IP Library Granted Patent US 9,402,177
Granted Patent B2
US 9,402,177 · App. 14/097,070 · Granted Jul 26, 2016

Authentication in secure user plane location (SUPL) systems

Inventors: Philip Michael Hawkes (Warrimoo, AU); Andreas Klaus Wachter (Menlo Park, CA); Adrian Edward Escott (Reading, GB); Stephen William Edge (Escondido, CA)
Assignee: QUALCOMM Incorporated
H04W12/04H04L63/0823H04L63/166H04W12/06H04L63/205H04W4/02H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,402,177
App. No.
14/097,070
Granted
Jul 26, 2016
Kind
B2
Abstract

A particular method includes generating, at a secure user plane location (SUPL) server, a message to be sent to a mobile device, the message including: a server certificate including an identifier of the SUPL server and a public key of the SUPL server; and a request for a device certificate of the mobile device. The method also includes receiving a reply from the mobile device that includes a device certificate of the mobile device; and authenticating the mobile device as associated with a SUPL user based on the device certificate.

Claims (39)

1. A method comprising:

generating, at a secure user plane location (SUPL) server, a message to be sent to a mobile device, the message including:

a server certificate including an identifier of the SUPL server and a public key of the SUPL server; and

a request for a device certificate of the mobile device;

receiving a reply message from the mobile device that includes a device certificate of the mobile device, wherein the reply message is encrypted using the public key of the SUPL server; and

authenticating, at the SUPL server, the mobile device by verifying whether the mobile device is associated with an authorized SUPL user based on the device certificate, wherein the device certificate includes a device identification (ID), and wherein authenticating the mobile device comprises comparing the device ID to a stored device ID, wherein the stored device ID is previously securely verified by the SUPL server as being associated with the authorized SUPL user.

2. The method of claim 1 , wherein the mobile device comprises a SUPL enabled terminal (SET) and the SUPL server comprises a SUPL location platform (SLP).

3. The method of claim 1 , wherein the message is sent in response to receiving from the mobile device an indication of one or more transport layer security (TLS) cipher suites supported by the mobile device, and wherein the message further includes a selection of at least one of the one or more TLS cipher suites.

4. The method of claim 1 , wherein the device certificate includes a device identifier of the mobile device.

5. A non-transitory processor-readable medium comprising instructions that, when executed by a processor, cause the processor to:

generate, at a secure user plane location (SUPL) server, a message to be sent to a mobile device, the message including:

a server certificate including an identifier of the SUPL server and a public key of the SUPL server; and

a request for a device certificate of the mobile device;

receive a reply message from the mobile device that includes a device certificate of the mobile device, wherein the reply message is encrypted using the public key of the SUPL server; and

authenticate, at the SUPL server, the mobile device by verifying whether the mobile device is associated with an authorized SUPL user based on the device certificate, wherein the device certificate includes a device identification (ID), and wherein authenticating the mobile device comprises comparing the device ID to a stored device ID, wherein the stored device ID is previously securely verified by the SUPL server as being associated with the authorized SUPL user.

6. The non-transitory processor-readable medium of claim 5 , wherein the mobile device comprises a SUPL enabled terminal (SET) and the SUPL server comprises a SUPL location platform (SLP).

7. The non-transitory processor-readable medium of claim 5 , wherein the message is sent in response to receiving from the mobile device an indication of one or more transport layer security (TLS) cipher suites supported by the mobile device, and wherein the message further includes a selection of at least one of the one or more TLS cipher suites.

8. The non-transitory processor-readable medium of claim 5 , wherein the device certificate includes a device identifier of the mobile device.

9. An apparatus comprising:

a hardware processor; and

a memory coupled to the processor, wherein the memory is configured to store instructions; and

wherein the instructions are executable by the processor to:

generate, at a secure user plane location (SUPL) server, a message to be sent to a mobile device, the message including:

a server certificate including an identifier of the SUPL server and a public key of the SUPL server; and

a request for a device certificate of the mobile device;

receive a reply message from the mobile device that includes a device identifier of the mobile device, wherein the reply message is encrypted using the public key of the SUPL server; and

authenticate, at the SUPL server, the mobile device by verifying whether the mobile device is associated with an authorized SUPL user based on the device certificate, wherein the device certificate includes a device identification (ID), and wherein authenticating the mobile device comprises comparing the device ID to a stored device ID, wherein the stored device ID is previously securely verified by the SUPL server as being associated with the authorized SUPL user.

10. The apparatus of claim 9 , wherein the message is sent in response to receiving at the SUPL server from the mobile device an indication of one or more transport layer security (TLS) cipher suites supported by the mobile device, and wherein the message further includes a selection of at least one of the one or more TLS cipher suites.

11. An apparatus comprising:

means for generating, at a secure user plane location (SUPL) server, a message to be sent to a mobile device, the message including:

a server certificate including an identifier of the SUPL server and a public key of the SUPL server; and

a request for a device certificate of the mobile device;

means for receiving a reply message from the mobile device that includes a device certificate of the mobile device, wherein the reply message is encrypted using the public key of the SUPL server; and

means for authenticating, at the SUPL server, the mobile device by verifying whether the mobile device is associated with an authorized SUPL user based on the device certificate, wherein the device certificate includes a device identification (ID), and wherein means for authenticating the mobile device comprises means for comparing the device ID to a stored device ID, wherein the stored device ID is previously securely verified by the SUPL server as being associated with the authorized SUPL user.

12. The apparatus of claim 11 , wherein the mobile device comprises a SUPL enabled terminal (SET) and the SUPL server comprises a SUPL location platform (SLP).

13. The apparatus of claim 11 , wherein the message is sent in response to receiving from the mobile device an indication of one or more transport layer security (TLS) cipher suites supported by the mobile device, and wherein the message further includes a selection of at least one of the one or more TLS cipher suites.

14. The apparatus of claim 11 , wherein the device certificate includes a device identifier of the mobile device.

15. The method of claim 1 , further comprising:

decrypting the reply message, at the SUPL server, using a private key of the SUPL server to obtain the device certificate of the mobile device.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2015
From: HAWKES, PHILIP MICHAEL; WACHTER, ANDREAS; ESCOTT, ADRIAN EDWARD; EDGE, STEPHEN WILLIAM
To: QUALCOMM INCORPORATED
Reel/Frame 036098/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2014
From: HAWK, PHILIP MICHAEL; WACHTER, ANDRE; ESCOTT, ADRIAN EDWARD; EDGE, STEPHEN WILLIAM
To: QUALCOMM INCORPORATED
Reel/Frame 033274/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2013
From: HAWKES, PHILIP MICHAEL; WACHTER, ANDREAS; ESCOTT, ADRIAN EDWARD; EDGE, STEPHEN WILLIAM
To: QUALCOMM INCORPORATED
Reel/Frame 031722/0877 →
Continuity (6)
Division 13288949 · Nov 3, 2011
Provisional Application 61410882 · Nov 6, 2010
Provisional Application 61437184 · Jan 28, 2011
Provisional Application 61471048 · Apr 1, 2011
Provisional Application 61527341 · Aug 25, 2011
Related Publication 20140094147A1 · Apr 3, 2014