PRE-PERSONALIZATION OF eSIMs TO SUPPORT LARGE-SCALE eSIM DELIVERY
    41.
    发明申请
    PRE-PERSONALIZATION OF eSIMs TO SUPPORT LARGE-SCALE eSIM DELIVERY 审中-公开
    电子商务的预先个性化支持大规模的eSIM交付

    公开(公告)号:US20160345162A1

    公开(公告)日:2016-11-24

    申请号:US15157332

    申请日:2016-05-17

    申请人: Apple Inc.

    摘要: Representative embodiments described herein set forth techniques for optimizing large-scale deliveries of electronic Subscriber Identity Modules (eSIMs) to mobile devices. Specifically, instead of generating and assigning eSIMs when mobile devices are being activated—which can require significant processing overhead—eSIMs are pre-generated with a basic set of information, and are later-assigned to the mobile devices when they are activated. This can provide considerable benefits over conventional approaches that involve generating and assigning eSIMs during mobile device activation, especially when new mobile devices (e.g., smartphones, tablets, etc.) are being launched and a large number of eSIM assignment requests are to be fulfilled in an efficient manner.

    摘要翻译: 本文描述的代表性实施例阐述了用于优化向移动设备大规模地递送电子订户身份模块(eSIM)的技术。 具体而言,代替在移动设备被激活时生成和分配eSIM,这可能需要很大的处理开销 - eSIM是用一组基本信息预先生成的,并且在激活时被分配给移动设备。 这可以提供相当于在移动设备激活期间生成和分配eSIM的传统方法的显着优点,特别是当新的移动设备(例如,智能电话,平板电脑等)正在启动并且大量的eSIM分配请求将被满足时 有效的方式。

    TECHNIQUES FOR DYNAMICALLY SUPPORTING DIFFERENT AUTHENTICATION ALGORITHMS
    42.
    发明申请
    TECHNIQUES FOR DYNAMICALLY SUPPORTING DIFFERENT AUTHENTICATION ALGORITHMS 审中-公开
    动态支持不同认证算法的技术

    公开(公告)号:US20160249214A1

    公开(公告)日:2016-08-25

    申请号:US14868257

    申请日:2015-09-28

    申请人: Apple Inc.

    IPC分类号: H04W12/06

    摘要: Disclosed herein are different techniques for enabling a mobile device to dynamically support different authentication algorithms. A first technique involves configuring an eUICC included in the mobile device to implement various authentication algorithms that are utilized by MNOs (e.g., MNOs with which the mobile device can interact). Specifically, this technique involves the eUICC storing executable code for each of the various authentication algorithms. According to this technique, the eUICC is configured to manage at least one eSIM, where the eSIM includes (i) an identifier that corresponds to one of the various authentication algorithms implemented by the eUICC, and (ii) authentication parameters that are compatible with the authentication algorithm. A second technique involves configuring the eUICC to interface with an eSIM to extract (i) executable code for an authentication algorithm used by an MNO that corresponds to the eSIM, and (ii) authentication parameters that are compatible with the authentication algorithm.

    摘要翻译: 这里公开了使移动设备能够动态地支持不同认证算法的不同技术。 第一种技术涉及配置包括在移动设备中的eUICC来实现由MNO(例如,移动设备可以与之交互的MNO)利用的各种认证算法。 具体地说,这种技术涉及用于各种认证算法中的每一种的可执行代码的eUICC。 根据该技术,eUICC被配置为管理至少一个eSIM,其中eSIM包括(i)对应于由eUICC实现的各种认证算法之一的标识符,以及(ii)与 认证算法。 第二种技术是将eUICC配置为与eSIM进行接口,以提取(i)与eSIM对应的MNO使用的认证算法的可执行代码,以及(ii)与认证算法兼容的认证参数。

    MANAGING FIRMWARE UPDATES FOR INTEGRATED COMPONENTS WITHIN MOBILE DEVICES
    43.
    发明申请
    MANAGING FIRMWARE UPDATES FOR INTEGRATED COMPONENTS WITHIN MOBILE DEVICES 有权
    管理移动设备中的集成组件的固件更新

    公开(公告)号:US20160246585A1

    公开(公告)日:2016-08-25

    申请号:US14629388

    申请日:2015-02-23

    申请人: Apple Inc.

    IPC分类号: G06F9/445 H04W8/24

    摘要: Disclosed herein is a technique for updating firmware of an embedded Universal Integrated Circuit Card (eUICC) included in a mobile device. The technique includes the steps of (1) receiving, from a firmware provider, an indication that an updated firmware is available for the eUICC, (2) in response to the indication, providing, to the firmware provider, (i) a unique identifier (ID) associated with the eUICC, and (ii) a nonce value, (3) subsequent to providing, receiving, from the firmware provider, a firmware update package, wherein the firmware update package includes (i) authentication information, and (ii) the updated firmware, (4) subsequent to verifying the authentication information, persisting, to a memory included in the mobile device, a hash value that corresponds to the updated firmware, and (5) installing the updated firmware on the eUICC.

    摘要翻译: 这里公开了一种用于更新包括在移动设备中的嵌入式通用集成电路卡(eUICC)的固件的技术。 该技术包括以下步骤:(1)从固件提供商接收更新的固件可用于eUICC的指示,(2)响应于该指示,向固件提供商提供(i)唯一标识符 (i)与所述eUICC相关联,以及(ii)随机值,(3)在从所述固件提供商提供固件更新包之后,其中所述固件更新包包括(i)认证信息,和(ii) )更新的固件,(4)在验证认证信息之后,将包含在移动设备中的存储器持久化到与更新的固件相对应的散列值,以及(5)在eUICC上安装更新的固件。

    METHODS AND APPARATUS FOR ESTABLISHING A SECURE COMMUNICATION CHANNEL
    44.
    发明申请
    METHODS AND APPARATUS FOR ESTABLISHING A SECURE COMMUNICATION CHANNEL 有权
    建立安全通信通道的方法和设备

    公开(公告)号:US20160006729A1

    公开(公告)日:2016-01-07

    申请号:US14789905

    申请日:2015-07-01

    申请人: Apple Inc.

    IPC分类号: H04L29/06

    摘要: A method for establishing a secure communication channel between an off-card entity and an embedded Universal Integrated Circuit Card (eUICC) is provided. The method involves establishing symmetric keys that are ephemeral in scope. Specifically, an off-card entity, and each eUICC in a set of eUICCs managed by the off-card entity, possess long-term Public Key Infrastructure (PKI) information. When a secure communication channel is to be established between the off-card entity and an eUICC, the eUICC and the off-card entity can authenticate one another in accordance with the respectively-possessed PKI information (e.g., verifying public keys). After authentication, the off-card entity and the eUICC establish a shared session-based symmetric key for implementing the secure communication channel. Specifically, the shared session-based symmetric key is generated according to whether perfect or half forward security is desired. Once the shared session-based symmetric key is established, the off-card entity and the eUICC can securely communicate information.

    摘要翻译: 提供了一种用于在卡外实体和嵌入式通用集成电路卡(eUICC)之间建立安全通信信道的方法。 该方法涉及建立在范围上短暂的对称密钥。 具体来说,脱卡实体和由脱机实体管理的一组eUICC中的每个eUICC都具有长期公钥基础设施(PKI)信息。 当在离线卡实体和eUICC之间建立一个安全通信信道时,eUICC和离开卡实体可以根据分别拥有的PKI信息(例如,验证公开密钥)来彼此认证。 认证后,离线卡实体和eUICC建立共享的基于会话的对称密钥,用于实现安全通信信道。 具体地,基于会话的对称密钥是根据是否需要完美的或半正向的安全来生成的。 一旦建立了共享的基于会话的对称密钥,离卡实体和eUICC就可以安全地传递信息。

    METHODS AND APPARATUS FOR MANAGING DATA WITHIN A SECURE ELEMENT
    45.
    发明申请
    METHODS AND APPARATUS FOR MANAGING DATA WITHIN A SECURE ELEMENT 审中-公开
    用于在安全元件中管理数据的方法和装置

    公开(公告)号:US20150181433A1

    公开(公告)日:2015-06-25

    申请号:US14639861

    申请日:2015-03-05

    申请人: Apple Inc.

    IPC分类号: H04W12/08 H04L29/06

    摘要: Apparatus and methods for managing and sharing data across multiple access control clients in devices. In one embodiment, the access control clients comprise electronic Subscriber Identity Modules (eSIMs) disposed on an embedded Universal Integrated Circuit Card (eUICC). Each eSIM contains its own data. An Advanced Subscriber Identity Toolkit application maintained within the eUICC facilitates managing and sharing multiple eSIMs' data for various purposes such as sharing phonebook contacts or facilitating automatic switch-over between the multiple eSIMs (such as based on user context).

    摘要翻译: 用于在设备中的多个访问控制客户端上管理和共享数据的装置和方法。 在一个实施例中,访问控制客户端包括设置在嵌入式通用集成电路卡(eUICC)上的电子订户身份模块(eSIM)。 每个eSIM都包含自己的数据。 在eUICC内部维护的高级用户身份工具包应用程序便于管理和共享多个eSIM的数据,用于各种目的,例如共享电话簿联系人或促进多个eSIM之间的自动切换(例如基于用户上下文)。

    METHODS AND APPARATUS FOR AUTOMATED COMMUNICATIONS FORWARDING
    46.
    发明申请
    METHODS AND APPARATUS FOR AUTOMATED COMMUNICATIONS FORWARDING 审中-公开
    自动通信的方法和装置

    公开(公告)号:US20150004955A1

    公开(公告)日:2015-01-01

    申请号:US14323974

    申请日:2014-07-03

    申请人: Apple Inc.

    摘要: Methods and apparatus for the automated updating of forwarding preferences for communications in a telecommunications network. In one embodiment, the network includes a wireless (e.g., cellular) network with user mobile user devices configured to detect a change to their configuration (such as a user changing out SIM cards or virtual access clients). In response, the device causes an update to its associated communication forwarding preferences to reflect the change. If the configuration alteration meets certain criteria (e.g., changes the phone number at which the device may be reached), the device sends a forwarding message instructing a network entity (e.g., routing server) to direct communications addressed to the old phone number to the new phone number. Thus, a user with two or more user profiles (such as two different carrier accounts) may be reached at any number associated with any of the profiles, even if only one profile is currently active.

    摘要翻译: 用于自动更新电信网络中的通信的转发偏好的方法和装置。 在一个实施例中,网络包括无线(例如,蜂窝)网络,其中用户移动用户设备被配置为检测对其配置的改变(诸如用户改变SIM卡或虚拟接入客户端)。 作为响应,设备导致其相关联的通信转发偏好的更新以反映该变化。 如果配置更改满足某些标准(例如,更改可能到达设备的电话号码),则设备发送指示网络实体(例如,路由服务器)的转发消息,以将寻址到旧电话号码的通信指向 新电话号码 因此,即使只有一个配置文件当前是活动的,具有两个或多个用户配置文件(例如两个不同的运营商帐户)的用户可以以与任何配置文件相关联的任何号码达到。

    IMEI BINDING AND DYNAMIC IMEI PROVISIONING FOR WIRELESS DEVICES

    公开(公告)号:US20240007834A1

    公开(公告)日:2024-01-04

    申请号:US18468661

    申请日:2023-09-15

    申请人: Apple Inc.

    IPC分类号: H04W4/50 H04W8/18

    CPC分类号: H04W4/50 H04W8/183

    摘要: This Application sets forth techniques for binding and dynamic provisioning of international mobile equipment identifier (IMEI) values with cellular wireless service profiles, such as subscriber identity modules (SIMs) on physical SIM (pSIM) cards and electronic SIMs (eSIMs) on an embedded universal integrated circuit card (eUICC) of the mobile wireless device. When pSIMs and/or eSIMs change on the mobile wireless device, e.g., based on installation, activation, deactivation, de-installation, etc., IMEI binding logic accounts for the changes and maps IMEI values to pSIMs and/or eSIMs as required. IMEI values can be assigned based on a history of bindings between IMEI values and ICCID values of one or more eSIMS on an eUICC. A most recently used or a newly assigned IMEI value can be associated with an eSIM. Whether to assign an identical IMEI value to multiple eSIMs depends on requirements of associated cellular wireless service subscriptions.

    FLEXIBLE ELECTRONIC SUBSCRIBER IDENTITY MODULE DEPLOYMENT

    公开(公告)号:US20230247414A1

    公开(公告)日:2023-08-03

    申请号:US18161810

    申请日:2023-01-30

    申请人: Apple Inc.

    摘要: Techniques for flexible electronic subscriber identity module (eSIM) deployment to a wireless device by a network server, including generation of multiple eSIMs using an identical eSIM identifier value, such as an identical integrated circuit card identifier (ICCID) value, and subsequent selection of an eSIM based on capabilities of the wireless device. Multiple eSIMs that correspond to different sets of wireless device capabilities are generated without knowledge of the wireless communication standards that a wireless device supports. The multiple eSIMs include a first eSIM that includes fifth generation (5G) wireless communication protocol information and a second eSIM that excludes 5G wireless communication protocol information. The network server selects an eSIM from the multiple eSIMs based on whether the wireless device is 5G capable. After selection and binding of a profile package that includes the eSIM, the remaining eSIMs that use the identical ICCID value are deleted, for security enforcement against cloning.

    EUICC ACCESS WITHOUT BASEBAND WIRELESS SUPPORT

    公开(公告)号:US20230199662A1

    公开(公告)日:2023-06-22

    申请号:US18065607

    申请日:2022-12-13

    申请人: Apple Inc.

    IPC分类号: H04W52/02

    CPC分类号: H04W52/028 H04W52/0264

    摘要: Embodiments described herein relate to managing access to an embedded universal integrated circuit card (eUICC) to obtain subscriber identity module (SIM) information without requiring cellular baseband wireless processing support. A baseband component of a wireless device that connects to the eUICC via a first interface can be in a reduced power state, and under certain conditions a processor external to the eUICC can access the eUICC via a second interface without booting up the baseband component to a normal (full) power state. When access to the eUICC via the first interface through the baseband component is required, the baseband component can be booted to a normal (full) power state to communicate with the eUICC. Additionally, a wireless device in which the baseband component is in a reduced power state or is absent can access one or more services of a mobile network operator (MNO) via a non-cellular wireless interface.