Incognito mode on mobile devices that automatically returns to default operating mode

UEs temporarily switch to incognito identifiers to protect privacy and prevent identifier correlation, enhancing privacy and reducing data storage congestion through automatic transitions.

JP2026510171APending Publication Date: 2026-04-02GOOGLE LLC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-10-28
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing user equipment (UE) devices lack a mechanism to temporarily operate with incognito identifiers to protect user privacy and avoid identifier correlation and congestion, while seamlessly transitioning back to default identifiers.

Method used

UEs are configured to operate temporarily in an incognito mode using incognito subscriber and hardware identifiers, which are automatically switched back to default identifiers after a period, facilitated by an Incognito server and client application.

Benefits of technology

This approach enhances user privacy by avoiding identifier correlation and reduces data storage congestion, ensuring seamless network transitions and service continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026510171000001_ABST
    Figure 2026510171000001_ABST
Patent Text Reader

Abstract

A method for a UE to temporarily operate in incognito mode includes detecting a trigger to do so when the UE is operating in default mode, where a first operational eSIM profile having a first subscriber identifier is active on the UE's eSIM, and responding by (i) transitioning the UE to incognito mode, and (ii) automatically returning the UE to default mode after a period of time. Transitioning may include deactivating the first operational eSIM profile and activating a second eSIM profile having a second identifier instead, and automatically returning may include deactivating the second operational eSIM profile and reactivating the first operational eSIM profile instead. Furthermore, the trigger for entering incognito mode may be location and / or time, among other options.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] User equipment devices (UEs) such as mobile phones, tablet computers, and other devices typically have one or more identifiers that can facilitate wireless communication services. For example, a UE can have one or more hardware identifiers that uniquely identify the UE itself, and the UE can also have one or more subscriber identifiers that uniquely identify a subscription that the UE or the UE's user has with a mobile network operator (MNO). Such a UE, when first powered on, or otherwise when entering the wireless coverage provided by the MNO or a roaming partner, can obtain connectivity by engaging in an attachment process, which can include the UE transmitting an attach request that transmits one or more of the UE's identifiers, the MNO authenticating the UE for the service based on one or more identifiers, and the MNO recording the location where the UE is operating such that subsequently the MNO can page or signal the UE.

Summary of the Invention

[0002] According to the present disclosure, a user's UE can be configured to operate temporarily in an incognito mode. Operating temporarily in an incognito mode can include transitioning from operating in a default subscriber profile to instead operating in an incognito subscriber profile and then automatically reverting to operating in the default subscriber profile after the period of operation in the incognito subscriber profile.

[0003] In this configuration, each subscriber profile may have a different subscriber identifier. The default profile has a default subscriber identifier associated with the UE's subscription service, while the incognito profile has an incognito subscriber identifier that differs from the default subscriber identifier and is not associated with the UE's subscription service. Therefore, temporarily operating in incognito mode may involve temporarily operating with an incognito subscriber identifier, which can help avoid association with the user's service subscription.

[0004] Furthermore, temporarily operating in incognito mode may include operating with one or more temporarily assigned identifiers and then automatically reverting to operating with one or more default identifiers after a certain period of time. For example, if a UE has a persistent hardware identifier, temporarily operating in incognito mode may include operating with one or more incognito hardware identifiers instead of the persistent hardware identifier and then automatically reverting to operating with the persistent hardware identifier instead of the incognito identifier after a certain period of time. As another example, if a UE supports a voice telephone service and has an assigned default telephone number (for example, as part of a default subscriber profile), temporarily operating in incognito mode may include operating with an incognito telephone number (for example, as part of an incognito profile) instead of the default telephone number and then automatically reverting to operating with the default telephone number instead of the incognito telephone number after a certain period of time.

[0005] Accordingly, in one embodiment, a method is disclosed for temporarily enabling incognito mode for a UE having an embedded subscriber interface module (eSIM). The method may include detecting a trigger for the UE to temporarily operate in incognito mode, the detection of which occurs when the UE is operating in default mode with a first operational eSIM profile having a first subscriber identifier active on the eSIM. Furthermore, in response to the detection of the trigger, the method may include (i) the UE transitioning from operation in default mode to operation incognito mode, and (ii) the UE automatically returning from operation in incognito mode to operation in default mode after operating in incognito mode for a period of time.

[0006] In this method, transitioning from operation in default mode to operation in incognito mode includes (a) deactivating the first operational eSIM profile on the eSIM and activating the second operational eSIM profile on the eSIM in place of the first operational eSIM profile, the second operational eSIM profile having a second subscriber identifier different from the first subscriber identifier, and not previously active on the eSIM, and the transition may further include (b) using the second subscriber identifier in accordance with the second operational eSIM profile to facilitate engagement with wireless communication services. Furthermore, the act of automatically returning from operation in incognito mode to operation in default mode may include (a) deactivating the second operational eSIM profile on the eSIM and reactivating the first operational eSIM profile on the eSIM in place of the second operational eSIM profile, and (b) using the first subscriber identifier in accordance with the first operational eSIM profile to facilitate engagement with wireless communication services.

[0007] In another embodiment, a UE is disclosed. The UE includes a processor, non-transient data storage, an eSIM, a transceiver, and an antenna structure that supports air interface communication. Furthermore, the non-transient data storage holds program instructions that can be executed by the processor to cause the UE to perform the operations described above. Specifically, the operation may include detecting a trigger for the UE to temporarily operate in incognito mode, and the detection of the trigger occurs when the UE is operating in default mode with a first operational eSIM profile having a first subscriber identifier active on the eSIM. Furthermore, in response to the detection of the trigger, the operation may include (i) transitioning from operation in default mode to operation in incognito mode, and (ii) after operating in incognito mode for a period of time, automatically returning from operation in incognito mode to operation in default mode.

[0008] As described above, the transition operation includes (a) deactivating the first operational eSIM profile on the eSIM and activating the second operational eSIM profile on the eSIM in place of the first operational eSIM profile, wherein the second operational eSIM profile has a second subscriber identifier different from the first subscriber identifier and was not previously active on the eSIM, and the transition operation may further include (b) using the second subscriber identifier in accordance with the second operational eSIM profile to facilitate engagement with wireless communication services. Furthermore, the automatic return operation may include (a) deactivating the second operational eSIM profile on the eSIM and reactivating the first operational eSIM profile on the eSIM in place of the second operational eSIM profile, and (b) using the first subscriber identifier in accordance with the first operational eSIM profile to facilitate engagement with wireless communication services.

[0009] In yet another embodiment, a non-temporary computer-readable medium is disclosed which stores instructions that can be executed by a processor to cause the UE to perform the operations described above.

[0010] In yet another embodiment, a system is disclosed that includes various means for performing each of the operations described herein.

[0011] These and other embodiments, advantages, and alternatives will become apparent to those skilled in the art by reading the following detailed description with reference to the accompanying drawings as appropriate. Furthermore, it should be understood that the summary of this invention and the description provided below are illustrative examples of the invention and are not intended to limit it. [Brief explanation of the drawing]

[0012] [Figure 1] This is a simplified block diagram of an exemplary UE. [Figure 2] This is a simplified block diagram of an exemplary network configuration for providing cellular wireless communication to a UE. [Figure 3] This is a simplified block diagram of an exemplary network configuration for provisioning an operational eSIM profile within the UE's eSIM. [Figure 4] This is a simplified block diagram of an exemplary network configuration supporting temporary incognito services. [Figure 5] This is a simplified block diagram of an exemplary Incognito server. [Figure 6] This is a flowchart illustrating an exemplary method. [Modes for carrying out the invention]

[0013] Exemplary methods, devices, and systems are described herein. However, it should be understood that any embodiment disclosed should not necessarily be construed as more preferable or advantageous than other embodiments unless otherwise stated. Furthermore, it should be understood that variations are possible from certain configurations and processes disclosed. For example, various entities, components, connections, operations, and other elements disclosed may be added, omitted, distributed, duplicated, rearranged, rearranged, combined, or otherwise modified. Furthermore, it should be understood that various technical operations disclosed may be implemented at least in part by processing units programmed to perform the operation or to cause one or more other entities to perform the operation.

[0014] Referring to the drawing, as shown above, Figure 1 is a simplified block diagram of an exemplary UE 100. This exemplary UE includes a wireless communication interface 102, a user interface 104, a positioning module 106, a host processor 108, non-temporary data storage 110, and an eSIM 112, all of which can be connected to each other in a communicative manner by a system bus or other connection mechanism 114. Other configurations are also possible, for example, including dedicated connections (e.g., serial interfaces) that facilitate secure communication between specific components, such as between the host processor 108 and the eSIM 112.

[0015] The wireless communication interface 102 may include one or more transceivers 116 that comply with one or more wireless communication protocols, including, in some cases, one or more cellular radio access technologies (RATs) such as Long-Term Evolution (LTE) and / or 5G New Radio (5G NR), and / or one or more wireless wide-area network technologies such as Wi-Fi. Each such transceiver may include a transmit / receive chain having its own modem, amplifier, and other components. Furthermore, the wireless communication interface 102 may include one or more antenna structures 118 that work in conjunction with one or more transceivers to support air interface communication with the service network infrastructure.

[0016] The user interface 104 may include one or more components that facilitate interaction between the UE100 and the user. These components may include, among other options, user output components such as a display screen, sound speaker, indicator light, and haptic feedback mechanism, as well as user input components such as a touchscreen, microphone, and keypad.

[0017] The positioning module 106 may be a Global Navigation Satellite System (GNSS) receiver, such as a Global Positioning System (GPS) receiver, and can facilitate the determination of the geolocation of the UE 100. Such a module can determine the geographical location of the UE with high granularity by receiving signals from satellites and performing or triggering triangulation processes, etc. The positioning module 106 may also take other forms, such as being configured to use WiFi signaling or other signaling in some cases to facilitate the determination of the UE's position.

[0018] The host processor 108 may include one or more general-purpose processors (e.g., one or more microprocessors) and / or one or more dedicated processors (e.g., application-specific integrated circuits). Furthermore, the non-temporary data storage 110 may include one or more volatile and / or non-volatile storage components (e.g., read-only memory, random-access memory, flash storage, cache memory, etc.) and may be integrated with the host processor in whole or in part.

[0019] As shown in the figure, data storage 110 may store program instructions 120, including an operating system 122 and an application 124, which are executable by the host processor 108 to perform various UE operations. As further shown in the exemplary configuration, the operating system 122 may define a set of eSIM application programming interfaces (APIs) 126, and the application 124 may include a local profile assistant (LPA) 128 configured to interact with the eSIM 112 using the eSIM APIs 126 as the basis, for example, by sending commands to cause the eSIM 112 to take various actions.

[0020] The eSIM 112 may take the form of a secure element (e.g., a dedicated system-on-a-chip (SoC)), in particular an embedded universal integrated circuit card (eUICC), which may be soldered to the UE's system board or otherwise mounted, and may function to hold and manage the eSIM profile. The eSIM 112 may also include an eSIM processor 130 and eSIM data storage 132. Furthermore, although not shown, the eSIM 112 may include a communication interface for engaging in direct secure communication with the host processor 108. The eSIM processor 130 may include one or more general-purpose processors and / or one or more dedicated processors, and the eSIM data storage 132 may include one or more non-temporary storage components, which may hold program instructions executable by the eSIM processor 130 and perform various eSIM operations. The eSIM may also have an eSIM identifier or eUICC identifier, known as an EID, which uniquely identifies the eSIM.

[0021] As further illustrated, the eSIM data storage 132 may store or be configured to store one or more eSIM profiles 134. Each eSIM profile may be a set of data that enables the UE to receive services from a particular MNO (i.e., a real MNO or a virtual mobile network operator (MVNO)). This may include data and applets such as one or more network access applications that provide authorization to access the MNO's network, and various network access data such as encryption keys and definitions of security algorithms that enable the MNO's network to authenticate the UE. Furthermore, the eSIM profile may also include other data, among other options, such as the MNO's network coverage and roaming partner coverage, as well as a preferred roaming list (PRL) that enables the UE to look up and discover other application logic.

[0022] As shown in the figure, the eSIM profile 134 may include one or more non-operating eSIM profiles 136 and one or more operating eSIM profiles 138. The non-operating eSIM profile 136 is not associated with a specific service subscription with an MNO, but is a bootstrap or provisioning profile that enables the UE to connect to the MNO and receive services from the MNO in order to download and install an operating eSIM profile. On the other hand, the operating eSIM profile 138 is specific to an MNO service subscription and includes data and application logic that enables the UE to receive services from the MNO according to that service subscription. Typically, the user enters into a service subscription contract with the MNO for the MNO to provide services to the user's UE, and the MNO's profile provisioning system provisions the operating eSIM profile associated with that service subscription to the UE's eSIM.

[0023] Also, as shown in the figure, each of the one or more operating eSIM profiles 138 stored in the eSIM 112 has a respective subscriber identifier 140, which can uniquely identify the associated service subscription and can further help to identify the eSIM profile. Examples of such subscriber identifiers include a Subscription Permanent Identifier (SUPI), and more specifically, an International Mobile Subscriber Identity (IMSI). The IMSI is a unique number of an international standard that includes a Mobile Country Code (MCC) (which identifies the country where the service is provided), a Mobile Network Code (MNC) (which identifies the MNO that provides the service), and a Mobile Subscriber Identification Number (MSIN) (which identifies the subscriber of the MNO).

[0024] When a user subscribes to an MNO and the MNO provides services to the user's UE, the MNO may assign a respective IMSI to the UE's subscription and establish an eSIM profile associated with the user's service subscription for the UE with that IMSI. For example, the MNO may have a pool of IMSIs approved by an international standardization body, and the MNO may select one of those IMSIs and assign it to the user's subscription, and establish an operational eSIM profile for the user that includes the assigned IMSI and related network access data. The MNO may then be configured to install that eSIM profile onto the eSIM of the user's UE. Further, the MNO may register the assigned IMSI and related data such as network access data with the MNO's network such as an authentication center and / or a related subscriber profile store so that the MNO can later authenticate the UE when the UE attempts to connect for services.

[0025] Further, each of the one or more operational eSIM profiles 138 may also have one or more other identifiers. For example, the operational eSIM profile may also store a telephone number of the UE that can be used to engage in telephone services such as voice calls and / or text messaging. For example, the operational eSIM profile may store a Mobile Station Integrated Services Digital Network (MSISDN) number, which is a unique telephone number of an international standard that includes a country code (CC), a national destination code (NDC), and a subscriber number (SN). When a user subscribes to an MNO and the MNO provides services to the user's UE, the MNO may assign an MSISDN to the user's UE (perhaps using a subscriber number carried over from another service subscription), and store that MSISDN in an associated operational eSIM profile that is installed onto the eSIM of the UE and registered with the MNO's network.

[0026] When the eSIM 112 contains one or more operational eSIM profiles 138, each operational eSIM profile may be set to either active or inactive, and may toggle between these two states. For example, the LPA 128 may activate or deactivate a given operational eSIM profile using the eSIM API 126, and accordingly, the eSIM 112 may flag that operational eSIM profile as active or inactive. When an operational eSIM profile is active, the UE may, accordingly, use that operational eSIM profile as a basis to enable the UE to receive services from the associated MNO in accordance with the associated service subscription. For example, when the UE is first powered on, or otherwise when it enters the MNO's coverage, the UE may obtain IMSI and network access data from the active operational eSIM profile and send that information to the MNO to facilitate the UE's authentication as a condition for connecting to the MNO and receiving services from the MNO.

[0027] LPA128 may ensure that only one operational eSIM profile is active in eSIM112 at any given time. If eSIM112 contains multiple operational eSIM profiles, LPA128 may allow switching between those operational eSIM profiles, i.e., deactivating one and activating another instead. Alternatively, LPA128 may support a multi-profile implementation in which two or more operational eSIM profiles are active simultaneously, and one of the operational eSIM profiles may be designated as the primary operational eSIM profile used for wireless communication services.

[0028] Although not shown in Figure 1, the exemplary UE100 itself also has a persistent hardware identifier that can uniquely identify the UE. Examples of such hardware identifiers include the Mobile Equipment Identifier (MEID) and the International Mobile Equipment Identification Number (IMEI), which are globally unique identifiers indicating the manufacturing number and serial number of the mobile station equipment, respectively. A UE manufacturer may have a pool of such unique hardware identifiers authorized by an international standardization body. When manufacturing the exemplary UE100, the manufacturer may select one of these hardware identifiers and assign it to the UE, and permanently record the assigned hardware identifier within the UE. When a user subscribes to an MNO and the MNO provides services to the UE, the MNO may also register the UE's hardware address in its network, and the MNO may also use the UE's hardware address as a basis for later authenticating the UE when the UE attempts to connect for services.

[0029] Figure 2 is a simplified block diagram showing an exemplary network configuration in which an exemplary UE 100 may provide cellular wireless communication services. As shown, the exemplary configuration includes multiple access nodes 200, such as evolved node B (eNB), each access node providing its own wireless coverage area 202 that serves the UE. Each such coverage area 202 may be defined by one or more radio frequency (RF) carriers across a range of frequency bandwidths and may be frequency division duplexing (FDD) where the uplink and downlink operate on separate frequencies, or time division duplexing (TDD) where the uplink and downlink are multiplexed over time on the same frequency. Furthermore, each coverage area 202 may be defined according to a standard RAT, such as one of the RATs described above, and may provide various air interface control channels and bearer channels to facilitate the transmission of control signaling and bearer communications between the UE and the access nodes.

[0030] As further illustrated, each access node is located as a node on the MNO's core network 204 and provides connectivity to a transport network 206 such as the Internet. As illustrated, the core network 204 includes a control plane subsystem 208 and a user plane subsystem 210. Furthermore, as illustrated, the control plane subsystem 208 may include a network controller 212, an authentication center 214, and a subscriber profile store 216, and the user plane subsystem 210 may include one or more gateways 218 for transmitting user plane data, such as application layer data, to be communicated with the serviced UE. In an exemplary embodiment, the subscriber profile store 216 may hold subscriber profile records for each service subscription with the MNO, each matching the associated subscriber identifier and / or UE hardware identifier, and containing associated network access authentication information and other data.

[0031] Each access node may broadcast a reference signal within its coverage area that the UE can measure as a basis for detecting the presence and strength of coverage. When the UE 100 first powers on within the coverage of one of the illustrated access nodes 200, or otherwise enters the coverage of one of the illustrated access nodes 200, the UE may use PRL in its active operation eSIM profile to scan for applicable coverage, thereby finding a strong coverage threshold from the access nodes 200. The UE may then responsively engage in random access signaling and radio resource control (RRC) signaling to establish an RRC connection (i.e., a radio link layer connection) between the UE and the access nodes 200. Furthermore, once this RRC connection is established, the UE may engage in an attachment process to register for service from the MNO.

[0032] In an exemplary attach process, the UE may generate an attach request and send it to the network controller 212 via its RRC connection (and thus via the access node 200). In this attach request, the UE may provide its subscriber identifier, such as the IMSI of the UE's active operation eSIM profile (e.g., the UE's primary active operation eSIM profile). The network controller 212 may then interact with the authentication center 214 to trigger a process of authenticating the UE for the service, matched to the UE's subscriber identifier. For example, the authentication center may use the provided subscriber identifier as a basis to look up the associated record in the subscriber profile store 216, and then engage in authentication signaling with the UE, using network access authentication information to ensure, for example, that the UE and the authentication center calculate a matching authentication result.

[0033] Upon successful authentication of the UE, the network controller 212 may record in the subscriber profile store 216 a record of where the UE is being served, including which access nodes or associated location / tracking areas of the MNO's network are serving the UE, enabling paging and other messaging to the UE. Furthermore, the network controller 212 may assign a temporary subscriber identifier to the UE, such as a globally unique temporary UE identifier (GUTI), which the network controller may provide to the UE and map to the UE's actual subscriber identifier within the subscriber profile store 216. Because the network controller may trigger associated authentication and other processes by mapping the temporary subscriber identifier to the UE's actual subscriber identifier, this assignment of a temporary subscriber identifier may allow the UE to later connect with the MNO's network without needing to transmit its actual subscriber identifier over the radio.

[0034] In some embodiments, the attachment process and / or authentication process may also use the UE's hardware identifier. For example, when the UE sends an attach request to the network controller 212, or in response to a further request from the network controller, the UE may provide the network controller with the UE's hardware identifier, such as MEID or IMEI. The authentication center may then use the provided hardware identifier as a basis to retrieve the associated record in the subscriber profile store 216 and engage in the authentication process as described above. Furthermore, upon successful authentication, the network controller 212 may also record in the subscriber profile store 216 the location where the UE is being served.

[0035] Once the UE is authenticated for service, the network controller 212 may then engage in control signaling with the user plane subsystem 210 to establish a user plane bearer for the UE to transmit user plane data between the UE and the transport network 206. Once this bearer is established, the MNO may provide services to the UE according to the UE's service subscription. For example, when the UE has data to transmit on the transport network 206, the UE may engage in control signaling with its serving access node 200 to schedule the access node to uplink the data, and accordingly, the UE may transmit the data to the access node as scheduled, and the access node may forward the data along the UE's established bearer for output on the transport network. Similarly, when data arrives from the transport network for delivery to the UE, the data may flow from the UE's bearer to the UE's serving access node, and the access node may then schedule and engage in downlink transmission of the data to the UE.

[0036] Furthermore, while the UE is being serviced by an access node, the UE may periodically measure the strength of coverage from the access node and from adjacent access nodes, and if one or more measurement conditions are met, the UE and / or its serving access node may trigger a handover of the UE from the serving access node to an adjacent access node. As part of this handover process, signaling may also be moved to the network controller 212, which may responsively update a record of where the UE is being serviced within the MNO's network, such as indicating the coverage area or tracking / location area in which the UE is operating.

[0037] As further shown in Figure 2, the MNO's network control plane subsystem may also include a Mobile Location System (MLS) 220. The MLS 220 may operate to determine, store, and report the geolocation of a UE when authorized. For example, the MLS 220 may work in conjunction with the UE's positioning module 106 to determine the UE's geolocation based on GNSS signals received by the UE. Furthermore, the MLS 220 may store the determined geolocation in association with the UE's subscriber identifier and / or hardware identifier, and the MLS 220 may report the determined location if authorized to various location-based service providers, such as navigation services.

[0038] Figure 3 is a simplified block diagram showing a network configuration in which an MNO may provision an operational eSIM profile within the eSIM 112 of a UE 100. The illustrated configuration includes a profile provisioning system 300, which includes a subscription manager data preparation (SM-DP+) system 302 and a subscription manager discovery service (SM-DS) 304. This exemplary profile provisioning system 300 is shown to be interconnected with the MNO's cellular network 306 and also accessible via a public transport network 308 such as the Internet. This configuration allows the profile provisioning system 300 to interact with the MNO's core network and, for example, load subscriber profiles into the subscriber profile store described above. Furthermore, the UE 100 may be able to communicate with the profile provisioning system 300 via a WiFi connection or via an MNO connection established by the UE using a non-operational eSIM profile.

[0039] In this exemplary configuration, the SM-DP+ may handle the creation and installation of operational eSIM profiles, and the SM-DS may enable the LPA to find and download such profiles. For example, when a user is subscribed to an MNO of an MNO providing services to an exemplary UE100, the MNO may work with the SM-DP+ to generate operational eSIM profiles specific to its service subscription for the UE, and work with the SM-DS to notify the UE's LPA of the availability of operational eSIM profiles to download. Furthermore, the MNO may store associated service profile data, including associated subscriber identifiers and possibly associated UE hardware identifiers, in its subscriber profile store. The UE's LPA may then engage in signaling with the SM-DP+ to download and store the operational eSIM profile on the UE's eSIM, and a secure exchange between the LPA and the SM-DP+ successfully transmits the UE's EID to the SM-DP+, which then maintains the mapping between the assigned profile (or associated IMSI) and its EID. Furthermore, the LPA can activate the downloaded operational eSIM profile, signal to the SM-DP+ to indicate that the operational eSIM profile is active, and the MNO can record the display of the operational active status in the subscriber profile store. Other profile provisioning processes are similarly possible.

[0040] As described above, this disclosure provides a means to facilitate temporary incognito services. In particular, a UE may normally operate in default mode using one or more default identifiers, a UE may temporarily transition to operating in incognito mode using one or more incognito identifiers, and then, after a period of time, automatically return to operating in default mode again using one or more default identifiers.

[0041] In one example of this process, a UE may migrate to operate with the Incognito operation eSIM profile instead of the UE's default operation eSIM profile, and then, after a period of time, automatically revert to operating with the default operation eSIM profile instead of the Incognito operation eSIM profile. Alternatively or additionally, a UE may migrate to operate with the Incognito hardware identifier instead of the UE's persistent hardware identifier, and then, after a period of time, automatically revert to operating with the persistent hardware identifier instead of the Incognito hardware identifier. Furthermore, if the UE has a default telephone number, the UE may migrate to operate with the Incognito telephone number instead of the default telephone number, and then, after a period of time, automatically revert to operating with the default telephone number instead of the Incognito telephone number.

[0042] Having a UE temporarily operate with one or more incognito identifiers instead of one or more default identifiers of the UE can help protect the privacy of UE users. For example, this process can help avoid correlation between the UE's location (e.g., network location or geolocation) and the UE's actual default identifiers, which can help keep the presence of a user at a particular location secret. Furthermore, having a UE temporarily operate with one or more incognito identifiers instead of one or more default identifiers of the UE can help avoid congestion of data storage over time due to data relating to any one given identifier.

[0043] In an exemplary implementation, this Incognito service may be provided or facilitated by an Incognito service provider. The Incognito service provider may be the same MNO with which the UE has an established service subscription, and with which the UE typically operates using an associated default operating eSIM profile. Alternatively, the Incognito service provider may be another MNO or other entity, possibly an MVNO, which may supply the UE with an Incognito eSIM profile for temporary use, and / or an Incognito UE hardware identifier and / or Incognito telephone number for use by the UE.

[0044] Figure 4 is a simplified block diagram showing an exemplary network configuration for implementing an example of this process. Specifically, Figure 4 shows a UE 100 configured to communicate with an Incognito Server 400 (or more generally, a cloud-based computing system, possibly a Secure Enclave Server or a confidential computing system) and a Profile Provisioning System 402. In particular, the figure shows a UE having radio connectivity to one or more networks 404 that provide connectivity enabling the UE to communicate with the Incognito Server 400 and the Profile Provisioning System 402. One or more networks 404 may include a wireless communications network (e.g., one or more access nodes and core networks) provided by an MNO to which the UE subscribes and which the UE operates with an associated default operating eSIM profile. Alternatively or additionally, one or more networks 404 may include, among other options, WiFi access points, local area networks, and the public internet.

[0045] In an exemplary configuration, the profile provisioning system 402 is an MNO (e.g., an MVNO) profile provisioning system, and the profile provisioning system 402 is structured as described above, including SM-DP+ and SM-DS, to facilitate the creation and installation of operational eSIM profiles on the UE. However, to further assist in protecting user privacy, the SM-DP+ in a preferred embodiment may be configured not to maintain a mapping between the UE's EID and the Incognito profile (and / or one or more specific Incognito identifiers) assigned to the UE. Furthermore, as shown in the illustration, the Incognito server 400 in the exemplary configuration communicates with the profile provisioning system 402, thereby allowing the Incognito server 400 to work in conjunction with the profile provisioning system 402 to trigger the creation and installation of Incognito eSIM operational profiles on the UE.

[0046] As further illustrated, the Incognito server 400 includes, or has access to, various sets of identifiers that can be assigned to function as Incognito identifiers as described herein. In an exemplary configuration, this includes a set of subscriber identifiers 406, a set of UE hardware identifiers 408, and a set of telephone numbers 410. Each of these sets of identifiers may be authorized by its respective authorization entity and may take the form described above, among other options. For example, the set of subscriber identifiers 406 may be a set of unique IMSIs authorized by a standardizing body responsible for IMSI authorization, the set of UE hardware identifiers 408 may be a set of unique MEIDs authorized by a standardizing body responsible for MEID authorization, and the set of telephone numbers 410 may be a set of unique MSISDNs authorized by a standardizing body responsible for telephone number authorization. In scenarios where a particular identifier is on a block identifier list (such as a MEID on a global block MEID list), the authorized set of identifiers may help to avoid assigning block identifiers for use in Incognito by excluding any such block identifiers.

[0047] The Incognito Server 400 may be operated by an MNO (e.g., an MVNO), thereby enabling the Incognito Server to obtain at least subscriber identifiers (e.g., IMSI) and telephone numbers (e.g., MSISDN), similar to how an MNO would typically obtain such identifiers for assignment to subscribers. Furthermore, the Incognito Server 400 may obtain hardware identifiers (e.g., MEID), similar to how a UE manufacturing plant would typically obtain such identifiers for assignment to the UEs it manufactures. Each of these sets of identifiers may contain hundreds or thousands of such identifiers. Furthermore, the Incognito Server 400 may have each of these sets of identifiers (or a particular set of such identifiers) pre-provisioned, or the Incognito Server 400 may dynamically obtain various such identifiers as needed, such as by requesting and obtaining identifiers from issuing entities when desired.

[0048] In exemplary embodiments, UE100 may further include an Incognito client application 412 that can facilitate interaction with the Incognito server 400 and, among other options, interaction with the UE's LPA to manage the transition of the UE to Incognito mode and the automatic return of the UE to default operating mode. For example, the Incognito client 412 may engage in signaling with the Incognito server 400 to provision an Incognito operating eSIM profile and / or an Incognito UE hardware identifier to the UE and to indicate when its Incognito data is being used and when it can be released for other uses. Furthermore, the Incognito client 412 may engage in signaling with the UE's LPA to install and activate an Incognito operational eSIM profile for use, and then automatically revert to the default operational eSIM profile after a certain period of time. The Incognito client 412 may also register an Incognito UE hardware identifier with the UE for use, and then automatically revert to the UE's persistent hardware identifier after a certain period of time.

[0049] The incognito client 412 may further promote abuse prevention services, for example, to prevent abuse of incognito mode and avoid service charges such as data service fees.

[0050] To facilitate the transition from the UE's default operating mode (for example, with the operating eSIM profile associated with the UE's normal service subscription) to incognito mode, the incognito client 412 may send an incognito_request message to the incognito server 400. In response to this incognito_replace message, the incognito server 400 may then randomly select one or more identifiers for temporary use incognito and provision them to the UE 100.

[0051] For example, in response to this incognito_request message, the incognito server 400 may randomly select a subscriber identifier from the set of subscriber identifiers 406 for temporary use by the UE 100, and in conjunction with the profile provisioning system 402, may cause the profile provisioning system 402 to establish an operational eSIM profile using the selected subscriber identifier and to input a service profile corresponding to the associated MNO subscriber profile store, thereby facilitating authentication and service for the UE operating under this operational eSIM profile. Additionally or alternatively, the incognito server 400 may randomly select a telephone number from the set of telephone numbers 408 for temporary use by the UE 100, and the incognito server 400 may cause the profile provisioning system to include the selected telephone number in the operational eSIM profile. The incognito server 400 may also flag each of such selected identifiers as currently in use (or, for example, remove them from the set of identifiers) to help avoid duplicate assignment of the same identifier to multiple UEs at once.

[0052] Furthermore, the Incognito Server 400 may enable the UE's LPA to download newly established operational eSIM profiles from the profile provisioning system 402 and respond to the Incognito Client 412 with information to cause the UE's LPA to download them. For example, the Incognito Server 400 may provide the Incognito Client 412 with a Universal Resource Locator (URL) or another address to retrieve new operational eSIM profiles from the profile provisioning system 402, and the Incognito Client 412 may respond by directing the UE's LPA to retrieve the operational eSIM profiles accordingly. Thus, the UE's LPA may download operational eSIM profiles having subscriber identifiers randomly selected by the Incognito Server 400 from a set of subscriber identifiers 406 and / or telephone numbers randomly selected by the Incognito Server 400 from a set of telephone numbers 410, and the LPA may store the downloaded operational eSIM profiles in the UE's eSIM.

[0053] To enter Incognito mode with respect to this downloaded and installed operational eSIM profile, the Incognito client 412 may deactivate the UE by instructing the UE to deactivate from any MNO network to which the UE is currently attached, and then instruct the UE's LPA to deactivate and activate the new operational eSIM profile as the Incognito operational eSIM profile instead of the UE's current active (e.g., primary) operational eSIM profile. The UE may then operate in Incognito mode, at least partially, by operating with this Incognito operational eSIM profile instead of the default operational eSIM profile. For example, the UE may then perform a new scan for coverage along the PRL of the new active Incognito operational eSIM profile, and if it finds a strong coverage threshold, it may engage in attachments including random access signaling, RRC signaling, and authentication matched to the subscriber identifier in the Incognito operational eSIM profile. Furthermore, where applicable, the UE may use the phone number of the Incognito operation eSIM profile to engage in telephone services.

[0054] In an alternative embodiment, if the UE has multiple active operational eSIM profiles, the Incognito client 412 may instruct the UE to change its current primary operational eSIM profile to a secondary operational eSIM profile, thereby changing the UE to a secondary operational eSIM profile, and then activate the new Incognito operational eSIM profile and set it as the UE's primary operational eSIM profile.

[0055] After a period of operation in incognito mode, the incognito client 412 may then automatically return the UE from incognito mode to the UE's default operating mode. For example, the incognito client 412 may deactivate the UE by instructing the UE to disconnect from any MNO network to which the UE is currently attached, and then instruct the UE's LPA to deactivate and reactivate the incognito operating eSIM profile (perhaps including deleting the incognito operating eSIM profile) and instead reactivate (or change to primary) the UE's default operating eSIM profile, i.e., the operating eSIM profile that the incognito operating eSIM profile replaced. The UE may then operate again in default mode, at least partially, by operating with this default operating eSIM profile instead of the incognito operating eSIM profile. For example, the UE may then perform a new scan for coverage along the PRL of the default operating eSIM profile, and if it finds a strong coverage threshold, it may engage in attachments including random access signaling, RRC signaling, and authentication matched to the subscriber identifier in the default operating eSIM profile. Furthermore, where applicable, the UE may engage in telephone services using the telephone number in the default operating eSIM profile.

[0056] Furthermore, the Incognito client 412 may notify the Incognito server 400 and / or the profile provisioning system 402 when the UE ceases using the Incognito operation eSIM profile. When the UE ceases using the Incognito operation eSIM profile, the Incognito server 400 may release the subscriber identifiers and / or telephone numbers that were temporarily assigned to the UE, making each such identifier newly available in the identifier pool for random selection and assignment. The profile provisioning system 402 may also update its records and the MNO subscriber profile records, for example, by removing the service profile data associated with the temporarily assigned Incognito operation eSIM profile.

[0057] Furthermore, in addition to, or instead of, making the UE operate with the Incognito operating eSIM profile, the process may include making the UE operate with an Incognito UE hardware identifier. For example, in response to an incognito_request from an Incognito client 412, the Incognito server 400 may, additionally or alternatively, randomly select a UE hardware identifier from a set of UE hardware identifiers 408 for the UE to use temporarily, and the Incognito server 400 may return that UE hardware identifier to the UE in response, flagging it as currently in use (or removing it from the set of hardware identifiers) to help avoid duplicate assignment. The Incognito client 412 may then store this received UE hardware identifier for use. Furthermore, the Incognito server 400 may, in conjunction with the profile provisioning system 402 and / or the associated MNO, record the hardware identifier as the UE's hardware identifier.

[0058] To enter Incognito mode with respect to this received UE hardware identifier, perhaps as part of entering Incognito mode as described above, the Incognito client 412 may register the received hardware identifier to be used as an Incognito hardware identifier instead of the UE's persistent hardware identifier. For example, the Incognito client 412 may call an operating system API and set a flag to specify and use this Incognito hardware identifier instead of the UE's persistent hardware identifier. The UE may operate in Incognito mode, at least partially, by operating with this Incognito hardware identifier instead of the UE's persistent hardware identifier. For example, if the UE provides its hardware identifier as part of an attachment process and / or authentication process, the UE may provide its Incognito hardware identifier instead. Furthermore, if another action is taken on the UE's hardware identifier, the Incognito hardware identifier may be used instead.

[0059] After this period of operation in Incognito mode, the Incognito client's automatic return of the UE from Incognito mode to the UE's default operating mode may then involve the Incognito client 412 unregistering the Incognito hardware identifier from the UE by, for example, calling an operating system API and clearing a specified flag to use the Incognito hardware identifier instead of the UE's persistent hardware identifier. Thus, the UE reverts to using the persistent hardware identifier instead of the Incognito hardware identifier for the associated operation.

[0060] It should also be noted that variations of the above process are equally possible. For example, an alternative approach might be to provision a skeleton eSIM operational profile to the UE, having one or more placeholders that can be populated with one or more temporarily assigned Incognito identifiers, and then dynamically populate that skeleton profile with one or more such Incognito identifiers. Such a skeleton profile might include, among other options, an IMSI placeholder that can be populated with a temporarily assigned Incognito IMSI, and possibly an MSISDI placeholder that can be populated with a temporarily assigned Incognito MSISD.

[0061] In an exemplary embodiment of this alternative approach, instead of using a typical eSIM provisioning process, an Incognito server or other entity may securely load such a skeleton eSIM operational profile into the UE's eSIM using its own provisioning process, possibly through interaction with an Incognito client 412. This provisioning, or any other initial provisioning of the skeleton profile into the UE's eSIM, may occur at various points in time, among other options, such as during UE manufacturing, when the Incognito client is first installed on the UE, or when the UE first transitions to Incognito mode. Furthermore, to further protect user privacy, the Incognito server or any other entity performing this process may avoid recording the mapping between the UE's EID and this skeleton profile.

[0062] Using this skeleton profile, in order to transition the UE into Incognito mode, the Incognito server may operate as described above and randomly provision one or more Incognito identifiers for temporary use by the UE. However, instead of provisioning an Incognito operational eSIM profile to the UE thereafter, the Incognito server may provide the UE's Incognito client with a selected Incognito identifier(s), which can then insert the provided Incognito identifier(s) into the appropriate location(s) of the UE's skeleton operational eSIM profile. For example, the Incognito server may provide the UE with a randomly selected IMSI, and the Incognito client, possibly working with the UE's LPA, may dynamically insert that IMSI into the UE's skeleton profile in place of an IMSI placeholder to establish an Incognito eSIM operational profile for the UE, which can then be activated in place of the UE's current active and / or primary eSIM operational profile, as described above. Next, the act of returning from Incognito mode to the UE's default mode may involve switching back to the UE's default operating eSIM profile and clearing any temporarily assigned identifiers from the skeleton profile, so that the skeleton profile can be reused later using one or more newly assigned Incognito identifiers.

[0063] Furthermore, a UE may be provisioned with multiple incognito identifiers, and the UE may rotate randomly among them.

[0064] There may be various triggers for the UE to transition from its default operating mode to Incognito mode, or vice versa. Three exemplary triggers, though not limited to them, are (i) position, (ii) time, and (iii) manual user input. In an exemplary embodiment, the Incognito client 412 may provide a configuration dialog that the UE can present on the display screen of its user interface 104, through which the user may specify when the Incognito client should monitor for triggers to enter (or exit) Incognito mode, and / or the user may manually instruct the Incognito client to put the UE into (or exit) Incognito mode.

[0065] Regarding location, the Incognito client 412 may detect (e.g., learn) when the UE's current location satisfies a predetermined location condition, for example, that the UE's location is within a geographical area where it is desirable to operate the UE in Incognito mode. The Incognito client 412 may make this determination through interaction with the UE's positioning module 106, or, among other options, further interact with the UE's serving MNO's MLS220. Furthermore, the Incognito client 412 may provision data defining “geofenced” areas where Incognito mode should or should not be used, possibly through user configuration in the Incognito client 412's settings dialog. Thus, the Incognito client 412 may monitor the UE's location and compare it to a geofence, and if the UE's location enters (or leaves) the geofence, it may transition the UE to (or out of) Incognito mode.

[0066] By using location as a trigger for entering incognito mode, it may be possible to encourage the UE to operate in incognito mode when it is located in a sensitive location such as a hospital or other such facility where it is undesirable to correlate the UE's location with the user.

[0067] With respect to time, the Incognito client 412 may detect (e.g., learn) when the current time (e.g., hour, day of the week, etc.) satisfies a predetermined time condition, for example, when the current time falls within a time range in which it is desirable for the UE to operate in Incognito mode. The Incognito client 412 may make this determination by monitoring a time recorder. Furthermore, the Incognito client 412 may provision data defining the time range in which Incognito mode should be used (or not used), or the time in which Incognito mode should start (or end), perhaps by the user's schedule in a calendar stored in the UE, and / or similarly, perhaps by the user configuration in the Incognito client 412's configuration diagram. Thus, the Incognito client 412 may monitor the current time and compare it to the defined time range or start time, and if the time condition is met, it may responsively transition the UE into (or out of) Incognito mode.

[0068] By using time as a trigger for entering incognito mode, it may be possible to encourage the UE to operate in incognito mode when the UE is located in a sensitive location, such as indicated by the UE's calendar data.

[0069] Furthermore, as described above, the UE may automatically return from incognito mode to its default operating mode after a period of time, such as 24 hours or another period of time, while operating in incognito mode.

[0070] The Incognito client 412 can control this automatic return by setting a timer when the Incognito client 412 transitions the UE to Incognito mode, and then automatically returning the UE from Incognito mode to default mode in response to the timer's expiration. The duration of this timer may be set by default and / or set by user input via the Incognito client 412's settings dialog. Thus, the Incognito client 412 can detect the expiration of such a timer, reflecting that the UE operated in Incognito mode for a period corresponding to the timer's duration, and then the Incognito client 412 can respond by returning the UE from Incognito mode to default mode.

[0071] Alternatively or additionally, as described above, there may be one or more other criteria for the Incognito client 412 to determine when it should automatically return the UE from Incognito mode to default mode. For example, in an embodiment where the UE's location was perhaps the trigger for transitioning the UE to Incognito mode, the Incognito client 412 may use the UE's location as a further trigger for automatically returning the UE to its default operating mode. For example, if the Incognito client 412 transitioned the UE to Incognito mode in response to detecting that the UE's location is within a given geofence, the Incognito client 412 may then automatically return the UE to default mode in response to subsequently detecting that the UE's location is no longer within the geofence.

[0072] In an exemplary embodiment, the incognito client 412 may first acquire incognito data that facilitates the UE operating in incognito mode, in which case the act of transitioning the UE to incognito mode may include activating that incognito data instead of the default data. Furthermore, when the UE returns from incognito mode to its default mode, the incognito client 412 may then acquire new incognito data that is available to activate the next time a trigger is detected for the UE to transition to incognito mode.

[0073] For example, the Incognito client 412 may first cause the UE to obtain an Incognito operation eSIM profile, and then the Incognito client 412 may transition the UE to Incognito mode by causing the UE's LPA to deactivate the UE's default operation eSIM profile and activate the Incognito operation eSIM profile. Next, when the Incognito client 412 returns the UE from using the Incognito operation eSIM profile to using its default operation eSIM profile by deactivating the Incognito operation eSIM profile and reactivating the UE's default operation eSIM profile, the Incognito client 412 may then move to obtain a new Incognito operation eSIM profile, which may similarly activate the next time the Incognito client 412 detects a trigger to do so instead of the UE's default operation eSIM profile.

[0074] Similarly, the Incognito client 412 may have already obtained an Incognito UE hardware identifier, and the Incognito client 412 may transition the UE to Incognito mode by registering that hardware identifier for use by the UE instead of the UE's persistent hardware identifier. Next, when the Incognito client 12 brings the UE back from using the Incognito hardware identifier to using its persistent hardware identifier, the Incognito client 412 may move to obtain a new Incognito hardware identifier, which may cause the Incognito client 412 to use the next time it detects a trigger to do so, instead of the UE's persistent hardware identifier.

[0075] Alternatively, the Incognito client 412 may dynamically acquire such Incognito data in place when the data is used. For example, when the Incognito client 412 detects a location trigger and / or a time trigger, or when it receives a manual user request trigger to transition the UE to Incognito mode, the Incognito client 412 may then send an incognito_request to the Incognito server 400 and proceed to transition the UE to Incognito mode as described above. Thus, in response to detecting a trigger to transition to Incognito mode, the Incognito client 412 may cause the UE to provision a new Incognito operation eSIM profile and activate that Incognito operation eSIM profile instead of the UE's default operation eSIM profile. Furthermore, in response to the UE detecting a trigger to transition to Incognito mode, the Incognito client may obtain an Incognito hardware identifier and register that Incognito hardware identifier for use in place of the UE's persistent hardware identifier.

[0076] It should also be noted that the detection of triggers for transitioning to Incognito mode and / or triggers for automatically returning to default mode may be coordinated and / or partially performed by the Incognito server 400 and / or one or more other entities. For example, the Incognito server 400 may detect location and / or time triggers as described above and respond by sending a signal to the Incognito client 412 to trigger a transition to Incognito mode.

[0077] Figure 5 is a simplified block diagram of an exemplary incognito server that may operate in the configuration shown in Figure 4, for example. As shown, the exemplary incognito server includes a network communication interface 500, a processor 502, and non-temporary data storage 504, all of which may be connected to each other in a communicative manner by a system bus or other connection mechanism 506.

[0078] The network communication interface 500 may include any communication module that facilitates communication with other entities, as shown in Figure 4. The processor 502 may include one or more general-purpose processors (e.g., microprocessors) and / or one or more dedicated processors (e.g., application-specific integrated circuits). The non-temporary data storage 504 may include one or more volatile and / or non-volatile storage components. As shown, the non-temporary data storage 504 may hold program instructions 508 that can be executed by the processor 502 to perform various incognito server operations. Thus, the incognito server may be configured to perform various such operations by being programmed with instructions that can be executed by the processor 502 to perform those operations, among other options.

[0079] Next, Figure 6 is a flowchart illustrating an exemplary method that may be implemented in accordance with this disclosure to temporarily operate a UE in incognito mode and then automatically return to operating in its default mode.

[0080] As shown in Figure 6, in block 600, the method may include detecting a trigger for the UE to temporarily operate in incognito mode, the trigger being detected when the UE is operating in default mode with a first operational eSIM profile having a first subscriber identifier active on the UE's eSIM. Furthermore, in block 602, the method may include, in response to the detection of the trigger, (i) the UE transitioning from operation in default mode to operation incognito mode, and (ii) the UE automatically returning from operation in incognito mode to operation in default mode after operating in incognito mode for a period of time.

[0081] The act of transitioning a UE from operation in default mode to operation in incognito mode includes (a) deactivating a first operational eSIM profile on the eSIM and activating a second operational eSIM profile on the eSIM in place of the first operational eSIM profile, the second operational eSIM profile having a second subscriber identifier different from the first subscriber identifier, and which was previously not active on the eSIM, and the transition may further include (b) using the second subscriber identifier in accordance with the second operational eSIM profile to facilitate engagement with wireless communication services.

[0082] Furthermore, the act of automatically returning the UE from incognito mode to default mode may include (a) deactivating the second operational eSIM profile on the eSIM and reactivating the first operational eSIM profile on the eSIM in place of the second operational eSIM profile, and (b) using the first subscriber identifier in accordance with the first operational eSIM profile to facilitate engagement with wireless communication services.

[0083] Furthermore, the act of automatically returning from operating in incognito mode to operating in default mode after operating in incognito mode for a certain period may include the UE detecting the end of the period of operation in incognito mode and the UE automatically returning from operating in incognito mode to operating in default mode in response to detecting the end of the period of operation in incognito mode.

[0084] Furthermore, the method may also include the UE sending a request to a cloud-based computing system (e.g., an Incognito server) for the assignment of an Incognito profile to the UE, and the cloud-based computing system may be configured to respond to the request by assigning a second subscriber identifier to the UE and triggering the establishment of a second operational eSIM profile for download to the UE. In that case, the act of automatically returning from Incognito mode to default mode may also include the UE sending a message to the cloud-based computing system indicating that the UE has finished using the second subscriber identifier, and the cloud-based computing system may be configured to respond to the message by releasing the second subscriber identifier for assignment to another UE.

[0085] Furthermore, a UE may have a persistent hardware identifier that it uses in default mode to facilitate engagement with wireless communication services. In that case, the method may also include using a temporary hardware identifier instead of the persistent hardware identifier in incognito mode to facilitate engagement with wireless communication services. Furthermore, the act of automatically returning from incognito mode to default mode may also include returning to using the persistent hardware identifier to facilitate engagement with wireless communication services.

[0086] Furthermore, the method may further include sending a request from the UE to a cloud-based computing system for the assignment of an incognito hardware identifier to the UE, and the cloud-based computing system may be configured to respond to the request by assigning the UE a temporary hardware identifier for use by the UE in place of a persistent hardware identifier. Moreover, the act of automatically returning from incognito mode to default mode may further include sending a message from the UE to the cloud-based computing system indicating that the UE has finished using the temporary hardware identifier, and the cloud-based computing system may be configured to respond to the message by releasing the temporary hardware identifier for assignment to another UE.

[0087] Furthermore, the first operational eSIM profile in the method may be an operational eSIM profile for services from a first mobile network operator, and the second operational eSIM profile may be an operational eSIM profile for services from a second mobile network operator different from the first mobile network operator. Alternatively, the second operational eSIM profile may be another operational eSIM profile for services from the first mobile network operator.

[0088] Furthermore, the act of detecting a trigger for the UE to temporarily operate in incognito mode may include detecting that the UE's current geolocation satisfies predetermined location conditions. Moreover, the act of automatically returning from incognito mode to default mode after operating in incognito mode for a period of time may include (i) detecting that the UE's current geolocation no longer satisfies predetermined location conditions, and (ii) automatically returning from incognito mode to default mode in response to the detection that the UE's current geolocation no longer satisfies predetermined location conditions.

[0089] Alternatively or additionally, the act of detecting a trigger for the UE to temporarily operate in Incognito mode may include detecting that the current time meets a predetermined time condition. Further alternatively, the act of detecting a trigger for the UE to temporarily operate in Incognito mode may include detecting the reception to the UE of user input (e.g., an entry into the Incognito-Client Settings dialog or other user interface) that defines the UE to temporarily operate in Incognito mode.

[0090] Furthermore, the method may include pre-storing a second operational eSIM profile in the eSIM in anticipation of detecting a trigger, in which case the act of activating the second operational eSIM profile may include activating the pre-storing second operational eSIM profile. Alternatively, the act of the UE transitioning to incognito mode operation may include (i) the UE downloading a second operational eSIM profile and (ii) the UE storing the second operational eSIM profile in the eSIM, in which case the act of activating the second operational eSIM profile may include activating the downloaded second operational eSIM profile.

[0091] Furthermore, the first operational eSIM profile may have a first telephone number configured for use by the UE in default mode to facilitate engagement with telephone services, and the second operational eSIM profile may also have a second telephone number, which differs from the first telephone number, and is configured for use by the UE in incognito mode to facilitate engagement with telephone services.

[0092] Furthermore, it should be noted that the various operations described herein that are performed with respect to eSIM technology may also be performed with respect to other forms of subscriber identifier technology.

[0093] Furthermore, while the above description provides a method for temporarily assigning one or more incognito identifiers to a UE for a certain period and then automatically reverting to the UE's default identifier(s) after that period, alternative embodiments may include changing one or more such incognito identifiers during that period. For example, if a UE operates in incognito mode for nine minutes, (i) the system may randomly select and assign to the UE a first incognito IMSI to be used by the UE instead of the default IMSI at the start of the nine-minute period; (ii) the system may then randomly select and assign to the UE a second different incognito IMSI to be used by the UE instead of the first incognito IMSI starting from the third minute of the nine-minute period; (iii) the system may then randomly select and assign to the UE a third different incognito IMSI to be used by the UE instead of the second incognito IMSI starting from the sixth minute of the nine-minute period. Once the nine-minute period has expired, the system may then revert the UE to use the UE's default IMSI. Other examples could be similarly possible.

[0094] As further described above, the disclosure also envisions a UE having a processor, non-temporary data storage, an eSIM, a transceiver, and an antenna structure supporting air interface communication, wherein the non-temporary data storage holds program instructions executable by the processor that cause the UE to perform the operations described above. Furthermore, the disclosure envisions a non-temporary computer-readable medium storing the processor-executable instructions that cause the UE to perform such operations.

[0095] Exemplary embodiments are described above. However, those skilled in the art will understand that these embodiments may be modified and altered without departing from the true scope and spirit of the invention.

Claims

1. It is a method, The method includes detecting a trigger for a user equipment device (UE) to temporarily operate in incognito mode, wherein the UE has an embedded subscriber interface module (eSIM), and when the trigger is detected, the UE operates in a default mode in which a first operational eSIM profile having a first subscriber identifier is active on the eSIM, and the method further includes In response to the detection of the trigger, the UE includes (i) transitioning from operation in the default mode to operation in the incognito mode, and (ii) after operating in the incognito mode for a certain period of time, automatically returning from operation in the incognito mode to operation in the default mode, The migration includes (a) deactivating the first operational eSIM profile on the eSIM and activating a second operational eSIM profile on the eSIM in place of the first operational eSIM profile, wherein the second operational eSIM profile has a second subscriber identifier different from the first subscriber identifier and was not previously active on the eSIM, and the migration further includes (b) using the second subscriber identifier in accordance with the second operational eSIM profile to facilitate engagement with wireless communication services. The automatic recovery method includes (a) deactivating the second operational eSIM profile on the eSIM and reactivating the first operational eSIM profile on the eSIM in place of the second operational eSIM profile and (b) using the first subscriber identifier in accordance with the first operational eSIM profile to facilitate engagement with wireless communication services.

2. After operating in the incognito mode for a certain period, the automatic return from operating in the incognito mode to operating in the default mode is, The UE detects the elapsed time during which it is operating in the incognito mode, The method according to claim 1, further comprising the UE automatically returning from operation in incognito mode to operation in default mode in response to detecting the elapsed period during which it was operating in incognito mode.

3. Further including sending a request from the UE to a cloud-based computing system for the assignment of an Incognito Profile to the UE, The cloud-based computing system is configured to respond to the request by assigning the second subscriber identifier to the UE and triggering the establishment of the second operational eSIM profile for download to the UE. Automatically returning from the incognito mode to the default mode further includes the UE sending a message to the cloud-based computing system indicating that the UE has finished using the second subscriber identifier, The method according to claim 1, wherein the cloud-based computing system is configured to respond to the message by releasing the second subscriber identifier for assignment to another UE.

4. The UE has a persistent hardware identifier for the UE that the UE uses in the default mode to facilitate engagement with wireless communication services, and the method is The incognito mode further includes using a temporary hardware identifier instead of the persistent hardware identifier in order to facilitate engagement with wireless communication services, The method according to claim 1, wherein the automatic return from the incognito mode to the default mode further includes returning to use the persistent hardware identifier to facilitate engagement with wireless communication services.

5. The UE further includes sending a request to a cloud-based computing system for the assignment of an incognito hardware identifier to the UE, The cloud-based computing system is configured to respond to the request by assigning the temporary hardware identifier to the UE for use by the UE in place of the persistent hardware identifier, Automatically returning from the incognito mode to the default mode further includes the UE sending a message to the cloud-based computing system indicating that the UE has finished using the temporary hardware identifier, The method according to claim 4, wherein the cloud-based computing system is configured to respond to the message by releasing the temporary hardware identifier for assignment to another UE.

6. The aforementioned first operational eSIM profile is for services from a first mobile network operator, The method according to claim 1, wherein the second operational eSIM profile is for services from a second mobile network operator different from the first mobile network operator.

7. The method according to claim 1, wherein deactivating the second operational eSIM profile on the eSIM includes deleting the second operational eSIM profile from the eSIM.

8. The method according to claim 1, wherein detecting the trigger for the UE to temporarily operate in the incognito mode includes detecting that the current geolocation of the UE satisfies predetermined location conditions.

9. After operating in the incognito mode for a certain period, the automatic return from operating in the incognito mode to operating in the default mode is, The detection of the current geolocation of the UE no longer satisfying the predetermined location conditions, The method according to claim 8, further comprising: detecting that the current geolocation of the UE no longer satisfies the predetermined location conditions, and automatically returning from operation in incognito mode to operation in default mode.

10. The method according to claim 1, wherein detecting the trigger for the UE to temporarily operate in the incognito mode includes detecting that the current time satisfies a predetermined time condition.

11. The method according to claim 1, wherein detecting the trigger for the UE to temporarily operate in the incognito mode includes detecting the reception to the UE of a user input defining a request for the UE to temporarily operate in the incognito mode.

12. The method further includes pre-storing the second operational eSIM profile in the eSIM in anticipation of detecting the trigger, The method according to claim 1, wherein activating the second operation eSIM profile includes activating the pre-stored second operation eSIM profile.

13. The transition to operation in incognito mode by the aforementioned UE is: (i) Downloading the second operational eSIM profile using the UE, (ii) further includes storing the downloaded second operational eSIM profile in the eSIM, The method according to claim 1, wherein activating the second operational eSIM profile includes activating the downloaded second operational eSIM profile.

14. The first operational eSIM profile also includes a first telephone number which is configured to be used by the UE in the default mode to facilitate the engagement of telephone services. The method according to claim 1, wherein the second operational eSIM profile also has a second telephone number, which, unlike the first telephone number, is configured to be used by the UE in the incognito mode to facilitate the engagement of telephone services.

15. User equipment (UE), Processor and Non-temporary data storage and Embedded subscriber interface module (eSIM), Transceiver and, Includes an antenna structure that supports air interface communication, The non-temporary data storage holds program instructions that can be executed by the processor to cause the UE to perform an operation, and the operation is The UE includes detecting a trigger for temporarily operating in incognito mode, and when the trigger is detected, the UE operates in a default mode in which a first operational eSIM profile having a first subscriber identifier is active on the eSIM, and the operation further includes In response to the detection of the trigger, the system includes (i) transitioning from operation in the default mode to operation in the incognito mode, and (ii) after operating in the incognito mode for a certain period of time, automatically returning from operation in the incognito mode to operation in the default mode. The migration includes (a) deactivating the first operational eSIM profile on the eSIM and activating a second operational eSIM profile on the eSIM in place of the first operational eSIM profile, wherein the second operational eSIM profile has a second subscriber identifier different from the first subscriber identifier and was not previously active on the eSIM, and the migration further includes (b) using the second subscriber identifier in accordance with the second operational eSIM profile to facilitate engagement with wireless communication services. The automatic recovery described above includes (a) deactivating the second operational eSIM profile on the eSIM and reactivating the first operational eSIM profile on the eSIM in place of the second operational eSIM profile, and (b) using the first subscriber identifier in accordance with the first operational eSIM profile to facilitate engagement with wireless communication services for the UE.

16. After operating in the incognito mode for a certain period, the automatic return from operating in the incognito mode to operating in the default mode is, The UE detects the elapsed time during which it is operating in the incognito mode, The UE according to claim 15, further comprising automatically returning from operation in incognito mode to operation in default mode in response to detection of the elapsed period during which the UE has been operating in incognito mode.

17. The UE has a persistent hardware identifier for the UE that the UE uses in the default mode to facilitate engagement with wireless communication services. In the incognito mode, the UE uses a temporary hardware identifier instead of the persistent hardware identifier to facilitate engagement with wireless communication services. The UE according to claim 15, wherein the automatic return from the incognito mode to the default mode further includes returning to use the persistent hardware identifier to facilitate engagement with wireless communication services.

18. The UE according to claim 15, wherein the detection of the trigger for the UE to temporarily operate in the incognito mode includes the detection of at least one contextual state selected from the group consisting of (i) a current geolocation that satisfies a predetermined positional condition and (ii) a current time that satisfies a predetermined time condition.

19. A non-temporary computer-readable medium storing instructions that can be executed by a processor to cause a user equipment device (UE) to perform an action, wherein the action is: The UE includes detecting a trigger for temporarily operating in incognito mode, the UE having an embedded subscriber interface module (eSIM), and when the trigger is detected, the UE operates in a default mode in which a first operational eSIM profile having a first subscriber identifier is active on the eSIM, and the operation further includes: In response to the detection of the trigger, the system includes (i) transitioning from operation in the default mode to operation in the incognito mode, and (ii) after operating in the incognito mode for a certain period of time, automatically returning from operation in the incognito mode to operation in the default mode. The migration includes (a) deactivating the first operational eSIM profile on the eSIM and activating a second operational eSIM profile on the eSIM in place of the first operational eSIM profile, wherein the second operational eSIM profile has a second subscriber identifier different from the first subscriber identifier and was not previously active on the eSIM, and the migration further includes (b) using the second subscriber identifier in accordance with the second operational eSIM profile to facilitate engagement with wireless communication services. The automatic recovery described above includes (a) deactivating the second operational eSIM profile on the eSIM and reactivating the first operational eSIM profile on the eSIM in place of the second operational eSIM profile, and (b) using the first subscriber identifier in accordance with the first operational eSIM profile to facilitate engagement with wireless communication services, in a non-temporary computer-readable medium.

20. The UE has a persistent hardware identifier for the UE that the UE uses in the default mode to facilitate engagement with wireless communication services. In the incognito mode, the UE uses a temporary hardware identifier instead of the persistent hardware identifier to facilitate engagement with wireless communication services. The non-temporary computer-readable medium according to claim 19, wherein the automatic return from the incognito mode to the default mode further includes returning to use the persistent hardware identifier to facilitate engagement with wireless communication services.