IP Library Granted Patent US 9,288,670
Granted Patent B2
US 9,288,670 · App. 13/866,390 · Granted Mar 15, 2016

Dynamic distribution of authentication sessions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,288,670
App. No.
13/866,390
Granted
Mar 15, 2016
Kind
B2
Abstract

This disclosure relates to authenticating and providing transport security over unsecured IP networks to network subscribers. The system includes an authentication service that authenticates network subscribers. The authentication service can dynamically define expiry times for network authentication.

Claims (31)

1. A computer-implemented method for management of authentication sessions, the computer-implemented method comprising:

receiving an authentication request for an authentication session, wherein an authentication service receives the authentication request from a telecommunication device associated with a subscriber;

analyzing a distribution of subscriber expiry times over a time frame wherein the time frame can be characterized into a plurality of time periods;

determining an expiry time for the authentication session based, at least in part, on the distribution of subscriber expiry times over the time frame, wherein the expiry time is one of the plurality of time periods;

generating an authentication token with the determined expiry time; and

sending the authentication token to a telecommunication device responsive to the authentication request.

2. The computer-implemented method of claim 1 further comprising:

analyzing historical data related to the distribution of subscriber expiry times; and

determining the expiry time based, at least in part, the historical data in addition to the distribution of subscriber expiry times.

3. The computer-implemented method of claim 2 , wherein the historical data is associated with the subscriber.

4. The computer-implemented method of claim 1 , wherein the authentication service comprises a bootstrapping server function.

5. The computer-implemented method of claim 1 , wherein the defined time frame is twenty-four hours.

6. The computer-implemented method of claim 1 , wherein the defined time frame is eight hours.

7. The computer-implemented method of claim 1 , wherein the determined expiry time is greater than twenty-four hours after generating the authentication token.

8. The computer-implemented method of claim 1 , wherein the determined expiry time is less than twenty-four hours after generating the authentication token.

9. The computer-implemented method of claim 1 , wherein each of the plurality of time periods are equal.

10. The computer-implemented method of claim 1 , wherein each of the plurality of time periods is one hour.

11. The computer-implemented method of claim 1 , wherein the determined expiry time is the time period with the least number of subscriber expiry times.

12. The computer-implemented method of claim 1 , wherein the determined expiry time is based, at least in part, on an algorithm.

13. A telecommunication system, the system comprising:

an authentication server configured to:

communicate with a telecommunication device;

receive an authentication request for an authentication session;

analyze a distribution of subscriber expiry times over a time frame;

determine an expiry time for the authentication session based, at least in part, on the distribution of subscriber expiry times over the time frame;

generate an authentication token comprising the expiry time; and

send the authentication token to a telecommunication device responsive to the authentication request.

14. The system of claim 13 , wherein the authentication service is configured to communicate with the telecommunication device over a bootstrapping interface.

15. The system of claim 13 , wherein the authentication service comprises a bootstrapping service function.

16. The system of claim 13 , wherein the authentication service is a network application function.

17. The system of claim 13 , further comprising an application gateway configured to communicate with the authentication service.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
RELEASE OF SECURITY INTEREST Recorded Apr 1, 2020
From: DEUTSCHE TELEKOM AG
To: T-MOBILE USA, INC.; IBSV LLC
Reel/Frame 052969/0381 →
RELEASE OF SECURITY INTEREST Recorded Apr 1, 2020
From: DEUTSCHE BANK AG NEW YORK BRANCH
To: T-MOBILE USA, INC.; IBSV LLC; METROPCS COMMUNICATIONS, INC.; METROPCS WIRELESS, INC.; T-MOBILE SUBSIDIARY IV CORPORATION; LAYER3 TV, INC.; PUSHSPRING, INC.
Reel/Frame 052969/0314 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 30, 2016
From: T-MOBILE USA, INC.
To: DEUTSCHE TELEKOM AG
Reel/Frame 041225/0910 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2016
From: ENGELHART, ROBERT L.
To: T-MOBILE USA, INC.
Reel/Frame 038323/0750 →
SECURITY AGREEMENT Recorded Nov 17, 2015
From: T-MOBILE USA, INC.; METROPCS COMMUNICATIONS, INC.; T-MOBILE SUBSIDIARY IV CORPORATION
To: DEUTSCHE BANK AG NEW YORK BRANCH, AS ADMINISTRATIVE AGENT
Reel/Frame 037125/0885 →