IP Library Granted Patent US 10,263,984
Granted Patent B2
US 10,263,984 · App. 15/273,165 · Granted Apr 16, 2019

Authentication failure handling for access to services through untrusted wireless networks

Inventors: Krisztian Kiss (Hayward, CA); Thomas F. Pauly (Cupertino, CA); Ajoy K. Singh (Milpitas, CA); Rohan C. Malthankar (San Jose, CA); Vikram Bhaskara Yerrabommanahalli (Sunnyvale, CA); Rafael L. Rivera-Barreto (Santa Clara, CA)
Assignee: Apple Inc.
H04L63/0884H04L63/0853H04W12/06H04W76/18H04W4/12H04W4/16H04W8/183H04W84/02H04W84/12H04W88/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,263,984
App. No.
15/273,165
Granted
Apr 16, 2019
Kind
B2
Abstract

Apparatus and methods to support authentication failure handling by network elements and by a wireless communication device when attempting access to services through non-cellular wireless networks by the wireless communication device are disclosed. Error messages received from evolved packet core (EPC) network elements, such as an authentication, authorization, and accounting (AAA) server, are mapped to failure messages provided to wireless communication devices by internetworking equipment, such as an evolved packet data gateway (ePDG). The wireless communication device determines a failures cause based on the failure messages and disallows retry attempts until select criteria are satisfied.

Claims (40)

1. A method to control service access for a wireless communication device, the method comprising:

by the wireless communication device:

establishing an encrypted connection with an evolved packet data gateway (ePDG) server through a non-third generation partnership project (non-3GPP) wireless access network;

requesting access to a particular service of a third generation partnership project (3GPP) cellular wireless network via the ePDG server and the non-3GPP wireless access network;

receiving an authentication failure message from the ePDG server, the authentication failure message comprising a specific error indication mapped by the ePDG server based on an error code received from an authentication server of the 3GPP cellular wireless network;

determining a failure cause based at least in part on the specific error indication of the authentication failure message; and

disallowing retry attempts to request access to the particular service until one or more criteria are satisfied.

2. The method of claim 1 , wherein the wireless communication device requests access to the particular service of the 3GPP cellular wireless network by at least attempting to establish a secure tunnel to an access point name (APN).

3. The method of claim 2 , wherein the authentication failure message from the ePDG server indicates to the wireless communication device that the wireless communication device is not allowed access to the APN.

4. The method of claim 2 , wherein the authentication failure message from the ePDG server indicates to the wireless communication device that the wireless communication device is not allowed access to the particular service of the 3GPP cellular wireless network.

5. The method of claim 2 , wherein the authentication failure message from the ePDG server indicates to the wireless communication device that the wireless communication device is not allowed access to the APN or to the particular service of the 3GPP cellular wireless network via the non-3GPP wireless access network.

6. The method of claim 1 , wherein the authentication failure message comprises an Internet Key Exchange Version 2 (IKEv2) message indicating the particular service is not available to the wireless communication device for a geographic location at which the wireless communication device is operating.

7. The method of claim 1 , wherein the one or more criteria are satisfied based at least in part on a network-specified back-off time period following each retry attempt.

8. The method of claim 1 , wherein the one or more criteria are satisfied based at least in part on changes to security credentials of a Subscriber Identity Module (SIM) for the wireless communication device.

9. The method of claim 1 , wherein the one or more criteria are satisfied based at least in part on the wireless communication device changing its geographic location by a pre-configured measure.

10. The method of claim 1 , wherein the one or more criteria are satisfied based on the wireless communication device requesting access to the particular service via a different non-3GPP wireless access network.

11. A wireless communication device comprising:

one or more antennas,

wireless circuitry communicatively coupled to the one or more antennas and to processing circuitry; and

the processing circuitry comprising one or more processors and a storage medium storing instructions that, when executed on the one or more processors, cause the wireless communication device to:

establish an encrypted connection with an evolved packet data gateway (ePDG) server through a non-third generation partnership project (non-3GPP) wireless access network;

request access to a particular service of a third generation partnership project (3GPP) cellular wireless network via the ePDG server and the non-3GPP wireless access network;

receive an authentication failure message from the ePDG server, the authentication failure message comprising a specific indication mapped by the ePDG server based on an error code received from an authentication server of the 3GPP cellular wireless network;

determine a failure cause based at least in part on the specific error indication of the authentication failure message; and

disallow retry attempts to request access to the particular service until one or more criteria are satisfied.

12. The wireless communication device of claim 11 , wherein the wireless communication device requests access to the particular service of the 3GPP cellular wireless network by at least attempting to establish a secure tunnel to an access point name (APN).

13. The wireless communication device of claim 12 , wherein the authentication failure message from the ePDG server indicates to the wireless communication device that the wireless communication device is not allowed access to the APN.

14. The wireless communication device of claim 12 , wherein the authentication failure message from the ePDG server indicates to the wireless communication device that the wireless communication device is not allowed access to the particular service of the 3GPP cellular wireless network.

15. The wireless communication device of claim 12 , wherein the authentication failure message from the ePDG server indicates to the wireless communication device that the wireless communication device is not allowed access to the APN or to the particular service of the 3GPP cellular wireless network via the non-3GPP wireless access network.

16. The wireless communication device of claim 11 , wherein the authentication failure message comprises an Internet Key Exchange Version 2 (IKEv2) message indicating the particular service is not available to the wireless communication device for a geographic location at which the wireless communication device is operating.

17. The wireless communication device of claim 11 , wherein the one or more criteria are satisfied based at least in part on a network-specified back-off time period following each retry attempt.

18. The wireless communication device of claim 11 , wherein the one or more criteria are satisfied based at least in part on changes to security credentials of a Subscriber Identity Module (SIM) for the wireless communication device.

19. The wireless communication device of claim 11 , wherein the one or more criteria are satisfied based at least in part on the wireless communication device changing its geographic location by a pre-configured measure.

20. An apparatus configurable for operation in a wireless communication device, the apparatus comprising:

processing circuitry including a processor and a memory storing instructions that, when executed by the processor, cause the wireless communication device to:

establish an encrypted connection with an evolved packet data gateway (ePDG) server through a non-third generation partnership project (non-3GPP) wireless access network;

request access to a particular service of a third generation partnership project (3GPP) cellular wireless network via the ePDG server and the non-3GPP wireless access network;

receive an authentication failure message from the ePDG server, the authentication failure message comprising a specific error indication mapped by the ePDG server based on an error code received from an authentication server of the 3GPP cellular wireless network;

determine a failure cause based at least in part on the specific error indication of the authentication failure message; and

disallow retry attempts to request access to the particular service until one or more criteria are satisfied.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2016
From: KISS, KRISZTIAN; PAULY, THOMAS F.; SINGH, AJOY K.; MALTHANKAR, ROHAN C.; YERRABOMMANAHALLI, VIKRAM BHASKARA; RIVERA-BARRETO, RAFAEL L.
To: APPLE INC.
Reel/Frame 039835/0797 →
Continuity (2)
Provisional Application 62235439 · Sep 30, 2015
Related Publication 20170094512A1 · Mar 30, 2017