SECURE eSIM SUBSCRIPTION TRANSFER
    11.
    发明公开

    公开(公告)号:US20230403563A1

    公开(公告)日:2023-12-14

    申请号:US18317323

    申请日:2023-05-15

    Applicant: Apple Inc.

    CPC classification number: H04W12/72 H04W12/106 H04L9/3228

    Abstract: The described embodiments set forth techniques for securely transferring a cellular wireless service subscription associated with an electronic subscriber identity module (eSIM) profile from a source wireless device to a target wireless device via communication with servers of a mobile network operator (MNO). An MNO provisioning server encrypts an activation code, used for transfer of the cellular wireless service subscription, with a session key generated based on a one-time-use eUICC public key and a one-time-use server private key. The encrypted activation code is protected from malicious third parties, as only the eUICC of the source wireless device can perform the decryption required by generating an identical session key to recover the activation code. The eUICC of the source wireless device deletes the eSIM profile from the eUICC before providing the activation code to the target wireless device to protect against eSIM profile cloning.

    ELECTRONIC SUBSCRIBER IDENTITY MODULE TRANSFER CREDENTIAL WRAPPING

    公开(公告)号:US20220399993A1

    公开(公告)日:2022-12-15

    申请号:US17820236

    申请日:2022-08-16

    Applicant: Apple Inc.

    Abstract: Embodiments described herein relate to credential wrapping for secure transfer of electronic SIMs (eSIMs) between wireless devices. Transfer of an eSIM from a source device to a target device includes re-encryption of sensitive eSIM data, e.g., eSIM encryption keys, financial transaction credentials, transit authority credentials, and the like, using new encryption keys that include ephemeral elements applicable to a single, particular transfer session between the source device and the target device. The sensitive eSIM data encrypted with a symmetric key (Ks) is re-wrapped with a new header that includes a version of Ks encrypted with a new key encryption key (KEK) and information to derive KEK by the target device. The re-encrypted sensitive SIM data is formatted with additional eSIM data into a new bound profile package (BPP) to transfer the eSIM from the source device to the target device.

    ELECTRONIC SUBSCRIBER IDENTITY MODULE TRANSFER ELIGIBILITY CHECKING

    公开(公告)号:US20210219142A1

    公开(公告)日:2021-07-15

    申请号:US17147410

    申请日:2021-01-12

    Applicant: Apple Inc.

    Abstract: Embodiments described herein relate to eligibility checking for transfer of one or more electronic subscriber identity modules (eSIMs) between two mobile wireless devices. Eligibility to transfer an eSIM to an eUICC of a target device can depend on whether the eUICC of the target device satisfies certain security requirements for the eSIMs to be transferred. The mobile wireless devices can obtain a transfer eligibility result based on communication with one or more network-based servers that can determine compatibility for eSIM transfer.

    ENFORCING SERVICE POLICIES IN EMBEDDED UICCs
    17.
    发明申请

    公开(公告)号:US20180295511A1

    公开(公告)日:2018-10-11

    申请号:US15944738

    申请日:2018-04-03

    Applicant: Apple Inc.

    Abstract: The embodiments set forth techniques for an embedded Universal Integrated Circuit Card (eUICC) to conditionally require, when performing management operations in association with electronic Subscriber Identity Modules (eSIMs), human-based authentication. The eUICC receives a request to perform a management operation in association with an eSIM. In response, the eUICC determines whether a policy being enforced by the eUICC indicates that a human-based authentication is required prior to performing the management operation. Next, the eUICC causes the mobile device to prompt a user of the mobile device to carry out the human-based authentication. The management operation is then performed or ignored in accordance with results of the human-based authentication.

    IN-ADVANCE eSIM MANAGEMENT NOTIFICATION
    18.
    发明申请

    公开(公告)号:US20180295500A1

    公开(公告)日:2018-10-11

    申请号:US15940804

    申请日:2018-03-29

    Applicant: Apple Inc.

    Inventor: Xiangying YANG

    Abstract: Techniques to manage notifications for state changes of eSIMs of a mobile device are described. Processing circuitry of the mobile device provides a command to the eUICC to delete an eSIM. The eUICC changes the state of the eSIM to a locked state and generates a notification of the forthcoming state change before completion of the transition to the deleted state. The processing circuitry sends the notification to a provisioning server and provides to the eUICC a response indicating successful delivery of the notification, and the eUICC subsequently transitions the eSIM to the deleted state. While the eSIM is in the locked state, applications and files of the eSIM can be unusable. In some embodiments, credentials of the eSIM can be reused to re-authenticate with a wireless network in order to deliver the notification to the provisioning server.

    EMBEDDED UNIVERSAL INTEGRATED CIRCUIT CARD (eUICC) PROFILE CONTENT MANAGEMENT

    公开(公告)号:US20180294949A1

    公开(公告)日:2018-10-11

    申请号:US15940797

    申请日:2018-03-29

    Applicant: Apple Inc.

    Inventor: Xiangying YANG

    Abstract: A mobile network operator (MNO) uses a provisioning server to update or install profile content in a profile or electronic subscriber identity module (eSIM). In an exemplary embodiment, the profile is present on a secure element such as an embedded universal integrated circuit card (eUICC) in a wireless device. One or more MNOs use the provisioning server to perform profile content management on profiles in the eUICC. In some embodiments, an MNO has a trust relationship with the provisioning server. In some other embodiments, the MNO does not have a trust relationship with the provisioning server and protects payload targeted for an MNO-associated profile using an over the air (OTA) key.

    METHODS AND APPARATUS FOR ESTABLISHING A SECURE COMMUNICATION CHANNEL

    公开(公告)号:US20180278604A1

    公开(公告)日:2018-09-27

    申请号:US15936331

    申请日:2018-03-26

    Applicant: Apple Inc.

    Abstract: A method for establishing a secure communication channel between an off-card entity and an embedded Universal Integrated Circuit Card (eUICC) is provided. The method involves establishing symmetric keys that are ephemeral in scope. Specifically, an off-card entity, and each eUICC in a set of eUICCs managed by the off-card entity, possess long-term Public Key Infrastructure (PKI) information. When a secure communication channel is to be established between the off-card entity and an eUICC, the eUICC and the off-card entity can authenticate one another in accordance with the respectively-possessed PKI information (e.g., verifying public keys). After authentication, the off-card entity and the eUICC establish a shared session-based symmetric key for implementing the secure communication channel. Specifically, the shared session-based symmetric key is generated according to whether perfect or half forward security is desired. Once the shared session-based symmetric key is established, the off-card entity and the eUICC can securely communicate information.

Patent Agency Ranking