IP Library Granted Patent US 11,882,442
Granted Patent B2
US 11,882,442 · App. 17/541,578 · Granted Jan 23, 2024

Handset identifier verification

Inventor: Chris Loreskar (Cambridge, GB)
Assignee: Trustonic Limited
H04W12/06H04L9/3247H04L63/0823H04L63/0876H04L63/0892H04L63/101H04W8/24H04W12/08H04W12/71H04W8/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,882,442
App. No.
17/541,578
Granted
Jan 23, 2024
Kind
B2
Abstract

A terminal device seeking access to a mobile network retrieves a handset identifier identifying the terminal device and a cryptographic key for proving an identity of the terminal device from storage circuitry of the terminal device. The terminal device generates signature information by signing a block of information including the handset identifier using the cryptographic key. During a network connection process for negotiating access to the mobile network with a network control device, the terminal device communicates the signature information to the network control device.

Claims (22)

1. A terminal device comprising:

storage circuitry to store a handset identifier identifying the terminal device and a cryptographic key for proving an identity of the terminal device;

processing circuitry to generate signature information by signing a block of information including the handset identifier using the cryptographic key; and

communication circuitry to communicate on a mobile network, wherein during a network connection process for negotiating access to the mobile network with a network control device, the communication circuitry is configured to communicate the signature information to the network control device, wherein

the signature information comprises information for verifying a binding between the handset identifier and the terminal device, and

during the network connection process for negotiating access to the mobile network with the network control device, the communication circuitry is configured to receive an indication from the network control device whether the terminal device is allowed to switch from a limited communication mode, in which a limited subset of network communication functionality including emergency calls only and handshaking for the handset identifier based on retrieval of the verification information is allowed, to a full communication mode in which communication functionality other than said limited subset is allowed, in dependence on whether the binding between the handset identifier and the terminal device allows the network control device to verify the terminal device as an authorized terminal device.

2. The terminal device according to claim 1 , wherein said block of information comprises a function of at least one freshness indicator shared between the network control device and the terminal device which varies between different requests for use of the mobile network.

3. The terminal device according to claim 2 , wherein said at least one freshness indicator comprises at least one nonce received at the terminal device.

4. The terminal device according to claim 1 , wherein the device has a hardware architecture providing a protected communication channel for protecting at least the cryptographic key between the storage circuitry, the processing circuitry and the communication circuitry.

5. The terminal device according to claim 1 , wherein the handset identifier comprises an International Mobile Equipment Identity (IMEI) number.

6. The terminal device according to claim 1 , wherein the network control device is a network operator device.

7. A method for a terminal device seeking access to a mobile network, the method comprising:

retrieving a handset identifier identifying the terminal device and a cryptographic key for proving an identity of the terminal device from storage circuitry of the terminal device;

generating signature information by signing a block of information including the handset identifier using the cryptographic key; and

during a network connection process for negotiating access to the mobile network with a network control device, communicating the signature information to the network control device, wherein

the signature information comprises information for verifying a binding between the handset identifier and the terminal device, and

during the network connection process for negotiating access to the mobile network with the network control device, an indication from the network control device is received whether the terminal device is allowed to switch from a limited communication mode, in which a limited subset of network communication functionality including emergency calls only and handshaking for the handset identifier based on retrieval of the verification information is allowed, to a full communication mode in which communication functionality other than said limited subset is allowed, in dependence on whether the binding between the handset identifier and the terminal device allows the network control device to verify the terminal device as an authorized terminal device.

8. The method according to claim 7 , wherein said block of information comprises a function of at least one freshness indicator shared between the network control device and the terminal device which varies between different requests for use of the mobile network.

9. The method according to claim 8 , wherein said at least one freshness indicator comprises at least one nonce received at the terminal device.

10. The method according to claim 7 , wherein the handset identifier comprises an International Mobile Equipment Identity (IMEI) number.

11. The method according to claim 7 , wherein the network control device is a network operator device.

12. A non-transitory, computer-readable storage medium storing a computer program for controlling a data processing apparatus to perform the method of claim 7 .

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2026
From: TT SECURE PLATFORM LIMITED
To: QUALCOMM TECHNOLOGIES, INC.
Reel/Frame 075332/0723 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2026
From: TRUSTONIC LIMITED
To: TT SECURE PLATFORM LIMITED
Reel/Frame 075325/0627 →
CHANGE OF ASSIGNEE ADDRESS Recorded Apr 14, 2023
From: TRUSTONIC LIMITED
To: TRUSTONIC LIMITED
Reel/Frame 064025/0775 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2021
From: LORESKAR, CHRIS
To: TRUSTONIC LIMITED
Reel/Frame 058280/0665 →
Priority Claims (1)
GB 1619918 · Nov 24, 2016 · national
Continuity (2)
Division 16346618
Related Publication 20220095107A1 · Mar 24, 2022