Methods and apparatus for user authentication and human intent verification in mobile devices

    公开(公告)号:US10856148B2

    公开(公告)日:2020-12-01

    申请号:US16557770

    申请日:2019-08-30

    Applicant: Apple Inc.

    Abstract: Methods and apparatus for user authentication and human intent verification of administrative operations for eSIMs of an eUICC included in a mobile device are disclosed. Certain administrative operations, such as import, modification, and/or export, of an eSIM and/or for an eUICCs firmware can require user authentication and/or human intent verification before execution of the administrative operations are performed or completed by the mobile device. A user of the mobile device provides information to link an external user account to an eSIM upon (or subsequent to) installation on the eUICC. User credentials, such as a user name and password, and/or information generated therefrom, can be used to authenticate the user with an external server. In response to successful user authentication, the administrative operations are performed. Human intent verification can also be performed in conjunction with user authentication to prevent malware from interfering with eSIM and/or eUICC functions of the mobile device.

    Access data provisioning apparatus and methods

    公开(公告)号:US10327135B2

    公开(公告)日:2019-06-18

    申请号:US15656988

    申请日:2017-07-21

    Applicant: Apple Inc.

    Abstract: Methods and apparatus for activating a purchased or previously deployed device by a subscriber. In one embodiment, activation includes authenticating the device to a service provider or carrier, and providing the device with data necessary for enabling the service to the device. In one variant, a user device is activated at a retail store, with the assistance of a carrier representative. In another variant, user equipment is activated via a communications network without the assistance of a representative. In yet another variant, the user equipment is activated via the Internet without the assistance of a representative. The provision of access data includes pre-assigning eSIM from a population of unassigned eSIMs to certain devices for various carrier networks. Alternatively, the eSIM may be assigned on an as-needed basis. Unassigned and/or unused eSIMs can be released (or sold back to the vendor) and/or reused. Solutions for eSIM backup and restoration are also described.

    Update of a trusted name list
    35.
    发明授权

    公开(公告)号:US10141966B2

    公开(公告)日:2018-11-27

    申请号:US15807516

    申请日:2017-11-08

    Applicant: Apple Inc.

    Abstract: Methods, devices, and servers for as-needed update of a trusted list are provided herein. An electronic subscriber identity module (eSIM) server receives a request for an eSIM of a particular type from a wireless device. The eSIM server evaluates the particular type and requests an eSIM of the particular type from a second eSIM server, which is not initially trusted by a secure element (SE) of the wireless device. The eSIM server sends a policy update to the wireless device. The wireless device passes the policy update to the SE, for example, a universal integrated circuit card (UICC). The UICC updates the trusted list with an identity of the second eSIM server. When the wireless device downloads a bound profile package (BPP) containing an eSIM from the second eSIM server, the UICC validates the BPP based on the updated trusted list. The eSIM is then installed on the UICC.

    Electronic access client distribution apparatus and methods
    38.
    发明授权
    Electronic access client distribution apparatus and methods 有权
    电子访问客户端分发设备及方法

    公开(公告)号:US09419970B2

    公开(公告)日:2016-08-16

    申请号:US14512137

    申请日:2014-10-10

    Applicant: Apple Inc.

    Abstract: Apparatus and methods for distributing access control clients. In one exemplary embodiment, a network infrastructure is disclosed that enables delivery of electronic subscriber identity modules (eSIMs) to secure elements (e.g., electronic Universal Integrated Circuit Cards (eUICCs), etc.) The network architecture includes one or more of: (i) eSIM appliances, (ii) secure eSIM storages, (iii) eSIM managers, (iv) eUICC appliances, (v) eUICC managers, (vi) service provider consoles, (vii) account managers, (viii) Mobile Network Operator (MNO) systems, (ix) eUICCs that are local to one or more devices, and (x) depots. Moreover, each depot may include: (xi) eSIM inventory managers, (xii) system directory services, (xiii) communications managers, and/or (xiv) pending eSIM storages. Functions of the disclosed infrastructure can be flexibly partitioned and/or adapted such that individual parties can host portions of the infrastructure. Exemplary embodiments of the present invention can provide redundancy, thus ensuring maximal uptime for the overall network (or the portion thereof).

    Abstract translation: 用于分发访问控制客户端的设备和方法。 在一个示例性实施例中,公开了能够将电子订户身份模块(eSIM)传送到安全元件(例如,电子通用集成电路卡(eUICC)等)的网络基础设施。网络架构包括以下中的一个或多个:(i )eSIM设备,(ii)安全eSIM存储,(iii)eSIM管理员,(iv)eUICC设备,(v)eUICC管理人员,(vi)服务提供商控制台,(vii)客户经理,(viii)移动网络运营商 )系统,(ix)一个或多个设备本地的eUIC,以及(x)仓库。 此外,每个仓库可能包括:(xi)eSIM库存管理器,(xii)系统目录服务,(xiii)通信管理器和/或(xiv)未决的eSIM存储。 所公开的基础设施的功能可以灵活地划分和/或调整,使得各方可以托管基础设施的部分。 本发明的示例性实施例可以提供冗余,从而确保整个网络(或其部分)的最大正常运行时间。

    Virtual access module distribution apparatus and methods
    39.
    发明授权
    Virtual access module distribution apparatus and methods 有权
    虚拟接入模块配送设备及方法

    公开(公告)号:US09326322B2

    公开(公告)日:2016-04-26

    申请号:US14288212

    申请日:2014-05-27

    Applicant: Apple Inc.

    CPC classification number: H04W88/06 G06Q30/06 H04L67/34 H04W4/50 H04W8/183

    Abstract: Apparatus and methods for distributing electronic access client modules for use with electronic devices. In one embodiment, the access client modules are virtual subscriber identity modules (VSIMs) that can be downloaded from online services for use with cellular-equipped devices such as smartphones. The online services may include a point of sale (POS) system that sells electronic devices to users. A broker may be used to facilitate the selection of a virtual subscriber identity module. A provisioning service may also be used to provision the selected VSIM.

    Abstract translation: 用于分发用于电子设备的电子访问客户端模块的装置和方法。 在一个实施例中,接入客户端模块是虚拟订户身份模块(VSIM),其可以从在线服务下载,以便与配备蜂窝的设备如智能电话一起使用。 在线服务可以包括向用户销售电子设备的销售点(POS)系统。 可以使用代理来促进对虚拟订户身份模块的选择。 还可以使用供应服务来配置所选择的VSIM。

Patent Agency Ranking