Obtaining and using time information on a secure element (SE)

    公开(公告)号:US10680833B2

    公开(公告)日:2020-06-09

    申请号:US15686023

    申请日:2017-08-24

    Applicant: Apple Inc.

    Inventor: Xiangying Yang

    Abstract: A secure element (SE) with a notion of time useful for checking secure items is disclosed herein. Use of Public Key Infrastructure (PKI) with secure elements is improved by verifying secure items used by an SE. Methods of obtaining time information by the SE include push, pull, opportunistic, local interface, and multi-check methods. The SE uses the time information to evaluate arriving and stored public key certificates and to discard those which fail the evaluation. The SE, in some embodiments, uses the time information in cooperation with certificate revocation lists (CRLs) and/or online certificate status protocol (OCSP) stapling procedures. A multi-check architecture is provided herein by which more than entity is involved in checking a time value before the time value reaches the SE. The multi-check architecture uses both PKI and blockchain techniques.

    Apparatus and methods for electronic subscriber identity module (eSIM) installation and interoperability

    公开(公告)号:US10462654B2

    公开(公告)日:2019-10-29

    申请号:US16102189

    申请日:2018-08-13

    Applicant: Apple Inc.

    Abstract: Methods and apparatus for managing processing of electronic Subscriber Identity Modules (eSIM) data at a mobile device are disclosed. An eSIM management entity of an embedded Universal Integrated Circuit Card (eUICC) in the mobile device obtains an encrypted eSIM package, decrypts the eSIM package to obtain eSIM contents formatted generically and not specifically tailored to requirements of the eUICC. In some embodiments, the eSIM contents are formatted based on an abstract syntax notation (ASN) distinguished encoding rules (DER) format. The eSIM management entity parses the formatted eSIM contents to retrieve individual eSIM components and installs each eSIM component for the eSIM in an eSIM security domain on the eUICC. In some embodiments, the eSIM management entity acts as a local, personalization server to provide local Trusted Service Manager (TSM) server functionality for eSIM installation that transforms “generically formatted” eSIM contents into eSIM components that match specific requirements of the eUICC.

    Semi-Static and Dynamic TDD Configuration for 5G-NR

    公开(公告)号:US20180367289A1

    公开(公告)日:2018-12-20

    申请号:US15950368

    申请日:2018-04-11

    Applicant: Apple Inc.

    Abstract: TDD configuration may be dynamically and/or semi-statically signaled to user equipment devices by a base station. Semi-static TDD configuration may include: an initial portion for downlink transmission; a flexible portion; and a terminal portion for uplink transmission. TDD structure of the flexible portion may be determined later by transmission of dynamic physical layer configuration information such as downlink control information (DCI) and/or slot format indicator (SFI). (The SFI may be included in a group common PDCCH of a slot.) The downlink portion and/or the uplink portion may include subsets whose nominal transmit direction is subject to override by transmission of dynamic physical layer configuration information.

    MAC and RRC Multiplexing for Inter-RAT Dual Connectivity UE

    公开(公告)号:US20180367230A1

    公开(公告)日:2018-12-20

    申请号:US16009379

    申请日:2018-06-15

    Applicant: Apple Inc.

    Abstract: Apparatuses, systems, and methods for a wireless device to perform simultaneous uplink activity for multiple RATs in the same carrier using multiplexing at a layer above the physical layer. The wireless device may establish wireless links with first and second base stations, respectively, according to first and second radio access technologies (RATs), respectively. The first base station may provide a first cell operating in a first system bandwidth and the second base station may provide a second cell operating in a second system bandwidth. The wireless device may determine whether inter-RAT uplink coexistence in the same frequency band is enabled. If so, the wireless device may perform uplink activity for both the first RAT and the second RAT in the first system bandwidth by multiplexing uplink data for the first RAT and uplink data for the second RAT at a layer above the physical layer.

    Methods and apparatus for establishing a secure communication channel

    公开(公告)号:US09722975B2

    公开(公告)日:2017-08-01

    申请号:US14789905

    申请日:2015-07-01

    Applicant: Apple Inc.

    Abstract: A method for establishing a secure communication channel between an off-card entity and an embedded Universal Integrated Circuit Card (eUICC) is provided. The method involves establishing symmetric keys that are ephemeral in scope. Specifically, an off-card entity, and each eUICC in a set of eUICCs managed by the off-card entity, possess long-term Public Key Infrastructure (PKI) information. When a secure communication channel is to be established between the off-card entity and an eUICC, the eUICC and the off-card entity can authenticate one another in accordance with the respectively-possessed PKI information (e.g., verifying public keys). After authentication, the off-card entity and the eUICC establish a shared session-based symmetric key for implementing the secure communication channel. Specifically, the shared session-based symmetric key is generated according to whether perfect or half forward security is desired. Once the shared session-based symmetric key is established, the off-card entity and the eUICC can securely communicate information.

    Electronic subscriber identity module application identifier handling
    58.
    发明授权
    Electronic subscriber identity module application identifier handling 有权
    电子用户识别模块应用标识符处理

    公开(公告)号:US09439062B2

    公开(公告)日:2016-09-06

    申请号:US14503048

    申请日:2014-09-30

    Applicant: Apple Inc.

    CPC classification number: H04W8/183 H04W8/205 H04W88/06

    Abstract: Embodiments are described for identifying and accessing an electronic subscriber identity module (eSIM) and associated content of the eSIM in a multiple eSIM configuration. An embedded Universal Integrated Circuit Card (eUICC) can include multiple eSIMs, where each eSIM can include its own file structures and applications. Some embodiments include a processor of a mobile device transmitting a special command to the eUICC, including an identification that uniquely identifies an eSIM in the eUICC. After selecting the eSIM, the processor can access file structures and applications of the selected eSIM. The processor can then use existing commands to access content in the selected eSIM. The special command can direct the eUICC to activate or deactivate content associated with the selected eSIM. Other embodiments include an eUICC platform operating system interacting with eSIMs associated with logical channels to facilitate identification and access to file structures and applications of the eSIMs.

    Abstract translation: 描述了用于在多个eSIM配置中识别和访问电子订户身份模块(eSIM)和eSIM的相关内容的实施例。 嵌入式通用集成电路卡(eUICC)可以包括多个eSIM,每个eSIM可以包括其自己的文件结构和应用程序。 一些实施例包括向eUICC发送特殊命令的移动设备的处理器,包括在eUICC中唯一地标识eSIM的标识。 选择eSIM后,处理器可以访问所选eSIM的文件结构和应用程序。 然后,处理器可以使用现有命令访问所选eSIM中的内容。 特殊命令可以指示eUICC激活或停用与所选eSIM相关联的内容。 其他实施例包括与与逻辑信道相关联的eSIM交互的eUICC平台操作系统,以便于识别和访问eSIM的文件结构和应用。

    ELECTRONIC SUBSCRIBER IDENTITY MODULE PROVISIONING
    59.
    发明申请
    ELECTRONIC SUBSCRIBER IDENTITY MODULE PROVISIONING 有权
    电子订户身份识别模块提供

    公开(公告)号:US20150341791A1

    公开(公告)日:2015-11-26

    申请号:US14715761

    申请日:2015-05-19

    Applicant: Apple Inc.

    Abstract: A method for preparing an eSIM for provisioning is provided. The method can include a provisioning server encrypting the eSIM with a symmetric key. The method can further include the provisioning server, after determining a target eUICC to which the eSIM is to be provisioned, encrypting the symmetric key with a key encryption key derived based at least in part on a private key associated with the provisioning server and a public key associated with the target eUICC. The method can additionally include the provisioning server formatting an eSIM package including the encrypted eSIM, the encrypted symmetric key, and a public key corresponding to the private key associated with the provisioning server. The method can also include the provisioning server sending the eSIM package to the target eUICC.

    Abstract translation: 提供了一种用于准备用于配置的eSIM的方法。 该方法可以包括用对称密钥加密eSIM的供应服务器。 所述方法还可以包括所述供应服务器,在确定要向其提供所述eSIM的目标eUICC之后,至少部分地基于与所述供应服务器相关联的私钥和公共的公共密钥来加密所述对称密钥,所述密钥加密密钥 与目标eUICC相关联的关键。 该方法还可以包括配置服务器格式化包括加密eSIM,加密对称密钥和对应于与配置服务器相关联的私有密钥的公钥的eSIM包。 该方法还可以包括配置服务器将eSIM包发送到目标eUICC。

    RF chain management in a carrier aggregation capable wireless communication device
    60.
    发明授权
    RF chain management in a carrier aggregation capable wireless communication device 有权
    RF链管理在载波聚合能力的无线通信设备中

    公开(公告)号:US09119211B2

    公开(公告)日:2015-08-25

    申请号:US13911826

    申请日:2013-06-06

    Applicant: Apple Inc.

    CPC classification number: H04W76/30 H04L5/001 H04L5/0098 H04W76/15 H04W76/34

    Abstract: A method for managing radio frequency (RF) chains in a carrier aggregation capable wireless communication device is provided. The method can include a wireless communication device using a first RF chain associated with a first component carrier and a second RF chain associated with a second component carrier to support a connection to a network. The method can further include the wireless communication device formatting a deactivation message configured to trigger deactivation of the second component carrier. The method can additionally include the wireless communication device sending the deactivation message to the network to trigger deactivation of the second component carrier. The method can also include the wireless communication device discontinuing usage of the second RF chain to support the connection to the network via the second component carrier after sending the deactivation message.

    Abstract translation: 提供了一种在具有载波聚合能力的无线通信设备中管理射频(RF)链的方法。 该方法可以包括使用与第一分量载波相关联的第一RF链和与第二分量载波相关联的第二RF链以支持到网络的连接的无线通信设备。 该方法还可以包括无线通信设备格式化被配置为触发第二分量载波的去激活的去激活消息。 该方法还可以包括向网络发送去激活消息的无线通信设备,以触发第二分量载波的去激活。 该方法还可以包括无线通信设备在发送去激活消息之后停止使用第二RF链以支持经由第二分量载波到网络的连接。

Patent Agency Ranking