IP Library Granted Patent US 9,590,987
Granted Patent B2
US 9,590,987 · App. 15/067,113 · Granted Mar 7, 2017

Dynamic distribution of authentication sessions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,590,987
App. No.
15/067,113
Granted
Mar 7, 2017
Kind
B2
Abstract

This disclosure relates to authenticating and providing transport security over unsecured IP networks to network subscribers. The system includes an authentication service that authenticates network subscribers. The authentication service can dynamically define expiry times for network authentication.

Claims (47)

1. A computer-implemented method for management of authentication sessions, the computer-implemented method comprising:

receiving an authentication request for an authentication session, wherein an authentication server receives the authentication request from a telecommunication device;

determining a proposed expiry time for the authentication session, wherein the proposed expiry time is within a first time period;

determining a number of subscribers with expiry times within the first time period;

based on a determination that the number of subscribers in the first time period exceeds a first subscriber threshold,

determining a modified expiry time within a second time period, wherein the number of subscribers with authentication session expiry times within the second time period does not exceed a second subscriber threshold;

generating an authentication token with the second expiry time; and

transmitting the authentication token to the telecommunication device responsive to the authentication request.

2. The computer-implemented method of claim 1 further comprising:

based on a determination that the number of subscribers in the first time period does not exceed a first subscriber threshold, generating an authentication token with the proposed expiry time.

3. The computer-implemented method of claim 1 , wherein the modified expiry time corresponds to a time prior to the proposed expiry time.

4. The computer-implemented method of claim 1 , wherein the modified expiry time corresponds to a time after the proposed expiry time.

5. The computer-implemented method of claim 1 , wherein the first subscriber threshold for the first time period and second subscriber threshold for the second time period are different.

6. The computer-implemented method of claim 1 , wherein the threshold for the first time period and the second time period are equal.

7. A telecommunication system comprising:

an authentication server configured to:

receive an authentication request for an authentication session from a telecommunication device;

determine a first expiry time for the authentication session, wherein the first expiry time is within a first time period;

determine a number of subscribers with authentication session expiry times within the first time period;

based on a determination that the number of subscribers in the first time period exceeds a first subscriber threshold,

determine a second expiry time within a second time period, wherein the number of subscribers with authentication session expiry times within the second time period does not exceed a second subscriber threshold;

generate an authentication token with the second expiry time; and

transmit the authentication token to the telecommunication device responsive to the authentication request.

8. The telecommunication system of claim 7 , wherein the authentication server is configured to communicate with the telecommunication device over a bootstrapping interface.

9. The telecommunication system of claim 7 , wherein the authentication server comprises a bootstrapping service function.

10. The telecommunication system of claim 7 , wherein the first subscriber threshold and the second subscriber threshold are the same.

11. The telecommunication system of claim 7 , wherein the authentication server is further configured to:

analyze historical data related to the distribution of subscriber expiry times; and

determine the second expiry time based, at least in part, the historical data in addition to the number of subscribers with authentication session expiry times within the second time period.

12. The telecommunication system of claim 7 , wherein the first expiry time corresponds to a defined expiry time period.

13. The telecommunication system of claim 12 , wherein the defined expiry time period is twenty-four hours.

14. The telecommunication system of claim 7 , wherein the first time period and the second time period are equal.

15. The telecommunication system of claim 7 , wherein the first subscriber threshold is a maximum number of authentication session expiry times within the first time period.

16. A non-transitory computer-readable medium storing computer-executable instructions that, when executed by one or more computing devices, configure the one or more computing devices to perform operations comprising:

receiving an authentication request for an authentication session from a telecommunication device;

determining a first expiry time for the authentication session, wherein the first expiry time is within a first time period;

determining a number of subscribers with authentication session expiry times within the first time period;

based on a determination that the number of subscribers in the first time period exceeds a first subscriber threshold,

determining a second expiry time within a second time period, wherein the number of subscribers with authentication session expiry times within the second time period does not exceed a second subscriber threshold;

generating an authentication token with the second expiry time; and

transmitting the authentication token to the telecommunication device responsive to the authentication request.

17. The non-transitory computer-readable medium of claim 16 , wherein the modified expiry time corresponds to a time less than the proposed expiry time.

18. The non-transitory computer-readable medium of claim 16 , wherein the modified expiry time corresponds to a time greater than the proposed expiry time.

19. The non-transitory computer-readable medium of claim 16 , wherein the first subscriber threshold for the first time period and the second subscriber threshold for the second time period are different.

20. The non-transitory computer-readable medium of claim 16 further comprising:

analyzing historical data related to the distribution of subscriber expiry times; and

determining the second expiry time based, at least in part, the historical data in addition to the number of subscribers with authentication session expiry times within the second time period.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
RELEASE OF SECURITY INTEREST Recorded Apr 1, 2020
From: DEUTSCHE TELEKOM AG
To: T-MOBILE USA, INC.; IBSV LLC
Reel/Frame 052969/0381 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 30, 2016
From: T-MOBILE USA, INC.
To: DEUTSCHE TELEKOM AG
Reel/Frame 041225/0910 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2016
From: ENGELHART, ROBERT L.
To: T-MOBILE USA, INC.
Reel/Frame 038323/0750 →