IP Library Granted Patent US 9,537,663
Granted Patent B2
US 9,537,663 · App. 13/528,802 · Granted Jan 3, 2017

Manipulation and restoration of authentication challenge parameters in network authentication procedures

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,537,663
App. No.
13/528,802
Granted
Jan 3, 2017
Kind
B2
Abstract

A challenge manipulation and restoration capability is provided for use during network authentication. A mobile device (MD) and a subscriber server (SS) each have provisioned therein a binding key (B-KEY) that is associated with a subscriber identity of a network authentication module (NAM) of the MD. The SS obtains an authentication vector (AV) in response to a request from a Radio Access Network (RAN) when the MD attempts to attach to the RAN. The AV includes an original authentication challenge parameter (ACP). The SS encrypts the original ACP based on its B-KEY, and updates the AV by replacing the original ACP with the encrypted ACP. The MD receives the encrypted ACP, and decrypts the encrypted ACP based on its B-KEY to recover the original ACP. The MD provides the original ACP to the NAM for use in computing an authentication response for validation by the RAN.

Claims (37)

1. An apparatus, comprising:

a processor and a memory communicatively connected to the processor, the processor configured to:

receive an equipment identity of a mobile device and a subscriber identity associated with a network authentication module of the mobile device;

determine, based on the subscriber identity associated with the network authentication module of the mobile device and the equipment identity of the mobile device, whether the network authentication module of the mobile device is authorized to be used with the mobile device;

obtain an authentication vector (AV) for the mobile device, the AV including an original authentication challenge parameter;

obtain, based on the equipment identity of the mobile device, a binding key associated with the network authentication module of the mobile device;

encrypt the original authentication challenge parameter of the AV, based on the binding key, to form an encrypted authentication challenge parameter;

replace the original authentication challenge parameter of the AV with the encrypted authentication challenge parameter;

propagate the AV including the encrypted authentication challenge parameter toward a wireless access network supporting the mobile device;

receive, from the wireless access network, a synchronization failure message including an authentication token and the encrypted authentication challenge parameter;

decrypt the encrypted authentication challenge parameter of the synchronization failure message, based on the binding key, to recover the original authentication challenge parameter; and

regenerate the AV for the mobile device based on the original authentication challenge parameter recovered from the synchronization failure message.

2. The apparatus of claim 1 , wherein the processor is configured to:

in response to an AV request being received from the wireless access network:

retrieve the AV including the encrypted authentication challenge parameter; and

propagate the AV including the encrypted authentication challenge parameter toward the wireless access network.

3. The apparatus of claim 1 , wherein, to obtain the AV including the original authentication challenge parameter, the processor is configured to:

generate the AV including the original authentication challenge parameter; or

retrieve the AV including the original authentication challenge parameter.

4. The apparatus of claim 1 , wherein the processor is configured to:

propagate the AV including the encrypted authentication challenge parameter toward the wireless access network.

5. The apparatus of claim 1 , wherein the equipment identity of the mobile device comprises an International Mobile Equipment Identity (IMEI) or a Mobile Equipment Identifier (MEID).

6. The apparatus of claim 1 , wherein the binding key comprises one of a pre-provisioned random number or string, a string provisioned during a bootstrapping procedure, an output of a hash function, or a string or number.

7. The apparatus of claim 1 , wherein the processor is configured to:

receive, from the wireless access network, the encrypted authentication challenge parameter; and

decrypt the encrypted authentication challenge parameter based on the binding key.

8. A method, comprising:

receiving, via a processor, an equipment identity of a mobile device and a subscriber identity associated with a network authentication module of the mobile device;

determining, based on the subscriber identity associated with the network authentication module of the mobile device and the equipment identity of the mobile device, whether the network authentication module of the mobile device is authorized to be used with the mobile device;

obtaining an authentication vector (AV) for the mobile device, the AV including an original authentication challenge parameter;

obtaining, based on the equipment identity of the mobile device, a binding key associated with the network authentication module of the mobile device;

encrypting the original authentication challenge parameter of the AV, based on the binding key, to form an encrypted authentication challenge parameter;

replacing the original authentication challenge parameter of the AV with the encrypted authentication challenge parameter;

propagating the AV including the encrypted authentication challenge parameter toward a wireless access network supporting the mobile device;

receiving, from the wireless access network, a synchronization failure message including an authentication token and the encrypted authentication challenge parameter;

decrypting the encrypted authentication challenge parameter of the synchronization failure message, based on the binding key, to recover the original authentication challenge parameter; and

regenerating the AV for the mobile device based on the original authentication challenge parameter recovered from the synchronization failure message.

Assignments (14)
PATENT SECURITY AGREEMENT Recorded Aug 6, 2024
From: RPX CORPORATION; RPX CLEARINGHOUSE LLC
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 068328/0674 →
RELEASE OF LIEN ON PATENTS Recorded Aug 5, 2024
From: BARINGS FINANCE LLC
To: RPX CORPORATION
Reel/Frame 068328/0278 →
PATENT SECURITY AGREEMENT Recorded Apr 22, 2023
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 063429/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 9, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA INC.
Reel/Frame 033949/0016 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2013
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 031029/0788 →
SECURITY INTEREST Recorded Mar 7, 2013
From: ALCATEL-LUCENT USA INC.
To: CREDIT SUISSE AG
Reel/Frame 030510/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2012
From: MIZIKOVSKY, SEMYON; BROUSTIS, IOANNIS; CAKULEV, VIOLETA
To: ALCATEL-LUCENT USA INC.
Reel/Frame 028578/0717 →