Mobile device incognito mode with automatic return to standard usage mode
UE devices operate in a temporary incognito mode using alternate identifiers, enhancing privacy by avoiding identifier correlation and data overfilling, while ensuring seamless network connectivity.
Patent Information
- Application Number
- DE112022007964
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-10-28
- Publication Date
- 2025-10-02
AI Technical Summary
Existing user equipment (UE) devices face challenges in maintaining user privacy and avoiding data correlation by consistently using permanent identifiers, which can lead to exposure of user location and identity, and may result in overfilling data stores with user-specific information.
UE devices are configured to operate in a temporary 'incognito mode' using alternate subscriber and hardware identifiers, transitioning automatically to default identifiers after a set time, facilitated by an incognito service provider and a client application managing eSIM profiles and hardware identifiers.
This approach enhances user privacy by avoiding correlation of location with permanent identifiers and prevents overfilling of data stores, while maintaining seamless network connectivity.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
BACKGROUND OF THE INVENTION
[0001] User equipment (UE) devices such as mobile phones, tablet computers, and other devices typically have one or more identifiers that can facilitate wireless communication services. For example, a UE may have one or more hardware identifiers that uniquely identify the UE itself, and the UE may also have one or more subscriber identifiers that uniquely identify a subscription that the UE or a user of the UE has with a mobile network operator (MNO).When such a UE is first switched on or otherwise enters the radio coverage area provided by the mobile network operator or a roaming partner, the UE may acquire a connection by undergoing a connection process that involves the UE possibly transmitting an attach request using one or more of its identifiers, the MNO using the one or more identifiers as the basis for authenticating the UE for service, and the MNO maintaining a record of where the UE is operating so that the MNO can thereafter page and otherwise signal the UE. SUMMARY
[0002] In accordance with the present disclosure, a user's UE could be configured to temporarily operate in incognito mode. Temporary operation in incognito mode could involve transitioning from operating with a default subscriber profile to operating with an incognito subscriber profile and then, after a period of operating with the incognito subscriber profile, automatically reverting to operating with the default subscriber profile.
[0003] Each subscriber profile in this arrangement could have a different respective subscriber identifier, with the default profile having a default subscriber identifier associated with a service subscription of the UE, and the incognito profile having an incognito subscriber identifier that is different from the default subscriber identifier and not associated with the UE's service subscription. Temporarily operating in incognito mode could therefore temporarily involve operating with the incognito subscriber identifier, which may help avoid association with the user's service subscription.
[0004] Furthermore, temporarily operating in incognito mode could involve operating with one or more other temporarily assigned identifiers and then, after the period has elapsed, automatically reverting to operating with one or more default identifiers. For example, if the UE has a permanent hardware identifier, temporarily operating in incognito mode could involve operating with one or more incognito hardware identifiers instead of the permanent hardware identifier, and then, after the period has elapsed, automatically reverting to operating with the permanent hardware identifier instead of the incognito identifier. As another example, if the UE supports voice telephony services and has an assigned default telephone number (e.g., as part of the default subscriber profile), temporarily operating in incognito mode could involve operating with an incognito telephone number (e.g.,as part of the incognito profile) instead of the standard phone number and then automatically return to working with the standard phone number instead of the incognito phone number after the period has expired.
[0005] Accordingly, in one aspect, a method is disclosed that enables a temporary incognito mode for a UE having an embedded subscriber interface module (eSIM). The method may include detecting a trigger for the UE to temporarily operate in an incognito mode, wherein detecting the trigger occurs when the UE is operating in a standard mode in which a first eSIM usage profile having a first subscriber identifier is active in the eSIM. Further, in response to detecting the trigger, the method may include (i) transitioning the UE from operating in the standard mode to operating in the incognito mode, and (ii) after operating in the incognito mode for a period of time, automatically returning the UE from operating in the incognito mode to operating in the standard mode.
[0006] In this method, transitioning from operating in the standard mode to operating in the incognito mode could include (a) deactivating the first eSIM usage profile in the eSIM and activating a second eSIM usage profile in the eSIM in place of the first eSIM usage profile, wherein the second eSIM usage profile has a second subscriber identifier that is different from the first subscriber identifier and was not previously active in the eSIM, and (b) using the second subscriber identifier in accordance with the second eSIM usage profile to facilitate engagement of a wireless communication service.Furthermore, the process of automatically reverting from operating in the incognito mode to operating in the standard mode could include (a) deactivating the second eSIM usage profile in the eSIM and reactivating the first eSIM usage profile in the eSIM instead of the second eSIM usage profile, and (b) using the first subscriber identifier in accordance with the first eSIM usage profile to facilitate procuring a wireless communication service.
[0007] In another aspect, a UE is disclosed. The UE includes a processor, a non-transitory data store, an eSIM, a transceiver, and an antenna supporting communication over the air interface. Furthermore, the non-transitory data store includes program instructions executable by the processor to cause the UE to perform operations such as those mentioned above. The operations could include detecting the UE to temporarily operate in an incognito mode, wherein the detection trigger occurs when the UE operates in a standard mode in which a first eSIM usage profile comprising a first subscriber identifier is active in the eSIM.Further, the operations in response to detecting the trigger could include (i) transitioning from operating in the standard mode to operating in the incognito mode and (ii) after operating in the incognito mode for a period of time, automatically returning from operating in the incognito mode to operating in the standard mode.
[0008] As previously discussed, the act of transitioning could include (a) deactivating the first eSIM usage profile in the eSIM and activating a second eSIM usage profile in the eSIM in place of the first eSIM usage profile, wherein the second eSIM usage profile has a second subscriber identifier that is different from the first subscriber identifier and was not previously active in the eSIM, and (b) using the second subscriber identifier in accordance with the second eSIM usage profile to facilitate snooping on a wireless communication service. Further, the automatic reset process could include (a) deactivating the second eSIM usage profile in the eSIM and reactivating the first eSIM usage profile in the eSIM instead of the second eSIM usage profile, and (b) using the first subscriber identifier according to the first eSIM usage profile to facilitate the procuring of a wireless communication service.
[0009] In another aspect, a non-transitory computer-readable medium having stored thereon instructions executable by a processor for causing a UE to perform operations such as those described above.
[0010] In yet another aspect, a system is disclosed that includes various means for performing each of the operations described herein.
[0011] These and other aspects, advantages, and alternatives will become apparent to those skilled in the art upon reading the following detailed description, with reference, where appropriate, to the accompanying drawings. It should also be understood that the descriptions provided in this summary and below are intended to illustrate the invention by way of example only and not by way of limitation. BRIEF DESCRIPTION OF THE DRAWINGS Fig. Figure 1 is a simplified block diagram of an example UE. Fig. Figure 2 is a simplified block diagram of an example network arrangement for providing wireless cellular communication to the UE. Fig. 3 is a simplified block diagram of an exemplary network arrangement for providing an eSIM usage profile in an eSIM of a UE. Fig. Figure 4 is a simplified block diagram of an example network arrangement supporting a temporary incognito service. Fig. Figure 5 is a simplified block diagram of an example incognito server. Fig. Figure 6 is a flowchart illustrating an example procedure. DETAILED DESCRIPTION
[0012] Example methods, devices, and systems are described herein. However, it should be understood that any disclosed embodiment is not necessarily preferred or advantageous over other embodiments unless so stated. Further, it should be understood that variations from the specific arrangements and processes disclosed are possible. For example, various disclosed entities, components, connections, operations, and other elements could be added, omitted, distributed, replicated, rearranged, reordered, combined, or otherwise altered. Additionally, it is contemplated that various disclosed technical acts could be implemented, at least in part, by a processing entity programmed to perform the acts or to cause one or more other entities to perform the acts.
[0013] With reference to the drawings as noted above, Fig. 1 shows a simplified block diagram of an example UE 100. This example UE includes a wireless communication interface 102, a user interface 104, a location module 106, a host processor 108, a non-transitory data store 110, and an eSIM 112, all of which can communicate with each other via a system bus or other connection 114. Other arrangements would also be possible, including, for example, dedicated connections (e.g., serial interfaces) to facilitate secure communication between specific components, such as between the host processor 108 and the eSIM 112, among other possibilities.
[0014] The wireless communication interface 102 may include one or more transceivers 116 compliant with one or more radio communication protocols, including possibly one or more cellular radio access technology (RAT) technologies such as Long Term Evolution (Long Term Evolution, LTE) and / or 5G New Radio (5G NR) and / or one or more wireless wide area network technologies such as Wi-Fi or others. Each such transceiver may include a transmit / receive chain having a respective modem, amplifier, and other components. Further, the wireless communication interface 102 may include one or more antennas 118 that cooperate with one or more transceivers and support communication over the air interface with the serving network infrastructure.
[0015] The user interface 104 may include one or more components to facilitate interaction with a user of the UE 100. These components may include, but are not limited to, user input components such as a display screen, a speaker, indicator lights, and a haptic feedback mechanism, as well as user input components such as a touchscreen, a microphone, and a keyboard.
[0016] The location determination module 106 could be a Global Navigation Satellite System (GNSS) receiver, such as a Global Positioning System (GPS) receiver, which could facilitate determining the geolocation of the UE 100. Such a module could receive signals from satellites and perform or trigger a triangulation process or the like to determine the geographic location of the UE with a high level of granularity. The location determination module 106 may also take other forms and may be configured to use Wi-Fi signals or other signals to facilitate determining the location of the UE.
[0017] The host processor 108 may include one or more general-purpose processors (e.g., one or more microprocessors, etc.) and / or one or more special-purpose processors (e.g., application-specific integrated circuits, etc.). Furthermore, the non-volatile data storage 110 may include one or more volatile and / or non-volatile components (e.g., read-only memory, random access memory, flash memory, cache memory, etc.), which may be integrated in whole or in part into the host processor.
[0018] As illustrated, the data store 110 may store program instructions 120, including an operating system 122 and applications 124, where the program instructions 120 are executable by the host processor 108 to perform various UE operations. As further shown in the example arrangement, the operating system 122 may define a set of eSIM application programming interfaces (APIs) 126, and the applications 124 may include a local profile assistant (LPA) 128 configured to utilize the eSIM API 126 as a basis for interacting with the eSIM 112 to send commands that cause the eSIM 112 to perform various actions.
[0019] The eSIM 112 could be manufactured in the form of a secure element (e.g., a dedicated system-on-a-chip (SoC)), in particular an embedded universal integrated circuit card (eUICC), which can be soldered or otherwise mounted onto a circuit board of the UE and serves to store and manage eSIM profiles. The eSIM 112 can include an eSIM processor 130 and an eSIM data store 132. Further, although not shown, the eSIM 112 can include a communication interface via which direct, secure communication with the host processor 108 can be established.The eSIM processor 130 may include one or more general-purpose processors and / or one or more special-purpose processors, and the eSIM data store 132 may include one or more non-transitory memory components that may include program instructions executable by the eSIM processor 130 to perform various eSIM operations. The eSIM may also include an eSIM identifier or eUICC identifier, known as an EID, that uniquely identifies the eSIM.
[0020] As further shown, the eSIM data store 132 could store or be configured to store one or more eSIM profiles 134. Each eSIM profile could be a corresponding set of data that enables the UE to be served by a particular MNO (i.e., an actual MNO or a mobile virtual network operator (MVNO)). This could include data and applets, such as one or more network access applications that provide the authority to access the MNO network, and various network access data, such as encryption keys and security algorithm definitions that could enable the MNO network to authenticate the UE. Furthermore, the eSIM profile may also contain other data, such asa Preferred Roaming List (PRL), which could enable the UE to search for and determine, among other things, the network coverage of the MNO and the network coverage of roaming partners, as well as other applications.
[0021] As shown, the eSIM profiles 134 may include one or more non-eSIM usage profiles 136 and one or more eSIM usage profiles 138. A non-eSIM usage profile 136 is a bootstrap or provisioning profile that is not tied to a specific service subscription with an MNO, but rather allows the UE to connect to and be served by an MNO to download and install an eSIM usage profile. An eSIM usage profile 138, on the other hand, is specific to an MNO service subscription and contains data and application logic that enables the UE to be served by the MNO according to that service subscription. Typically, a user enters into a service subscription agreement with an MNO for the MNO to serve the user's UE, and an MNO profile provisioning system then provisions the UE's eSIM with an eSIM usage profile tied to the service subscription.
[0022] As further shown, each of the one or more eSIM usage profiles 138 stored in the eSIM 112 includes a respective subscriber identifier 140 that can uniquely identify the associated service subscription and can further serve to identify the eSIM profile. An example of such a subscriber identifier is the Subscription Permanent Identifier (SUPI) or, more specifically, an International Mobile Subscriber Identity (IMSI). An IMSI is an internationally standardized, unique number that includes a mobile country code (MCC) (identifying the country of service), a mobile network code (MNC) (identifying the serving MNO), and a mobile subscriber identification number (MSIN) (identifying the MNO's subscriber).
[0023] When a user subscribes to an MNO to have the user's UE served by the MNO, the MNO may assign a corresponding IMSI to the UE's subscription and create an eSIM profile for the UE that links this IMSI to the user's service subscription. For example, the MNO may have a pool of IMSIs approved by an international standards organization, and the MNO may select one of these IMSIs and assign it to the user's subscription and create an eSIM usage profile for the user that contains the assigned IMSI and the associated network data access. The MNO may then arrange for this eSIM profile to be installed in the eSIM of the user's UE. Furthermore, the MNO may store associated data, such as the assigned IMSI and the network access data, in the MNO's network, e.g.in an authentication center and / or an associated subscriber profile store, to enable the MNO to authenticate the UE later when the UE wishes to establish a connection for the service.
[0024] Additionally, each of the one or more eSIM usage profiles 138 may also include one or more other identifiers. For example, an eSIM usage profile may also store a telephone number of the UE that may be used for telephone services such as voice calls and / or text messages. For example, an eSIM usage profile may store a Mobile Station Integrated Services Digital Network (MSISDN) number, which is an internationally standardized, unique telephone number that includes a country code (CC), a national destination code (NDC), and a subscriber number (SN).When a user registers with a MNO to have the user's UE served by the MNO, the MNO may assign an MSISDN to the user's UE (possibly using the subscriber number ported from another service subscription) and store this MSISDN in the associated eSIM usage profile, which is installed in the UE's eSIM and registered in the MNO's network.
[0025] If the eSIM 112 contains one or more eSIM usage profiles 138, each eSIM usage profile can be set as either active or inactive and toggled between these two states. For example, the LPA 128 can use the eSIM API 126 to enable or disable an eSIM usage profile, and the eSIM 112 can mark this eSIM usage profile as active or inactive accordingly. Accordingly, if an eSIM usage profile is active, the UE could use this eSIM usage profile as the basis for serving the UE through the associated MNO according to the associated service subscription. For example, the UE could obtain the IMSI and network access data from the active eSIM usage profile and transmit this information to the MNO to facilitate the authentication of the UE, as a condition for connecting to and being served by the MNO when the UE initially powers on the MNO or otherwise enters its coverage.
[0026] The LPA 128 may allow only one eSIM usage profile to be active in the eSIM 112 at any given time. If the eSIM 112 contains multiple eSIM usage profiles, the LPA 128 may enable switching between these eSIM usage profiles by disabling one and enabling another in its place. Alternatively, the LPA 128 may support a multi-profile implementation where two or more eSIM usage profiles are active simultaneously and designate one of the eSIM usage profiles as the primary eSIM usage profile to be used for wireless communication services.
[0027] Although in Fig. 1, the example UE 100 also includes a permanent hardware identifier that can uniquely identify the UE. Examples of such a hardware identifier include a Mobile Equipment Identifier (MEID) and an International Mobile Equipment Identity (IMEI), each representing a globally unique identifier that specifies the manufacturer and serial number of the mobile device's equipment. A UE manufacturer may have a pool of such unique hardware identifiers authorized by an international standards organization. When manufacturing the example UE 100, the manufacturer may then select one of these hardware identifiers and assign it to the UE, and permanently store the assigned hardware identifier in the UE.When a user subscribes to an MNO to use the MNO's services for the UE, the MNO can also register the UE's hardware address in its network, which the MNO can also use as a basis for later authentication of the UE when the UE wishes to establish a connection for services.
[0028] Fig. 2 is a simplified block diagram illustrating an example network arrangement in which the example UE 100 may be served with a wireless mobile service. As shown, the example arrangement includes multiple access nodes 200, such as evolved Node-Bs (eNBs), each providing a respective wireless coverage area 202 for UE provisioning. Each such coverage area 202 could be defined on one or more radio frequency (RF) carriers covering a frequency range and could be frequency division duplex (FDD) with uplink and downlink on separate frequencies, or time division duplex (TDD) with uplink and downlink multiplexed on the same frequency. Further, each coverage area 202 could be defined according to a standard RAT, such asone of the above, with different air interface control channels and bearer channels being provided to facilitate control signaling and communication between the UEs and the access node.
[0029] As further shown, each access node is located as a node in the core network 204 of a mobile network operator, which in turn provides the connection to a transport network 206, such as the Internet. As shown, the core network 204 includes a control plane subsystem 208 and a user plane subsystem 210. As shown, the control plane subsystem 208 may include a network controller 212, a means 214 for authentication, and a subscriber profile store 216, and the user plane subsystem 210 may include one or more gateways 218 to transmit user plane data, such as application layer data, communicated to and from served UEs.In example implementations, the subscriber profile store 216 may contain a subscriber profile record for each service subscription at the MNO that is matched to the associated subscriber identifier and / or UE hardware identifier and includes associated network access credentials and other data.
[0030] Each access node may broadcast a reference signal within its coverage area, which the UE could measure as a basis for detecting the presence and strength of coverage. When the UE 100 initially powers on or otherwise enters coverage of one of the illustrated access nodes 200, the UE may use the PRL in its active eSIM usage profile to search for applicable coverage and thereby determine sufficiently strong coverage by the access node 200. The UE may then responsively assert random access signaling and radio resource control (RRC) signaling to establish an RRC connection (i.e., a radio link layer connection) between the UE and the access node 200. Further, after establishing this RRC connection, the UE may assert a process to register for delivery through the MNO.
[0031] In one example of an attachment process, the UE may generate and transmit an attachment request to the network controller 212 via its RRC connection (and thus via the access node 200). In this attachment request, the UE may specify its subscriber identifier, e.g., the IMSI of the UE's active eSIM usage profile (e.g., the UE's primary active eSIM usage profile). The network controller 212 may then interact with the authentication center 214 to initiate an authentication process of the UE for the service that is matched to the UE's subscriber identifier.For example, the authentication center may use the provided subscriber identifier as a basis to look up an associated record in the subscriber profile 216 memory and then perform authentication signaling with the UE using the network access credentials, for example, to confirm that the UE and the authentication center would calculate a matching authentication result.
[0032] After successful authentication of the UE, the network controller 212 may store in the subscriber profile memory 216 a record of where the UE is served, e.g., which access node or associated location / tracking area of the MNO's network the UE is serving, to enable paging and other messaging to the UE. Furthermore, the network controller 212 may assign a temporary subscriber identifier to the UE, such as a globally unique temporary UE identity (GUTI), which the network controller may provide to the UE and map to the UE's actual subscriber identifier in the subscriber profile memory 216.Assigning this temporary subscriber identifier may allow the UE to later connect to the MNO's network without having to transmit the actual subscriber identifier over the air, since the network controller has a mapping of the temporary subscriber identifier to the UE's actual subscriber identifier and can therefore trigger the associated authentication and other processing.
[0033] In some implementations, the attachment and / or authentication process may also utilize the UE hardware identifier. For example, when the UE sends an attachment request to the network controller 212, or in response to a further request from the network controller, the UE may provide the network controller with the UE's hardware identifier, such as an MEID or IMEI. The authentication center may then use the provided hardware identifier as a basis to look up an associated record in the subscriber profile store 216 and then initiate an authentication process as described above. Further, upon successful authentication, the network controller 212 may similarly record in the subscriber profile store 216 a record of where the UE is served.
[0034] Once the UE has been authenticated for the service, the network controller 212 can then populate the control signal with the user plane subsystem 210 to establish a user plane bearer for the UE for transmitting user plane data between the UE and the transport network 206. With this established bearer, the MNO can then serve the UE according to the UE's service subscription. For example, if the UE has data to transmit over the transport network 206, the UE can exchange control signals with its serving access node 200 to have the access node schedule the uplink transmission of the data. The UE can accordingly transmit the data to the access node as scheduled, and the access node can forward the data along the bearer established by the UE for output to the transport network.Similarly, when data arrives from the transport network for delivery to the UE, it can flow on the UE's bearer to the UE's access node, and the access node can then schedule and intervene in the downlink transmission of the data to the UE.
[0035] Furthermore, while the UE is being served by an access node, the UE may periodically measure the strength of coverage provided by the access node and the strength of coverage provided by neighboring access nodes. If one or more conditions for the measurement are met, the UE and / or its serving access node may trigger the handover of the UE from the serving access node to a neighboring access node. As part of this handover process, the signaling may also be handed over to the network controller 212, and the network controller may responsively update the record indicating where the UE is being served in the MNO's network, e.g., to indicate the coverage area or tracking / location area in which the UE operates.
[0036] As further stated in Fig. 2, the control plane subsystem of the MNO network may further include a mobile location system (MLS) 220. The MLS 220 may operate to determine, store, and report the geolocation of the UE, if authorized to do so. For example, the MLS 220 may cooperate with the UE location determining module 106 of the UE 100 to determine the geolocation of the UE based on GNSS signals received by the UE. Further, the MLS 220 may store the determined geolocation in association with the UE subscriber identifier and / or hardware identifier, and the MLS 220 may report its determined location to various service providers of location-based services, such as navigation services or the like, if authorized to do so.
[0037] Fig. Figure 3 is a simplified block diagram illustrating a network arrangement by which a mobile network operator could provision an eSIM usage profile in the eSIM 112 of UE 100. The arrangement shown includes a profile provisioning system 300 including a subscription manager data preparation (SM-DP+) system 302 and a subscription manager discovery service (SM-DS) 304. This example profile provisioning system 300 is shown interfacing with the MNO's mobile network 306 and also providing access via a public transport network 308, such as the Internet. With this arrangement, the profile provisioning system 300 could interact with the MNO's core network so that subscription profiles can be loaded into the aforementioned subscription profile store.Furthermore, the UE 100 may communicate with the profile provisioning system 300, either via a WLAN connection or via a connection to an MNO that the UE establishes using a non-eSIM usage profile.
[0038] With this example arrangement, the SM-DP+ could handle the creation and installation of eSIM usage profiles, and the SM-DS could enable LPAs to detect and download such profiles. For example, when a user registers with an MNO to serve the example UE 100, the MNO can use the SM-DP+ to generate an eSIM usage profile for the UE specific to that service subscription and the SM-DS to inform the UE's LPA of the availability of that eSIM usage profile for download. Furthermore, the MNO can store associated service profile data, including the associated subscriber identifier and possibly the associated UE hardware identifier, in its subscriber profile memory.The UE's LPA can then begin signaling the SM-DP+ to download the eSIM usage profile and store it in the UE's eSIM. A secure exchange between the LPA and the SM-DP+ typically transmits the UE's EID to the SM-DP+, and the SM-DP+ maintains a mapping between the assigned profile (or IMSI) and this EID. Additionally, the LPA can activate the downloaded eSIM usage profile and signal the SM-DP+ that the eSIM usage profile is active. The MNO can record an indication of the activity status of the process in the subscription profile store. Other profile provisioning processes are also possible.
[0039] As noted above, the present disclosure provides for enabling a temporary incognito service. In particular, the UE may periodically operate in a default mode with one or more default identifiers, and the UE may temporarily enter an incognito mode with one or more incognito identifiers and then automatically return to the default mode with the one or more default identifiers after a certain period of time.
[0040] An example of this process is that the UE may transition from operating with an incognito eSIM usage profile instead of the UE's default eSIM usage profile and, after a certain period of time, automatically return to operating with the default eSIM usage profile instead of the incognito eSIM usage profile. Alternatively, or additionally, the UE may transition to operating with an incognito hardware identifier instead of the UE's permanent hardware identifier and, after a certain period of time, automatically return to operating with the permanent hardware identifier instead of the incognito hardware identifier. Furthermore, if the UE has a default phone number, it may transition to operating with an incognito phone number instead of the default phone number and, after a certain period of time, automatically return to operating with the default phone number instead of the incognito phone number.
[0041] Having the UE temporarily operate with one or more incognito identifiers instead of the UE's one or more default identifiers can help protect the privacy of the UE user. For example, this process can help avoid correlation between the UE's location (e.g., network location or geolocation) and the UE's actual default identifiers, thereby keeping the user's presence at certain locations secret. Furthermore, having the UE temporarily operate with one or more incognito identifiers instead of the UE's one or more default identifiers can help prevent the data store from becoming overcrowded with data related to a given identifier over time.
[0042] In an example implementation, this incognito service could be provided or enabled by an incognito service provider. The incognito service provider may be the same MNO with which the UE has an existing service subscription and for which the UE normally operates under an associated default eSIM usage profile. Alternatively, the incognito service provider could be another MNO or entity, possibly an MVNO, which could provide the UE with an incognito eSIM usage profile for temporary use by the UE and / or an incognito UE hardware identifier and / or an incognito phone number for use by the UE.
[0043] Fig. Figure 4 is a simplified block diagram depicting an exemplary network arrangement to perform an example of this process. Fig. 4 illustrates how the UE 100 is arranged to communicate with an incognito server 400 (or more generally, with a cloud-based computing system, perhaps a secure enclave server or a confidential computing system) and with a profile provisioning system 402. In particular, the figure shows that the UE has a wireless connection to one or more networks 404 that provide a connection to enable the UE to communicate with the incognito server 400 and with the profile provisioning system 402. The one or more networks 404 may include a wireless communication network (e.g., one or more access nodes and a core network) provided by the MNO to which the UE is registered and for which the UE operates under an associated default eSIM usage profile.Alternatively or additionally, the networks may include 404 or more, among others, wireless access points, local area networks, and the public Internet.
[0044] In the example arrangement, the profile provisioning system 402 is a profile provisioning system of an MNO (e.g., a virtual MVNO), and the profile provisioning system 402 could be structured as previously discussed, including an SM-DP+ and an SM-DS to facilitate the creation and installation of eSIM usage profiles on the UE. To further protect user privacy, the SM-DP+ could, in a preferred implementation, be configured not to maintain an association between the UE's EID and an incognito profile (and / or one or more specific incognito identifiers) assigned to the UE. Furthermore, as shown, the incognito server 400 in the example arrangement communicates with the profile provisioning system 402, whereby the incognito server 400 can cooperate with the profile provisioning system 402 to trigger the creation and installation of incognito eSIM usage profiles on the UE.
[0045] As further shown, the incognito server 400 includes or has access to various sets of identifiers that can be assigned to serve as incognito identifiers in accordance with the present disclosure. In the example arrangement, this includes a set of subscriber identifiers 406, a set of UE hardware identifiers 408, and a set of telephone numbers 410. Each of these sets of identifiers can be authorized by a respective authorizing entity and can be in, among other forms, the ones discussed above.For example, the set of subscriber identifiers 406 may be a set of unique IMSIs authorized by a standards organization responsible for authorizing IMSIs, the set of UE hardware identifiers 408 may be a set of unique MEIDs authorized by a standards organization responsible for authorizing MEIDs, and the set of telephone numbers 410 may be a set of unique MSISDNs authorized by a standards organization responsible for authorizing telephone numbers. In a scenario where certain identifiers are on restricted identifier lists (such as MEID on a global restricted MEID list), the sets of authorized identifiers could exclude such restricted identifiers to avoid assigning a restricted identifier for incognito use.
[0046] The incognito server 400 could be operated by an MNO (e.g., an MVNO), which would allow the incognito server to obtain at least the subscriber identifiers (e.g., IMSI) and telephone numbers (e.g., MSISDN), as an MNO would normally obtain such identifiers for assignment to its subscribers. Furthermore, the incognito server 400 may obtain the hardware identifiers (e.g., MEID), just as a UE manufacturing facility would normally obtain such identifiers for assignment to the UEs it manufactures. Each of these sets of identifiers may include, in sequence, hundreds or thousands of such identifiers. Furthermore, the incognito server 400 may be provided in advance with each of these sets of identifiers (or with particularities of such sets), or the incognito server 400 may dynamically acquire various such identifiers as needed, such as by requesting and obtaining the identifiers from issuing entities when desired.
[0047] In an example implementation, the UE 100 could further include an incognito client application 412, which could, among other things, facilitate cooperation with the incognito server 400 and with the UE's LPA to manage the UE's transition to incognito mode and the UE's automatic return to its standard usage mode. For example, the incognito client 412 may signal with the incognito server 400 to facilitate the provision of an incognito eSIM usage profile and / or an incognito UE hardware identifier, and to indicate when this incognito data is being used and when it can be shared with others.Further, the incognito client 412 may signal with the UE's LPA to install and activate the incognito eSIM usage profile and then automatically revert to a standard eSIM usage profile after a certain period of time, and the incognito client 412 may operate to register the incognito UE hardware identifier for use in the UE and then automatically revert to the UE's permanent hardware identifier after a certain period of time.
[0048] The incognito client 412 may further enable an abuse protection service to prevent, for example, abuse of incognito mode to avoid service charges, such as data charges.
[0049] To facilitate transitioning from the UE's default usage mode (e.g., with the eSIM usage profile associated with the UE's normal service subscription) to incognito mode, the client 412 could transmit an incognito_request message to the incognito server 400. In response to this incognito_request message, the incognito server 400 could then randomly select the UE 100 and assign it one or more identifiers for temporary incognito usage.
[0050] As an example, in response to this incognito_request message, the incognito server 400 could randomly select a subscriber identifier from the set of subscriber identifiers 406 for temporary use by the UE 100, and the incognito server 400 could cooperate with the profile provisioning system 402 to have the profile provisioning system 402 create an eSIM usage profile with the selected subscriber identifier and populate a corresponding service profile in an associated MNO subscriber profile store to facilitate authentication and service of the UE operating with this eSIM usage profile. Additionally or alternatively, the incognito server 400 could randomly select a telephone number from the set of telephone numbers 408 for temporary use by the UE 100, and the incognito server 400 could have the profile provisioning system include the selected telephone number in the operational eSIM profile.The incognito server 400 may also set a current usage flag for each such selected identifier (or, for example, remove them from the sets of identifiers) to avoid the same identifier being assigned to more than one UE at the same time.
[0051] Furthermore, the incognito server 400 may respond to the incognito client 412 with information enabling and initiating the download of the newly established eSIM usage profile by the UE's LPA from the profile provisioning system 402. For example, the incognito server 400 may provide the incognito client 412 with a Universal Resource Locator (URL) or other address from which to retrieve the new eSIM usage profile from the profile provisioning system 402, and the incognito client 412 may responsively instruct the UE's LPA to obtain the eSIM usage profile accordingly.Thus, the LPA of the UE may download the eSIM usage profile comprising a subscriber identifier randomly selected by the incognito server 400 from the set of subscriber identifiers 406 and / or a telephone number randomly selected by the incognito server 400 from the set of telephone numbers 410, and the LPA may store the downloaded eSIM usage profile on the UE's eSIM.
[0052] To enter incognito mode with respect to this downloaded and installed eSIM usage profile, the incognito client 412 may instruct and cause the UE to disconnect from any MNO network to which the UE is currently connected, and may then instruct and cause the UE's LPA to deactivate the UE's currently active (e.g., primary) eSIM usage profile and, in its place, activate the new eSIM usage profile as an incognito eSIM usage profile. The UE could then operate at least partially in incognito mode by operating with this incognito eSIM usage profile instead of its default eSIM usage profile.For example, the UE may then re-search for coverage consistent with a PRL in the newly active incognito eSIM usage profile and, upon detection of sufficiently strong coverage, perform random access signaling (RRC) and connection, including authentication, based on the subscriber identifier in the incognito eSIM usage profile. Furthermore, the UE may, if appropriate, offer a telephone service using the telephone number in the incognito eSIM usage profile.
[0053] In an alternative implementation, if there are multiple active eSIM usage profiles on the UE, the incognito client 412 may cause the UE to change the UE's current primary eSIM usage profile to a secondary eSIM usage profile, thereby causing the new incognito eSIM usage profile to be activated and set as the UE's primary eSIM usage profile.
[0054] After operating in incognito mode for a period of time, the incognito client 412 may then automatically reset the UE from incognito mode to the UE's default usage mode. For example, the incognito client 412 may instruct and cause the UE to disconnect from any MNO network to which the UE is currently connected, and may then instruct and cause the UE's LPA to deactivate the incognito eSIM usage profile (including possibly deleting the incognito eSIM usage profile from the eSIM) and instead reactivate (or change to primary) the UE's default eSIM usage profile, i.e., the eSIM usage profile that was replaced by the incognito eSIM usage profile. The UE could then at least partially return to standard mode by using its standard eSIM usage profile instead of the incognito eSIM usage profile.For example, the UE may then re-scan for coverage consistent with a PRL in its default eSIM usage profile and, upon detection of sufficiently strong coverage, perform random access signaling (RRC) and connect, including authentication, based on the subscriber identifier in its default eSIM usage profile. Furthermore, the UE may, if appropriate, offer a phone service using the phone number in its default eSIM usage profile.
[0055] Additionally, the incognito client 412 may inform the incognito server 400 and / or the profile provisioning system 402 when the UE ceases to use the incognito eSIM usage profile. When the UE ceases to use the incognito eSIM usage profile, the incognito server 400 may release the subscriber identifier and / or telephone number temporarily assigned to the UE to make each such identifier newly available in the identifier pool for random selection and assignment. The profile provisioning system 402 may also update its records and the MNO subscriber profile records, such as by removing the service profile data associated with the temporarily assigned incognito eSIM usage profile.
[0056] Furthermore, in addition to or instead of a UE having an incognito eSIM usage profile, the present process may include a UE having an incognito UE hardware identifier. For example, in response to the incognito_request of the incognito client 412, the incognito server 400 may additionally or alternatively randomly select a UE hardware identifier from the set of UE hardware identifiers 408 for temporary use by the UE, and the incognito server 400 may return this UE hardware identifier to the UE in a response, marking the hardware identifier as currently in use (or removing it from the set of hardware identifiers) to avoid duplicate assignment. The incognito client 412 may then store this received UE hardware identifier for use.Furthermore, the incognito server 400 may cooperate with the profile provisioning system 402 and / or with the associated MNO to record the hardware identifier as the hardware identifier of the UE.
[0057] To enter incognito mode with respect to this received UE hardware identifier, possibly as part of the transition to incognito mode discussed above, the incognito client 412 may register the received hardware identifier for use as the incognito hardware identifier instead of the UE's permanent hardware identifier. For example, the incognito client 412 may call an operating system API to set a flag that designs and causes the use of this incognito hardware identifier for incognito, instead of the UE's permanent hardware identifier. The UE could then operate at least partially in incognito mode by operating with this incognito hardware identifier instead of the UE's permanent hardware identifier. For example, if the UE would provide its hardware identifier as part of the attachment and / or authentication process, the UE may provide its incognito hardware identifier instead.Furthermore, if another action is performed on the UE's hardware identifier, the incognito hardware identifier may be used instead.
[0058] After a period of operating in this incognito mode, the UE's automatic reversion from incognito mode to the UE's standard usage mode may involve the incognito client 412 deregistering the incognito hardware identifier from the UE, for example, by calling an operating system API to clear the flag that specified and caused the use of the incognito hardware identifier instead of the UE's permanent hardware identifier. The UE would therefore revert to using its permanent hardware identifier instead of the incognito hardware identifier for associated operations.
[0059] It should also be noted that variations of the process described above are possible. For example, without limitation, an alternative approach could be to provide the UE with a skeleton eSIM operational profile with one or more placeholders that could be populated with one or more temporarily assigned incognito identifiers, and then dynamically populate this basic profile with one or more such incognito identifiers. Such a basic profile could, for example, include an IMSI placeholder that could be populated with a temporarily assigned incognito IMSI and perhaps an MSISDI placeholder that could be populated with a temporarily assigned incognito MSISD, among other possibilities.
[0060] In an exemplary implementation of this alternative approach, instead of a typical eSIM provisioning process, an incognito server or other entity could use its own provisioning process, possibly by interacting with the incognito client 412, to securely load such an eSIM base usage profile into the UE's eSIM. This or other initial provisioning of the base profile into the UE's eSIM could occur at various times, such as during UE manufacturing, when the incognito client is first installed on the UE, or when the UE first transitions to incognito mode, among other possibilities. In addition to further protecting user privacy, the incognito server or other entity performing this process may avoid recording a mapping between the UE's EID and this base profile.
[0061] To use this basic profile, the incognito server can, as described above, randomly provide one or more incognito identifiers for temporary use by the UE to put the UE into incognito mode. However, instead of providing the UE with an incognito eSIM usage profile, the incognito server could provide the selected incognito identifiers to the UE's incognito client, and the incognito client could insert the provided incognito identifiers into the appropriate locations of the UE's eSIM usage profile.For example, the UE's incognito server could provide a randomly selected IMSI, and the incognito client, possibly working with the UE's LPA, could dynamically insert this IMSI into the UE's basic profile instead of an IMSI wildcard to create an incognito eSIM usage profile for the UE, which could be activated in place of the UE's current active and / or primary eSIM usage profile, as discussed above. Conversely, the process of reverting the UE from incognito mode to standard mode could then involve switching back to the UE's standard eSIM usage profile and deleting any temporarily assigned identifiers from the basic profile, allowing the basic profile to be reused later with one or more newly assigned incognito identifiers.
[0062] Furthermore, the UE may be provided with more than one incognito identifier, and the UE may randomly switch between them.
[0063] There may be various triggers for the UE to enter incognito mode from its standard usage mode or vice versa. Without limitation, three example triggers may be (i) location, (ii) time, and (iii) manual user input. In an example implementation, the incognito client 412 may provide a settings dialog that the UE may present on a display screen of its user interface 104, and through this settings dialog, the incognito client may allow a user to specify when the incognito client should monitor for a trigger to enter (or exit) incognito mode and / or through which a user may manually instruct the incognito client to enter (or exit) the UE into incognito mode.
[0064] Regarding location, the incognito client 412 may detect (i.e., learn) when the current location of the UE satisfies a predefined condition, such as the UE's location being within a geographical area where it may be desirable for the UE to operate in incognito mode. The incognito client 412 may make this determination by interacting with the UE location determination module 106, which may further interact with the MLS 220 of the UE's serving MNO, among other possibilities. Furthermore, the incognito client 412 may be provided with data defining a "geofence" area in which incognito mode should or should not be used, possibly through user configuration in the settings dialog of the incognito client 412.The incognito client 412 can thus monitor the location of the UE and compare it with the geofence and, if the location of the UE is inside (or outside) the geofence, put the UE into (or out of) incognito mode.
[0065] Using location as a trigger for entering incognito mode may facilitate the UE operating in incognito mode when the UE is located in a sensitive location, such as a doctor's office or other such facility, where it may be desirable not to correlate the UE's location with the user.
[0066] Regarding time, the incognito client 412 may detect (e.g., learn) when the current time (e.g., time of day, day of the week, etc.) meets a predefined condition, such as that the current time is within a time range during which it may be desirable for the UE to operate in incognito mode. The incognito client 412 may make this determination by monitoring a timer. Furthermore, the incognito client 412 may be provided with data defining a period during which incognito mode should (or should not) be used, or a time at which incognito mode should begin (or end), possibly according to a user's schedule in a calendar stored in the UE and / or possibly also by the user's configuration in the settings dialog of the incognito client 412.The incognito client 412 can thus monitor the current time and compare it with the defined time range or start time and, in response to a condition being met, put the UE into (or out of) incognito mode.
[0067] Using time as a trigger for entering incognito mode may facilitate the UE being in incognito mode at a time when the UE is in a sensitive location, as may be indicated by calendar data in the UE.
[0068] As further noted above, the UE may automatically return from Incognito Mode to its standard usage mode after a certain period of time, such as after a period of 24 hours in which it has been operating in Incognito Mode or after the expiration of another period of time.
[0069] The incognito client 412 may control this automatic reversal by setting a timer when the incognito client 412 transitions the UE into incognito mode and then responding to the expiration of the timer by automatically reversing the UE from incognito mode to standard mode. The duration of this timer may be set to a default duration and / or by user input via the settings dialog of the incognito client 412. Thus, the incognito client 412 may detect expiration of such a timer, reflecting that the UE has operated in incognito mode for a period of time corresponding to the timer duration, and the incognito client 412 may then, in response, reset the UE from incognito mode to standard mode.
[0070] Alternatively or additionally, as mentioned above, there may be one or more other criteria for the incognito client 412 to determine when the UE should be automatically reset from incognito mode to standard mode. For example, in an implementation where the UE's location was a trigger for the UE to enter incognito mode, the incognito client 412 could use the UE's location as a further trigger for automatically resetting the UE to its standard usage mode. For example, if the incognito client 412 has placed the UE into incognito mode in response to detecting that the UE's location is within a predefined geofence, the incognito client 412 may automatically reset the UE to standard mode if it subsequently detects that the UE's location is no longer within that geofence.
[0071] In an example implementation, the incognito client 412 may have previously acquired the incognito data that would facilitate the UE's operation in incognito mode. In this case, the process of transitioning the UE to incognito mode may involve activating this incognito data instead of standard data. Furthermore, once the UE returns from incognito mode to standard mode, the incognito client 412 may acquire new incognito data that, when a trigger is detected, is available for transitioning the UE to incognito mode.
[0072] For example, the incognito client 412 may have previously caused the UE to acquire an incognito eSIM usage profile, and the incognito client 412 may then place the UE into incognito mode by causing the UE's LPA to deactivate the UE's default eSIM usage profile and activate the incognito eSIM usage profile. Once the incognito client 412 then switches the UE from using the incognito eSIM usage profile to using its default eSIM usage profile by deactivating the incognito eSIM usage profile and reactivating the UE's default eSIM usage profile, the incognito client 412 may then work to acquire a new incognito eSIM usage profile, which the incognito client 412 could cause the LPA to also activate instead of the UE's default eSIM usage profile the next time the incognito client 412 detects a trigger for it.
[0073] Likewise, the incognito client 412 may have previously acquired an incognito UE hardware identifier, and the incognito client 412 may then transition the UE into incognito mode by registering this hardware identifier for use by the UE instead of the UE's permanent hardware identifier. Once the incognito client 412 then resets the UE from using the incognito hardware identifier to using its permanent hardware identifier, the incognito client 412 may then work to acquire a new incognito hardware identifier, which the incognito client 412 could prompt the UE to use instead of the UE's permanent hardware identifier the next time the incognito client 412 detects a trigger for doing so.
[0074] Alternatively, the incognito client 412 may dynamically acquire such incognito data during operation when the data is to be used. For example, if the incognito client 412 detects a location and / or time trigger or receives a manual user request trigger to place the UE into incognito mode, the incognito client 412 may, in response, transmit an incognito_request to the incognito server 400 and act as described above to initiate the transition of the UE into incognito mode. Thus, if a trigger for entering incognito mode is detected, the incognito client 412 could cause the UE to be provided with a new incognito eSIM usage profile and cause this incognito eSIM usage profile to be activated instead of the UE's default eSIM usage profile.Furthermore, in response to detecting a trigger for the UE to enter incognito mode, the incognito client may obtain an incognito hardware identifier and register this incognito hardware identifier for use instead of the UE's permanent hardware identifier.
[0075] It should also be noted that detecting triggers for transitioning to incognito mode and / or automatically reverting to standard mode may be coordinated and / or performed in part by the incognito server 400 and / or one or more other entities. For example, the incognito server 400 may detect a location and / or time trigger as described above and, in response, signal the incognito client 412 to initiate the transition to incognito mode.
[0076] Fig. Figure 5 is a simplified block diagram of an exemplary incognito server, for example, in the arrangement of Fig. 4. As shown, the example incognito server includes a network communications interface 500, a processor 502, and a non-volatile data store 504, all of which may be communicatively coupled by a system bus or other interconnection mechanism 506.
[0077] The network communication interface 500 could include any communication module that facilitates communication with other units, as in Fig. 4. The processor 502 could include one or more general-purpose processors (e.g., microprocessors) and / or one or more special-purpose processors (e.g., application-specific integrated circuits). The non-transitory data storage 504 could then include one or more volatile and / or non-volatile components of the memory. As shown, the non-transitory data storage 504 could include instructions 508 that could be executed by the processor 502 to perform various operations of the incognito server. Thus, the incognito server could be configured to perform various such operations by being programmed with instructions executable by the processor 502 to perform these operations, among other possibilities.
[0078] Fig. 6 is next a flowchart depicting an example of a method that may be performed according to the present disclosure to have a UE temporarily operate in an incognito mode and then automatically return to the standard usage mode.
[0079] As in Fig.6, the method may involve detecting a trigger for a UE to temporarily operate in incognito mode at block 600, wherein the trigger is detected when the UE is operating in a standard mode in which a first eSIM usage profile comprising a first subscriber identifier is active in the UE eSIM. Further, in response to detecting the trigger, the method may involve (i) transitioning the UE from operating in the standard mode to operating in incognito mode, and (ii) after operating in incognito mode for a period of time, automatically returning the UE from operating in incognito mode to operating in standard mode at block 602.
[0080] The process of transitioning the UE from operating in the standard mode to operating in the incognito mode involves (a) deactivating the first eSIM usage profile in the eSIM and activating a second eSIM usage profile in the eSIM in place of the first eSIM usage profile, wherein the second eSIM usage profile has a second subscriber identifier that is different from the first subscriber identifier and was not previously active in the eSIM, and (b) using the second subscriber identifier in accordance with the second eSIM usage profile to facilitate roaming of a wireless communication service.
[0081] Furthermore, the process of automatically reverting the UE from operating in the incognito mode to operating in the standard mode could involve (a) deactivating the second eSIM usage profile in the eSIM and reactivating the first eSIM usage profile in the eSIM instead of the second eSIM usage profile, and (b) using the first subscriber identifier according to the first eSIM usage profile to facilitate the seizure of a wireless communication service.
[0082] Additionally, the process of automatically reverting from operating in the incognito mode to operating in the standard mode after operating in the incognito mode for a period of time may involve detecting the expiration of the time period of the UE operating in the incognito mode and, in response to detecting the expiration of the time period of the UE operating in the incognito mode, automatically reverting from operating in the incognito mode to operating in the standard mode.
[0083] Furthermore, the method could further include transmitting a request to assign an incognito profile to the UE from the UE to a cloud-based computing system (e.g., an incognito server), and the cloud-based computing system could be configured to respond to the request by assigning the second subscriber identifier to the UE and triggering the setup of the second eSIM usage profile for download to the UE. In this case, the process of automatically reverting from incognito mode to standard mode could further include transmitting a message from the UE to the cloud-based computing system indicating that the UE has ceased using the second subscriber identifier, and the cloud-based computing system could be configured to respond to the message by releasing the second subscriber identifier for assignment to another UE.
[0084] Additionally, the UE may have a permanent hardware identifier that the UE uses in standard mode to facilitate the acquisition of a wireless communication service. In this case, the method may further involve using a temporary hardware identifier in place of the permanent hardware identifier in incognito mode to facilitate the acquisition of a wireless communication service. Furthermore, the process of automatically reverting from incognito mode to standard mode may further involve reverting to the use of the permanent hardware identifier to facilitate the acquisition of a wireless communication service.
[0085] Furthermore, the method could additionally involve transmitting a request to assign an incognito hardware identifier to the UE from the UE to a cloud-based computing system. The cloud-based computing system could be configured to respond to the request by assigning the temporary hardware identifier to the UE for use by the UE instead of the permanent hardware identifier. Furthermore, the automatic reversion from incognito mode to standard mode could additionally involve transmitting a message from the UE to the cloud-based computing system indicating that the UE has ceased using the temporary hardware identifier, and the cloud-based computing system could be configured to respond to the message by releasing the temporary hardware identifier for assignment to another UE.
[0086] Furthermore, the first eSIM usage profile in the method could be an eSIM usage profile for services from a first mobile network operator, and the second eSIM usage profile could be an eSIM usage profile for services from a second mobile network operator that is different from the first mobile network operator. Alternatively, the second eSIM usage profile could be another eSIM usage profile for services from the first mobile network operator.
[0087] Furthermore, detecting the trigger for the UE to temporarily operate in incognito mode could involve detecting that a current geolocation of the UE meets a predefined location condition. Furthermore, the process of automatically reverting from incognito mode to standard mode after a certain time in incognito mode could involve (i) detecting that a current geolocation of the UE no longer meets the predefined location condition, and (ii) in response to detecting that the current geolocation of the UE no longer meets the predefined location condition, automatically reverting from incognito mode to standard mode.
[0088] Alternatively or additionally, detecting the trigger for the UE to temporarily operate in incognito mode could involve detecting that a current time meets a predefined time condition. Alternatively, the process of detecting the trigger for the UE to temporarily operate in incognito mode involves detecting receipt of user input at the UE (e.g., input to a dialog for the settings of an incognito client or other user interface), defining a request for the UE to temporarily operate in incognito mode.
[0089] Additionally, the method could include pre-storing the second eSIM usage profile in the eSIM in anticipation of detecting the trigger, wherein activating the second eSIM usage profile could involve activating the pre-stored second eSIM usage profile. Alternatively, the act of the UE entering incognito mode could involve (i) the UE downloading the second eSIM usage profile and (ii) storing the downloaded second eSIM usage profile in the eSIM, in which case the act of activating the second eSIM usage profile could involve activating the downloaded second eSIM usage profile.
[0090] Furthermore, the first eSIM usage profile could further comprise a first telephone number configured for the UE to use in the standard mode to facilitate the engagement of a telephone service, and the second eSIM usage profile could further comprise a second telephone number different from the first telephone number and configured for the UE to use in the incognito mode to facilitate the engagement of a telephone service.
[0091] It should also be noted that various operations described herein as being performed with respect to eSIM technology could alternatively be performed with respect to other forms of subscriber identifier technology.
[0092] While the above discussion further provides a possibility to temporarily assign one or more incognito identifiers to a UE and automatically revert to the default UE identifiers after that period, an alternative implementation could involve changing one or more of such assigned incognito identifiers during the period.For example, if the UE operates in incognito mode for nine minutes, (i) the system could randomly select and assign to the UE a first incognito IMSI for the UE to use instead of its default IMSI at the beginning of the nine-minute period, (ii) the system could then assign to the UE a second, different incognito IMSI for the UE to use instead of the first incognito IMSI starting three minutes after the start of the nine-minute period, and (iii) the system could then randomly select and assign to the UE a third, different incognito IMSI for the UE to use instead of the second incognito IMSI starting six minutes after the start of the nine-minute period. After the nine minutes have elapsed, the system could then cause the UE to revert to using the UE's default IMSI. Other examples may also be possible.
[0093] As further explained above, the present disclosure also provides a UE comprising a processor, a non-transitory data store, an eSIM, a transceiver, and an antenna supporting air interface communication, wherein the non-transitory data store contains program instructions executable by the processor to cause the UE to perform operations such as those described above. Additionally, the present disclosure provides a non-transitory computer-readable medium storing instructions executable by a processor to cause a UE to perform such operations.
[0094] Exemplary embodiments have been described above. However, those skilled in the art will understand that changes and modifications may be made to these embodiments without departing from the true scope and spirit of the invention.
Claims
[1] Method comprising: Detecting a trigger for a user equipment (UE) to temporarily operate in an incognito mode, wherein the UE has an embedded subscriber interface module (eSIM), and wherein, when the trigger is detected, the UE operates in a default mode in which a first eSIM usage profile having a first subscriber identifier is active in the eSIM; and in response to detecting the trigger, (i) transitioning by the UE from operating in the standard mode to operating in the incognito mode and (ii) after operating in the incognito mode for a period of time, automatically reverting by the UE from operating in the incognito mode to operating in the standard mode, wherein the transition includes (a) deactivating the first eSIM usage profile in the eSIM and activating a second eSIM usage profile in the eSIM in place of the first eSIM usage profile, wherein the second eSIM usage profile has a second subscriber identifier that is different from the first subscriber identifier and was not previously active in the eSIM, and (b) using the second subscriber identifier in accordance with the second eSIM usage profile to facilitate subscription to a wireless communication service, and wherein the automatic reset includes (a) deactivating the second eSIM usage profile in the eSIM and reactivating the first eSIM usage profile in the eSIM instead of the second eSIM usage profile, and (b) using the first subscriber identifier in accordance with the first eSIM usage profile to facilitate procuring a wireless communication service. [2] The method of claim 1, wherein automatically reverting from working in the incognito mode to working in the standard mode after working in the incognito mode for a period of time comprises: Detecting the expiration of the period during which the UE operates in incognito mode; and in response to detecting the expiration of the period during which the UE operates in the incognito mode, automatically reverting from operating in the incognito mode to operating in the standard mode. [3] The method of claim 1, further comprising transmitting a request to assign an incognito profile to the UE from the UE to a cloud-based computing system, wherein the cloud-based computing system is configured to respond to the request by assigning the second subscriber identifier to the UE and triggering the setup of the second eSIM usage profile for download to the UE, wherein the automatic reversion from the incognito mode to the standard mode further includes transmitting a message from the UE to the cloud-based computing system indicating that the UE has ceased using the second subscriber identifier, wherein the cloud-based computing system is configured to respond to the message by releasing the second subscriber identifier for assignment to another UE. [4] The method of claim 1, wherein the UE has a permanent UE hardware identifier that the UE uses in the standard mode to facilitate the occupation of a wireless communication service, the method further comprising: in incognito mode, using a temporary hardware identifier in place of the permanent hardware identifier to facilitate the occupation of a wireless communication service, wherein automatically resetting from the incognito mode to the standard mode further includes resetting to use the persistent hardware identifier to facilitate occupying a wireless communication service. [5] The method of claim 4, further comprising transmitting a request to assign an incognito hardware identifier to the UE from the UE to a cloud-based computing system, wherein the cloud-based computing system is configured to respond to the request by assigning the temporary hardware identifier to the UE for use by the UE instead of the permanent hardware identifier. wherein automatically reverting from the incognito mode to the standard mode further includes transmitting a message from the UE to the cloud-based computing system indicating that the UE has ceased using the temporary hardware identifier, wherein the cloud-based computing system is configured to respond to the message by releasing the temporary hardware identifier for assignment to another UE. [6] The method of claim 1, wherein the first eSIM usage profile is provided for the service by a first mobile network operator and wherein the second eSIM usage profile is provided for the service by a second mobile network operator that is different from the first mobile network operator. [7] The method of claim 1, wherein deactivating the second eSIM usage profile in the eSIM comprises deleting the second eSIM usage profile from the eSIM. [8] The method of claim 1, wherein detecting the trigger for the UE to temporarily operate in incognito mode comprises detecting that a current geolocation of the UE satisfies a predefined condition for the location. [9] The method of claim 8, wherein automatically reverting from working in the incognito mode to working in the standard mode after working in the incognito mode for a period of time comprises: Detecting that a current geolocation of the UE no longer meets the predefined location condition; and in response to detecting that the current geolocation of the UE no longer meets the predefined location condition, automatically reverting from working in incognito mode to working in standard mode. [10] The method of claim 1, wherein detecting the trigger for the UE to temporarily operate in the incognito mode comprises detecting that a current time satisfies a predefined time condition. [11] The method of claim 1, wherein detecting the trigger for the UE to temporarily operate in the incognito mode comprises detecting receipt of a user input to the UE defining a request for the UE to temporarily operate in the incognito mode. [12] The method of claim 1, further comprising pre-storing the second eSIM usage profile in the eSIM in anticipation of detecting the trigger, wherein activating the second eSIM usage profile comprises activating the pre-stored second eSIM usage profile. [13] The method of claim 1, wherein transitioning by the UE to operate in the incognito mode further comprises (i) downloading by the UE the second eSIM usage profile and (ii) storing the downloaded second eSIM usage profile in the eSIM, wherein activating the second eSIM usage profile comprises activating the downloaded second eSIM usage profile. [14] The method of claim 1, wherein the first eSIM usage profile further comprises a first telephone number configured for use by the UE in the standard mode to facilitate the engagement of a telephone service, and wherein the second eSIM usage profile further comprises a second telephone number different from the first telephone number and configured for use by the UE in the incognito mode to facilitate the engagement of a telephone service. [15] A terminal device (UE) comprising: a processor; non-transitory data storage; an embedded subscriber interface module (eSIM); a transmitter-receiver; and an antenna structure supporting air interface communication; wherein the non-transitory data store contains program instructions executable by the processor to cause the UE to perform operations including: Detecting a trigger for the UE to temporarily operate in an incognito mode, wherein when the trigger is detected, the UE operates in a standard mode in which a first eSIM usage profile having a first subscriber identifier in the eSIM is active, and in response to detecting the trigger, (i) transition from working in the standard mode to working in the incognito mode and (ii) after working in the incognito mode for a period of time, automatically revert from working in the incognito mode to working in the standard mode, wherein the transition includes (a) deactivating the first eSIM usage profile in the eSIM and activating a second eSIM usage profile in the eSIM in place of the first eSIM usage profile, wherein the second eSIM usage profile has a second subscriber identifier that is different from the first subscriber identifier and was not previously active in the eSIM, and (b) using the second subscriber identifier in accordance with the second eSIM usage profile to facilitate subscription to a wireless communication service, and wherein the automatic reset includes (a) deactivating the second eSIM usage profile in the eSIM and reactivating the first eSIM usage profile in the eSIM instead of the second eSIM usage profile, and (b) using the first subscriber identifier in accordance with the first eSIM usage profile to facilitate procuring a wireless communication service. [16] The UE of claim 15, wherein automatically reverting from working in incognito mode to working in standard mode after working in incognito mode for a period of time comprises: Detecting the expiration of the period during which the UE operates in incognito mode; and in response to detecting the expiration of the period during which the UE operates in the incognito mode, automatically reverting from operating in the incognito mode to operating in the standard mode. [17] UE according to claim 15, wherein the UE has a permanent UE hardware identifier that the UE uses in the standard mode to facilitate the occupation of a wireless communication service, wherein the UE in the incognito mode uses a temporary hardware identifier in place of the permanent hardware identifier to facilitate the occupation of a wireless communication service, and wherein automatically resetting from the incognito mode to the standard mode further includes resetting to use the persistent hardware identifier to facilitate occupying a wireless communication service. [18] The UE of claim 15, wherein detecting the trigger for the UE to temporarily operate in incognito mode comprises detecting at least one context selected from the group consisting of (i) a current geolocation of the UE that satisfies a predefined condition, and (ii) a current time that satisfies a predefined condition. [19] A non-transitory computer-readable medium having instructions stored thereon that are executable by a processor to cause a terminal device (UE) to perform operations comprising: Detecting a trigger for the UE to temporarily operate in an incognito mode, wherein the UE has an embedded subscriber interface module (eSIM), and wherein, when the trigger is detected, the UE operates in a default mode in which a first eSIM usage profile having a first subscriber identifier is active in the eSIM; and in response to detecting the trigger, (i) transition from working in the standard mode to working in the incognito mode and (ii) after working in the incognito mode for a period of time, automatically revert from working in the incognito mode to working in the standard mode, wherein the transition includes (a) deactivating the first eSIM usage profile in the eSIM and activating a second eSIM usage profile in the eSIM in place of the first eSIM usage profile, wherein the second eSIM usage profile has a second subscriber identifier that is different from the first subscriber identifier and was not previously active in the eSIM, and (b) using the second subscriber identifier in accordance with the second eSIM usage profile to facilitate subscription to a wireless communication service, and wherein the automatic reset includes (a) deactivating the second eSIM usage profile in the eSIM and reactivating the first eSIM usage profile in the eSIM instead of the second eSIM usage profile, and (b) using the first subscriber identifier in accordance with the first eSIM usage profile to facilitate procuring a wireless communication service. [20] A non-transitory computer-readable medium according to claim 19, wherein the UE has a permanent UE hardware identifier that the UE uses in the standard mode to facilitate the occupation of a wireless communication service, wherein the UE in the incognito mode uses a temporary hardware identifier in place of the permanent hardware identifier to facilitate the occupation of a wireless communication service, and wherein automatically resetting from the incognito mode to the standard mode further includes resetting to use the persistent hardware identifier to facilitate occupying a wireless communication service.