IP Library › Granted Patent US 12,520,146
Granted Patent B2
US 12,520,146 · App. 18/808,879 · Granted Jan 6, 2026

Mobile device authentication without electronic subscriber identity module (eSIM) credentials

Inventors: Xiangying Yang (Cupertino, CA); Jean-Marc Padova (San Francisco, CA); Li Li (Los Altos, CA); Shu Guo (Beijing, CN)
Assignee: Apple Inc.
H04W12/069H04L9/3247H04L9/3263H04W8/205H04W12/041H04W12/0431H04L63/166H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,520,146
App. No.
18/808,879
Filed
Aug 19, 2024
Granted
Jan 6, 2026
Kind
B2
Art Unit
2499
USPC
713/176
Abstract

This application sets forth techniques for authenticating a mobile device with a cellular wireless network without electronic Subscriber Identity Module (eSIM) credentials by using an Extensible Authentication Protocol Transport Layer Security (EAP-TLS) procedure. The mobile device authenticates with an Authentication Server Function (AUSF) of the cellular wireless network using an embedded Universal Integrated Circuit Card (eUICC) certificate. Processing circuitry of the mobile wireless device external to the eUICC implements the EAP-TLS procedure and authenticates validity of the AUSF. In some embodiments, the eUICC provides key generation and storage for a session key for communication between the mobile device and the cellular wireless network. In some embodiments, a third-party managed Unified Data Management (UDM) broker authenticates the mobile device based on knowledge of the eUICC certificate and provides a session key to the cellular wireless network for subsequent communication with the mobile device, upon successful authentication of the mobile device.

Claims (80)

1 . A method for authentication of a user equipment (UE) with a cellular wireless network, the method comprising:

by an embedded universal integrated circuit card (eUICC) of the UE:

receiving, from mobile equipment (ME) comprising processing circuitry of the UE external to the eUICC, a binary large object (blob) comprising content for an extensible authentication protocol (EAP) transport layer security (TLS) authentication response message;

generating a digital signature for the blob using a signature key associated with an eUICC certificate; and

providing, to the ME, the digital signature for the blob; and

by the ME of the UE:

sending, to an authentication server of a cellular wireless network in the EAP-TLS authentication response message, a signed version of the blob that includes the digital signature and a copy of the eUICC certificate for authentication of the UE; and

receiving, from the authentication server, an indication of successful authentication of the UE.

2 . The method of claim 1 , further comprising:

by the ME of the UE:

generating a root session key K AUSF using an elliptic curve key agreement (ECKA) based on a static private key of the eUICC (SK eUICC ) and/or an ephemeral private key (eSK) generated by the ME.

3 . The method of claim 2 , further comprising:

by the ME of the UE:

generating an ephemeral key pair comprising an ephemeral public key (ePK) and the ephemeral private key eSK,

wherein the EAP-TLS authentication response message further comprises the ephemeral public key ePK.

4 . The method of claim 1 , further comprising:

by the eUICC of the UE:

generating a root session key K AUSF using an elliptic curve key agreement (ECKA) based on a static private key of the eUICC (SK eUICC ) and/or an ephemeral private key (eSK) generated by the eUICC; and

providing the root session key K AUSF to the ME of the UE.

5 . The method of claim 4 , further comprising:

by the eUICC of the UE:

generating an ephemeral key pair comprising an ephemeral public key (ePK) and the ephemeral private key eSK; and

providing, to the ME of the UE, the ephemeral public key ePK;

wherein the EAP-TLS authentication response message further comprises the ephemeral public key ePK.

6 . The method of claim 1 , further comprising:

by the ME of the UE:

deriving one or more cryptographic keys for secure communication between the UE and the cellular wireless network based on a root session key K AUSF derived by the ME or by the eUICC.

7 . The method of claim 1 , wherein:

the authentication server comprises an Authentication Service Function (AUSF) located in a core network portion of a home wireless network associated with the UE; and

the ME of the UE sends the signed version of the blob to the AUSF via a security anchor function (SEAF) of a serving cellular wireless network in which the UE is roaming.

8 . An apparatus configured for authentication of a user equipment (UE) with a cellular wireless network, the apparatus comprising:

an embedded universal integrated circuit card (eUICC) configured to:

receive, from mobile equipment (ME) comprising processing circuitry of the UE external to the eUICC, a binary large object (blob) comprising content for an extensible authentication protocol (EAP) transport layer security (TLS) authentication response message;

generate a digital signature for the blob using a signature key associated with an eUICC certificate; and

provide, to the ME, the digital signature for the blob; and

the ME of the UE configured to:

send, to an authentication server of a cellular wireless network in the EAP-TLS authentication response message, a signed version of the blob that includes the digital signature and a copy of the eUICC certificate for authentication of the UE; and

receive, from the authentication server, an indication of successful authentication of the UE.

9 . The apparatus of claim 8 , wherein the ME of the UE is further configured to:

generate a root session key K AUSF using an elliptic curve key agreement (ECKA) based on a static private key of the eUICC (SK eUICC ) and/or an ephemeral private key (eSK) generated by the ME.

10 . The apparatus of claim 9 , wherein the ME of the UE is further configured to:

generate an ephemeral key pair comprising an ephemeral public key (ePK) and the ephemeral private key eSK,

wherein the EAP-TLS authentication response message further comprises the ephemeral public key ePK.

11 . The apparatus of claim 8 , wherein the eUICC of the UE is further configured to:

generate a root session key K AUSF using an elliptic curve key agreement (ECKA) based on a static private key of the eUICC (SK eUICC ) and/or an ephemeral private key (eSK) generated by the eUICC; and

provide the root session key K AUSF to the ME of the UE.

12 . The apparatus of claim 11 , wherein the eUICC of the UE is further configured to:

generate an ephemeral key pair comprising an ephemeral public key (ePK) and the ephemeral private key eSK; and

provide, to the ME of the UE, the ephemeral public key ePK;

wherein the EAP-TLS authentication response message further comprises the ephemeral public key ePK.

13 . The apparatus of claim 8 , wherein the ME of the UE is further configured to:

derive one or more cryptographic keys for secure communication between the UE and the cellular wireless network based on a root session key K AUSF derived by the ME or by the eUICC.

14 . The apparatus of claim 8 , wherein:

the authentication server comprises an Authentication Service Function (AUSF) located in a core network portion of a home wireless network associated with the UE; and

the ME of the UE sends the signed version of the blob to the AUSF via a security anchor function (SEAF) of a serving cellular wireless network in which the UE is roaming.

15 . A user equipment (UE) comprising:

wireless circuitry comprising one or more antennas;

an embedded universal integrated circuit card (eUICC); and

mobile equipment (ME) comprising processing circuitry communicatively coupled to eUICC and to the wireless circuitry, the processing circuitry comprising one or more processors and a memory storing instructions,

wherein the eUICC of the UE is configured to:

receive, from mobile equipment (ME) comprising processing circuitry of the UE external to the eUICC, a binary large object (blob) comprising content for an extensible authentication protocol (EAP) transport layer security (TLS) authentication response message;

generate a digital signature for the blob using a signature key associated with an eUICC certificate; and

provide, to the ME, the digital signature for the blob; and

wherein the ME of the UE is configured to:

send, to an authentication server of a cellular wireless network in the EAP-TLS authentication response message, a signed version of the blob that includes the digital signature and a copy of the eUICC certificate for authentication of the UE; and

receive, from the authentication server, an indication of successful authentication of the UE.

16 . The UE of claim 15 , wherein the ME of the UE is further configured to:

generate a root session key K AUSF using an elliptic curve key agreement (ECKA) based on a static private key of the eUICC (SK eUICC ) and/or an ephemeral private key (eSK) generated by the ME.

17 . The UE of claim 16 , wherein the ME of the UE is further configured to:

generate an ephemeral key pair comprising an ephemeral public key (ePK) and the ephemeral private key eSK,

wherein the EAP-TLS authentication response message further comprises the ephemeral public key ePK.

18 . The UE of claim 15 , wherein the eUICC of the UE is further configured to:

generate a root session key K AUSF using an elliptic curve key agreement (ECKA) based on a static private key of the eUICC (SK eUICC ) and/or an ephemeral private key (eSK) generated by the eUICC; and

provide the root session key K AUSF to the ME of the UE.

19 . The UE of claim 18 , wherein the eUICC of the UE is further configured to:

generate an ephemeral key pair comprising an ephemeral public key (ePK) and the ephemeral private key eSK; and

provide, to the ME of the UE, the ephemeral public key ePK;

wherein the EAP-TLS authentication response message further comprises the ephemeral public key ePK.

20 . The UE of claim 15 , wherein the ME of the UE is further configured to:

derive one or more cryptographic keys for secure communication between the UE and the cellular wireless network based on a root session key K AUSF derived by the ME or by the eUICC.

Continuity (2)
Division 17634950
Related Publication 20240414536A1 · Dec 12, 2024
References Cited (26)
US 10743176B1 · Khan · 2020 [cited by examiner]
US 20080209206A1 · Vaha-Sipila et al. · 2008 [cited by applicant]
US 20090209232A1 · Cha et al. · 2009 [cited by applicant]
US 20110113252A1 · Krischer et al. · 2011 [cited by applicant]
US 20130227646A1 · Haggerty et al. · 2013 [cited by applicant]
US 20160174065A1 · Li · 2016 [cited by examiner]
US 20160277930A1 · Li et al. · 2016 [cited by applicant]
US 20170104750A1 · Li et al. · 2017 [cited by applicant]
US 20170127264A1 · Yang et al. · 2017 [cited by applicant]
US 20170150356A1 · Li et al. · 2017 [cited by applicant]
US 20180013568A1 · Muhanna · 2018 [cited by examiner]
US 20180014178A1 · Baek · 2018 [cited by examiner]
US 20180123803A1 · Park · 2018 [cited by examiner]
US 20190074983A1 · Yang et al. · 2019 [cited by applicant]
US 20190141533A1 · Kang · 2019 [cited by examiner]
US 20190174314A1 · Joseph et al. · 2019 [cited by applicant]
US 20190261178A1 · Rajadurai et al. · 2019 [cited by applicant]
US 20200029212A1 · Lee et al. · 2020 [cited by applicant]
US 20220295276A1 · Yang et al. · 2022 [cited by applicant]
CN 109417709A · 2019 [cited by applicant]
CN 109691157A · 2019 [cited by applicant]
WO 2018008983A1 · 2018 [cited by applicant]
WO 2019028698A1 · 2019 [cited by applicant]
WO 2019137630A1 · 2019 [cited by applicant]
Cordasco et al, Implementation and Performance Evaluation of EAP-TLS-KS, Sep. 1, 2006, IEEE, pp. 1-12. (Year: 2006). [cited by examiner]
Ryu et al, Unlinkable Authentication for Roaming User in Hetergeneous Wireless Networks, Dec. 6, 2013, IEEE, pp. 629-634. (Year: 2013). [cited by examiner]