IP Library Granted Patent US 9,913,236
Granted Patent B2
US 9,913,236 · App. 15/247,065 · Granted Mar 6, 2018

Method and system to authenticate multiple IMS identities

Inventors: Andrew Michael Allen (Hallandale Beach, FL); Adrian Buckley (Tracy, CA); Michael Eoin Buckley (Crystal Lake, IL)
Assignee: BlackBerry Limited
H04W60/005H04L41/08H04L61/2007H04L61/2592H04L65/1016H04M15/57H04W4/10H04W12/06H04W76/002H04W76/022
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,913,236
App. No.
15/247,065
Granted
Mar 6, 2018
Kind
B2
Abstract

A method and UE for registering with a third network node using IMS, the method creating a tunnel; authenticating a first public identity associated with the UE to the first network node; receiving configuration information with a second private identifier and a second public user identifier, and registering with a third network node using the second private identifier and the second public user identifier. Further, a method and first network node configured for authentication between a UE and a third network node using IMS, the method establishing a tunnel; authenticating a first public identity of the UE; receiving a configuration information message from the UE including a network identifier for a network the UE is registered on; obtaining, from a second network node, a second private identifier and second public user identifier; and providing the second private identifier and second public user identifier to the UE.

Claims (54)

1. A method at a user equipment for registering with a third network node using an internet protocol (IP) multimedia subsystem (IMS), the method comprising:

creating a tunnel between the user equipment and a first network node;

sending a first public identity associated with the user equipment to the first network node;

receiving configuration information from the first network node with a second private user identifier and a second public user identifier, the second private user identifier and second public user identifier being associated with a second network node;

registering with a third network node using the second private user identifier and the second public user identifier;

wherein the configuration information is divided into validity areas,

wherein the validity area is defined based on a Public Land Mobile Network (PLMN) identity or a geographic bounding area the user equipment falls within, and

wherein the user equipment uses the second private user identifier and second public user identifier based on the location of the user equipment.

2. The method of claim 1 , wherein a certificate is provided in the tunnel.

3. The method of claim 2 , wherein the certificate is created based on an identifier at the user equipment.

4. The method of claim 3 , wherein the identifier is one of a device identifier or a private user identifier.

5. The method of claim 4 , wherein the identifier is stored on a universal integrated circuit card on the user equipment.

6. The method of claim 4 , wherein the identifier is stored in a mobile equipment (ME) of the user equipment.

7. The method of claim 1 , wherein the creating uses a certificate requested by the user equipment.

8. The method of claim 1 , wherein the authenticating provides from the user equipment to the first network node at least one of a device identifier or a network the UE is registered on.

9. The method of claim 1 , wherein the receiving configuration information is subsequent to providing a configuration request to the first network node, including a network identifier that the user equipment is registered on.

10. The method of claim 1 , wherein the registering includes receiving challenge vectors for the second private user identifier and second public user identifier.

11. A user equipment configured for registering with a third network node using an internet protocol (IP) multimedia subsystem (IMS), the user equipment comprising:

a processor; and

a communications subsystem,

wherein the user equipment is configured to:

create a tunnel between the user equipment and a first network node;

send a first public identity associated with the user equipment to the first network node;

receive configuration information from the first network node with a second private user identifier and a second public user identifier, the second private user identifier and second public user identifier being associated with a second network node;

register with a third network node using the second private user identifier and the second public user identifier;

wherein the configuration information is divided into validity areas,

wherein the validity area is defined based on a Public Land Mobile Network (PLMN) identity or a geographic bounding area the user equipment falls within, and

wherein the user equipment uses the second private user identifier and second public user identifier based on the location of the user equipment.

12. A method at first network node configured for authentication between a user equipment and a third network node using an internet protocol (IP) multimedia subsystem (IMS), the method comprising:

establishing a tunnel with the user equipment;

sending a first public identity of the user equipment at first network node;

receiving a configuration information message from the user equipment, the configuration information message including a network identifier for a network the user equipment is registered on;

obtaining, from a second network node, a second private user identifier and second public user identifier;

providing configuration information with the second private user identifier and second public user identifier to the user equipment;

wherein the configuration information is divided into validity areas,

wherein the validity area is defined based on a Public Land Mobile Network (PLMN) identity or a geographic bounding area the user equipment falls within, and

wherein the user equipment uses the second private user identifier and second public user identifier based on the location of the user equipment.

13. The method of claim 12 , wherein the establishing uses a certificate requested by the user equipment.

14. The method of claim 13 , wherein the certificate is created based on an identifier at the user equipment.

15. The method of claim 14 , wherein the identifier is one of a device identifier or a private user identifier from a universal integrated circuit card on the user equipment.

16. The method of claim 14 , wherein the identifier is stored in a mobile equipment (ME) of the user equipment.

17. The method of claim 12 , wherein the authenticating includes receiving from the user equipment at the first network node at least one of a device identifier or a network the UE is registered on.

18. A first network node configured for authentication between a user equipment and a third network node using an internet protocol (IP) multimedia subsystem (IMS) the first network node comprising:

a processor; and

a communications subsystem,

wherein the first network node is configured to:

establish a tunnel with the user equipment;

send a first public identity of the user equipment at first network node;

receive a configuration information message from the user equipment, the configuration information message including a network identifier for a network the user equipment is registered on;

obtain, from a second network node, a second private user identifier and second public user identifier;

provide configuration information with the second private user identifier and second public user identifier to the user equipment;

wherein the configuration information is divided into validity areas,

wherein the validity area is defined based on a Public Land Mobile Network (PLMN) identity or a geographic bounding area the user equipment falls within, and

wherein the user equipment uses the second private user identifier and second public user identifier based on the location of the user equipment.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2016
From: ALLEN, ANDREW MICHAEL; BUCKLEY, ADRIAN; BUCKLEY, MICHAEL EOIN
To: BLACKBERRY CORPORATION
Reel/Frame 039764/0128 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2016
From: BLACKBERRY CORPORATION
To: BLACKBERRY LIMITED
Reel/Frame 039764/0257 →
Continuity (2)
Continuation 14788099 · Jun 30, 2015
Related Publication 20170006571A1 · Jan 5, 2017