Method for modifying rights to security domain for smartcard, and server, smartcard, and terminal for same
The present invention relates to modifying rights to a security domain for a smartcard, and more specifically, to a server for managing modification of rights to a security domain, a smartcard for modifying the rights to the security domain, a terminal which is loaded with the smartcard, and to a method for modifying the rights.
1. An Embedded Universal Integrated Circuit Card (e-UICC) communicating with a Subscription Manager (SM) and a plurality of Mobile Network Operators, the e-UICC comprising:
a memory storing instructions; and
a processor which executes the instructions to thereby perform the operations of:
controlling a first security domain in the e-UICC to share a key with a management server managing the e-UICC; and
controlling a plurality of second security domains in the e-UICC, to each share another a-key with an SM-Data Preparation (SM-DP),
wherein the processor controls one of the second security domains according to a signal received through the first security domain,
wherein the first security domain and the second security domains are representatives for off-card authorities, and
wherein, in response to receiving a request to switch from a first Mobile Network Operator to a second Mobile Network Operator, the processor changes a life cycle state of a second security domain corresponding to the first Mobile Network Operator and changes a life cycle state of another second security domain corresponding to the second Mobile Network and wherein a status of the e-UICC is managed by an SM-Secure Routing (SM-SR) in connection with the first security domain and managed by the SM-DP in connection with the second security domains.
2. The e-UICC of claim 1 , wherein a status of one of the second security domains is controlled to one of installed, active, inactive, and deleted states based on the signal received through the first security domain.
3. The e-UICC of claim 1 , wherein the first security domain is a representative of an off-card entity that administers or issues e-UICC cards.
4. The e-UICC of claim 3 , wherein the off-card entity is the Subscription Manager (SM).
5. The e-UICC of claim 1 , wherein the second security domains are representatives of application providers.
6. The e-UICC of claim 5 , wherein the application providers are SM-DPs.
7. A method for managing security domains for an embedded Universal Integrated Circuit Card (e-UICC) configured to communicate with a Subscription Manager (SM) and a plurality of Mobile Network Operators, the method comprising:
configuring a first security domain to share a key with a management server configured to manage the e-UICC;
configuring a plurality of second security domains, each configured to share a key with an SM-Data Preparation (SM-DP); and
controlling one of the second security domains according to a signal received through the first security domain;
wherein the first security domain and the second security domains are representatives for off-card authorities, and
wherein the method further comprises, in response to receiving a request to switch from a first Mobile Network Operator to a second Mobile Network Operator, changing a life cycle state of second security domain corresponding to the first Mobile Network Operator and changing a life cycle state of another second security domain corresponding to the second Mobile Network, wherein a status of the E-UICC is managed by an SM-Secure Routing (SM-SR) in connection with the first security domain and managed by the SM-DP in connection with the second security domains.
8. The method of claim 7 , wherein a status of one of the second security domains, is controlled to one of installed, active, inactive, and deleted states based on the signal received through the first security domain.
9. The method of claim 7 , wherein the first security domain is a representative of an off-card entity that administers or issues e-UICC cards.
10. The method of claim 9 , wherein the off-card entity is the Subscription Manager (SM).
11. The method of claim 7 , wherein the second security domains are representatives of application providers.
12. The method of claim 11 , wherein one of the application providers is the SM-DP.