WO2023008712A1 - 전자 장치 및 전자 장치에서 임베디드 가입자 식별 모듈을 이용하여 회선을 이동하기 위한 방법 - Google Patents
전자 장치 및 전자 장치에서 임베디드 가입자 식별 모듈을 이용하여 회선을 이동하기 위한 방법 Download PDFInfo
- Publication number
- WO2023008712A1 WO2023008712A1 PCT/KR2022/007415 KR2022007415W WO2023008712A1 WO 2023008712 A1 WO2023008712 A1 WO 2023008712A1 KR 2022007415 W KR2022007415 W KR 2022007415W WO 2023008712 A1 WO2023008712 A1 WO 2023008712A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- electronic device
- information
- profile
- authentication
- line
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
- H04W8/20—Transfer of user or subscriber data
- H04W8/205—Transfer to or from user equipment or user record carrier
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/80—Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
- H04W8/183—Processing at user equipment or user record carrier
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
- H04W8/20—Transfer of user or subscriber data
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W88/00—Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
- H04W88/02—Terminal devices
Definitions
- the present disclosure relates to an electronic device and a method for migrating a line using an embedded subscriber identity module (eSIM) in an electronic device.
- eSIM embedded subscriber identity module
- an electronic device eg, user equipment (UE)
- UE user equipment
- a wireless communication network may access a wireless communication network and use a voice communication or data communication service while moving or at a fixed location.
- An appropriate authentication process is required to provide a communication service to an electronic device.
- a universal integrated circuit card UICC
- MNO mobile network operator
- USIM universal subscriber identity module
- UICC is a SIM (subscriber identity module) card for GSM (global system for mobile communications), WCDMA (wideband code division multiple access), LTE (long term evolution), NR (new radio) USIM (universal subscriber identity) module) can be called a card.
- SIM subscriber identity module
- GSM global system for mobile communications
- WCDMA wideband code division multiple access
- LTE long term evolution
- NR new radio
- USIM universal subscriber identity
- the communication service provider provides the user with a UICC (eg, SIM card or USIM card), and the user can insert the provided UICC into his/her electronic device.
- a UICC eg, SIM card or USIM card
- the USIM application installed inside the UICC is executed, and communication in which the same value is stored using the IMSI (international mobile subscriber identity) value stored inside the UICC and the encryption key value for authentication
- IMSI international mobile subscriber identity
- the UICC is manufactured as a dedicated card for a specific telecommunications operator at the request of a specific telecommunications operator when manufacturing the card, and authentication information for network access of the telecommunications operator (eg, USIM application and subscriber identification ID (eg, IMSI)), An encryption key (eg, a known K value or Ki value) may be preloaded.
- the UICC is provided to subscribers of communication services through a corresponding communication service provider, and the communication service provider can perform management such as installation, modification, and deletion of applications in the UICC by utilizing technology such as OTA (over the air) when necessary. there is.
- the user can use the network and application services of the telecommunication service provider by inserting the UICC into the terminal, and when replacing the terminal, by inserting the detachable UICC from the existing terminal to the new terminal, authentication information, phone number, and personal phone book stored in the corresponding UICC can be stored. etc. can be used as it is in the new terminal.
- a user purchases a specific UICC or subscribes to (or purchases) a communication service at the time after acquiring the UICC, and the user subscribes to, cancels, and opens a specific wireless communication operator , or by changing the subscription to another communication operator (eg, line transfer), the USIM application, subscriber identification ID, encryption key, etc. of the communication operator are remotely installed in the UICC, and authentication information of various communication operators A method for flexible installation and management is being proposed.
- eUICC embedded UICC
- the eUICC may be manufactured as a pre-mounted UICC fixed in the terminal in the form of a chip, for example, during the manufacturing process of the terminal. Therefore, the eUICC can be used in various terminals that may have a structure in which the UICC is not physically removable, such as a machine to machine (M2M) or device to device (D2D) terminal, as well as a general wireless terminal such as a mobile phone.
- M2M machine to machine
- D2D device to device
- the eUICC may also be referred to as an eSIM.
- a physical UICC e.g., SIM card
- the user moves the line to the new electronic device while maintaining authentication information, mobile communication phone number, and personal phone book stored in the UICC ( subscription transfer).
- a configuration for inserting a physical UICC in the new electronic device eg, a slot for inserting the UICC
- OPEN ID In order to move a line between electronic devices without going through a physical SIM card, various authentication methods such as an OPEN ID or a short message service (SMS)-one time password (OTP) method may be used. In the OPEN ID or SMS-OTP method, inconvenience of additional user input for authentication may occur.
- SMS-OTP short message service
- one aspect of the present disclosure is to provide an electronic device capable of migrating a line without moving a physical UICC from an existing electronic device to a new electronic device and a method for migrating a line using an embedded SIM in an electronic device.
- the electronic device when moving a line from an existing electronic device to a new electronic device, the electronic device is connected through communication and an authentication result of the existing electronic device is transmitted to the new electronic device, thereby changing the line without additional user input. It is possible to provide a movable electronic device and a method for moving a line using an embedded SIM in an electronic device.
- EAP-AKA extensible authentication protocol for authentication and key agreement
- an electronic device includes at least one embedded universal integrated circuit card (eUICC) each storing at least one subscriber identification information, and at least one processor electrically connected to the eUICC.
- the at least one processor connects to an external electronic device through communication, receives a request for line information for line transfer from the external electronic device, and in response to receiving the request for line information, provides at least one line information that can be moved.
- eUICC embedded universal integrated circuit card
- a method of operating an electronic device performing line transfer comprises a line circuit in an electronic device including at least one embedded universal integrated circuit card (eUICC) each storing at least one subscriber identification information, and at least one processor electrically connected to the eUICC.
- eUICC embedded universal integrated circuit card
- a method for performing movement comprising: connecting to an external electronic device through communication; receiving a request for line information for line movement from the external electronic device; An operation of checking line information from profile information stored in the eUICC, an operation of transmitting the checked at least one movable line information to the external electronic device, and an operation of moving selected from among the at least one movable line information from the external electronic device.
- an electronic device may include a display, at least one embedded universal integrated circuit card (eUICC) each storing at least one subscriber identification information, and at least one processor electrically connected to the eUICC. .
- the at least one processor displays at least one line information on the display based on the profile information stored in the eUICC, receives a selection of a line to be moved to an external electronic device from among the at least one line information, and sends the server Request authentication for a line to be moved to the selected external electronic device, receive information corresponding to an authentication result from the server in response to the authentication request, and perform line transfer based on the information corresponding to the authentication result. It is possible to control to display information for the display on the display.
- eUICC embedded universal integrated circuit card
- a line may be moved without moving a physical UICC from an existing electronic device to a new electronic device.
- the electronic device when moving a line from an existing electronic device to a new electronic device, the electronic device is connected through communication and an authentication result of the existing electronic device is transmitted to the new electronic device, thereby moving the line without additional user input. can make it
- EAP-AKA extensible authentication protocol for authentication and key agreement or extensible authentication protocol for 3 rd part authentication and key agreement
- FIG. 1A is a block diagram of an electronic device in a network environment according to an embodiment of the present disclosure.
- 1B is a diagram illustrating a network environment including electronic devices according to an embodiment of the present disclosure.
- FIG. 2 is a diagram for explaining a system for providing a profile-based communication connection to an electronic device according to an embodiment of the present disclosure.
- FIG. 3 is a block diagram showing the configuration of an electronic device according to an embodiment of the present disclosure.
- FIG. 4 is a diagram for explaining the internal structure of an eUICC according to an embodiment of the present disclosure.
- FIG. 5 is a block diagram illustrating a network system for circuit migration according to an embodiment of the present disclosure.
- 6A and 6B are signal flow diagrams between devices illustrating a line transfer method according to various embodiments of the present disclosure.
- FIG. 7a, 7b, and 7c are views illustrating a user interface displayed on a screen of a new electronic device according to various embodiments of the present disclosure.
- FIG. 8 is a flowchart illustrating a line transfer method of an electronic device according to an embodiment of the present disclosure.
- 9A and 9B are signal flow diagrams between devices illustrating a line transfer method according to various embodiments of the present disclosure.
- FIGS. 10A, 10B, and 10C are views illustrating a user interface displayed on a screen of a new electronic device according to various embodiments of the present disclosure.
- FIG. 11 is a flowchart illustrating a line transfer method of an electronic device according to an embodiment of the present disclosure.
- 12A and 12B are signal flow diagrams between devices illustrating a line transfer method according to various embodiments of the present disclosure.
- FIG. 13 is a flowchart illustrating a line transfer method of an electronic device according to an embodiment of the present disclosure.
- 14A and 14B are signal flow diagrams between devices illustrating a line transfer method according to various embodiments of the present disclosure.
- 15 is a flowchart illustrating a line transfer method of an electronic device according to an embodiment of the present disclosure.
- FIG. 1A is a block diagram of an electronic device 101 within a network environment 100, according to various embodiments.
- an electronic device 101 communicates with an electronic device 102 through a first network 198 (eg, a short-range wireless communication network) or through a second network 199. It is possible to communicate with the electronic device 104 or the server 108 through (eg, a long-distance wireless communication network).
- the electronic device 101 may communicate with the electronic device 104 through the server 108 .
- the electronic device 101 includes a processor 120, a memory 130, an input module 150, an audio output module 155, a display module 160, an audio module 170, a sensor module ( 176), interface 177, connection terminal 178, haptic module 179, camera module 180, power management module 188, battery 189, communication module 190, subscriber identification module 196 , or the antenna module 197 may be included.
- at least one of these components eg, the connection terminal 178) may be omitted or one or more other components may be added.
- some of these components eg, sensor module 176, camera module 180, or antenna module 197) are integrated into a single component (eg, display module 160). It can be.
- the processor 120 for example, executes software (eg, the program 140) to cause at least one other component (eg, hardware or software component) of the electronic device 101 connected to the processor 120. It can control and perform various data processing or calculations. According to one embodiment, as at least part of data processing or operation, the processor 120 transfers instructions or data received from other components (e.g., sensor module 176 or communication module 190) to volatile memory 132. , processing commands or data stored in the volatile memory 132 , and storing resultant data in the non-volatile memory 134 .
- software eg, the program 140
- the processor 120 transfers instructions or data received from other components (e.g., sensor module 176 or communication module 190) to volatile memory 132. , processing commands or data stored in the volatile memory 132 , and storing resultant data in the non-volatile memory 134 .
- the processor 120 may include a main processor 121 (eg, a central processing unit or an application processor) or a secondary processor 123 (eg, a graphic processing unit, a neural network processing unit ( NPU: neural processing unit (NPU), image signal processor, sensor hub processor, or communication processor).
- a main processor 121 eg, a central processing unit or an application processor
- a secondary processor 123 eg, a graphic processing unit, a neural network processing unit ( NPU: neural processing unit (NPU), image signal processor, sensor hub processor, or communication processor.
- NPU neural network processing unit
- the secondary processor 123 may be implemented separately from or as part of the main processor 121 .
- the secondary processor 123 may, for example, take the place of the main processor 121 while the main processor 121 is in an inactive (eg, sleep) state, or the main processor 121 is active (eg, running an application). ) state, together with the main processor 121, at least one of the components of the electronic device 101 (eg, the display module 160, the sensor module 176, or the communication module 190) It is possible to control at least some of the related functions or states.
- the auxiliary processor 123 eg, image signal processor or communication processor
- the auxiliary processor 123 may include a hardware structure specialized for processing an artificial intelligence model.
- AI models can be created through machine learning. Such learning may be performed, for example, in the electronic device 101 itself where artificial intelligence is performed, or may be performed through a separate server (eg, the server 108).
- the learning algorithm may include, for example, supervised learning, unsupervised learning, semi-supervised learning or reinforcement learning, but in the above example Not limited.
- the artificial intelligence model may include a plurality of artificial neural network layers.
- Artificial neural networks include deep neural networks (DNNs), convolutional neural networks (CNNs), recurrent neural networks (RNNs), restricted boltzmann machines (RBMs), deep belief networks (DBNs), bidirectional recurrent deep neural networks (BRDNNs), It may be one of deep Q-networks or a combination of two or more of the foregoing, but is not limited to the foregoing examples.
- the artificial intelligence model may include, in addition or alternatively, software structures in addition to hardware structures.
- the memory 130 may store various data used by at least one component (eg, the processor 120 or the sensor module 176) of the electronic device 101 .
- the data may include, for example, input data or output data for software (eg, program 140) and commands related thereto.
- the memory 130 may include volatile memory 132 or non-volatile memory 134 .
- the program 140 may be stored as software in the memory 130 and may include, for example, an operating system 142 , middleware 144 , or an application 146 .
- the input module 150 may receive a command or data to be used by a component (eg, the processor 120) of the electronic device 101 from the outside of the electronic device 101 (eg, a user).
- the input module 150 may include, for example, a microphone, a mouse, a keyboard, a key (eg, a button), or a digital pen (eg, a stylus pen).
- the sound output module 155 may output sound signals to the outside of the electronic device 101 .
- the sound output module 155 may include, for example, a speaker or a receiver.
- the speaker can be used for general purposes such as multimedia playback or recording playback.
- a receiver may be used to receive an incoming call. According to one embodiment, the receiver may be implemented separately from the speaker or as part of it.
- the display module 160 may visually provide information to the outside of the electronic device 101 (eg, a user).
- the display module 160 may include, for example, a display, a hologram device, or a projector and a control circuit for controlling the device.
- the display module 160 may include a touch sensor set to detect a touch or a pressure sensor set to measure the intensity of force generated by the touch.
- the audio module 170 may convert sound into an electrical signal or vice versa. According to one embodiment, the audio module 170 acquires sound through the input module 150, the sound output module 155, or an external electronic device connected directly or wirelessly to the electronic device 101 (eg: Sound may be output through the electronic device 102 (eg, a speaker or a headphone).
- the audio module 170 acquires sound through the input module 150, the sound output module 155, or an external electronic device connected directly or wirelessly to the electronic device 101 (eg: Sound may be output through the electronic device 102 (eg, a speaker or a headphone).
- the sensor module 176 detects an operating state (eg, power or temperature) of the electronic device 101 or an external environmental state (eg, a user state), and generates an electrical signal or data value corresponding to the detected state. can do.
- the sensor module 176 may include, for example, a gesture sensor, a gyro sensor, an air pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a bio sensor, It may include a temperature sensor, humidity sensor, or light sensor.
- the interface 177 may support one or more designated protocols that may be used to directly or wirelessly connect the electronic device 101 to an external electronic device (eg, the electronic device 102).
- the interface 177 may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.
- HDMI high definition multimedia interface
- USB universal serial bus
- SD card interface Secure Digital Card interface
- audio interface audio interface
- connection terminal 178 may include a connector through which the electronic device 101 may be physically connected to an external electronic device (eg, the electronic device 102).
- the connection terminal 178 may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (eg, a headphone connector).
- the haptic module 179 may convert electrical signals into mechanical stimuli (eg, vibration or motion) or electrical stimuli that a user may perceive through tactile or kinesthetic senses.
- the haptic module 179 may include, for example, a motor, a piezoelectric element, or an electrical stimulation device.
- the camera module 180 may capture still images and moving images. According to one embodiment, the camera module 180 may include one or more lenses, image sensors, image signal processors, or flashes.
- the power management module 188 may manage power supplied to the electronic device 101 .
- the power management module 188 may be implemented as at least part of a power management integrated circuit (PMIC), for example.
- PMIC power management integrated circuit
- the battery 189 may supply power to at least one component of the electronic device 101 .
- the battery 189 may include, for example, a non-rechargeable primary cell, a rechargeable secondary cell, or a fuel cell.
- the communication module 190 is a direct (eg, wired) communication channel or a wireless communication channel between the electronic device 101 and an external electronic device (eg, the electronic device 102, the electronic device 104, or the server 108). Establishment and communication through the established communication channel may be supported.
- the communication module 190 may include one or more communication processors that operate independently of the processor 120 (eg, an application processor) and support direct (eg, wired) communication or wireless communication.
- the communication module 190 is a wireless communication module 192 (eg, a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module 194 (eg, : a local area network (LAN) communication module or a power line communication module).
- a corresponding communication module is a first network 198 (eg, a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network 199 (eg, a legacy communication module).
- the wireless communication module 192 uses subscriber information (eg, International Mobile Subscriber Identifier (IMSI)) stored in the subscriber identification module 196 within a communication network such as the first network 198 or the second network 199.
- IMSI International Mobile Subscriber Identifier
- the wireless communication module 192 may support a 5G network after a 4G network and a next-generation communication technology, for example, NR access technology (new radio access technology).
- NR access technologies include high-speed transmission of high-capacity data (enhanced mobile broadband (eMBB)), minimization of terminal power and access of multiple terminals (massive machine type communications (mMTC)), or high reliability and low latency (ultra-reliable and low latency (URLLC)).
- eMBB enhanced mobile broadband
- mMTC massive machine type communications
- URLLC ultra-reliable and low latency
- -latency communications can be supported.
- the wireless communication module 192 may support a high frequency band (eg, mmWave band) to achieve a high data rate, for example.
- the wireless communication module 192 uses various technologies for securing performance in a high frequency band, such as beamforming, massive multiple-input and multiple-output (MIMO), and full-dimensional multiplexing. Technologies such as input/output (FD-MIMO: full dimensional MIMO), array antenna, analog beam-forming, or large scale antenna may be supported.
- the wireless communication module 192 may support various requirements defined for the electronic device 101, an external electronic device (eg, the electronic device 104), or a network system (eg, the second network 199).
- the wireless communication module 192 is a peak data rate for eMBB realization (eg, 20 Gbps or more), a loss coverage for mMTC realization (eg, 164 dB or less), or a U-plane latency for URLLC realization (eg, Example: downlink (DL) and uplink (UL) each of 0.5 ms or less, or round trip 1 ms or less) may be supported.
- eMBB peak data rate for eMBB realization
- a loss coverage for mMTC realization eg, 164 dB or less
- U-plane latency for URLLC realization eg, Example: downlink (DL) and uplink (UL) each of 0.5 ms or less, or round trip 1 ms or less
- the antenna module 197 may transmit or receive signals or power to the outside (eg, an external electronic device).
- the antenna module 197 may include an antenna including a radiator formed of a conductor or a conductive pattern formed on a substrate (eg, PCB).
- the antenna module 197 may include a plurality of antennas (eg, an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network such as the first network 198 or the second network 199 is selected from the plurality of antennas by the communication module 190, for example. can be chosen A signal or power may be transmitted or received between the communication module 190 and an external electronic device through the selected at least one antenna.
- other components eg, a radio frequency integrated circuit (RFIC) may be additionally formed as a part of the antenna module 197 in addition to the radiator.
- RFIC radio frequency integrated circuit
- the antenna module 197 may form a mmWave antenna module.
- the mmWave antenna module includes a printed circuit board, an RFIC disposed on or adjacent to a first surface (eg, a lower surface) of the printed circuit board and capable of supporting a designated high frequency band (eg, mmWave band); and a plurality of antennas (eg, array antennas) disposed on or adjacent to a second surface (eg, a top surface or a side surface) of the printed circuit board and capable of transmitting or receiving signals of the designated high frequency band. can do.
- peripheral devices eg, a bus, general purpose input and output (GPIO), serial peripheral interface (SPI), or mobile industry processor interface (MIPI)
- signal e.g. commands or data
- commands or data may be transmitted or received between the electronic device 101 and the external electronic device 104 through the server 108 connected to the second network 199 .
- Each of the external electronic devices 102 or 104 may be the same as or different from the electronic device 101 .
- all or part of operations executed in the electronic device 101 may be executed in one or more external electronic devices among the external electronic devices 102 , 104 , or 108 .
- the electronic device 101 when the electronic device 101 needs to perform a certain function or service automatically or in response to a request from a user or another device, the electronic device 101 instead of executing the function or service by itself.
- one or more external electronic devices may be requested to perform the function or at least part of the service.
- One or more external electronic devices receiving the request may execute at least a part of the requested function or service or an additional function or service related to the request, and deliver the execution result to the electronic device 101 .
- the electronic device 101 may provide the result as at least part of a response to the request as it is or additionally processed.
- cloud computing distributed computing, mobile edge computing (MEC), or client-server computing technology may be used.
- the electronic device 101 may provide an ultra-low latency service using, for example, distributed computing or mobile edge computing.
- the external electronic device 104 may include an internet of things (IoT) device.
- Server 108 may be an intelligent server using machine learning and/or neural networks. According to one embodiment, the external electronic device 104 or server 108 may be included in the second network 199 .
- the electronic device 101 may be applied to intelligent services (eg, smart home, smart city, smart car, or health care) based on 5G communication technology and IoT-related technology.
- FIG. 1B is a diagram illustrating a network environment including electronic devices according to an embodiment of the present disclosure.
- a network may include an electronic device 101 , a first communication network 111a and/or a second communication network 112a.
- the electronic device 101 may operate as a dual SIM dual standby (DSDS) or dual SIM dual active (DSDA) electronic device supporting two SIMs in one device.
- the electronic device 101 may include a first SIM 111 and an eSIM 201 .
- the first SIM 111 may be an rSIM.
- a SIM card may be installed in the electronic device 101 .
- the SIM card will be referred to as a SIM.
- the electronic device 101 may include a slot (not shown) to accommodate the first SIM 111 .
- the electronic device 101 may accommodate two or more SIMs.
- the electronic device 101 may include a plurality of slots for accommodating a plurality of SIMs.
- the first SIM 111 is a SIM subscribed to a communication service provider of the first communication network 111a, and the electronic device 101 accesses the first communication network 111a using the first SIM 111, thereby wirelessly Communication services can be provided.
- the electronic device 101 may include an embedded subscriber identity module (eSIM) 201 .
- eSIM may also be named eUICC.
- the electronic device 101 can receive a wireless communication service by accessing the second communication network 112a using the eSIM 201 .
- the first communication network 111a and the second communication network 112a may be provided by the same communication service provider or may be provided by different communication providers.
- the electronic device 101 may not include the first SIM 111 and/or a slot for accommodating the first SIM 111 .
- the electronic device 101 may include only the eSIM 201 .
- the configuration of the electronic device 101 according to various embodiments of the present disclosure is not limited as long as the electronic device includes the eSIM 201 .
- FIG. 2 is a diagram for explaining a system for providing a profile-based communication connection to an electronic device according to an embodiment of the present disclosure.
- a system 200 includes an electronic device 101, an SM-DS server 210, an SM-DP+ server 220, an MNO server 230, and a communication service server 240. ) may be included.
- the electronic device 101 may include an eSIM 201 .
- the electronic device 101 may include at least one slot capable of accommodating at least one rSIM.
- the electronic device 101 may include or accommodate N (N is a natural number) SIMs (eSIMs or rSIMs), and may perform switching to use some of them. There is no limit to the combination of N number of SIMs, and there is also no limit to the number.
- the eSIM 201 may be inserted into the electronic device 101, integrally provided with the electronic device 101, or implemented to be accessible by the electronic device 101.
- the eSIM 201 is configured so that the electronic device 101 uses information (eg, a profile including universal subscriber identity module (USIM) information) in the eSIM 201 to obtain information from a mobile network operator; MNO) server and authentication can be performed.
- information eg, a profile including universal subscriber identity module (USIM) information
- MNO mobile network operator
- the eSIM 201 is called a subscriber identity module (SIM) card, wideband code division multiple access (WCDMA) in the case of a global system for mobile communications (GSM) method, long term evolution (LTE), NR ( In the case of a new radio) method, it may be called a USIM (universal subscriber identity module) card, and in addition, it may be called various names according to communication methods.
- SIM subscriber identity module
- WCDMA wideband code division multiple access
- GSM global system for mobile communications
- LTE long term evolution
- NR In the case of a new radio) method, it may be called a USIM (universal subscriber identity module) card, and in addition, it may be called various names according to communication methods.
- IMSI international mobile subscriber identity
- the wireless communication service After performing an appropriate authentication process with the server of the communication service provider in which the same value is stored using the K value, which is the encryption key for , the wireless communication service can be used.
- the appropriate authentication process may be AKA (authentication and key agreement) authentication (eg, EAP-AKA (extensible authentication protocol for authentication and key agreement)), and other authentication methods may be used.
- the eSIM 201 may be manufactured as a dedicated card for a corresponding communication service provider at the request of a specific communication service provider, and authentication information (eg, USIM application and subscriber identification ID (eg, USIM application and subscriber identification ID) for network access of the corresponding communication service provider). For example, IMSI)) and an encryption key (eg, a known K value or Ki value) may be preloaded.
- Applications (or information) within the eSIM 201 may be installed, modified, deleted, or updated using technology such as over the air (OTA), if necessary.
- OTA over the air
- the eSIM 201 may download or/and store information for providing a communication service in the form of a profile.
- the profile may be installed or stored in the manufacturing process of the eSIM 201 or downloaded by a terminal in an over the air (OTA) method and installed or stored in the eSIM 201 .
- the profile may include a provisioning profile and an operational profile. Even when the provisioning profile is not installed, the electronic device 101 may download the operational profile through a Wi-Fi short-range connection or Internet connection, and the provisioning profile needs to be installed in the electronic device 101.
- OTA over the air
- the operational profile may be a profile including subscriber identification information of a user of an electronic device
- the provisioning profile may be subscriber identification information or subscriber identification information (hereinafter referred to as 'first subscriber identification information') in the electronic device. It may include information (hereinafter also referred to as "first information") for downloading a profile (hereinafter referred to as 'first operational profile') including.
- the electronic device may download the first operational profile based on first information on the provisioning profile in the eSIM 201 .
- the electronic device 101 provides subscriber identification information (hereinafter referred to as 'second subscriber identification information') of an operational profile (hereinafter referred to as 'second operational profile') installed or stored in the eSIM 201. ) can be used to receive communication services.
- a profile including subscriber identification information may be a subscriber identity module (SIM) profile.
- the operational profile includes, in addition to subscriber identification information, subscriber's network access authentication information, subscriber's phone book, subscriber's personal information (eg SMS), subscribed carrier name, available service, and available data amount. , rate or service provision speed, or information enabling safe wireless communication use by performing subscriber authentication and traffic security key generation when accessing a wireless communication network such as GSM, WCDMA, LTE, or NR.
- a wireless communication network such as GSM, WCDMA, LTE, or NR.
- the first information for downloading data (eg, the first operational profile) including the first subscriber identification information is for a first communication connection designated for downloading the first operational profile. It may contain communication session information.
- the communication session information is SM-DS (subscription manager discovery service) server 210 access information for downloading the first operational profile or communication operator network information available for SM-DS server 210 access.
- SM-DS subscription manager discovery service
- the SM-DS server 210 may provide the electronic device 101 with the address of the SM-DP+ server 220 from which the first operational profile can be downloaded based on the provisioning profile. .
- the subscription manager data preparation plus (SM-DP+) server 220 is a profile providing server, an off-card entity of a profile domain, a profile encryption server, a profile creation server, and a profile It may be a profile provisioner or a profile provider.
- the SM-DP+ server 220 may perform a first communication connection 22 with the electronic device 101 through a wireless communication network based on a first communication connection request based on a provisioning profile from the electronic device 101, , the first operational profile may be provided to the electronic device 101 through the first communication connection 22 .
- the wireless communication network may be a specific node of the wireless communication network.
- the wireless communication network may be a base station, a subscriber information management node, or a mobility management node of the wireless communication network.
- the wireless communication network may include a home location register (HLR) and/or an authentication center (AuC) server to which the electronic device 101 accesses and performs a subscriber authentication function, and accesses after authentication to perform voice communication.
- HLR home location register
- AuC authentication center
- it may be connected to the communication service server 240 capable of providing communication services such as data communication.
- the mobile network operator (MNO) server 230 may be a server associated with a mobile communication network operator. According to various embodiments, the MNO server 230 prepares at least one profile (or profile package) (eg, first operational profile) associated with at least one subscriber identification information (eg, first subscriber identification information). may be requested to the SM-DP+ server 220, and information related to the first operational profile may be transmitted to the SM-DP+ server 220. According to an embodiment, the MNO server 230 may transmit a signal for updating and managing the first operational profile to the SM-DP+ server 220 . The MNO server 230 may allow a second communication connection 24 between the electronic device 101 and the communication service server 240 through the second operational profile installed in the eSIM 201 of the electronic device 101. there is.
- the MNO server 230 may allow a second communication connection 24 between the electronic device 101 and the communication service server 240 through the second operational profile installed in the eSIM 201 of the electronic device 101. there is.
- the communication service server 240 may be a server providing communication services.
- the communication service may be a service related to transmission or reception of data through a wireless communication network.
- the communication service transmits or receives other profiles (or data) that do not include subscriber identification information in addition to downloading an operational profile (eg, a first operational profile including first subscriber identification information). may include related services.
- the communication service server 240 may include a service server associated with various data transmission and reception, such as a server associated with various applications, a push server, a search server, or a market server, and communication by the communication service server 240
- the service may include various services such as data transmission/reception, notification reception, push reception, link reception and access, or service request by an application.
- the electronic device 101 when the electronic device 101 requests a service associated with transmission or reception of a profile (or data) that does not include subscriber identification information, the electronic device 101 communicates with the communication service server 240 based on the second operational profile. 2 communication connections 24 can be made.
- the SM-DS server 210, the SM-DP+ server 220, the MNO server 230, or the communication service server 240 are merely implementation examples of servers for performing each function, and , It may be called by another name, and each of the SM-DS server 210, SM-DP + server 220, MNO server 230, or communication service server 240 may be composed of one or a plurality of servers. Some or all of the SM-DS server 210, SM-DP+ server 220, MNO server 230, or communication service server 240 may be configured as one integrated server.
- an electronic device eg, the electronic device 101 of FIG. 1A or 1B or the electronic device 101 of FIG.
- a display eg, the display module 160 of FIG. 1A
- a communication module eg, the electronic device 101 of FIG. 1A or 1B
- Communication module 190 of FIG. 1A embedded subscriber identification for storing first information associated with a first communication connection for downloading data including first subscriber identification information for accessing at least one communication service providing server module (e.g. subscriber identification module 196 in FIG. 1A or eSIM 201 in FIG. 2), memory (e.g. memory 130 in FIG. 1A or memory 211 in FIG. 2) and the display, the communication module and a processor (eg, the processor 120 of FIG.
- the processor transmits data including the first subscriber identification information based on the first information using the communication module.
- the processor transmits data including the first subscriber identification information based on the first information using the communication module.
- the first information may include a provisioning profile
- the data including the first subscriber identification information may include a first operational profile
- the processor displays the second subscriber identification information through the display. It may be set to indicate that the corresponding second operational profile does not exist.
- the processor may be further configured to display a purchase screen associated with the second operational profile when the second operational profile does not exist.
- the processor may be configured to perform a second communication session based on the previously used second operational profile.
- the processor may be configured to perform a second communication session based on a second operational profile selected by a user.
- the processor may be configured to display at least one indicator indicating the first communication connection based on the provisioning profile through the display.
- the at least one indicator may include at least one type of a service provider name (SPN), a radio access technology (RAT), and a received signal strength indicator (RSSI).
- SPN service provider name
- RAT radio access technology
- RSSI received signal strength indicator
- the processor may be configured to select the provisioning profile associated with a network being accessed through the communication module.
- the processor may be configured to select the provisioning profile associated with the network being accessed based on at least one of a PLMN identifier, MCC, and area information of the network being accessed through the communication module.
- the electronic device 101 of FIG. 1A or 1B or the electronic device 101 of FIG. 2 includes a processor 120, an eSIM 201, a communication module 190, a display module 160 and an input module 150.
- the electronic device 101 may include two or more slots capable of accommodating two or more rSIMs.
- the processor 120 is one or a plurality of processors (eg, the main processor 121 and the auxiliary processor 123 of FIG. 1A , or an application processor and a communication processor). ), and a local profile assistant (LPA) 312 (eg, LPAd (device)) according to an embodiment.
- LPA local profile assistant
- the processor 120 includes a plurality of processors, a portion of the LPA 312 may be included in some of the plurality of processors, and another portion of the LPA 312 may be included in other portions.
- the LPA 312 may be included in the eSIM 201, and in this case, the LPA 312 may be referred to as LPAe (eUICC).
- the LPA 312 may communicate with a server to support profile download, installation, and management operations of the eSIM 201 or provide a user interface necessary for profile download, installation, and management operations.
- the LPA 312 provides local discovery services (LDS) 31, a local profile download (LPD) 33, and a local user interface in the electronic device 101.
- LUI) 35 may be a module that provides operations.
- the LDS 31 communicates with the SM-DS server 210 and uses the SM-DP+ server 220 capable of downloading an operational profile based on a provisioning profile from the SM-DS server 210. An operation of receiving an address may be performed.
- the LPD 33 performs a first communication connection 22 with the SM-DP + server 220 through a wireless communication network based on the address of the SM-DP + server 220, and the first communication connection An operation of receiving the first operational profile from the SM-DP+ server 220 may be performed through (22).
- the LPD 33 supports network-initiated profile download, enable, disable, delete, or profile policy rule (PPR) download operations, A profile activation, deactivation, deletion, or eUICC reset operation by an electronic device may be supported.
- PPR profile policy rule
- the LUI 35 may perform an operation of providing various user interfaces when the operational profile is downloaded.
- the LUI 35 may support data exchange between the LDS 31 and the LPD 33 and the user, and includes a UI that transfers the user's input to the LDS 31 or the LPD 33. can do.
- the processor 120 may perform a communication service based on information stored in the eSIM 201 using (or executing) the LPA 312 .
- the processor 120 includes the SM-DP+ server 220 and the first subscriber identification information through the communication module 190 based on the provisioning profile stored in the eSIM 201 using the LPA 312.
- a first communication connection for downloading a profile (eg, a first operational profile) may be performed.
- the processor 120 uses the LPA 312 to terminate the first communication connection when transmission or reception of a profile or data not including subscriber identification information is requested during the first communication connection, and the second communication connection is based on the second subscriber identification information.
- transmission or reception of a profile or data not including the subscriber identification information may be performed.
- the eSIM 201 may include one or a plurality of profiles as information for receiving a communication service.
- the profile may mean that at least one of an application stored in the eSIM 201, a file system, and an authentication key value is packaged in a software form (eg, packaged in a protected profile package (PPP) or bound profile package (BPP) form). there is.
- the profile may include a provisioning profile and an operational profile.
- the operational profile may include subscriber identification information, and in addition to subscriber identification information, the subscriber's network access authentication information, subscriber's phone book, subscriber's personal information (eg SMS), subscribed communication service provider name, available services, It may further include information that enables safe wireless communication use by performing subscriber authentication and traffic security key generation when accessing a wireless communication network such as available data amount, rate or service provision speed, or GSM, WCDMA, LTE, NR, etc. there is.
- an operational profile may include a SIM profile.
- the SIM profile may include a SIM file system (master file (MF), dedicated file (DF), elementary files (EF)), and subscriber identification information (IMSI) values may be stored in the elementary file (EF). there is.
- the provisioning profile may be a profile including first information for downloading the first operational profile in the electronic device.
- the first information may include communication session information for a first communication connection designated for downloading the first operational profile.
- the communication session information may include SM-DS server (eg, SM-DS server 210 of FIG. 2) access information for downloading the first operational profile, and may include SM-DS server access. It may include communication provider network information available for use.
- the communication module 190 may perform first communication based on a provisioning profile or second communication based on a second operational profile. At least one screen associated with the first communication based on the provisioning profile or the second communication based on the second operational profile may be displayed on the display module 160 .
- the LPA 312 has been described as a configuration included in the processor 120, but at least some functions of the LPA 312 are performed by the processor 120 or a separate LPA 312 It may also operate in conjunction with the processor 120 .
- LPA 312 may be included in a program (eg, program 140 of FIG. 1A ), may be loaded into processor 120 and executed, and LPA 312 may be loaded into processor 120 and executed. If it is, it can be understood as an operation of the processor 120.
- the functional modules included in the LPA 312 eg, the LDS 31, the LPD 33, or the LUI 35
- the LPA 312 may be included in the eSIM 201 .
- FIG. 4 is a diagram for explaining the internal structure of an eUICC according to an embodiment of the present disclosure.
- the eUICC 401 (eg, the eSIM 201 of FIG. 2 or 3) according to an embodiment may be in the form of a card or chip, and at least one profile 410, 420, 430 in software form can be installed According to various embodiments, each of the one or more profiles 410, 420, and 430 may be a provisioning profile or an operational profile. At least one of the profiles 410, 420, and 430 may operate on an eUICC operating system (OS) 450. Each of the at least one profile 410, 420, 430 is enabled or disabled by a processor or an LPA (eg, the LPA 312 of FIG. 3 or the LPA 480 of FIG. 4). can be In FIG. 4 , one profile 410 according to an embodiment may be in an enabled state, and the remaining profiles 420 and 430 may be in a disabled state.
- OS eUICC operating system
- the eUICC operating system (OS) 450 of the eUICC 401 may include a profile policy enabler 452, a profile package interpreter 454, and a telecom framework 456.
- the profile policy enabler 452 may manage a profile policy rule (PPR) for each of the at least one profile 410 , 420 , and 430 .
- the profile package interpreter 454 may install a profile package (eg, protected profile package (PPP) or bound profile package (BPP)) received from the SM-DP+ 220 into the eUICC 401. It can be unpackaged in any form.
- the telecom framework 456 may perform functions related to communication of applications within the eUICC 401.
- the eUICC 401 may include an issuer security domain root (ISD-R) 460 and an ECASD 470.
- the ISD-R (460) may manage at least one profile (410, 420, 430) installed in the eUICC (401).
- the ISD-R 460 may include LPA services 462, and the LPA services 462 may include a processor or an LPA (eg, the LPA 312 of FIG. 3 or the LPA 480 of FIG. 4). It is possible to manage at least one profile (410, 420, 430) installed in the eUICC (401) through an interface with.
- an eUICC controlling authority security domain (ECASD) 470 may perform security processing of at least one profile 410 , 420 , and 430 installed in the eUICC 401 .
- ECASD eUICC controlling authority security domain
- each of the at least one profile 410, 420, and 430 is an ISD-P (410-1, 420-1, or 430-1), an MNO-SD (410-2, 420-2, or 430-1). 2), SSD (supplementary security domain) (410-3, 420-3 or 430-3), CASD (controlling authority security domain) (410-4, 420-4 or 430-4), Applets (410-5, 420-5 or 430-5), network access applications (NAAs) (410-6, 420-6 or 430-6), file system (410-7, 420-7 or 430-7), or profile metadata (410 -8, 420-8 or 430-8).
- the ISD-P (410-1, 420-1, or 430-1) may include information for decoding and interpreting the profile package, and cooperate with the profile package interpreter (454) to SM-DP + (220). ) can be used for unpacking and installing the received profile package.
- the MNO-SD (410-2, 420-2, or 430-2) may include an over the air (OTA) key of MN0 and provide a secure OTA channel for communication with MN0. information may be included.
- OTA over the air
- a supplementary security domain (410-3, 420-3 or 430-3) and a controlling authority security domain (CASD) (410-4, 420-4 or 430-4) process security of a profile. It may contain information to perform.
- SSD supplementary security domain
- CASD controlling authority security domain
- the Applets 410-5, 420-5, or 430-5 may include various application information related to the user of the profile.
- network access applications (NAAs) 410-6, 420-6, or 430-6 may include application information allowing a profile to access a network.
- the file system (410-7, 420-7 or 430-7) may include a file system associated with each information of the profile.
- the profile metadata (410-8, 420-8, or 430-8) may also be referred to as a profile record, and may include metadata information about a profile in text form.
- the metadata information includes at least one of the profile's integrated circuit card ID (ICCID), profile name, name of the MNO providing the profile, user's profile nickname, icon, profile class, notification configuration information, profile owner information, or profile policy rules (PPRs).
- ICCID integrated circuit card ID
- profile name name
- name of the MNO providing the profile
- user's profile nickname providing the profile
- icon providing the profile
- profile class a profile class
- notification configuration information profile owner information
- profile policy rules PPRs
- the ICCID of a profile is a profile identifier and may represent a unique identifier of each profile.
- the profile name may include the name of each profile.
- the MNO name providing the profile may include the name of a telecommunications service provider providing the profile.
- the user's profile nickname may include a profile nickname designated by the user.
- the icon may include an icon corresponding to a profile.
- the profile class may include information indicating whether the type of profile is a provisioning profile or an operational profile.
- Notification configuration information may include the address of a server (eg, SM-DP+ server 220) to receive notification.
- the profile owner information may include mobile country code (MCC), mobile network code (MNC), and group identifier (GID) 1 or 2 information associated with the profile owner.
- a mobile country code may be a code for identifying a country
- a mobile network code may be a code for identifying a mobile communication operator.
- Group identifier (GID) 1 or 2 may be code area information for identifying a group or area to which the profile belongs. Regional information may include a group including a plurality of countries.
- a profile policy rule (PPR) may include policy rule information for managing a profile.
- the electronic device 101 includes profile metadata (410-8, 420-8 or 430-8) included in each of the at least one profile (410, 420, 430) included in the eUICC (401). It is possible to identify whether it is a provisioning profile or an operational profile using profile class information, and activates or activates a provisioning profile or an operational profile through an LPA (LPA 312 in FIG. can be deactivated.
- profile metadata 410-8, 420-8 or 430-8 or 430-8
- LPA LPA 312 in FIG.
- a network system includes an electronic device 101, a web server 510, a profile information delivery server 520, a profile providing server 530, an authentication server 540, or a setting server. (configuration server) 550 may be included. At least one of the web server 510, the profile information delivery server 520, the profile providing server 530, the authentication server 540, and the setting server 550 may be included in a communication service provider server managed by a communication service provider. there is. According to various embodiments, the web server 510 and the profile information delivery server 520 may be servers managed by the same communication service provider or different communication service providers.
- the profile information delivery server 520 and the profile providing server 530 may be servers managed by the same communication service provider or different communication service providers.
- the eSIM 201 may be inserted or built into the electronic device 101 .
- a profile may be downloaded and installed in the eSIM 201 .
- the electronic device 101 may access the web server 510 through the profile information delivery server 520 or directly access the profile information delivery server 520 .
- the profile information delivery server 520 authenticates the electronic device 101 or the user of the electronic device 101 through the authentication server 540. and conduct an eligibility test.
- the profile information delivery server 520 transmits information accessible to the web server 510 to the electronic device 101 when it is determined that the electronic device 101 or the user of the electronic device 101 is normally authenticated and qualified. can transmit
- the electronic device 101 can access the web server 510 using information accessible to the web server 510 received through the profile information delivery server 520 .
- the profile information delivery server 520 may be accessed through the web server 510, or the profile information delivery server 520 may be directly accessed without the web server 510.
- the web server 510 may provide a user interface (UI) or web page for the profile information delivery server 520 .
- the electronic device 101 may request subscription, opening, or line transfer for a specific profile through a web page provided from the web server 510 .
- the profile information delivery server 520 may manage and generate communication lines, control services, and provide status information.
- the profile information delivery server 520 may be referred to as an entitlement server, but is not limited to the term.
- the profile information delivery server 520 is a GSMA standard document TS.
- the profile information delivery server 520 transmits information related to a profile provided to the electronic device 101 (eg, profile download information (eg, address information of the profile providing server 530) or profile download related information). It can perform the function of transmission.
- profile information may include information related to the profile, and for convenience of description, it will be referred to as profile download information or profile download related information.
- the profile information delivery server 520 includes a discovery and push function (DPF), subscription manager discovery service (SM-DS), subscription manager secure routing (SM-SR), subscription manager secure routing plus (SM-SR+), off- It may include a card entity of eUICC Profile Manager or PMC holder (profile management credentials holder), or EM (eUICC manager), but is not limited thereto.
- DPF discovery and push function
- SM-DS subscription manager discovery service
- SM-SR subscription manager secure routing
- SM-SR+ subscription manager secure routing plus
- off- It may include a card entity of eUICC Profile Manager or PMC holder (profile management credentials holder), or EM (eUICC manager), but is not limited thereto.
- the profile providing server 530 may perform functions of managing and downloading profiles.
- the profile providing server 530 is SM-DP (subscription manager data preparation), SM-DP+ (subscription manager data preparation plus), off-card entity of Profile Domain, profile encryption server, profile creation server, profile provider ( It may include, but is not limited to, a profile provisioner (PP), a profile provider, or a PPC holder (profile provisioning credentials holder).
- SM-DP subscription manager data preparation
- SM-DP+ subscription manager data preparation plus
- off-card entity of Profile Domain profile encryption server
- profile creation server profile provider
- profile provider It may include, but is not limited to, a profile provisioner (PP), a profile provider, or a PPC holder (profile provisioning credentials holder).
- PP profile provisioner
- PPC holder profile provisioning credentials holder
- the setting server 550 may provide setting information to the electronic device 101 .
- the setting information provided by the setting server 550 may include communication operator information.
- the communication service provider information includes the address of the server (e.g., web server 510, profile information delivery server 520, profile providing server 530), supportable on device activation (ODA) function, and supportable authentication method (e.g., SMS (short message service)-OTP (one time password) authentication method, EAP-AKA (extensible authentication protocol for authentication and key agreement) authentication method), MCC (mobile country code) and MNC (mobile network code) of telecommunication service providers may contain at least one.
- subscription transfer means transfer of subscription information installed in a first electronic device (eg, an existing electronic device) to a second electronic device (eg, a new electronic device). It can mean to move.
- the movement of the line from the first electronic device to the second electronic device may have the same or similar result as the movement of the SIM card from the first electronic device to the second electronic device.
- the first profile installed in the first electronic device may be processed to be unusable according to the line movement, and the second A second profile corresponding to the first profile may be newly installed in the electronic device.
- the second profile may include at least a part of the same or similar information (eg, the same or similar subscription information) as the first profile.
- the second profile may include the same subscription conditions (eg, billing conditions) as the first profile, and may include subscription conditions similar to or different from those of the first profile as the subscription conditions are changed when the line is moved.
- line migration for a profile installed in the eSIM 201 is described, but according to various embodiments, the same or similar method may be applied to line migration for a UICC.
- FIGS. 6A and 6B are signal flow diagrams between devices illustrating a line transfer method according to various embodiments of the present disclosure. Referring to FIGS. 6A and 6B , as line transfer is performed from the first electronic device 101a to the second electronic device 101b as described below, the eSIM 201 of the first electronic device 101a A second profile corresponding to the installed first profile may be installed in the eSIM 201 of the second electronic device 101b.
- the first electronic device 101a may download setting information from the setting server 550 in operation 602 .
- the setting information downloaded from the setting server 550 may include communication operator information.
- the communication service provider information includes the address of the server (e.g., web server 510, profile information delivery server 520, profile providing server 530), supportable on device activation (ODA) function, and supportable authentication method (e.g., At least one of SMS (short message service)-OTP (one time password) authentication method, EAP-AKA (extensible authentication protocol authentication and key agreement) authentication method), MCC (mobile country code) and MNC (mobile network code) of the telecommunication service provider can contain one
- SMS short message service
- ODA supportable on device activation
- MCC mobile country code
- MNC mobile network code
- the first electronic device 101a may be connected to the second electronic device 101b through short-range wireless communication in operation 604 .
- the short-range wireless communication is infrared data association (IrDA), Bluetooth, bluetooth low energy (BLE), WiFi, WiFi direct, ultra wide band (UWB), or near field (NFC) communication), but is not limited thereto.
- the first electronic device 101a and the second electronic device 101b are connected via a wired cable (eg, universal serial port (USB) instead of the short-range wireless communication).
- bus may be connected by a cable).
- data transmitted/received by short-range wireless communication between the first electronic device 101a and the second electronic device 101b may be transmitted/received through the wired cable.
- FIG. 7A, 7b, and 7c are views illustrating a user interface displayed on a screen of a new electronic device according to various embodiments of the present disclosure.
- the screen 710 of the second electronic device 101b appears as shown in FIG. 7A.
- Information 711 indicating connection with the first electronic device 101a may be displayed.
- information 711 indicating connection with the first electronic device 101a is information for preparing a job related to line movement for a profile stored in the first electronic device 101a (eg, “ Check your old phone to start the data transfer”).
- the first electronic device 101b is displayed on the screen 710 of the second electronic device 101b as shown in FIG. 7B.
- a guide message for bringing data from the electronic device 101a eg, a guide message for moving a line
- the guide message is information inducing unlocking the first electronic device 101a and turning on the corresponding plan (eg, “To bring your mobile plan, unlock your old phone and turn on your plan”) 720 may be further included.
- a button eg, “continue” button
- a line transfer procedure described later may proceed.
- a button eg, “skip” button
- the second electronic device 101b may request line information from the connected first electronic device 101a in operation 606 .
- the first electronic device 101a identifies movable line information among profiles stored in the eSIM in operation 608. Whether the line information for the profiles stored in the first electronic device 101a can be moved can be checked based on the information received from the setting server 550 in operation 602 described above.
- the first electronic device 101a may transmit the identified movable line information to the second electronic device 101b.
- the second electronic device 101b identifies a list of profiles corresponding to the movable line information received from the first electronic device 101a in operation 612 and, as shown in FIG. 7C, provides information corresponding to the corresponding profile. It can be displayed on the screen 730.
- the second electronic device 101b displays an image 731 corresponding to a movable profile from the first electronic device 101a and a button for requesting line movement for the profile ( 732) (eg, a “Bring and use it now” button) may be displayed on the screen 730.
- FIG. 7C illustrates the case of one movable profile, if there are a plurality of movable profiles, a list corresponding to the plurality of movable profiles may be displayed on the screen 730 .
- the second electronic device 101b may provide a menu for selecting a service provider on the screen 730 .
- the second electronic device 101b when the user selects the button 732 for requesting line movement for a specific profile on the screen 730, the second electronic device 101b corresponds to the selection of the button 732.
- the line information for the specific profile can be identified as line information for movement request.
- the second electronic device 101b identifies the line information for the specific profile selected as described above as line information to request movement, and in operation 616, the line information to request movement (eg, information corresponding to the profile) may be transmitted to the first electronic device 101a.
- the line information to request movement eg, information corresponding to the profile
- the second electronic device 101b transfers the information of the second electronic device 101b to the first electronic device 101a through operation 604, operation 606, operation 616 or a separately added operation.
- the information of the second electronic device 101b may include identification information of the second electronic device 101b.
- the identification information of the second electronic device 101b is an international mobile subscriber identity (IMSI), an eUICC identity (EID), an international mobile equipment identity (IMEI), an integrated circuit card identity (ICCID), or a mobile station international ISDN number (MSISDN).
- IMSI international mobile subscriber identity
- EID eUICC identity
- IMEI international mobile equipment identity
- ICCID integrated circuit card identity
- MSISDN mobile station international ISDN number
- the second electronic device 101b when the first electronic device 101a transmits an authentication token and/or information for line movement to the second electronic device 101b as will be described later, the second electronic device 101b is identified.
- the authentication token and/or information for line transfer may be encrypted using at least a portion of the information and then transmitted to the second electronic device 101b.
- the second electronic device 101b receives the encrypted authentication token and/or information for line movement from the first electronic device 101a, and receives the information of the second electronic device 101b (eg, the second electronic device 101b).
- the encrypted authentication token and/or information for line transfer may be decrypted using at least a part of identification information of the device 101b.
- FIGS. 6A and 101b An embodiment of encrypting the authentication token and/or information for line movement using the identification information of the second electronic device 101b and then transmitting the information to the second electronic device 101b is illustrated in FIGS. 6A and 101b.
- FIGS. 6B An embodiment of encrypting the authentication token and/or information for line movement using the identification information of the second electronic device 101b and then transmitting the information to the second electronic device 101b is illustrated in FIGS. 6A and 101b.
- FIG. 6B the same or similar method may be applied to other embodiments to be described later (eg, the embodiments of FIGS. 12A and 12B ).
- the first electronic device 101a may perform authentication for line transfer according to a line transfer request for a profile selected by the second electronic device 101b.
- the first electronic device 101a may perform authentication for line transfer with the authentication server 540 through the profile information delivery server 520 .
- the authentication method for circuit movement may include an extensible authentication protocol for authentication and key agreement (EAP-AKA) authentication method.
- EAP-AKA authentication method is relatively secure compared to other types of authentication methods (eg, SMS-OTP), and can provide intuitive and simple line transfer without requiring additional information input by the user.
- Operations 618 to 626 in FIG. 6A may operate according to the EAP-AKA authentication scheme.
- the EAP-AKA authentication method is a GSMA standard document TS. At least a part of the EAP-AKA authentication method disclosed in 43 may be included.
- the first electronic device 101a may request authentication from the profile information delivery server 520 in operation 618 .
- the first electronic device 101a may request authentication based on the EAP-AKA authentication method to the profile information delivery server 520 .
- the first electronic device 101a may transmit an authentication request including the IMSI, IMEI, or a combination thereof of the first electronic device 101a to the profile information delivery server 520 .
- the profile information delivery server 520 may transmit a challenge to the first electronic device 101a in response to the authentication request in operation 620 .
- the challenge may be an arbitrary number for authenticating the eSIM 201 of the first electronic device 101a.
- the first electronic device 101a may obtain a payload for the challenge based on information stored in the eSIM 201 .
- the first electronic device 101a may calculate and obtain a payload for a challenge based on the authentication key value of the eSIM 201 .
- the first electronic device 101a may transmit the payload obtained based on the eSIM 201 to the profile information delivery server 520 in operation 624 .
- the profile information delivery server 520 may receive a payload from the first electronic device 101a and perform authentication through the authentication server 540 .
- the authentication server 540 may determine whether authentication succeeds by comparing a value obtained by converting a challenge based on a key previously designated for the eSIM 201 of the first electronic device 101a with a payload.
- the authentication server 540 may determine that authentication is successful when a value obtained by converting a challenge based on a key previously designated for the eSIM 201 is identical to a payload.
- the first electronic device 101a may perform the above-described EAP-AKA authentication for the eSIM 201 for the UICC included in the first electronic device 101a.
- the first electronic device 101a may perform line transfer to the second electronic device 101b for subscription information stored in the UICC by performing EAP-AKA authentication on the UICC.
- the profile information delivery server 520 sends an authentication token as a payload result in operation 606 to the first electronic device ( 101a).
- the first electronic device 101a transmits the information of the second electronic device 101b through the above-described EAP-AKA authentication operation (eg, operations 618 to 626) or a separately added operation. It can be transmitted to the profile information delivery server 520.
- the information of the second electronic device 101b may include identification information of the second electronic device 101b.
- the identification information of the second electronic device 101b is an international mobile subscriber identity (IMSI), an eUICC identity (EID), an international mobile equipment identity (IMEI), an integrated circuit card identity (ICCID), or a mobile station international ISDN number (MSISDN).
- IMSI international mobile subscriber identity
- EID eUICC identity
- IMEI international mobile equipment identity
- ICCID integrated circuit card identity
- MSISDN mobile station international ISDN number
- the profile information delivery server 520 when receiving a line transfer request from the second electronic device 101b, receives the second electronic device 101a from the first electronic device 101a. The validity of the second electronic device 101b may be verified using at least some of the identification information of the device 101b.
- the first electronic device 101a may transmit the acquired authentication token to the second electronic device 101b when the EAP-AKA authentication is normally completed as described above.
- the first electronic device 101a may transmit information for line movement including the authentication token to the second electronic device 101b through short-range wireless communication or a wired cable.
- the information for line transfer may include information about the first electronic device 101a.
- the information about the first electronic device 101a may include a mobile country code (MCC) and mobile network code (MNC), international mobile subscriber identity (IMSI), and EID identified from profile information stored in the eSIM 201.
- the information for line movement transmitted from the first electronic device 101a to the second electronic device 101b may be encrypted and transmitted.
- the token information and/or the information for line transfer is encrypted using at least a part of the identification information of the second electronic device 101b received from the second electronic device 101b as described above. It can be. For example, when the first electronic device 101a transmits token information and/or line movement information to the second electronic device 101b, at least a part of the identification information of the second electronic device 101b is used.
- the token information and/or the information for line transfer may be encrypted and then transmitted to the second electronic device 101b.
- the second electronic device 101b receives the encrypted token information and/or the line transfer information from the first electronic device 101a, and receives the information of the second electronic device 101b (eg, the second electronic device 101b).
- the encrypted token information and/or the information for line movement may be decrypted using at least a part of the identification information of the electronic device 101b.
- the second electronic device 101b that has received information for line transfer from the first electronic device 101a communicates with the profile information delivery server 520 based on the received information for line transfer. You can perform procedures for line transfer. For example, in operation 630, the second electronic device 101b may check access rights to the profile information delivery server 520 through the profile information delivery server 520. For example, the second electronic device 101b has the authority to access the profile information delivery server 520 (or the communication service provided by the profile information delivery server 520 after accessing the profile information delivery server 520). The authentication token may be transmitted to the profile information delivery server 520 in order to confirm the right to use).
- the second electronic device 101b may transmit information (eg, IMEI of the first electronic device 101a) of the first electronic device 101a to the profile information delivery server 520. .
- the second electronic device 101b transmits, to the profile information delivery server 520, information other than the IMEI of the first electronic device 101a, the protocol version, and the manufacturer of the first electronic device 101a. At least one of (vendor), model name, and software version may be further transmitted.
- the profile information delivery server 520 provides the second electronic device 101b with access rights to the profile information delivery server 520 based on the information transmitted from the second electronic device 101b. You can check whether it exists or not.
- the profile information delivery server 520 provides at least information received from the first electronic device 101a and information received from the second electronic device 101b during an authentication process with the first electronic device 101a. Based on a part, whether or not the access authority of the second electronic device 101b may be checked. According to various embodiments, when the profile information delivery server 520 determines that the second electronic device 101b has authority to access the profile information delivery server 520, the second electronic device 101b The second electronic device 101b may transmit information indicating that it has authority to access the profile information delivery server 520. On the other hand, if the profile information delivery server 520 determines that the second electronic device 101b does not have the authority to access the profile information delivery server 520, the authority to access the second electronic device 101b is granted.
- Information indicating "no" may be transmitted, or a uniform resource locator (URL) may be transmitted so that the second electronic device 101b displays the web page of the profile information delivery server 520 or the web page of the web server 510.
- a uniform resource locator URL
- a guide message may be displayed on the screen.
- the second electronic device 101b may request a line transfer to the profile information delivery server 520 after the authority check is completed in operation 632 .
- the second electronic device 101b receives information indicating that the second electronic device 101b has authority to access the profile information delivery server 520 from the profile information delivery server 520.
- information requesting line transfer may be transmitted to the profile information delivery server 520 .
- the profile information delivery server 520 may transmit information for confirming line movement to the second electronic device 101b in operation 634 .
- the profile information delivery server 520 to the second electronic device 101b, information indicating that line transfer will occur, information of the first electronic device 101a (eg, information of the first electronic device 101a) IMEI), information of the second electronic device 101b (eg, IMEI of the second electronic device 101b), or mobile station international ISDN number (MSISDN) of the first electronic device 101a.
- MSISDN mobile station international ISDN number
- the second electronic device 101b may transmit information indicating confirmation of line movement to the profile information delivery server 520.
- the information indicating the confirmation of line movement may include an authentication token received as a result of EAP-AKA authentication of the first electronic device 101a.
- the second electronic device 101b transmits information indicating confirmation of line movement in operation 636 using the URL of the web page received from the profile information delivery server 520 in operation 634, so that the profile information delivery server ( 520) may receive web page information.
- the second electronic device 101b receives web page information from the profile information delivery server 520 and, through a display (eg, the display module 160 of FIG. 1A ), line transfer occurs.
- At least one of the information representing the first electronic device 101a, the information of the second electronic device 101b, or the MSISDN of the first electronic device 101a may be displayed.
- the information displayed on the screen of the second electronic device 101b through the web page information received from the profile information delivery server 520 is not limited to the above example.
- the second electronic device 101b may include information indicating that the line transfer will occur, information on the first electronic device 101a, information on the second electronic device 101b, or information on the first electronic device 101b ( While displaying at least one of the MSISDNs of step 101a) on the screen through the web page, a user input confirming line transfer (or agreeing to line transfer) may be received.
- the profile information delivery server 520 may confirm the user input for confirming the line movement.
- the profile information delivery server 520 may request the profile providing server 530 to generate (or prepare) a second profile in operation 638 .
- the first electronic device 101a determines whether the second electronic device 101b is a valid device by using at least a part of the identification information of the second electronic device 101b received from the electronic device 101b.
- the profile information delivery server 520 checks whether the second electronic device 101b is a valid device using at least a part of the identification information of the second electronic device 1010b, so that the other than the second electronic device 101b It is possible to prevent the case where the authentication token is stolen and used by the device.
- An embodiment in which the profile information delivery server 520 checks whether the second electronic device 101b is a valid device by using at least a part of the identification information of the second electronic device 1010b is not limited to the aforementioned FIGS. 6A and 6B . However, the same or similar method may be applied to other embodiments described later (eg, the embodiments of FIGS. 12A and 12B ).
- the profile providing server 530 generates a second profile in response to receiving a request to create a second profile from the profile information delivery server 520, and the generated second profile may be transmitted to the second electronic device 101b.
- the profile information delivery server 520 may transmit second profile download information to the second electronic device 101b in operation 640 .
- the second profile download information transmitted from the profile information delivery server 520 to the second electronic device 101b may include the address of the profile providing server 530 .
- operations 634 and 636 described above may be omitted.
- the profile information delivery server 520 receives the line transfer request from the second electronic device 101b.
- second profile download information may be transmitted to the second electronic device 101b in operation 640.
- the second electronic device 101b in operation 642, based on the second profile download information (eg, address information of the profile providing server 530) received from the profile information delivery server 520
- a second profile may be downloaded from the profile providing server 530 .
- the second profile may be packaged in a software form (eg, packaged in a protected profile package (PPP) or bound profile package (BPP) form) and transmitted to the second electronic device 101b.
- the second electronic device 101b may store or install the second profile received from the profile providing server 530 in the eSIM 201 .
- the second electronic device 101b may download a second profile packaged in a PPP or BPP form from the profile providing server 530 and install it in an eUICC (eg, the eUICC 401 of FIG. 4 ).
- the profile package interpreter 454 described above in FIG. 4 may install in the eUICC 401 after unpacking the PPP or BPP including the second profile received from the profile providing server 530. .
- the second electronic device 101b may request line renewal to the profile information delivery server 520 in operation 644. .
- the profile information delivery server 520 receives the line update request from the second electronic device 101b, and in operation 646 deactivates the first profile installed in the first electronic device 101a. (deactivate) (or disable).
- the profile information delivery server 520 may transmit a message about line update completion to the second electronic device 101b in operation 648 .
- the second electronic device 101b may activate the second profile installed in the eSIM 201 .
- the second electronic device 101b After the second electronic device 101b receives a response signal (eg, line update completion message) for line update from the profile information delivery server 520 in operation 648, the second electronic device 101b transmits the second electronic device 101b to the eSIM 201.
- Profiles can be activated.
- the second electronic device 101b may use a network (eg, a cellular network) provided by a communication service provider associated with the profile information providing server 520 by using the second profile activated in operation 650 .
- operations 644 to 648 may be omitted.
- the profile information delivery server 520 transmits a second profile creation request to the profile providing server 530 in operation 638, the profile providing server 530 or the profile information delivery server 520 1 profile can be deactivated.
- an electronic device 101 eg, a first electronic device 101a
- an external electronic device eg, a second electronic device 101b
- an electronic device may be connected to an external electronic device through short-range wireless communication.
- the electronic device may receive a line information request for line transfer from the external electronic device.
- the electronic device may check at least one movable line information from profile information in response to receiving the line information request.
- the electronic device may transmit at least one movable line information to an external electronic device.
- the electronic device may receive information about a line to be moved selected from among information on at least one line capable of being moved from an external electronic device.
- the electronic device may request authentication for the line to be moved selected by the external electronic device to a server (eg, the profile information delivery server 520).
- a server eg, the profile information delivery server 520.
- the authentication request may include an authentication request based on an extensible authentication protocol for authentication and key agreement (EAP-AKA) authentication method.
- EAP-AKA extensible authentication protocol for authentication and key agreement
- the electronic device may receive information corresponding to an authentication result from the server in response to the authentication request.
- the information corresponding to the authentication result may include an authentication token.
- the electronic device may transmit information for line transfer including information corresponding to the authentication result to an external electronic device.
- the information for line transfer may include information about the electronic device.
- the information about the electronic device includes a mobile country code (MCC) and a mobile network code (MNC) identified from the profile information, an international mobile subscriber identity (IMSI), an eUICC identity (EID), an international mobile equipment identity (IMEI), It may include at least one of an integrated circuit card identity (ICCID) and a product model name.
- MCC mobile country code
- MNC mobile network code
- IMSI international mobile subscriber identity
- EID eUICC identity
- IMEI international mobile equipment identity
- ICCID integrated circuit card identity
- FIGS. 9A and 9B are signal flow diagrams between devices illustrating a line transfer method according to various embodiments of the present disclosure. Referring to FIGS. 9A and 9B , as line movement is performed from the first electronic device 101a to the second electronic device 101b, the first profile installed in the eSIM 201 of the first electronic device 101a A second profile corresponding to may be installed in the eSIM 201 of the second electronic device 101b.
- the first electronic device 101a may download setting information from the setting server 550 in operation 902 .
- the setting information downloaded from the setting server 550 may include communication operator information.
- the communication service provider information includes the address of the server (e.g., web server 510, profile information delivery server 520, profile providing server 530), supportable on device activation (ODA) function, and supportable authentication method (e.g., At least one of SMS (short message service)-OTP (one time password) authentication method, EAP-AKA (extensible authentication protocol authentication and key agreement) authentication method), MCC (mobile country code) and MNC (mobile network code) of the telecommunication service provider can contain one
- SMS short message service
- ODA supportable on device activation
- MCC mobile country code
- MNC mobile network code
- the first electronic device 101a may select a line to move to the second electronic device 101b based on profile information stored in the eSIM 201 in operation 904 . For example, as shown in FIG. 10A , when a SIM card manager app is executed in the first electronic device 101a, a SIM card manager screen 1010 may be displayed.
- FIGS. 10A, 10B, and 10C are diagrams illustrating a user interface displayed on the screen of the first electronic device 101a according to various embodiments of the present disclosure.
- information 1011 on the physical SIM installed in the first electronic device 101a and information 1012 on the eSIM are displayed on the SIM card manager screen 1010.
- an eSIM setting screen 1020 may be displayed as shown in FIG. 10B.
- the setting screen 1020 for the eSIM may include a menu (Transfer to New Device) 1021 for moving a line corresponding to the corresponding profile to a new electronic device (eg, the second electronic device 101b). .
- the first electronic device 101a may perform authentication for the line transfer according to the line transfer request for the selected profile.
- the first electronic device 101a may perform authentication for line transfer with the authentication server 540 through the profile information delivery server 520 .
- the authentication method for the line transfer may include an extensible authentication protocol authentication and key agreement (EAP-AKA) authentication method.
- EAP-AKA authentication method is relatively secure compared to other types of authentication methods (eg, SMS-OTP), and can provide intuitive and simple line transfer without requiring additional information input by the user.
- Operations 906 to 914 in FIG. 9A may operate according to the EAP-AKA authentication scheme.
- the EAP-AKA authentication method is a GSMA standard document TS. At least a part of the EAP-AKA authentication method disclosed in 43 may be included.
- the first electronic device 101a may request authentication from the profile information delivery server 520 in operation 906 .
- the first electronic device 101a may request authentication based on the EAP-AKA authentication method to the profile information delivery server 520 .
- the first electronic device 101a may transmit an authentication request including the IMSI, IMEI, or a combination thereof of the first electronic device 101a to the profile information delivery server 520 .
- the profile information delivery server 520 may transmit a challenge to the first electronic device 101a in response to the authentication request in operation 908 .
- the challenge may be an arbitrary number for authenticating the eSIM 201 of the first electronic device 101a.
- the first electronic device 101a may obtain a payload for the challenge based on information stored in the eSIM 201 .
- the first electronic device 101a may calculate and obtain a payload for a challenge based on an authentication key value of the eSIM 201 .
- the first electronic device 101a may transmit the payload acquired based on the eSIM 201 to the profile information delivery server 520 in operation 912 .
- the profile information delivery server 520 may receive a payload from the first electronic device 101a and perform authentication through the authentication server 540 .
- the authentication server 540 may determine whether authentication succeeds by comparing a value obtained by converting a challenge based on a key previously designated for the eSIM 201 of the first electronic device 101a with a payload.
- the authentication server 540 may determine that authentication is successful when a value obtained by converting a challenge based on a key previously designated for the eSIM 201 is identical to a payload.
- the profile information delivery server 520 sends an authentication token as a payload result in operation 914 to the first electronic device ( 101a).
- the first electronic device 101a transmits information for line transfer including the acquired authentication information (eg, authentication token) in operation 916. can be displayed on the screen.
- the first electronic device 101a may generate a QR code 1031 on the screen based on the authentication information and information for line movement, and the generated QR code can be displayed on the screen.
- the information for line transfer may include information about the first electronic device 101a.
- the information about the first electronic device 101a may include a mobile country code (MCC) and mobile network code (MNC), international mobile subscriber identity (IMSI), and EID identified from profile information stored in the eSIM 201. It may include at least one of (eUICC identity), international mobile equipment identity (IMEI), integrated circuit card identity (ICCID), and product model name.
- the second electronic device 101b may acquire information for line movement in operation 918 by scanning the QR code 1031 displayed on the first electronic device 101a.
- a cancel button eg, “Cancel button” 1032 on the screen shown in FIG. 10C
- the line transfer process can be canceled.
- the cancel button 1032 when the cancel button 1032 is selected, the second electronic device 101b can delete the acquired information for line transfer.
- the second electronic device 101b may perform a line transfer procedure based on the received information for line transfer.
- operations 920, 922, 924, 926, 928, and 930 of FIG. 9B are the same as operations 630, 632, 634, 636, 638, and 640 of FIG. 6B, respectively.
- operations 630, 632, 634, 636, 638, and 640 of FIG. 6B are the same as operations 630, 632, 634, 636, 638, and 640 of FIG. 6B, respectively.
- detailed description will be omitted.
- the second electronic device 101b performs the above operation 932 based on the second profile download information (eg, address information of the profile providing server 530) received from the profile information delivery server 520.
- a second profile may be downloaded from the profile providing server 530 .
- the second profile may be packaged in a software form (eg, packaged in a protected profile package (PPP) or bound profile package (BPP) form) and transmitted to the second electronic device 101b.
- the second electronic device 101b may store or install the second profile received from the profile providing server 530 in the eSIM 201 .
- the second electronic device 101b may download a second profile packaged in a PPP or BPP form from the profile providing server 530 and install it in an eUICC (eg, the eUICC 401 of FIG. 4 ).
- the profile package interpreter 454 described above in FIG. 4 may install in the eUICC 401 after unpacking the PPP or BPP including the second profile received from the profile providing server 530. .
- the second electronic device 101b may request line renewal to the profile information delivery server 520 in operation 934.
- the profile information delivery server 520 receives the line update request from the second electronic device 101b, and in operation 936 deactivates the first profile installed in the first electronic device 101a. (deactivate) (or disable).
- the profile information delivery server 520 may transmit a message about line update completion to the second electronic device 101b in operation 938 .
- the second electronic device 101b may activate the second profile installed in the eSIM 201 .
- the second electronic device 101b After the second electronic device 101b receives a response signal (eg, line update completion message) for line update from the profile information delivery server 520 in operation 938, the second electronic device 101b transmits the second electronic device 101b to the eSIM 201.
- Profiles can be activated.
- the second electronic device 101b may use a network (eg, a cellular network) provided by a communication service provider associated with the profile information providing server 520 by using the second profile activated in operation 940 .
- operations 934 to 938 may be omitted.
- the profile information delivery server 520 transmits a second profile creation request to the profile providing server 530 in operation 928, the profile providing server 530 or the profile information delivery server 520 1 profile can be deactivated.
- the electronic device 101 may display at least one line information based on stored profile information in operation 1110.
- the electronic device may receive a selection of a line to be moved to an external electronic device (eg, the second electronic device 101b) from among the displayed at least one piece of line information in operation 1120 .
- an external electronic device eg, the second electronic device 101b
- the electronic device may request authentication for the line to be moved selected by the external electronic device to a server (eg, the profile information delivery server 520).
- a server eg, the profile information delivery server 520.
- the authentication request may include an authentication request based on an extensible authentication protocol authentication and key agreement (EAP-AKA) authentication method.
- EAP-AKA extensible authentication protocol authentication and key agreement
- the electronic device may receive information corresponding to an authentication result from the server in response to the authentication request.
- the information corresponding to the authentication result may include an authentication token.
- the electronic device may display information for line transfer including information corresponding to the authentication result on the screen.
- the electronic device 101 may generate a QR code 1031 on the screen based on the authentication information and information for line movement, and display the generated QR code on the screen.
- the information for line transfer may include information about the electronic device 101 .
- the information about the electronic device includes a mobile country code (MCC) and a mobile network code (MNC) identified from the profile information, an international mobile subscriber identity (IMSI), an eUICC identity (EID), an international mobile equipment identity (IMEI), It may include at least one of an integrated circuit card identity (ICCID) and a product model name.
- MCC mobile country code
- MNC mobile network code
- IMSI international mobile subscriber identity
- EID eUICC identity
- IMEI international mobile equipment identity
- It may include at least one of an integrated circuit card identity (ICCID) and a product model name.
- the first electronic device 101a may download setting information from the setting server 550 in operation 1202 .
- the setting information downloaded from the setting server 550 may include communication operator information.
- the communication service provider information includes the address of the server (e.g., web server 510, profile information delivery server 520, profile providing server 530), supportable on device activation (ODA) function, and supportable authentication method (e.g., At least one of SMS (short message service)-OTP (one time password) authentication method, EAP-AKA (extensible authentication protocol authentication and key agreement) authentication method), MCC (mobile country code) and MNC (mobile network code) of the telecommunication service provider may contain one.
- the server e.g., web server 510, profile information delivery server 520, profile providing server 530
- ODA supportable on device activation
- supportable authentication method e.g., At least one of SMS (short message service)-OTP (one time password) authentication method, EAP-AKA (extensible authentication protocol authentication and key agreement) authentication method), MCC (mobile country code) and MNC (mobile network code) of the telecommunication service provider may contain one.
- the first electronic device 101a may select a line to be moved to the second electronic device 101b based on the profile information stored in the eSIM 201 in operation 1204 .
- a SIM card manager screen 1010 may be displayed.
- 10A, 10B, and 10C illustrate a user interface displayed on a screen of a first electronic device 101a according to various embodiments.
- Information 1011 on the physical SIM installed in the first electronic device 101a and information 1012 on the eSIM may be displayed on the SIM card manager screen 1010 .
- the eSIM information 1012 is selected in FIG.
- an eSIM setting screen 1020 may be displayed as shown in FIG. 10B.
- the setting screen 1020 for the eSIM may include a menu (Transfer to New Device) 1021 for moving a line corresponding to the corresponding profile to a new electronic device (eg, the second electronic device 101b). .
- a user when a user selects a menu 1021 capable of moving a line corresponding to the corresponding profile to a new electronic device (eg, the second electronic device 101b), the corresponding profile as described later. It is possible to perform a line transfer procedure corresponding to .
- the first electronic device 101a may establish a short-range communication connection with the second electronic device 101b in operation 1206 according to the line transfer request for the selected profile.
- the short-range wireless communication includes infrared data association (IrDA), Bluetooth, bluetooth low energy (BLE), WiFi, WiFi direct, ultra wide band (UWB), and near field communication (NFC). ), but is not limited thereto.
- the first electronic device 101a and the second electronic device 101b are connected via a wired cable (eg, universal serial port (USB) instead of the short-range wireless communication).
- bus may be connected by a cable).
- data transmitted and received between the first electronic device 101a and the second electronic device 101b through short-range wireless communication may be transmitted and received through the wired cable.
- the first electronic device 101a requests device information on a new electronic device (eg, the second electronic device 101b) from the second electronic device 101b through the short-range communication in operation 1208.
- the second electronic device 101b transmits device information about the second electronic device 101b to the first electronic device 101a through the short-range communication in operation 1210 according to the request of the first electronic device 101a.
- the device information on the second electronic device 101b may include at least one of EID and IMEI, but is not limited thereto.
- the first electronic device 101a performs line transfer with the authentication server 540 through the profile information delivery server 520 based on the received device information on the second electronic device 101b. authentication can be performed.
- the authentication method for the line transfer may include an extensible authentication protocol authentication and key agreement (EAP-AKA) authentication method.
- EAP-AKA authentication method is relatively secure compared to other types of authentication methods (eg, SMS-OTP), and can provide intuitive and simple line transfer without requiring additional information input by the user.
- operations 1212 to 1220 may operate according to the EAP-AKA authentication method.
- the EAP-AKA authentication method is a GSMA standard document TS. At least a part of the EAP-AKA authentication method disclosed in 43 may be included.
- the first electronic device 101a may request authentication from the profile information delivery server 520 in operation 1212 .
- the first electronic device 101a may request authentication based on the EAP-AKA authentication method to the profile information delivery server 520 .
- the first electronic device 101a may transmit an authentication request including IMSI, IMEI, or a combination thereof of the first electronic device 101a to the profile information delivery server 520 .
- the profile information delivery server 520 may transmit a challenge to the first electronic device 101a in response to the authentication request in operation 1214 .
- the challenge may be an arbitrary number for authenticating the eSIM 201 of the first electronic device 101a.
- the first electronic device 101a may obtain a payload for the challenge based on information stored in the eSIM 201 .
- the first electronic device 101a may calculate and obtain a payload for a challenge based on the authentication key value of the eSIM 201 .
- the first electronic device 101a may transmit the payload obtained based on the eSIM 201 to the profile information delivery server 520 in operation 1218 .
- the profile information delivery server 520 may receive a payload from the first electronic device 101a and perform authentication through the authentication server 540 .
- the authentication server 540 may determine whether authentication succeeds by comparing a value obtained by converting a challenge based on a key previously designated for the eSIM 201 of the first electronic device 101a with a payload.
- the authentication server 540 may determine that authentication is successful when a value obtained by converting a challenge based on a key previously designated for the eSIM 201 is identical to a payload.
- the profile information delivery server 520 sends an authentication token as a payload result value in operation 1220 to the first electronic device ( 101a).
- the first electronic device 101a may perform a line transfer procedure based on the authentication result. For example, in operation 1222, the first electronic device 101a may check access rights to the profile information delivery server 520 through the profile information delivery server 520. For example, the first electronic device 101a has the authority to access the profile information delivery server 520 (or the communication service provided by the profile information delivery server 520 after accessing the profile information delivery server 520). The authentication token may be transmitted to the profile information delivery server 520 in order to confirm the right to use). According to various embodiments, the first electronic device 101a may transmit information (eg, IMEI of the first electronic device 101a) of the first electronic device 101a to the profile information delivery server 520. .
- information eg, IMEI of the first electronic device 101a
- the first electronic device 101a in addition to the IMEI of the first electronic device 101a to the profile information delivery server 520, the protocol version and the manufacturer of the first electronic device 101a. At least one of (vendor), model name, and software version may be further transmitted.
- the profile information delivery server 520 has access authority for the profile information delivery server 520 by the first electronic device 101a based on the information transmitted from the first electronic device 101a. You can check whether it exists or not. For example, when the profile information delivery server 520 determines that the first electronic device 101a has authority to access the profile information delivery server 520, the first electronic device 101b transmits the first electronic device 101b to the first electronic device 101b.
- the electronic device 101a may transmit information indicating that it has authority to access the profile information delivery server 520 .
- the profile information delivery server 520 determines that the first electronic device 101a does not have the authority to access the profile information delivery server 520, the authority to access the first electronic device 101a is granted.
- Information indicating that there is none may be transmitted, or a URL may be transmitted so that the first electronic device 101a displays the web page of the profile information delivery server 520 or the web page of the web server 510 .
- the first electronic device 101a may request a line transfer to the profile information delivery server 520 after the authority check in operation 1222 is completed. For example, the first electronic device 101a receives information indicating that the first electronic device 101a has authority to access the profile information delivery server 520 from the profile information delivery server 520. In response, information requesting line transfer may be transmitted to the profile information transmission server 520 .
- the profile information delivery server 520 transmits information for checking line movement and a new electronic device (eg, the second electronic device 101b) to which line movement is performed, to the first electronic device 101a. You can request information about a new electronic device (eg, the second electronic device 101b) to which line movement is performed, to the first electronic device 101a. You can request information about a new electronic device (eg, the second electronic device 101b) to which line movement is performed, to the first electronic device 101a. You can request information about
- the first electronic device 101a may transmit information indicating confirmation of line movement and information of a new electronic device to the profile information delivery server 520 at the request of the profile information delivery server 520.
- the information on the new electronic device may include at least one of EID and IMEI of the second electronic device 101b, but is not limited thereto.
- the profile information delivery server 520 when the profile information delivery server 520 receives new electronic device information and line movement confirmation information from the first electronic device 101a, the profile information delivery server 520 operates In operation 1230, the profile providing server 530 may be requested to create (or prepare) a second profile. According to various embodiments, the profile providing server 530 may create a second profile in response to receiving a request to create a second profile from the profile information delivery server 520 .
- the profile information delivery server 520 may transmit second profile download information to the first electronic device 101a in operation 1232 .
- the second profile download information transmitted from the profile information delivery server 520 to the first electronic device 101a may include the address of the profile providing server 530 .
- the first electronic device 101a transmits the second profile download information (eg, address information of the profile providing server 530) received from the profile information delivery server 520 in operation 1234 to the second electronic device 101a. may be sent to device 101b.
- the first electronic device 101a receives the second electronic device 101b from the second electronic device 101b before the operation 1234.
- information eg, identification information of the second electronic device 101b
- the second profile download information is encrypted by using at least a part of the received identification information of the second electronic device 101b. It can be transmitted to the second electronic device 101b.
- the second electronic device 101b receives encrypted second profile download information from the first electronic device 101a, and information of the second electronic device 101b (eg, information of the second electronic device 101b) At least a portion of the identification information) may be used to decrypt the encrypted second profile download information. By encrypting and transmitting the second profile download information, it is possible to prevent the second profile download information from being stolen and used by a device other than the second electronic device 101b.
- the second electronic device 101b downloads the second profile from the profile providing server 530 in operation 1236 based on the second profile download information received from the first electronic device 101a.
- the second electronic device 101b may store or install the second profile received from the profile providing server 530 in the eSIM 201 .
- the second profile may be packaged in a software form (eg, packaged in a protected profile package (PPP) or bound profile package (BPP) form) and transmitted to the second electronic device 101b.
- the second electronic device 101b may store or install the second profile received from the profile providing server 530 in the eSIM 201 .
- the second electronic device 101b may download a second profile packaged in a PPP or BPP form from the profile providing server 530 and install it in an eUICC (eg, the eUICC 401 of FIG. 4 ).
- the profile package interpreter 454 described above in FIG. 4 may install in the eUICC 401 after unpacking the PPP or BPP including the second profile received from the profile providing server 530. .
- the second electronic device 101b may activate the second profile of the eSIM 201 .
- the second electronic device 101b may use a network (eg, a cellular network) provided by a communication service provider related to the profile information providing server 520 by using the second profile activated in operation 1238 .
- a network eg, a cellular network
- the profile providing server 530 receives information (eg, the second electronic device (eg, the second electronic device ( identification information of 101b)) may be received. Thereafter, when the profile providing server 530 receives a second profile download request from the second electronic device 101b in operation 1236, the profile information delivery server 520 receives the information received from the first electronic device 101a and the profile information delivery server 520. The validity of the second electronic device 101b may be verified using at least a part of the identification information of the second electronic device 101b.
- the electronic device 101 may display at least one piece of line information based on stored profile information in operation 1310.
- the electronic device may receive a selection of a line to be moved to an external electronic device (eg, the second electronic device 101b) from among the displayed at least one piece of line information in operation 1320 .
- an external electronic device eg, the second electronic device 101b
- the electronic device may communicate with an external electronic device in operation 1330.
- an electronic device may be connected to an external electronic device through short-range wireless communication.
- the electronic device may receive information about the external electronic device from the external electronic device.
- the information on the external electronic device may include at least one of EID and IMEI, but is not limited thereto.
- the electronic device may request authentication of a line to be moved to the external electronic device to the server based on the information about the external electronic device and the information about the selected line to be moved.
- the authentication request may include an authentication request based on an extensible authentication protocol authentication and key agreement (EAP-AKA) authentication method.
- EAP-AKA extensible authentication protocol authentication and key agreement
- the electronic device may receive profile download information (eg, download information for the second profile) from the server in response to the authentication request in operation 1360 .
- profile download information eg, download information for the second profile
- the electronic device may transmit profile download information to an external electronic device.
- the external electronic device may download the second profile based on the profile download information received from the electronic device and install it in the eSIM.
- the first electronic device 101a may download setting information from the setting server 550 in operation 1402 .
- the setting information downloaded from the setting server 550 may include communication operator information.
- the communication service provider information includes the address of the server (e.g., web server 510, profile information delivery server 520, profile providing server 530), supportable on device activation (ODA) function, and supportable authentication method (e.g., At least one of SMS (short message service)-OTP (one time password) authentication method, EAP-AKA (extensible authentication protocol authentication and key agreement) authentication method), MCC (mobile country code) and MNC (mobile network code) of the telecommunication service provider may contain one.
- the server e.g., web server 510, profile information delivery server 520, profile providing server 530
- ODA supportable on device activation
- supportable authentication method e.g., At least one of SMS (short message service)-OTP (one time password) authentication method, EAP-AKA (extensible authentication protocol authentication and key agreement) authentication method), MCC (mobile country code) and MNC (mobile network code) of the telecommunication service provider may contain one.
- the first electronic device 101a may select a line to move to the second electronic device 101b based on profile information stored in the eSIM 201 in operation 1404 .
- a SIM card manager screen 1010 may be displayed.
- 10A, 10B, and 10C are diagrams illustrating user interfaces displayed on the screen of the first electronic device 101a according to various embodiments.
- Information 1011 on the physical SIM installed in the first electronic device 101a and information 1012 on the eSIM may be displayed on the SIM card manager screen 1010 .
- the eSIM information 1012 is selected in FIG.
- an eSIM setting screen 1020 may be displayed as shown in FIG. 10B.
- the setting screen 1020 for the eSIM may include a menu (Transfer to New Device) 1021 for moving a line corresponding to the corresponding profile to a new electronic device (eg, the second electronic device 101b). .
- a user when a user selects a menu 1021 capable of moving a line corresponding to the corresponding profile to a new electronic device (eg, the second electronic device 101b), the corresponding profile as described later. It is possible to perform a line transfer procedure corresponding to .
- a user may request device information on a new electronic device through the second electronic device 101b, and the second electronic device 101b, in operation 1406, sends information about the new electronic device to the eSIM according to the user's request.
- Device information is requested, and in operation 1408, device information of the new electronic device may be displayed on the screen.
- the device information of the new electronic device may be displayed in the form of a QR code on the screen of the second electronic device 101b as shown in FIG. 10c.
- the first electronic device 101a scans the QR code displayed on the second electronic device 101b as shown in FIG. Device information of (101b)) may be obtained.
- the device information on the second electronic device 101b may include at least one of EID and IMEI, but is not limited thereto.
- the first electronic device 101a performs line transfer with the authentication server 540 through the profile information delivery server 520 based on the received device information on the second electronic device 101b. authentication can be performed.
- the authentication method for the line transfer may include an extensible authentication protocol authentication and key agreement (EAP-AKA) authentication method.
- EAP-AKA authentication method is relatively secure compared to other types of authentication methods (eg, SMS-OTP), and can provide intuitive and simple line transfer without requiring additional information input by the user.
- Operations 1412 to 1420 in FIG. 14A may operate according to the EAP-AKA authentication scheme.
- the EAP-AKA authentication method is a GSMA standard document TS. At least a part of the EAP-AKA authentication method disclosed in 43 may be included.
- the first electronic device 101a may request authentication from the profile information delivery server 520 in operation 1412 .
- the first electronic device 101a may request authentication based on the EAP-AKA authentication method to the profile information delivery server 520 .
- the first electronic device 101a may transmit an authentication request including IMSI, IMEI, or a combination thereof of the first electronic device 101a to the profile information delivery server 520 .
- the profile information delivery server 520 may transmit a challenge to the first electronic device 101a in response to the authentication request in operation 1414 .
- the challenge may be an arbitrary number for authenticating the eSIM 201 of the first electronic device 101a.
- the first electronic device 101a may obtain a payload for the challenge based on information stored in the eSIM 201 .
- the first electronic device 101a may calculate and obtain a payload for a challenge based on the authentication key value of the eSIM 201 .
- the first electronic device 101a may transmit the payload acquired based on the eSIM 201 to the profile information delivery server 520 in operation 1418 .
- the profile information delivery server 520 may receive a payload from the first electronic device 101a and perform authentication through the authentication server 540 .
- the authentication server 540 may determine whether authentication succeeds by comparing a value obtained by converting a challenge based on a key previously designated for the eSIM 201 of the first electronic device 101a with a payload.
- the authentication server 540 may determine that authentication is successful when a value obtained by converting a challenge based on a key previously designated for the eSIM 201 is identical to a payload.
- the profile information delivery server 520 sends an authentication token as a payload result value in operation 1420 to the first electronic device ( 101a).
- the first electronic device 101a may perform a line transfer procedure based on the authentication result. For example, in operation 1422, the first electronic device 101a may check access rights to the profile information delivery server 520 through the profile information delivery server 520. For example, the first electronic device 101a has the authority to access the profile information delivery server 520 (or the communication service provided by the profile information delivery server 520 after accessing the profile information delivery server 520). The authentication token may be transmitted to the profile information delivery server 520 in order to confirm the right to use). According to various embodiments, the first electronic device 101a may transmit information (eg, IMEI of the first electronic device 101a) of the first electronic device 101a to the profile information delivery server 520. .
- information eg, IMEI of the first electronic device 101a
- the first electronic device 101a in addition to the IMEI of the first electronic device 101a to the profile information delivery server 520, the protocol version and the manufacturer of the first electronic device 101a. At least one of (vendor), model name, and software version may be further transmitted.
- the profile information delivery server 520 has access authority for the profile information delivery server 520 by the first electronic device 101a based on the information transmitted from the first electronic device 101a. You can check whether it exists or not. For example, when the profile information delivery server 520 determines that the first electronic device 101a has authority to access the profile information delivery server 520, the first electronic device 101b transmits the first electronic device 101b to the first electronic device 101b.
- the electronic device 101a may transmit information indicating that it has authority to access the profile information delivery server 520 .
- the profile information delivery server 520 determines that the first electronic device 101a does not have the authority to access the profile information delivery server 520, the authority to access the first electronic device 101a is granted.
- Information indicating that there is none may be transmitted, or a URL may be transmitted so that the first electronic device 101a displays the web page of the profile information delivery server 520 or the web page of the web server 510 .
- the first electronic device 101a may request line transfer to the profile information delivery server 520 after the authority check in operation 1422 is completed. For example, the first electronic device 101a receives information indicating that the first electronic device 101a has authority to access the profile information delivery server 520 from the profile information delivery server 520. In response, information requesting line transfer may be transmitted to the profile information delivery server 520 .
- the profile information delivery server 520 transmits information for checking line movement and a new electronic device (eg, the second electronic device 101b) to which line movement is performed, to the first electronic device 101a. You can request information about a new electronic device (eg, the second electronic device 101b) to which line movement is performed, to the first electronic device 101a. You can request information about a new electronic device (eg, the second electronic device 101b) to which line movement is performed, to the first electronic device 101a. You can request information about
- the first electronic device 101a transmits, in operation 1428, information indicating line movement confirmation and information on a new electronic device to the profile information delivery server 520.
- information on the new electronic device may include at least one of EID and IMEI of the second electronic device 101b, but is not limited thereto.
- the profile information delivery server 520 when the profile information delivery server 520 receives new electronic device information and line movement confirmation information from the first electronic device 101a, the profile information delivery server 520 operates In operation 1430, the profile providing server 530 may be requested to create (or prepare) a second profile.
- the profile providing server 530 may create a second profile in response to receiving a request to create a second profile from the profile information delivery server 520 .
- the profile information delivery server 520 may transmit second profile download information to the first electronic device 101a in operation 1432 .
- the second profile download information transmitted from the profile information delivery server 520 to the first electronic device 101a may include the address of the profile providing server 530 .
- the first electronic device 101a displays second profile download information (eg, address information of the profile providing server 530) received from the profile information delivery server 520 in operation 1434 on the screen.
- second profile download information can be displayed on the screen in the form of a QR code as shown in FIG. 10C.
- the second electronic device 101b may acquire the second profile download information in operation 1436 by scanning the QR code displayed on the first electronic device 101a.
- the second electronic device 101b downloads the second profile from the profile providing server 530 in operation 1438 based on the second profile download information received from the first electronic device 101a.
- the second electronic device 101b may store or install the second profile received from the profile providing server 530 in the eSIM 201 .
- the second electronic device 101b may download a second profile packaged in a PPP or BPP form from the profile providing server 530 and install it in an eUICC (eg, the eUICC 401 of FIG. 4 ).
- the profile package interpreter 454 described above in FIG. 4 may install in the eUICC 401 after unpacking the PPP or BPP including the second profile received from the profile providing server 530. .
- the second electronic device 101b may activate the second profile of the eSIM 201 .
- the second electronic device 101b may use a network (eg, cellular network) provided by a communication service provider associated with the profile information providing server 520 by using the second profile activated in operation 1440 .
- a network eg, cellular network
- the electronic device 101 may display at least one piece of line information based on stored profile information in operation 1510.
- the electronic device may receive a selection of a line to be moved to an external electronic device (eg, the second electronic device 101b) from among the displayed at least one piece of line information in operation 1520.
- an external electronic device eg, the second electronic device 101b
- the electronic device may obtain information about the external electronic device from the external electronic device in operation 1530 .
- the electronic device may acquire information about the external electronic device by scanning a QR code displayed on the external electronic device.
- the information on the external electronic device may include at least one of EID and IMEI, but is not limited thereto.
- the electronic device may request authentication of a line to be moved to the external electronic device to the server based on the information about the external electronic device and the information about the selected line to be moved.
- the authentication request may include an authentication request based on an extensible authentication protocol authentication and key agreement (EAP-AKA) authentication method.
- EAP-AKA extensible authentication protocol authentication and key agreement
- the electronic device may receive profile download information (eg, download information for the second profile) from the server in response to the authentication request in operation 1550.
- profile download information eg, download information for the second profile
- the electronic device may display profile download information on the screen in operation 1560.
- the electronic device may generate a QR code corresponding to the profile download information and display it on the screen.
- the external electronic device can obtain profile download information by scanning the QR code displayed on the screen of the electronic device.
- the external electronic device may download the second profile based on the profile download information acquired from the electronic device and install it in the eSIM.
- An electronic device includes at least one embedded universal integrated circuit card (eUICC) each storing at least one subscriber identification information, and at least one electrically connected to the eUICC. and a processor, wherein the at least one processor connects to an external electronic device through communication, receives a line information request for line movement from the external electronic device, and is movable in response to receiving the line information request.
- eUICC embedded universal integrated circuit card
- the at least one processor connects to an external electronic device through communication, receives a line information request for line movement from the external electronic device, and is movable in response to receiving the line information request.
- One line information is checked from the profile information stored in the eUICC, the checked at least one movable line information is transmitted to the external electronic device, and the selected movable line information among the at least one movable line information is transmitted from the external electronic device.
- Receive line information request authentication for the line to be moved selected by the external electronic device to a server, receive information corresponding to an authentication result from the server in response to the authentication request, and respond to the authentication result It is possible to control transmission of information for line transfer including the information to the external electronic device.
- the at least one processor may control to receive setting information from a setting server.
- the setting information may include whether or not a corresponding communication service provider supports a line portability function.
- the electronic device is connected to the external electronic device through short-range wireless communication, and the at least one processor transmits the identified at least one movable line information to the external electronic device through short-range wireless communication. It can be controlled to be transmitted to an electronic device.
- the authentication request may include an authentication request based on an extensible authentication protocol authentication and key agreement (EAP-AKA) method.
- EAP-AKA extensible authentication protocol authentication and key agreement
- the information corresponding to the authentication result may include an authentication token.
- the information for line transfer may include information about the electronic device.
- the information about the electronic device may include a mobile country code (MCC) and a mobile network code (MNC) identified from the profile information, an international mobile subscriber identity (IMSI), an eUICC identity (EID), and an IMEI ( It may include at least one of international mobile equipment identity), integrated circuit card identity (ICCID), and product model name.
- MCC mobile country code
- MNC mobile network code
- IMSI international mobile subscriber identity
- EID eUICC identity
- IMEI It may include at least one of international mobile equipment identity
- ICCID integrated circuit card identity
- An operating method of an electronic device includes at least one embedded universal integrated circuit card (eUICC) each storing at least one subscriber identification information and electrically connected to the eUICC.
- eUICC embedded universal integrated circuit card
- a method for performing line transfer in an electronic device including at least one processor comprising: connecting to an external electronic device through communication; receiving a request for line information for line transfer from the external electronic device; and requesting the line information.
- an operation of transmitting the checked at least one movable line information to the external electronic device Corresponding to the reception of at least one movable line information to the profile information stored in the eUICC, an operation of transmitting the checked at least one movable line information to the external electronic device, and an operation from the external electronic device.
- the method may further include receiving configuration information from a configuration server.
- the setting information may include whether or not a corresponding communication service provider supports a line portability function.
- the method may include an operation of transmitting the identified at least one movable line information to the external electronic device through short-range wireless communication.
- the authentication request may include an authentication request based on an extensible authentication protocol authentication and key agreement (EAP-AKA) method.
- EAP-AKA extensible authentication protocol authentication and key agreement
- the information corresponding to the authentication result may include an authentication token.
- the information for line transfer may include information about the electronic device.
- the information about the electronic device may include a mobile country code (MCC) and a mobile network code (MNC) identified from the profile information, an international mobile subscriber identity (IMSI), an eUICC identity (EID), and an IMEI ( It may include at least one of international mobile equipment identity), integrated circuit card identity (ICCID), and product model name.
- MCC mobile country code
- MNC mobile network code
- IMSI international mobile subscriber identity
- EID eUICC identity
- IMEI It may include at least one of international mobile equipment identity
- ICCID integrated circuit card identity
- An electronic device includes a display, at least one embedded universal integrated circuit card (eUICC) each storing at least one subscriber identification information, and at least one electrically connected to the eUICC. It includes one processor, wherein the at least one processor displays at least one line information on the display based on profile information stored in the eUICC, and for a line to be moved to an external electronic device among the at least one line information. Receiving a selection, requesting a server to authenticate a line to be moved to the selected external electronic device, receiving information corresponding to an authentication result from the server in response to the authentication request, and receiving information corresponding to the authentication result Based on the information, it is possible to control to display information for line movement on the display.
- eUICC embedded universal integrated circuit card
- the authentication request may include an authentication request based on an extensible authentication protocol authentication and key agreement (EAP-AKA) scheme.
- EAP-AKA extensible authentication protocol authentication and key agreement
- the information corresponding to the authentication result may include an authentication token.
- the information for line movement is displayed in the form of a quick response (QR) code
- the information for line movement includes a mobile country code (MCC) and a mobile network (MNC) identified from the profile information.
- code international mobile subscriber identity (IMSI), eUICC identity (EID), international mobile equipment identity (IMEI), integrated circuit card identity (ICCID), and product model name.
- IMSI international mobile subscriber identity
- EID eUICC identity
- IMEI international mobile equipment identity
- ICCID integrated circuit card identity
- product model name product model name
- An electronic device may be a device of various types.
- the electronic device may include, for example, a computer device, a portable communication device (eg, a smart phone), a portable multimedia device, a portable medical device, a camera, a wearable device, or a home appliance.
- An electronic device according to an embodiment of the present document is not limited to the aforementioned devices.
- first, second, or first or secondary may simply be used to distinguish that component from other corresponding components, and may refer to that component in other respects (eg, importance or order) is not limited.
- a (e.g. first) component is said to be “coupled” or “connected” to another (e.g. second) component, with or without the terms “functionally” or “communicatively”.
- a component may be connected to another component directly (eg by wire), wirelessly, or through a third component.
- module used in this document may include a unit implemented by hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit, for example.
- a module may be an integral part or the smallest unit of a part or part thereof that performs one or more functions.
- the module may be implemented in the form of an application-specific integrated circuit (ASIC).
- ASIC application-specific integrated circuit
- One embodiment of this document is software (eg, a master device or a task performing device) including one or more instructions stored in a storage medium (eg, internal memory or external memory) readable by a machine (eg, a master device or a task performing device). e.g. program).
- a processor of a device e.g. a master device or a task performing device
- One or more instructions may include code generated by a compiler or code executable by an interpreter.
- the device-readable storage medium may be provided in the form of a non-transitory storage medium.
- 'non-temporary' only means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and this term refers to the case where data is stored semi-permanently in the storage medium. It does not discriminate when it is temporarily stored.
- signals e.g., electromagnetic waves
- the method according to one embodiment disclosed in this document may be included and provided in a computer program product.
- Computer program products may be traded between sellers and buyers as commodities.
- a computer program product is distributed in the form of a device-readable storage medium (e.g. compact disc read only memory (CD-ROM)), or through an application store (e.g. Play StoreTM) or on two user devices (e.g. It can be distributed (eg downloaded or uploaded) online, directly between smartphones.
- a device-readable storage medium e.g. compact disc read only memory (CD-ROM)
- an application store e.g. Play StoreTM
- It can be distributed (eg downloaded or uploaded) online, directly between smartphones.
- at least part of the computer program product may be temporarily stored or temporarily created in a device-readable storage medium such as a manufacturer's server, an application store server, or a relay server's memory.
- each component eg, module or program of the described components may include singular or plural entities.
- one or more components or operations among the corresponding components described above may be omitted, or one or more other components or operations may be added.
- a plurality of components eg modules or programs
- the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to integration.
- the actions performed by a module, program, or other component are executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations are executed in a different order, omitted, or , or one or more other operations may be added.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Databases & Information Systems (AREA)
- Computer Security & Cryptography (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims (15)
- 전자 장치에 있어서,각각 적어도 하나의 가입자 식별 정보를 저장하는 적어도 하나의 임베디드 범용 집적 회로 카드(embedded universal integrated circuit card; eUICC); 및상기 eUICC에 전기적으로 연결된 적어도 하나의 프로세서를 포함하며,상기 적어도 하나의 프로세서는:외부 전자 장치와 통신으로 연결하고,상기 외부 전자 장치로부터 회선 이동을 위한 회선 정보 요청을 수신하고,상기 회선 정보 요청을 수신함에 상응하여, 이동 가능한 적어도 하나의 회선 정보를 상기 eUICC에 저장된 프로파일 정보로부터 확인하고,상기 확인된 이동 가능한 적어도 하나의 회선 정보를 상기 외부 전자 장치로 전송하고,상기 외부 전자 장치로부터 상기 이동 가능한 적어도 하나의 회선 정보 중 선택된 이동할 회선 정보를 수신하고,서버로 상기 외부 전자 장치에 의해 선택된 이동할 회선에 대한 인증을 요청하고,상기 인증의 요청에 상응하여, 상기 서버로부터 인증 결과에 대응하는 정보를 수신하고,상기 인증 결과에 대응하는 정보를 포함하는 상기 회선 이동을 위한 정보를 상기 외부 전자 장치로 전송하도록 제어하는, 전자 장치.
- 제1항에 있어서, 상기 적어도 하나의 프로세서는,설정 서버로부터 설정 정보를 수신하도록 제어하는, 전자 장치.
- 제2항에 있어서, 상기 설정 정보는,해당 통신 사업자의 회선 이동 기능 지원 여부에 관한 정보를 포함하는, 전자 장치.
- 제1항에 있어서, 상기 전자 장치가 상기 외부 전자 장치와 연결되는 상기 통신은 근거리 무선 통신을 포함하고,상기 적어도 하나의 프로세서는,상기 확인된 이동 가능한 적어도 하나의 회선 정보를 상기 근거리 무선 통신을 통해 상기 외부 전자 장치로 전송하도록 제어하는, 전자 장치.
- 제1항에 있어서, 상기 인증 요청은,EAP-AKA(extensible authentication protocol authentication and key agreement) 방식에 의한 인증 요청을 포함하는, 전자 장치.
- 제1항에 있어서, 상기 인증 결과에 대응하는 정보는,인증 토큰(token)을 포함하는, 전자 장치.
- 제1항에 있어서, 상기 회선 이동을 위한 정보는,상기 전자 장치에 관한 정보를 포함하는, 전자 장치.
- 제7항에 있어서, 상기 전자 장치에 관한 정보는,상기 프로파일 정보로부터 확인된 MCC(mobile country code) 및 MNC(mobile network code), IMSI(international mobile subscriber identity), EID(eUICC identity), IMEI(international mobile equipment identity), ICCID(integrated circuit card identity), 제품 모델명 중 적어도 하나를 포함하는, 전자 장치.
- 각각 적어도 하나의 가입자 식별 정보를 저장하는 적어도 하나의 임베디드 범용 집적 회로 카드(embedded universal integrated circuit card; eUICC), 및 상기 eUICC에 전기적으로 연결된 적어도 하나의 프로세서를 포함하는 전자 장치에서 회선 이동을 수행하는 방법에 있어서,외부 전자 장치와 통신으로 연결하는 동작;상기 외부 전자 장치로부터 회선 이동을 위한 회선 정보 요청을 수신하는 동작;상기 회선 정보 요청을 수신함에 상응하여, 이동 가능한 적어도 하나의 회선 정보를 상기 eUICC에 저장된 프로파일 정보로부터 확인하는 동작;상기 확인된 이동 가능한 적어도 하나의 회선 정보를 상기 외부 전자 장치로 전송하는 동작;상기 외부 전자 장치로부터 상기 이동 가능한 적어도 하나의 회선 정보 중 선택된 이동할 회선 정보를 수신하는 동작;서버로 상기 외부 전자 장치에 의해 선택된 이동할 회선에 대한 인증을 요청하는 동작;상기 인증의 요청에 상응하여, 상기 서버로부터 인증 결과에 대응하는 정보를 수신하는 동작; 및상기 인증 결과에 대응하는 정보를 포함하는 상기 회선 이동을 위한 정보를 상기 외부 전자 장치로 전송하는 동작을 포함하는, 전자 장치의 동작 방법.
- 제9항에 있어서, 상기 방법은,설정 서버로부터 설정 정보를 수신하는 동작을 더 포함하는, 전자 장치의 동작 방법.
- 제10항에 있어서, 상기 설정 정보는,해당 통신 사업자의 회선 이동 기능 지원 여부를 포함하는, 전자 장치의 동작 방법.
- 제9항에 있어서, 상기 방법은,상기 확인된 이동 가능한 적어도 하나의 회선 정보를 근거리 무선 통신을 통해 상기 외부 전자 장치로 전송하는 동작을 포함하는, 전자 장치의 동작 방법.
- 제9항에 있어서, 상기 인증 요청은,EAP-AKA(extensible authentication protocol authentication and key agreement) 방식에 의한 인증 요청을 포함하는, 전자 장치의 동작 방법.
- 전자 장치에 있어서,디스플레이;각각 적어도 하나의 가입자 식별 정보를 저장하는 적어도 하나의 임베디드 범용 집적 회로 카드(embedded universal integrated circuit card; eUICC); 및상기 eUICC에 전기적으로 연결된 적어도 하나의 프로세서를 포함하며,상기 적어도 하나의 프로세서는:상기 eUICC에 저장된 프로파일 정보에 기반하여 적어도 하나의 회선 정보를 상기 디스플레이에 디스플레이하고,상기 적어도 하나의 회선 정보 중 외부 전자 장치로 이동할 회선에 대한 선택을 수신하고,서버로 상기 선택된 상기 외부 전자 장치로 이동할 회선에 대한 인증을 요청하고,상기 인증의 요청에 상응하여, 상기 서버로부터 인증 결과에 대응하는 정보를 수신하고,상기 인증 결과에 대응하는 정보에 기반하여 회선 이동을 위한 정보를 상기 디스플레이에 디스플레이하도록 제어하는, 전자 장치.
- 제14항에 있어서, 상기 인증 요청은,EAP-AKA(extensible authentication protocol authentication and key agreement) 방식에 의한 인증 요청을 포함하는, 전자 장치.
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202280051876.1A CN117693953A (zh) | 2021-07-30 | 2022-05-25 | 电子装置和通过使用电子装置中的嵌入式用户识别模块来移动线路的方法 |
| EP22849691.5A EP4329347A4 (en) | 2021-07-30 | 2022-05-25 | Electronic device and method for moving line by using embedded subscriber identification module in electronic device |
| US17/856,405 US12520126B2 (en) | 2021-07-30 | 2022-07-01 | Electronic device and method for transferring subscription by using embedded SIM in the electronic device |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020210100920A KR20230018893A (ko) | 2021-07-30 | 2021-07-30 | 전자 장치 및 전자 장치에서 임베디드 sim을 이용하여 회선을 이동하기 위한 방법 |
| KR10-2021-0100920 | 2021-07-30 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US17/856,405 Continuation US12520126B2 (en) | 2021-07-30 | 2022-07-01 | Electronic device and method for transferring subscription by using embedded SIM in the electronic device |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2023008712A1 true WO2023008712A1 (ko) | 2023-02-02 |
Family
ID=85087941
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2022/007415 Ceased WO2023008712A1 (ko) | 2021-07-30 | 2022-05-25 | 전자 장치 및 전자 장치에서 임베디드 가입자 식별 모듈을 이용하여 회선을 이동하기 위한 방법 |
Country Status (2)
| Country | Link |
|---|---|
| KR (1) | KR20230018893A (ko) |
| WO (1) | WO2023008712A1 (ko) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2026005371A1 (ko) * | 2024-06-26 | 2026-01-02 | 삼성전자 주식회사 | 임베디드 가입자 식별 모듈을 인증하는 전자 장치, 방법, 및 기록 매체 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20160020816A (ko) * | 2014-08-14 | 2016-02-24 | 삼성전자주식회사 | 그룹단말의 프로파일 설치 방법 |
| US20160373920A1 (en) * | 2014-12-10 | 2016-12-22 | Telefonaktiebolaget Lm Ericsson (Publ) | Managing network connectivity of a device comprising an embedded uicc |
| CN105637498B (zh) * | 2014-05-23 | 2019-05-28 | 华为技术有限公司 | eUICC的管理方法、eUICC、SM平台和系统 |
| KR20210004809A (ko) * | 2019-07-03 | 2021-01-13 | 삼성전자주식회사 | 회선을 이동하기 위한 방법 및 이를 지원하는 전자 장치 |
-
2021
- 2021-07-30 KR KR1020210100920A patent/KR20230018893A/ko active Pending
-
2022
- 2022-05-25 WO PCT/KR2022/007415 patent/WO2023008712A1/ko not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN105637498B (zh) * | 2014-05-23 | 2019-05-28 | 华为技术有限公司 | eUICC的管理方法、eUICC、SM平台和系统 |
| KR20160020816A (ko) * | 2014-08-14 | 2016-02-24 | 삼성전자주식회사 | 그룹단말의 프로파일 설치 방법 |
| US20160373920A1 (en) * | 2014-12-10 | 2016-12-22 | Telefonaktiebolaget Lm Ericsson (Publ) | Managing network connectivity of a device comprising an embedded uicc |
| KR20210004809A (ko) * | 2019-07-03 | 2021-01-13 | 삼성전자주식회사 | 회선을 이동하기 위한 방법 및 이를 지원하는 전자 장치 |
Non-Patent Citations (1)
| Title |
|---|
| QUALCOMM INCORPORATED: "Introducing 5G-NG TC 15.1.2A, Authentication procedure for EAP-AKA' – Authentication is successful - GSM UICC for BlackBox Testing", 3GPP DRAFT; C6-200790, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. CT WG6, no. E-meeting; 20201117 - 20201120, 11 November 2020 (2020-11-11), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051953458 * |
Also Published As
| Publication number | Publication date |
|---|---|
| KR20230018893A (ko) | 2023-02-07 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2019221504A1 (en) | Control method of secure module connected to a plurality of processors and electronic device for implementing the same | |
| WO2022108357A1 (en) | Method and apparatus for handling profiles by considering removable euicc supporting multiple enabled profiles | |
| WO2020190057A1 (en) | Method for setting device based on information associated with account and electronic device therefor | |
| WO2016003200A1 (en) | Method and apparatus for installing profile for euicc | |
| WO2020204505A1 (ko) | 엣지 컴퓨팅 서비스를 위한 방법 및 그의 전자 장치 | |
| WO2018147711A1 (en) | APPARATUS AND METHOD FOR ACCESS CONTROL ON eSIM | |
| WO2021172873A1 (en) | Method and device for remote management and verification of remote management authority | |
| WO2019039813A1 (ko) | 전자 장치 및 전자 장치에 프로파일을 원격으로 제공하는 방법 | |
| WO2020032445A1 (en) | Electronic device, external electronic device, and method of managing embedded subscriber identity modules of external electronic device | |
| WO2017052136A1 (ko) | 이동 통신 시스템에서 프로파일 다운로드 방법 및 장치 | |
| WO2021066569A1 (en) | Method and apparatus for reinstalling sim profile in wireless communication system | |
| WO2021221325A1 (ko) | 복수 심을 지원하는 전자 장치 및 그 동작 방법 | |
| WO2022139481A1 (ko) | 임베디드 심을 이용하여 검증을 수행하는 전자 장치 및 그 동작 방법 | |
| WO2022220584A1 (ko) | 전자 장치 및 전자 장치에서 외부 전자 장치의 클라우드 온보딩을 수행하는 방법 | |
| WO2021241849A1 (ko) | 에지 컴퓨팅 서비스를 수행하는 전자 장치 및 전자 장치의 동작 방법 | |
| WO2022240144A1 (en) | Method and apparatus for identifying profile deletion when euicc terminal is changed | |
| WO2022114483A1 (ko) | 에지 컴퓨팅 서비스를 수행하는 전자 장치 및 전자 장치의 동작 방법 | |
| WO2022225195A1 (ko) | 무선 네트워크에서 장치 프로비져닝을 위한 전자 장치 및 그 동작 방법 | |
| WO2022045869A1 (en) | Apparatus and method for managing events in communication system | |
| WO2020032353A1 (ko) | 전자 장치, 외부 전자 장치 및 외부 전자 장치의 esim 관리 방법 | |
| WO2022220436A1 (ko) | 네트워크 억세스 동작을 수행하는 전자 장치 및 그 동작 방법 | |
| WO2022045705A1 (ko) | 전자 장치 및 복수의 가입자 식별 모듈들을 지원하는 전자 장치에서 단문 메시지를 수신하는 방법 | |
| WO2020171475A1 (ko) | 무선 통신 시스템의 기기변경 방법 및 장치 | |
| WO2023008712A1 (ko) | 전자 장치 및 전자 장치에서 임베디드 가입자 식별 모듈을 이용하여 회선을 이동하기 위한 방법 | |
| WO2022191426A1 (ko) | 복수의 가입자 식별 모듈들을 포함하는 전자 장치 및 그의 동작 방법 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22849691 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2022849691 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 2022849691 Country of ref document: EP Effective date: 20231120 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202280051876.1 Country of ref document: CN |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202417014140 Country of ref document: IN |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |