service provider 또는 SP), 프로파일 소유자 (profile owner, PO), 이동통신 사업자 (mobile service operator) 등으로 명명될 수 있으며, 각 통신사업자는 통신사업자의 이름 그리고/또는 고유 식별자 (object identifier, OID)를 적어도 하나 설정하거나 할당 받을 수 있다. 만일 통신사업자가 하나 이상의 사업체의 그룹 또는 연합체 또는 대행사를 지칭하는 경우, 임의의 그룹 또는 연합체 또는 대행사의 이름 또는 고유 식별자는 해당 그룹 또는 연합체에 소속한 모든 사업체 내지 해당 대행사와 협력하는 모든 사업체가 공유하는 이름 또는 고유 식별자일 수 있다.
"가입자(Subscriber)"는 단말에 대한 소유권을 지닌 서비스 공급자(Service Provider)를 지칭하거나, 단말에 대한 소유권을 가지고 있는 사용자(End User)를 지칭하는 용어로서 사용될 수 있다. 일반적으로 서비스 공급자가 소유권을 가지는 단말은 M2M 단말(M2M Device)로, 사용자가 소유권을 가지는 단말은 사용자 단말(Consumer Device)로 명명될 수 있다. M2M 단말의 경우 단말에 대한 소유권을 지니지는 않았으나 서비스 공급자(Service Provider)로부터 단말을 양도 또는 임대 받아 사용하는 사용자(End User)가 존재할 수 있고, 이 경우 가입자는 서비스 공급자와 다르거나 같을 수도 있다.
'단말'은 이동국(MS), 사용자 장비(UE; User Equipment), 사용자 터미널(UT; User Terminal), 무선 터미널, 액세스 터미널(AT), 터미널, 가입자 유닛(Subscriber Unit), 가입자 스테이션(SS; Subscriber Station), 무선 기기(wireless device), 무선 통신 디바이스, 무선 송수신 유닛(WTRU; Wireless Transmit/Receive Unit), 이동 노드, 모바일 또는 다른 용어들로 지칭될 수 있다. 단말의 다양한 실시 예들은 셀룰러 전화기, 무선 통신 기능을 가지는 스마트 폰, 무선 통신 기능을 가지는 개인 휴대용 단말기(PDA), 무선 모뎀, 무선 통신 기능을 가지는 휴대용 컴퓨터, 무선 통신 기능을 가지는 디지털 카메라와 같은 촬영장치, 무선 통신 기능을 가지는 게이밍 장치, 무선 통신 기능을 가지는 음악저장 및 재생 가전제품, 무선 인터넷 접속 및 브라우징이 가능한 인터넷 가전제품 뿐만 아니라 그러한 기능들의 조합들을 통합하고 있는 휴대형 유닛 또는 단말기들을 포함할 수 있다. 또한, 단말은 M2M(Machine to Machine) 단말, MTC(Machine Type Communication) 단말/디바이스를 포함할 수 있으나, 이에 한정되는 것은 아니다. 본 개시에서 단말은 전자장치라 지칭될 수도 있다.
본 개시에서 전자장치에는 프로파일을 다운로드 하여 설치 가능한 UICC가 내장될 수 있다. UICC가 전자장치에 내장되지 않은 경우, 물리적으로 전자장치와 분리된 UICC는 전자장치에 삽입되어 전자장치와 연결될 수 있다. 예를 들어, 카드 형태로 UICC는 전자장치에 삽입될 수 있다. 전자 장치는 단말을 포함할 수 있고, 이때, 단말은 프로파일을 다운로드하여 설치 가능한 UICC를 포함하는 단말일 수 있다. 단말에 UICC는 내장될 수 있을 뿐만 아니라, 단말과 UICC가 분리된 경우 UICC는 단말에 삽입될 수 있고, 단말에 삽입되어 단말과 연결될 수 있다. 프로파일을 다운로드하여 설치 가능한 UICC는 예를 들어 eUICC라 지칭할 수 있다.
“LPA(Local Profile Assistant)”는 단말 또는 전자장치에서 UICC 또는 eUICC를 제어하도록 단말 또는 전자장치 내에 설치된 소프트웨어 또는 애플리케이션을 지칭할 수 있다. 본 개시에서 단말이 eUICC에게 명령을 전송하거나 eUICC로부터 단말이 명령을 수신한다고 표현하는 경우에, 단말의 end point는 LPA로 해석될 수 있다. LPA에 저장했다고 표현하는 경우에, LPA에서 접근 가능한 단말 내부 또는 외부 메모리에 저장했다는 의미로 해석될 수 있다. 예를 들어, LPA가 설치된 단말에 고정된 또는 탈착 가능한 메모리 뿐만 아니라, 단말에 유무선을 연결된 외장 메모리, 클라우드 서버의 메모리를 포함해 적용 할 수 있다. 본 도면에서는 예를 들어 단말 내부 메모리로 가정하여 설명한다."이벤트(Event)"는 본 개시에서 다음과 같은 용도로 사용될 수 있다. 물론 하기 예시에 제한되지 않는다.
"이벤트(Event)"는 프로파일 다운로드(Profile Download), 또는 원격 프로파일 관리(Remote Profile Management), 또는 기타 프로파일이나 eUICC의 관리/처리 명령어를 포함하는 용어일 수 있다. 이벤트(Event)는 원격 SIM 제공 동작(Remote SIM Provisioning Operation, 또는 RSP 동작, 또는 RSP Operation) 또는 이벤트 기록(Event Record)으로 명명될 수 있으며, 각 이벤트(Event)는 그에 대응하는 이벤트 식별자(Event Identifier, Event ID, EventID) 또는 매칭 식별자(Matching Identifier, Matching ID, MatchingID)와, 해당 이벤트가 저장된 프로파일 제공서버(SM-DP+) 또는 개통중개서버(SM-DS)의 주소(FQDN, IP Address, 또는 URL)와, 프로파일 제공서버(SM-DP+) 또는 개통중개서버(SM-DS)의 서명과, 프로파일 제공서버(SM-DP+) 또는 개통중개서버(SM-DS)의 디지털 인증서를 적어도 하나 포함하는 데이터로 지칭될 수 있다.
이벤트(Event)에 대응하는 데이터는 "명령코드(Command Code)"로 지칭될 수 있다. 명령코드를 이용하는 절차의 일부 또는 전체를 "명령코드 처리 절차" 또는 "명령코드 절차" 또는 "LPA API(Local Profile Assistant Application Programming Interface)"라 지칭할 수 있다. 프로파일 다운로드(Profile Download)는 프로파일 설치(Profile Installation)와 혼용될 수 있다.
또한 "이벤트 종류(Event Type)"는 특정 이벤트가 프로파일 다운로드인지 원격 프로파일 관리(예를 들어, 삭제, 활성화, 비활성화, 교체, 업데이트 등)인지 또는 기타 프로파일이나 eUICC 관리/처리 명령인지를 나타내는 용어로 사용될 수 있으며, 동작 종류(Operation Type 또는 OperationType), 동작 분류(Operation Class 또는 OperationClass), 이벤트 요청 종류(Event Request Type), 이벤트 분류(Event Class), 이벤트 요청 분류(Event Request Class) 등으로 명명될 수 있다. 임의의 이벤트 식별자(EventID 또는 MatchingID)는 단말이 해당 이벤트 식별자(EventID 또는 MatchingID)를 획득한 경로 또는 사용 용도(EventID Source 또는 MatchingID Source)가 지정되어 있을 수 있다.
"로컬 프로파일 관리(Local Profile Management, LPM)"는 프로파일 로컬관리(Profile Local Management), 로컬관리(Local Management), 로컬관리 명령 (Local Management Command), 로컬 명령(Local Command), 로컬 프로파일 관리 패키지 (LPM Package), 프로파일 로컬 관리 패키지(Profile Local Management Package), 로컬관리 패키지(LOCAL MANAGEMENT PACKAGE), 로컬관리 명령 패키지(Local Management Command Package), 로컬명령 패키지(Local Command Package)로 명명될 수 있다. LPM은 단말에 설치된 소프트웨어 등을 통해 특정 프로파일의 상태(Enabled, Disabled, Deleted)를 변경하거나, 특정 프로파일의 내용 (예를 들면, 프로파일의 별칭(Profile Nickname), 또는 프로파일 요약 정보(Profile Metadata) 등)을 변경(update)하는 용도로 사용될 수 있다. LPM은 하나 이상의 로컬관리명령을 포함할 수도 있으며, 이 경우 각 로컬관리명령의 대상이 되는 프로파일은 로컬관리명령마다 서로 같거나 다를 수 있다.
"인증서(Certificate)" 또는 디지털 인증서(Digital Certificate)는 공개 키(Public Key, PK)와 비밀 키(Secret Key, SK)의 쌍으로 구성되는 비대칭 키(Asymmetric Key) 기반의 상호 인증(Mutual Authentication)에 사용되는 디지털 인증서(Digital Certificate)를 나타낼 수 있다. 각 인증서는 하나 이상의 공개 키(Public Key, PK)와, 각 공개 키에 대응하는 공개 키 식별자(Public Key Identifier, PKID)와, 해당 인증서를 발급한 인증서 발급자(Certificate Issuer, CI)의 식별자(Certificate Issuer ID) 및 디지털 서명(Digital Signature)을 포함할 수 있다. 예를 들어, 인증서 발급자(Certificate Issuer)는 인증 발급자(Certification Issuer), 인증서 발급기관(Certificate Authority, CA), 또는 인증 발급기관(Certification Authority)으로 명명될 수 있다. 예를 들어, 본 개시에서 공개 키(Public Key, PK)와 공개 키 식별자(Public Key ID, PKID)는 특정 공개 키 내지 해당 공개 키가 포함된 인증서, 또는 특정 공개 키의 일부분 내지 해당 공개 키가 포함된 인증서의 일부분, 또는 특정 공개 키의 연산 결과(예를 들면, 해시(Hash))값 내지 해당 공개 키가 포함된 인증서의 연산 결과(예를 들면, 해시(Hash))값, 또는 특정 공개 키의 일부분의 연산 결과(예를 들면, 해시(Hash))값 내지 해당 공개 키가 포함된 인증서의 일부분의 연산 결과(예를 들면, 해시(Hash))값, 또는 데이터들이 저장된 저장 공간을 지칭하는 의미로서 사용될 수 있다.
"인증서 연쇄(Certificate Chain)" 또는 인증서 계층구조(Certificate Hierarchy)는 "인증서 발급자(Certificate Issuer)"가 발급한 인증서들(1차 인증서)이 다른 인증서(2차 인증서)를 발급하는데 사용되거나, 2차 인증서들이 3차 이상의 인증서들을 연계적으로 발급하는데 사용되는 경우, 해당 인증서들의 상관관계를 나타낼 수 있다. 예를 들어, 최초 인증서 발급에 사용된 CI 인증서는 인증서 근원(Root of Certificate), 최상위 인증서, 근원 CI(Root CI), 근원 CI 인증서(Root CI Certificate), 근원 CA(Root CA), 또는 근원 CA 인증서(Root CA Certificate)로 명명될 수 있다.
이하 본 개시의 실시 예에서, "데이터를 서명하여 전송" 또는 "서명된 데이터를 전송"한다고 표현하는 경우, 전송하는 entity가 전송할 데이터의 무결성 보장을 위해서 자신의 private key로 전송할 데이터를 디지털 서명(signature)한 값, 예를 들면, 전송하는 entity가 signature를 포함하는 메시지를 구성하여 전송한다는 의미일 수 있다. 예를 들어, eUICC가 서명한 삭제 결과를 전송 또는 eUICC가 삭제 결과를 서명하여 전송한다는 표현은, eUICC가 삭제 결과 데이터 및 자신의 private key로 해당 삭제 결과 데이터를 서명한 signature를 포함하는 메시지를 전송한다는 의미로 해석될 수 있다. 수신 측은 메시지에 포함된 signature를 대응되는 public key(예를 들어, eUICC의 public key)로 검증하여 데이터의 변조 여부를 판단하고, 무결성을 판단할 수 있다.
"ES(External Storage) 이동 지원"은 eUICC 외부로 eUICC에 설치된 프로파일의 이동 저장을 지원하는 기능으로 해석될 수 있다. ES 이동 지원은 ES 지원으로 혼용되어 표기될 수 있다. 프로파일 서버 측면에서 ES 이동 지원의 의미는, 프로파일 서버가 단말에 제공하고자 하는 프로파일의 설치를 위한 충분한 메모리가 eUICC에 없다고 판단하는 경우에, eUICC의 가용 메모리를 확보하기 위해서, 단말이 참고할 수 있는 추가 정보를 제공하는 기능일 수 있다. 일 실시 예에 따르면, 단말이 참고할 수 있는 추가 정보는 사용자가 다운로드를 수행하고자 하는 해당 프로파일의 예상 설치 데이터 크기일 수 있다. 이러한 프로파일 데이터 크기 정보는 단말이 단말의 eUICC에서 하나 이상의 프로파일의 삭제 또는 이동 절차를 수행하기 위한 정보로서 활용될 수 있다. 따라서, 본 발명에서는 해당 기능(일 실시예에 따른 다운로드를 수행하고자 하는 해당 프로파일의 예상 데이터 크기를 제공하는)을 제공할 수 있는 프로파일 서버를 “ES 이동 지원” 프로파일 서버로 해석해야 한다.
한편, 상기 ES는 Extended Storage를 포함하는 개념으로 사용될 수도 있다.
단말(의) 정보는 단말의 성능(Capability)으로 SGP.22에 정의된 Device Info를 의미할 수 있다. SGP.22를 참조하면, Device Info는 RSP(Remote SIM Provisioning)을 위한 LPA의 성능으로 LpaRspCapability를 포함할 수 있다. 따라서, 후술하는 도면에서 “ES 지원”이 포함된 단말 정보란, 단말 또는 이를 구성하는 entity로 LPA의 성능 정보에 “ES 지원” 정보를 포함한다는 의미로 해석될 수 있다.
한편, eUICC에 저장된 프로파일들 중에 eUICC 외부 메모리로 이동 가능한 프로파일인지 판단하는 방법으로, 후술하는 도면에서 프로파일의 "ES 지원" 용어를 사용하였다. 프로파일의 ES 지원이란, ES 이동 지원(허용) 식별자 또는 분할 추출 식별자 (예를 들어, 네트워크 키등 보안 데이터를 구분하여 eUICC에 저장하는 경우) 중 적어도 하나를 포함할 수 있다. 한편, 후술하는 도면에서 논점을 흐리지 않기 위해 프로파일에 명시적인 식별 정보가 있는 경우를 예로 들어 설명하나, 단말(의 LPA) 그리고/또는 ES지원 eUICC가, ES를 지원하는 eUICC에 설치된 프로파일(들)은, “ES 이동 지원”으로 간주하는 방법도 가능할 수 있다.
insufficient Memory 지시자는 명시적인 insufficient를 나타내는 지시자일 수 일 수도 있다. 다만, estimated Profile Size가 회신 되는 경우, 상기 estimated Profile Size를 통해 insufficient memory를 지시한다고 단말에서 간주할 수도 있다. 예를 들면 본 실시 예의 도면에서 estimated Profile Size를 회신하면서 insufficient memory를 별도로 회신하는 것으로 분리하여 설명하였으나, estimated Profile Size로 insufficient memory 지시자가 갈음될 수도 있다. 한편, insufficient를 나타내는 지시자는 프로파일 서버가 단말로 회신하는 회신 메시지 또는 회신 메시지 내에 포함되는 데이터의 하나로 표기될 수 있다.
그리고, 본 개시를 설명함에 있어서, 관련된 기능 또는 구성에 대한 구체적인 설명이 본 개시의 요지를 불필요하게 흐릴 수 있다고 판단된 경우, 그 상세한 설명은 생략한다.
그리고, 본 개시는 GSMA(GSMA Association)의 SGP 규격의 프로파일의 설치 절차, 예를 들어 SGP.22 규격을 기반으로 설명하고 하므로, 이를 참조하여 해석될 수 있다. 본 개시를 설명 함에 있어 명명된 function 또는 데이터, 파라미터 이름은 실시 예에 따라 여러 가지로 변경이 가능하다.
도 1은 본 개시의 일 실시 예에 따른 프로파일을 이동하기 위한 구성 요소 간의 관계를 나타내는 도면이다.
단말(110)에는 eUICC(130)이 장착되어 있고, eUICC(130)에 프로파일(미도시)이 설치되어 있을 수 있다. 또한 단말(110)에 LPA(120)가 설치되어 있을 수 있다. eUICC(130)는 LPA(120)의 제어를 받을 수 있다. 사용자(100)는 단말(110)의 LPA(120)을 통해 단말(110)의 eUICC(130)를 제어할 수 있다. 단말(110)에 장착된 eUICC(130)는 복수 개 일 수 있다. 복 수 개의 eUICC(130)가 있는 경우, 각 eUICC(130)를 제어하는 복수 개의 LPA(120)를 가정할 수 있다. eUICC(130)는 프로파일의 단말(110) 내 이동을 지원할 수 있다.
LPA(120)는 단말(110)에 프로파일 데이터를 저장할 수 있고, 이하 도면에서 LPA(120)를 통해 단말(110)에 저장하는 경우를 "LPA(120)에 저장" 또는 "단말(110)에 저장"된 데이터로 혼용되어 사용될 수 있다. LPA(120)는 프로파일을 eUICC(130) 외부로 이동을 지원할 수 있다. 여기서 LPA(120)를 통해 단말(110)에 저장하는 경우라 함으로, LPA(120)에서 프로파일 데이터를 eUICC(130)으로부터 수신하여 LPA(120)가 단말(110)의 메모리(미도시)에 저장하는 경우일 수 있고, 또는 LPA(120)에서 eUICC(130)에 프로파일 데이터 외부 저장을 요청하여 eUICC(130)로 하여금 단말의 메모리(110)에 저장을 처리하고 처리 결과를 LPA(120)에 회신하는 경우일 수도 있다. 따라서, "LPA(120)에 저장"이라는 의미는 이 두 경우를 모두 포괄하고 있음에 유의해야 하며 후술할 본 발명은 이 두 가지 경우에 모두 적용될 수 있다.
통신사업자(150)는 프로파일 서버(160)에 연결되어 있을 수 있다. 통신사업자(150)는 하나 이상의 사업자 서버로 구성될 수 있다. 도면에서는 편의상 단일 서버로서 구성되는 경우를 도시하였으나, 구현 및 실시 예에 따라, 하나 이상의 프로파일 서버(SM-DP+)가 서버 구성에 포함될 수 있고, 특정 프로파일 서버와 단말의 연결 생성을 보조하는 하나 이상의 개통중개서버(SM-DS)가 서버 구성에 포함될 수도 있다. 이와 같이 다양한 서버의 구성을 이하 도면에는 간략하게 단일 프로파일 서버 또는 SM-DP+로 표기할 수도 있다.
사용자(100)는 통신사업자(150)의 통신서비스에 가입하여 단말(110)의 eUICC(130)에 프로파일(들)을 설치해 둔 상태일 수 있다. 또한, 사용자(100)는 단말(110)의 eUICC(130)에 추가적인 프로파일을 설치하고자 할 수 있다.
도 2은 본 개시의 일 실시 예에 따른 eUICC 외부로 프로파일의 이동 절차를 나타내는 도면이다.
LPA(205)는 사용자 화면을 구성해서 보여주기 위해, eUICC(215)에 eUICC 정보를 요청할 수 있다. eUICC(215)는 "ES(External Storage) 이동 지원" 여부를 포함하여 eUICC 정보를 LPA(205)로 회신(230 단계)할 수 있다. 상기 eUICC 정보는 GSMA SGP 규격에 정의된 eUICCInfo2에 포함되는 정보로써 회신 될 수 있다. 상기 회신을 수신한 LPA(205)는 eUICC(215)에 ES10c.getProfileInfo를 요청하여 List of Profiles을 수신하여, 프로파일의 메타데이터에 ES 이동 지원에 대한 식별 정보가 있는지를 더 확인할 수도 있다. (235 단계)
표기되는 일 예는 ASN.1 형식으로 eUICCInfo2에 아래와 같은 데이터 필드 형태로 추가될 수도 있고,
extStorageInfo [21] ExtStorageSpecificInfo OPTIONAL, -- reserved for SGP.60
또는 EUICCInfo2 EuiccRspCapability의 신규 bit로 아래의 예와 같이 추가되는 것도 가능할 수 있다.
extendedStorageSupport (25) -- #SupportedFromV3.X.Y# support for ExtendedStorage
LPA(205)는 수신한 eUICC의 "ES 이동 지원" 식별 정보와 프로파일의 "ES 이동 지원" 식별 정보 또는 적어도 eUICC의 "ES 이동 지원" 식별 정보 참조하여 ES로 이동 기능 여부를 판단할 수 있다. (240 단계)
수신되는 eUICC 정보(230)에 ES 이동 지원이 있고 프로파일에 ES 지원으로 표기되는 경우, LPA(205)는 사용자 표기 화면에 이동 저장 가능한 프로파일들을 표기해 줄 수 있다. 수신되는 eUICC 정보(230)에 ES 이동 지원 정보가 없거나, eUICC 정보(230)에 ES 지원 정보가 있으나 프로파일에 ES 지원 정보가 없는 경우, LPA(205)는 이동 저장 가능한 프로파일들을 사용자 화면에 표기하지 않고, 프로파일 이동에 대한 절차를 종료할 수도 있다.
전술한 바와 같이, 프로파일들의 ES 지원 여부는, 해당 ICCID의 ES 지원 여부에 대한 식별 정보, 민감 데이터에 대한 분리 저장에 대한 정보 중의 하나일 수 있다.
또는, LPA는 ES 지원 eUICC에 설치된 ICCID의 경우, “ES 지원”을 허용한다고 간주할 수도 있다. 예를 들어, eUICC 정보(230)에 ES 지원 정보가 있는 경우에 프로파일에 명시적인 ES 지원 정보가 없더라도, LPA(205)는 이동 저장 가능한 프로파일들로 판단하여 사용자 화면에 표기하여 줄 수도 있다. 이후 특정 시점에, 단말 사용자(200)가 이동할 프로파일을 선택(243)할 수 있고, LPA (205)에서 eUICC(215)로 eUICC 외부로 프로파일 이동 요청을 전송할 수 있다. 상기 프로파일 이동 요청을 수신한 eUICC(215)는 eUICC 외부로 이동할 프로파일 데이터를 생성하고, 상기 생성된 프로파일 데이터를 LPA(205)에 회신해 줄 수 있다. LPA (205)는 수신한 데이터를 저장하여 이동을 처리할 수 있다. (245 단계, 도 9에서 후술)
한편, 상기 230 단계 이전에 단말 사용자(200)에게 "프로파일 이동 저장" 메뉴가 제공될 수 있고, 이때 사용자가 "프로파일 이동 저장" 메뉴를 선택하여 도 2의 절차가 시작될 수도 있다.
도 3는 본 개시의 일 실시 예에 따른 eUICC 외부로 프로파일의 이동 절차를 나타내는 다른 도면이다.
단말에서 eUICC의 가용 메모리를 확보를 위해 프로파일을 eUICC 외부로 이동 저장이 필요한 지 여부를 결정하는 상황이 발생할 수 있다. (325 단계) 일 예로 기기 변경을 진행하는 과정에서 다른 단말로부터 프로파일(들)을 해당 eUICC로 이전 설치하고자 하는 경우일 수도 있다. 또는 이후 도면 들에서 상세 기술하는 신규 프로파일 설치의 경우일 수 있다.
신규 프로파일 설치를 위한 eUICC 메모리가 부족한 경우, 단말은 몇 개의 프로파일을 삭제 또는 이동해야 설치가 가능한 지를 판단할 수 있다.
LPA(305)는 eUICC(315)에 eUICC 정보를 요청할 수 있다. eUICC(315)는 eUICC(315)의 "ES(External Storage) 이동 지원", extCardResource를 확인하여 LPA(305)로 잔여 메모리 정보를 더 포함해 회신할 수 있다. 상기 잔여 메모리 정보는 eUICCInfo2에 포함되어 회신될 수 있다. 이는 일 예로 extCardResource에 포함되는 정보로 회신될 수도 있다. (330 단계)
상기 잔여 메모리 정보를 수신한 ES(External Storage) 이동을 지원하는 LPA(305)는 eUICC(315)에 프로파일을 설치할 공간이 부족한 지 여부를 판단(335 단계)할 수 있다. 그리고 LPA(305)는 추가적으로 이동할 프로파일이 있는지를 확인할 수 있다.
일 예로 LPA(305)는 eUICC(315)에 ES10c.getProfileInfo를 요청하여 List of Profiles을 수신하여, 프로파일들의 메타데이터 정보를 수신할 수 있다. 프로파일의 메타데이터로 ES 이동 지원 여부에 대한 식별 정보를 포함하는 프로파일이 있는 경우, LPA(305)는 해당 프로파일을 eUICC(315) 외부로 이동 가능한 프로파일로 판단할 수 있다 (345 단계). 프로파일들의 ES 지원 여부는, 해당 ICCID의 ES 지원 여부에 대한 식별 정보, 민감 데이터에 대한 분리 저장에 대한 정보 중의 하나일 수 있다. 또는, LPA는 ES 지원 eUICC에 설치된 ICCID의 경우, “ES 지원”을 허용한다고 간주할 수도 있다.
LPA(305)는 수신한 eUICC의 "ES 이동 지원" 정보와 프로파일의 "ES 이동 지원" 정보 또는 적어도 eUICC의 "ES 이동 지원" 식별 정보를 참조 사용자 표기 화면에 외부 저장공간으로 이동 가능한 프로파일들을 표기할 수 있다. 또는, 단말은 프로파일의 활성화 상태를 파악하여, 비활성화 상태의 프로파일들 중에 단말 내 이동 지원하는 프로파일들을 단말 설정에 따라 모두 이동으로 처리할 수도 있다. 단말은 비활성화된 프로파일들 중에 마지막 사용 시점 그리고/또는 최초 설치 시점을 저장하고, 상기 저장된 정보를 참조하여 이동할 프로파일들의 순서/개수를 결정할 수도 있다. 앞서 전술한 바와 같이, 단말 내 이동 지원하는 프로파일이란, ES 이동 기능 지원 식별 정보가 있는 프로파일일수도 있고 ES지원 eUICC에 설치된 모든 프로파일일 수도 있다.
한편, 사용자(300)가 프로파일을 선택해 삭제 또는 이동하고자 하는 경우, LPA(305)는 삭제할 해당 프로파일의 활성화 상태를 추가적으로 판단할 수 있다. 만약, 해당 프로파일의 상태가 Enabled 상태인 경우, 해당 프로파일의 삭제 또는 이동 시, LPA(305)는 단말에서 망 접속이 여전히 가능한 지 확인하고, 프로파일 삭제 또는 이동 후, 프로파일의 설치를 진행하기 위해 네트워크 연결 유지(와이파이 연결 필요 등)가 필요함을 사용자(300)에게 추가 고지해 줄 수도 있다.
단계 330에서 수신되는 eUICC 정보에 ES 이동 지원 정보가 없거나, eUICC 정보에 ES 지원 정보가 있더라도 이동 가능한 프로파일이 없는 경우에, LPA(305)는 이동 가능한 프로파일들을 표기하지 않고, 프로파일 이동에 대한 절차를 종료할 수도 있다.
LPA(305)는 프로파일을 eUICC(315)에서 단말로 이동하는 절차를 진행할 수 있다. 도 9에서 후술하는 바와 같이, LPA(305)에서 eUICC(315)로 프로파일 이동 요청을 전송할 수 있다. 상기 프로파일 이동 요청을 수신한, eUICC(315)는 eUICC(315)외부로 이동할 프로파일 데이터를 생성하고, 상기 생성된 프로파일 데이터를 LPA (305)에 회신해 줄 수 있다. 그리고 단계 350에서 LPA(305)는 수신한 데이터를 저장하여 이동을 처리할 수 있다. LPA(305)는 프로파일의 이동 저장을 처리한 후에, 요청되는 동작을 이어서 진행할 수 있다. 이는 일 예로 프로파일 설치 또는 기기 변경 처리와 같은 절차일 수 있다.
이후 도 4 내지 도 9, 도 12a, 도 12b를 들어 프로파일 설치 시 적용되는 처리를 상세하게 기술한다.
도 4은 본 개시의 일 실시 예에 따른 프로파일 다운로드 설치 시 eUICC 가용 메모리 확인 및 프로파일을 이동하는 실시 예를 나타내는 도면이다.
도 4는 일 실시 예에 따라, 전술한 도 3에서 eUICC에 설치된 프로파일(들)을 eUICC 외부로 이동을 판단이 필요한 동작의 예로 단말 사용자(400)가 신규 프로파일을 단말에 설치하는 과정에서 적용되는 방법을 설명하기 위한 도면이다.
단말 사용자(400)는 신규 프로파일을 프로파일 서버(420)로부터 다운로드 받아 설치하고자 할 수 있다.
이때 단말은 프로파일을 설치하는 과정 중에서 eUICC(415)에 해당 프로파일 설치하기 위한 저장 공간이 있는지를 판단할 수 있다. 예를 들어, 단말의 LPA(405)에서는 프로파일 서버로부터 설치할 프로파일의 예상 데이터 크기를 먼저 확인할 수 있다.
프로파일을 설치하기 위한 상호 인증 과정 중에 LPA(405)는 프로파일 서버(420)에 단말의 정보와 eUICC의 정보를 포함하여 전송할 수 있다. 상기 정보는 예를 들어 클라이언트 검증에 대한 AuthenticateClient 요청메시지의 데이터에 포함되어 전송될 수 있다. 단말의 정보에 "ES 이동 지원", eUICCInfo2에 "ES 이동 지원", eUICC(415)의 가용한 메모리 정보가 포함되어 전송될 수 있다. eUICC(415)의 가용한 메모리를 판단할 수 있는 정보는 extCardResource 데이터에 포함되어 전송될 수 있고 byte 형식일 수 있다. (425 단계)
상기 정보를 수신한 프로파일 서버(420)는 프로파일 설치를 위한 eSIM칩의 메모리가 부족하다고 판단하는 경우, 회신데이터로 에러를 리턴할 수 있다. 일 예로 상기 프로파일 서버(420)는 AuthenticateClient의 Response로 에러와 에러 이유로 insufficientMemory를 회신할 수 있다.
한편, 프로파일 서버(420)는 eUICCInfo2에 "additionalProfile" bit가 0으로 설정된 경우에 insufficientMemory를 회신하도록 할 수도 있다. 이와 같은 내용은 후술하는 도 5 내지 도 9, 도 12a, 도 12b에서도 동일하게 적용될 수 있다.
상기 회신을 수신한 단말 LPA(405)는 프로파일 설치를 위한 RSP 세션을 종료할 수 있다. 또한, LPA(405)는 저장 공간이 부족함을 (사용자에게) 알리고 프로파일 설치 절차를 종료 하거나 또는, 프로파일(들)을 삭제 후 설치로 안내할 수도 있다.
ES 이동을 지원하는 프로파일 서버인 경우, eUICCInfo2에 "additionalProfile" bit가 1로 설정되어 있는지 여부와 무관하게 insufficientMemory를 회신할 수도 있다. 단말의 정보에 "ES 이동 지원", eUICCInfo2에 "ES 이동 지원" 중 적어도 하나을 포함해 수신하면 프로파일 서버(420)는 AuthenticateClient의 Response로 에러와 에러 이유로 insufficientMemory를 회신하면서 추정 프로파일 용량 (estimated Profile size)정보를 더 추가하여 전송할 수도 있다. (430 단계)
이와 같은 내용은 후술하는 도 5 내지 도 9, 도 12a, 도 12b에서도 동일하게 적용될 수 있다.
상기 회신을 수신한 단말 LPA(405)는 AuthencateClient의 Response로 에러를 수신하더라도 estimated Profile size를 추가 수신 시, 프로파일 설치 절차를 종료(Cancel Session)하고 또는 종료하지 않고, eSIM칩에 프로파일 설치를 위한 저장 공간을 추가로 확보하는 동작을 수행할 수 있다. 상기 저장 공간을 추가로 확보하는 동작은 프로파일 이동 또는 삭제 절차일 수 있다. 프로파일 이동 또는 삭제 절차로 진입을 위해서 단말은 사용자의 동의를 추가로 획득할 수도 있다.
LPA는(405) 해당 프로파일 설치를 위해 eSIM칩 외부로 이동 가능한 프로파일이 있는지, 그리고/또는 프로파일 이동을 통해 확보 가능한 저장 공간을 확인하기 위해 추가적으로 기 설치된 프로파일들에 대한 정보를 확인(438 단계 및 439 단계)할 수 있다. 예를 들어, LPA(405)은 GetProfileInfo(438 단계)를 eUICC(415)에 전송하고, eUICC(415)로부터 각 프로파일들의 정보를 수신(439 단계)할 수 있다. 이때 수신된 프로파일(들)의 메타데이터의 정보로, LPA(400)은 프로파일(들)이 ES 지원 여부를 확인할 수 있다. 프로파일들의 ES 지원 여부는, 해당 ICCID의 ES 지원 식별 정보, 민감 데이터의 분리 저장에 대한 정보 중의 하나일 수 있다. 또는, LPA는 ES 지원 eUICC에 설치된 ICCID의 경우, “ES 지원”을 허용한다고 간주할 수도 있다. LPA는 해당 수신된 메타데이터의 estimatedProfileSize 또는 eUICC에 설치된 프로파일들의 개수를 더 확인할 수도 있다. (439 단계)
LPA(405)은 수집한 정보를 기반으로, 프로파일의 이동을 통해서 신규 프로파일 다운로드 저장을 위한 공간 확보가 가능한 지 판단할 수 있다. (440 단계) LPA(405)가 판단을 위해 활용하는 정보는 예를 들어, 앞서 eUICCInfo2로부터 수집한 eSIM칩의 가용 메모리 정보, 그리고/또는 프로파일 서버로부터 수신한 추정 프로파일 용량 (estimatedProfileSize), 439 단계에서 수신한 기 설치된 프로파일들의 Ext. Storage 지원 여부, estimatedProfileSize 중 적어도 하나 이상의 정보일 수 있다.
LPA(405)는 eUICC(415)가 ES 이동을 지원하더라도 기 설치된 프로파일들 중에 ES 이동을 지원하는 프로파일이 없는 경우, 설치를 종료할 수 있다. (445 단계)
설치 종료(445 단계, 앞서 435 단계도 동일하게 적용 가능)시에, LPA(405)는 SGP.22에 정의된 바와 같이 eUICC에 CancelSession (CancelSessionReason, transaction Id) 메시지를 전송하여 eUICC(415)가 프로파일 설치를 위한 세션을 종료하도록 요청할 수 있다. 또한 상기 요청을 수신 받은 eUICC(415)는 CancelSession Reason을 포함하는 eUICC 서명된 데이터를 LPA에 회신해 주어 LPA(405)는 상기 데이터를 다시 프로파일 서버에(420) 전송할 수 있다. 이때, Cancel Session Reason은 세션 종료 (SessionAborted)이거나, ES지원 프로파일이 없음을 나타내는 Cancel Session Reason, 예를 들어, NoProfileWithExtStorageSupport이 사용될 수도 있다.
한편, 프로파일 서버(420)는 수신된 Cancel Session 메시지를 확인하여, RSP Session을 종료할 수 있다. 프로파일 서버(420)는 통신사업자 (미도시)에게 프로파일 설치 에러에 대한 이유를 제공할 수 있다.
eUICC(415) 외부로 이동 가능한 프로파일이 있는 경우, LPA(405)는 eUICC(415) 외부로 프로파일 이동 절차를 수행할 수 있다. (450 단계) 이는 후술하는 도면 7 내지 도 8과 같이, Session을 종료하고, 또는 종료하지 않고 수행될 수 있다.
프로파일 이동 절차(450 단계)는 단말 사용자(400)의 이동할 프로파일을 선택 또는 단말 설정에 따른 프로파일 이동으로 시작할 수도 있다. 도 9에서 후술하는 바와 같이, LPA(405)에서 eUICC(415)로 프로파일 이동 요청을 전송할 수 있다. 상기 이동 요청을 수신한, eUICC(415)는 eUICC 외부로 이동할 프로파일 데이터를 생성하고, 상기 생성된 프로파일 데이터를 LPA (405)에 회신해 줄 수 있다. LPA(405)는 수신한 데이터를 저장하여 이동을 처리할 수 있다. (450 단계) LPA(405)는 프로파일의 이동 저장을 처리한 후에, 프로파일 설치를 진행할 수 있다. (455 단계).
예를 들어, 단말은 프로파일 서버(420)와 RSP Session을 유지하면서 프로파일 이동을 처리하고 프로파일 다운로드 절차를 이어서 진행하거나,
또는 프로파일 서버(420)와의 RSP Session을 종료(Cancel)하고 프로파일 이동을 처리 후, 프로파일 설치를 처음부터 시작하여 프로파일을 설치를 진행하거나,
또는, 프로파일 서버(420)와의 RSP Session을 보류(Resume)하고 프로파일 이동을 처리 후, 프로파일 설치를 재개하여 이후 처리를 수행할 수도 있다.
앞서, 단말은 프로파일 서버(420)와 RSP Session을 유지하면서 프로파일 이동을 처리하고 프로파일 다운로드 절차를 이어서 진행하는 경우, 일 예로 LPA(405)는 authenticateClient Request를 프로파일 서버(420)에 다시 전송하여, 상기 요청에 대한 회신으로 프로파일 메타데이터를 획득함으로써 이후 절차를 이어 갈 수도 있다.
도 5는 본 개시의 다른 실시 예에 따른 프로파일 다운로드 설치 시 eUICC 가용 메모리 확인 및 eUICC에서 프로파일을 이동하는 실시 예를 나타내는 도면이다.
도 5는 일 실시 예에 따라, 전술한 도 3에서 eUICC에 설치된 프로파일(들)을 eUICC 외부로 이동을 판단이 필요한 동작의 예로 단말 사용자(500)가 신규 프로파일을 단말에 설치하는 과정에서 적용되는 다른 방법을 설명하기 위한 도면이다.
단말 사용자(500)는 신규 프로파일을 프로파일 서버(520)부터 다운로드 받아 설치하고자 할 수 있다. 이때 단말은 프로파일을 설치하는 과정 중에서 eUICC(515)에 해당 프로파일 설치하기 위한 저장 공간이 있는지를 판단할 수 있다.
예를 들어, 단말의 LPA(505)에서는 프로파일 서버로부터 설치할 프로파일의 예상 데이터 크기를 먼저 확인할 수 있다.
프로파일을 설치하기 위한 상호 인증 과정 중에 LPA(505)는 프로파일 서버(520)에 단말의 정보와 eUICC(515)의 정보를 포함하여 전송할 수 있다. 상기 예를 들어 클라이언트 검증에 대한 AuthenticateClient의 데이터에 포함되어 전송될 수 있다. 단말의 정보에 "ES 이동 지원", eUICCInfo2에 "ES 이동 지원", eUICC(515)의 가용한 메모리 정보가 포함되어 전송될 수 있다. eUICC(515)의 가용한 메모리를 판단할 수 있는 정보는 extCardResource 데이터에 포함되어 전송될 수 있다. (525 단계)
상기 정보를 수신한 프로파일 서버(520)는 프로파일 설치를 위한 eSIM칩의 메모리가 부족하다고 판단하는 경우, 프로파일 서버(520)가 단말의 정보 또는 eUICCInfo2 정보에 "ES 지원" 정보 없이 메시지를 수신하거나 또는 ES 지원 식별자를 이해하지 못하는 경우, 프로파일 서버(520)는 에러와 에러 이유로 insufficientMemory를 회신할 수 있다.
일 예로 상기 프로파일 서버(520)는 AuthenticateClient의 Response로 에러와 에러 이유로 insufficientMemory를 회신할 수 있다. 상기 회신을 수신한 단말 LPA(505)는 프로파일 설치를 위한 RSP 세션을 종료 (535 단계)할 수 있다. 또한, LPA는 저장 공간이 부족함을 (사용자에게) 알리고 프로파일 설치 절차를 종료 하거나 또는, 프로파일(들)을 삭제 후 설치로 안내할 수도 있다.
ES를 지원하는 프로파일 서버인 경우, 상기 프로파일 서버(520)는 예상되는 프로파일 크기 정보를 포함한 메시지 회신을 생성해 회신할 수 있다. 예를 들어, ES 이동을 지원하는 서버인 경우, 단말의 정보에 "ES 이동 지원", eUICCInfo2에 "ES 이동 지원"을 포함해 수신하면 프로파일 서버(520)는 에러를 전송하는 대신 AuthenticateClient의 Response Ok를 전송하면서 insufficientMemory를 알려 줄 수 있다. 이때, 추정 프로파일 용량 (estimated Profile size)에 대한 정보가 포함되어 회신 될 수도 있다. (530 단계)
상기 AuthenticateClient의 Response Ok는 일 실시 예에 따르면 다음과 같은 표 1 또는 표 2와 같은 형태를 포함할 수 있다.
AuthenticateClientOk ::= SEQUENCE {
transactionId [0] TransactionId,
insufficientMemory NULL OPTIONAL, - Not enough space for this Profile download
estimatedProfileSize [33] INTEGER OPTIONAL -- estimated Profile Size to be downloaded,
waitingTime INTEGER OPTIONAL, -- estimated time in minutes by when the SM-DP+ maintains the session for this Profile Download.
esSessionId [X] OCTET STRING (SIZE(1..16)) OPTIONAL -- the LPA will use this identifier to check to restart session, or continue the remained RSP session
}
AuthenticateClientOkExtStorage ::= SEQUENCE {
transactionId [0] TransactionId,
smdpSignedX SmdpSignedX, -- Signed information
smdpSignature [APPLICATION 55] OCTET STRING -- tag '5F37'
}
SmdpSignedX ::= SEQUENCE { -- #SupportedForExtStorage#
transactionId [0] TransactionId, -- The TransactionID generated by the SMDP+
insufficientMemory NULL OPTIONAL, - Not enough space for this Profile download
estimatedProfileSize [33] INTEGER OPTIONAL -- estimated Profile Size to be downloaded
waitingTime INTEGER OPTIONAL, -- estimated time in minutes by when the SM-DP+ maintains the session for this Profile Download.
esSessionId [X] OCTET STRING (SIZE(1..16)) OPTIONAL -- the LPA will use this identifier to check to restart session, or continue the remained RSP session

}
상기 정보를 수신한 단말 LPA(505)는 설치 종료로 진입하지 않고, eSIM칩에 프로파일 설치를 위한 저장 공간을 추가로 확보하는 동작을 수행할 수 있다. 상기 동작은 프로파일 이동 또는 삭제 절차일 수 있다. 프로파일 이동 또는 삭제 절차로 진입을 위해서 단말은 사용자의 동의를 추가로 획득할 수도 있다.LPA는(505), 해당 프로파일 설치를 위해 eSIM칩 외부로 이동 가능한 프로파일이 있는지, 그리고/또는 프로파일 이동을 통해 확보 가능한 저장 공간을 확인하기 위해 추가적으로 기 설치된 프로파일들에 대한 정보를 확인(538 단계 및 539 단계)할 수 있다. 예를 들어, LPA(505)은 GetProfileInfo(538 단계)를 eUICC(515)에 전송하고, eUICC(515)로부터 각 프로파일들의 정보를 수신(539 단계)할 수 있고, 이 때 수신된 프로파일(들)의 메타데이터의 정보로, 프로파일(들)이 ES 이동 허용 식별자가 있는지 확인할 수도 있다. 또한, LPA(505)은 해당 수신된 메타데이터의 estimatedProfileSize 또는 eUICC에 설치된 프로파일들의 개수를 더 확인할 수 있다. (539 단계)
LPA(505)은 수집한 정보를 기반으로, 프로파일의 이동을 통해서 신규 프로파일 다운로드 저장을 위한 공간 확보가 가능한 지 판단할 수 있다. (540 단계) LPA(505)가 판단을 위해 활용하는 정보는 예를 들어, 앞서 eUICCInfo2로부터 수집한 eSIM칩의 가용 메모리 정보, 그리고/또는 프로파일 서버로부터 수신한 추정 프로파일 용량 (estimatedProfileSize), 539 단계에서 수신한 기 설치된 프로파일들의 Ext. Storage 지원 여부, estimatedProfileSize 중 적어도 하나 이상의 정보일 수 있다. 프로파일들의 ES 지원 여부는, 해당 ICCID의 ES 지원 식별 정보, 민감 데이터의 분리 저장에 대한 정보 중의 하나일 수 있다. 또는, ES 지원 eUICC에 설치된 ICCID의 경우, “ES 지원”을 허용한다고 간주할 수도 있다.
LPA(505)는 eUICC(515)가 ES 이동을 지원하더라도 기 설치된 프로파일들 중에 ES 이동을 지원하는 프로파일이 없는 경우, 설치를 종료할 수 있다. (545 단계)
설치 종료(545 단계, 앞서 535 단계도 동일하게 적용 가능)시에, LPA(505)는 SGP.22에 정의된 바와 같이 eUICC(515)에 CancelSession (CancelSessionReason, transaction Id) 메시지를 전송하여 eUICC(515)가 프로파일 설치를 위한 세션을 종료하도록 요청할 수 있다. 또한 이를 수신 받은 eUICC(515)는 CancelSession Reason을 포함하는 eUICC 서명된 데이터를 LPA에 회신해 주어 LPA(505)는 이를 다시 프로파일 서버에 전송하여 줄 수 있다. 이때, Cancel Session Reason은 세션 종료 (SessionAborted)이거나, ES지원 프로파일이 없음을 나타내는 Cancel Session Reason, 예를 들어, NoProfileWithExtStorageSupport이 사용될 수도 있다.
한편, 프로파일 서버(520)는 수신된 Cancel Session 메시지를 확인하여, RSP Session을 종료할 수 있다. 프로파일 서버(520)는 통신사업자 (미도시)에게 프로파일 설치 에러에 대한 이유를 제공해 줄 수 있다.
eUICC (515) 외부로 이동 가능한 프로파일이 있는 경우, LPA(505)는 eUICC(515) 외부로 프로파일 이동 절차를 수행할 수 있다. (550 단계) 이는 후술하는 도면 7 내지 도 8과 같이, Session을 종료하고, 또는 종료하지 않고 수행될 수 있다.
프로파일 이동 절차(550 단계)는 단말 사용자의 이동할 프로파일을 선택 또는 단말 설정에 따른 프로파일 이동으로 시작할 수도 있다. 도 9에서 후술하는 바와 같이, LPA(505)에서 eUICC(515)로 프로파일 이동 요청을 전송할 수 있다. 상기 이동 요청을 수신한, eUICC(515)는 eUICC 외부로 이동할 프로파일 데이터를 생성하고 상기 프로파일 데이터를 LPA (505)에 회신해 줄 수 있다. LPA(505)는 수신한 데이터를 저장하여 이동을 처리할 수 있다. (550 단계) LPA(505)는 프로파일의 이동 저장을 처리한 후에, 프로파일 설치를 진행할 수 있다. (555 단계).
예를 들어, 단말은 프로파일 서버(520)와 RSP Session을 유지하면서 프로파일 이동을 처리하고 프로파일 다운로드 절차를 이어서 진행하거나,
또는 프로파일 서버(520)와의 RSP Session을 종료(Cancel)하고 프로파일 이동을 처리 후, 프로파일 설치를 처음부터 시작하여 프로파일을 설치를 진행하거나,
또는, 프로파일 서버(520)와의 RSP Session을 보류(Resume)하고 프로파일 이동을 처리 후, 프로파일 설치를 재개하여 이후 처리를 수행할 수도 있다.
앞서, 단말은 프로파일 서버(520)와 RSP Session을 유지하면서 프로파일 이동을 처리하고 프로파일 다운로드 절차를 이어서 진행하는 경우, 일 예로 LPA(505)는 authenticateClient Request를 프로파일 서버(520)에 다시 전송하여, 이에 대한 회신으로 프로파일 메타데이터를 획득함으로써 이후 절차를 이어 갈 수도 있다.
도 6는 본 개시의 다른 실시 예에 따른 프로파일 다운로드 설치 시 eUICC 가용 메모리 확인 및 eUICC에서 프로파일을 이동하는 실시 예를 나타내는 도면이다.
도 6은 일 실시 예에 따라, 전술한 도 3에서 eUICC에 설치된 프로파일(들)을 eUICC 외부로 이동을 판단이 필요한 동작의 예로 단말 사용자(600)가 신규 프로파일을 단말에 설치하는 과정에서 적용되는 다른 방법을 설명하기 위한 도면이다.
단말 사용자(600)는 신규 프로파일을 프로파일 서버(620)부터 다운로드 받아 설치하고자 할 수 있다. 이때 단말은 프로파일을 설치하는 과정 중에서 eUICC(615)에 해당 프로파일을 설치하기 위한 저장 공간이 있는지를 판단할 수 있다.
예를 들어, 단말의 LPA(605)에서는 프로파일 서버(620)로부터 설치할 프로파일의 예상 데이터 크기를 먼저 확인할 수 있다.
프로파일을 설치하기 위한 상호 인증 과정 중에 LPA(605)는 프로파일 서버(620)에 단말의 정보와 eUICC(615)의 정보를 포함하여 전송할 수 있다. 상기 정보는 예를 들어 클라이언트 검증에 대한 AuthenticateClient의 데이터에 포함되어 전송될 수 있다. 단말의 정보에 "ES 이동 지원", eUICCInfo2에 "ES 이동 지원", eUICC(615)의 가용한 메모리 정보가 포함되어 전송될 수 있다. eUICC(615)의 가용한 메모리를 판단할 수 있는 정보는 extCardResource 데이터에 포함되어 전송될 수 있다. 또한, eUICCInfo2에 estimatedProifleSizeIndicationSupport가 더 포함되어 전송될 수도 있다. (625 단계)
상기 정보를 수신한 프로파일 서버(620)는 프로파일 설치를 위한 eSIM칩의 메모리가 부족하다고 판단하는 경우, 프로파일 서버(620)가 단말의 정보 또는 eUICCInfo2 정보에 "ES 지원" 정보 없이 메시지를 수신하거나 또는 ES 지원 식별자를 이해하지 못하는 경우, 프로파일 서버(620)는 에러와 에러 이유로 insufficientMemory를 회신할 수 있다.
일 예로 프로파일 서버(620)는 AuthenticateClient의 Response로 에러와 에러 이유로 insufficientMemory를 회신할 수 있다. 상기 회신을 수신한 단말 LPA(605)는 프로파일 설치를 위한 RSP 세션을 종료 (635 단계)할 수 있다. 또한, LPA(605)는 저장 공간이 부족함을 (사용자에게) 알리고 프로파일 설치 절차를 종료 하거나 또는, 프로파일(들)을 삭제 후 설치로 안내할 수도 있다.
ES를 지원하는 프로파일 서버(620)인 경우, 에러를 회신하는 대신 insufficientMemory가 발생하더라도 성공 응답으로 회신할 수 있다. 예를 들어, ES 이동을 지원하는 서버인 경우, 단말의 정보에 "ES 이동 지원", eUICCInfo2에 "ES 이동 지원"을 포함해 수신한 경우, 프로파일 서버(620)는 AuthenticateClient의 Response Ok로 프로파일 메타데이터를 전송하면서 insufficientMemory 여부를 더 포함해 회신해 줄 수도 있다.
상기 AuthenticateClient의 Response Ok는 일 실시 예에 따르면, 다음과 같은 표 3의 형태를 포함할 수 있다.
AuthenticateClientOk ::= SEQUENCE {
transactionId [0] TransactionId,
profileMetadata [37] StoreMetadataRequest, -- tag 'BF25'
smdpSignedY SmdpSignedY, -- Signed information
smdpSignatureY [APPLICATION 55] OCTET STRING, -- tag '5F37'
smdpCertificate Certificate, -- CERT.DPpb.SIG
insufficientMemory NULL OPTIONAL, - Not enough space for this Profile download
waitingTime INTEGER OPTIONAL, -- estimated time in minutes by when the SM-DP+ maintains the session for this Profile Download.
EsSessionId [X] OCTET STRING (SIZE(1..16)) OPTIONAL -- the LPA will use this identifier to check to restart session, or continue the remained RSP session
}
앞서, 625 단계에서 프로파일 서버(620)가 estimatedProfileSizeSupport를 더 포함해 단말로부터 수신한 경우, 프로파일 서버(620)는 프로파일의 메타데이터에 추정프로파일 용량(estimated Profile size)를 포함 제공할 수 있다. (630 단계)
그리고 단말 LPA(605)는 프로파일의 메타데이터를 사용자 화면에 보여주고 설치에 대한 동의를 획득하는 절차를 수행하기에 앞서, eSIM칩에 프로파일 설치를 위한 저장 공간을 추가로 확보가 가능한 지 판단하는 동작을 수행할 수도 있다.
LPA(605)는, 해당 프로파일 설치를 위해 eSIM칩 외부로 이동 가능한 프로파일이 있는지, 그리고/또는 프로파일 이동을 통해 확보 가능한 저장 공간을 확인하기 위해 추가적으로 기 설치된 프로파일들에 대한 정보를 확인(638 단계 및 639 단계)할 수 있다. 예를 들어, LPA(605)은 GetProfileInfo(638 단계)를 eUICC(615)에 전송하고, eUICC(615)로부터 각 프로파일들의 정보를 수신(639 단계)할 수 있고, 상기 LPA(605)는 수신된 프로파일(들)의 메타데이터의 정보로, 프로파일(들)이 ES 이동 허용 식별자가 있는지 확인할 수 있다. 상기 ES 이동 허용 식별자란 ES 지원 여부에 대한 식별 정보, 민감 데이터에 대한 분리 저장에 대한 정보 중의 하나일 수 있다. 또는, ES 지원 eUICC에 설치된 ICCID의 경우, ICCID의 정책으로 “ES 지원”을 허용한다고 간주할 수도 있다.상기 LPA(605)는 해당 수신된 메타데이터의 estimatedProfileSize 또는 eUICC에 설치된 프로파일들의 개수를 더 확인할 수도 있다. (639 단계)
LPA(605)은 수집한 정보를 기반으로, 프로파일의 이동을 통해서 신규 프로파일 다운로드 저장을 위한 공간 확보가 가능한 지 판단할 수 있다. (640 단계) LPA(605)가 판단을 위해 활용하는 정보는 예를 들어, 앞서 eUICCInfo2로부터 수집한 eSIM칩의 가용 메모리 정보, 그리고/또는 프로파일 서버로부터 수신한 추정 프로파일 용량 (estimatedProfileSize), 639 단계에서 수신한 기 설치된 프로파일들의 ES 지원 여부, estimatedProfileSize 중 적어도 하나 이상의 정보일 수 있다.
한편, LPA(605)는 프로파일의 설치 진행을 위한 사용자 동의를 획득할 수 있다. (643 단계)
프로파일 설치 진행을 위해, 기 설치된 프로파일들의 eSIM칩 외부 이동/삭제 후 설치가 가능에 대한 정보 및 동의도 추가적으로 더 획득할 수 있다. 한편, 643 단계는 638 단계 ~ 640 단계를 수행하기 이전에 수행될 수 있다.
LPA(605)는 eUICC(615)가 ES 이동을 지원하더라도 기 설치된 프로파일들 중에 ES 이동을 지원하는 프로파일이 없는 경우, 설치를 종료할 수 있다. (645 단계)
설치 종료(645 단계, 앞서 635 단계도 동일하게 적용 가능)시에, LPA(605)는 SGP.22에 정의된 바와 같이 eUICC(615)에 CancelSession (CancelSessionReason, transaction Id) 메시지를 전송하여 eUICC(615)가 프로파일 설치를 위한 세션을 종료하도록 요청할 수 있다. 또한 상기 요청을 수신 받은 eUICC(615)는 CancelSession Reason을 포함하는 eUICC 서명된 데이터를 LPA(605)에 회신할 수 있다. 이때 LPA(605)는 상기 회신을 다시 프로파일 서버에 전송할 수 있다. 이때, Cancel Session Reason은 세션 종료 (SessionAborted)이거나, ES지원 프로파일이 없음을 나타내는 Cancel Session Reason, 예를 들어, NoProfileWithExtStorageSupport이 사용될 수도 있다.
한편, 프로파일 서버(620)는 수신된 Cancel Session 메시지를 확인하여, RSP Session을 종료할 수 있다. 프로파일 서버(620)는 통신사업자 (미도시)에게 프로파일 설치 에러에 대한 이유를 제공해 줄 수 있다.
eUICC 외부로 이동 가능한 프로파일이 있는 경우, LPA(605)는 eUICC(615) 외부로 프로파일 이동 절차를 수행할 수 있다. (650 단계) 이는 후술하는 도면 7 내지 도 8과 같이, Session을 종료하고, 또는 종료하지 않고 수행될 수 있다.
도 9에서 후술하는 바와 같이, LPA(605)에서 eUICC(615)로 프로파일 이동 요청을 전송할 수 있다. 상기 요청을 수신한, eUICC(615)는 eUICC 외부로 이동할 프로파일 데이터를 생성하고, 상기 생성된 프로파일 데이터를 LPA (605)에 회신할 수 있다. LPA(605)는 수신한 데이터를 저장하여 이동을 처리할 수 있다. (650 단계) LPA(605)는 프로파일의 이동 저장을 처리한 후에, 프로파일 설치를 진행할 수 있다. (655 단계).
예를 들어, 단말은 프로파일 서버(620)와 RSP Session을 유지하면서 프로파일 이동을 처리하고 프로파일 다운로드 절차를 이어서 진행하거나,
또는 프로파일 서버(620)와의 RSP Session을 종료(Cancel)하고 프로파일 이동을 처리 후, 프로파일 설치를 처음부터 시작하여 프로파일을 설치를 진행하거나,
또는, 프로파일 서버(620)와의 RSP Session을 보류(Resume)하고 프로파일 이동을 처리 후, 프로파일 설치를 재개하여 이후 처리를 수행할 수도 있다.
앞서, 단말은 프로파일 서버와 RSP Session을 유지하면서 프로파일 이동을 처리하고 프로파일 다운로드 절차를 이어서 진행하는 경우, LPA(605)는 getBoundProfilePackageRequest를 프로파일 서버(620)에 전송함으로써, 설치를 이어 진행할 수도 있다.
getBoundProfilePackageRequest를 수신한 프로파일 서버(620)는 가용 메모리가 확보 되었다고 암묵적으로 인지하고, BoundProfilePakcage를 생성하여 회신할 수 있다.
도 7은 본 개시의 일 실시 예에 따른 프로파일의 단말 내 이동 후 기존 프로파일 설치를 재개하는 방법에 대한 도면이다.
도 7 또는 도 8은 전술한 도 3 내지 도 6, 도 9, 도 12a, 도 12b에서의 프로파일들을 eUICC에서 외부로 이동 후 적용될 수 있는 예시 도면으로, 도 7은 RSP Session을 유지한 상태에서 기 설치된 프로파일을 eUICC 외부로 이동을 수행 후, 프로파일 설치를 이어 진행하는 절차를 설명한다.
도 3 내지 도 6, 도 9, 도 12a, 도 12b에서 전술한 바와 같이, 단계 730에서 가용 메모리 부족으로 eUICC(715)의 프로파일의 Ext. Storage 이동을 결정할 수 있다.
프로파일(들)에 대한 이동 설치(775 단계)를 수행한 다음에 LPA(705)는 이후 동작으로, SGP.22에 정의된 이후 프로파일 설치 절차를 완료할 수 있다. 상기 설치 절차의 완료에 대한 이후 동작의 일 예로, GetBoundProfilePackage Request를 프로파일 서버(720)에 요청하는 동작일 수 있다. 프로파일 서버(720)가 insufficient Memory를 단말의 LPA(705)에 회신하고 이후 GetBoundProfilePackage Request 수신 시, 프로파일 서버(720)는 단말에서 가용한 메모리가 확보되었다고 판단하고 ProfilePackage를 회신할 수 있다.
LPA(705)는 가용 eUICC 메모리 정보가 확보되었음을 명시적으로 프로파일 서버(720)에 알려 주는 절차(780 단계에서 788 단계)를 790 단계 이전에 더 수행할 수도 있다.
예를 들어, LPA(705)는 프로파일 서버(720)에 eUICC 서명된 데이터로 가용 eUICC 메모리 정보, 그리고 transaction id 중 적어도 하나의 정보를 포함하여 제공할 수도 있다.
일 예로, LPA(705)가 780 단계의 메시지에 포함하여 전송한 정보로 수집 또는 eUICC (715)에서 LPA(705)의 780 단계의 명령을 받아 eUICC가 수집한 정보로, eUICC는 세션 식별 정보인 transaction id, 가용 eUICC 메모리 정보 중 하나 이상의 정보를 획득할 수 있다.
LPA(705)로부터 eUICC(715)는 가용 eUICC 메모리 정보 전송을 위한 eUICC의 서명된 데이터를 요청 받을 수 있다. (780 단계) 이때, eUICC(715)는 가용 eUICC 메모리 정보, transaction id가 포함한 데이터를 생성하고, 해당 데이터를 서명하여 LPA(705)에 회신(783 단계)할 수 있다. LPA(705)는 eUICC(715)로부터 상기 회신을 수신하여 프로파일 서버(720)에 전송(785 단계)할 수 있다. 785 단계에서 전송하는 메시지는 가용 메모리 확보에 대한 신규 ES9+ 함수일 수도 있고, 현재 SGP.22에 정의된 ES9+. AuthenticateClient Request 함수일 수도 있다.
프로파일 서버(720)는 수신된 eUICC의 서명을 검증하고, transaction id를 통해 앞서 프로파일 설치에 대한 RSP 세션임을 판단하고 또한 추가적으로 가용 eUICC 메모리 확보에 대한 정보를 확인하여 회신할 수 있다. (788 단계) 프로파일 서버(720)는 프로파일 설치를 위한 메모리가 예상 프로파일 사이즈 보다 큰 경우, 성공 응답(Response Ok)을 회신할 수 있다. 만약 프로파일 설치를 위한 메모리가 부족한 경우, 프로파일 서버(720)는 에러를 회신하고 절차를 종료할 수도 있다.
앞서 성공 응답을 수신하여 LPA (705)는 790 단계를 이어 진행할 수 있다.
한편, 프로파일 서버는 단말에 RSP 세션 유지 시간을 명시적으로 더 제공하여 줄 수도 있다. 예를 들어, 프로파일 서버가 RSP 세션 유지에 대한 잔여 시간 정보 또는/그리고 세션 식별 정보는 AuthenticateClient의 Response에 포함되어 회신될 수 있다. 이는 일 예로, 앞서, 430 단계, 530 단계, 630 단계, 1230 단계 중의 하나에 해당할 수 있다. 추가적으로 프로파일 서버는 ES 이동 후의 프로파일 다운로드 절차를 연결해 진입을 고려 시, 어떤 프로파일 다운로드를 수행 중에서 발생한 동작인지를 판단하기 위한 식별 정보를 단말에 더 제공하여 줄 수도 있다. 이는 해당 세션의 transaction ID 일 수도 있고, 이와 별도의 신규 ID로 정의될 수도 있다.
이 경우에, 단말의 LPA(705)는 RSP 세션 유지 시간 내, ES 이동 절차를 완료하여, 도 7의 790 단계로 진입할 수 있다. 또는 LPA(705)는 해당 제공된 시간을 초과하여 재 다운로드를 시도하는 경우에, 세션이 유효하지 않음을 판단하여, 프로파일 다운로드를 다시 시작하는 절차로 진입할 수도 있다.
한편, 도 8은 본 개시의 다른 실시 예에 따른 프로파일의 단말 내 이동 후 기존 프로파일 설치를 재개하는 방법에 대한 도면이다.
도 7 또는 도 8은 전술한 도 3 내지 도 6, 도 12a, 도 12b에서의 프로파일들을 eSIM칩에서 외부로 이동 후 적용될 수 있는 예시 도면으로, 도 8은 RSP Session을 종료하고, 프로파일을 eUICC 외부로 이동을 수행 후, 프로파일 설치를 다시 시작하는 절차를 설명한다.
도 3 내지 도 6, 도12에서 전술한 바와 같이, 단계 830에서 가용 메모리 부족으로 eUICC(815)의 프로파일의 Ext. Storage 이동을 결정할 수 있다. 예를 들어 앞서 도 3 내지 도 6에서 사용자가 프로파일의 ES 이동을 선택하는 경우에, 단말은 기존 세션을 취소(Cancel)하고 eUICC 서명된 데이터로 프로파일 서버(820)에 CancellSession 결과를 회신하여 줄 수 있다. 일 예로 LPA(805)는 SGP.22에 정의된 바와 같이 eUICC(815)에 CancelSession (CancelSessionReason, transaction Id) 메시지를 전송하여 eUICC(815)가 프로파일 설치를 위한 세션을 종료하도록 요청할 수 있다. 또한 상기 요청을 수신 받은 eUICC(815)는 CancelSession Reason을 포함하는 eUICC 서명된 데이터를 LPA(805)에 회신할 수 있다. LPA(805)는 상기 데이터를 다시 프로파일 서버(820)에 전송할 수 있다. 이때, Cancel Session Reason은 세션 종료 (SessionAborted)이거나, 프로파일 이동 후 재 접속을 나타내기 위한 Cancel Session Reason으로, 예를 들어, postpone, afterProfileExportToStorage 와 같은 Cancel Session Reason이 정의될 수 있다.
postpone, afterProfileExportToStorage 과 같은 프로파일을 단말로 이동 후에 설치 재개를 나타내기 위한 Reason code를 수신 받는 경우에, eUICC(815)는 프로파일의 설치를 위해 생성한 암호화 키들, 일 예로 otPK/otSK (세션 생성 시 input으로 사용되는 일회용 공개키 및 비밀키 쌍)을 삭제하지 않고 저장할 수 있다. 한편, 프로파일 서버(820)는 수신된 Cancel Session 메시지를 확인하여 서명을 검증하고, RSP Session을 종료할 수 있다. 프로파일 서버(820)는 프로파일의 설치 재개가 예상되는 경우, 예를 들어 postpone, afterProfileExportToStorage 과 같은 에러 코드를 수신한 경우 통신사업자 (미도시)에게 프로파일 설치 에러에 대한 이유를 제공하지 않을 수도 있다.
단말은 세션을 종료한 후에, 도 9에서 후술하는 것과 같이 프로파일 이동 설치 절차를 수행할 수 있다.
프로파일 이동 절차를 수행 후, LPA(805)는 프로파일 서버 (820)에 프로파일 설치 절차를 위해 SGP.22에 정의된 프로파일 설치 절차를 처음부터 다시 시작하여 절차를 진행할 수 있다.
도 9는 본 개시의 일 실시 예에 따라 eUICC에서 프로파일을 eUICC 외부로 이동하는 절차를 나타내는 도면이다.
도 9는 eUICC에서 프로파일을 eUICC 외부로 이동하는 절차를 나타내는 하나의 실시 예시 도면으로 전술한 도 3 내지 도 8, 도 12a, 도 12b의 실시 예에서 공통적으로 적용될 수 있다.
프로파일 이동 절차는 단말 사용자(900)의 이동할 프로파일을 선택(935 단계)하여 시작될 수 있다. 또는, 단말에서 단말 설정에 따른 프로파일 이동이 필요함을 인지하여 (예. eUICC의 가용 메모리 부족 감지 등), 사용자의 동의를 획득하거나 또는 단말 판단에 기반하여 시작될 수도 있다.
앞서 도 3 내지 도 8, 또는 도 12a, 도 12b에서 설명한 바와 같이 프로파일 이동 절차는 eUICC(910)에 가용 메모리가 부족함을 단말(905)에서 인지하는 것(915 단계)에 따른 후속 동작으로 진행될 수 있다. 예를 들면, 단말 LPA(905)는 프로파일 삭제 또는 이동이 필요함을 사용자에게 알려주고 추가 동작을 요청할 수 있다. (920 단계)
사용자가 프로파일 삭제 결정을 돕는 소정의 정보로 LPA(905)는 또한, 우선 삭제를 위한 프로파일들을 판단하여 정보를 제공해 줄 수도 있다. (925 단계) 실시 예에 따라, 925 단계는 920 단계 이전에 수행되어 920 단계에서 추가 정보로 제공될 수도 있다.
단말은 프로파일(들)의 메타데이터 또는 프로파일의 파일로부터 획득한 정보, 또는 해당 프로파일의 사용 이력, 해당 프로파일에 대한 사용자 설정 정보 등과 같은 소정의 정보를 조합하여 삭제를 위한 프로파일들을 제안해 줄 수도 있다. 상기 정보는 예를 들어, 해당 프로파일로 사용 가능한 통신 서비스 기간, 프로파일 자체의 유효 기간, 통신사 식별자(PLMN ID)를 통해 단말 사용자가 있는 해당 지역의 통신 사업자인지 여부, 프로파일이 해당 동작을 수행하는 시점에서 비활성화되어 있는지 여부, 해당 프로파일이 비활성화되어 있는 경우에 마지막으로 활성화(enabled)된 시점에 대한 정보, 사용자가 선택한 사용 우선 순위와 같은 정보 중 적어도 하나 일 수 있다.
단계 930에서 사용자가 삭제할 프로파일을 선택하는 경우, LPA(905)는 SGP.22에 정의된 바와 같이 프로파일 삭제 절차에 진입하여 eUICC(910)에서 프로파일 삭제를 처리할 수 있다. 삭제를 통해 가용한 eUICC 메모리가 확보되는 경우, LPA (905)는 프로파일 이동 절차로 진입하지 않고, 이후 절차를 수행할 수도 있다. 예를 들면, 본 발명에서는 프로파일 설치 절차가 재개되거나, 또는 다시 시작될 수도 있다.
한편, 935 단계에서 단말 사용자(900)가 프로파일 삭제를 결정하지 않고 프로파일 이동을 선택할 수도 있다.
단말 사용자(900) 또는 단말의 설정에 따라 프로파일 이동이 결정되면, LPA(905)에서 eUICC(910)으로 프로파일 이동 요청 메시지를 전송(940 단계)할 수 있다. 상기 요청은 일 예로 RequestToExtStorage와 같은 신규 명령일 수 있고, 이동할 프로파일의 식별 정보로 사용자 또는 단말이 선택한 프로파일의 ICCID 또는 AID(Application ID)가 포함되어 전송될 수 있다. 또한, 상기 요청을 수신한 eUICC(910)는 해당 ICCID의 정책으로 "ES 지원" 허용 여부를 포함하여 ES 지원 가능한 지 여부를 판단(945 단계)할 수도 있다. 만약 해당 ICCID로 식별되는 프로파일이 없거나 또는 ES를 지원하지 않는 경우, eUICC (910)은 에러를 리턴할 수 있다. 해당 ICCID의 정책으로 "ES 지원" 허용에 대한 정보는, ES 지원 여부에 대한 식별 정보, 민감 데이터에 대한 분리 저장에 대한 정보 중의 하나일 수 있다. 또는, ES 지원 eUICC는, ES 지원 eUICC에 설치된 ICCID의 경우, ICCID의 정책으로 “ES 지원”을 허용한다고 간주할 수도 있다.
프로파일이 ES 이동을 지원하는 경우, eUICC(910)는 내보 낼 (외부로 전송할) 해당 프로파일의 데이터를 구성(950 단계)할 수 있다. 상기 데이터(ESPPa로 임의로 명명)는 해당 프로파일의 전체 또는 일부의 파일들을 포함하여 구성된 데이터 패키지일 수 있다. 예를 들어 프로파일의 메타데이터 또는 네트워크 접속을 위한 인증 정보와 같은 민감 데이터 파일들은 제외한 일부로만 파일이 구성될 수 있고 바이너리 데이터 형태로 구성될 수도 있다. eUICC(910)는 외부로 내보내기 하는 해당 프로파일 패키지를 동일 EID를 가진 eUICC에서만 복호화 가능하도록 암호화 키로 암호화할 수도 있다.
eUICC(910)는 ESPPa을 LPA(905)에 요청에 대한 응답으로 회신할 수 있다. (955 단계) 이때 ESPPa만 회신되거나, 또는 ESPPa와 함께 추가적으로 복호화 가능한 eUICC 정보로 EID, 어떤 프로파일에 대한 데이터인지를 식별할 수 있도록 ICCID 와 같은 정보 중의 하나 이상이 포함되어 회신될 수도 있다. 회신되는 eUICC 데이터는 eUICC 서명이 함께 포함되어 회신될 수도 있다.
단계 960에서, LPA(905)는 수신한 데이터를 저장하여 이동을 처리할 수 있다.
또한 LPA(905)는 프로파일의 이동 저장을 처리한 후에, 연속적인 동작을 이어서 수행할 수도 있다. 연속적인 동작은 일 실시 예에 따르면, 프로파일 설치 동작일 수 있다.
LPA(905)가 프로파일 설치 과정 중에 프로파일 이동 저장을 처리하여 eUICC내 저장 공간을 획득하고, 다시 프로파일 설치를 수행(기존 세션을 종료하고 다시 처음부터 시작하거나, 또는 세션을 유지한 채 재개)하는 경우엔, LPA는 다시 사용자 동의를 획득하지 않고, 프로파일 설치 절차를 수행할 수도 있다.
전술한 도면들에서는 발명의 논지를 흐리지 않기 위해 본 도 9에서 기술한 LPA가 프로파일 데이터를 수신 받아 저장하는 절차를 기반으로 설명하였으나, 이에 한정하지 않고, LPA가 eUICC에 ESPP 요청을 하는 경우, eUICC에서 ESPP를 생성하여 단말 메모리로 전송하고 이에 대한 처리 결과를 LPA에 회신하는 형태로 프로파일 이동 동작이 수행될 수도 있음에 유의해야 한다.
한편, 도 10은 본 개시의 일 실시 예에 따른 단말의 구성을 도시하는 도면이다.
도 10을 참조하면 단말은 송수신부(1020), 프로세서(1010) 및 메모리(1030)를 포함할 수 있다. 또한, 단말은 eUICC(미도시)를 더 포함할 수도 있다. 본 개시에서 상술한 단말들은 도 10에서 설명하는 단말에 대응될 수 있다. 예를 들면, 도 1 내지 도 9에서 설명하는 단말은 도 10에서 설명하는 단말의 구성을 포함할 수 있다.
다만, 단말의 구성은 도 10에 제한되지 않으며, 도 10에 도시된 구성 요소들보다 더 많은 구성 요소를 포함하거나, 더 적은 구성 요소를 포함할 수도 있다. 일부 실시 예에 따르면, 송수신부(1020), 프로세서(1010), 메모리(1030) 및 eUICC는 하나의 칩(Chip) 형태로 구현될 수 있다. 또한, 프로세서(1020)는 적어도 하나의 프로세서로서 구성될 수 있다.
다양한 실시 예에 따르면, 송수신부(1020)는 다른 단말의 송수신부 혹은 외부 서버와 본 개시의 다양한 실시 예에 따른 신호, 정보, 데이터 등을 송신 및 수신할 수 있다. 송수신부(1020)는 송신되는 신호의 주파수를 상승 변환(up converting) 및 증폭하는 RF 송신기와, 수신되는 신호를 저 잡음 증폭하고 주파수를 하강 변환(down converting)하는 RF 수신기 등으로 구성될 수 있다. 다만, 이는 송수신부(1020)의 일 실시 예일 뿐이며, 송수신부(1020)의 구성요소가 RF 송신기 및 RF 수신기에 한정되는 것은 아니다. 또한, 송수신부(1020)는 무선 채널을 통해 신호를 수신하여 프로세서(1010)로 출력하고, 프로세서(1010)로부터 출력된 신호를 무선 채널을 통해 전송할 수 있다.
한편, 프로세서(1010)는 단말을 전반적으로 제어하기 위한 구성요소이다. 프로세서(1010)는 전술한 바와 같은 본 개시의 다양한 실시 예에 따라, 단말의 전반적인 동작을 제어할 수 있다. 프로세서(1010) eUICC의 제어 애플리케이션으로 도 1에서 도시한 LPA를 포함할 수 있다.
한편, 단말은 메모리(1030)를 더 포함할 수 있으며, 단말의 동작을 위한 기본 프로그램, 응용 프로그램, 설정 정보 등의 데이터를 저장할 수 있다. 또한, 메모리(1030)는 플래시 메모리 타입(Flash Memory Type), 하드 디스크 타입(Hard Disk Type), 멀티미디어 카드 마이크로 타입(Multimedia Card Micro Type), 카드 타입의 메모리(예를 들면, SD 또는 XD 메모리 등), 자기 메모리, 자기 디스크, 광디스크, 램(Random Access Memory, RAM), SRAM(Static Random Access Memory), 롬(Read-Only Memory, ROM), PROM(Programmable Read-Only Memory), EEPROM(Electrically Erasable Programmable Read-Only Memory) 중 적어도 하나의 저장매체를 포함할 수 있다. 또한, 프로세서(1010)는 메모리(1030)에 저장된 각종 프로그램, 컨텐츠, 데이터 등을 이용하여 다양한 동작을 수행할 수 있다. 메모리(1030)는 앞서 도 1에서 전술한 바와 같이 LPA와 연결되어 LPA가 eUICC로부터 추출한 프로파일 데이터를 저장 또는 LPA가 요청 시 제공해 줄 수 있다.
eUICC(미도시)는 송수신부 및 프로세서, 메모리를 포함할 수 있다. eUICC의 프로세서는 ISD-R 애플리케이션을 포함할 수 있다. ISD-R은 eUICC의 시스템 애플리케이션 (예를 들어, OS의 일부 또는 OS 위에 존재하는 시스템 애플리케이션)으로 존재할 수 있다. ISD-R은 LPA로부터 수신되는 명령을 송수신부를 통해 수신하고, 수신한 명령을 해석하여 eUICC에 프로파일 설치, 삭제, 이동 등과 같은 프로파일의 관리 동작을 수행할 수 있다. eUICC의 프로세서는 처리 결과를 eUICC로부터 수신하여 송수신부를 통해 LPA로부터 회신하여 주는 역할을 수행할 수 있다. 또한 eUICC의 프로세서는 프로파일의 상태 정보 및 프로파일의 권한 정보 (이동 지원 여부 포함)를 프로파일의 메타데이터로부터 획득하고 프로파일 삭제를 처리하는 경우에 삭제 처리 결과 메시지를 생성할 수도 있다. 또한 프로파일의 이동을 처리하는 경우에 이동할 프로파일 패키지를 생성하고, 이동할 프로파일 패키지를 포함하여 메시지를 구성해 LPA에 회신하여 줄 수도 있다. 또한, eUICC는 eUICC의 메모리에 프로파일의 메타데이터 정보 및 메타 데이터의 일부 또는 추가 정보로서 프로파일의 상태 정보, 프로파일의 예상 용량, 프로파일의 ES 이동 지원 여부, eUICC의 ES 지원 여부, eUICC의 잔영 메모리에 대한 정보 중 적어도 하나를 저장하여 둘 수도 있고, 프로세서는 해당 메모리에 접근하여 상술한 정보 중의 하나를 획득하여 프로파일 이동 처리, 삭제 처리 등 적어도 하나의 동작을 수행하는데 필요한 소정의 정보로서 활용할 수도 있다.
한편, 도 11은 본 개시의 일 실시 예에 따른 서버의 구성을 도시하는 도면이다.
도 11을 참조하면, 서버는 송수신부(1120), 프로세서(1110), 및 메모리(1130)를 포함할 수 있다. 본 개시에서 상술한 서버들은 각각 도 11에서 설명하는 서버에 대응될 수 있다. 예를 들면, 앞서 도 1에서 도 9에서 설명하는 서버(예를 들면, 사업자 서버, RSP 서버, SM-DP+, 또는 SM-DS)는 각각 도 11에서 설명하는 서버의 구성을 포함할 수 있다.
다만, 서버의 구성은 도 11에 제한되지 않으며, 도 11에 도시된 구성 요소들보다 더 많은 구성 요소를 포함하거나, 더 적은 구성 요소를 포함할 수도 있다. 일부 실시 예에 따르면, 송수신부(1120), 프로세서(1110), 및 메모리(1130)는 하나의 칩(Chip) 형태로 구현될 수 있다. 또한, 프로세서(1110)는 적어도 하나의 프로세서로서 구성될 수 있다.
일부 실시 예에 따르면, 송수신부(1120)는 단말과 본 개시의 다양한 실시 예에 따른 신호, 정보, 데이터 등을 송신 및 수신할 수 있다. 송수신부(1120)는 송신되는 신호의 주파수를 상승 변환 및 증폭하는 RF 송신기와, 수신되는 신호를 저 잡음 증폭하고 주파수를 하강 변환하는 RF 수신기 등으로 구성될 수 있다. 다만, 이는 송수신부(1120)의 일 실시 예일 뿐이며, 송수신부(1120)의 구성요소가 RF 송신기 및 RF 수신기에 한정되는 것은 아니다. 또한, 송수신부(1120)는 무선 채널을 통해 신호를 수신하여 프로세서(1110)로 출력하고, 프로세서(1110)로부터 출력된 신호를 무선 채널을 통해 전송할 수 있다.
한편, 적어도 하나의 프로세서(1110)는 서버를 전반적으로 제어하기 위한 구성요소이다. 프로세서(1110)는 전술한 바와 같은 본 개시의 다양한 실시 예에 따라, 서버의 전반적인 동작을 제어할 수 있다. 상기 적어도 하나의 프로세서(1110)는 제어부로 명명할 수 있다.
한편, 서버는 메모리(1130)를 더 포함할 수 있으며, 서버의 동작을 위한 기본 프로그램, 응용 프로그램, ES 이동 지원에 대한 설정 정보 등의 데이터를 저장할 수 있다. 또한, 메모리(1130)는 플래시 메모리 타입(Flash Memory Type), 하드 디스크 타입(Hard Disk Type), 멀티미디어 카드 마이크로 타입(Multimedia Card Micro Type), 카드 타입의 메모리(예를 들면, SD 또는 XD 메모리 등), 자기 메모리, 자기 디스크, 광디스크, 램(Random Access Memory, RAM), SRAM(Static Random Access Memory), 롬(Read-Only Memory, ROM), PROM(Programmable Read-Only Memory), EEPROM(Electrically Erasable Programmable Read-Only Memory) 중 적어도 하나의 저장매체를 포함할 수 있다. 또한, 프로세서(1110)는 메모리에 저장된 각종 프로그램, 컨텐츠, 데이터 등을 이용하여 다양한 동작을 수행할 수 있다.
서버는 아래 언급한 동작 중 적어도 하나의 동작을 수행할 수 있다.
서버는 송수신부(1120)를 통해 프로파일 설치를 위한 하나 이상의 메시지를 수신하여 프로세서(1110)에 전달하고, 프로세서(1110)에서 eUICC 서명을 검증할 수 있다. 서버는 사업자에게 검증 결과를 전달해 주는 역할을 수행할 수 있다.
또한, 서버는 단말로부터 상호 인증을 위해 수신된 메시지, 일 예로 AuthenticateClient에 포함된 eUICC 정보로써 수신된 가용 메모리 정보를 참조하고,
설치를 위해 내려줄 프로파일의 예상 메모리 사이즈를 비교하고, 단말 정보(DeviceInfo)와 eUICC의 정보(eUICCInfo2) 중 적어도 하나에서 "ES 지원" 식별자가 있는지를 더 판단하여, 메시지를 다르게 구성하여 송수신부(1120)를 통해 단말에 회신해 줄 수도 있다.
또한, 서버의 프로세서(1110)는 단말 정보(DeviceInfo)와 eUICC의 정보(eUICCInfo2)중 적어도 하나에서 "ES 지원" 식별자를 수신한 경우, 설치 불가 이유가 불충분한 메모리(insufficientMemory)인 경우, 불충분한 메모리가 발생하였음을 메시지에 포함하여 구성하고 이를 송수신부(1120)를 통해 단말에 회신해 줄 수 있다, 또한, 서버의 프로세서(1110)은 해당 프로파일 설치 세션을 종료하지 않고 세션 식별 정보 및 세션 생성을 위한 암호화 키들을 메모리(1130)에 저장하여 둘 수도 있다.
서버의 송수신부(1120)은 단말로부터 프로파일 요청 메시지(GetBoundProfilePakcage)를 수신할 수 있다. 서버가 동일 세션에서 단말 정보(DeviceInfo)와 eUICC의 정보(eUICCInfo2)중 적어도 하나에서 "ES 지원" 식별자를 수신하여 설치 불가 이유를 불충분한 메모리(insufficientMemory)를 단말에 회신해 준 경우, 서버는 설치될 프로파일을 위한 가용 메모리가 확보 되었다고 판단하여 프로파일 패키지 (bound profile package)를 생성하고, 이를 송수신부(1120)를 통해 단말에 회신해 줄 수도 있다.
또한, 서버는 프로파일 서버에서 전송하는 메시지 중 적어도 하나를 서버의 암호화 key로 서명하고 프로파일 서버의 서명이 포함된 메시지로써 송수신부(1120)를 통해 단말에 전송해 주는 동작을 수행할 수도 있다.
본 개시의 일 실시 예에 따른 방법은, 단말에서 eUICC로부터 eUICC의 가용 메모리를 확인하는 단계; 단말에서 획득한 eUICC의 가용 메모리 정보에 기반하여 프로파일의 eUICC 외부 공간으로 이동으로 결정하는 단계를 포함할 수 있다.
또한, 단말에서 eUICC로부터 eUICC의 가용 메모리를 확인하는 단계는 프로파일의 다운로드를 처리하는 과정에서 발생할 수 있고, 단말은 프로파일을 eUICC 외부로 이동 후에 프로파일 다운로드를 재개하여 처리하는 단계를 더 포함하여 수행될 수 있다.
도 12a 및 도 12b는 본 개시의 다른 실시 예에 따른 프로파일 다운로드 설치 시 eUICC 가용 메모리 확인 및 eUICC에서 프로파일을 이동하는 실시 예를 나타내는 도면이다.
일 실시 예에 따르면, 도 12b는 도 12a에 도시된 실시 예에서, AdditionalProfile bit에 따라 프로파일 서버(1220)의 판단이 달라지는 구체적인 실시 예를 나타낸 도면이다.
도 12a 및 도 12b는 일 실시 예에 따라, 전술한 도 3에서 eUICC에 설치된 프로파일(들)을 eUICC 외부로 이동을 판단이 필요한 동작의 예로 단말 사용자(1200)가 신규 프로파일을 단말에 설치하는 과정에서 적용되는 다른 방법을 설명하기 위한 도면이다. 이 예시는 앞서 도 4 내지 도 9에서 단말과 프로파일 서버 간의 상호 인증 과정에 대한 부분에 대체하여 적용할 수 있다.
앞서 도 4 내지 도 9에서 전술한 바와 같이, 프로파일을 설치하기 위한 상호 인증 과정 중에 LPA(1205)는 프로파일 서버(1220)에 단말의 정보(Device Info)와 eUICC(1215)의 정보(eUICCInfo2)를 전송할 수 있다. 예를 들어 클라이언트 검증에 대한 AuthenticateClient의 데이터에 상기 단말의 정보와 eUICC(1215)의 정보가 포함되어 전송될 수 있다. 이때, eUICC의 정보에 적어도 eUICC(1215)의 가용한 메모리 정보가 포함되어 전송될 수 있다. eUICC(1215)의 가용한 메모리를 판단할 수 있는 정보는 extCardResource 데이터에 포함되어 전송될 수 있다. (1225 단계)
상기 정보를 수신한 프로파일 서버(1220)는 적어도 다음 중 하나의 절차를 수행할 수 있다. 상기 프로파일 설치를 위한 eSIM칩의 메모리가 부족하다고 판단할 수 있다. 또한, 추가적으로 eUICC의 정보에 AdditionalProfile 여부에 대한 식별자가 포함되어 전송될 수 있다. (1225 단계)
구체적으로 도 12b에 도시된 바와 같이 이를 수신한 프로파일 서버(1220)는 단계 1227에서, Eligibility Check를 수행할 수도 있다. 그리고 프로파일 서버 (1220)는 상기 프로파일의 추정 프로파일 설치 사이즈가 수신된 가용 메모리 대비 큰 경우에 insufficientMemory, 그리고 추정 프로파일 설치 용량 (estimated Profile size)에 대한 정보를 더 포함된 메시지를 생성해 회신(1230-2 단계)할 수 있다. 이와 같은 실시 예에서는, 해당 프로파일 서버(1220)가 ES 이동을 지원하거나 특정 버전을 지원하는(예를 들어, GSMA SGP.22 V3.2 및 이후) 프로파일 서버인 경우일 수 있다.
일 실시 예에 따르면 도 12b에 도시된 바와 같이, GSMA SGP.22 V3.2를 지원하는 프로파일 서버 (1220)는, EuiccRspCapability에 포함된 additionalProfile bit가 1로 설정되어 있지 않으면, eUICC - Insufficient memory"를 회신(1230-1 단계)하고 EuiccRspCapability bit가 1로 설정되어 있으면, eUICC - Insufficient memory"를 회신하거나 또는 eUICC-Insufficient memmory를 회신하지 않으면서, estimatedProfileSize를 회신할 수도 있다(1230-2 단계). 프로파일 서버 (1220)는 estimatedProfileSize를 회신하는 조건으로, eUICCInfo2 또는/그리고, DeviceInfo 중 적어도 하나의 정보에 ES 지원 여부가 포함되었는지를 추가적인 정보로써 더 판단할 수도 있고, 상기 ES 지원 여부가 포함된 경우에 estimatedProfileSize를 제공할 수도 있다. ES 이동을 지원하지 않거나 또는 해당 기능 이전의 버전 (예를 들어, GSMA SGP.22 V3.2 이전) 프로파일 서버(1220)인 경우에는 프로파일 서버는 수신한 eUICC 정보에 additionalProfile bit가 1로 설정되지 않은 경우 또는 additionalProfile bit 설정 여부를 떠나 프로파일의 추정 설치 사이즈가 가용 메모리 대비 더 큰 경우에 에러와 에러 이유로 insufficientMemory을 리턴하고 절차를 종료할 수 있다.(1230-1 단계) 상기 insufficientMemory을 수신한 LPA(1250)은 SGP.22에 정의된 Cancel Session 절차를 시작하여 해당 RSP 세션 절차를 종료할 수 있다. (1231 단계)
도 4 내지 도 9에서 전술한 바와 같이, estimatedProfileSize를 포함하는 해당 메시지는 AuthenticateClient의 Response로 회신될 수 있다. 그리고 해당 회신되는 데이터는 AuthenticatedClient의 에러 메시지, 또는 성공 응답 메시지 중의 하나에 포함될 수 있으며, estimatedProfileSize는 Profilemetadata에 포함된 하나의 데이터로써 전송될 수도 있다. (1230-2 단계).
프로파일 서버(1220)가 에러 메시지로 회신하는 경우, 프로파일 서버(1220)는 해당 RSP 세션을 종료할 수도 있다.
상기 메시지를 수신한 LPA (1205)는 eUICC 내부의 프로파일을 삭제 또는 이동하는 절에 진입하여 동작을 수행할 수 있으며, 이후 동작은 일 예로 전술한 각 도면에서, AuthenitcateClient Response를 수신한 후 단계를 참고하여 수행(1235 단계)될 수 있으므로, 본 도면에서는 설명을 생략하기로 한다.
한편 본 발명은 프로파일 서버에서 단말로부터 수신된 eUICC 정보와 단말의 정보 중 적어도 하나의 정보를 확인하는 단계; 상기 수신된 정보를 참조하여 eUICC가 준비한 프로파일 설치가 가능한 지를 판단하는 단계; 단말로 추정 프로파일 크기를 회신하여 주는 단계; 프로파일 서버로부터 수신된 추정 프로파일 크기를 기반으로 단말에서 eUICC에 저장된 하나 이상의 프로파일의 삭제 또는 이동을 판단하여 처리하는 것으로 특징으로 할 수 있다.
도 13은 본 개시의 일 실시 예에 따라 프로파일 서버가 단말에 세션 유지에 대한 정보를 추가하여 제공하여 주는 실시 예를 나타내는 도면이다.
프로파일 서버(1320)는 단말에 RSP 세션 유지에 대한 정보를 명시적으로 더 제공하여 줄 수도 있다. 상기 RSP 세션 유지에 대한 정보는 전술한 도면들에서 추가적인 정보로써 함께 제공될 수 있다. 전술한 바와 같이, 단계 1325에서, 프로파일 서버(1320)는 상호 인증 과정 중에 LPA(1305)로부터 수신된 extCardResource의 정보를 참고하여 다운로드해 줄 프로파일의 추정 설치 사이즈를 비교할 수 있다. 그리고 비교 결과 프로파일 서버(1320)는 eUICC(1315)에 프로파일 설치를 위한 가용 메모리가 불충분하다고 판단할 수 있다. 프로파일 서버(1320)는 가용 메모리가 불충분하다고 판단하면 세션을 종료 또는 종료하지 않고 유지할 수 있다. 일 예로, 단계 1330에서, 프로파일 서버(1320)는 세션을 종료하지 않고 일정 시간동안 세션을 유지한 후에 세션을 종료하는 것으로 처리할 수도 있다. 단계 1335에서, 프로파일 서버(1320)는 해당 세션 유지에 대한 정보를 단말에 제공하여 줄 수도 있다.
일 실시 예에 따르면 세션 유지에 대한 정보는, RSP 세션 식별 정보와 RSP 세션 유지 시간 정보 중 적어도 하나를 포함할 수 있다. 해당 RSP 세션 식별 정보는, SGP.22에서 정의한 해당 세션의 transaction ID 일 수도 있고, 가용 eUICC 메모리 부족에 따른 프로파일 설치 지연임을 식별하도록 신규 ID로 정의될 수도 있다. 상기 신규 ID는 일 예로 ES session Id라고 설명할 수 있다. 본 발명의 설명에서는 세션 ID 또는 세션 식별 정보, Es session Id 용어로 사용한다.
프로파일 서버(1320)는 RSP 세션 유지 시간 정보 (앞서 도면에서 waiting time으로 표기), RSP 세션 식별 정보(앞서 도면의 예시에서는 ES session Id로 표기) 중 적어도 하나를 포함하여 단말에 전송하여 줄 수 있다. 상기 회신 메시지의 일 예는 AuthenticateClient의 Response일 수 있다. 상기 회신 메시지는 일 예로, 앞서, 430 단계, 530 단계, 630 단계, 1230 단계 중의 하나에 포함되어 회신 될 수 있다.
상기 회신 메시지를 수신한 단말(의 LPA(1305))는 해당 정보를 저장할 수도 있다. 단계 1340에서, LPA(1305)는 eUICC에서 기존 프로파일(들)을 삭제 또는 ES 이동을 수행할 수 있다. 단계 1345에서, LPA(1305)는 RSP 세션 유지 시간, 세션 식별 정보 중 적어도 하나의 정보를 참고하여, LPA(1305)가 기존 프로파일 다운로드 절차를 이어 진행할 지 또는 프로파일 설치 절차를 처음부터 재 시작할 지를 판단하는 정보로써 사용할 수 있다.
단계 1350에서 LPA(1305)는 메시지를 구성하여 프로파일 서버(1320) 또는 eUICC(1315)에 전송하여 이후 동작을 수행할 수 있다.
일 예로, 단계 1345에서 RSP 세션 유지 시간 내, ES 이동 절차를 완료하는 경우에, LPA(1305)는 프로파일 다운로드를 위한 이후 절차로 진입(일 예로 도 7의 790 단계로 진입)을 결정하여, 단계 1350에서, Authenticate Response 이후 연결되는 프로파일 다운로드 설치를 위한 전송 메시지를 구성하여 프로파일 서버(1320)에 전송할 수 있다. 또는, 단계 1345에서 LPA(1305)는 상기 수신된 세션 유지 시간을 초과했다고 판단하는 경우, 단계 1350에서, 프로파일 다운로드를 처음부터 시작하는 절차로 진입(일 예로 도 8의 870 단계로 진입)하여 프로파일 서버와의 상호 인증 절차를 재 시작하는 절차를 수행할 수 있다. 단계 1355에서, 프로파일 서버(1320)는 단말 요청 메시지의 처리 여부를 결정할 수 있다. 상기 처리 여부에 대한 결정은 세션 정보가 만료되었는지를 포함하여 수행될 수 있다.
예를 들어, 수신되는 메시지에 프로파일 서버가 단말에 전달한 RSP 세션 식별 정보가 있고 세션 유지 시간 내 접속이거나, 수신되는 메시지에 프로파일 서버가 단말에 전달한 RSP 세션 식별 정보가 없으나, 세션 유지 시간 내 접속인 경우 프로파일 서버(1320)는 요청한 동작을 수행할 수 있다. 상기 동작은 일 예로, 프로파일 서버(1320)가 BPP를 생성하여 다운로드 해주는 절차로 진입하는 동작일 수 있다. 프로파일 서버(1320)는, 수신된 세션 식별 정보를 찾을 수 없거나 또는 만료된 경우, 에러를 리턴하고 절차를 종료한다고 판단할 수 있다.
단계 1360에서, 프로파일 서버(1320)는 1355 단계의 판단의 결과로 회신 메시지를 구성하여 LPA(1305)에 전송하여 줄 수 있다. 상기 회신 메시지는 일 예로, 성공 응답 그리고/또는 BPP 일 수 있고, 또는 Error 그리고/또는 세션 만료에 대한 에러 사유를 포함할 수도 있다.
상기 회신 메시지를 수신한 LPA(1305)는 이후 동작을 수행할 수 있다. 일 예로, 에러 메시지를 수신한 LPA(1305)는 해당 절차를 종료할 수 있다. 또는, 성공 응답 메시지를 수신한 LPA(1305)는 이후 SGP.22에 정의된 프로파일 설치 절차를 이어서 진행하여 프로파일 설치를 완료할 수 있다.
상술한 본 개시의 구체적인 실시 예들에서, 개시에 포함되는 구성 요소는 제시된 구체적인 실시 예에 따라 단수 또는 복수로 표현되었다. 그러나, 단수 또는 복수의 표현은 설명의 편의를 위해 제시한 상황에 적합하게 선택된 것으로서, 본 개시가 단수 또는 복수의 구성 요소에 제한되는 것은 아니며, 복수로 표현된 구성 요소라 하더라도 단수로 구성되거나, 단수로 표현된 구성 요소라 하더라도 복수로 구성될 수 있다.
한편 본 개시의 상세한 설명에서는 구체적인 실시 예에 관해 설명하였으나, 본 개시의 범위에서 벗어나지 않는 한도 내에서 여러 가지 변형이 가능함은 물론이다. 그러므로 본 개시의 범위는 설명된 실시 예에 국한되어 정해져서는 아니 되며 후술하는 특허청구의 범위뿐만 아니라 이 특허청구의 범위와 균등한 것들에 의해 정해져야 한다.
본 개시의 다양한 실시 예들 및 이에 사용된 용어들은 본 개시에 기재된 기술을 특정한 실시 형태에 대해 한정하려는 것이 아니며, 해당 실시예의 다양한 변경, 균등물, 및/또는 대체물을 포함하는 것으로 이해되어야 한다. 도면의 설명과 관련하여, 유사한 구성요소에 대해서는 유사한 참조 부호가 사용될 수 있다. 단수의 표현은 문맥상 명백하게 다르게 뜻하지 않는 한, 복수의 표현을 포함할 수 있다. 본 개시에서, "A 또는 B", "A 및/또는 B 중 적어도 하나", "A, B 또는 C" 또는 "A, B 및/또는 C 중 적어도 하나" 등의 표현은 함께 나열된 항목들의 모든 가능한 조합을 포함할 수 있다. "제 1", "제 2", "첫째" 또는 "둘째" 등의 표현들은 해당 구성요소들을, 순서 또는 중요도에 상관없이 수식할 수 있고, 한 구성요소를 다른 구성요소와 구분하기 위해 사용될 뿐 해당 구성요소들을 한정하지 않는다. 어떤(예: 제 1) 구성요소가 다른(예: 제 2) 구성요소에 "(기능적으로 또는 통신적으로) 연결되어" 있다거나 "접속되어" 있다고 언급된 때에는, 상기 어떤 구성요소가 상기 다른 구성요소에 직접적으로 연결되거나, 다른 구성요소(예: 제3 구성요소)를 통하여 연결될 수 있다.
본 개시에서 사용된 용어 "모듈"은 하드웨어, 소프트웨어 또는 펌웨어로 구성된 유닛을 포함하며, 예를 들면, 로직, 논리 블록, 부품, 또는 회로 등의 용어와 상호 호환적으로 사용될 수 있다. 모듈은, 일체로 구성된 부품 또는 하나 또는 그 이상의 기능을 수행하는 최소 단위 또는 그 일부가 될 수 있다. 예를 들면, 모듈은 ASIC(application-specific integrated circuit)으로 구성될 수 있다.
본 개시의 다양한 실시 예들은 기기(machine)(예: 컴퓨터)로 읽을 수 있는 저장 매체(machine-readable storage media)(예: 내장 메모리 또는 외장 메모리)에 저장된 명령어를 포함하는 소프트웨어(예: 프로그램)로 구현될 수 있다. 기기는, 저장 매체로부터 저장된 명령어를 호출하고, 호출된 명령어에 따라 동작이 가능한 장치로서, 다양한 실시 예들에 따른 단말을 포함할 수 있다. 상기 명령이 프로세서에 의해 실행될 경우, 프로세서가 직접, 또는 상기 프로세서의 제어 하에 다른 구성요소들을 이용하여 상기 명령에 해당하는 기능을 수행할 수 있다. 명령은 컴파일러 또는 인터프리터에 의해 생성 또는 실행되는 코드를 포함할 수 있다.
기기로 읽을 수 있는 저장매체는, 비일시적(non-transitory) 저장매체의 형태로 제공될 수 있다. 여기서, '비일시적'은 저장매체가 신호(signal)를 포함하지 않으며 실재(tangible)한다는 것을 의미할 뿐 데이터가 저장매체에 반영구적 또는 임시적으로 저장됨을 구분하지 않는다.
본 개시에 개시된 다양한 실시 예들에 따른 방법은 컴퓨터 프로그램 제품(computer program product)에 포함되어 제공될 수 있다. 컴퓨터 프로그램 제품은 상품으로서 판매자 및 구매자 간에 거래될 수 있다. 컴퓨터 프로그램 제품은 기기로 읽을 수 있는 저장 매체(예: compact disc read only memory (CD-ROM))의 형태로, 또는 어플리케이션 스토어(예: 플레이 스토어TM)를 통해 온라인으로 배포될 수 있다. 온라인 배포의 경우에, 컴퓨터 프로그램 제품의 적어도 일부는 제조사의 서버, 어플리케이션 스토어의 서버, 또는 중계 서버의 메모리와 같은 저장 매체에 적어도 일시 저장되거나, 임시적으로 생성될 수 있다. 다양한 실시 예들에 따른 구성 요소(예: 모듈 또는 프로그램) 각각은 단수 또는 복수의 개체로 구성될 수 있으며, 전술한 해당 서브 구성 요소들 중 일부 서브 구성 요소가 생략되거나, 또는 다른 서브 구성 요소가 다양한 실시 예에 더 포함될 수 있다. 대체적으로 또는 추가적으로, 일부 구성 요소들(예: 모듈 또는 프로그램)은 하나의 개체로 통합되어, 통합되기 이전의 각각의 해당 구성 요소에 의해 수행되는 기능을 동일 또는 유사하게 수행할 수 있다. 다양한 실시 예들에 따른, 모듈, 프로그램 또는 다른 구성 요소에 의해 수행되는 동작들은 순차적, 병렬적, 반복적 또는 휴리스틱하게 실행되거나, 적어도 일부 동작이 다른 순서로 실행되거나, 생략되거나, 또는 다른 동작이 추가될 수 있다.

Claims (14)

  1. 무선 통신 시스템에서 단말에 의해 수행되는 방법에 있어서,
    프로파일 설치를 위해 프로파일 서버로 additionalprofile 정보를 포함하는 제1 메시지를 전송하는 단계;
    상기 additionalprofile 정보가 기설정된 값으로 설정된 경우, 상기 프로파일 서버로부터 상기 예측된 프로파일 사이즈에 대한 정보를 포함하는 제2 메시지를 수신하는 단계;
    상기 예측된 프로파일 사이즈에 대한 정보를 포함하는 제 2 메시지의 수신에 기반하여, embedded universal integrated circuit card (eUICC) 메모리를 확보하도록 제어하는 단계; 및
    상기 eUICC 메모리 확보에 기반하여 상기 프로파일 설치를 수행하는 단계; 를 포함하는 방법.
  2. 제1항에 있어서,
    상기 eUICC 메모리 확보는,
    상기 프로파일의 이동 또는 상기 프로파일의 삭제에서 적어도 하나를 포함하는 것을 특징으로 하는 방법.
  3. 제1항에 있어서,
    상기 eUICC 메모리 확보를 위해, 상기 프로파일 서버와의 세션을 유지하거나 종료하도록 결정하는 단계; 를 더 포함하는 것을 특징으로 하는 방법.
  4. 제1항에 있어서,
    상기 제1 메시지는,
    상기 eUICC와 연관된 메모리 정보를 더 포함하는 것을 특징으로 하는 방법.
  5. 무선 통신 시스템에서 프로파일 서버에 의해 수행되는 방법에 있어서,
    프로파일 설치를 위해 단말로부터 additionalprofile 정보를 포함하는 제1 메시지를 수신하는 단계;
    상기 additionalprofile 정보가 기설정된 값으로 설정되었는지 여부를 확인하는 단계; 및 상기 additionalprofile 정보가 기설정된 값으로 설정된 경우, 예측된 프로파일 사이즈에 대한 정보를 포함하는 제2 메시지를 전송하는 단계; 를 포함하는 방법.
  6. 제5항에 있어서,
    상기 제1 메시지는 상기 eUICC와 연관된 메모리 정보를 더 포함하고,
    상기 additionalprofile 정보가 기설정된 값으로 설정된 경우, 상기 eUICC와 연관된 메모리 정보 및 상기 예측된 프로파일 사이즈를 비교하여, 상기 비교 결과에 따라 상기 예측된 프로파일 사이즈에 대한 정보가 상기 제2 메시지에 포함되는 것을 특징으로 하는 방법.
  7. 제5항에 있어서,
    상기 예측된 프로파일 사이즈에 대한 정보를 포함하는 메타 데이터를 생성하는 단계; 를 더 포함하고,
    상기 메타 데이터를 포함하는 상기 제2 메시지가 전송되는 것을 특징으로 하는 방법.
  8. 무선 통신 시스템에서 단말에 있어서,
    송수신부; 및
    프로파일 설치를 위해 프로파일 서버로 additionalprofile 정보를 포함하는 제1 메시지를 상기 송수신부를 통해 전송하고,
    상기 additionalprofile 정보가 기설정된 값으로 설정된 경우, 상기 프로파일 서버로부터 상기 예측된 프로파일 사이즈에 대한 정보를 포함하는 제2 메시지를 상기 송수신부를 통해 수신하며,
    상기 예측된 프로파일 사이즈에 대한 정보를 포함하는 제 2 메시지의 수신에 기반하여, embedded universal integrated circuit card (eUICC) 메모리를 확보하도록 제어하고,
    상기 eUICC 메모리 확보에 기반하여 상기 프로파일 설치를 수행하도록 제어하는 제어부; 를 포함하는 단말.
  9. 제8항에 있어서,
    상기 eUICC 메모리 확보는,
    상기 프로파일의 이동 또는 상기 프로파일의 삭제에서 적어도 하나를 포함하는 것을 특징으로 하는 단말.
  10. 제8항에 있어서,
    상기 제어부는,
    상기 eUICC 메모리 확보를 위해, 상기 프로파일 서버와의 세션을 유지하거나 종료하도록 결정하도록 제어하는 것을 특징으로 하는 단말.
  11. 제8항에 있어서,
    상기 제1 메시지는,
    상기 eUICC와 연관된 메모리 정보를 더 포함하는 것을 특징으로 하는 단말.
  12. 무선 통신 시스템에서 프로파일 서버에 있어서,
    송수신부; 및
    프로파일 설치를 위해 단말로부터 additionalprofile 정보를 포함하는 제1 메시지를 상기 송수신부를 통해 수신하고,
    상기 additionalprofile 정보가 기설정된 값으로 설정되었는지 여부를 확인하는 단계; 및 상기 additionalprofile 정보가 기설정된 값으로 설정된 경우, 예측된 프로파일 사이즈에 대한 정보를 포함하는 제2 메시지를 전송하도록 제어하는 제어부; 를 포함하는 프로파일 서버.
  13. 제12항에 있어서,
    상기 제1 메시지는 상기 eUICC와 연관된 메모리 정보를 더 포함하고,
    상기 additionalprofile 정보가 기설정된 값으로 설정된 경우, 상기 eUICC와 연관된 메모리 정보 및 상기 예측된 프로파일 사이즈를 비교하여, 상기 비교 결과에 따라 상기 예측된 프로파일 사이즈에 대한 정보가 상기 제2 메시지에 포함되는 것을 특징으로 하는 프로파일 서버.
  14. 제12항에 있어서,
    상기 제어부는,
    상기 예측된 프로파일 사이즈에 대한 정보를 포함하는 메타 데이터를 생성하도록 제어하고,
    상기 메타 데이터를 포함하는 상기 제2 메시지가 전송되는 것을 특징으로 하는 프로파일 서버.
PCT/KR2025/009001 2024-06-26 2025-06-26 Embedded universal integrated circuit card (euicc) 외부로 프로파일을 이동 및 저장하기 위한 방법 및 장치 Pending WO2026005508A1 (ko)

Applications Claiming Priority (6)

Application Number Priority Date Filing Date Title
KR20240083838 2024-06-26
KR10-2024-0083838 2024-06-26
KR1020250033994A KR20260001068A (ko) 2024-06-26 2025-03-17 embedded universal integrated circuit card (eUICC) 외부로 프로파일을 이동 및 저장하기 위한 방법 및 장치
KR10-2025-0033994 2025-03-17
KR10-2025-0056560 2025-04-29
KR1020250056560A KR20260001076A (ko) 2024-06-26 2025-04-29 embedded universal integrated circuit card (eUICC) 외부로 프로파일을 이동 및 저장하기 위한 방법 및 장치

Publications (1)

Publication Number Publication Date
WO2026005508A1 true WO2026005508A1 (ko) 2026-01-02

Family

ID=98222517

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2025/009001 Pending WO2026005508A1 (ko) 2024-06-26 2025-06-26 Embedded universal integrated circuit card (euicc) 외부로 프로파일을 이동 및 저장하기 위한 방법 및 장치

Country Status (1)

Country Link
WO (1) WO2026005508A1 (ko)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20200280839A1 (en) * 2017-10-27 2020-09-03 Telefonaktiebolaget Lm Ericsson (Publ) Customized pin/puk remote provisioning
US20200351656A1 (en) * 2018-01-15 2020-11-05 Telefonaktiebolaget Lm Ericsson (Publ) Profile handling of a communications device
EP3890378A1 (en) * 2019-02-19 2021-10-06 Samsung Electronics Co., Ltd. Device changing method and apparatus of wireless communication system
EP4301021A1 (en) * 2022-06-30 2024-01-03 Thales Dis France Sas A method for informing a mobile network operator server which profile of a profile type should be downloaded from a sm-dp+ to a secure element

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20200280839A1 (en) * 2017-10-27 2020-09-03 Telefonaktiebolaget Lm Ericsson (Publ) Customized pin/puk remote provisioning
US20200351656A1 (en) * 2018-01-15 2020-11-05 Telefonaktiebolaget Lm Ericsson (Publ) Profile handling of a communications device
EP3890378A1 (en) * 2019-02-19 2021-10-06 Samsung Electronics Co., Ltd. Device changing method and apparatus of wireless communication system
EP4301021A1 (en) * 2022-06-30 2024-01-03 Thales Dis France Sas A method for informing a mobile network operator server which profile of a profile type should be downloaded from a sm-dp+ to a secure element

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
GSMA: "SGP.22 GSMA RSP Technical Specification Version 3.1 - part 1/2", 1 December 2023 (2023-12-01), pages 1 - 501, XP093275465, Retrieved from the Internet <URL:https://www.gsma.com/solutions-and-impact/technologies/esim/wp-content/uploads/2023/12/SGP.22-v3.1.pdf> *

Similar Documents

Publication Publication Date Title
WO2020091310A1 (en) Method and apparatus for managing bundles of smart secure platform
WO2022031148A1 (en) Method and apparatus for installing and managing multiple esim profiles
WO2018101775A1 (en) Apparatus and method for installing and managing esim profiles
WO2021172873A1 (en) Method and device for remote management and verification of remote management authority
WO2022108357A1 (en) Method and apparatus for handling profiles by considering removable euicc supporting multiple enabled profiles
WO2016080726A1 (en) Apparatus and method for profile installation in communication system
WO2020226466A1 (en) Method and apparatus for managing and verifying certificate
WO2016153281A1 (ko) 무선 통신 시스템에서 프로파일을 다운로드 하는 방법 및 장치
WO2021066569A1 (en) Method and apparatus for reinstalling sim profile in wireless communication system
WO2018147711A1 (en) APPARATUS AND METHOD FOR ACCESS CONTROL ON eSIM
WO2017052136A1 (ko) 이동 통신 시스템에서 프로파일 다운로드 방법 및 장치
WO2022177310A1 (en) Method and apparatus for transmitting and processing profile management message for multiple enabled profiles between terminal and universal integrated circuit card
WO2023158243A1 (en) Method and apparatus for transferring and storing activation code for esim device change
WO2019194639A1 (en) Method and apparatus for negotiating euicc version
WO2024072114A1 (ko) 무선 통신 시스템에서 프로파일 프로비저닝을 위한 euicc의 암호화 키 관리 방법 및 장치
EP3530016A1 (en) Apparatus and method for installing and managing esim profiles
WO2022240144A1 (en) Method and apparatus for identifying profile deletion when euicc terminal is changed
WO2022045869A1 (en) Apparatus and method for managing events in communication system
WO2024225739A1 (ko) 무선 통신 시스템에서 프로파일 프로비저닝을 위한 임시 암호화 키 관리 방법 및 장치
WO2020171475A1 (ko) 무선 통신 시스템의 기기변경 방법 및 장치
WO2020032589A1 (en) Method, apparatus, and system for authorizing remote profile management
WO2024205259A1 (en) Method and apparatus for handling profile loading result in wireless communication system
WO2026005508A1 (ko) Embedded universal integrated circuit card (euicc) 외부로 프로파일을 이동 및 저장하기 위한 방법 및 장치
WO2022220616A1 (en) Method and apparatus for managing events in a wireless communication system
WO2022092976A1 (en) Method and device for managing communication bundle of smart secure platform

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 25827078

Country of ref document: EP

Kind code of ref document: A1