IP Library Patent Application 11867808
Patent Application
App. No. 11/867,808

Method, Apparatus and Computer Program Product for Providing Key Management for a Mobile Authentication Architecture

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/867,808
Abstract

An apparatus for providing key management for a mobile authentication architecture may include a processor. The processor may be configured to provide a request for key revocation over an interface otherwise defined for sharing key acquisition information between a bootstrapping server function and a network application function, and cancel key information associated with the request for key revocation.

Claims (33)

1 . A method comprising:

providing a key revocation message over an interface otherwise defined for sharing key acquisition information between a bootstrapping server function and a network application function; and

canceling key information associated with the key revocation message.

2 . The method of claim 1 , wherein providing the key revocation message comprises communicating a key cancellation message from the bootstrapping server function in response to a user initiated request.

3 . The method of claim 2 , wherein providing the key revocation message comprises communicating the key cancellation message to at least one different network application function in response to an indication of a user request for cancellation of an identified key received from the network application function and cancellation of the key information at the bootstrapping server function.

4 . The method of claim 3 , further comprising determining the at least one different network application function to be a network application function having the identified key prior to communicating the key cancellation message.

5 . The method of claim 1 , wherein providing the key revocation message comprises communicating the key revocation message from the network application function in response to receipt of a user initiated request indicative of a key to be revoked, the network application function being associated with a service using the key to be revoked.

6 . The method of claim 1 , wherein providing the key revocation message comprises providing the key revocation message in response to an operator initiated request indicative of a key to be revoked.

7 . The method of claim 1 , wherein providing the key revocation message comprises communicating a key cancellation message in response to an indication of an account cancellation, the bootstrapping server function being associated with a home network of a user associated with the canceled account.

8 . The method of claim 1 , wherein providing the key revocation message comprises providing a request to revoke all keys associated with a shared secret generated pursuant to a generic bootstrapping architecture framework or providing a request to revoke an application specific key associated with the shared secret.

9 . The method of claim 1 , wherein providing the key revocation message comprises communicating a key cancellation message in response to receiving a request redirected from a service provider associated with a service from which a user communicating the request wishes to logout, in which the service is accessible through a single sign on procedure, and wherein canceling the key information provides a single sign on logout function by deleting keys associated with the user at both the bootstrapping server function and the network application function.

10 . A computer program product comprising at least one computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions comprising:

a first executable portion for providing a request for key revocation over an interface otherwise defined for sharing key acquisition information between a bootstrapping server function and a network application function; and

a second executable portion for canceling key information associated with the request for key revocation.

11 . The computer program product of claim 10 , wherein the first executable portion includes instructions for communicating a key cancellation message from the bootstrapping server function in response to a user initiated request.

12 . The computer program product of claim 11 , wherein the first executable portion includes instructions for communicating the key cancellation message to at least one different network application function in response to an indication of a user request for cancellation of an identified key received from the network application function and cancellation of the key information at the bootstrapping server function.

13 . The computer program product of claim 12 , further comprising a third executable portion for determining the at least one different network application function to be a network application function having the identified key prior to communicating the key cancellation message.

14 . The computer program product of claim 10 , wherein the first executable portion includes instructions for communicating the key revocation message from the network application function in response to receipt of a user initiated request indicative of a key to be revoked, the network application function being associated with a service using the key to be revoked.

15 . The computer program product of claim 10 , wherein the first executable portion includes instructions for providing the key revocation message in response to an operator initiated request indicative of a key to be revoked.

16 . An apparatus comprising a processor configured to:

provide a request for key revocation over an interface otherwise defined for sharing key acquisition information between a bootstrapping server function and a network application function; and

cancel key information associated with the request for key revocation.

17 . The apparatus of claim 16 , wherein the processor is configured to communicate a key cancellation message from the bootstrapping server function in response to a user initiated request.

18 . The apparatus of claim 17 , wherein the processor is further configured to communicate the key cancellation message to at least one different network application function in response to an indication of a user request for cancellation of an identified key received from the network application function and cancellation of the key information at the bootstrapping server function.

19 . The apparatus of claim 18 , wherein the processor is further configured to determine the at least one different network application function to be a network application function having the identified key prior to communicating the key cancellation message.

20 . The apparatus of claim 16 , wherein the processor is further configured to communicate the key revocation message from the network application function in response to receipt of a user initiated request indicative of a key to be revoked, the network application function being associated with a service using the key to be revoked.

21 . The apparatus of claim 16 , wherein the processor is further configured to provide the key revocation message in response to an operator initiated request indicative of a key to be revoked.

22 . The apparatus of claim 16 , wherein the processor is further configured to communicate a key cancellation message in response to an indication of an account cancellation, the bootstrapping server function being associated with a home network of a user associated with the canceled account.

23 . The apparatus of claim 16 , wherein the processor is further configured to provide a request to revoke all keys associated with a shared secret generated pursuant to a generic bootstrapping architecture framework or providing a request to revoke an application specific key associated with the shared secret.

24 . The apparatus of claim 16 , wherein the processor is further configured to communicate a key cancellation message in response to receiving a request redirected from a service provider associated with a service from which a user communicating the request wishes to logout, in which the service is accessible through a single sign on procedure, and wherein the processor is further configured to cancel the key information to provide a single sign on logout function by deleting keys associated with the user at both the bootstrapping server function and the network application function.

25 . A method comprising:

receiving a request for key revocation over an interface otherwise defined for sharing key acquisition information between a bootstrapping server function and a network application function; and

canceling key information associated with the request for key revocation.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2009
From: HOLTMANNS, SILKE; LAITINEN, PEKKA; TUOMINEN, HANNU
To: NOKIA SIEMENS NETWORKS OY
Reel/Frame 022759/0157 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2008
From: NOKIA CORPORATION
To: NOKIA SIEMENS NETWORKS OY
Reel/Frame 021797/0942 →