IP Library Patent Application 15643142
Patent Application
App. No. 15/643,142

FACILITATING PROVISIONING OF AN OUT-OF-BAND PSEUDONYM OVER A SECURE COMMUNICATION CHANNEL

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/643,142
Filed
Jul 6, 2017
Art Unit
2492
USPC
713/151
Abstract

Facilitation of out-of-band pseudonym provisioning for a subscriber of a device is provided herein. In one embodiment, a method comprises: receiving, by a device comprising a processor, one way authentication data from a secure server; transmitting, by the device, to the secure server, via a secure communication channel, an identifier for a subscriber of the device, wherein the transmitting is performed based on the receiving the one way authentication data from the secure server; and receiving, by the device from the secure server, a pseudonym, wherein the pseudonym enables access by the device to an authentication device at a first time.

Claims (37)

1 . A method, comprising:

receiving, by a device comprising a processor, one way authentication data from a secure server;

transmitting, by the device, to the secure server, via a secure communication channel, an identifier for a subscriber of the device, wherein the transmitting is performed based on the receiving the one way authentication data from the secure server; and

receiving, by the device from the secure server, a pseudonym for the subscriber of the device, wherein the pseudonym enables access by the device to an authentication device at a first time.

2 . The method of claim 1 , wherein the secure communication channel is a first secure communication channel, and wherein the pseudonym is generated by an authentication server communicatively coupled to the secure server via a second secure communication channel.

3 . The method of claim 2 , further comprising:

transmitting, by the device to the authentication device, the pseudonym to obtain the access to the authentication device, wherein the transmitting the pseudonym is via an in-band communication channel, and wherein the receiving the pseudonym is via an out-of-band communication channel; and

authenticating, by the device, the subscriber, to the authentication device based on the pseudonym, wherein the authentication device is communicatively coupled to the authentication server.

4 . The method of claim 3 , wherein the pseudonym is a first pseudonym, and the method further comprising:

receiving, by the device from the authentication server, a second pseudonym after the authenticating, wherein the second pseudonym enables access to a second authentication device at a second time, and wherein the first time is prior to the second time.

5 . The method of claim 1 , wherein the secure communication channel is encrypted via a secure hypertext transfer protocol.

6 . The method of claim 1 , wherein the secure communication channel is encrypted via an Internet key exchange protocol.

7 . The method of claim 1 , wherein the secure server is a publicly accessible secure server.

8 . The method of claim 7 , wherein the publicly accessible secure server implements secure entitlement service.

9 . The method of claim 1 , wherein the identifier comprises an international mobile subscriber identifier.

10 . A machine-readable storage medium, comprising executable instructions that, when executed by a processor of a mobile device, facilitate performance of operations, comprising:

obtaining one way authentication data from a secure server;

sending, to the secure server, via a secure communication channel, an identifier for a subscriber of the mobile device, wherein the sending is performed based on the obtaining the one way authentication data from the secure server; and

obtaining, from the secure server, a pseudonym, wherein the pseudonym enables access by the mobile device to an authentication device at a first time.

11 . The machine-readable storage medium of claim 10 , wherein the secure communication channel is a first secure communication channel, and wherein the pseudonym is generated by an authentication server communicatively coupled to the secure server via a second secure communication channel.

12 . The machine-readable storage medium of claim 11 , wherein the operations further comprise:

sending, to the authentication device, the pseudonym to obtain the access to the authentication device, wherein the sending the pseudonym is via an in-band communication channel, and wherein the obtaining the pseudonym is via an out-of-band communication channel; and

authenticating to the authentication device based on the pseudonym, wherein the authentication device is communicatively coupled to the authentication server.

13 . The machine-readable storage medium of claim 12 , wherein the pseudonym is a first pseudonym, and wherein the operations further comprise:

obtaining, from the authentication server, a second pseudonym after the authenticating, wherein the second pseudonym enables access to a second authentication device at a second time, and wherein the first time is prior to the second time.

14 . The machine-readable storage medium of claim 10 , wherein the secure communication channel is encrypted via a secure hypertext transfer protocol.

15 . The machine-readable storage medium of claim 10 , wherein the secure communication channel is encrypted via an Internet key exchange protocol.

16 . The machine-readable storage medium of claim 10 , wherein the secure server is a publicly accessible secure server.

17 . A first device, comprising:

a processor; and

a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations, comprising:

receiving, from a second device, an identifier for a subscriber of the second device based on transmission to the second device of one way authentication data for the first device, wherein the receiving is performed via a secure communication channel; and

authenticating the subscriber of the second device employing the identifier, and receiving from a secure server a pseudonym for the second device, wherein the receiving from the secure server is performed via a second secure communication channel.

18 . The first device of claim 17 , wherein the operations further comprise:

transmitting, to the second device, the pseudonym, via the secure communication channel, and wherein the secure communication channel is encrypted with a secure hypertext transfer protocol or an Internet key exchange protocol.

19 . The first device of claim 18 , wherein the transmitting is performed as part of out-of-band communication for the second device and wherein the pseudonym is configured to be employed for in-band authentication by the second device with an authentication device.

20 . The first device of claim 17 , wherein the first device a publicly accessible secure server that implements secure entitlement service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2017
From: HANCOCK, PAUL; STEELE, STUART
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 043630/0087 →