IP Library Granted Patent US 8,424,070
Granted Patent B1
US 8,424,070 · App. 12/613,185 · Granted Apr 16, 2013

Dynamic network-centric generation of public service access identification

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,424,070
App. No.
12/613,185
Granted
Apr 16, 2013
Kind
B1
Abstract

Systems and media are provided for authenticating a mobile device using credentials supplied by a network rather than using a credential configured in the mobile device. As the mobile device requests access to the Internet, an AUD request is sent to an AUD service based on the generic credential in the mobile device. The AUD service generates a user-specific credential for the mobile that enables authentication by an authentication server and subsequent registration at a registration server.

Claims (37)

1. A system for authenticating a mobile device with a re-assignable generic credential in the mobile device, comprising:

a network access server configured to receive the re-assignable generic credential from the mobile device when the mobile device requests data services, and recognize the re-assignable generic credential as an authentication user delegate request based on a format of the re-assignable generic credential, wherein the re-assignable generic credential is not configured to authenticate the mobile device;

an authentication server configured to receive the re-assignable generic credential from the network access server, receive information that the re-assignable generic credential is the authentication user delegate request, verify that the re-assignable generic credential is valid, and contact an authentication user delegate server through a relay responsive to the re assignable generic credential being the authentication user delegate request; and

the authentication user delegate server configured to receive the re-assignable generic credential select a unique user credential for the mobile device, and instruct the authentication server to use the unique user credential to authenticate the mobile device,

wherein the authentication server instructs the network access server to use the unique user credential for the mobile device in place of the re-assignable generic credential, and wherein the network access server registers the mobile device at a registration server using the unique user credential.

2. The system of claim 1 , wherein the network access server cannot register the mobile device with the re-assignable generic credential.

3. The system of claim 2 , wherein the re-assignable generic credential is provided to the mobile device when the mobile device participates in an authentication user delegate service.

4. The system of claim 3 , wherein the authentication user delegate request comprises an identifier that indicates an authentication of the mobile device is accomplished using credentials provided by a network service rather than using credentials in the mobile device.

5. The system of claim 4 , wherein the unique user credential comprises a username and password for the mobile device.

6. The system of claim 4 , wherein the unique user credential is generated at the authentication user delegate server based on at least one of a set of rules, contextual information about the mobile device, user settings in the mobile device, a time, and a geographic location of the mobile device.

7. The system of claim 6 , wherein the unique user credential is assigned and shared among multiple mobile devices.

8. One or more non-transitory computer-readable media having computer useable instructions embodied thereon for causing one or more servers to authenticate a mobile device, comprising:

receiving a credential at an authentication server transferred by the mobile device wherein the mobile device requests access to data services;

determining if the credential comprises an authentication user delegate request based on a format of the credential;

if the credential does not comprise the authentication user delegate request, authenticating the mobile device at the authentication server and sending an acknowledgement that the mobile device is authenticated; and

if the credential comprises the authentication user delegate request and the credential comprises a re-assignable generic credential that is not configured to authenticate the mobile device:

verifying that the credential is valid, contacting an authentication user delegate server through a relay of a plurality of relays wherein the relay is selected based on the format of the credential and wherein the plurality of relays are respectively connected to a plurality of authentication user delegate servers,

receiving the credential at the authentication user delegate server,

selecting a unique user credential for the mobile device,

instructing the authentication server to use the unique user credential in place of the credential to authenticate the mobile device, and

sending the acknowledgement that the mobile device is authenticated.

9. The media of claim 8 , wherein the network access server cannot register the mobile device with the credential when the credential comprises the authentication user delegate request.

10. The media of claim 9 , wherein the authentication user delegate request comprises an identifier that indicates an authentication of the mobile device is accomplished using credentials provided by a network service rather than using credentials in the mobile device.

11. The media of claim 10 , wherein the unique user credential comprises a username and password for the mobile device.

12. The media of claim 10 , wherein the unique user credential is generated at the authentication user delegate server based on at least one of a set of rules, contextual information about the mobile device, user settings in the mobile device, a time, and a geographic location of the mobile device.

13. The media of claim 12 , wherein the unique user credential is assigned and shared among multiple mobile devices.

14. The media of claim 13 , further comprising registering the mobile device at a registration server using the unique user credential.

15. A system for causing one or more servers to authenticate a mobile device, comprising:

an authentication server configured to receive a credential transferred by the mobile device and determines if the credential comprises an authentication user delegate request based on a format of the credential, wherein the mobile device requests access to data services;

if the credential does not comprise the authentication user delegate request, the authentication server is configured to authenticate the mobile device at the authentication server and send an acknowledgement that the mobile device is authenticated; and

if the credential comprises the authentication user delegate request and the credential comprises a re-assignable generic credential that is not configured to authenticate the mobile device, the authentication server is configured to verify that the credential is valid and contact an authentication user delegate server through a relay of a plurality of relays wherein the relay is selected based on the format of the credential and wherein the plurality of relays are respectively connected to a plurality of authentication user delegate servers, and send the acknowledgement that the mobile device is authenticated after receiving instructions from the authentication user delegate server;

the authentication user delegate server configured to receive the credential, selects a unique user credential for the mobile device, and instruct the authentication server to use the unique user credential to authenticate the mobile device.

16. The system of claim 15 , wherein the network access server cannot register the mobile device with the credential when the credential comprises the authentication user delegate request.

17. The system of claim 16 , wherein the authentication user delegate request comprises an identifier that indicates an authentication of the mobile device is accomplished using credentials provided by a network service rather than using credentials in the mobile device.

18. The system of claim 17 , wherein the unique user credential is generated at the authentication user delegate server based on at least one of a set of rules, contextual information about the mobile device, user settings in the mobile device, a time, and a geographic location of the mobile device.

19. The system of claim 18 , wherein the unique user credential is assigned and shared among multiple mobile devices.

20. The system of claim 19 , further comprising a registration server that registers the mobile device using the unique user credential.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 055604/0001 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2009
From: REEVES, RAYMOND EMILIO; KARKI, PRABHAT; LAMSAL, SAILESH; WICK, RYAN ALAN
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 023477/0562 →