IP Library Granted Patent US 9,769,665
Granted Patent B2
US 9,769,665 · App. 15/496,502 · Granted Sep 19, 2017

Sponsored connectivity to cellular networks using existing credentials

Inventors: Soo Bum Lee (San Diego, CA); Anand Palanigounder (San Diego, CA); Gavin Bernard Horn (La Jolla, CA)
H04W12/06H04L9/0643H04L9/085H04L63/083H04L63/18H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,769,665
App. No.
15/496,502
Granted
Sep 19, 2017
Kind
B2
Abstract

Systems and techniques are disclosed to facilitate the sponsored connectivity of a user equipment on a serving network so that the UE may access a service whose connectivity is sponsored by an application service provider. The application service provider provisions the serving network so that it is aware of the sponsored connectivity. In an attach attempt to the serving network, the UE provides a client token based on a pre-existing credential (established between the UE and the application service provider) instead of a subscriber identifier with the attach request. The application service provider's server validates the access credential to authenticate the UE and provides information that the serving network uses to mutually authenticate with the UE. The UE may then use the serving network to access the service via the sponsored connection, even where the UE does not have a subscriber identity and subscription with a cellular network.

Claims (48)

1. A method for enabling access to a sponsored service by an application service provider server, comprising:

receiving, from an intervening network through which the application service provider server sponsors access to the service, an authentication information request based on an attach request from a user equipment (UE), the authentication information request comprising a client token based on a pre-existing credential associated with the UE and established with the application service provider server, the client token being unrecognizable as a cellular access credential to the network;

determining, by the application service provider server, authentication information based on the pre-existing credential accessible by the application service provider server in response to the authentication information request; and

transmitting, from the application service provider server, the authentication information in a response to the network, wherein the authentication information configured to assist in authentication between the UE and the network for sponsored access to the service based on the pre-existing credential.

2. The method of claim 1 , wherein the pre-existing credential is based on a password established with the application service provider server generated via an out-of-band channel and the authentication information request includes a user name associated with the password and the application service provider server, the determining further comprising:

verifying, by the application service provider server, the user name and client token based on one or more records accessible by the application service provider server, wherein the client token comprises the pre-existing credential hashed with a first value and the pre-existing credential comprises the password hashed with a second value.

3. The method of claim 2 , further comprising:

generating, by the application service provider server, an authentication vector comprising a shared key, authentication token, and expected response based on the pre-existing credential.

4. The method of claim 1 , wherein the receiving further comprises:

providing, by the application service provider server, the client token to the UE for the UE to use as proof of possessing the pre-existing credential prior to receiving the authentication information request.

5. The method of claim 1 , further comprising:

agreeing, after the receiving, upon a shared secret key based on a handshake between the UE and the application service provider server;

determining, by the application service provider server, a base key based on the shared secret key; and

generating, by the application service provider server, an authentication vector comprising the base key, an authentication token, and an expected response based on the pre-existing credential.

6. The method of claim 1 , further comprising:

providing, prior to receiving the authentication information request, a list of trusted networks to the UE.

7. An application service provider server that sponsors access to a service, comprising:

a transceiver configured to receive, from an intervening network through which the application service provider server sponsors access to the service, an authentication information request based on an attach request from a user equipment (UE), the authentication information request comprising a client token based on a pre-existing credential established with the application service provider server and being unrecognizable as a cellular access credential to the network; and

a processor configured to determine authentication information based on the pre-existing credential accessible by the application service provider server in response to the authentication information request,

wherein the transceiver is further configured to transmit the authentication information in a response to the network, and

wherein the authentication information assists in authentication between the UE and the network for sponsored access to the service based on the pre-existing credential.

8. The application service provider server of claim 7 , wherein the pre-existing credential is based on a password established with the application service provider server generated via an out-of-band channel and the authentication information request includes a user name associated with the password and the application service provider server, the processor being further configured to:

verify the user name and client token based on one or more records accessible by the application service provider server, wherein the client token comprises the pre-existing credential hashed with a first value and the pre-existing credential comprises the password hashed with a second value.

9. The application service provider server of claim 8 , wherein the processor is further configured to:

generate an authentication vector comprising a shared key, authentication token, and expected response based on the pre-existing credential.

10. The application service provider server of claim 7 , wherein the transceiver is further configured to:

provide the client token to the UE for the UE to use as proof of possessing the pre-existing credential prior to receiving the authentication information request.

11. The application service provider server of claim 7 , wherein the processor is further configured to:

agree, after receiving the authentication information request, upon a shared secret key based on a handshake between the UE and the application service provider server;

determine a base key based on the shared secret key; and

generate an authentication vector comprising the base key, an authentication token, and an expected response based on the pre-existing credential.

12. The application service provider server of claim 7 , wherein the processor is further configured to provide, prior to receiving the authentication information request, a list of trusted networks to the UE.

13. A non-transitory computer-readable medium having program code recorded thereon, the program code comprising:

code for causing an application service provider server to receive, from an intervening network through which the application service provider server sponsors access to a service, an authentication information request based on an attach request from a user equipment (UE), the authentication information request comprising a client token based on a pre-existing credential associated and established with the application service provider server, the client token being unrecognizable as a cellular access credential to the network;

code for causing the application service provider server to determine authentication information based on the pre-existing credential accessible by the application service provider server in response to the authentication information request; and

code for causing the application service provider server to transmit the authentication information in a response to the network, wherein the authentication information assists in authentication between the UE and the network for sponsored access to the service based on the pre-existing credential.

14. The non-transitory computer-readable medium of claim 13 , wherein the access credential is based on a password established with the application service provider server generated via an out-of-band channel and the authentication information request includes a user name associated with the password and the application service provider server, further comprising:

code for causing the application service provider server to verify the user name and client token based on one or more records accessible by the application service provider server, wherein the client token comprises the pre-existing credential hashed with a first value and the pre-existing credential comprises the password hashed with a second value.

15. The non-transitory computer-readable medium of claim 14 , further comprising:

code for causing the application service provider server to generate an authentication vector comprising a shared key, authentication token, and expected response based on the pre-existing credential.

16. The non-transitory computer-readable medium of claim 13 , further comprising:

code for causing the application service provider server to provide the client token to the UE for the UE to use as proof of possessing the pre-existing credential prior to receiving the authentication information request.

17. The non-transitory computer-readable medium of claim 13 , further comprising:

code for causing the application service provider server to agree, after receiving the authentication information request, upon a shared secret key based on a handshake between the UE and the server;

code for causing the application service provider server to determine a base key based on the shared secret key; and

code for causing the application service provider server to generate an authentication vector comprising the base key, an authentication token, and an expected response based on the pre-existing credential.

18. The non-transitory computer-readable medium of claim 13 , further comprising:

code for causing the application service provider server to provide, prior to receiving the authentication information request, a list of trusted networks to the UE.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2017
From: LEE, SOO BUM; PALANIGOUNDER, ANAND; HORN, GAVIN BERNARD
To: QUALCOMM INCORPORATED
Reel/Frame 042214/0768 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2017
From: LEE, SOO BUM; PALANIGOUNDER, ANAND; HORN, GAVIN BERNARD
To: QUALCOMM INCORPORATED
Reel/Frame 042166/0832 →
Continuity (3)
Division 14817123 · Aug 3, 2015
Provisional Application 62129462 · Mar 6, 2015
Related Publication 20170230829A1 · Aug 10, 2017