APPARATUS AND METHODS FOR STORING ELECTRONIC ACCESS CLIENTS
    1.
    发明申请
    APPARATUS AND METHODS FOR STORING ELECTRONIC ACCESS CLIENTS 审中-公开
    用于存储电子访问客户的装置和方法

    公开(公告)号:WO2012138778A2

    公开(公告)日:2012-10-11

    申请号:PCT/US2012/032195

    申请日:2012-04-04

    Abstract: Apparatus and methods for storing and controlling access control clients. In one embodiment, transmitting and receiving devices ensure that only one copy of an eSIM is active at any time. Specifically, each transferred eSIM is encrypted for the destination device; the eSIM from the source device is deleted, deactivated, or otherwise rendered unusable. Various aspects of network infrastructure are also described, including electronic Universal integrated Circuit Card (eUICC) appliances, and mobile devices. Various scenarios for transfer of eSIMs are also disclosed.

    Abstract translation: 用于存储和控制访问控制客户端的装置和方法。 在一个实施例中,发送和接收设备确保在任何时间只有一个eSIM的副本被激活。 具体来说,每个转移的eSIM对目的设备进行加密; 来自源设备的eSIM被删除,停用或以其他方式呈现不可用。 还描述了网络基础设施的各个方面,包括电子通用集成电路卡(eUICC)设备和移动设备。 还披露了用于传送eSIM的各种场景。

    MANAGEMENT SYSTEMS FOR MULTIPLE ACCESS CONTROL ENTITIES
    4.
    发明公开
    MANAGEMENT SYSTEMS FOR MULTIPLE ACCESS CONTROL ENTITIES 有权
    管理系统具有多点触摸控单元

    公开(公告)号:EP2633711A1

    公开(公告)日:2013-09-04

    申请号:EP11793892.8

    申请日:2011-10-20

    Applicant: Apple Inc.

    CPC classification number: H04W8/205

    Abstract: Methods and apparatus for managing multiple user access control entities or clients. For example, in one embodiment, a “wallet” of electronic subscriber identity modules (eSIMs) may be stored and used at a user device and/or distributed to other devices for use thereon. In another embodiment, a networked server may store and distribute eSIM to a plurality of user devices in communication therewith. A database of available eSIM is maintained at the wallet entity and/or at the network which enables request for a particular eSIM to be processed and various rules for the distribution thereof to be implemented. Security precautions are implemented to protect both user and network carrier specific data as the data is transmitted between networked entities. Solutions for eSIM backup and restoration are also described.

    METHODS AND APPARATUS FOR USER AUTHENTICATION AND HUMAN INTENT VERIFICATION IN MOBILE DEVICES
    6.
    发明申请
    METHODS AND APPARATUS FOR USER AUTHENTICATION AND HUMAN INTENT VERIFICATION IN MOBILE DEVICES 审中-公开
    移动设备用户认证和人员验证的方法和设备

    公开(公告)号:WO2016153977A1

    公开(公告)日:2016-09-29

    申请号:PCT/US2016/023062

    申请日:2016-03-18

    Applicant: APPLE INC.

    Abstract: Methods and apparatus for user authentication and human intent verification of administrative operations for eSIMs of an eUICC included in a mobile device are disclosed. Certain administrative operations, such as import, modification, and/or export, of an eSEVI and/or for an eUICCs firmware can require user authentication and/or human intent verification before execution of the administrative operations are performed or completed by the mobile device. A user of the mobile device provides information to link an external user account to an eSEVI upon (or subsequent to) installation on the eUICC. User credentials, such as a user name and password, and/or information generated therefrom, can be used to authenticate the user with an external server. In response to successful user authentication, the administrative operations are performed. Human intent verification can also be performed in conjunction with user authentication to prevent malware from interfering with eSIM and/or eUICC functions of the mobile device.

    Abstract translation: 公开了用于移动设备中包括的eUICC的eSIM的管理操作的用户认证和人为意图验证的方法和装置。 eSEVI和/或eUICC固件的某些管理操作(例如导入,修改和/或导出)可能需要在由移动设备执行或完成执行管理操作之前的用户认证和/或人为意图验证。 移动设备的用户提供在eUICC上(或之后)安装时将外部用户帐户链接到eSEVI的信息。 可以使用诸如用户名和密码的用户凭证和/或从其生成的信息来用外部服务器认证用户。 响应成功的用户认证,执行管理操作。 人员意图验证还可以与用户认证一起执行,以防止恶意软件干扰移动设备的eSIM和/或eUICC功能。

    ELECTRONIC ACCESS CLIENT DISTRIBUTION APPARATUS AND METHODS
    7.
    发明申请
    ELECTRONIC ACCESS CLIENT DISTRIBUTION APPARATUS AND METHODS 审中-公开
    电子访问客户端分发设备和方法

    公开(公告)号:WO2012149219A2

    公开(公告)日:2012-11-01

    申请号:PCT/US2012/035297

    申请日:2012-04-26

    Abstract: Apparatus and methods for distributing access control clients. In one exemplary embodiment, a network infrastructure is disclosed that enables delivery of electronic subscriber identity modules (eSIMs) to secure elements (e.g., electronic Universal Integrated Circuit Cards (eUICCs), etc.) The network architecture includes one or more of: (i) eSIM appliances, (ii) secure eSIM storages, (hi) eSIM managers, (iv) eUICC appliances, (v) eUICC managers, (vi) service provider consoles, (vii) account managers, (viii) Mobile Network Operator (MNO) systems, (ix) eUICCs that are local to one or more devices, and (x) depots. Moreover, each depot may include: (xi) eSIM inventory managers, (xii) system directory services, (xiii) communications managers, and/or (xiv) pending eSIM storages. Functions of the disclosed infrastructure can be flexibly partitioned and/or adapted such that individual parties can host portions of the infrastructure. Exemplary embodiments of the present invention can provide redundancy, thus ensuring maximal uptime for the overall network (or the portion thereof).

    Abstract translation: 用于分发访问控制客户端的设备和方法。 在一个示例性实施例中,公开了能够将电子订户身份模块(eSIM)传送到安全元件(例如,电子通用集成电路卡(eUICC)等)的网络基础设施。网络架构包括以下中的一个或多个:(i )eSIM设备,(ii)安全eSIM存储,(嗨)eSIM管理员,(iv)eUICC设备,(v)eUICC经理,(vi)服务提供商控制台,(vii)客户经理,(viii)移动网络运营商 )系统,(ix)一个或多个设备本地的eUIC,以及(x)仓库。 此外,每个仓库可能包括:(xi)eSIM库存管理器,(xii)系统目录服务,(xiii)通信管理器和/或(xiv)等待的eSIM存储。 所公开的基础设施的功能可以被灵活地划分和/或调整,使得各方可以托管基础结构的一部分。 本发明的示例性实施例可以提供冗余,从而确保整个网络(或其一部分)的最大正常运行时间。

    APPARATUS AND METHODS FOR DISTRIBUTING AND STORING ELECTRONIC ACCESS CLIENTS
    8.
    发明申请
    APPARATUS AND METHODS FOR DISTRIBUTING AND STORING ELECTRONIC ACCESS CLIENTS 审中-公开
    用于分发和存储电子访问客户的装置和方法

    公开(公告)号:WO2012138780A2

    公开(公告)日:2012-10-11

    申请号:PCT/US2012/032198

    申请日:2012-04-04

    Abstract: Apparatus and methods for efficiently distributing and storing access control clients within a network, in one embodiment, the access clients include electronic Subscriber Identity Modules (eSIMs), and an eSIM distribution network infrastructure is described which enforces eSIM uniqueness and conservation, distributes network traffic to prevent "bottle necking" congestion, and provides reasonable disaster recovery capabilities, in one variant, eSIMs are securely stored at electronic Universal Integrated Circuit Card (eUICC) appliances which ensure eSIM uniqueness and conservation. Access to the eUICC appliances is made via multiple eSIM depots, which ensure that network load is distributed. Persistent storage is additionally described, for among other activities, archiving and backup.

    Abstract translation: 在一个实施例中,访问客户端包括电子用户识别模块(eSIM),并且描述了实施eSIM​​独特性和保存的eSIM分发网络基础设施,将网络业务分配到 防止“瓶颈收缩”拥塞,提供合理的灾难恢复能力,一个变通方式是将eSIM安全地存储在电子通用集成电路卡(eUICC)设备中,确保eSIM的独特性和保存性。 通过多个eSIM仓库访问eUICC设备,确保网络负载分布。 另外描述了持久存储,用于其他活动中的归档和备份。

    MANAGEMENT OF CREDENTIALS ON AN ELECTRONIC DEVICE USING AN ONLINE RESOURCE
    9.
    发明申请
    MANAGEMENT OF CREDENTIALS ON AN ELECTRONIC DEVICE USING AN ONLINE RESOURCE 审中-公开
    使用在线资源管理电子设备的证书

    公开(公告)号:WO2015183380A1

    公开(公告)日:2015-12-03

    申请号:PCT/US2015/021185

    申请日:2015-03-18

    Applicant: APPLE INC.

    Abstract: Systems, methods, and computer-readable media for using an online resource to manage credentials on an electronic device are provided. In one example embodiment, a method, at an electronic device, includes, inter alia , receiving account data via an online resource, accessing commerce credential status data from a secure element of the electronic device, providing initial credential management option data via the online resource based on the received account data and based on the accessed commerce credential status data, in response to the providing, receiving a selection of an initial credential management option via the online resource, and changing the status of a credential on the secure element based on the received selection. Additional embodiments are also provided.

    Abstract translation: 提供了用于使用在线资源来管理电子设备上的凭证的系统,方法和计算机可读介质。 在一个示例实施例中,电子设备的方法尤其包括经由在线资源接收帐户数据,从电子设备的安全元件访问商业凭证状态数据,经由在线资源提供初始凭证管理选项数据 基于所接收到的帐户数据并且基于所访问的商业凭证状态数据,响应于所述提供,经由所述在线资源接收初始凭证管理选项的选择,以及基于所述安全元件改变所述安全元件上的凭证的状态 收到选择。 还提供了另外的实施例。

    PROVISIONING OF CREDENTIALS ON AN ELECTRONIC DEVICE USING PASSWORDS COMMUNICATED OVER VERIFIED CHANNELS
    10.
    发明申请
    PROVISIONING OF CREDENTIALS ON AN ELECTRONIC DEVICE USING PASSWORDS COMMUNICATED OVER VERIFIED CHANNELS 审中-公开
    使用通过经过验证通道传播的通讯录在电子设备上提供证书

    公开(公告)号:WO2015080844A1

    公开(公告)日:2015-06-04

    申请号:PCT/US2014/064224

    申请日:2014-11-06

    Applicant: APPLE INC.

    Abstract: Systems, methods, and computer-readable media for provisioning credentials on an electronic device are provided. In one example embodiment, a secure platform system may be in communication with an electronic device and a financial institution subsystem. The secure platform system may be configured to, inter alia , detect a selection of a particular commerce credential, access communication mechanism data indicative of at least one communication mechanism of the device, where the at least one mechanism is configured to receive a communication on the device, transmit information to the financial subsystem, where the information includes the mechanism data and the selection of the particular commerce credential, and instruct the financial subsystem to provision the particular commerce credential in a disabled state on the device and communicate credential enablement data to the device using a particular communication mechanism of the at least one communication mechanism indicated by the communication mechanism data.

    Abstract translation: 提供了用于在电子设备上提供凭证的系统,方法和计算机可读介质。 在一个示例性实施例中,安全平台系统可以与电子设备和金融机构子系统通信。 安全平台系统可以被配置为特别地检测对特定商业凭证的选择,指示设备的至少一个通信机制的访问通信机制数据,其中所述至少一个机制被配置为在其上接收通信 设备,将信息传送到财务子系统,其中信息包括机构数据和特定商业凭证的选择,并指示财务子系统将设备上的特定商业凭证设置为禁用状态,并将凭证启用数据传送到 使用由通信机构数据指示的至少一个通信机制的特定通信机制的设备。

Patent Agency Ranking