Virtual subscriber identity module
Abstract
A mobile trusted platform (MTP) configured to provide virtual subscriber identify module (vSIM) services is disclosed. In one embodiment, the MTP includes: a device manufacturer-trusted subsystem (TSS-DM) configured to store and provide credentials related to a manufacturer of the MTP; a mobile network operator-trusted subsystem (MNO-TSS) configured to store and provide credentials related to a mobile network operator (MNO); and a device user/owner-trusted subsystem (TSS-DO/TSS-U) configured to store and provide credentials related to user of the MTP. The TSS-MNO includes a vSIM core services unit, configured to store, provide and process credential information relating to the MNO. The TSS-DO/TSS-U includes a vSIM management unit, configured to store, provide and process credential information relating to the user/owner of the MTP. The TSS-DO/TSS-U and the TSS-MNO communicate through a trusted vSIM service.
Claims
exact text as granted — not AI-modified1 . A method of registering and receiving a virtual subscriber identity module (vSIM) credential, on a mobile trusted processor (MTP) having a vSIM-core trusted execution environment, and a vSIM-management (vSIM-MGMT) trusted execution environment, the method comprising:
sending a request for registration and ticket to a trusted point of sale (POS); receiving a ticket from the trusted POS in response to the request, and other trust verification procedures.
2 . The method of claim 1 further comprising:
establishing a trusted relationship with the POS.
3 . The method of claim 2 wherein the establishing a trusted relationship includes performing an attestation procedure with the POS.
4 . The method of claim 2 wherein the establishing a trusted relationship includes performing an authentication procedure with the POS.
5 . A method executed by a remote point of sale (POS) for registering and providing a virtual subscriber identity module (vSIM) credential to a mobile trusted processor (MTP) having a vSIM-core trusted execution environment, and a vSIM-management (vSIM-MGMT) trusted execution environment, the method comprising:
receiving a request for registration and ticket from the MTP; selecting the a registration ticket; sending subscriber registration data relating to the MTP and a request for a registration ticket to a network provider (MNO); receiving a registration ticket from the MNO; and sending the registration ticket to the MTP.
6 . The method of claim 5 wherein the POS is a trusted POS.
7 . The method of claim 5 wherein sending subscriber registration data relating to the MTP and a request for a registration ticket includes attestation data.
8 . The method of claim 5 further comprising establishing a trusted relationship with the MNO.
9 . The method of claim 5 further comprising establishing a trusted relationship with the MTP.
10 . The method of claim 5 wherein the received ticket request includes at least part of a public encryption key.
11 . The method of claim 5 wherein subscriber registration data relating to the MTP and a request for a registration ticket includes a signature for authentication.
12 . The method of claim 5 wherein registration ticket includes attestation information.
13 . The method of claim 5 wherein registration ticket includes authentication information.
14 . The method of claim 5 wherein registration ticket includes a signed certificate.
15 . The method of claim 5 further comprising:
establishing a certified asymmetric key pair with the MTP.
16 . The method of claim 5 wherein the received registration ticket is encrypted.
17 . The method of claim 5 wherein the POS is not trusted.
18 . A mobile trusted platform (MTP) comprising:
a device manufacturer-trusted subsystem (TSS-DM) configured to store and provide credentials related to a manufacture of the MTP; a mobile network operator-trusted subsystem (TSS-MNO) configured to store and provide credentials related to a mobile network operator (MNO); a device user-trusted subsystem (TSS-U) configured to store and provide credentials related to user of the MTP.
19 . The MTP of claim 18 wherein the TSS-MNO includes a virtual subscriber identity module (vSIM) core services unit, configured to store, provide and process credential information relating to the MNO.
20 . The MTP of claim 18 wherein TSS-DO includes a virtual subscriber identity module (vSIM) management unit, configured to store, provide and process credential information relating to the user of the MTP.
21 . The MTP of claim 18 wherein TSS-DO and the TSS-MNO communicate through a trusted virtual subscriber identity module (vSIM) service.
22 . The MTP of claim 1 further comprising:
a second TSS-U configured to store and provide credentials relating to a second user of the MTP.
23 . The MTP of claim 18 further comprising:
a device owner-trusted subsystem TSS-DO configured to store and provide credentials related an owner of the MTP.
24 . The MTP of claim 18 further comprising:
a second TSS-MNO configured to store and provide credentials related to a second MNO.Join the waitlist — get patent alerts
Track US2009125996A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.