IP Library Granted Patent US 9,154,527
Granted Patent B2
US 9,154,527 · App. 13/412,141 · Granted Oct 6, 2015

Security key creation

Inventors: Kwai Yeung Lee (Pittsburg, CA); William C. King (Lafayette, CA); Priscilla Lau (Fremont, CA)
Assignee: Verizon Patent and Licensing Inc.
H04L65/1016H04L63/061H04L65/1073H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,154,527
App. No.
13/412,141
Granted
Oct 6, 2015
Kind
B2
Abstract

A device may obtain calling security parameters, may communicate the calling security parameters to a network device, and may receive, from the network device, a calling parameters identifier associated with the calling security parameters. The device may communicate the calling parameters identifier to a called device, may receive a called parameters identifier from the called device, and may communicate the called parameters identifier to the network device. The device may receive called security parameters from the network device, may create a security key based on the calling security parameters and the called security parameters, and may communicate with the called device using the security key.

Claims (100)

1. A method, comprising:

authenticating, by a calling device, with a network;

obtaining, by the calling device and based on the authenticating, calling security parameters;

communicating, by the calling device, the calling security parameters to a network device;

communicating, by the calling device, an identifier, corresponding to a called device, to the network device to enable the network device to associate the calling security parameters with an identifier corresponding to the calling device;

receiving, by the calling device and from the network device, a calling parameters identifier associated with the calling security parameters;

communicating, by the calling device, the calling parameters identifier to the called device;

receiving, by the calling device, a called parameters identifier from the called device in response to communicating the calling parameters identifier to the called device;

communicating, by the calling device, the called parameters identifier to the network device; receiving, by the calling device and from the network device, called security parameters in response to communicating the called parameters identifier to the network device;

creating, by the calling device, a security key based on the calling security parameters and the called security parameters; and

communicating, by the calling device, with the called device using the security key.

2. The method of claim 1 , where communicating with the called device using the security key, comprises:

establishing a communication session with the called device,

encrypting communications sent to the called device, and

decrypting communications received from the called device.

3. The method of claim 1 , where communicating the calling parameters identifier to the called device comprises:

providing the calling parameters identifier in a session invitation message; and

communicating the session invitation message to the called device.

4. The method of claim 3 , where receiving the called parameters identifier from the called device comprises:

receiving a response, that includes the called parameters identifier, to the session invitation message from the called device.

5. The method of claim 1 , where:

the calling security parameters comprise at least one of:

a security parameter generated locally by the calling device;

a security parameter received from a network authentication function and associated with the calling device; or

a security parameter received from a bootstrapping authentication function and associated with the calling device.

6. The method of claim 1 , wherein the called security parameter comprises at least one of:

a security parameter generated locally by the called device;

a security parameter received from a network authentication function and associated with the called device; or

a security parameter received from a bootstrapping authentication function and associated with the called device.

7. The method of claim 1 , further comprising:

authenticating with the network, via a bootstrapping function, prior to obtaining the calling security parameters; and

authenticating with the network device, via a network application function, prior to communicating the calling security parameters to the network device.

8. A called device, comprising:

a processor to:

receive a calling parameters identifier from a calling device,

authenticate with a network;

obtain, based on the authenticating, called security parameters,

provide the called security parameters to a network device in response to receiving the calling parameters identifier,

communicate an identifier, corresponding to the called device, to the network device to enable the network device to associate the called security parameters with an identifier corresponding to the calling device,

receive a called parameters identifier in response to communicating the called security parameters to the network device,

provide the called parameters identifier to the calling device,

provide the calling parameters identifier to the network device,

receive calling security parameters from the network device in response to communicating the calling parameters identifier to the network device, and

produce a security key based on the called security parameters and the calling security parameters.

9. The called device of claim 8 , where the processor is further to:

communicate with the calling device by:

decrypting, with the security key, information received from the calling device, and

encrypting, with the security key, information sent to the calling device.

10. The called device of claim 8 , where the processor is further to:

receive the calling parameters via a session invitation message received from the calling device.

11. The called device of claim 10 , where the processor is further to:

provide the called parameters identifier to the calling device by including the called parameters identifier in a response to the session invitation message received from the calling device.

12. The called device of claim 8 , where:

the calling security parameters comprise at least one of:

a security parameter generated locally by the calling device;

a security parameter received from a network authentication function and associated with the calling device; or

a security parameter received from a bootstrapping authentication function and associated with the calling device.

13. The called device of claim 8 , where:

the called security parameter comprises at least one of:

a security parameter generated locally by the called device;

a security parameter received from a network authentication function and associated with the called device; or

a security parameter received from a bootstrapping authentication function and associated with the called device.

14. The called device of claim 8 , where the processor is further to:

authenticate with network, via a bootstrapping function, prior to obtaining the called security parameters; and

authenticate with the network device, via a network application function, prior to communicating the called security parameters to the network device.

15. One or more non-transitory computer-readable storage media, comprising:

one or more instructions that, when executed by a processor of a network device, cause the processor to:

receive calling security parameters from a calling device,

receive an identifier, corresponding to a called device, from the calling device,

associate the identifier with the calling security parameters,

authenticate the called device, based on the identifier,

associate the calling security parameters with a calling parameters identifier,

communicate the calling parameters identifier to the calling device in response to receiving the calling security parameters from the calling device,

receive the calling parameters identifier from the called device,

identify the calling security parameters associated with the calling parameters identifier,

communicate the calling security parameters to the called device in response to receiving the calling parameters identifier,

receive called security parameters from the called device,

associate the called security parameters with a called parameters identifier,

communicate the called parameters identifier to the called device in response to receiving the called security parameters from the called device,

receive the called parameters identifier from the calling device,

identify the called security parameters based on the called parameters identifier, and

communicate the called security parameters to the calling device in response to receiving the called parameters from the calling device,

the calling security parameters and the called security parameters being used to create security keys.

16. The computer-readable storage media of claim 15 , further comprising:

one or more instructions that, when executed by the processor of the network device, cause the processor to:

authenticate the calling device with respect to a communication service corresponding to the network device prior to associating the calling security parameters with the calling parameters identifier.

17. The computer-readable storage media of claim 15 , further comprising:

one or more instructions that, when executed by the processor of the network device, cause the processor to:

authenticate the called device with respect to a communication service corresponding to the network device prior to associating the called security parameters with a called parameters identifier.

18. The computer-readable storage media of claim 15 , wherein the calling security parameters comprise at least one of:

a security parameter generated locally by the calling device;

a security parameter received from a network authentication function and associated with the calling device; or

a security parameter received from a bootstrapping authentication function and associated with the calling device.

19. The computer-readable storage media of claim 15 , wherein the called security parameter comprises at least one of:

a security parameter generated locally by the called device;

a security parameter received from a network authentication function and associated with the called device; or

a security parameter received from a bootstrapping authentication function and associated with the called device.

20. The computer-readable storage media of claim 15 , further comprising:

one or more instructions that, when executed by the processor of the network device, cause the processor to:

store the called security parameters after receiving the called security parameters from the called device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2012
From: LEE, KWAI YEUNG; KING, WILLIAM C.; LAU, PRISCILLA
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 027806/0779 →
Continuity (2)
Continuation In Part 13174644 · Jun 30, 2011
Related Publication 20130003950A1 · Jan 3, 2013