Method for control and enforcement of policy rule and EUICC

US9674690B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9674690-B2
Application numberUS-201314403076-A
CountryUS
Kind codeB2
Filing dateMay 23, 2013
Priority dateMay 23, 2012
Publication dateJun 6, 2017
Grant dateJun 6, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The present invention relates to a method for the control and enforcement of a policy rule in eUICC. The present invention relates to a method for the control and enforcement of a policy rule and to an eUICC, the method providing a function of controlling (defining, setting, updating, etc.) the policy rule for profiles on the eUICC according to the requirement of a business operator or a service provider, and providing a function of enforcing such as activating, deactivating, loading or deleting the profiles based on the thus-controlled policy rule.

First claim

Opening claim text (preview).

What is claimed is: 1. An embedded universal integrated circuit card (eUICC) configured to control and enforce policy rules, the eUICC comprising: a policy rule storage configured to define actions and conditions required to enforce a plurality of policies and store a plurality of policy rules including a plurality of policy rules for each profile and a plurality of policy rules for the eUICC; a policy controller configured to control the plurality of policy rules; and a policy enforcer configured to enforce the plurality of policy rules, wherein, when a change from a first mobile network operator (MNO) to a second MNO is attempted, the policy controller is configured to perform: setting a profile of the second MNO for a loadable profile ID through a policy rule for the eUICC; in response to determining that the eUICC is locked, checking effective period information of a lock status of the eUICC through the policy rule for the eUICC; and rejecting a subscription change for the second MNO in response to a result of the checking. 2. The eUICC of claim 1 , wherein the plurality of policy rules for each profile comprises a policy rule associated with a profile which is enabled in the eUICC. 3. The eUICC of claim 2 , wherein the plurality of policy rules for each profile further comprises one or more policy rules associated with a profile which is disabled in the eUICC. 4. The eUICC of claim 3 , wherein the policy rule associated with the enabled profile can be enforced by the policy enforcer, and wherein the policy rule associated with the disabled profile cannot be enforced by the policy enforcer. 5. The eUICC of claim 1 , wherein the policy enforcer is configured to evaluate conditions of the policy rules and configured to determine execution of a command based on the evaluation. 6. The eUICC of claim 1 , wherein credentials used in security conditions for the policy enforcer and the policy controller comprise one or more of a profile access credential, a profile installer credential, and a profile management credential. 7. The eUICC of claim 1 , wherein the policy rules for each profile and the policy rules for the eUICC comprise a file structure having one or more of a type of policy rule, a variable representing the type of the policy rule, and a location in which the policy rule is located. 8. The eUICC of claim 1 , wherein a policy rule list for each profile comprises at least one of a policy rule including a unique profile identifier (ID), a policy rule having a profile owner ID as a variable, a policy rule having a profile management authorizer ID as the variable, a policy rule which has a profile management type and has information as to whether a provisioning profile is used at a time of a profile change as the variable, a policy rule having information as to whether profile deletion is allowed as the variable, and a policy rule which has a profile capabilities type and has memory size information for enabling the profile as the variable. 9. The eUICC of claim 8 , wherein the policy rule which has the profile management authorizer ID as the variable is configured to specify whether a profile management command including at least one of enabling, disabling, loading, and deleting a relevant profile is executed from an authorized entity or an authenticated entity when the profile management command is executed. 10. The eUICC of claim 1 , wherein a policy rule list for the eUICC profile comprises at least one of a policy rule which has a type of eUICC capabilities and has a download and loading-allowed profile ID list as a variable, a policy rule which has information of a number of profiles which can be enabled as the variable, a policy rule which has information of an ID list of profiles which can be enabled as the variable, a policy rule which has information as to whether to notify a previous profile owner of a change after a profile change as the variable, a policy rule which has information of an allowable memory size for all profiles on the eUICC as the variable, a policy rule which has information of a total number of allowable profiles on the eUICC as the variable, a policy rule which has information of a memory size to enable the profile as the variable, a policy rule which has a type of eUICC lock and which has an eUICC lock status as the variable, and a policy rule which has the effective period information of the eUICC lock as the variable. 11. A method of controlling and enforcing policy rules on an embedded universal integrated circuit card (eUICC), the method comprising: defining, by the eUICC, actions and conditions in order to enforce policies and storing policy rules including policy rules for each profile and policy rules for the eUICC; setting, by the eUICC, the policy rules through a policy control function (PCF); and enforcing, by the eUICC, the set policy rules through a policy enforcement function (PEF), wherein, when a change from a first mobile network operator (MNO) to a second MNO is attempted, the setting comprises: setting a profile of the second MNO for a loadable profile ID through a policy rule for the eUICC; in response to determining that the eUICC is locked, checking effective period information of a lock status of the eUICC through the policy rule for the eUICC; and rejecting a subscription change for the second MNO in response to a result of the checking. 12. A method of controlling and enforcing policy rules on an embedded universal integrated circuit card (eUICC), the method comprising: setting, by a first external entity, the policy rules through a policy control function (PCF) provided on the eUICC; and performing, by a second external entity, a policy enforcement function (PEF), provided on the eUICC, for the set policy rules so that the set policy rules are applied to at least one of a target profile and the entire eUICC, wherein, when a change from a first mobile network operator (MNO) to a second MNO is attempted, the setting comprises: setting a profile of the second MNO for a loadable profile ID through a policy rule for the eUICC; in response to determining that the eUICC is locked, checking effective period information of a lock status of the eUICC through the policy rule for the eUICC; and rejecting a subscription change for the second MNO in response to a result of the checking. 13. The method of claim 12 , wherein, in the setting, security is ensured based on a predefined credential for the PCF when the policy rules are set for the PCF. 14. A method of controlling and enforcing policy rules on an embedded universal integrated circuit card (eUICC), the method comprising: setting, by a first external entity, the policy rules through a policy control function (PCF); and performing, by a second external entity, a policy enforcement function (PEF) for the set policy rules so that the set policy rules are applied to at least one of a target profile and the entire eUICC, wherein, when a change from a first mobile network operator (MNO) to a second MNO is attempted, the setting the policy rules comprises: checking, by the second MNO, the policy rules through the PCF using an entity having profile access authority; setting a profile of the second MNO for a loadable profile ID through a policy rule for the eUICC; determining whether the profile of the second MNO can be installed by checking information of a number of profiles which can be enabled and information of a total number of allowable profiles through the policy rule for the eUICC; checking information of an allowable memory size for all of the profiles and information of a memory size to enable the profil

Assignees

Inventors

Classifications

  • H04W8/183Primary

    Processing at user equipment or user record carrier · CPC title

  • involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved (negotiation of communication capabilities H04L69/24) · CPC title

  • gathering intelligence information for situation awareness or reconnaissance · CPC title

  • Access security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9674690B2 cover?
The present invention relates to a method for the control and enforcement of a policy rule in eUICC. The present invention relates to a method for the control and enforcement of a policy rule and to an eUICC, the method providing a function of controlling (defining, setting, updating, etc.) the policy rule for profiles on the eUICC according to the requirement of a business operator or a servic…
Who is the assignee on this patent?
Kt Corp
What technology area does this patent fall under?
Primary CPC classification H04W8/183. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 06 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).