Enhanced Security for Access Stratum Transmission

    公开(公告)号:US20210204129A1

    公开(公告)日:2021-07-01

    申请号:US17057622

    申请日:2018-06-22

    Applicant: Apple Inc.

    Abstract: This disclosure relates to techniques, base stations, and user equipment devices (UEs) for performing base station authentication through access stratum signaling transmissions. The UE may operate in idle mode and may receive an authentication message from a base station through the wireless interface while operating in idle mode. The UE may determine whether a signature comprised within the authentication message is valid, and the UE may continue a connection procedure with the base station based on a determination that the signature is valid. If it is determined that the signature is invalid, the UE may designate the base station as a barred base station and may perform cell re-selection. The authentication message may be one of a radio resource control (RRC) connection setup message, a special RRC message, a media access control (MAC) message, or a random access channel (RACH) message comprising a random access response (RAR) message.

    USER AUTHENTICATION FRAMEWORK
    83.
    发明申请

    公开(公告)号:US20210105265A1

    公开(公告)日:2021-04-08

    申请号:US17033415

    申请日:2020-09-25

    Applicant: Apple Inc.

    Abstract: Techniques are disclosed relating to authenticating a user with a mobile device. In some embodiments, a computing device stores a first signed attestation indicating an ability of the computing device to securely perform a user authentication. The computing device receives a request to store credential information of an identification document issued by an issuing authority to a user for establishing an identity of the user. In response to the request, the computing device sends, to the issuing authority, a request to store the credential information, the sent request including the first signed attestation to indicate an ability to perform a user authentication prior to permitting access to the credential information. In response to an approval of the sent request based on the first signed attestation, the computing device stores the credential information in a secure element of the computing device.

    Methods and apparatus for user authentication and human intent verification in mobile devices

    公开(公告)号:US10856148B2

    公开(公告)日:2020-12-01

    申请号:US16557770

    申请日:2019-08-30

    Applicant: Apple Inc.

    Abstract: Methods and apparatus for user authentication and human intent verification of administrative operations for eSIMs of an eUICC included in a mobile device are disclosed. Certain administrative operations, such as import, modification, and/or export, of an eSIM and/or for an eUICCs firmware can require user authentication and/or human intent verification before execution of the administrative operations are performed or completed by the mobile device. A user of the mobile device provides information to link an external user account to an eSIM upon (or subsequent to) installation on the eUICC. User credentials, such as a user name and password, and/or information generated therefrom, can be used to authenticate the user with an external server. In response to successful user authentication, the administrative operations are performed. Human intent verification can also be performed in conjunction with user authentication to prevent malware from interfering with eSIM and/or eUICC functions of the mobile device.

    Semi-static and dynamic TDD configuration for 5G-NR

    公开(公告)号:US10673605B2

    公开(公告)日:2020-06-02

    申请号:US15950368

    申请日:2018-04-11

    Applicant: Apple Inc.

    Abstract: TDD configuration may be dynamically and/or semi-statically signaled to user equipment devices by a base station. Semi-static TDD configuration may include: an initial portion for downlink transmission; a flexible portion; and a terminal portion for uplink transmission. TDD structure of the flexible portion may be determined later by transmission of dynamic physical layer configuration information such as downlink control information (DCI) and/or slot format indicator (SFI). (The SFI may be included in a group common PDCCH of a slot.) The downlink portion and/or the uplink portion may include subsets whose nominal transmit direction is subject to override by transmission of dynamic physical layer configuration information.

    Control channel for UE power saving

    公开(公告)号:US10609700B2

    公开(公告)日:2020-03-31

    申请号:US15923078

    申请日:2018-03-16

    Applicant: Apple Inc.

    Abstract: A downlink control information (DCI), such as a blanking DCI (bDCI) message may be transmitted by a base station (e.g., eNB) and received by a mobile device (e.g., UE). The bDCI may indicate that the eNB will not transmit a subsequent DCI to the UE for a duration of time. The UE may be in continuous reception mode or connected discontinuous reception (C-DRX) mode. The UE may therefore determine to enter a sleep state or take other action. The bDCI may specify an explicit blanking duration, or an index indicating a blanking duration from a lookup table, and/or the blanking duration (and/or a blanking duration offset value) may be determined in advance, e.g., semi-statically. When the UE is in C-DRX mode, the UE may be configured such that either the sleep/wake period of the C-DRX mode or the blanking period of the bDCI may take precedence over the other.

    Enforcing service policies in embedded UICCs

    公开(公告)号:US10425818B2

    公开(公告)日:2019-09-24

    申请号:US16384844

    申请日:2019-04-15

    Applicant: Apple Inc.

    Abstract: The embodiments set forth techniques for an embedded Universal Integrated Circuit Card (eUICC) to conditionally require, when performing management operations in association with electronic Subscriber Identity Modules (eSIMs), human-based authentication. The eUICC receives a request to perform a management operation in association with an eSIM. In response, the eUICC determines whether a policy being enforced by the eUICC indicates that a human-based authentication is required prior to performing the management operation. Next, the eUICC causes the mobile device to prompt a user of the mobile device to carry out the human-based authentication. The management operation is then performed or ignored in accordance with results of the human-based authentication.

    Mobile device-centric electronic subscriber identity module (eSIM) provisioning

    公开(公告)号:US10425118B2

    公开(公告)日:2019-09-24

    申请号:US15073426

    申请日:2016-03-17

    Applicant: Apple Inc.

    Inventor: Xiangying Yang

    Abstract: The embodiments set forth techniques for enabling mobile devices to trigger an electronic Subscriber Identity Module (eSIM) provisioning process. In some embodiments, a main operating system (OS) of the mobile device communicates a provisioning command to an embedded Universal Integrated Circuit Card (eUICC) included in the mobile device. In turn, the provisioning command causes the eUICC to establish a secure channel with a provisioning server. The provisioning command can include, for example, a network address (e.g., a uniform resource locator (URL), Internet Protocol (IP) address, etc.) associated with the provisioning server, an indication of a security protocol to be used for the secure channel, and/or other information. Using this information, the eUICC establishes the secure channel with the provisioning server, whereupon the provisioning server can provision the eSIM to the eUICC over the secure channel.

Patent Agency Ranking