Electronic subscriber identity module application identifier handling
    141.
    发明授权
    Electronic subscriber identity module application identifier handling 有权
    电子用户识别模块应用标识符处理

    公开(公告)号:US09439062B2

    公开(公告)日:2016-09-06

    申请号:US14503048

    申请日:2014-09-30

    Applicant: Apple Inc.

    CPC classification number: H04W8/183 H04W8/205 H04W88/06

    Abstract: Embodiments are described for identifying and accessing an electronic subscriber identity module (eSIM) and associated content of the eSIM in a multiple eSIM configuration. An embedded Universal Integrated Circuit Card (eUICC) can include multiple eSIMs, where each eSIM can include its own file structures and applications. Some embodiments include a processor of a mobile device transmitting a special command to the eUICC, including an identification that uniquely identifies an eSIM in the eUICC. After selecting the eSIM, the processor can access file structures and applications of the selected eSIM. The processor can then use existing commands to access content in the selected eSIM. The special command can direct the eUICC to activate or deactivate content associated with the selected eSIM. Other embodiments include an eUICC platform operating system interacting with eSIMs associated with logical channels to facilitate identification and access to file structures and applications of the eSIMs.

    Abstract translation: 描述了用于在多个eSIM配置中识别和访问电子订户身份模块(eSIM)和eSIM的相关内容的实施例。 嵌入式通用集成电路卡(eUICC)可以包括多个eSIM,每个eSIM可以包括其自己的文件结构和应用程序。 一些实施例包括向eUICC发送特殊命令的移动设备的处理器,包括在eUICC中唯一地标识eSIM的标识。 选择eSIM后,处理器可以访问所选eSIM的文件结构和应用程序。 然后,处理器可以使用现有命令访问所选eSIM中的内容。 特殊命令可以指示eUICC激活或停用与所选eSIM相关联的内容。 其他实施例包括与与逻辑信道相关联的eSIM交互的eUICC平台操作系统,以便于识别和访问eSIM的文件结构和应用。

    ELECTRONIC SUBSCRIBER IDENTITY MODULE PROVISIONING
    142.
    发明申请
    ELECTRONIC SUBSCRIBER IDENTITY MODULE PROVISIONING 有权
    电子订户身份识别模块提供

    公开(公告)号:US20150341791A1

    公开(公告)日:2015-11-26

    申请号:US14715761

    申请日:2015-05-19

    Applicant: Apple Inc.

    Abstract: A method for preparing an eSIM for provisioning is provided. The method can include a provisioning server encrypting the eSIM with a symmetric key. The method can further include the provisioning server, after determining a target eUICC to which the eSIM is to be provisioned, encrypting the symmetric key with a key encryption key derived based at least in part on a private key associated with the provisioning server and a public key associated with the target eUICC. The method can additionally include the provisioning server formatting an eSIM package including the encrypted eSIM, the encrypted symmetric key, and a public key corresponding to the private key associated with the provisioning server. The method can also include the provisioning server sending the eSIM package to the target eUICC.

    Abstract translation: 提供了一种用于准备用于配置的eSIM的方法。 该方法可以包括用对称密钥加密eSIM的供应服务器。 所述方法还可以包括所述供应服务器,在确定要向其提供所述eSIM的目标eUICC之后,至少部分地基于与所述供应服务器相关联的私钥和公共的公共密钥来加密所述对称密钥,所述密钥加密密钥 与目标eUICC相关联的关键。 该方法还可以包括配置服务器格式化包括加密eSIM,加密对称密钥和对应于与配置服务器相关联的私有密钥的公钥的eSIM包。 该方法还可以包括配置服务器将eSIM包发送到目标eUICC。

    Methods and apparatus for correcting error events associated with identity provisioning
    143.
    发明授权
    Methods and apparatus for correcting error events associated with identity provisioning 有权
    用于纠正与身份提供相关的错误事件的方法和装置

    公开(公告)号:US09148841B2

    公开(公告)日:2015-09-29

    申请号:US13762897

    申请日:2013-02-08

    Applicant: Apple Inc.

    Abstract: Methods and apparatus for correcting error events associated with identity provisioning. In one embodiment, repeated requests for access control clients are responded to with the execution of a provisioning feedback mechanism which is intended to prevent the unintentional (or even intentional) over-consumption or waste of network resources via the delivery of an excessive amount of access control clients. These provisioning feedback mechanisms include rate-limiting algorithms and/or methodologies which place a cost on the user. Apparatus for implementing the aforementioned provisioning feedback mechanisms are also disclosed and include specialized user equipment and/or network side equipment such as a subscriber identity module provisioning server (SPS).

    Abstract translation: 用于纠正与身份提供相关的错误事件的方法和装置。 在一个实施例中,对访问控制客户机的重复请求响应于供应反馈机制的执行,其旨在通过传递过多的访问来防止无意(甚至故意的)过度消费或浪费网络资源 控制客户端。 这些供应反馈机制包括对用户造成成本的速率限制算法和/或方法。 还公开了用于实现上述提供反馈机制的装置,并且包括专用用户设备和/或诸如订户身份模块提供服务器(SPS)的网络侧设备。

    POLICY-BASED TECHNIQUES FOR MANAGING ACCESS CONTROL
    144.
    发明申请
    POLICY-BASED TECHNIQUES FOR MANAGING ACCESS CONTROL 有权
    用于管理访问控制的基于策略的技术

    公开(公告)号:US20140143826A1

    公开(公告)日:2014-05-22

    申请号:US14085951

    申请日:2013-11-21

    Applicant: Apple Inc.

    CPC classification number: G06F21/604 H04L63/102 H04L63/105 H04L63/20 H04W12/08

    Abstract: A policy-based framework is described. This policy-based framework may be used to specify the privileges for logical entities to perform operations associated with an access-control element (such as an electronic Subscriber Identity Module) located within a secure element in an electronic device. Note that different logical entities may have different privileges for different operations associated with the same or different access-control elements. Moreover, the policy-based framework may specify types of credentials that are used by the logical entities during authentication, so that different types of credentials may be used for different operations and/or by different logical entities. Furthermore, the policy-based framework may specify the security protocols and security levels that are used by the logical entities during authentication, so that different security protocols and security levels may be used for different operations and/or by different logical entities.

    Abstract translation: 描述了基于策略的框架。 该基于策略的框架可以用于指定逻辑实体执行与位于电子设备中的安全元件内的访问控制元素(例如电子订户身份模块)相关联的操作的权限。 注意,对于与相同或不同的访问控制元素相关联的不同操作,不同的逻辑实体可以具有不同的权限。 此外,基于策略的框架可以指定在认证期间由逻辑实体使用的凭证的类型,使得不同类型的凭证可以用于不同的操作和/或由不同的逻辑实体使用。 此外,基于策略的框架可以指定在认证期间由逻辑实体使用的安全协议和安全级别,使得不同的安全协议和安全级别可以用于不同的操作和/或不同的逻辑实体。

Patent Agency Ranking