IP Library Granted Patent US 11,108,773
Granted Patent B1
US 11,108,773 · App. 16/518,368 · Granted Aug 31, 2021

Mobile user authentication over WIFI using IPX networks

Inventor: Govardhan Reddy Dhani Reddy (Dublin, IE)
Assignee: Facebook, Inc.
H04L63/0876H04L9/32H04L63/0272H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,108,773
App. No.
16/518,368
Granted
Aug 31, 2021
Kind
B1
Abstract

A client device accesses an online system using an authentication process when it is connected to a public network and not a private network. The client device requests access using an authentication broker via the public network. The authentication broker determines an authentication system and transmits identification information for the client device to the authentication system via the private network. The authentication broker receives an authentication vector generated by the authentication system via the private network, and receives a verification response from the client device via the public network. The verification response corresponds to a verification challenge generated based on the authentication vector by the authentication broker. The authentication broker determines the client device is authorized to access the online system based on the authentication vector and verification response and transmits an authorization to the client device via the public network allowing access to the online system.

Claims (54)

1. A method comprising:

receiving, from a client device via a public network, an authentication request for the client device to access an online system, the authentication request comprising identification information for the client device;

determining a mobile network operator of a plurality of mobile network operators to authenticate the client device, the plurality of mobile network operators using an internetwork packet exchange protocol (IPX) to exchange information;

transmitting the identification information to the mobile network operator via a private network executing the IPX protocol and associated with the determined mobile network operator;

receiving, from the mobile network operator via the private network, an authentication vector, the authentication vector for identifying the client device having the identification information;

receiving, from the client device via the public network, a verification indicating that the client device has the identification information included in the authentication vector; and

in response to the verification that the client system has the identification information, transmitting, to the client device via the public network, an authentication for the client device to access the online system.

2. The method of claim 1 , wherein receiving the authentication request for the client device further comprises:

receiving, from a network access point connected to the client device via a local-area wireless network, the authentication request for the client device to access the online system.

3. The method of claim 1 , receiving the verification further comprises:

transmitting, to a network access point connected to the client device via a local-area wireless network, the verification request; and

receiving, from the access point connected to the client device via the local-area wireless network, the verification that the client system has the identification information.

4. The method of claim 1 , wherein receiving the verification further comprises:

generating a verification challenge, the verification challenge configured to verify the client device has the identification information, the verification challenge generated using the authentication vector received from the mobile network operator.

5. The method of claim 1 , wherein receiving the authentication request is in response to the client device determining a connectivity to the private network and the public network.

6. The method of claim 1 , wherein determining the mobile network operator is based on a cost of transmitting the authorization request to the mobile network operator via the private network.

7. The method of claim 1 , wherein determining the mobile network operator further comprises:

accessing an identifier for the client device from the identification information;

accessing a network code associated with the identifier, the network code indicating a particular mobile network operator of the plurality of mobile network operators; and

determining the mobile network operator is the particular mobile network operator associated with the network code.

8. The method of claim 1 , wherein determining the mobile network operator further comprises:

accessing an identifier associated with a user profile for the client device on the online system, the user profile indicating a particular mobile network operator of the plurality of mobile network operators; and

determining the mobile network operator is the particular network operator indicated by the user profile.

9. The method of claim 1 , wherein determining the mobile network operator further comprises:

determining, for each mobile network operator of the plurality of mobile network operators, a connectivity of the client device the mobile network operator; and

determining the mobile network operator based on the connectivities.

10. The method of claim 1 , wherein the identification information at least comprises information stored on a Subscriber Information Module (SIM) Card of the client device.

11. The method of claim 1 , wherein the client system cannot connect to the mobile network operator via the private network.

12. The method of claim 1 , wherein the private network operates using the internetwork packet exchange (IPX) protocol for communicating with the plurality of mobile network operators.

13. The method of claim 1 , wherein the mobile network operator is a mobile carrier and the private network is a mobile carrier network (MCN).

14. A computer program product comprising a non-transitory computer readable storage medium containing computer program code for:

receiving, from a client device via a public network, an authentication request for the client device to access an online system, the authentication request comprising identification information for the client device;

determining a mobile network operator of a plurality of mobile network operators to authenticate the client device, the plurality of mobile network operators using an internetwork packet exchange protocol (IPX) to exchange information;

transmitting the identification information to the mobile network operator via a private network executing the IPX protocol and associated with the determined mobile network operator;

receiving, from the mobile network operator via the private network, an authentication vector, the authentication vector for identifying the client device having the identification information;

receiving, from the client device via the public network, a verification indicating that the client device has the identification information included in the authentication vector; and

in response to the verification that the client system has the identification information, transmitting, to the client device via the public network, an authentication for the client device to access the online system.

15. The computer program product of claim 14 , wherein receiving the authentication request for the client device further comprises:

receiving, from a network access point connected to the client device via a local-area wireless network, the authentication request for the client device to access the online system.

16. The computer program product of claim 14 , receiving the verification further comprises: transmitting, to a network access point connected to the client device via a local-area wireless network, the verification request; and receiving, from the access point connected to the client device via the local-area wireless network, the verification that the client system has the identification information.

17. The computer program product of claim 14 , wherein determining the mobile network operator further comprises: accessing an identifier for the client device from the identification information; accessing a network code associated with the identifier, the network code indicating a particular mobile network operator of the plurality of mobile network operators: and determining the mobile network operator is the particular mobile network operator associated with the network code.

18. The computer program product of claim 14 , wherein determining the mobile network operator further comprises: accessing an identifier associated with a user profile for the client device on the online system, the user profile indicating a particular mobile network operator of the plurality of mobile network operators: and determining the mobile network operator is the particular network operator indicated by the user profile.

19. The computer program product of claim 15 , wherein determining the mobile network operator further comprises:

determining, for each mobile network operator of the plurality of mobile network operators, a connectivity of the client device to the mobile network operator; and

determining the mobile network operator based on the connectivities.

20. A system comprising:

one or more processors;

a datastore comprising a non-transitory computer-readable storage medium computer program code that, when executed by the one or more processors, cause the processors to execute a method for:

receiving, from a client device via a public network, an authentication request for the client device to access an online system, the authentication request comprising identification information for the client device;

determining a mobile network operator of a plurality of mobile network operators to authenticate the client device, the plurality of mobile network operators using an internetwork packet exchange protocol (IPX) to exchange information;

transmitting the identification information to the mobile network operator via a private network executing the IPX protocol and associated with the determined mobile network operator;

receiving, from the mobile network operator via the private network, an authentication vector, the authentication vector for identifying the client device having the identification information;

receiving, from the client device via the public network, a verification indicating that the client device has the identification information included in the authentication vector; and

in response to the verification that the client system has the identification information, transmitting, to the client device via the public network, an authentication for the client device to access the online system.

Assignments (2)
CHANGE OF NAME Recorded Nov 18, 2021
From: FACEBOOK, INC.
To: META PLATFORMS, INC.
Reel/Frame 058897/0824 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2019
From: DHANI REDDY, GOVARDHAN REDDY
To: FACEBOOK, INC.
Reel/Frame 049848/0895 →