IP Library Granted Patent US 8,554,912
Granted Patent B1
US 8,554,912 · App. 13/047,047 · Granted Oct 8, 2013

Access management for wireless communication devices failing authentication for a communication network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,554,912
App. No.
13/047,047
Granted
Oct 8, 2013
Kind
B1
Abstract

When a failure notification is received that was transmitted from a service node indicating a failure of a wireless communication device to pass an authentication when attempting to register with a communication network, device information, network data, and a user profile associated with the wireless communication device is retrieved and processed to generate a network access score for the wireless communication device. If the network access score exceeds a priority threshold, a priority notification is transferred instructing the service node to bypass the authentication for the wireless communication device. If the network access score exceeds a legitimate user threshold but does not exceed the priority threshold, an access notification is transferred instructing the service node to bypass the authentication for the wireless communication device, and subsequent usage of the wireless communication device is monitored for fraudulent activity. If the network access score does not exceed the legitimate user threshold, a suspect notification is transferred instructing the service node to maintain the authentication for the wireless communication device.

Claims (36)

1. A method of operating a network access control system to manage access to a communication network, the method comprising:

receiving a failure notification transmitted from a service node indicating a failure of a wireless communication device to pass an authentication when attempting to register with the communication network, wherein the notification includes a device identifier that identifies the wireless communication device;

retrieving device information, network data, and a user profile associated with the wireless communication device based on the device identifier;

processing the device information, the network data, and the user profile to generate a network access score for the wireless communication device;

if the network access score exceeds a priority threshold, transferring a priority notification for delivery to the service node that instructs the service node to bypass the authentication for the wireless communication device;

if the network access score exceeds a legitimate user threshold but does not exceed the priority threshold, transferring an access notification for delivery to the service node that instructs the service node to bypass the authentication for the wireless communication device and monitoring subsequent usage of the wireless communication device for fraudulent activity; and

if the network access score does not exceed the legitimate user threshold, transferring a suspect notification for delivery to the service node that instructs the service node to maintain the authentication for the wireless communication device.

2. The method of claim 1 wherein processing the device information, the network data, and the user profile to generate the network access score for the wireless communication device comprises determining that the wireless communication device is associated with an emergency service provider to generate the network access score that exceeds the priority threshold.

3. The method of claim 1 wherein processing the device information, the network data, and the user profile to generate the network access score for the wireless communication device comprises processing a device type of the wireless communication device to generate the network access score.

4. The method of claim 1 wherein monitoring the subsequent usage of the wireless communication device for the fraudulent activity comprises comparing a service usage history of the wireless communication device to the subsequent usage of the wireless communication device to detect the fraudulent activity.

5. The method of claim 1 wherein, if the network access score exceeds the legitimate user threshold but does not exceed the priority threshold, imposing restrictions on the subsequent usage of the wireless communication device.

6. The method of claim 1 wherein processing the device information, the network data, and the user profile to generate the network access score for the wireless communication device comprises determining that the wireless communication device is associated with an exploitability to generate the network access score that does not exceed the legitimate user threshold.

7. The method of claim 1 wherein processing the device information, the network data, and the user profile to generate the network access score for the wireless communication device comprises determining that the wireless communication device is associated with a fraudulent service usage history to generate the network access score that does not exceed the legitimate user threshold.

8. The method of claim 1 wherein the network data comprises a failure type associated with the failure of the wireless communication device to register with the communication network, an identifier of the service node, a geographic location of the service node, and a time of the failure.

9. The method of claim 1 wherein the user profile comprises a service activation date, a service expiration date, a service type, a service plan, authorized devices, and a fraudulent service usage history associated with the user of the wireless communication device.

10. The method of claim 1 wherein the device information comprises a model and a firmware version of the wireless communication device.

11. A network access control system to manage access to a communication network, the system comprising:

a communication transceiver configured to receive a failure notification transmitted from a service node indicating a failure of a wireless communication device to pass an authentication when attempting to register with the communication network, wherein the notification includes a device identifier that identifies the wireless communication device; and

a processing system configured to retrieve device information, network data, and a user profile associated with the wireless communication device based on the device identifier, process the device information, the network data, and the user profile to generate a network access score for the wireless communication device, and if the network access score exceeds a priority threshold, direct the communication transceiver to transfer a priority notification for delivery to the service node that instructs the service node to bypass the authentication for the wireless communication device;

the processing system configured to, if the network access score exceeds a legitimate user threshold but does not exceed the priority threshold, direct the communication transceiver to transfer an access notification for delivery to the service node that instructs the service node to bypass the authentication for the wireless communication device, and the processing system further configured to monitor subsequent usage of the wireless communication device for fraudulent activity; and

the processing system configured to, if the network access score does not exceed the legitimate user threshold, direct the communication transceiver to transfer a suspect notification for delivery to the service node that instructs the service node to maintain the authentication for the wireless communication device.

12. The system of claim 11 wherein the processing system configured to process the device information, the network data, and the user profile to generate the network access score for the wireless communication device comprises the processing system configured to determine that the wireless communication device is associated with an emergency service provider to generate the network access score that exceeds the priority threshold.

13. The system of claim 11 wherein the processing system configured to process the device information, the network data, and the user profile to generate the network access score for the wireless communication device comprises the processing system configured to process a device type of the wireless communication device to generate the network access score.

14. The system of claim 11 wherein the processing system configured to monitor the subsequent usage of the wireless communication device for the fraudulent activity comprises the processing system configured to compare a service usage history of the wireless communication device to the subsequent usage of the wireless communication device to detect the fraudulent activity.

15. The system of claim 11 wherein the processing system is configured to, if the network access score exceeds the legitimate user threshold but does not exceed the priority threshold, impose restrictions on the subsequent usage of the wireless communication device.

16. The system of claim 11 wherein the processing system configured to process the device information, the network data, and the user profile to generate the network access score for the wireless communication device comprises the processing system configured to determine that the wireless communication device is associated with an exploitability to generate the network access score that does not exceed the legitimate user threshold.

17. The system of claim 11 wherein the processing system configured to process the device information, the network data, and the user profile to generate the network access score for the wireless communication device comprises the processing system configured to determine that the wireless communication device is associated with a fraudulent service usage history to generate the network access score that does not exceed the legitimate user threshold.

18. The system of claim 11 wherein the network data comprises a failure type associated with the failure of the wireless communication device to register with the communication network, an identifier of the service node, a geographic location of the service node, and a time of the failure.

19. The system of claim 11 wherein the user profile comprises a service activation date, a service expiration date, a service type, a service plan, authorized devices, and a fraudulent service usage history associated with the user of the wireless communication device.

20. A method of operating a network access control system to manage access to a communication network, the method comprising:

receiving a failure notification transmitted from a service node indicating a failure of a wireless communication device to pass an authentication when attempting to register with the communication network, wherein the notification includes a device identifier that identifies the wireless communication device;

retrieving device information, network data, and a user profile associated with the wireless communication device based on the device identifier;

processing the device information, the network data, and the user profile to generate a network access score for the wireless communication device;

if the network access score exceeds a priority threshold, transferring a priority notification for delivery to the service node that instructs the service node to bypass the authentication for the wireless communication device;

if the network access score exceeds a legitimate user threshold but does not exceed the priority threshold, transferring an access notification for delivery to the service node that instructs the service node to bypass the authentication for the wireless communication device, imposing restrictions on subsequent usage of the wireless communication device, and monitoring the subsequent usage of the wireless communication device for fraudulent activity by comparing a service usage history of the wireless communication device to the subsequent usage of the wireless communication device to detect the fraudulent activity; and

if the network access score does not exceed the legitimate user threshold, transferring a suspect notification for delivery to the service node that instructs the service node to maintain the authentication for the wireless communication device.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 055604/0001 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2011
From: REEVES, RAYMOND EMILIO; YOUNGS, SIMON; PEDEN, MARK DOUGLAS; KOLLER, GARY DUANE; JETHWA, PIYUSH
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 025947/0052 →