Method, computer program, computer-readable data carrier, terminal and communication network for transmitting a user dataset
The method enables authorized users to securely transfer user data records between terminal devices by using export and import flags, encryption, and security mechanisms, addressing the challenge of unauthorized transfer and maintaining user-specific settings.
Patent Information
- Application Number
- PCT/EP2024/083071
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-24
- Filing Date
- 2024-11-21
- Publication Date
- 2025-05-30
AI Technical Summary
Existing technologies do not allow authorized users to transfer their user data records, such as eUICC data records, from one terminal device to another without losing user-specific settings and without the risk of unauthorized transfer or cloning.
A method for transmitting user data records from a source device to a receiving device involves identifying an export flag, authorizing the export if permitted, and securely transferring the data using encryption keys, while preventing unauthorized transfer through mechanisms like export and import flags, counting variables, and lifetime management.
Authorized users can transfer their user data records securely and independently of communication networks, maintaining user-specific settings and preventing unauthorized transfer or cloning, thus enhancing user manageability and security.
Smart Images

Figure EP2024083071_30052025_PF_FP_ABST
Abstract
Description
[0001] Method, computer program, computer-readable data carrier, terminal device and communication network for transmitting a user data record
[0002] Field of the invention
[0003] The present invention relates to a transmission of data records handled on embedded secure elements. The embedded secure element can, in particular, be an embedded Universal Integrated Circuit Card (eUICC). The handled data records, hereinafter referred to as user data records or eUICC data records, can be, for example, user profiles with which users can log in to mobile networks. In particular, the invention relates to a method for transmitting a user data record, in particular an eUICC data record, from a source device to at least one receiving device, a computer program, a computer-readable data carrier, a terminal for participating in a communications network, and a communications network.
[0004] Background of the invention
[0005] Methods for handling user data records or eUICC data records, as well as computer programs, computer-readable data storage devices, terminals for participation in communication networks, and communication networks are known from the state of the art. For example, on eUICCs, for example on mobile devices such as mobile phones, smartphones, tablets, or similar, the respective identification features of users of the terminals are managed. On an eUICC, this usually takes place in the form of corresponding embedded Subscriber Identity Modules (eSIM). This procedure is necessary to meet the security requirements for managing the identification features. This requires a trusted party, which can be provided on eUICCs and / or servers, such aseSIM download servers, from which eUICC data sets can be obtained or managed as trusted subscription manager data preparation platforms (SM-DP+) in compliance with the respective security requirements.
[0006] EP 4 192 060 A1 discloses a method, devices, and computer program products for managing subscriber profiles on an eUICC. In this context, a method for managing subscriber profiles stored in an eUICC comprises an ISD-R and an application programming interface (API) implemented on the eUICC, wherein the API enables the execution or performance of a profile management operation via the ISD-R on a subscriber profile of the eUICC. Furthermore, an application installed on the eUICC instructs the API to perform the profile management operation with respect to the subscriber profile. The invention further relates to a corresponding eUICC, a device with an eUICC embedded therein, and computer program products representing the API and the application.
[0007] EP 4 175 337 A1, for example, relates to a method for managing at least one eUICC information set of an eUICC. The method comprises the following sequential steps: generating a first request for registering the eUICC information set with an eUICC manufacturer, wherein the first request comprises a first Function Call Identifier (FCI); sending the first request from the eUICC manufacturer to an intermediate buffer proxy; generating a response to the first request within the intermediate buffer proxy; and sending the response to the request to the eUICC manufacturer. Originally, identity modules for mobile devices were known as subscriber identity cards (SIM cards) and were mechanically interchangeable or transferable from one device to another, as long as the respective form factor of the SIM card permitted it.By embedding SIM cards as eSIMs on eUICCs, user data records managed on them, such as user profiles, can no longer be transferred by the user themselves from one device to another. The aforementioned procedures, computer programs, computer-readable data storage devices, devices, and communication networks do not allow the transfer of user data records or eUICC data records solely by the user authorized to use the data records.
[0008] Description
[0009] It is an object of the present invention to improve the manageability of user data records by authorized users. In particular, it is an object of the present invention to enable authorized users to transfer their personal user data records, such as the eUICC data records, for example in the form of user profiles, from one terminal (source device) to another terminal (receiving device).
[0010] This object is achieved by the subject matter of the independent claims. Exemplary embodiments emerge from the dependent claims and the following description. Features described herein with reference to methods, as well as corresponding method steps, can be implemented as device features, or vice versa. Sections of the description related to the method therefore also apply analogously to computer programs, computer-readable data carriers, terminal devices for participation in communication networks, and communication networks.In particular, method steps and related components mentioned can be implemented as functions of the computer programs, computer-readable data carriers, terminal devices for participation in communication networks and communication networks and any functions of the computer programs, computer-readable data carriers, terminal devices for participation in communication networks and communication networks can be implemented as method steps.
[0011] A method for transmitting a user data record, in particular an eUICC data record, from a source device to at least one receiving device comprises the following steps:
[0012] Identifying an export flag authorizing the export in the user record on the source device;
[0013] Detect whether the export flag indicates that export and / or import of the user data set from the source device or on the receiving device is permitted; and
[0014] Authorize the export of the user record from the source device to the receiving device if the export flag indicates that export and / or import of the user record is permitted.
[0015] A computer program comprises instructions which, when the program is executed by a terminal device capable of participating in a communications network, cause a corresponding procedure to be carried out.
[0016] A computer-readable data carrier includes a corresponding computer program stored thereon.
[0017] A terminal device for participating in a communication network comprises a corresponding computer program stored thereon, a corresponding computer-readable data carrier and / or is configured as a source device and / or receiving device for executing a corresponding method.
[0018] A communication network comprises at least one corresponding terminal device and / or a server with a corresponding computer program stored thereon, a corresponding computer-readable data carrier or the server is configured to execute a corresponding method.
[0019] The method can therefore be carried out by a data processing device or with the aid of a computer, which can be implemented as a terminal or server. A computer program can comprise instructions that, when executed by a data processing device or a computer, cause the computer to carry out the method. A computer-readable storage medium, a computer-readable data carrier, and / or a data carrier signal can store or transmit the computer program. A corresponding computer-readable data carrier can be present as a computer-readable medium and / or a data carrier signal.
[0020] The user data record or eUICC data record may be a subscription and / or user profile, or the user data record may include parts thereof and / or the entire user profile, which may be authorized to use the source device and / or participate in a communications network. The process or method for transferring the user data record may be initiated by a user of the user data record, for example, by triggering it via a corresponding local profile assistant (LPA), which may be managed by the source device or an eUICC circuit and / or corresponding programming or application interface (API).
[0021] After the export has been authorized, the user data record or eUICC data record can be deactivated on the source device or rendered unusable for the source device and / or a connection between the user data record and the source device can be terminated. The user data record can be exported in an encrypted format using a corresponding export key, provided the export is not interrupted or canceled, for example, due to a lack of authorization. An application interface on the source device can establish a secure channel with an application interface on the receiving device to transfer the user data record from the source device to the receiving device. The source device can receive a connection key to connect the user data record to the receiving device in order to send the user data record to the source device and connect it to it using the connection key and / or the export key.The user data record can first be encrypted with the export key, and a corresponding export data record can then be encrypted with the connection key to an import data record. The export key can be transmitted from the source device to the receiving device. A transport key for secure transport of the user data record from the source device to the receiving device can be applied independently of the export key. The export key can be preconfigured in the receiving device, and a corresponding public key can be transmitted from the receiving device to the source device, for example, via a secure channel that can be secured with the transport key.
[0022] The application interface of the source device can send the export data set or import data set to an application interface of the receiving device. The application interface of the receiving device can import the user data set in the form of the export data set or import data set. On the eUICC of the source device, the import data set can be decrypted using the connection key to obtain the export data set. The export data set can be decrypted using the export key to obtain the unencrypted user data set.
[0023] The inventive solution has the advantage that authorized users can transfer their user data records or eUICC data records, for example their user profiles, from one terminal device (source device) to another terminal device (receiving device) essentially according to their preferences and while observing appropriate security precautions, without losing user-specific settings in the data records. At the same time, unauthorized transfer or cloning of eUICC data records is prevented. Nevertheless, the transfer can take place without a connection to a communications network, such as the Internet or similar, while adhering to the respective security standards. This eliminates server connections and communications, and allows authorized users to transfer their user data records from source devices to receiving devices independently of such communications networks.The transfer can be carried out using local wired or wireless connection technologies such as USB, Bluetooth, WiFi, etc.
[0024] The solution is not limited to eUICCs, but is generally suitable for so-called secure elements (SEs), which are referred to herein, for example, as integrated circuit cards. As such, secure elements include, in addition to eUICCs, for example, classic UICCs, integrated UICCs (iUICCs) and all integrated secure elements of other types, such as integrated secure elements (iSE / eSE), smart cards, subscriber identity modules, subscriber identity modules (SIMs) and / or virtual SIMs (vSIMs). What all such secure elements have in common is that user data records or eUICC data records can be stored on them, for example as telecommunications profiles or "profiles" for short, with the help of which users can authenticate themselves to communication networks, for example as subscribers in telecommunications networks.The secure elements are characterized by the fact that the information stored on them, in particular the profiles, is particularly protected against attacks by third parties and is neither physically nor software-wise easily manipulated.
[0025] According to one embodiment, the user data record contains a counting variable that indicates how often the user data record has been imported and / or exported, that the counting variable is compared to a limit value that indicates how often the user data record may be imported and / or exported, and that the user data record is exported again if the counting variable is below or above the limit value or equal to the limit value, or that further export is denied if the counting variable exceeds or falls below the limit value. The counting variable can be implemented as a downcounter managed by the eUICC by subtracting a number of export operations already performed from the limit value until it reaches a value of 0. In other words, a corresponding counter can be reduced by one count value with each export. If the value of 0 is reached, the export can be denied.The limit value can therefore be used in two counting directions: For example, in a first counting direction, with a limit value starting at 3, the counter can be decremented with each export or successful transmission until it reaches a value of 0. In a second counting direction, the counter could be incremented from an initial value of 0, for example, up to a limit value of 3. Thus, the counting variable fulfills security requirements when transmitting eUICC data records, in particular by limiting the number of permissible transmissions and thus preventing or at least hindering any cloning of the data records.
[0026] According to one embodiment, a method further comprises a step of querying a transfer key, wherein the export is only authorized after a user has entered the transfer key. This prevents unauthorized or unencrypted transmission of eUICC data records. The transfer key thus helps to further increase security during the transmission of eUICC data records.
[0027] According to one embodiment, the number of export and / or transfer keys assigned for the user data set is limited, and after all export or transfer keys available at a given time have been used, the export is denied. For example, the transfer keys can be managed by a server. If a quota of assigned transfer keys is exhausted, the user must request an additional quota of transfer keys from the server, for example, using a request key. In this way, the number of transfers of user data sets can be limited, or a server can be integrated into the transfer process as a secure instance, at least temporarily. This creates a balance between user convenience and security interests.
[0028] According to one embodiment, it is provided that the user data record is assigned a
[0029] A lifetime is assigned to the eUICC and export and / or import is refused if the lifetime is exceeded. Implementing a lifetime is particularly relevant for the design of the eUICC as an integrated eUICC, i.e. integrated into a so-called System on a Chip (SoC), as this type of technology may have secure access to a time source. Once the lifetime is exceeded, a user can request an extension of the lifetime and, if the extension is approved, export and / or import is permitted until the end of the extended lifetime. For example, the lifetime can be managed by a server. If the lifetime has expired, a request for an extension of the lifetime must be made from the server, e.g. using an extension key. In this way, user data records cannot be transmitted or stored for an indefinite period of time.The transferability can be limited in time by integrating a server into the transfer process as a secure instance, at least temporarily. This creates a further balance between user convenience and security concerns.
[0030] According to one embodiment, a method may further comprise the following steps:
[0031] Identifying an import flag authorizing the import in the user record on the receiving device;
[0032] Detect whether the import flag indicates that export and / or import of the user record is permitted; and
[0033] Authorize the import of the user record from the source device to the receiving device if the import flag indicates that export and / or import of the user record is permitted.
[0034] For example, the export marking and / or the import marking can be a combined transfer marking, which can include corresponding markers regarding authorization of the export and / or import. Furthermore, the receiving device can perform version control of the user data record, for example, checking a TCA IPP format of the user data record or eUICC data record to determine whether the receiving device supports the version of the user data record to be imported. If support is not available, the receiving device can refuse the import. This prevents transmission to unauthorized receiving devices and / or devices that are not capable of using the user data record.
[0035] If export and import are authorized, the receiving device can import and / or install the user data record. If the export is authorized, the eUICC in the source device can create the export data record. If the export is not authorized, the eUICC can refuse creation of the export data record. If the export has taken place but an import is not authorized, the eUICC in the receiving device can refuse the import. The application interface of the receiving device can trigger activation of the imported user data record or enable it by prompting the user for input, or the activation can be performed automatically by the receiving device. The application interface of the receiving device can inform the application interface of the source device about the success and / or failure of the import or activation.If successful, the application interface of the source device can cause the source device to delete the export data record, import data record, and / or user data record. If unsuccessful, the export data record or import data record can be deleted and / or the user data record can be reactivated on the source device if it was previously deactivated or activated. This prevents simultaneous use of the user data record on two devices, or on both the source device and the receiving device. This helps increase transmission security, both technically and with regard to user authorization, and further prevents data cloning.
[0036] Short description of the characters
[0037] Fig. 1 shows a schematic view of an inventive
[0038] Communication network including terminal devices for carrying out a method for transmitting a user data set from a source device to at least one receiving device.
[0039] Detailed description of exemplary embodiments
[0040] The representations in the figure are schematic and not to scale. Where the same reference symbols are used in different figures in the following description, they refer to identical or similar elements. Identical or similar elements may also be designated by different reference symbols.
[0041] Fig. 1 shows a schematic view of a communication network 1 according to the invention, including terminal devices 2, for carrying out a method for transmitting an eUICC data record P, for example an eUICC data record, from one of the terminal devices 2, which functions as source device A, to at least one other of the terminal devices 2, which functions as receiving device B. Furthermore, the communication network 3 can comprise a server 3. The terminal devices 2 and the server 3 can carry out a method according to the invention using a computer program 4 based on computer-readable instructions contained therein.
[0042] The computer program 4 can be stored at least in sections on a computer-readable data carrier 5 and can define a series of parameters, labels, limit values G, keys K and / or steps S as well as regulate their generation, use and / or handling. The computer-readable data carrier 5 can be present as a computer-readable medium 6 and / or data carrier signal 7. In particular, the data carrier signal 7 can be designed to be transferable via the communication network 1 between terminal devices 2 and / or server 3 for respective execution thereon. Thus, the computer program 4 and thus a corresponding method for transferring the user data record P from the source device A to the receiving device B can be executed on the terminal devices 2 and / or the server 3. For this purpose, the terminal devices 2 can each contain a local profile assistant (LPA) 8 and an integrated circuit card 9, for example in the form of an eUICC, which at least in sections
[0043] Computer program 4 and thus can carry out corresponding process steps S.
[0044] Thus, in a first method step S1, a respective data set and / or parameter as well as the user data set P can be obtained by the source device A from the server 3 according to the respective standards, for example, by retrieving the user data set P from the LPA 8 of the source device via the publication network 1 from the server 3 and forwarding it to the circuit board 9 for installation and execution thereon. In a step
[0045] 52, an export marking E can be recognized on the source device A, in particular in its circuit board 9, which indicates whether an export and / or import of the user data set P between terminal devices 2 from the source device A to the receiving device B or by the receiving device B from the source device A is permitted.
[0046] If the export marking E is generally permissible, then in one step
[0047] 53, a counting variable Z must be checked to determine whether it is above or below a certain limit value G for the number of permissible exports. For example, the counting variable Z or corresponding counter can be reduced by one count value for each export, and if the value of the counting variable Z is 0 as the limit value Gz, the export can be denied. If this is the case, a new counting variable Z would have to be requested by the integrated circuit card 9 via the LPA 8 from the server 3, whereby the method can return to step S1.
[0048] If both export marking E and counting variable Z are permissible after their respective checks, a check can be made in step S4 to determine whether a lifetime T is below a corresponding limit value GT. In particular, the integrated circuit card 9 can be checked using access to a reliable time source managed therein to determine whether the lifetime T or the corresponding limit value G has been exceeded. If this is the case, a new lifetime T or lifetime extension would have to be requested by the integrated circuit card 9 via the LPA 8 from the server 3, whereby the method can return to step S1.As soon as a review of the export identifier E, counting variable Z, and / or life cycle time T has shown that a further export operation is permissible, the user data record P can be encrypted in a step S5 using an export key KE on the source device A, in particular by its integrated circuit card 9, in order to generate an encrypted export data record PE ZU, which can contain the user data record encrypted by the export key KE. In a step S6, the export data record PE can be transferred from the integrated circuit card 9 to the LPA 8 and thus made available for further processing by the LPA 8.
[0049] In a step S7, it can be queried whether a secure connection key Kc is available for creating a corresponding encrypted copy C of the export data record PE in the form of a transmission or import data record PEC. This verification and / or encryption can take place in the LPA 8 and / or in the circuit board 9. As soon as the transmission key Kc is available, the import data record PEC can be provided in a step S8 by appropriate encryption with the connection key Kc. The connection key Kc can be provided by the receiving device B, in particular by the circuit board 9 of the receiving device B transmitting the connection key Kc to the source device A via the LPA 9 of the receiving device B, in particular by the LPA 9 of the source device A receiving the connection key KC and possibly forwarding it to the sound cascade 9 of the source device A for processing.In a step S9, the export process between source device A and receiving device B may have been initiated previously and / or simultaneously. For this purpose, in a step S10, the source device A and the receiving device B may authenticate each other, for example, to subsequently negotiate and / or transmit the connection key Kc.
[0050] In a step SI 1, the actual export of the user data record P can then be authorized. For this purpose, in a step S12, a session can be initiated between the source device A and the receiving device B to carry out the actual transmission operation using the transmission or import data record PEC, possibly by generating a corresponding connection key Kv to establish a secure connection V between the source device A and the receiving device B, in particular between the circuit card 9 of the source device A and the circuit card 9 of the source device B, so that the secure connection V to transmit the import data record PEC can take place accordingly between secured instances, for example in the form of the respective eUICCs.In other words, if the export flag E indicates that export and / or import of the user data set P is permitted, authorizing the export of the user data set P from the source device A to the receiving device B should take place on or through the circuit board of the source device A.
[0051] In a step S13, a transfer or import request R from the receiving device B, which may already have been transmitted and / or negotiated in step S12, can be checked. In particular, the import request can be sent to the circuit board 9. With the import request, an import identifier I can be recognized and checked in a step S14, which may also have been transmitted from the receiving device B to the source device A in step S12 and may possibly indicate, using appropriate markers, whether the export or import to the receiving device B is permissible. In this case, in step S15, for example, a version check of the eUICC data set P can be performed to determine whether the eUICC data set P is compatible with the circuit board 9 of the receiving device B.
[0052] In a step S15, a transfer or import release can then be granted, for example by the circuit card 9 of the source device A. In a step S16, the transfer or import release can be transmitted from the circuit card 9 of the source device A to the LPA 8 of the source device A, possibly together with the encrypted copy C or the import data record PEC, which contains the eUICC data record P. In a step S17, the actual transmission of the import data record PEC from the source device A to the receiving device B can then take place, and for security reasons in particular initially from the LPA 8 of the source device A to the LPA 8 of the receiving device B. In a step S18, the actual import authorization for the import data record PEC or the eUICC data record P contained therein can take place on the receiving device B, in particular by its circuit card 9.Alternatively or additionally, corresponding steps S13 to S16 relating to an import request, recognition or verification of the import marking I and import release can take place on the receiving device B, in particular in its circuit boards 9, so that a secure instance can be used for these steps, similar to the export authorization in step SI 1.
[0053] Once the import authorization has been granted, the eUICC data set P can be imported or installed on or in the circuit board 9 of the receiving device B in a step S19. Corresponding keys K can be used to access the eUICC data set P, for example, using the transmission key Kc, connection key Kv, and / or export key KE. The entire export and import—i.e., transmission—process can be completed in a step S20. For this purpose, a transmission confirmation F can be generated for confirmation purposes, for example, in a secure form by the circuit board 9 of the receiving device B. The transmission confirmation F can be used to signal the source device A and / or the server 3 that the transmission has taken place.The source device A and / or the server 3 can then initiate appropriate steps to complete the transfer process, for example by deactivating and / or deleting any remaining copies C of the user data record P, adjusting count variables Z, storing transfer notes, for example by generating a blockchain, etc.
[0054] List of reference symbols
[0055] 1 Communication network T Lifespan
[0056] 2 Terminal V secure connection
[0057] 3 Server Z counting variable
[0058] 4 Computer program
[0059] 5 computer-readable data carrier 51 Obtaining server data
[0060] 6 computer-readable medium 52 Recognition of
[0061] 7 Data carrier signal export marking
[0062] 8 Local Profile Assistant (LPA) 53 Checking counting variables
[0063] 9 integrated circuit card 54 lifespan check
[0064] (eUICC) 55 Export encryption of the
[0065] User data record
[0066] A Source device 56 Provision export data set
[0067] B Receiver 57 Query transmission key
[0068] C encrypted copy S9 initiation export
[0069] E Export marking 510 mutual authentication
[0070] F Transfer Confirmation 511 Export Authorization
[0071] G Limit 512 Session setup
[0072] G Lifetime limit 513 Transmission or
[0073] Gz export number limit import request
[0074] I Import marking 514 Import request
[0075] K Key 515 Version Control
[0076] Kc transmission keys 516 transmission or
[0077] KE export key import release
[0078] Kv connection key 517 Detect import marking
[0079] P User data record / eUICC- 518 Import authorization
[0080] Data set 519 Import / Installation
[0081] R Import Request 520 Completion
[0082] S step
Claims
Patent claims 1. A method for transmitting a user data record (P), in particular an eUICC data record, from a source device (A) to at least one receiving device (B), comprising the following steps: Identifying an export flag (E) concerning authorization of the export in the user data record (P) on the source device (A); - Detecting whether the export flag (E) indicates that export and / or import of the user data set from the source device (A) or to the receiving device (B) is permitted; and authorizing the export of the user data set (P) from the source device (A) to the receiving device (B) if the export flag (E) indicates that export and / or import of the user data set (P) is permitted.
2. Method according to claim 1, characterized in that the user data record (P) contains a counting variable (Z) which indicates how often the user data record (P) has been imported and / or exported, that the counting variable (Z) is compared with a limit value (G) which indicates how often the user data record (P) may be imported and / or exported, and that the user data record (P) is exported a further time if the counting variable (Z) is below or above the limit value (G) or is equal to the limit value, or that further export is refused if the counting variable (Z) exceeds or falls below the limit value (G).
3. Method according to claim 1 or 2, characterized in that it further comprises a step of querying a transmission key (Kc), wherein the export is only authorized after input of the transmission key (Kc) by a user.
4. Method according to claim 3, characterized in that a number of export and / or transmission keys (KE, KC) assigned for the user data record (P) is limited and after the use of all export or transmission keys (KE, KC) available at the given time, the export is refused.
5. Method according to at least one of the above claims, characterized in that the user data record (P) is assigned a lifetime (T) and that if the lifetime (T) is exceeded, the export and / or import is refused.
6. Method according to at least one of the above claims, characterized in that it further comprises the following steps: Identifying an import marking (I) concerning authorization of the import in the user data record (P) on the receiving device (B); - Detect whether the import flag (I) indicates that export and / or import of the user data set is permitted; and Authorizing the import of the user data record (P) from the source device (A) to the receiving device (B) if the import flag (I) indicates that export and / or import of the user data record (P) is permitted.
7. Computer program (4), characterized by instructions which, when the program is executed by a terminal (2) capable of participating in a communication network (1), cause a method according to one of claims 1 to 6 to be carried out.
8. Computer-readable data carrier (5), characterized by a computer program (4) according to claim 7 stored thereon.
9. Terminal (2) for participation in a communication network (1), characterized by a computer program (4) stored thereon according to Claim 7, a computer-readable data carrier according to claim 8 and / or in that it is set up as a source device (A) and / or receiving device (B) for carrying out a method according to at least one of claims 1 to 6.
10. Communications network (1), characterized by at least one terminal (2) according to claim 9 and / or by a server (3) with a computer program (4) stored thereon according to claim 7, a computer-readable data carrier according to claim 8 and / or in that it is set up to carry out a method according to at least one of claims 1 to 6.
Citation Information
Patent Citations
Method for managing at least one euicc information set (EIS) of a euicc and intermediate buffer proxy
EP4175337A1
Management of subscriber profiles on an euicc
EP4192060A1
Policy-based techniques for managing access control
US20140143826A1
Methods and apparatus for user authentication and human intent verification in mobile devices
US20180249333A1
Cellular service account transfer error recovery mechanisms
US20200137558A1