IP Library Granted Patent US 9,560,524
Granted Patent B1
US 9,560,524 · App. 14/095,686 · Granted Jan 31, 2017

Wireless network application access by a wireless communication device via an untrusted access node

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,560,524
App. No.
14/095,686
Granted
Jan 31, 2017
Kind
B1
Abstract

Embodiments disclosed herein provide systems and methods to provide wireless network application access to a wireless device via an untrusted access node. In a particular embodiment, a method provides receiving communications directed to an application system within a wireless communication network from a wireless communication device via a wireless access node external to the wireless communication network. The method further provides determining whether the communications are authorized for the application system based on a signature included in the communications, wherein the signature comprises a unique identifier generated at the wireless communication device that corresponds to an identity of the wireless communication device and an identity of an integrated circuit within that wireless communication device that is associated with a subscriber of the wireless communication network. Upon determining that the communications are authorized, the method provides transferring the communications to the application system.

Claims (25)

1. A method of operating a wireless communication system to authorize communications, the method comprising:

receiving communications directed to an application system in a wireless communication network from a wireless communication device via an untrusted wireless access node external to the wireless communication network, wherein the application system provides a communications service in the wireless communication network and the wireless communication device has been previously authenticated to access the wireless communication network via a trusted wireless access node;

processing a signature included with the communications to determine when the communications are authorized for the communication service provided by the application system, wherein the communications comprise a plurality of data packets and the signature is included in a header of the data packets, the signature comprising a unique identifier generated at the wireless communication device corresponding to an identity of the wireless communication device and an identity of an integrated circuit within the wireless communication device that is associated with a subscriber of the wireless communication network; and

when the communications are authorized for the communication service, replacing an IP address associated with the data packets with a private IP address that is trusted by the wireless communication network and transferring the communications to the application system.

2. The method of claim 1 , wherein the communications are authorized when the signature indicates that the communications are transferred from an authorized wireless communication device having an authorized integrated circuit therein.

3. The method of claim 1 , wherein the unique identifier comprises an output of a hash function using, as inputs, at least a device identifier for the wireless communication device, an identifier for the integrated circuit, and an application identifier that identifies an application associated with the communications.

4. The method of claim 3 , wherein the integrated circuit comprises a subscriber identity module (SIM).

5. The method of claim 3 , wherein the hash function further uses an authentication key (A-key) and shared secret data (SSD) information as input.

6. The method of claim 5 , wherein the A-key and SSD information is obtained from an ANSI IS-41 authentication of the wireless communication device.

7. The method of claim 1 , wherein, when the communications are authorized for the communication service, the application system treats the communications as though the communications were received via an access node of the wireless communication network.

8. A wireless communication system, comprising:

a communication interface including electronic circuitry configured to receive communications directed to an application system within a wireless communication network from a wireless communication device via an untrusted wireless access node external to the wireless communication network, wherein the application system provides a communications service in the wireless communication network and the wireless communication device has been previously authenticated to access the wireless communication network via a trusted wireless access node;

a processing system configured to determine when the communications are authorized for the communication service provided by the application system based on a signature included with the communications, wherein the communications comprise a plurality of data packets and the signature is included in a header of the data packets, the signature comprising a unique identifier generated at the wireless communication device that corresponds to an identity of the wireless communication device and an identity of an integrated circuit within the wireless communication device that is associated with a subscriber of the wireless communication network, and when the communications are authorized for the communication service, replace an IP address associated with the data packets with a private IP address that is trusted by the wireless communication network; and

the communication interface further configured to transfer the communications to the application system when the communications are authorized for the communication service.

9. The wireless communication system of claim 8 , wherein the communications are authorized when the signature indicates that the communications are transferred from an authorized wireless communication device having an authorized integrated circuit therein.

10. The wireless communication system of claim 8 , wherein the unique identifier comprises an output of a hash function using, as inputs, at least a device identifier for the wireless communication device, an identifier for the integrated circuit, and an application identifier that identifies an application associated with the communications.

11. The wireless communication system of claim 10 , wherein the integrated circuit comprises a subscriber identity module (SIM).

12. The wireless communication system of claim 10 , wherein the hash function further uses an authentication key (A-key) and shared secret data (SSD) information as input.

13. The wireless communication system of claim 12 , wherein the A-key and SSD information is obtained from an ANSI IS-41 authentication of the wireless communication device.

14. The wireless communication system of claim 8 , wherein, when the communications are authorized for the communication service, the application system treats the communications as though the communications were received via an access node of the wireless communication network.

15. A wireless communication device, comprising:

an integrated circuit that is associated with a subscriber of a wireless communication network;

a processing system configured to generate a signature for inclusion with communications directed to an application system that provides a communications service on a wireless communication network, wherein the communications comprise a plurality of data packets and the signature is included in a header of the data packets, the signature comprising a unique identifier that corresponds to an identity of the wireless communication device and an identity of the integrated circuit, and wherein the wireless communication device has been previously authenticated to access the wireless communication network via a trusted wireless access node;

a communication interface configured to transfer the communications via an untrusted wireless access node external to the wireless communication network, wherein an edge node of the wireless communication network receives the communications, determines whether the communications are authorized for the application system based on the signature, and when the communications are authorized, replaces an IP address associated with the data packets with a private IP address that is trusted by the wireless communication network when the communications are authorized and transfers the communications to the application system.

16. The wireless communication device of claim 15 , wherein the communications are authorized when the signature indicates that the communications are transferred from an authorized wireless communication device having an authorized integrated circuit therein.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 055604/0001 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2013
From: REEVES, RAYMOND EMILIO; PEDEN, MARK DOUGLAS; KOLLER, GARY DUANE
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 031708/0638 →