IP Library Granted Patent US 7,239,864
Granted Patent B2
US 7,239,864 · App. 10/524,188 · Granted Jul 3, 2007

Session key management for public wireless LAN supporting multiple virtual operators

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,239,864
App. No.
10/524,188
Granted
Jul 3, 2007
Kind
B2
Abstract

A method and apparatus for managing a session key for allowing a mobile terminal to access a wireless local area network (WLAN). The invention provides for establishing a first secure channel between an access point and a virtual operator, and suggesting a session key to the virtual operator from the access point. A second secure channel is established between the virtual operator and a user, and the session key is sent to the user via the second secure channel upon successful user authentication. The mobile terminal accesses the WLAN using the session key.

Claims (38)

1. A method for managing a session key used for enabling communications between a mobile terminal and an access point in a wireless local area network (“WLAN”), comprising the steps of:

receiving a request for access to the WLAN from the mobile terminal;

determining a virtual operator associated with the access request;

establishing a first secure channel between the access point and the virtual operator;

requesting user authentication from the virtual operator via the first secure channel, wherein the virtual operator communicates with the mobile terminal via a second secure channel to authenticate the mobile terminal;

selecting a session key and sending the session key to the virtual operator via the first secure channel, wherein the virtual operator sends the session key to the mobile terminal via the second secure channel; and

communicating with the mobile terminal using the session key;

wherein the step of requesting user authentication is performed in parallel with the step of selecting and sending the session key.

2. The method according to claim 1 , wherein the communicating step comprises communicating with the mobile terminal using the session key upon receiving notification of successful user authentication from the virtual operator.

3. The method according to claim 1 , wherein the step of selecting a session key comprises placing the session key on hold until notification of successful user authentication from the virtual operator, and upon notification removing the session key from on hold and sending the session key to the virtual operator.

4. The method according to claim 3 , further comprising the step of removing the session key from on hold if the authentication is successful.

5. The method according to claim 1 , wherein the virtual operator includes one of an Internet Service Provider, a cellular provider and a credit card provider.

6. A method for managing a session key used for enabling communications between a mobile terminal and an access point in a wireless local area network (“WLAN”), comprising the steps of:

receiving a request for access to the WLAN from the mobile terminal;

determining a virtual operator associated with the access request;

establishing a first secure channel between the access point and the virtual operator;

requesting user authentication from the virtual operator via the first secure channel, wherein the virtual operator communicates with the mobile terminal via a second secure channel to authenticate the mobile terminal;

selecting a session key and sending the session key to the virtual operator via the first secure channel, wherein the virtual operator sends the session key to the mobile terminal via the second secure channel; and

communicating with the mobile terminal using the session key;

wherein the step of selecting a session key and sending the session key to the virtual operator via the first secure channel is performed only after receiving notification of successful user authentication from the virtual operator.

7. An apparatus for managing a session key used for enabling communications between a mobile terminal and a wireless local area network (“WLAN”), comprising:

means for receiving a request for access to the WLAN from the mobile terminal;

means for determining a virtual operator associated with the access request;

first means for communicating with the virtual operator via a first secure channel, the first communicating means requesting user authentication from the virtual operator via the first secure channel, wherein the virtual operator communicates with the mobile terminal via a second secure channel to authenticate the mobile terminal;

means, coupled to the first communicating means, for selecting a session key and sending the session key to the virtual operator via the first secure channel, wherein the virtual operator sends the session key to the mobile terminal via the second secure channel; and

second means for communicating with the mobile terminal using the session key;

wherein the first communicating means requests user authentication in parallel with selecting means selecting and sending the session key.

8. The apparatus according to claim 7 , wherein the second communicating means communicates with the mobile terminal using the session key upon receiving notification of successful user authentication from the virtual operator.

9. The apparatus according to claim 7 , wherein the selecting means places the session key on hold until notification of successful user authentication from the virtual operator, and upon notification removes the session key from on hold and sends the session key to the virtual operator.

10. The apparatus according to claim 9 wherein the selecting means removes the session key from on hold if the authentication is successful.

11. The apparatus according to claim 7 , wherein the virtual operator includes one of an Internet Service Provider, a cellular provider and a credit card provider.

12. An apparatus for managing a session key used for enabling communications between a mobile terminal and a wireless local area network (“WLAN”), comprising:

means for receiving a request for access to the WLAN from the mobile terminal;

means for determining a virtual operator associated with the access request;

first means for communicating with the virtual operator via a first secure channel, the first communicating means requesting user authentication from the virtual operator via the first secure channel, wherein the virtual operator communicates with the mobile terminal via a second secure channel to authenticate the mobile terminal;

means, coupled to the first communicating means, for selecting a session key and sending the session key to the virtual operator via the first secure channel, wherein the virtual operator sends the session key to the mobile terminal via the second secure channel; and

second means for communicating with the mobile terminal using the session key

wherein the selecting means selects a session key and sends the session key to the virtual operator via the first secure channel only after receiving notification of successful user authentication from the virtual operator.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY NAME FROM INTERDIGITAL CE PATENT HOLDINGS TO INTERDIGITAL CE PATENT HOLDINGS, SAS. PREVIOUSLY RECORDED AT REEL: 47332 FRAME: 511. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 28, 2024
From: THOMSON LICENSING
To: INTERDIGITAL CE PATENT HOLDINGS, SAS
Reel/Frame 066703/0509 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2018
From: THOMSON LICENSING
To: INTERDIGITAL CE PATENT HOLDINGS
Reel/Frame 047332/0511 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2007
From: THOMSON LICENSING S.A.
To: THOMSON LICENSING
Reel/Frame 019330/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2005
From: ZHANG, JUNBIAO
To: THOMSON LICENSING S.A.
Reel/Frame 016623/0330 →