IP Library Granted Patent US 10,506,439
Granted Patent B2
US 10,506,439 · App. 15/689,829 · Granted Dec 10, 2019

Secure control of profile policy rules

Inventor: Xiangying Yang (Cupertino, CA)
Assignee: Apple Inc.
H04W12/08G06F21/6218H04L63/0807H04L63/126H04L63/20H04W12/0023H04W12/06H04W12/10H04L63/102H04W48/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,506,439
App. No.
15/689,829
Granted
Dec 10, 2019
Kind
B2
Abstract

A secure element (SE) in a device processes profile policy rule (PPR) update information received in a message. The SE uses a rule authorization table (RAT), when processing the message, to control whether a PPR ON/OFF state will be adjusted. The PPR information identifies a profile. For example, a mobile network operator (MNO) in control of the profile may specify a policy indicating that the profile is to be deleted when the profile is disabled. The SE consults the RAT to determine verification rules for the identified policy. In some embodiments, public key infrastructure techniques authenticating a signature are used to verify that the MNO has signed the message. If the signature fails the verification, no change is made to the PPR ON/OFF state.

Claims (63)

1. A method by a secure element (SE), the method comprising:

i) receiving a binary large object (blob);

ii) parsing a first identifier of a mobile network operator (MNO) from the blob;

iii) parsing a signature from the blob;

iv) obtaining a key;

v) when a verification of the signature with the key indicates that the signature was created by the MNO:

a) parsing profile policy rule (PPR) update information from the blob, and

b) setting a policy rule variable to an enabled state or disabled state based on the PPR update information, wherein the policy rule variable is associated with a profile present on the SE; and

vi) when the verification of the signature with the key indicates that the signature was not created by the MNO:

making no change in the policy rule variable.

2. The method of claim 1 , further comprising:

when the verification of the signature with the key indicates that the signature was not created by the MNO:

discarding the blob.

3. The method of claim 1 , wherein an international mobile subscriber identity (IMSI) associated with the profile is associated with the MNO.

4. The method of claim 1 , wherein: i) the blob was received from an electronic subscriber identity module (eSIM) server via a device, and ii) the SE is housed in the device.

5. The method of claim 1 , wherein the parsing a profile identifier comprises parsing the profile identifier from a metadata portion of the blob.

6. The method of claim 1 , wherein: i) the blob does not comprise a bound profile package (BPP), and ii) the profile present on the SE is in a disabled state.

7. The method of claim 1 , wherein the obtaining a key comprises:

obtaining public key parameters from the blob, wherein the public key parameters are associated with the MNO.

8. The method of claim 1 , wherein the obtaining a key comprises:

obtaining the key from an SE memory location.

9. The method of claim 8 , wherein the obtaining a key comprises:

parsing an object identifier (OID) from the blob;

addressing an SE memory location based on the OID; and

obtaining the key from the SE memory location.

10. The method of claim 9 , wherein the OID is associated with a certificate authority (CA).

11. The method of claim 9 , wherein the OID is associated with the MNO.

12. The method of claim 1 , wherein the obtaining a key comprises:

obtaining the key from a certificate, wherein: i) the blob comprises the certificate and ii) the certificate comprises an identifier of the MNO.

13. The method of claim 12 , wherein: i) the certificate is signed by a certificate issuer (CI), and ii) a trusted list stored in the SE comprises an identifier of the CI.

14. A secure element (SE) comprising:

a memory; and

a processor, wherein the memory includes instructions that when executed by the processor cause the SE to perform operations comprising:

i) receiving a binary large object (blob),

ii) parsing a first identifier of a mobile network operator (MNO) from the blob,

iii) parsing a signature from the blob,

iv) obtaining a key,

v) when a verification of the signature with the key indicates that the signature was created by the MNO:

a) parsing profile policy rule (PPR) update information from the blob, and

b) setting a policy rule variable to an enabled state or disabled state based on the PPR update information, wherein the policy rule variable is associated with a profile present on the SE, and

vi) when the verification of the signature with the key indicates that the signature was not created by the MNO:

making no change in the policy rule variable.

15. The SE of claim 14 , wherein the parsing a profile identifier comprises parsing the profile identifier from a metadata portion of the blob.

16. The SE of claim 14 , wherein the blob does not comprise a bound profile package (BPP).

17. The SE of claim 14 , wherein the obtaining a key comprises:

obtaining the key from a certificate, wherein: i) the blob comprises the certificate and ii) the certificate comprises an identifier of the MNO.

18. The SE of claim 14 , wherein the obtaining a key comprises:

parsing an object identifier (OD) from the blob;

addressing an SE memory location based on the OID; and

obtaining the key from an SE memory location.

19. The SE of claim 18 , wherein the OID is associated with the MNO.

20. A non-transitory computer readable medium including instructions that when executed by a secure element (SE) cause the SE to perform operations comprising:

i) composing a payload, wherein the payload comprises a profile policy rule (PPR) update trigger value;

ii) signing the payload with private key of the SE to produce a first signature;

iii) forming a first message, wherein the first message comprises the payload and the first signature;

iv) sending the first message, via a device housing the SE, to a mobile network operator (MNO) server;

v) receiving a second message, via the device, from the MNO server;

vi) parsing a second signature from the second message;

vii) when a verification of the second signature indicates that the second signature was created by the MNO:

a) parsing a second payload from the second message, and

b) updating a PPR, wherein the updating is based on the second payload; and

viii) when the verification of the second signature indicates that the second signature was not created by the MNO:

making no change in the PPR.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2017
From: YANG, XIANGYING
To: APPLE INC.
Reel/Frame 043450/0876 →
Continuity (2)
Provisional Application 62396035 · Sep 16, 2016
Related Publication 20180084426A1 · Mar 22, 2018