IP Library Granted Patent US 11,533,625
Granted Patent B2
US 11,533,625 · App. 16/816,723 · Granted Dec 20, 2022

Authentication method and network device

Inventors: Chris Loreskar (Cambridge, GB); Florent Joubert (Cambridge, GB)
Assignee: Trustonic Limited
H04W12/48H04L63/0442H04L63/104H04W8/183H04W12/037H04W12/0431H04W12/069H04W12/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,533,625
App. No.
16/816,723
Granted
Dec 20, 2022
Kind
B2
Abstract

An authentication method is disclosed, the method comprising: receiving at least one request for an action in relation to an electronic device, wherein performance of the action requires verification of an association of a group of IDs specified by the request; verifying, via cryptographic verification, whether the group of IDs specified by the request match a cryptographically attested group of IDs associated with the electronic device, to determine whether the at least one request for an action is an authentic request; and, having determined the at least one request for an action is an authentic request, approving the at least one request, wherein the group of IDs comprises at least an Integrated Circuit Card Identifier (ICC ID) of a Subscriber Identity Module (SIM) of the electronic device and a device identifier associated with the electronic device.

Claims (29)

1. A method comprising:

receiving at least one request for an action in relation to an electronic device, wherein performance of the action requires verification of binding between a group of identifiers (IDs) specified by the request;

verifying, via cryptographic verification using a public key, whether the binding of a group of IDs specified by the request match a cryptographically attested bound group of IDs associated with the electronic device, wherein the cryptographically attested bound group of IDs is signed with a device key of the electronic device or a key derived from the device key of the electronic device, to determine whether the at least one request for an action is an authentic request; and,

having determined the at least one request for an action is an authentic request, approving the at least one request,

wherein the device key is a private key and the group of IDs comprises at least an Integrated Circuit Card Identifier (ICC ID) of a Subscriber Identity Module (SIM) of the electronic device and a device identifier associated with the electronic device.

2. A method according to claim 1 , wherein verifying whether the at least one request for an action is an authentic request comprises verifying by a public key associated with a private key of the electronic device.

3. A method according to claim 1 , wherein the device identifier associated with the electronic device comprises at least one of:

an identifier associated with a trusted execution environment (TEE) provided by the electronic device;

an International Mobile Equipment Identity (IMEI); and,

a media access control (MAC) address.

4. A method according to claim 1 , wherein the group of IDs comprises at least one of an International Mobile Subscriber Identity (IMSI) and a Temporary Mobile Subscriber Identity (TMSI).

5. A method according to claim 1 , wherein verifying whether the at least one request for an action is an authentic request comprises:

looking up, in a database of associations, the group of IDs specified by the at least one request.

6. A method according to claim 1 , wherein the action in the at least one request for an action comprises setting a user selected authentication step for use in an action with user selected data.

7. A method according to claim 6 , further comprising:

verifying an authenticity of a future request based on the user selected authentication step.

8. A network device comprising processing circuitry configured to:

receive at least one request for an action in relation to an electronic device, wherein performance of the action requires verification of binding between a group of identifiers (IDs) specified by the request;

verify, via cryptographic verification using a public key, whether the binding of a group of IDs specified by the request match a cryptographically attested bound group of IDs associated with the electronic device, wherein the cryptographically attested bound group of IDs is signed with a device key of the electronic device or a key derived from the device key of the electronic device, to determine whether the at least one request for an action is an authentic request; and,

approve the at least one request, having determined the at least one request for an action is an authentic request,

wherein the device key is a private key and the group of IDs comprises at least an Integrated Circuit Card Identifier (ICC ID) of a Subscriber Identity Module (SIM) of the electronic device and a device identifier associated with the electronic device.

9. A network device according to claim 8 , wherein the cryptographic verification comprises verification by a public key associated with a private key of the electronic device.

10. A network device according to claim 8 , wherein the device identifier associated with the electronic device comprises at least one of:

an identifier associated with a trusted execution environment (TEE) provided by the electronic device;

an International Mobile Equipment Identity (IMEI); and

a media access control (MAC) address.

11. A network device according to claim 8 , wherein the group of IDs comprises at least one of an International Mobile Subscriber Identity (IMSI) and a Temporary Mobile Subscriber Identity (TMSI).

12. A network device according to claim 8 , wherein the cryptographic verification comprises a look up in a database of associations of the group of IDs specified by the at least one request.

13. A network device according to claim 8 , wherein the action in the at least one request for an action comprises setting a user selected authentication step for use in an action with user selected data.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2026
From: TT SECURE PLATFORM LIMITED
To: QUALCOMM TECHNOLOGIES, INC.
Reel/Frame 075332/0723 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2026
From: TRUSTONIC LIMITED
To: TT SECURE PLATFORM LIMITED
Reel/Frame 075325/0627 →
CHANGE OF ASSIGNEE ADDRESS Recorded Apr 14, 2023
From: TRUSTONIC LIMITED
To: TRUSTONIC LIMITED
Reel/Frame 064025/0775 →
CHANGE OF ASSIGNEE ADDRESS Recorded Nov 3, 2020
From: TRUSTONIC LIMITED
To: TRUSTONIC LIMITED
Reel/Frame 054283/0428 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2020
From: LORESKAR, CHRIS; JOUBERT, FLORENT
To: TRUSTONIC LIMITED
Reel/Frame 052938/0495 →
Priority Claims (1)
GB 1903449 · Mar 13, 2019 · national
Continuity (1)
Related Publication 20200296581A1 · Sep 17, 2020
Cited By (1)
US 12,213,211