IP Library Granted Patent US 11,539,681
Granted Patent B2
US 11,539,681 · App. 16/721,153 · Granted Dec 27, 2022

Network supporting two-factor authentication for modules with embedded universal integrated circuit cards

Inventor: John A. Nix (Evanston, IL)
Assignee: Network-1 Technologies, Inc.
H04L63/08H04B1/3816H04L9/0819H04L9/0869H04L9/3271H04L63/0428H04L63/0435H04L63/06H04L63/062H04L63/101H04W4/70H04W12/06H04W12/35
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,539,681
App. No.
16/721,153
Granted
Dec 27, 2022
Kind
B2
Abstract

A network with a set of servers can support authentication from a module, where the module includes an embedded universal integrated circuit card (eUICC). The network can send a first network module identity, a first key K, and an encrypted second key K for an eUICC profile to an eUICC subscription manager. The second key K can be encrypted with a symmetric key. The module can receive and activate the eUICC profile, and the network can authenticate the module using the first network module identity and the first key K. The network can (i) authenticate the user of the module using a second factor, and then (ii) send the symmetric key to the module. The module can decrypt the encrypted second key K using the symmetric key. The network can authenticate the module using the second key K. The module can comprise a mobile phone.

Claims (24)

1. A computer system comprising:

(a) one or more processors; and

(b) one or more non-transitory computer-readable media operatively connected to the one or more processors and having stored thereon instructions that, when executed by the one or more processors, cause the computer system to perform a method of:

(1) receiving, by the computer system from a mobile device which includes an embedded universal integrated circuit card (eUICC), (i) a message including an eUICC identity and (ii) an eUICC public key corresponding to an eUICC private key;

(2) generating, by the computer system, an eUICC subscription manager private key and an eUICC subscription manager public key;

(3) deriving, by the computer system, a profile key using an elliptic curve Diffie Hellman (ECDH) key exchange with the eUICC subscription manager private key and the eUICC public key, wherein the profile key is configured to be separately derived, by the eUICC, using the eUICC subscription manager public key and the eUICC private key;

(4) encrypting, by the computer system with the profile key, a first portion of an eUICC profile, wherein the first portion comprises network parameters associated with a mobile network operator;

(5) before step (1), encrypting, by the computer system with a symmetric key, a second portion of the eUICC profile comprising a subscriber identity and a key K, wherein the second portion is distinct from the first portion; and

(6) sending, by the computer system to the mobile device and using transport layer security, the eUICC profile comprising (i) the encrypted first portion of the eUICC profile, (ii) the encrypted second portion of the eUICC profile, and (iii) a plaintext profile identity.

2. The computer system of claim 1 , the method further comprising:

(7) after authenticating a user associated with the mobile device, sending, by the computer system to the mobile device, the symmetric key, wherein the symmetric key is configured to decrypt the second portion of the eUICC profile.

3. The computer system of claim 1 , wherein the network parameters comprise a list of numbers associated with the mobile network operator.

4. The computer system of claim 1 , wherein the network parameters comprise identification information for the mobile network operator.

5. The computer system of claim 1 , wherein the computer system performs step (5) before step (4).

6. The computer system of claim 1 , wherein the computer system communicates with the mobile device using a wireless network comprising a collection of base stations and licensed radio spectrum.

7. The computer system of claim 1 , wherein the method further comprises receiving, by the computer system, a response value for authenticating the mobile device, wherein the response value is generated using the key K.

8. The computer system of claim 1 , the method further comprising, in step (1), receiving a digital signature for at least the eUICC identity and the eUICC public key, wherein the computer system verifies the digital signature.

9. The computer system of claim 2 , wherein the method further comprises sending, by the computer system to the mobile device, a ciphertext for the symmetric key, wherein the computer system generates the ciphertext using at least the eUICC public key.

10. The computer system of claim 1 , wherein the subscriber identity comprises an International Mobile Subscriber Identity (IMSI).

11. The computer system of claim 1 , wherein the mobile device comprises at least one of a wireless handset, a cellular phone, a smartphone, a tablet computer, a laptop, a tracking device, and a circuit board with a radio.

12. The computer system of claim 2 , wherein the method further comprises sending, by the computer system, the symmetric key before sending the encrypted second portion of the eUICC profile.

13. The computer system of claim 2 , wherein the computer system authenticates the user by (i) storing identification information for the user in a database, and (ii) verifying the identification information received from the user.

14. The computer system of claim 7 , wherein the computer system generates the response value for an authentication vector with the key K.

15. The computer system of claim 1 , wherein the mobile device (i) downloads the eUICC subscription manager public key and (ii) mutually derives the profile key using the ECDH key exchange with the eUICC subscription manager public key and the eUICC private key.

Assignments (4)
CHANGE OF ADDRESS Recorded Sep 10, 2025
From: NETWORK-1 TECHNOLOGIES, INC.
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 072827/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2020
From: M2M AND IOT TECHNOLOGIES, LLC
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 051782/0198 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2020
From: VOBAL TECHNOLOGIES, LLC
To: NIX, JOHN A.
Reel/Frame 051586/0708 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2020
From: NIX, JOHN
To: M2M AND IOT TECHNOLOGIES, LLC
Reel/Frame 051545/0861 →
Continuity (4)
Continuation 16271455 · Feb 8, 2019
Continuation 15162292 · May 23, 2016
Continuation 14139419 · Dec 23, 2013
Related Publication 20200127991A1 · Apr 23, 2020
Cited By (1)
US 12,474,466