IP Library Granted Patent US 8,438,391
Granted Patent B2
US 8,438,391 · App. 13/209,519 · Granted May 7, 2013

Credential generation management servers and method for communications devices and device management servers

Inventors: Vasilios Daskalopoulos (Edison, NJ); Badri Nath (Edison, NJ); Rakesh Kushwaha (Marlboro, NJ)
Assignee: Mformation Software Technologies, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,438,391
App. No.
13/209,519
Granted
May 7, 2013
Kind
B2
Abstract

Systems and methods are described for establishing credentials at a device and at a device management server for the purpose of exchanging secure credentials in order to mutually authenticate the device and the server. A credential generation algorithm is described which uses a plurality of seeds, including the hardware identity of the device, the server identity, and a shared private key, to generate two sets of credentials, one to be used by the device and the other to be used by the device management server. The credentials are exchanged between the device and the server during any session, thereby assuring mutual authentication.

Claims (62)

1. A method of mutually authenticating a communications device and a server, the method comprising:

generating with the communications device a first credential;

generating with the server a second credential;

providing a third credential from the communications device to the server;

providing a fourth credential from the server to the communications device;

authenticating the communications device to the server when the third credential matches the second credential; and

authenticating the server to the communications device when the fourth credential matches the first credential,

wherein the communications device and the server use the same function to generate the first and second credentials, the function using a unique identifier of the communications device including at least one of an electronic serial number (ESN), mobile equipment identifier (MEID), international mobile equipment identity (IMEI), and a media access control (MAC) address of the communications device.

2. The method of claim 1 , wherein at least one of the credentials includes a password.

3. The method of claim 1 , wherein at least one of the credentials includes a digest of a plurality of parameters.

4. The method of claim 3 , wherein the plurality of parameters includes a username, a password, and a nonce.

5. The method of claim 1 , wherein the credentials are unique to the communications device.

6. The method of claim 1 , wherein the credentials are unique to the server.

7. The method of claim 1 , wherein the credentials are unique to a service provider.

8. The method of claim 1 comprising:

providing the unique identifier of the communications device from the communications device to the server; and

providing a unique identifier of the server from the server to the communications device;

wherein the first credential is generated by the communications device as a function of the unique identifiers of the communications device and the server, and the second credential is generated by the server as a function of the unique identifiers of the communications device and the server.

9. A method of mutually authenticating a communications device and a server, the method comprising:

generating with the communications device a first credential;

generating with the server a second credential;

providing a third credential from the communications device to the server;

providing a fourth credential from the server to the communications device;

authenticating the communications device to the server when the third credential matches the second credential; and

authenticating the server to the communications device when the fourth credential matches the first credential,

wherein the communications device and the server use the same function to generate the first and second credentials, the function including a one-way hash function which uses at least two parameters, the first and third credentials being generated with the at least two parameters arranged in a first order, and the second and fourth credentials being generated with the at least two parameters arranged in a second order.

10. The method of claim 9 , wherein the one-way hash function which uses at least three parameters including a private key.

11. The method of claim 10 , wherein the private key is unique to a service provider.

12. The method of claim 9 , wherein the credentials are unique to the communications device.

13. The method of claim 9 , wherein the credentials are unique to the server.

14. The method of claim 9 , wherein the credentials are unique to a service provider.

15. The method of claim 9 , wherein the function uses a unique identifier of the communications device.

16. The method of claim 9 , wherein at least one of the credentials includes a password.

17. The method of claim 9 , wherein at least one of the credentials includes a digest of a plurality of parameters.

18. The method of claim 17 , wherein the plurality of parameters includes a username, a password, and a nonce.

19. The method of claim 9 comprising:

providing a first of the at least two parameters from the communications device to the server; and

providing a second of the at least two parameters from the server to the communications device;

wherein the first credential is generated by the communications device as a function of the first and second parameters, and the second credential is generated by the server as a function of the first and second parameters.

20. The method of claim 19 , wherein the first parameter includes a unique identifier of the communications device and the second parameter includes a unique identifier of the server.

21. A method of mutually authenticating a communications device and a server, the method comprising:

generating with the communications device a first credential;

generating with the server a second credential;

providing a third credential from the communications device to the server;

providing a fourth credential from the server to the communications device;

authenticating the communications device to the server when the third credential matches the second credential;

authenticating the server to the communications device when the fourth credential matches the first credential; and

conducting a remote management session after the communications device and device management server are mutually authenticated.

22. The method of claim 21 , wherein the device management server operates in accordance with at least one standard including an Open Mobile Alliance Device management standard, a TR-69 standard, and a DOCSIS standard.

23. The method of claim 21 , wherein the credentials are generated using the same function.

24. The method of claim 23 , wherein the function uses a unique identifier of the communications device.

25. The method of claim 21 , wherein the credentials are unique to the communications device.

26. The method of claim 21 , wherein the credentials are unique to the server.

27. The method of claim 21 , wherein the credentials are unique to a service provider.

28. The method of claim 21 , wherein at least one of the credentials includes a password.

29. The method of claim 21 , wherein at least one of the credentials includes a digest of a plurality of parameters.

30. The method of claim 29 , wherein the plurality of parameters includes a username, a password, and a nonce.

31. The method of claim 21 comprising:

providing a first parameter from the communications device to the server; and

providing a second parameter from the server to the communications device;

wherein the first credential is generated by the communications device as a function of the first and second parameters, and the second credential is generated by the server as a function of the first and second parameters.

32. The method of claim 31 , wherein the first parameter includes a unique identifier of the communications device and the second parameter includes a unique identifier of the server.

Assignments (5)
CHANGE OF NAME Recorded Mar 13, 2019
From: ALCATEL-LUCENT USA INC.
To: NOKIA OF AMERICA CORPORATION
Reel/Frame 048581/0530 →
MERGER Recorded May 25, 2016
From: MFORMATION SOFTWARE TECHNOLOGIES LLC
To: ALCATEL-LUCENT USA INC.
Reel/Frame 038715/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2014
From: MFORMATION TECHNOLOGIES INC.
To: MFORMATION SOFTWARE TECHNOLOGIES INC.
Reel/Frame 033005/0564 →
CHANGE OF NAME Recorded Jun 2, 2014
From: MFORMATION SOFTWARE TECHNOLOGIES, INC.
To: MFORMATION SOFTWARE TECHNOLOGIES LLC
Reel/Frame 033072/0760 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2014
From: DASKALOPOULOS, VASILIOS; NATH, BADRI; KUSHWAHA, RAKESH
To: MFORMATION TECHNOLOGIES INC.
Reel/Frame 032443/0508 →
Continuity (2)
Continuation 12055752 · Mar 26, 2008
Related Publication 20120096267A1 · Apr 19, 2012