IP Library Granted Patent US 11,076,296
Granted Patent B1
US 11,076,296 · App. 16/411,134 · Granted Jul 27, 2021

Subscriber identity module (SIM) application authentication

Inventors: Nishi Kant (Fremont, CA); Lyle W. Paczkowski (Mission Hills, KS); Ivo Rook (New York, NY)
Assignee: Sprint Communications Company L.P.
H04W12/37H04L63/0853H04L63/0892H04W8/183H04W12/041H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,076,296
App. No.
16/411,134
Granted
Jul 27, 2021
Kind
B1
Abstract

A method of authenticating access of an electronic device to an application server based on a subscriber identity module (SIM) associated with the electronic device. The method receiving an authentication challenge from an application executing on the device by a SIM application toolkit (SAT) executing on the device, transmitting a random number and an authentication value of the challenge to a SIM of the device by the SAT, receiving a response from the SIM by the SAT, transmitting an authentication response to the application by the SAT, where the authentication response comprises the response received from the SIM, generating an application key by the SAT based at least in part on the response received from the SIM, and transmitting the application key to the application by the SAT, whereby the application executing on the electronic device establishes a communication session with an application server via an access communication network.

Claims (59)

1. A method of authenticating access of an electronic device to an application server based on a subscriber identity module (SIM) associated with the electronic device, comprising:

receiving an identity request from an application executing on an electronic device by a subscriber identity module application toolkit (SAT) executing on the electronic device;

looking up a device identity by the SAT;

transmitting the device identity to the application by the SAT;

receiving an authentication challenge from the application by the SAT, where the authentication challenge comprises a random number and an authentication value generated based on the device identity by an authentication authorization accounting (AAA) server located in an operator domain;

transmitting the random number and the authentication value to a subscriber identity module (SIM) of the electronic device by the SAT;

receiving a response from the SIM by the SAT;

transmitting an authentication response to the application by the SAT, where the authentication response comprises the response received from the SIM;

generating an application session key by the SAT based at least in part on the response received from the SIM; and

transmitting the application session key to the application by the SAT, whereby the application executing on the electronic device establishes a communication session with an application server via an access communication network.

2. The method of claim 1 , wherein the electronic device is an Internet of things (IoT) device.

3. The method of claim 2 , wherein the application sends sensor data collected from a sensor of the electronic device to the application server.

4. The method of claim 1 , wherein the electronic device is one of a mobile phone, a smart phone, a wearable computer, a laptop computer, a tablet computer, or a notebook computer.

5. The method of claim 1 , wherein the application communicates with the access communication network via a non-cellular communication link.

6. The method of claim 5 , wherein the application communicates with the access communication network via one of a WiFi wireless communication link, a Bluetooth wireless communication link, an Ethernet communication link, and a power line communication (PLC) communication link.

7. The method of claim 5 , wherein the SAT executes on a cellular radio modem of the electronic device.

8. An electronic device, comprising:

a communication interface;

a subscriber identity module (SIM);

an application stored in a non-transitory memory of the electronic device that, when executed by a processor of the electronic device, authenticates into an access communication network and authenticates into an application service domain via the communication interface; and

a SIM application toolkit stored in a non-transitory memory of the electronic device that, when executed by a processor of the electronic device

receives an identity request from the application, wherein the identity request is associated with the application authenticating into the access network,

looks up a device identity,

transmits the device identity to the application,

receives an authentication challenge from the application, wherein the authentication challenge comprises a random number and an authentication value generated based on the device identity by an authentication authorization accounting (AAA) server located in an operator domain and wherein the authentication challenge is associated with the application authenticating into the access network,

transmits the random number and the authentication value to the SIM,

receives a response from the SIM,

transmits an authentication response to the application, where the authentication response comprises the response received from the SIM,

generates an application key based at least in part on the response received from the SIM, and

transmits the application key to the application, whereby the application authenticates into the application service domain and establishes a communication session with an application server in the application service domain via the communication interface.

9. The electronic device of claim 8 , wherein the electronic device is an Internet of things (IoT) device.

10. The electronic device of claim 8 , wherein the electronic device is one of a mobile phone, a smart phone, a wearable computer, a laptop computer, a tablet computer, or a notebook computer.

11. The electronic device of claim 8 , wherein the communication provides one of a WiFi wireless communication link, a Bluetooth wireless communication link, an Ethernet wired communication link, and a power line communication (PLC) communication link to the access communication network.

12. The electronic device of claim 8 , wherein the electronic device further comprises a sensor coupled to the processor on which the application executes, wherein the application collects data from the sensor and transmits data associated with the sensor to the application service domain.

13. The electronic device of claim 8 , wherein the electronic device further comprises a plurality of sensors coupled to the processor on which the application executes, wherein the application collects data from each of the sensors and transmits data associated with the sensors to the application service domain.

14. The electronic device of claim 8 , wherein the application and the SIM application toolkit execute on the same processor of the electronic device.

15. The electronic device of claim 8 , wherein the application executes on a first processor of the electronic device and the SIM application toolkit executes on a second processor of the electronic device.

16. A method of authenticating access of an electronic device into a communication access network based on a subscriber identity module (SIM) associated with the electronic device, comprising:

receiving a first identity request from a first application executing on an electronic device by a subscriber identity module application toolkit (SAT) executing on the electronic device, wherein the first application is associated with a first sensor;

looking up a device identity by the SAT;

transmitting the device identity to the first application by the SAT;

receiving a first authentication challenge from the first application by the SAT, where the first authentication challenge comprises a first random number and a first authentication value generated based on the device identity by an authentication authorization accounting (AAA) server located in an operator domain;

transmitting the first random number and the first authentication value to a subscriber identity module (SIM) of the electronic device by the SAT;

receiving a first response from the SIM by the SAT; and

transmitting a first authentication response to the first application by the SAT, wherein the first authentication response comprises the first response received from the SIM, whereby the first application authenticates into a first communication access network based in part on the first authentication response;

receiving a second identity request from a second application executing on the electronic device by the SAT, wherein the second application is associated with a second sensor;

transmitting the device identity to the second application by the SAT;

receiving a second authentication challenge from the second application by the SAT, where the second authentication challenge comprises a second random number and a second authentication value generated based on the device identity by the AAA server;

transmitting the second random number and the second authentication value to the SIM of the electronic device by the SAT;

receiving a second response from the SIM by the SAT; and

transmitting a second authentication response to the second application by the SAT, wherein the second authentication response comprises the second response received from the SIM, whereby the second application authenticates into a second communication access network based in part on the second authentication response.

17. The method of claim 16 , further comprising:

generating a first application key by the SAT based at least in part on the first response received from the SIM;

transmitting the first application key to the first application by the SAT, whereby the first application executing on the electronic device establishes a communication session with a first application server via the first communication access network;

generating a second application key by the SAT based at least in part on the second response received from the SIM; and

transmitting the second application key to the second application by the SAT, whereby the second application executing on the electronic device establishes a communication session with a second application server via the second communication access network.

18. The method of claim 17 , wherein the first application key is generated by the SAT at least in part on a uniform resource identity (URI) of the first application server and the second application key is generated by the SAT at least in part on a URI of the second application server.

19. The method of claim 16 , wherein the first sensor is one of a temperature sensor, a humidity sensor, a magnetic sensor, a pressure sensor, a gas detection sensor, and a flow sensor.

20. The method of claim 16 , wherein the first application communicates with the first communication access network via a first communication interface of the electronic device and the second application communicates with the second communication access network via a second communication interface of the electronic device.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2022
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 061524/0569 →
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2019
From: KANT, NISHI; PACZKOWSKI, LYLE W.; ROOK, IVO
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 049178/0765 →
Cited By (3)
US 12,598,470 US 12,621,170 US 12,627,980