WO2014073836A1 - 가입자 인증 장치를 내장한 단말 장치 및 이를 위한 프로파일 선택 방법 - Google Patents
가입자 인증 장치를 내장한 단말 장치 및 이를 위한 프로파일 선택 방법 Download PDFInfo
- Publication number
- WO2014073836A1 WO2014073836A1 PCT/KR2013/009954 KR2013009954W WO2014073836A1 WO 2014073836 A1 WO2014073836 A1 WO 2014073836A1 KR 2013009954 W KR2013009954 W KR 2013009954W WO 2014073836 A1 WO2014073836 A1 WO 2014073836A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- profile
- application
- information
- communication network
- provisioning
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims abstract description 50
- 238000010295 mobile communication Methods 0.000 claims abstract description 60
- 238000004891 communication Methods 0.000 claims abstract description 56
- 238000003860 storage Methods 0.000 claims abstract description 24
- 238000010586 diagram Methods 0.000 description 12
- 230000008859 change Effects 0.000 description 5
- 230000007774 longterm Effects 0.000 description 3
- 238000004519 manufacturing process Methods 0.000 description 3
- 238000010187 selection method Methods 0.000 description 3
- 230000004913 activation Effects 0.000 description 2
- 239000000969 carrier Substances 0.000 description 2
- 230000009849 deactivation Effects 0.000 description 2
- 230000014509 gene expression Effects 0.000 description 2
- 230000001413 cellular effect Effects 0.000 description 1
- 238000004590 computer program Methods 0.000 description 1
- 238000009826 distribution Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 238000009434 installation Methods 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 230000008569 process Effects 0.000 description 1
- 230000035939 shock Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
- H04W8/183—Processing at user equipment or user record carrier
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W88/00—Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
- H04W88/02—Terminal devices
Definitions
- the present invention relates to a technique for selecting a profile stored in an embedded general-purpose IC card, and more particularly, to a configuration of attribute information of a profile and a procedure of selecting a specific profile in the terminal device using the same.
- a UICC Universal Integrated Circuit Card
- UICC includes network information (International Mobile Subscriber Identity, Home Public Land Mobile Network, etc.), user information (Short Message Service, etc.) and telephone book (Phonebook), etc. can be stored.
- UICC is also known as a Subscriber Identity Module (SIM) card for Global System for Mobile communications (GSM), Wideband Code Division Multiple Access (WCDMA), and Universal Subscriber Identity Module (USIM) for Long Term Evolution (LTE). do.
- SIM Subscriber Identity Module
- GSM Global System for Mobile communications
- WCDMA Wideband Code Division Multiple Access
- USIM Universal Subscriber Identity Module
- NAAs Network access applications
- the user mounts the UICC on the user's terminal
- user authentication is made with the mobile communication network automatically subscribed using the information stored in the UICC, and the user can conveniently receive the mobile communication service through the terminal.
- the user can easily replace the terminal by removing the UICC from the existing terminal and mounted on a new terminal.
- the user wants to change the mobile communication provider it is possible to simply change the mobile communication provider by replacing the UICC removed from the existing terminal with the UICC of the operator to change.
- the UICC of the desired MNO can easily change the MNO to use the terminal. That is, in the conventional UICC environment, the SIM profile prepared in advance according to the requirements of the MNO is embedded in a separate card and distributed in a separate form from the terminal.
- a user purchases a terminal and a UICC to subscribe to a service of a specific MNO, inserts a UICC into the terminal, and uses the device after opening according to an opening procedure determined by an operator.
- eUICC provides network access authentication function similar to existing detachable UICC, but due to its physical structure, eUICC should be able to handle network access of multiple operators with one UICC, and there are many issues such as eUICC opening / distribution / subscriber information security. And it is necessary to prepare a plan for this.
- international standardization bodies such as GSMA and ETSI are conducting standardization activities on relevant elements such as carriers, manufacturers and SIM vendors, as well as necessary elements including top-level structures.
- the Working Group is working to establish the eUICC standard.
- WG Working Group
- a module called profile is defined to post-personalize applications for network access authentication function of various operators to eUICC and remotely Has established requirements for installation and management.
- management policy and application of the profile are discussed, but the specific method is not defined yet.
- the international standard only mentions the definition of a profile, but information for selecting a specific profile in the eUICC, for example, profile type (provisioning profile, production profile), profile provider (or operator), profile status (activation or deactivation) information. And how to obtain a corresponding profile, i.e., information for selecting a specific profile, and how to select a particular profile is not discussed. Therefore, how to configure the profile attribute information such as the type of profile (provisioning profile, operation profile), profile provider (operator), profile state (activation or deactivation) information stored in the eUICC, and the mobile communication terminal may configure the profile attribute. It is necessary to define how to implement the definition of how a specific profile can be selected using the information.
- An object of the present invention for solving the above problems is to propose a configuration of the attribute information for the profile stored in the eUICC, and to propose a procedure for selecting a specific profile of the terminal including the eUICC.
- profiles for mobile network authentication and access provided by many mobile carriers are stored in a terminal device, and a profile is selected and authenticated and accessed according to need to receive services provided by a mobile communication network provider.
- the purpose is to make it possible.
- the present invention proposes a subscriber authentication device and a terminal device having the same.
- a mobile communication terminal device for achieving the above object, the subscriber authentication module having at least one profile and the provisioning profile (provisioning profile) of the at least one profile for the communication network
- a network authentication unit that performs an authentication procedure and receives authentication completion information from a service provider server of a communication network, and accesses a communication network based on the authentication completion information, and an operation profile corresponding to a service provider of the communication network among at least one profile profile) may be configured to include a network connection that receives a service from an operator server.
- the mobile communication terminal device may further include a profile selector for selecting a provisioning profile and an operation profile based on an elementary file including attribute information for at least one profile.
- the attribute information may include an application identifier for identifying at least one profile.
- the application identifier is composed of an application registration authority identifier (RID) and an application identification extension (PIX, Proprietary application Identifier eXtension),
- the application identification extension is an application code (application code), country code It may include at least one or more information of a (country code), an application provider code (application provider code) and an application provider field option (application provider field option).
- the application code may include classification information for distinguishing at least one type of profile.
- the at least one type of profile may include a provisioning profile type, an operation profile type, and an operation profile type containing data of the provisioning profile.
- Subscriber authentication device for achieving the above object, in the subscriber authentication device embedded in the mobile communication terminal device to connect to the communication network using at least one profile, authentication information for the communication network
- a first storage to store at least one provisioning profile with a second storage to store at least one operational profile with service connection information to receive a service of a communication network, and to select at least one profile
- It may be configured to include an element file storage for storing an elementary file (elementary file) having attribute information for at least one profile.
- the subscriber authentication device may further comprise a third storage unit for storing at least one user profile having user information of the mobile communication terminal device.
- the subscriber authentication device may select a provisioning profile and an operation profile based on an elementary file including attribute information about at least one profile.
- the attribute information may include application identifier information, application label information, and application state information for any of at least one profile.
- the application identifier information includes an application identifier (AID) capable of identifying any profile, and the application identifier includes an application registration identifier (RID) and an application identification extension (PIX). , Proprietary application Identifier eXtension).
- the application identification extension may include at least one or more information of an application code, a country code, an application provider code, and an application provider field option. Can be.
- the application code may include classification information for distinguishing at least one type of profile.
- the at least one type of profile may include a provisioning profile type, an operation profile type, and an operation profile type containing data of the provisioning profile.
- a method for accessing a network of a mobile communication terminal device the method for accessing a communication network using at least one profile provided in a subscriber authentication module.
- step of receiving the authentication completion information further comprising the step of selecting a provisioning profile and the operation profile based on an elementary file (elementary file) containing attribute information for at least one profile to be configured Can be.
- the attribute information may include an application identifier for identifying at least one profile.
- the application identifier is composed of a registered application provider identifier (RID) and an application identification extension (PIX, Proprietary application Identifier eXtension), the application identification extension is an application code (application code), country code ( It may include at least one or more information of a country code, an application provider code and an application provider field option.
- RID registered application provider identifier
- PIX Proprietary application Identifier eXtension
- the application identification extension is an application code (application code), country code ( It may include at least one or more information of a country code, an application provider code and an application provider field option.
- the application code may include classification information for distinguishing at least one type of profile.
- the at least one type of profile may include a provisioning profile type, an operation profile type, and an operation profile type containing data of the provisioning profile.
- the terminal device can obtain attribute information on the profile stored in the eUICC, and select a specific profile using the same.
- the selected profile may be used to access a mobile communication network and provide related services.
- a user of a terminal device can change a provider network so as to easily access a network of various mobile communication operators, and can receive various related services.
- FIG. 1 is a conceptual diagram illustrating an environment of a mobile communication terminal device and a mobile service provider server according to an embodiment of the present invention.
- FIG. 2 is a conceptual diagram illustrating a mobile communication terminal device and its components according to an embodiment of the present invention.
- FIG. 3 is a block diagram illustrating a subscriber authentication module embedded in a mobile communication terminal device and its stored information according to another embodiment of the present invention.
- FIG. 4 is a conceptual diagram illustrating an application TLV (Tag, Length, Value) object among attribute information of a profile according to an embodiment of the present invention.
- TLV Tag, Length, Value
- FIG. 5 is a block diagram illustrating an application identifier and its configuration information according to an embodiment of the present invention.
- FIG. 6 is an exemplary view for showing an example of a value of an application identifier for each profile according to an embodiment of the present invention.
- FIG. 7 is a block diagram illustrating a subscriber authentication device and its components according to an embodiment of the present invention.
- FIG. 8 is a flowchart illustrating a profile selection method of a terminal device incorporating a subscriber authentication device according to an embodiment of the present invention.
- first, second, A, and B may be used to describe various components, but the components should not be limited by the terms. The terms are used only for the purpose of distinguishing one component from another.
- the first component may be referred to as the second component, and similarly, the second component may also be referred to as the first component.
- the term "operator” refers to a mobile network operator (MNO).
- Subscriber authentication module or subscriber authentication device is an eUICC (embedded UICC) or eSIM (embedded SIM), which is distinguished from the existing removable UICC, is used in the sense of embedded SIM (Subscriber Identity Module) that is integrally mounted when manufacturing the terminal. .
- eUICC embedded UICC
- SIM Subscriber Identity Module
- eUICC embedded UICC
- eSIM embedded SIM
- SIM subscriber identification module
- a SIM profile means a specific set (set) of information parameter values possessed by the SIM.
- a profile refers to such a SIM profile.
- Profiles are defined as profiles that can be stored in the built-in UICC, namely, MF (Master File), DF (Dedicated File), ADF (Application Dedicated File), EF (Elementary File), and Credential. do.
- a terminal is a mobile station (MS), a user equipment (UE), a user terminal (UT), a wireless terminal, an access terminal (AT), a terminal, a subscriber.
- a subscriber unit (SU), subscriber station (SS), wireless device, wireless communication device, wireless transmit / receive unit (WTRU), mobile node, mobile device or other terms May be referred to.
- Various embodiments of the terminal include a cellular telephone, a smartphone having a wireless communication function, a personal digital assistant (PDA) having a wireless communication function, a wireless modem, a portable computer having a wireless communication function, a digital having a wireless communication function.
- Portable units or terminals incorporating combinations of such functions, as well as photographing devices such as cameras, gaming devices with wireless communication capabilities, music storage and playback appliances with wireless communication capabilities, internet appliances with wireless internet access and browsing Can include them.
- the terminal may include a machine to machine (M2M) terminal, a machine type communication (MTC) terminal / device, but is not limited thereto.
- M2M machine to machine
- MTC machine type communication
- each block or step described herein may represent a portion of a module, segment, or code that includes one or more executable instructions for executing a particular logical function (s).
- a particular logical function s.
- the functions noted in the blocks or steps may occur out of order. For example, it is also possible that two blocks or steps shown in succession are performed simultaneously, or that the blocks or steps are sometimes performed in the reverse order, depending on the function in question.
- FIG. 1 is a conceptual diagram illustrating an environment of a mobile communication terminal device 200 and a mobile communication service provider server 100 according to an embodiment of the present invention.
- a wireless communication network including a mobile communication network referred to as 3rd Generation (3G), Long Term Evolution (LTE), Long Term Evolution Advanced (LTE-A), etc. is operated by mobile communication operators.
- 3G 3rd Generation
- LTE Long Term Evolution
- LTE-A Long Term Evolution Advanced
- Each operator has a wireless communication network that can provide their services, and users may be provided with a service by accessing each operator's wireless communication network through the mobile communication terminal device 200.
- Users may access a wireless communication network of a service provider to receive a service through the terminal device 200 provided by the service provider or by inserting a UICC provided by the service provider into the terminal device 200.
- a wireless communication network of a service provider may be used to receive a service through the terminal device 200 provided by the service provider or by inserting a UICC provided by the service provider into the terminal device 200.
- the method of using the eUICC already embedded in the terminal device 200 is also available among the methods for accessing the wireless communication network through the UICC provided by the operator.
- FIG. 2 is a conceptual diagram illustrating a mobile communication terminal device 200 and its components according to an embodiment of the present invention
- FIG. 3 is embedded in the mobile communication terminal device 200 according to another embodiment of the present invention. It is a block diagram for explaining the subscriber authentication module 500 and its stored information.
- the mobile communication terminal 200 includes a subscriber authentication module 500 having at least one profile 511, 521, 522, and 531, and at least one profile 511.
- Network authentication unit 210 for performing the authentication process for the communication network based on the provisioning profile (511) of the 521, 522, 531 and receiving authentication completion information from the operator server 100 of the communication network and
- the operator server is connected to the communication network based on the authentication completion information, and is based on an operational profile 521 or 522 corresponding to the operator of the communication network among at least one profile 511, 521, 522, or 531. It may be configured to include a network connection unit 220 receives a service from (100).
- the mobile communication terminal device 200 may perform user authentication and access to the mobile communication network by using the profiles 511, 521, 522, and 531 of the eUICC 500, and the eUICC 500 may include user information (Short). It can also be used as a storage space for Message Service, Multimedia Message Service, and Phonebook.
- the profile may be classified into a provisioning profile 511, a operational profile 521 and 522, an user profile 531, and the like.
- the provisioning profile 511 refers to a file that provides information necessary for authentication of the mobile communication network in order to support MNO opening when the eUICC 500 is not opened with the mobile communication network provider.
- the accessing mobile communication network may be a network of any MNO which is not specified, or may be a network of a predetermined MNO.
- the eUICC 500 can include one or multiple provisioning profiles 511. Alternatively, there may be an eUICC 500 that does not include a provisioning profile 511.
- the terminal device 200 may perform an authentication procedure of a specific mobile communication network operator and receive a service opening by using the authentication information stored in the provisioning profile 511, and receive authentication completion information thereof.
- the operation profiles 521 and 522 refer to a file that provides MNO network access information for accessing the opened MNO network and receiving services after the eUICC 500 is opened with the MNO.
- the eUICC 500 may include one or multiple operational profiles 521, 522. If the provisioning profile 511 does not exist in the eUICC, the operational profiles 521, 522 serve as the provisioning profile 511. You can also do
- the terminal device 200 may access a specific mobile communication network operator and receive a service of the operator using the access information stored in the operation profiles 521 and 522.
- a plurality of provisioning profiles 511, operation profiles 521 and 522, and a user profile 531 may exist, and the terminal may select a specific profile among them according to the purpose.
- the mobile communication terminal device 200 may provide a provisioning profile 511 and an operation profile based on an elementary file 541 including attribute information about at least one profile 511, 521, 522, or 531. It may be configured to further include a profile selection unit 230 for selecting (521, 522).
- the profile selector 230 may select a profile by referring to attribute information of the profile in the element file 541 stored in the subscriber authentication module 500.
- the element file 541 may include various other information defining the profile, including an application identifier 542 corresponding to the profile.
- Various other information may be defined by tags, lengths, values, etc. so as to be divided into object units to determine a standard for mobile communication.
- FIG. 4 is a conceptual diagram illustrating an application tag, length, and value TLV object among attribute information of a profile according to an embodiment of the present invention
- FIG. 5 is a block illustrating an application identifier 542 and its configuration information. It is also. 6 is an exemplary diagram for showing an example of the value of the application identifier 542 for each profile.
- the attribute information may include an application identifier 542 that may identify at least one profile 511, 521, 522, 531, and may include an application identifier ( 542 may include a Registered Application Provider Identifier (RID) 543 and a Proprietary Application Identifier eXtension (PIX) 544.
- an application identifier 542 may identify at least one profile 511, 521, 522, 531, and may include an application identifier ( 542 may include a Registered Application Provider Identifier (RID) 543 and a Proprietary Application Identifier eXtension (PIX) 544.
- RID Registered Application Provider Identifier
- PIX Proprietary Application Identifier eXtension
- the application identification extension 544 may include at least one or more information of an application code, a country code, an application provider code, and an application provider field option. Can be.
- the provisioning profile 511 and the operation profiles 521 and 522 stored in the eUICC 500 may be configured in the form of one or a plurality of application dedicated files (ADFs) as shown in FIG. 3. have.
- the ADF may store information that can be matched with an application identifier (AID) 542 among the attribute information stored in the element file 541 and the content of the profile.
- AID application identifier
- reference numeral 511 denotes a provisioning profile including one ADFUSIM for WCDMA or LTE network connection
- reference numeral 521 denotes MNO # 1 configured with ADFUSIM for WCDMA or LTE network access and ADFISIM for IMS (IP Multimedia Subsystem) network access
- the operation profile of 522 may represent an operation profile of MNO # 2 configured with one ADFUSIM for WCDMA or LTE network connection.
- 3 is only one embodiment and the number of profiles and the type of network are only one of many possible configurations.
- the initial eUICC 500 may include an ADF for the provisioning profile 511 or an ADF for the operation profiles 521 and 522 serving as the provisioning profile 511. And accessing the mobile communication network through the provisioning profile 511 or the provisioning profile 511 included in the initial eUICC to access the mobile communication network for one or more MNO's operational profiles 521 and 522. You can add an ADF. In addition, an ADF for a new provisioning profile 511 may be added.
- the eUICC 500 may provide an application identifier (AID) 542 for selecting a profile in the terminal device 200 and may include information on the element file 541.
- the subscriber authentication module 500 may include one or more component provisioning profiles 511, MNO # 1 operational profiles 521, and MNO # 2 operational profiles 522. It should be noted that this does not mean that all of them must be provided. That is, the elementary file directory (EFDIR) 541 of FIG. 3 may include one or more of AID # 1 to AID # 4 to include one or more of ADF files indicated by each AID.
- EDDIR elementary file directory
- the element file 541 may include one or more application template TLV (Tag, Length, Value) objects as a means for providing an application identifier 542.
- the application template TLV object may include application identifier information, application label information, and application state information.
- An application identifier TLV object, an application label TLV object, and an application state TLV object of FIG. 4 mean an object having application identifier information, application label information, and application state information, respectively.
- the application identifier TLV object may include application identifier information.
- the application identifier value 542 includes a registered application provider identifier (RID), which is an application registrar identifier (543), and a proprietary application identifier (PIX), which is an application identification extension (544), and may consist of a maximum of 16 bytes. Can be.
- the application registrar identifier 543 is the hexadecimal number of 'A000000009' if defined in ETSI, 'A000000087' if defined in 3GPP, and 'A000000343' if defined in 3GPP2. Can have.
- the application identification extension 544 includes proprietary information, and includes an application code, a country code, an application provider code, and an application provider field optional. It may include at least one or more information.
- the application code of the application identification extension 544 may include classification information for classifying at least one type of at least one profile 511, 521, 522, or 531, and the type of at least one profile is a provisioning profile 511. ), A type of operation profile 521, 522, and a type of operation profile 521, 522 containing data of the provisioning profile 511.
- the application code of the application identification extension 544 may include type information of the profile, that is, information indicating one of the provisioning profile 511 and the operation profiles 521 and 522.
- the application code may include information indicating a case in which the operation profile 521 or 522 is used as the provisioning profile 511 at the same time.
- application code in which profile type information and other information are defined may be defined. For example, any application code may be defined as a profile type being a provisioning profile 511 and a NAA (Network Access Application) being a USIM.
- the country code and the application provider code may include the country and provider (or business) code of the provider of the profile, respectively.
- the terminal may recognize ADFs composed of the same profile type, country code, and application provider code as one profile.
- the application code value may be different from the application code value of the ADF provided as the operational profile 521, 522. (521, 522).
- the application provider field option may include type information of the profile, that is, information indicating one of the provisioning profile 511 and the operation profiles 521 and 522.
- the application code may include information indicating a case in which the operation profile 521 or 522 is used as the provisioning profile 511 at the same time.
- an application provider field option in which profile type information and other information are defined may be defined.
- an example of defining an application identifier value 542 is provided.
- the application code for the eUICC provisioning profile 511 is allocated '0201' in ETSI, the country code is 'FF82', and the provider code is 'FF3089'. If it is assumed to be ', the application identifier value 542 can be defined as shown in the first row of FIG.
- the application identifier value 542 is second. Can be defined as a line.
- Application code for an eUICC operation profile (521, 522) and a provisioning profile (511) is assigned '0203' in the ETSI, assuming that the country code 'FF82' and the provider code 'FF3089'
- the application identifier value 542 may be defined as in the third row.
- the application code for the eUICC operation profiles 521 and 522 is assigned '0202' in the ETSI
- the country code is 'FF82'
- the provider code is 'FF3089'
- the eUICC operation profile in the application provider field option when an '1xxxxxxx' ('x' is an arbitrary value) is allocated as information for the case used as a provisioning profile, the application identifier value 542 may be defined as a fourth row.
- FIG. 7 is a block diagram illustrating a subscriber authentication apparatus 500 and its components according to an embodiment of the present invention.
- the subscriber authentication device 500 may include a subscriber authentication device 500 embedded in a mobile communication terminal 200 that accesses a communication network using at least one profile 511, 521, 522, or 531.
- a first storage unit 510 stores at least one provisioning profile 511 having authentication information for a communication network, and at least one operation profile 521 having service access information to receive a service of a communication network.
- a second storage unit 520 for storing the 522 and an element file storage unit 540 for storing the elementary file 541 having attribute information for the at least one profile so as to select at least one profile. It may be configured to include).
- the subscriber authentication apparatus 500 may be a subscriber authentication module 500 having a UICC embedded therein.
- the first storage unit 510 for storing the provisioning profile 511
- the second storage unit 520 for storing the operation profiles 521 and 522
- the element file storage unit 540 for storing the element file 541
- the actual location may be the same place or different places.
- the provisioning profile 511, the operation profiles 521 and 522, and the element file 541 have been described above and thus will not be redundantly described.
- the subscriber authentication apparatus 500 may further include a third storage unit 530 that stores at least one user profile 531 having user information of the mobile communication terminal 200. .
- the subscriber authentication apparatus 500 can also be used as a storage space for user information (Short Message Service, Multimedia Message Service, Phonebook, etc.). Since the third storage unit is also a logically divided unit, the actual storage location may be the same place or different places.
- the subscriber authentication apparatus 500 may select a provisioning profile and an operation profile based on an elementary file including attribute information of at least one profile, and the attribute information may include at least one profile 511, 521. , 522, and 531 may include application identifier information, application label information, and application state information for any profile.
- the element file 541 is a means for providing an application identifier 542.
- One or more Application Template TLV objects (TLV, Tag, Length, Value) It may include.
- the application template TLV object may include application identifier information, application label information, and application state information.
- An application identifier TLV object, an application label TLV object, and an application state TLV object of FIG. 4 mean an object having application identifier information, application label information, and application state information, respectively. Since application identifier information is described above, it will not be repeated.
- FIG. 8 is a flowchart illustrating a profile selection method of a terminal device 200 incorporating a subscriber authentication device 500 according to an embodiment of the present invention.
- a method for accessing a network of the mobile communication terminal device 200 may include accessing a communication network using at least one profile 511, 521, 522, or 531 included in the subscriber authentication module 500.
- the authentication procedure for the communication network is performed based on the provisioning profile 511 among the at least one profile 511, 521, 522, 531, and the authentication completion information is received from the operator server 100 of the communication network.
- the operation profile (521, 522) corresponding to the operator of the communication network of the at least one profile (511, 521, 522, 531) It may be configured to include a step (S895) receiving a service from the operator server 100 based on the).
- the mobile communication terminal device 200 may perform user authentication and access to the mobile communication network using the profiles 511, 521, and 522 of the eUICC 500, and the eUICC may provide user information (short message service, multimedia message). It can also be used as a storage space for services, phonebooks, etc.).
- the profile may be classified into a provisioning profile 511, an operation profile 521 and 522, a user profile 531, and the like.
- the provisioning profile 511 refers to a file that provides information necessary for authentication of the mobile communication network in order to support MNO opening when the eUICC 500 is not opened with the mobile communication network provider.
- the accessing mobile communication network may be a network of any MNO which is not specified, or may be a network of a predetermined MNO.
- the eUICC 500 can include one or multiple provisioning profiles 511. Alternatively, there may be an eUICC that does not include the provisioning profile 511.
- the terminal device 200 may perform an authentication procedure of a specific mobile communication network operator using the authentication information stored in the provisioning profile 511 (S870), receive a service opening, and receive authentication completion information thereof (S870). S880).
- the operation profiles 521 and 522 refer to a file that provides MNO network access information for accessing the opened MNO network and receiving services after the eUICC 500 is opened with the MNO.
- the eUICC 500 may include one or more operational profiles 521, 522. If the provisioning profile 511 does not exist in the eUICC 500, the operational profiles 521, 522 may be provisioned profiles 511. It can also play the role of).
- the terminal device 200 may access a specific mobile communication network operator using the access information stored in the operation profiles 521 and 522 (S890) and receive a service of the operator (S895).
- a plurality of provisioning profiles 511, operation profiles 521 and 522, and a user profile 531 may exist, and the terminal 200 may select a specific profile among them according to the purpose (S850). ).
- the network access method of the mobile communication terminal device 200 may include an element file including attribute information of at least one profile 511, 521, 522, or 531 before receiving authentication completion information (S880).
- the method may further include a step S850 of selecting a provisioning profile 511 and an operation profile 521 or 522 based on the elementary file.
- the terminal device 200 may obtain an application template TLV object information by selecting an element file (EFDIR, Elementary File Directory) 541 of the eUICC 500 (S810) and reading a corresponding value.
- the application code included in the application template TLV object information is used to distinguish a profile type (provisioning profile, operation profiles 521 and 522, and operation profiles 521 and 522 which simultaneously perform the provisioning profile).
- the application provider code to distinguish the profile provider, the application provider field option to the operation profile and the operation profile 521 and 522 which simultaneously serve as the provisioning profile, and the application label as the information of the profile text name.
- a specific profile may be selected using the application state as profile state information (S850).
- the profile selection step (S850) may select a profile by referring to the attribute information of the profile in the element file 541 stored in the subscriber authentication module 500.
- the element file 541 may include various other information defining the profile, including an application identifier 542 corresponding to the profile.
- Various other information may be defined by tags, lengths, values, etc. so as to be divided into object units to determine a standard for mobile communication. The role of each object constituting the structure and attribute information of the element file 541 has been described above.
- the attribute information may include an application identifier 542 that may identify at least one profile 511, 521, 522, 531, where the application identifier 542 includes an application registrar identifier 543 and an application identification extension ( 544, wherein the application identification extension 544 includes at least one of an application code, a country code, an application provider code, and an application provider field option. May contain information.
- the provisioning profile 511 and the operation profiles 521 and 522 stored in the eUICC 500 may be configured in the form of one or a plurality of application dedicated files (ADFs) as shown in FIG. 3. have.
- the ADF may store information that can be matched with the application identifier 542 and the contents of the profile among the attribute information stored in the element file 541.
- Various embodiments and detailed descriptions of the configuration of the element file 541 and the application identifier 542 have been described above.
- the application code may include classification information for distinguishing at least one type of profile, and the type of at least one profile may include a provisioning profile 511 type, an operation profile 521 and 522 type, and a provisioning profile 511. It may include a type of operation profile (521, 522) containing the data of.
- the application code of the application identification extension 544 may include type information of the profile, that is, information indicating one of the provisioning profile 511 and the operation profiles 521 and 522.
- the application code may include information indicating a case in which the operation profile 521 or 522 is used as the provisioning profile 511 at the same time.
- application code in which profile type information and other information are defined may be defined. For example, any application code may be defined as a profile type being a provisioning profile 511 and a NAA (Network Access Application) being a USIM.
- the country code and the application provider code may include the country and provider (or business) code of the provider of the profile, respectively.
- the terminal may recognize ADFs composed of the same profile type, country code, and application provider code as one profile.
- the application code value may be different from the application code value of the ADF provided as the operational profile 521, 522. (521, 522).
- the application provider field option may include type information of the profile, that is, information indicating one of the provisioning profile 511 and the operation profiles 521 and 522.
- the application code may include information indicating a case in which the operation profile 521 or 522 is used as the provisioning profile 511 at the same time.
- an application provider field option in which profile type information and other information are defined may be defined.
- embodiments of the invention may be implemented in hardware or software. Embodiments of the present invention may be performed as a computer program product having program code operative for performing one of the program codes, methods.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Databases & Information Systems (AREA)
- Telephone Function (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims (20)
- 적어도 하나의 프로파일을 구비하고 있는 가입자 인증 모듈;상기 적어도 하나의 프로파일 중 프로비저닝 프로파일(provisioning profile)에 기반하여 통신 네트워크에 대한 인증절차를 수행하고 상기 통신 네트워크의 사업자 서버로부터 인증 완료 정보를 수신하는 네트워크 인증부; 및상기 인증 완료 정보에 기반하여 상기 통신 네트워크에 접속하고, 상기 적어도 하나의 프로파일 중 상기 통신 네트워크의 사업자에 상응하는 운용 프로파일(operational profile)에 기반하여 상기 사업자 서버로부터 서비스를 제공받는 네트워크 접속부를 포함하는 이동통신 단말 장치.
- 청구항 1에 있어서,상기 이동통신 단말 장치는상기 적어도 하나의 프로파일에 대한 속성 정보를 포함하고 있는 요소 파일(elementary file)에 기반하여 상기 프로비저닝 프로파일 및 상기 운용 프로파일을 선택하는 프로파일 선택부를 더 포함하는 것을 특징으로 하는 이동통신 단말 장치.
- 청구항 2에 있어서,상기 속성 정보는상기 적어도 하나의 프로파일을 식별할 수 있는 어플리케이션 식별자(application identifier)를 포함하는 것을 특징으로 하는 이동통신 단말 장치.
- 청구항 3에 있어서,상기 어플리케이션 식별자는어플리케이션 등록기관 식별자(RID, Registered application provider Identifier) 및 어플리케이션 식별 확장자(PIX, Proprietary application Identifier eXtension)로 구성되고,상기 어플리케이션 식별 확장자는 어플리케이션 코드(application code), 국가 코드(country code), 어플리케이션 제공자 코드(application provider code) 및 어플리케이션 제공자 필드 옵션(application provider field option) 중 적어도 하나 이상의 정보를 포함하는 것을 특징으로 하는 이동통신 단말 장치.
- 청구항 4에 있어서,상기 어플리케이션 코드는상기 적어도 하나의 프로파일의 종류를 구분할 수 있는 구분 정보를 포함하는 것을 특징으로 하는 이동통신 단말 장치.
- 청구항 5에 있어서,상기 적어도 하나의 프로파일의 종류는프로비저닝 프로파일 타입, 운용 프로파일 타입, 프로비저닝 프로파일의 데이터를 내포하고 있는 운용 프로파일 타입을 포함하는 것을 특징으로 하는 이동통신 단말 장치.
- 적어도 하나의 프로파일을 이용하여 통신 네트워크에 접속하는 이동통신 단말 장치에 내장된 가입자 인증 장치에 있어서,상기 통신 네트워크에 대한 인증 정보를 가진 적어도 하나의 프로비저닝 프로파일을 저장하는 제1 저장부;상기 통신 네트워크의 서비스를 제공받도록 하는 서비스 접속 정보를 가진 적어도 하나의 운용 프로파일을 저장하는 제2 저장부; 및상기 적어도 하나의 프로파일을 선택하도록 상기 적어도 하나의 프로파일에 대한 속성 정보를 가진 요소 파일(elementary file)을 저장하는 요소 파일 저장부 를 포함하는 가입자 인증 장치.
- 청구항 7에 있어서,상기 가입자 인증 장치는상기 이동통신 단말 장치의 사용자 정보를 가진 적어도 하나의 사용자 프로파일(user profile)을 저장하는 제3 저장부를 더 포함하는 것을 특징으로 하는 가입자 인증 장치.
- 청구항 7에 있어서,상기 가입자 인증 장치는상기 적어도 하나의 프로파일에 대한 속성 정보를 포함하고 있는 요소 파일(elementary file)에 기반하여 상기 프로비저닝 프로파일 및 상기 운용 프로파일이 선택되는 것을 특징으로 하는 가입자 인증 장치.
- 청구항 9에 있어서,상기 속성 정보는상기 적어도 하나의 프로파일 중 임의의 프로파일을 위한 어플리케이션 식별자 정보, 어플리케이션 레이블 정보 및 어플리케이션 상태 정보를 포함하는 것을 특징으로 하는 가입자 인증 장치.
- 청구항 10에 있어서,상기 어플리케이션 식별자 정보는상기 임의의 프로파일을 식별할 수 있는 어플리케이션 식별자(AID, Application Identifier)를 포함하고,상기 어플리케이션 식별자는 어플리케이션 등록기관 식별자(RID, Registered application provider Identifier) 및 어플리케이션 식별 확장자(PIX, Proprietary application Identifier eXtension)로 구성되는 것을 특징으로 하는 가입자 인증 장치.
- 청구항 11에 있어서,상기 어플리케이션 식별 확장자는어플리케이션 코드(application code), 국가 코드(country code), 어플리케이션 제공자 코드(application provider code) 및 어플리케이션 제공자 필드 옵션(application provider field option) 중 적어도 하나 이상의 정보를 포함하는 것을 특징으로 하는 가입자 인증 장치.
- 청구항 12에 있어서,상기 어플리케이션 코드는상기 적어도 하나의 프로파일의 종류를 구분할 수 있는 구분 정보를 포함하는 것을 특징으로 하는 가입자 인증 장치.
- 청구항 13에 있어서,상기 적어도 하나의 프로파일의 종류는프로비저닝 프로파일 타입, 운용 프로파일 타입, 프로비저닝 프로파일의 데이터를 내포하고 있는 운용 프로파일 타입을 포함하는 것을 특징으로 하는 가입자 인증 장치.
- 가입자 인증 모듈에 구비된 적어도 하나의 프로파일을 이용하여 통신 네트워크에 접속하는 방법에 있어서,상기 적어도 하나의 프로파일 중 프로비저닝 프로파일(provisioning profile)에 기반하여 상기 통신 네트워크에 대한 인증절차를 수행하고 상기 통신 네트워크의 사업자 서버로부터 인증 완료 정보를 수신하는 단계; 및상기 인증 완료 정보에 기반하여 상기 통신 네트워크에 접속하고, 상기 적어도 하나의 프로파일 중 상기 통신 네트워크의 사업자에 상응하는 운용 프로파일(operational profile)에 기반하여 상기 사업자 서버로부터 서비스를 제공받는 단계를 포함하는 이동통신 단말 장치의 네트워크 접속 방법.
- 청구항 15에 있어서,상기 인증 완료 정보를 수신하는 단계 이전에,상기 적어도 하나의 프로파일에 대한 속성 정보를 포함하고 있는 요소 파일(elementary file)에 기반하여 상기 프로비저닝 프로파일 및 상기 운용 프로파일을 선택하는 단계를 더 포함하는 것을 특징으로 하는 이동통신 단말 장치의 네트워크 접속 방법.
- 청구항 15에 있어서,상기 속성 정보는상기 적어도 하나의 프로파일을 식별할 수 있는 어플리케이션 식별자(application identifier)를 포함하는 것을 특징으로 하는 이동통신 단말 장치의 네트워크 접속 방법.
- 청구항 17에 있어서,상기 어플리케이션 식별자는어플리케이션 등록기관 식별자(RID, Registered application provider Identifier) 및 어플리케이션 식별 확장자(PIX, Proprietary application Identifier eXtension)로 구성되고,상기 어플리케이션 식별 확장자는 어플리케이션 코드(application code), 국가 코드(country code), 어플리케이션 제공자 코드(application provider code) 및 어플리케이션 제공자 필드 옵션(application provider field option) 중 적어도 하나 이상의 정보를 포함하는 것을 특징으로 하는 이동통신 단말 장치의 네트워크 접속 방법.
- 청구항 18에 있어서,상기 어플리케이션 코드는상기 적어도 하나의 프로파일의 종류를 구분할 수 있는 구분 정보를 포함하는 것을 특징으로 하는 이동통신 단말 장치의 네트워크 접속 방법.
- 청구항 19에 있어서,상기 적어도 하나의 프로파일의 종류는프로비저닝 프로파일 타입, 운용 프로파일 타입, 프로비저닝 프로파일의 데이터를 내포하고 있는 운용 프로파일 타입을 포함하는 것을 특징으로 하는 이동통신 단말 장치의 네트워크 접속 방법.
Priority Applications (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US14/440,131 US10111092B2 (en) | 2012-11-06 | 2013-11-05 | Terminal device having subscriber identity device and method for selecting profile thereof |
US15/690,959 US10187798B2 (en) | 2012-11-06 | 2017-08-30 | Terminal device having subscriber identity device and method for selecting profile thereof |
Applications Claiming Priority (4)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR10-2012-0124606 | 2012-11-06 | ||
KR20120124606 | 2012-11-06 | ||
KR1020130133421A KR102141372B1 (ko) | 2012-11-06 | 2013-11-05 | 가입자 인증 장치를 내장한 단말 장치 및 이를 위한 프로파일 선택 방법 |
KR10-2013-0133421 | 2013-11-05 |
Related Child Applications (2)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US14/440,131 A-371-Of-International US10111092B2 (en) | 2012-11-06 | 2013-11-05 | Terminal device having subscriber identity device and method for selecting profile thereof |
US15/690,959 Continuation US10187798B2 (en) | 2012-11-06 | 2017-08-30 | Terminal device having subscriber identity device and method for selecting profile thereof |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2014073836A1 true WO2014073836A1 (ko) | 2014-05-15 |
Family
ID=50684879
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/KR2013/009954 WO2014073836A1 (ko) | 2012-11-06 | 2013-11-05 | 가입자 인증 장치를 내장한 단말 장치 및 이를 위한 프로파일 선택 방법 |
Country Status (1)
Country | Link |
---|---|
WO (1) | WO2014073836A1 (ko) |
Cited By (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2016043534A3 (en) * | 2014-09-16 | 2016-05-06 | Samsung Electronics Co., Ltd. | Method for providing network service and electronic device |
CN106211122A (zh) * | 2015-05-27 | 2016-12-07 | 意法半导体股份有限公司 | 用于管理sim模块中的多个简档的方法和对应的sim模块以及计算机程序产品 |
CN106664544A (zh) * | 2014-07-19 | 2017-05-10 | 三星电子株式会社 | 用于嵌入式sim供应的方法和设备 |
CN107005837A (zh) * | 2014-11-17 | 2017-08-01 | 三星电子株式会社 | 用于通信系统中的简档安装的装置和方法 |
CN107995620A (zh) * | 2016-10-27 | 2018-05-04 | 中兴通讯股份有限公司 | 网络接入方法和终端 |
CN113630763A (zh) * | 2015-09-22 | 2021-11-09 | 三星电子株式会社 | 在移动通信系统中下载简档的方法和设备 |
Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2009042840A1 (en) * | 2007-09-26 | 2009-04-02 | Qualcomm Incorporated | Systems and methods for provisioning wireless devices based on multiple network-service application profiles and data session conflict resolution |
US20110252240A1 (en) * | 2010-04-07 | 2011-10-13 | Gordie Freedman | Mobile Device Management |
US20120108295A1 (en) * | 2010-10-29 | 2012-05-03 | Schell Stephan V | Access data provisioning apparatus and methods |
KR20120044916A (ko) * | 2010-10-28 | 2012-05-08 | 애플 인크. | 무선 네트워크를 통해 전자 식별 컴포넌트들을 전달하기 위한 방법 및 장치 |
US20120135710A1 (en) * | 2010-11-12 | 2012-05-31 | Schell Stephan V | Apparatus and methods for recordation of device history across multiple software emulations |
-
2013
- 2013-11-05 WO PCT/KR2013/009954 patent/WO2014073836A1/ko active Application Filing
Patent Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2009042840A1 (en) * | 2007-09-26 | 2009-04-02 | Qualcomm Incorporated | Systems and methods for provisioning wireless devices based on multiple network-service application profiles and data session conflict resolution |
US20110252240A1 (en) * | 2010-04-07 | 2011-10-13 | Gordie Freedman | Mobile Device Management |
KR20120044916A (ko) * | 2010-10-28 | 2012-05-08 | 애플 인크. | 무선 네트워크를 통해 전자 식별 컴포넌트들을 전달하기 위한 방법 및 장치 |
US20120108295A1 (en) * | 2010-10-29 | 2012-05-03 | Schell Stephan V | Access data provisioning apparatus and methods |
US20120135710A1 (en) * | 2010-11-12 | 2012-05-31 | Schell Stephan V | Apparatus and methods for recordation of device history across multiple software emulations |
Cited By (12)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN106664544A (zh) * | 2014-07-19 | 2017-05-10 | 三星电子株式会社 | 用于嵌入式sim供应的方法和设备 |
CN106664544B (zh) * | 2014-07-19 | 2020-03-27 | 三星电子株式会社 | 用于嵌入式sim供应的方法和设备 |
WO2016043534A3 (en) * | 2014-09-16 | 2016-05-06 | Samsung Electronics Co., Ltd. | Method for providing network service and electronic device |
US10142829B2 (en) | 2014-09-16 | 2018-11-27 | Samsung Electronics Co., Ltd | Method for providing network service and electronic device |
CN107005837A (zh) * | 2014-11-17 | 2017-08-01 | 三星电子株式会社 | 用于通信系统中的简档安装的装置和方法 |
US10609549B2 (en) | 2014-11-17 | 2020-03-31 | Samsung Electronics Co., Ltd. | Apparatus and method for profile installation in communication system |
US10986487B2 (en) | 2014-11-17 | 2021-04-20 | Samsung Electronics Co., Ltd. | Apparatus and method for profile installation in communication system |
CN106211122A (zh) * | 2015-05-27 | 2016-12-07 | 意法半导体股份有限公司 | 用于管理sim模块中的多个简档的方法和对应的sim模块以及计算机程序产品 |
CN106211122B (zh) * | 2015-05-27 | 2020-01-24 | 意法半导体股份有限公司 | 用于管理sim模块中的多个简档的方法、sim模块以及计算机可读介质 |
CN113630763A (zh) * | 2015-09-22 | 2021-11-09 | 三星电子株式会社 | 在移动通信系统中下载简档的方法和设备 |
CN113630763B (zh) * | 2015-09-22 | 2024-03-08 | 三星电子株式会社 | 在移动通信系统中下载简档的方法和设备 |
CN107995620A (zh) * | 2016-10-27 | 2018-05-04 | 中兴通讯股份有限公司 | 网络接入方法和终端 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
WO2014092385A1 (ko) | 프로비져닝 프로파일을 이용하여 이동 통신 네트워크 사업자를 선택하는 방법 및 이를 이용하는 장치 | |
KR102141372B1 (ko) | 가입자 인증 장치를 내장한 단말 장치 및 이를 위한 프로파일 선택 방법 | |
WO2014073836A1 (ko) | 가입자 인증 장치를 내장한 단말 장치 및 이를 위한 프로파일 선택 방법 | |
WO2016010387A1 (en) | Method and device for updating profile management server | |
EP3487196B1 (en) | Privacy managing entity selection in communication system | |
WO2020145623A1 (en) | Apparatus and method for handling esim profile for issp device | |
WO2021066572A1 (ko) | 통신서비스를 위한 프로파일을 효율적으로 제공하는 방법 및 장치 | |
WO2017061800A1 (ko) | 통신 시스템에서 프로파일을 원격으로 제공하는 방법 및 장치 | |
WO2014193181A1 (ko) | 프로파일 설치를 위한 방법 및 장치 | |
WO2020004901A1 (ko) | 무선 통신 시스템에서 통신사 정보를 처리하는 방법 및 장치 | |
WO2014193188A1 (en) | Method and apparatus for setting profile | |
US20160373920A1 (en) | Managing network connectivity of a device comprising an embedded uicc | |
WO2016010312A1 (ko) | Euicc의 프로파일 설치 방법 및 장치 | |
US10862881B2 (en) | Method of managing shared files and device for authenticating subscriber by using same | |
KR20070056102A (ko) | 통신 네트워크에서의 이동국의 등록 | |
EP2911431A1 (en) | Communications system, mobile communications device, transition control device, transition control method, and transition control program | |
CN111656811B (zh) | 用于通信的方法、装置和介质 | |
WO2014046421A1 (ko) | eUICC의 식별자 관리 방법 및 그 장치 | |
CN105451359B (zh) | 数字集群通信系统中的终端接入方法和装置 | |
Abdalla et al. | Remote subscription management of M2M terminals in 4G cellular wireless networks | |
WO2014038874A2 (ko) | 프로비져닝 프로파일을 이용하는 가입자 인증 모듈 및 이를 이용한 네트워크 접속 방법 | |
WO2014035092A1 (ko) | 공유 파일 관리 방법 및 이를 이용하는 가입자 인증 장치 | |
WO2022071726A1 (en) | Method and apparatus for group management for group event monitoring | |
EP3205133B1 (en) | Method for transferring an assignment regarding an embedded universal integrated circuit entity from a first mobile network operator to a second mobile network operator | |
WO2021091274A1 (ko) | 무선 통신 시스템에서의 Paging 방법 및 장치 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13853636 Country of ref document: EP Kind code of ref document: A1 |
|
WWE | Wipo information: entry into national phase |
Ref document number: 14440131 Country of ref document: US |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 21.08.2015Y) |
|
122 | Ep: pct application non-entry in european phase |
Ref document number: 13853636 Country of ref document: EP Kind code of ref document: A1 |