On-demand network connection
The method allows communication-enabled applications to activate a secure profile for cellular network data sessions, addressing the lack of active connections in mobile devices and ensuring application functionality.
Patent Information
- Application Number
- JP2025032596
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2019-10-16
- Filing Date
- 2025-03-03
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2040-10-16
AI Technical Summary
Mobile devices often lack an active data communication connection, such as when roaming is disabled or Wi-Fi is unavailable, preventing communication-enabled applications from functioning fully, as existing methods relying on Wi-Fi or cellular connections do not address this issue.
A method for operating a communication-enabled application on a mobile device that detects the need for data transmission and activates a secure profile for a cellular network data communication session, allowing the application to establish a connection using a secure profile via an operating system and the cellular network.
Enables communication-enabled applications to function even when traditional data connections are unavailable, ensuring seamless operation by establishing a cellular network data session when needed.
Smart Images

Figure 2025098039000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to telecommunication and wireless communication systems.
Background Art
[0002] Generally, data communication-enabled applications installed on mobile devices, particularly smartphones, require a data communication connection to function fully. Without a data communication connection, applications that support data communication cannot provide all their functions to the user.
[0003] Considering the case of a large-scale taxi dispatch application, a data communication connection may be required to transmit the location on demand and order a taxi.
[0004] However, a mobile device does not always have an active data communication connection. For example, when the mobile device is overseas (such as when the user of the mobile device is traveling in a country other than their home country), for some reason, roaming on the overseas mobile phone network is not enabled, or the device is not connected to a Wi-Fi network or any other applicable access network for accessing the Internet. Without an Internet connection, an application that supports communication for calling a large-scale taxi cannot perform its main function.
[0005] Therefore, it is desirable to more efficiently provide options for maximizing the functionality of communication-enabled applications resident on mobile devices.
[0006] US Patent No. 9,325,941 of the prior art discloses a method for managing communication channels of a communication-enabled application, where a primary channel can use a first wireless access technology such as Wi-Fi or cellular connection, a secondary channel can use a second wireless access technology different from the first one, and data of the communication-enabled application can be transmitted simultaneously or redundantly via both the primary channel and the secondary channel. Since the method described in US9,325,941 requires the use of a first wireless access technology such as Wi-Fi, it does not provide a solution to the problem identified above of the lack of Wi-Fi network connection.
[0007] Prior art document US9,661,530 discloses a method in which a mobile device communicates with a cellular network via a cellular connection and a Wi-Fi network via a Wi-Fi connection, and generates a plurality of statistics from backhaul data to generate backhaul statistics. Based on a plurality of statistics passing through one or more thresholds, the mobile device can select a Wi-Fi connection for use in a communication-enabled application of the mobile device. Since this method requires the use of a Wi-Fi network via a Wi-Fi connection, the problem identified above is not solved. SUMMARY OF THE INVENTION
[0008] According to a first aspect of the present disclosure, there is provided a method of operating a communication-enabled application on a mobile device, including detecting a need for data transmission when the application currently has a data communication status that does not match the requirements of the mobile device, and sending a request to activate a secure profile of a cellular network data communication session.
[0009] According to a second aspect of the present disclosure, a method for controlling a secure profile via an operating system installed on a mobile device, the method comprising receiving a request from an application installed on the mobile device, the request being related to authentication of the application for accessing cellular network data communication via the secure profile, and activating a cellular network data communication session using the secure profile. A method is provided.
[0010] According to a third aspect of the present invention, a mobile device is provided, the mobile device including a memory circuit configured to store an operating system and an application, and a processing circuit configured to execute the method according to the first and second aspects when composed of the operating system and / or the application.
[0011] According to a fourth aspect of the present disclosure, a method for operating a cellular network to provide cellular network data communication to a mobile device, the method comprising receiving, by the cellular network, a request for establishing a cellular network data communication session from a mobile device that executes the method described with respect to the first and second aspects, and the cellular network establishing a cellular network data communication session with the mobile device using a secure profile included in the mobile device. A method is provided.
[0012] According to a fifth aspect of the present disclosure, a cellular network configured to execute the method according to the fourth aspect is provided.
[0013] Further features and advantages of the present invention will become apparent from the following description of the preferred embodiments of the present invention, given by way of example only, made with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0014]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8A
Figure 8B
[0015] Applications (or apps) running on a mobile device may require data transmission to perform primary and / or secondary functions. For example, a taxi booking application that connects a user of a mobile device to a taxi for the provision of a transportation service may use data transmission. Data representing the profile of the user of the mobile device, the current location of the user of the mobile device, and the intended destination of the user of the mobile device can all be sent to a service provider and / or a taxi operator to provide the taxi service. A billing function can also be performed via data transmission between the mobile device to enable the user of the mobile device to pay the service fee to the taxi operator.
[0016] Other examples of applications that require data transmission to perform primary and / or secondary functions include media streaming applications for providing music and / or video services to a user of a mobile device, news applications for providing news articles to a user of a mobile device, email applications, and the like.
[0017] In some cases, the mobile device may not have a data communication status that is compatible with the need to send data for an application. For example, the mobile device may not have an active secure profile at present, and thus may not be able to execute data transmission currently. The device may have an inactive communication status with respect to the cellular network data interface and / or any other data interface of the mobile device, and thus may not be able to meet the need for data transmission of the application. In other cases, the mobile device may have an inappropriate communication status with respect to its cellular network interface. For example, the mobile device may have enabled one or more secure profiles, but the application may not have the permission to access a cellular network data communication session (or data session) that uses the active secure profile(s). For example, when one or more active secure profiles are associated with an existing cellular network subscription to provide messaging, multimedia, and voice over IP services to the user of the mobile device, the existing cellular network subscription may restrict data communication to one or more approved applications and / or groups of purposes. By restricting data transmission of the cellular network subscription, excessive data usage and thus unexpected charges can be prevented.
[0018] The specific examples described herein relate to the provision of temporary or persistent connections for execution on a mobile device (or "user equipment, UE") or for use in an application currently being executed. The temporary or persistent connection can be provided using the secure profile of the mobile device, which is enabled and / or activated in response to a request from the application.
[0019] In certain embodiments, a data session established through the use of a secure profile may be restricted by the application, the mobile device, and / or the cellular network providing the data session. The restrictions of the data session may be specified by the application in a request for the data session and / or may be pre-determined and associated with the secure profile used to provide the data session. The restrictions may include which applications within the mobile device are authorized to use the data session, restrictions on the amount and type of data transmitted during the data session, and / or restrictions on the IP addresses accessible to the mobile device via the data session.
[0020] FIG. 1 shows a mobile device 100, which may be referred to as a user equipment, UE, including at least one processor 120, a computer-readable storage device 130, and one or more communication modules 140. The mobile device 100 is a device such as a smartphone or a laptop, supports cellular data connection, and can install and run software applications thereon. Although the term "mobile device" is used here, it should be understood that other remote devices capable of connecting to a cellular network, for example, devices permanently or semi-permanently installed in a remote location, may be used. For example, appliances, vehicles, and other machines capable of cellular network connection can be regarded as "mobile devices". The mobile device 100 is equipped with an operating system 170 (OS) included in the computer-readable storage device 130, for example, an operating system of a vendor. Examples of operating systems include open-source operating systems such as iOS (registered trademark), Android (registered trademark), MacOS, Microsoft Windows (registered trademark), and Linux-based operating systems. In some examples, the computer-readable storage device 130 may be referred to as a computer-readable storage medium. However, it should be understood that the computer-readable storage device 130 may include one or more physical storage media or may be a virtualized storage device.
[0021] The at least one processor 120 may include various processing devices including a central processing unit (CPU), a graphics processing unit (GPU), and / or specialized processing devices for performing specific functions inside the mobile device 100. The at least one processor 120 may include other specialized processing devices such as an application-specific integrated circuit (ASIC), a digital signal processor (DSP), or a field-programmable gate array (FPGA).
[0022] The memory device 130 can be embodied as any suitable combination of non-volatile memory devices and / or volatile memory devices. For example, the memory device 130 can include one or more solid state drives (SSDs), along with non-volatile random access memory (NVRAM) and / or volatile random access memory (RAM), such as static random access memory (SRAM) and dynamic random access memory (DRAM). Other types of memory, such as removable memory device synchronous DRAM, can be included. The memory device 130 can represent a portion of the memory included in the mobile device 100, and the memory device 130 can refer to a virtualized portion of the memory implemented as part of the overall memory included in the mobile device 100.
[0023] The communication module(s) 140 can include any communication module adapted to communicate via a suitable wireless communication type. For example, the communication module(s) 140 can use any one of Wi-Fi (registered trademark), Bluetooth (registered trademark), infrared, cellular frequency radio waves, or any other suitable wireless communication type. Additionally, the communication module(s) 140 can be configured to transmit and receive data via a wired connection.
[0024] Mobile device 100 includes a secure profile 150. The secure profile 150 is a data entity stored in memory that can be used to effect network authentication and access. In some examples, the secure profile 150 can be transmitted to the mobile device 100 via a data communication network. The secure profile 150, when used, can enable the mobile device 100 to establish a data communication connection via a cellular network. The secure profile 150 can be included in a secure module 110 installed in the mobile device 100. This entity, the secure profile 150, can be one or more of a "SIM profile", an "operating profile", or a "bootstrap profile", which can also be referred to as a "provisioning profile". In some examples, the primary function of the secure profile 150 is to endow the mobile device 100 with credentials and decryption capabilities for enabling the mobile device 100 to have a cellular data communication connection. This primary function is associated with the mobile device 100 and can be used for general mobile cellular network subscriptions used to facilitate everyday connections such as calls, SMS, and / or web browsing, and can be independent of the general mobile cellular network subscription used for the mobile device 100's cellular data communication connection.
[0025] The mobile device 100 includes a secure module 110 that can be a separate hardware module, such as an eSIM, an iUCC, and an eUICC, also referred to as a soft SIM, or an integrated and / or embedded module such as a SIM (such as a physical UICC). The secure module 110 can support any cellular network access technology (e.g., 2G, 3G, 4G, 5G, low power). The secure module 110 can be provided with one or more additional secure profiles 155, which are used by the mobile device 100 to provide cellular network communication services based on one or more subscriptions of the user of the mobile device for everyday communication.
[0026] Mobile device 100 includes a communication-enabled application (or "app") 160. App 160 is a software application that is executable and / or runs on mobile device 100. App 160 uses a data communication connection to execute certain applicable built-in functions. For example, if app 160 is a taxi dispatch application installed on mobile device 100, the data communication connection can be used by the application to send and receive data such as data related to the location of mobile device 100, the assigned taxi operator, user profile data, etc. Other examples may include a hotel reservation application, a media streaming application, and the like.
[0027] App 160 can be provided to mobile device 100 by being downloaded and installed on mobile device 100 from a digital distribution platform. The digital distribution platform, also referred to as the "App Store", is a platform for apps developed and maintained by an Original Device Manufacturer (ODM), a partner trademark manufacturing company (Original Equipment Manufacturer, OEM), or other third parties related to user equipment. The digital distribution platform can consist of a third-party marketplace that provides services requiring a data connection, such as the Apple App Store or the Google Play Store. The digital distribution platform can be accessed via the Internet and / or a remote network. App 160 can be downloaded from the digital distribution platform via an appropriate communication method. For example, mobile device 100 can communicate with the digital distribution platform via communication module(s) 140 using any appropriate communication type enabled by communication module(s) 140.
[0028] Figure 2 schematically shows the process by which a mobile device 100 downloads an app 160 from a digital distribution platform 205 according to one embodiment. The mobile device 100 initiates a data session 200 to download the app 160 from the digital distribution platform 205 via the World Wide Web. The app 160 is downloaded 210 and installed on the mobile device 100. In the example shown in Figure 2, the mobile device 100 communicates with the digital distribution platform 205 via the World Wide Web without accessing the cellular network 240. This may be the case, for example, when the mobile device 100 uses Wi-Fi (registered trademark) to access the digital distribution platform 205.
[0029] In other embodiments, the mobile device 100 is registered with the cellular network 240 via, for example, one or more secure profiles 155, and the data session 200 for downloading the app 160 is a cellular network data session established using one or more additional secure profiles 155. The cellular network 240 shown in Figure 2 includes a gateway 250, such as a Packet Data Network Gateway (PDN-GW), a Remote SIM Provisioning Platform 260, and network functions 270, such as billing, management, and accounting functions, which may also be collectively referred to as backend functions. The cellular network 240 may also include a tunneling proxy 280. The cellular network 240 may be implemented as one or more computing devices distributed over a geographic area, including any suitable combination of hardware and software, including suitable communication technologies for communicating with one or more mobile devices 100. The cellular network 240 may also include an interface for communicating with other networks and / or remote servers, such as the Internet.
[0030] In some cases, the app 160 can be pre-provisioned on the mobile device 100 during manufacturing. For example, the manufacturer of a particular mobile device 100 can include software such as the app 160 on the mobile device 100 during its manufacture before providing the mobile device 100 to a user.
[0031] As described above, the app 160 is a data communication-enabled app and may rely on having a secure profile 150 installed on the mobile device 100 to enable cellular network data communication, for example, when other data communication sessions such as via Wi-Fi® are not available. In an example where the mobile device 100 does not initially have a suitable secure profile 150 installed on the mobile device 100 for the app 160 to access a data communication session, the process of downloading the secure profile 150 from the cellular network 240 can be initiated. FIG. 2 shows the mobile device 100 downloading the secure profile 150 from the cellular network 240 via communications 220 and 230. The mobile device 100 can download the secure profile 100 via any suitable communication method. For example, the secure profile 150 can be downloaded using Wi-Fi, cellular connection, and other suitable communication methods.
[0032] Although two communications 220 and 230 (request and response) are shown in FIG. 2, it will be understood that any number of signals can be transmitted between the cellular network 240 and the mobile device 100 when downloading the secure profile 150. For example, an initial reservation message can be sent to the remote SIM provisioning platform 260 of the cellular communication network 240. Next, the operating system 170 of the mobile device 100 can request the secure profile 150 from the remote SIM provisioning platform 260. When the secure profile 150 is received, one or more notification messages can be transmitted between the mobile device 100 and the remote SIM provisioning 270 platform for confirmation. In some examples, after the operating system 170 installed on the mobile device 100 identifies the need for the secure profile 150 when downloading the app 160, it can initiate the download of the secure profile 150. For example, metadata included with or as part of the app 160 data can indicate the need for the secure profile 150. In other examples, the app 160 can identify that the appropriate secure profile 150 is not installed on the mobile device 100 and initiate the process by instructing the operating system 170 of the mobile device 100. In an example where the mobile device 100 does not have the appropriate secure profile 150 installed on the mobile device 100, installing the app 160 can trigger a process to download the secure profile 150 from the cellular network 240 and install the secure profile 150 on the mobile device 100. Alternatively, or additionally, the app 160 and / or the operating system 170 can initiate the download of the secure profile 150 later, for example, when the app 160 is first executed on the mobile device 100 or after a predetermined period from when the app 160 is downloaded.Alternatively, or additionally, a user of the mobile device 100 can initiate the download of the secure profile 150. For example, the user can operate the mobile device via a user interface, for example, to download the secure profile 150. In some cases, the mobile device 100 can determine that the secure profile 150 is needed, for example, by the app 160 or the operating system 170, and can notify the user to request confirmation from the user to download the secure profile 150 via, for example, the user interface.
[0033] In some examples, the secure profile 150 can be installed in the secure module 110, and the secure module 110 can store and operate one or more secure profiles including the secure profile 150. The secure profile 150 can be supplied by a counterparty trademark manufacturing company and is suitable for use by an application installed on the mobile device 100 configured to perform the method described below with respect to FIG. 3 to provide a data connection. Alternatively, the secure profile 150 may be suitable for use only by a subset of all applications installed on the mobile device 100, including, for example, the app 160. The person responsible for providing the secure profile 150 to the mobile device 100, for example, the counterparty The trademark manufacturing company may have the ability to supply multiple secure profiles to the mobile device 100, and each secure profile may be suitable for use in different geographical locations. The multiple secure profiles may also include one or more application-specific secure profiles used by a particular application, for example, the app 160, to provide a cellular network data connection to the application.
[0034] In certain cases, mobile device 100 may already include secure profile 150 and, under certain predefined conditions, may choose to enable secure profile 150 to access a remote server via the Internet or a private network if necessary to meet those predefined conditions. This example is a situation where mobile device 100 has not had a data communication connection for more than a week. In this case, mobile device 100 can use secure profile 150 to download the latest version of one or more configuration files. The predefined conditions under which such a secure profile 150 can be used can be extended by app 160 and / or operating system 170 to include providing a cellular network data connection for executing the functions of app 160.
[0035] FIG. 3 shows an example of a method 300 for operating a communication-enabled application 160 on a mobile device 100. In a first block 302, the method 300 includes detecting a need for data transmission when the application 160 has a data communication status that the mobile device 100 currently does not meet the need. For example, the mobile device 100 may have a restricted data connection such that only certain predetermined applications or functions within the mobile device 100 are authorized to use the data connection. Alternatively, the mobile device 100 may not have a data connection. The application 160 can detect the need for data transmission, for example, in response to an input from a user of the mobile device 100 when the application 160 is opened on the device 100. In other examples, when the user of the mobile device 100 attempts to perform a particular function within the application 160, the application 160 can detect the need for data transmission. Alternatively, or additionally, the application 160 can automatically detect the need for data transmission without input from the user. Once the need for data transmission is determined, the application 160 can communicate with the operating system 170 of the mobile device 100 to identify whether the current data communication status of the mobile device 100 is suitable to meet that need.
[0036] In the second block 304, the application 160 sends a request to activate the secure profile 150 for a cellular network data communication session. A cellular network data communication session (or "data session") is a cellular connection session that is enabled via the secure profile 150 of an authenticated application 160 on the mobile device 100 to provide access to the Internet or a remote network. The use of the data session can be for a temporary or permanent period and is suitable for one or more data communication-based functions of the application 160. The application 160 can send a request to the operating system 170 of the mobile device 100. FIG. 4 shows an example where the application 160 sends a request 410 to the operating system 170 of the mobile device 100 to enable the secure profile 150 to provide cellular network data communication. The mobile device 100, particularly the operating system 170 of the mobile device 100, may include one or more program software interfaces for the application 160 within the mobile device 100 to request that the secure profile 150 be able to provide a data session for use by the application 160. Accordingly, the request 410 can be implemented using a programmatic software interface(s). The programmatic software interface(s) can include any of the APIs, SDKs, or other suitable trigger mechanisms of the mobile device 100 available to the application 160. In order for the application 160 to use the programmatic software interface, the application 160 can be pre-configured while developing, compiling, or configuring the relevant metadata to support the use of the programmatic software interface(s).
[0037] The requirement 410 to activate the secure profile 150 may depend on the type of the required cellular network data communication session. In this case, the app 160 can determine the type of the required cellular network data communication session. For example, the type of the cellular network data communication session can specify the type of data transmitted and received by the app 160 and / or whether the data session is restricted by one or more characteristics such as duration, data usage, speed limit, whether other applications are authenticated to use the data session, and what services can be accessed using the data session.
[0038] Following the requirement 410, the operating system 170 of the mobile device 100 can control the secure profile 150 to execute a method for establishing a cellular network data communication session of the app 160, as described below in relation to FIG. 5. The app 160 can generate a unique identifier or string (a "UID") for the cellular network data communication session, which may be referred to as a session ID. The UID or its derivatives can be used by the app 160 to monitor and / or manage the cellular network data communication session, for purposes such as accounting, billing, and invoicing of the data session. In some examples, the UID includes an identifier associated with the mobile device 100 and / or an end-user identification known to the app 160. Alternatively, the UID can be a unique random alphanumeric string.
[0039] App 160 can send the session ID and initial session data to the operating system 170 of the mobile device 100. This may enable the operating system 170 to monitor and / or manage the data session. The initial session data may include any suitable information for establishing and / or monitoring the data session. For example, the initial session data may include metadata used to establish and / or monitor the session. The metadata may include one or more identifiers related to the mobile device 100 involved in establishing the data session, or components or functions of the cellular network 240. The metadata may additionally or alternatively include information identifying the user of the app 160. The initial session data may additionally or alternatively include data related to the initial communication between the mobile device 100 and the cellular network 240 when establishing the cellular network data communication session.
[0040] When the cellular network data communication session is established, App 160 can record data session metrics related to the cellular network data communication session. These data session metrics can be stored as session data in App 160. The metrics may include data usage, the type of data transmitted and / or received during the data session, the period during which the data session is established, and the like. The recorded metrics may be suitable for performing accounting, billing, and invoicing functions, and for monitoring the data session for diagnostic and troubleshooting purposes. The session data including these metrics can be sent to the operating system 170 of the mobile device 100 while the data session is operating and / or when the data session ends.
[0041] In some examples, app 160 can control and / or limit a data session. For example, app 160 can be operable to control the duration of a data session and / or the amount of data transmitted and received during the data session. For example, app 160 can monitor session data including metrics related to the data session and send a request to deactivate the data session when a predetermined limit on duration and / or data usage is reached. Alternatively, or additionally, when the functionality of app 160 that requires a data session is complete, app 160 can deactivate the data session. In other examples, the data session can end when a user command communicated via app 160 is received and / or when an alternative connection, such as a Wi-Fi connection, becomes available. When ending the data session, app 160 can send the final session data to operating system 170, and the final session data can include all session data generated during the data session or session data generated since app 160 last sent session data to operating system 170.
[0042] In certain examples, the data session requested by app 160 can be a restricted cellular network data communication session, and only the requesting app 160 is authenticated to use the data session. In other examples, app 160 can request a partially restricted or unrestricted cellular network data communication session. For example, app 160 can provide the end user of the device with the option to select a data plan via app 160 to permit access to a data session for a specified period and / or to permit a predetermined amount of data, such as 500 MB valid for one day, to be used by one or more groups of applications on mobile device 100.
[0043] If the end user of device 100 decides to accept the offer of app 160, the data session can be an open data session that allows other applications installed on mobile device 100 to access the data session. During the period when this data session is active, if another app attempts to activate secure profile 150, since secure profile 150 is already in use on mobile device 100, this request will be rejected. Application 160 may have the ability to provide multiple data package sizes with various characteristics. In some cases, the user of app 160 may be able to specify the desired characteristics of the data session that the user desires. For example, a taxi-hailing app can provide a temporary or permanent data package that is purchasable in app 160 and provided using secure profile 150 and mobile device 100, and / or the end user may be able to specify the total amount of data (uplink and downlink) provided in the data session. Other examples may include a media streaming service that provides a data package suitable for sending one or more movies, TV shows, and / or music albums or playlists to mobile device 100.
[0044] In other examples, one or more data packages can be purchasable from digital distribution platform 205 but provided to the user of mobile device 100 via app 160. In other words, app 160 can function as a resale channel through which the products and services provided by digital distribution platform 205 are presented to and / or selected by the user of mobile device 100.
[0045] Figure 5 shows a method 500 for controlling a secure profile 150 via an operating system 170 installed on a mobile device 100. In a first block 502, method 500 includes receiving a request from an app 160 installed on the mobile device 100. The request is related to the authentication of an application for having cellular network data communication access via the secure profile 150. As described above, this request can be received from the app 160 using a software interface by one or more programs. If the mobile device 100 does not yet have a secure profile 150 suitable for providing a cellular network data communication session to the app 160, the operating system 170 can download the secure profile 150 as described above in connection with Figure 2.
[0046] In a second block 504, method 500 includes activating a cellular network data communication session by utilizing the secure profile 150. Establishing a cellular network data communication session includes registering with the cellular network 240 using the secure profile 150 and sending a session ID to the cellular network 240. The session ID can be sent to the network function 270 for monitoring, billing, and charging purposes. Optionally, initial session data can also be sent to the cellular network 240 to establish the data session.
[0047] Alternatively, the operating system 170 can determine that the app 160 is a data communication-enabled application and / or that there is a need for the app 160 to connect to data, for example, based on metadata associated with the app 160 or via a push notification received on the mobile device. Based on this determination and if the mobile device 100 does not currently have a communication status suitable for meeting the app 160's need to connect to data, the operating system 170 can activate the secure profile 150 to enable a connection to data on the cellular network to be provided to the app 160.
[0048] In some examples, the operating system 170 can perform additional functions to manage the data session. For example, the operating system 170 can monitor data session metrics such as the use of uplink and downlink during the data session. These data session metrics may be included in the session data. The operating system 170 can alternatively or additionally receive, for example, from the app 160, data session metrics related to the cellular network data communication session. The operating system 170 can store the metrics and transmit the metrics related to the cellular network data session to, for example, the network function 270. The operating system 170 can transmit the metrics associated with the cellular network data communication session to the network function 270 of the cellular network 240 and / or to the digital distribution platform 205 via the cellular network 240 or via other suitable communication methods. The data session metrics can be transmitted by the operating system 170 at regular intervals or when certain predetermined criteria are met, for example, after a predetermined amount of data has been transmitted and / or received. The data session metrics can be included in the session data generated by the app 160, the operating system 170, or a combination of both.
[0049] Next, the data session metrics can be used by one or both of the network functions 270 of the cellular network 240 and the digital distribution platform 205 for accounting, billing, and invoicing purposes, and possibly for network diagnosis and / or troubleshooting purposes. In other words, the user of the mobile device can be billed for the data session via the digital distribution platform 205 or directly by the operator of the cellular network 240, e.g., if the user is registered with the operator of the cellular network 240. Alternatively, or additionally, the operator and / or manufacturer of the app 160 can be billed via the digital distribution platform 205 and can either bear these charges or transfer the costs to the user of the mobile device 100. These metrics can be associated with the session ID of the data session so that the use of the data can be tracked and accounted for.
[0050] Upon receiving a request to activate the secure profile 150 from the app 160, the operating system 170 can verify that the app 160 is authorized to access this functionality. Applicable methods for authentication can be executed locally on the mobile device 100. Authenticating the app 160 can include processing metadata included in or associated with the app 160 and / or cryptographic checks based on public key cryptography. It should be understood that other suitable authentication methods can be utilized. The operating system 170 can also check that the secure profile 150 can access the cellular network 240 corresponding to the current geographical location of the mobile device 100. The operating system 170 can perform other rule or authentication checks, including the number of times the app 160 has requested a data session within a given period. In other examples, the authentication of the app 160 can be managed by a remote server of the cellular network 240 and implemented locally on the mobile device 100 by the operating system 170.
[0051] In some cases, the operating system 170 of the mobile device 100 can restrict the data sessions provided to the requesting application 160, a group of applications, or any applicable software process that can utilize the data session of the mobile device. The type of restriction can be determined during the authentication of the request by the operating system 170. In some cases, the type of restriction required by the application 160 can be indicated in the initial request 410, or in subsequent communications to the operating system 170. Examples of data session restrictions can include, for example, allowing only outbound or inbound data traffic generated by or destined for one or more authenticated applications including the application 160, restricting the amount of data transmitted, the duration of the data session, and / or the applications that can access the data session. In such cases, the operating system 170 can track and monitor the data session, including the amount of uplink and downlink data utilized during the session.
[0052] At the end of the data session, for example, when the functionality of the application 160 using the data session ends, when a pre-determined data usage limit is reached, for example when an alternative data connection via Wi-Fi becomes available, and / or when the user of the application 160 chooses to end the data session, the application 160 can send a request to end the data session and / or invalidate the secure profile 150 of the mobile device 100. The request to end the data session can be sent from the application 160 to the operating system 170. Alternatively, the user of the mobile device can directly end the data session using the operating system 170, for example via the user interface.
[0053] Next, the operating system 170 of the mobile device 100 can invalidate the secure profile 150 of the mobile device 100. When ending a data session, the operating system 170 can transmit final total data usage information for reception by the cellular network 240, particularly the network function 270, and / or the digital distribution platform 205. The final total data usage information may be included in the final session data.
[0054] FIG. 6 shows a method 600 of operating the cellular network 240 to provide cellular network data communication to the mobile device 100. In a first block 602, the method 600 includes the cellular network 240 receiving a request from the mobile device 100 to establish a cellular network data communication session. The cellular network 240 can determine one or more settings of the data session based on this request. For example, the one or more settings may represent characteristics of the data session such as an authenticated application, data usage amount, and / or period.
[0055] The cellular network 240 may identify the application 160 and / or the mobile device 100 based on a request to establish a cellular network data communication session. For example, the request to establish a data session may include details of the identifier. The details of the identifier may include, for example, the access point name (APN) of the application 160, for example, the mobile station international subscriber directory number (MSISDN) of the mobile device 100 for the application 160, the International Mobile Subscriber Identity (IMSI) associated with the secure profile 150, the International Mobile Equipment Identifier (IMEI), or other suitable identifier details associated with the application 160 or the secure profile 150, and may include the APN associated with the secure profile 150 used to provide connectivity of data to the details of the identifier.
[0056] In a second block 604, the method 600 includes the cellular network 240 establishing a cellular network data communication session with the mobile device 100 based on the request. The cellular network data communication session may enable the mobile device 100 to connect to the Internet via a gateway 250 included in the cellular network 240, for example, a packet data network gateway (PDN-GW).
[0057] When establishing a data session, the cellular network 240 can rewrite (or "reconfigure") the app APN if the identifier details include the app APN. For example, an APN server can receive a request from the mobile device 100 and be included in the cellular network 240 configured to rewrite the APN to enable a data session connection for the functionality of app 160. The cellular network 240 can obtain DNS settings for the data session based on the app APN or other identifier details and establish an accounting session for the next data session. Thereby, information on the data sessions of the accounting, billing, and charging functions can be tracked and saved. The cellular network 240 can send session configuration data to the mobile device 100 when establishing a data session. The cellular network 240 can be configured to track and store data sessions and receive a session ID and other data (e.g., initial session data) from the mobile device 100 for the purpose of establishing a data session. For this purpose, the cellular network 240 can associate the session ID with the established accounting session. The session ID can be provided directly to the network function 270 of the cellular network 240 or via one or more other elements of the network 240.
[0058] In some examples, the cellular network 240 can be configured to manage and / or restrict data sessions. In this case, the session configuration data sent to the mobile device 100 can include restriction information specifying how the data session is restricted, such as data limits (uplink and downlink).
[0059] Cellular network 240 can actively restrict a data session, for example, when only a specific application (such as the requesting app 160) is authenticated to use the data session. In some examples, cellular network 240 can restrict access based on DNS requests from mobile device 100. Cellular network 240 can receive DNS requests for an app, for example, in the form of data received from mobile device 100 indicating a domain name request. If app 160 is not authenticated to access a data connection via cellular network 240, the request is rejected and the process ends. If app 160 is authenticated to access a data connection via cellular network 240, the request is accepted and the mobile device is authenticated to access a domain name server based on the request via cellular network 240 and obtain one or more IP addresses.
[0060] During the data session, app 160 can attempt to access a given IP address. If the IP address is not authenticated for the data session, data communication that app 160 attempts to send to the given IP address is rejected. If the IP address is authenticated for the data session, data communication transit is permitted by cellular network 240 and the data communication is transferred between the remote network associated with the IP address and mobile device 100 to establish a data connection to app 160 and enable its functionality.
[0061] In some examples, the restrictions can be communicated from the mobile device 100 to the cellular network 240 when establishing a data session. In other examples, the cellular network 240 can determine one or more settings of the data session based at least on configuration data associated with the secure profile. For example, when the secure profile 150 is used with a particular application, the cellular network 240 can access one or more data stores, such as a database containing configuration information associated with the secure profile 150. For example, the secure profile 150 can be associated with one or more specific domain names representing an authenticated list of domains that can be accessed using the secure profile 150, and / or one or more groups of authenticated IP addresses.
[0062] The app 160 and / or the operating system 170 can periodically register data usage information (e.g., in the form of session data) including, for example, data uplink and downlink usage amounts, data session duration, and web addresses accessed via the data session, with the cellular network 240. The cellular network 240 can use the data usage information to monitor and / or restrict the data session to the mobile device 100. Alternatively, or additionally, the cellular network 240 can use the data usage information to perform certain accounting, billing, and / or charging functions. For example, at the end of a data session, the cellular network 240 can use the data session information to bill the cost of the data session directly to the user of the mobile device 100 or to either of the digital distribution platforms 205, through which the app developer can bill or not bill the user of the mobile device 100. Aggregate data session usage information can also be sent to the cellular network 240 at the end of the data session for accounting, billing, and charging purposes.
[0063] The foregoing description has discussed the limitation of data sessions in the cellular network 240 based on DNS requests per session. However, the cellular network can manage or limit data sessions by alternative means. For example, a gateway 250 within the cellular network 240, such as a PDN-GW, used to effect communication between the mobile device 100 and an Internet Protocol network, such as the Internet, can be configured to allow only specific data traffic to pass through the gateway depending on the APN used to establish the data session. For example, the gateway 250 can implement specific rules by which it can transmit communications based on the APN. The rules can be determined based on DNS settings associated with the APN. As an example, when a data session is established using a bootstrap profile associated with an APN that identifies a remote SIM provisioning platform 260, the gateway 250 can limit the traffic during the data session such that only communications addressed to the remote SIM provisioning platform 260 are transmitted.
[0064] In some cases, the secure profile 150 used to access the data session on demand from the app 160 can be associated with a specific APN. For example, as described herein, the secure profile 150 used by the mobile device 100 to effect an on-demand connection to an app, such as app 160, can belong to a specific profile type, such as the Communication-as-a-Service (CaaS) profile type. The CaaS profile type is associated with a specific APN and is hereinafter referred to as the CaaS APN. The CaaS APN is further distinguished from the APN(s) associated with the secure profile(s) 155. When the secure profile 150 is supplied from the remote SIM provisioning platform 260, the remote SIM provisioning platform 260 can be configured to supply a secure profile belonging to the CaaS profile type and associated with the CaaS APN.
[0065] When a data session is established, using the CaaS APN, the cellular network 240 can establish the DNS settings of the secure profile 150 identified as the CaaS profile type based on the associated CaaS APN and determine a list of permitted IP addresses for the data session. In some examples, the type of the CaaS profile can be restricted such that only traffic directed to the tunneling proxy 280 is sent through the gateway 250 during each data session. For example, to prevent unauthorized use of the data session by unauthenticated applications on the mobile device 100, the tunneling proxy 280 can be secured such that only communications containing the relevant credentials are accepted by the tunneling proxy 280.
[0066] By using the tunneling proxy 280 as the destination of traffic during a data session, it may be possible to simplify the restrictions implemented by the gateway 250. In other words, the gateway 250 rejects all traffic that is not addressed to the IP address of the tunneling proxy 280 during a data session established with the secure profile 150. One such example of a tunneling proxy 280 that can be used is a SOCKS proxy.
[0067] In an example of restricting CaaS profile type data communication so that the gateway 250 can only communicate via the tunneling proxy 280, the configuration data can be supplied to the app 160 for use, for example, when configuring the app 160 to handle communication during a data session from the network function 270 to the tunneling proxy 280 via the mobile device 100. After receiving the configuration information, the app 160 can configure or reconfigure the HTTP client of the app 160 based on the configuration data. The configuration data can include information identifying, for example, an appropriate tunneling proxy host, port, and / or credentials. By controlling data traffic during a data communication session using the tunneling proxy 280, efficient monitoring of the data session may be possible and the data session may be distinguishable from other data sessions established on the mobile device 100.
[0068] FIG. 7 shows an example of a data session based on network restrictions in which tunneling proxy 280 is used. In a first step, SDK 702 implemented by app 160 sends a session start request 704 that includes an identifier for app 160. Network function 270 processes the identifier and, if app 160 is authenticated to access the data session, supplies 706 configuration data to be used during the data session. Network function 270 can maintain a database that identifies apps that are authenticated to use a data session established using secure profile 150. Alternatively, network function 270 can access an external database, either within cellular network 240 or external to cellular network 240, to establish whether app 160 is authenticated to access the data session. The configuration data can include data for identifying and accessing tunneling proxy 280. For example, the configuration data can include information identifying the proxy host, port of the tunneling proxy, and in some examples, credentials such as a username and password for accessing tunneling proxy 280.
[0069] SDK 702 communicates 710 with app 160 and supplies it with the configuration data. App 160, in step 712, configures an HTTP client within app 160 based on the configuration data. Next, app 160 sends an http or https request 714 to tunneling proxy 280. Request 714 is forwarded by tunneling proxy 280 and a response is received (716). The response is sent back from tunneling proxy 280 to app 160. At the end of the session, SDK 702 notifies 720 tunneling proxy 280, and the end of the session is communicated to network function 270.
[0070] Figures 8A and 8B illustrate an example of the above method, and for ease of understanding, specific method steps that may be performed by different entities, such as application 160 and operating system 170, are shown together. Figure 8A shows a method 800 including method steps 802a through 802j, where some steps 802a, 802b, 802d, 802i are performed by app 160 and other steps, 802c, 802e, 802f, 802g, 802h, 802j are performed by the operating system 170 of mobile device 100. Figure 8B shows a method 804 including steps 806a through 806m according to a specific embodiment described herein and implemented by cellular network 240.
[0071] Although the method steps of Figures 8A and 8B are shown in a particular order, it will be understood by those skilled in the art that the steps may be performed out of order and, in some cases, simultaneously. For example, the app that generates a session ID at 802d and the operating system that enables secure profile 802e can be executed in an order different from that shown in Figure 8A.
[0072] The above embodiments are to be understood as exemplary examples. Further embodiments of the present invention are contemplated. For example, if a data session abruptly ends due to a signal drop on mobile device 100, the final total data usage (e.g., final session data including final total data usage information) and any other relevant metadata can be submitted to cellular network 240, or digital distribution platform 205, when the next appropriate cellular network connection becomes available to mobile device 100, or via another bearer such as silent short message service (SMS) communication. In other examples, app 160 can provide a data session to an end user of app 160 for free and can separately settle any fees payable to the provider of secure profile 150. Combinations of the various billing and charging options described above are also possible.
[0073] It should be understood that any feature described in connection with any one embodiment may be used alone or in combination with any other feature described, and may also be used in combination with one or more features of any other embodiment, or any combination of any other embodiments. Further, equivalents and modifications not described above may be employed without departing from the scope of the invention as defined in the appended claims.
Claims
1. 1. A method for operating a communications-enabled application on a mobile device, comprising: The application detects the need for data transmission when the mobile device currently has a data communication status that is incompatible with the need; and the application sending a request to activate a secure profile for a cellular network data communication session; A method comprising:
2. 10. The method of claim 1, further comprising: sending the request to activate a secure profile to initiate the cellular network data communication session through a programmatic software interface of the mobile device.
3. The method of claim 1 or 2, wherein the method includes installing the secure profile on the mobile device.
4. The method of claim 1 , further comprising generating a unique identification for the cellular network data communication session.
5. The method comprises: determining the type of cellular network data communication session being requested; and sending the request to activate the secure profile for initiating the cellular network data communication session based on a type of the requested cellular network data communication session; The method of any one of claims 1 to 4, comprising:
6. The method comprises: sending the request to an operating system of the mobile device to activate the secure profile for initiating the cellular network data communication session; and The method of claim 5 , comprising generating initial session data based on the type of cellular network data communication session being requested.
7. The method of claim 6 , wherein the method includes transmitting the initial session data to the operating system.
8. The method comprises: recording metrics associated with the cellular network data communication session; and sending said metrics to said operating system; The method of claim 7, comprising:
9. The method of claim 8 , wherein the method includes sending a request to deactivate the cellular network data communication session.
10. The method comprises: receiving configuration data associated with the tunneling proxy; and using said configuration data to transmit a data communication during said data session; The method of any one of claims 1 to 9, comprising:
11. The method of claim 10 , wherein the configuration data includes credentials for accessing the tunneling proxy.
12. 1. A method for controlling a secure profile via an operating system installed on a mobile device, comprising: receiving a request from an application installed on the mobile device, the request relating to authentication of the application for accessing cellular network data communications via a secure profile; and activating a cellular network data communications session utilizing the secure profile; A method comprising:
13. The method of claim 12 , wherein the method includes the operating system installing the secure profile on the mobile device.
14. The method of claim 13 , wherein the method includes the operating system requesting installation of the application in the secure profile of the mobile device.
15. The method comprises: receiving metrics associated with the cellular network data communication session; storing metrics associated with the cellular network data communication session; and transmitting metrics associated with the cellular network data communication session; 15. The method of any one of claims 12 to 14, comprising:
16. 16. The method of claim 12, further comprising authorizing the application to utilize the cellular network data communication session.
17. 17. The method of any one of claims 12 to 16, wherein the method comprises transmitting initial session data to a digital distribution platform.
18. The method includes terminating the cellular network data communication session; and Transmitting the final session data to a digital distribution platform; 18. The method of any one of claims 12 to 17, comprising:
19. 1. A mobile device comprising: a memory circuit configured to store an operating system and applications; and 19. A mobile device comprising: a processing circuit configured, when configured with said operating system and / or said applications, to perform the method according to any of claims 1 to 18.
20. 1. A method of operating a cellular network to provide cellular network data communications to a mobile device, comprising: receiving a request to establish a cellular network data communication session from the mobile device of claim 19; the cellular network establishing a cellular network data communications session with the mobile device using a secure profile included in the mobile device; A method comprising:
21. Establishing the cellular network data communications session includes determining one or more settings for the cellular network data communications session based at least on the request; 21. The method of claim 20, wherein the cellular network data communication session is established in accordance with the one or more settings.
22. establishing the cellular network data communication session includes determining one or more settings for the cellular network data communication session based on at least configuration data associated with the secure profile; The method of claim 20 or 21, wherein the cellular network data communication session is established in accordance with the one or more settings.
23. 22. A method according to claim 20 or claim 21, comprising transmitting configuration data for a cellular network data communication session for receipt by the mobile device.
24. establishing an accounting session for said cellular network data communication session; receiving data representative of a unique session identification of the cellular network data communication session; and storing session data associated with the unique session identification of the cellular network data communication session; 24. The method of any one of claims 20 to 23, comprising:
25. 25. The method of claim 24, comprising transmitting session data to a digital distribution platform associated with the application included on the mobile device.
26. 26. The method of any one of claims 20 to 25, wherein the method comprises controlling access to the data session of one or more applications of the mobile device.
27. Controlling access to the data session comprises: Application Domain Name System, DNS, Requests, and if the application is an authorized application, authorizing the mobile device to access a domain name server based on a DNS request of the application; and blocking the mobile device from accessing the domain name server based on a DNS request of the application if the application is not an authorized application.
27. The method of claim 26, comprising receiving data representative of:
28. Controlling access to the data session comprises: receiving a request to access an IP address; and if the IP address is an authorized IP address, authorizing the mobile device to access the IP address; or if the IP address is not an authorized IP address, blocking the request to access the IP address.
28. The method of claim 26 or 27, comprising receiving.
29. A cellular network configured to carry out a method according to any one of claims 20 to 28.
Citation Information
Patent Citations
Method for providing plug-in cards provided with an identifier in a mobile radio terminal
DE10311980A1
Methods and apparatus for certificate processing
JP2010532596A
Updating profiles for secondary wireless devices
JP2018207479A
Managing multiple active Subscriber Identity Module profiles
JP2018518129A
Method and system for providing guaranteed quality of service and quality of experience channel
US20170332282A1