IP Library Granted Patent US 12713240
Granted Patent B2
US 12713240 · App. 18/446,427 · Granted Aug 18, 2026

Secure identification of applications in communication network

Inventors: Saurabh Khare (Bangalore, IN); Rainer Liebhart (Munich, DE); Bo Holm Bjerrum (Aalborg, DK)
Assignee: Nokia Technologies Oy
H04W12/10H04L63/0807H04W12/06H04W12/66
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12713240
App. No.
18/446,427
Granted
Aug 18, 2026
Kind
B2
Abstract

Techniques for securely identifying applications in a communication network are disclosed. For example, a method comprises receiving, at user equipment, a data item associated with an application program that is installed or being installed on the user equipment. The method further comprises storing, by the user equipment, the data item with an identifier of the application program. The method still further comprises utilizing, by the user equipment, the stored data item when deciding to apply a route selection rule for data traffic associated with the application program.

Claims (21)

1 . A user equipment comprising:

at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to perform operations, the operations comprising:

receiving, from a communication network, via a secure channel established between the user equipment and the communication network, a data item associated with an application program that is installed or being installed on the user equipment, wherein the data item comprises a secret;

storing the data item in association with an identifier of the application program;

receiving, from the communication network, a route selection rule for data traffic associated with the application program, the route selection rule comprising another data item, wherein the another data item comprises another secret; and

applying the route selection rule for data traffic associated with the application program when the secret matches the another secret; or

rejecting the route selection rule for data traffic associated with the application program when the secret does not match the another secret.

2 . The user equipment of claim 1 , wherein the data item comprising the secret is generated by: (i) an application server associated with the application program; or (ii) a network entity of a communication network connecting the user equipment and the application server.

3 . The user equipment of claim 1 , wherein the secret comprises a security token, wherein the security token is static or dynamic, and wherein the another secret comprises another security token that is static or dynamic.

4 . The user equipment of claim 1 , wherein the secret comprises a trust-based value, and wherein the another secret comprises another trust-based value.

5 . The user equipment of claim 4 , wherein the trust-based value is useable to compute a security token or a one-time pad.

6 . A method comprising:

receiving, at user equipment from a communication network via a secure channel established between the user equipment and the communication network, a data item associated with an application program that is installed or being installed on the user equipment, wherein the data item comprises a secret;

storing, by the user equipment, the data item in association with an identifier of the application program; and

receiving, by the user equipment from the communication network, a route selection rule for data traffic associated with the application program, the route selection rule comprising another data item, the another data item comprising another secret; and

applying, by the user equipment, the route selection rule for data traffic associated with the application program when the secret matches the another secret; or

rejecting, by the user equipment, the route selection rule for data traffic associated with the application program when the secret does not match the another secret.

7 . The method of claim 6 , wherein the data item comprising the secret is generated by: (i) an application server associated with the application program; or (ii) a network entity of a communication network connecting the user equipment and the application server.

8 . The method of claim 6 , wherein the secret comprises a security token, wherein the security token is static or dynamic, and wherein the another secret comprises another security token that is static or dynamic.

9 . The method of claim 6 , wherein the secret comprises a trust-based value, and wherein the another secret comprises another trust-based value.

10 . The method of claim 9 , wherein the trust-based value is useable to compute a security token or a one-time pad.