IP Library Granted Patent US 9,178,878
Granted Patent B2
US 9,178,878 · App. 13/699,066 · Granted Nov 3, 2015

Method for dynamically authorizing a mobile communications device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,178,878
App. No.
13/699,066
Granted
Nov 3, 2015
Kind
B2
Abstract

Physically access-protected service access, such as a service flap having a mechanical lock, for example, are used to ensure the secure establishment of security check information. Logical access security to service functions is produced using the security check information via additional, decentralized service interfaces. For this purpose, it is not the mobile service device that is connected to the physically access-protected communications interface, but rather a second authentication module associated with the mobile service device. Security check information is provided by the authentication module for secure service access to the network via additional, decentralized communications interfaces of the network.

Claims (33)

1. A method for dynamic authorization of a mobile communications device for a network, which comprises the steps of:

connecting an authentication module associated with the mobile communications device to the network via a physically access-protected communications interface, the authentication module being physically separate from the mobile communications device and being physically separate from the network, the authentication module being connected to the network when the mobile communications device needs access to the network;

transferring, via the mobile communications device, an access request to the network via a further wireless or wired communications interface;

providing an authentication check unit of the network with security check information of the mobile communications device directly from the authentication module, the authentication check unit authorizing the mobile communications device for the network with an aid of the access request and the security check information; and

physically disconnecting the authentication module from the network after access is granted to the mobile communication device.

2. The method according to claim 1 , wherein the security check information is configuration data for setting up a secure network connection of the mobile communications device.

3. The method according to claim 2 , wherein the configuration data includes at least one of identification information of the mobile communications device, symmetrical key information or asymmetrical key information for setting up the secure network connection.

4. The method according to claim 1 , wherein the security check information is an authentication functionality for setting up a secure network connection of the mobile communications device, the method further comprises:

transferring a check command by the authentication check unit to the authentication module;

determining a check response by the authentication module with an aid of the check command;

transferring the check response to the authentication check unit by the authentication module; and

analyzing the check response via the authentication check unit.

5. A system for dynamic authorization of a mobile communications device for a network by an authentication check unit of the network, the system comprising:

an authentication module associated with the mobile communications device, said authentication module having a processor and a memory electrically connected to said memory;

a physically access-protected communications interface for connecting said authentication module to the network, said physically access-protected communications interface enclosed in said lockable mechanical closure apparatus thus providing restricted public access;

further wireless or wired communications interfaces for connecting the mobile communications device to the network; and

said authentication module having means, which includes said processor and said memory, for providing security check information of the mobile communications device, with an aid of which the mobile communications device is authorized by the authentication check unit of the network, the authentication check unit of the network receiving the security check information directly from the authentication module, said authentication module being physically separate from the mobile communications device and being physically separate from the network, said authentication module being connected to the network when said mobile communications device needs access to the network and being physically disconnectable from the network after access is granted.

6. The system according to claim 5 , wherein the security check information is configuration data for setting up a secure network connection of the mobile communications device.

7. The system according to claim 6 , wherein the configuration data includes at least one of identification information of the mobile communications device, symmetrical key information or asymmetrical key information for setting up a secure network connection.

8. The system according to claim 5 , wherein the security check information is an authentication functionality for setting up a secure network connection of the mobile communications device, and said authentication module and the authentication check unit are embodied such that:

a check command can be transferred to said authentication module by the authentication check unit;

a check response can be determined by said authentication module with an aid of the check command and the check response can be transferred to the authentication check unit by said authentication module; and

the check response can be checked by the authentication check unit.

9. An authentication module providing a dynamic authorization of a mobile communications device for a network, the authentication module stored in non-transitory formed and being programmed to, when loaded into a memory of a non-transitory computer to:

connect the authentication module associated with the mobile communications device to the network via a physically access-protected communications interface, the authentication module being physically separate from the mobile communications device and being physically separate from the network, the authentication module being connected to the network when the mobile communications device needs access to the network;

transfer, via the mobile communications device, an access request to the network via a further wireless or wired communications interface;

provide an authentication check unit of the network with security check information of the mobile communications device directly from the authentication module, the authentication check unit authorizing the mobile communications device for the network with an aid of the access request and the security check information; and

physically disconnect the authentication module from the network after the mobile communication device is authorized to access the network.

10. A method for dynamic authorization of a mobile communications device for a network, which comprises the steps of:

connecting an authentication module associated with the mobile communications device to the network via a physically access-protected communications interface protected and enclosed in a lockable mechanical closure apparatus thus providing restricted public access, the authentication module being physically separate from the mobile communications device and being physically separate from the network, the authentication module being connected to the network when the mobile communications device needs access to the network;

transferring, via the mobile communications device, an access request to the network via a further wireless or wired communications interface;

providing an authentication check unit of the network with security check information of the mobile communications device directly from the authentication module, the authentication check unit authorizing the mobile communications device for the network with an aid of the access request and the security check information; and

physically disconnecting the authentication module from the network after the mobile communication device is authorized to access the network.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2019
From: SIEMENS AKTIENGESELLSCHAFT
To: SIEMENS MOBILITY GMBH
Reel/Frame 048079/0310 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2012
From: FALK, RAINER
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 029401/0140 →