Abstract:
Provisioning an embedded subscriber identity module (eSIM) in a user equipment (UE) device with personalized subscriber information. A request may be transmitted for personalized subscriber information. The personalized subscriber information may be received. The personalized subscriber information may be installed in an eSIM in the UE device.
Abstract:
Activities involving a secure element (SE) in a mobile device include a background operation. When the SE initiates the background operation, it informs the mobile device of an estimated duration. The mobile device thus recognizes that the SE is not in a stuck state, and maintains a clock signal and a power flow to the SE. Firmware updates to the SE include erasing a non-volatile (NV) memory in the SE in parallel with firmware or software updates to other processor systems in the mobile device. Needed data, for example calibration data or cryptographic key data, is preserved by storing data from some processor systems in one or more supplementary security domains (SSDs) in the SE. When a given processor system completes a firmware update, the needed data is restored to the processor system from the SSD.
Abstract:
Methods and apparatus enabling programming of electronic identification information of a wireless apparatus. In one embodiment, a previously purchased or deployed wireless apparatus is activated by a cellular network. The wireless apparatus connects to the cellular network using an access module to download operating system components and/or access control client components. The described methods and apparatus enable updates, additions and replacement of various components including Electronic Subscriber Identity Module (eSIM) data, OS components. One exemplary implementation of the invention utilizes a trusted key exchange between the device and the cellular network to maintain security.
Abstract:
An apparatus configured to engage in an embedded subscriber identity module (eSIM) profile transfer process to transfer an eSIM profile from a source device executing a first operating system (OS) that implements a first protocol stack related to eSIM profile transfers to a target device executing a second OS that implements a second protocol stack related to eSIM profile transfers, wherein the first protocol stack and the second protocol stack are different, process, based on signaling received from an entitlement server, a token for transferring the eSIM profile, generate, for transmission to the target device, a message comprising the token and establish a secure tunnel via a wireless communication connection with the target device.
Abstract:
This application describes a phased approach to provision eSIM profiles to a wireless device. Credentials are preloaded to an eUICC during manufacture of the eUICC and used subsequently to load eSIM profiles to the eUICC without requiring an active, real-time connection to an MNO provisioning server. Multiple bound profile packages (BPPs) can be pre-generated and encrypted by MNO provisioning servers for an eUICC and transferred to a BPP aggregator server before assembly of the eUICC in a respective wireless device. A local provisioning server in a manufacturing facility mutually authenticates and connects to the BPP aggregator server to download and store one or more of the encrypted BPPs for later installation on the eUICC. The local provisioning server subsequently mutually authenticates and connects to the eUICC to load at least one of the one or more pre-generated, encrypted BPPs to the eUICC during assembly and/or testing of the wireless device.
Abstract:
An apparatus or method for storing records for a plurality of embedded subscriber identity module (eSIM) profiles, wherein a record for each eSIM profile comprises a state of the eSIM profile, receiving, from a first user equipment (UE), a message indicating a first eSIM profile has been deleted from the first UE, changing the state of the first eSIM profile from installed to available, receiving a message requesting the first eSIM profile be allocated to a second UE, changing the state of the first eSIM profile to a state allowing the eSIM profile to be downloaded to the second UE and downloading the first eSIM profile to the second UE.
Abstract:
This application sets forth techniques for dynamically managing a shared provisioning electronic subscriber identity module (eSIM) for a wireless device. A shared (non-unique) provisioning eSIM is installed in the wireless device to provide limited functionality connectivity to services, such as for device activation and user eSIM provisioning. The shared provisioning eSIM includes records of IMSI values organized into groups of IMSI pools and priorities for selecting IMSI values for configuring the shared provisioning eSIM. An on-device shared provisioning SIM/eSIM controller resident on a cellular baseband processor of the wireless device selects and configures the shared provisioning eSIM with IMSI values based on the priorities and on results from scanning for available public land mobile networks (PLMNs). The shared provisioning eSIM can be re-configured with different IMSI values selected from different IMSI pools until successful registration using the configured provisioning eSIM occurs or a maximum number or retries occurs.
Abstract:
A user equipment (UE) is configured to determine that a private enterprise deployed cellular network is available, determine that a Wi-Fi network is available at a same time as the private enterprise deployed cellular network and prioritize connection to the private enterprise deployed cellular network over the Wi-Fi network based on one or more conditions.
Abstract:
The described embodiments set forth techniques for transferring an electronic subscriber identity module (eSIM) with the same integrated circuit card identifier (ICCID) value from a source mobile wireless device to a target mobile wireless device directly with a mobile network operator (MNO) provisioning server. The target mobile wireless device downloads the eSIM from the MNO provisioning server after deletion of the eSIM on the source mobile wireless device and reassignment of the eSIM with the same ICCID value to the target mobile wireless device.
Abstract:
Embodiments described herein relate to transfer of credentials between two mobile wireless devices that are within proximity of each other, via a secure local connection, or via a network-based cloud service, where the two mobile wireless devices are not in proximity to each other. Transfer of credentials can include communication between a source device, a target device, and/or one more network-based servers, which can include mobile network operator (MNO) managed servers, such as an entitlement server, a web-sheet server, an authentication server, a provisioning server, a subscription management data preparation (SM-DP+ ) server, a home subscriber server (HSS), and/or an authentication server, as well as third-party managed servers, such as a cloud service server and/or an identification services server. Authentication can be based at least in part on one or more tokens and/or a trust flag obtained by the source device and provided to the target device.