IP Library Granted Patent US 10,057,760
Granted Patent B2
US 10,057,760 · App. 15/340,933 · Granted Aug 21, 2018

Apparatus and methods for Electronic Subscriber Identity Module (ESIM) installation notification

Inventors: Xiangying Yang (Cupertino, CA); Li Li (Los Altos, CA)
Assignee: Apple Inc.
H04W8/183H04L9/3247H04L63/0428H04W4/003H04W4/60H04W8/205H04W12/02H04W12/04H04W12/10H04L63/0823H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,057,760
App. No.
15/340,933
Granted
Aug 21, 2018
Kind
B2
Abstract

Methods and apparatus for provisioning electronic Subscriber Identity Module (eSIM) data by a mobile device are disclosed. Processing circuitry of the mobile device transfers encrypted eSIM data to an embedded Universal Integrated Circuit Card (eUICC) of the mobile device as a series of data messages and receives corresponding response messages for each data message from the eUICC. The response messages from the eUICC are formatted with a tag field that indicates encryption and signature verification properties for the response message. Different values in the tag field indicate whether the response message is (i) encrypted and verifiably signed, (ii) verifiably signed only, or (iii) includes plain text information. Response messages without encryption are readable by the processing circuitry, and processing of the response messages, including forwarding to network elements, such as to a provisioning server are based at least in part on values in the tag field.

Claims (68)

1. A method for provisioning electronic Subscriber Identity Modules (eSIMs) on an embedded Universal Integrated Circuit Card (eUICC) included in a wireless device, the method comprising:

by processing circuitry of the wireless device external to the eUICC:

receiving, from a provisioning server via a secure connection, an encrypted eSIM package;

transferring a block of the encrypted eSIM package to the eUICC for loading and installation in an eSIM security domain on the eUICC;

receiving, from the eUICC in response to transfer of the block of the encrypted eSIM package, a response message that includes a tag field that indicates encryption and signing verification applicable to the response message; and

processing the response message in accordance with a value of the tag field,

wherein:

a first value for the tag field indicates the response message cannot be decrypted by the processing circuitry of the wireless device external to the eUICC;

a second value for the tag field indicates the response message is signed by the eUICC with a certificate that can be verified by the processing circuitry of the wireless device external to the eUICC;

a third value for the tag field indicates the response message is unencrypted and readable by the processing circuitry of the wireless device external to the eUICC; and

responses having the third value for the tag field are used only for local communication via a trusted communication channel between the eUICC and the processing circuitry of the wireless device external to the eUICC, where response messages having the third value for the tag field are not forwarded to the provisioning server.

2. The method of claim 1 , wherein the first value for the tag field indicates the response message is encrypted and signed using session keys applicable for a session established by the provisioning server.

3. The method of claim 2 , further comprising:

by the processing circuitry of the wireless device external to the eUICC:

forwarding the response message to the provisioning server without decrypting contents of the response message.

4. The method of claim 3 , further comprising:

by the processing circuitry of the wireless device external to the eUICC:

verifying integrity of the response message before forwarding the response message to the provisioning server.

5. The method of claim 1 , wherein the second value for the tag field indicates the response message is not encrypted and is verifiably signed by the eUICC.

6. The method of claim 5 , wherein the response message is verifiably signed using a session key having a message authentication code chain used only for local communication between the eUICC and the processing circuitry of the wireless device external to the eUICC and is distinct from one or more session keys used for response messages that include a first value for the tag field, the first value indicating encryption and signing using sessions keys applicable for a session established by the provisioning server.

7. The method of claim 5 , wherein the processing circuitry processes the response message based at least in part on a certificate associated with the eUICC.

8. The method of claim 5 , further comprising:

by the processing circuitry of the wireless device external to the eUICC:

determining whether to forward the response message to the provisioning server based at least in part on contents of the response message.

9. The method of claim 5 , wherein the third value for the tag field indicates the response message includes plain text.

10. The method of claim 1 , further comprising: by the processing circuitry of the wireless device external to the eUICC: providing a status indication of loading and/or installation of the encrypted eSIM package via a user interface of the wireless device.

11. The method of claim 10 , wherein the status indication is based at least in part on information from non-encrypted response messages received from the eUICC.

12. The method of claim 1 , further comprising:

by the processing circuitry of the wireless device external to the eUICC:

forwarding response messages that include error indications and/or warning indications received from the eUICC to the provisioning server;

refraining from forwarding to the provisioning server intermediate success messages received from the eUICC during loading and/or installation of the encrypted eSIM package; and

forwarding a final success message received from the eUICC to the provisioning server after successful completion of loading and/or installation of the encrypted eSIM package.

13. A wireless device configured to provision electronic Subscriber Identity Modules (eSIMs) on an embedded Universal Integrated Circuit Card (eUICC) included in the wireless device, the wireless device comprising processing circuitry configured to carry out steps that include:

receiving, from a provisioning server via a secure connection, an encrypted eSIM package;

transferring a block of the encrypted eSIM package to the eUICC for loading and installation in an eSIM security domain on the eUICC;

receiving, from the eUICC in response to transfer of the block of the encrypted eSIM package, a response message that includes a tag field that indicates encryption and signing verification applicable to the response message; and

processing the response message in accordance with a value of the tag field,

wherein:

a first value for the tag field indicates the response message cannot be decrypted by the processing circuitry of the wireless device external to the eUICC;

a second value for the tag field indicates the response message is signed by the eUICC with a certificate that can be verified by the processing circuitry of the wireless device external to the eUICC;

a third value for the tag field indicates the response message is unencrypted and readable by the processing circuitry of the wireless device external to the eUICC; and

responses having the third value for the tag field are used only for local communication via a trusted communication channel between the eUICC and the processing circuitry of the wireless device external to the eUICC, where response messages having the third value for the tag field are not forwarded to the provisioning server.

14. The wireless device of claim 13 , wherein:

the first value for the tag field indicates the response message is encrypted and signed using session keys applicable for a session established by the provisioning server; and

the steps further include forwarding the response message to the provisioning server without decrypting contents of the response message.

15. The wireless device of claim 14 , wherein:

the steps further include verifying integrity of the response message before forwarding the response message to the provisioning server.

16. The wireless device of claim 13 , wherein:

the second value for the tag field indicates the response message is not encrypted and is verifiably signed by the eUICC using a session key having a message authentication code chain used only for local communication between the eUICC and the processing circuitry of the wireless device external to the eUICC; and

the processing circuitry processes the response message based at least in part on a certificate associated with the eUICC.

17. The wireless device of claim 16 , wherein the steps further include determining whether to forward the response message to the provisioning server based at least in part on contents of the response message.

18. The wireless device of claim 13 , wherein:

the steps further include providing a status indication of loading and/or installation of the encrypted eSIM package via a user interface of the wireless device; and

the status indication is based at least in part on information from non-encrypted response messages received from the eUICC.

19. The wireless device of claim 13 , wherein the steps further include:

forwarding response messages that include error indications and/or warning indications received from the eUICC to the provisioning server;

refraining from forwarding to the provisioning server intermediate success messages received from the eUICC during loading and/or installation of the encrypted SIM package; and

forwarding a final success message received from the eUICC to the provisioning server after successful completion of loading and/or installation of the encrypted eSIM package.

20. A non-transitory computer-readable storage medium storing instructions that, when executed by processing circuitry of a wireless device, cause the processing circuitry to provision electronic Subscriber Identity Modules (eSIMs) on an Universal Integrated Circuit Card (eUICC) included in the wireless device, by carrying out steps that include:

receiving, from a provisioning server via a secure connection, an encrypted eSIM package;

transferring a block of the encrypted eSIM package to the eUICC for loading and installation in an eSIM security domain on the eUICC;

receiving, from the eUICC in response to transfer of the block of the encrypted eSIM package, a response message that includes a tag field that indicates encryption and signing verification applicable to the response message; and

processing the response message in accordance with a value of the tag field,

wherein:

a first value for the tag field indicates the response message cannot be decrypted by the processing circuitry of the wireless device external to the eUICC;

a second value for the tag field indicates the response message is signed by the eUICC with a certificate that can be verified by the processing circuitry of the wireless device external to the eUICC;

a third value for the tag field indicates the response message is unencrypted and readable by the processing circuitry of the wireless device external to the eUICC; and

responses having the third value for the tag field are used only for local communication via a trusted communication channel between the eUICC and the processing circuitry of the wireless device external to the eUICC, where response messages having the third value for the tag field are not forwarded to the provisioning server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2016
From: YANG, XIANGYING; LI, LI
To: APPLE INC.
Reel/Frame 040218/0776 →
Continuity (2)
Provisional Application 62249906 · Nov 2, 2015
Related Publication 20170127264A1 · May 4, 2017
Cited By (1)
US 12,260,007