IP Library Granted Patent US 9,936,384
Granted Patent B2
US 9,936,384 · App. 14/954,037 · Granted Apr 3, 2018

Systems and methods for providing security to different functions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,936,384
App. No.
14/954,037
Granted
Apr 3, 2018
Kind
B2
Abstract

Methods and systems are provided that use smartcards, such as subscriber identity module (SIM) cards to provide secure functions for a mobile client. One embodiment of the invention provides a mobile communication network system that includes a mobile network, a mobile terminal, a server coupled to the mobile terminal via the mobile network, and a subscriber identity module (SIM) card coupled to the mobile terminal. The SIM card includes a first key and a second key. The first key is used to authenticate an intended user of the mobile terminal to the mobile network. Upon successful authentication of the intended user to the mobile network, the mobile terminal downloads a function offered from the server through the mobile network. The second key is then used by the mobile terminal to authenticate the intended user to the downloaded function so that the intended user can utilize the function.

Claims (43)

1. A device comprising:

a memory storing:

a network key, a server key, and a capsule key; and

an authentication circuitry in data communication with the memory, the authentication circuitry including circuitry and program code which are together operative to:

authenticate the device or a component of the device, using a copy of the network key, to a data communication network to permit downloading a function capsule including a financial service function from the data communication network;

authenticate the device or a component of the device, using a copy of the server key, to a remote server to permit downloading of the function capsule including a financial service function from the remote server;

authenticate the device or a component of the device, using a copy of the server key, to a server to permit access to the server; and

authenticate the device or a component of the device, using a copy of the capsule key, to execute the financial service function of the function capsule.

2. The device of claim 1 wherein the authentication circuitry comprises circuitry and program code which together are operative to authenticate the device or a component of the device, using the copy of the capsule key, to enable a payment function of the device or a component of the device as the financial service function.

3. The device of claim 2 wherein the authentication circuitry comprises circuitry and program code which together are operative to authenticate the device or a component of the device, using the copy of the server key, to a remote server to permit downloading of the function capsule including the payment function from the remote server.

4. The device of claim 1 wherein the authentication circuitry includes circuitry and program code which together are operative to authenticate the device, using the copy of the capsule key, to enable a product-ordering function or a service-ordering function, or both, of the device or a component of the device.

5. The device of claim 1 wherein the authentication circuitry comprises a subscriber identity module (SIM).

6. The device of claim 1 wherein the authentication circuitry comprises a hardware security module of the device.

7. A device comprising

a memory storing:

a first network key, a second network key, a server key, and a capsule key; and

an authentication circuitry in data communication with the memory, the authentication circuitry including circuitry and program code which are together operative to:

authenticate the device or a component of the device, using a copy of the first network key, to a data communication network to permit downloading a function capsule including a financial service function from the data communication network;

authenticate the device or a component of the device, using a copy of the server key, to a server to permit access to the server including retrieving the function capsule including a financial service function, from the server;

authenticate the device or a component of the device, using a copy of the server key, to the server to permit downloading of the function capsule including the financial service function from the server over the data communication network;

authenticate the device or a component of the device, using a copy of the second network key, to a mobile communication network to permit executing financial transactions of the financial service function over the mobile communication network; and

authenticate the device or a component of the device, using a copy of the capsule key, to execute the financial service function of the function capsule.

8. The device of claim 7 wherein the authentication circuitry comprises circuitry and program code which together are operative to authenticate the device or a component of the device, using the copy of the capsule key, to enable a payment function as the financial service function, during a payment transaction over the mobile communication network.

9. A portable computer device comprising the device of claim 7 .

10. A method comprising:

through a mobile device comprising a memory,

accessing a server key from the memory of the mobile device, the server key matching a key stored with a server remotely from the mobile device;

authenticating the mobile device to access the server using the server key;

downloading, from the server, a function capsule comprising a financial service function;

configuring the function capsule including the financial service function using the server key; and

authenticating the mobile device to execute the financial service function using the server key.

11. The method of claim 1 wherein authenticating the mobile device to execute the financial service function comprises authenticating the mobile device to perform payment functions using the mobile device using the server key.

12. The method of claim 10 further comprising:

accessing a capsule key from the memory of the mobile device; and

enabling the financial service function using the capsule key.

13. The method of claim 12 wherein accessing a server key from the memory of the mobile device comprises accessing the server key from a subscriber identity module and wherein accessing a capsule key comprises accessing the capsule key from a subscriber identity module.

14. The method of claim 12 wherein enabling the financial service function comprises authenticating the mobile device to perform payment functions using the capsule key.

15. The method of claim 10 further comprising:

accessing a network key from the memory of the mobile device, the network key matching a key stored with a data communication network remotely from the mobile device; and

authenticating the mobile device, using the network key, to the data communication network to permit downloading the function capsule from the server and to permit executing the financial service function over the data communication network.

16. The method of claim 15 further comprising:

accessing a second network key from the memory of the mobile device, the network key matching a key stored with a wireless communication network remotely from the mobile device; and

authenticating the mobile device, using the second network key, to the wireless communication network to permit executing the financial service function over the wireless communication network using the second network key.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2016
From: BROADCOM CORPORATION
To: NXP B.V.
Reel/Frame 039901/0237 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2015
From: FRANK, EDWARD H.; BUER, MARK; KARAOGUZ, JEYHAN
To: BROADCOM CORPORATION
Reel/Frame 037168/0441 →