IP Library Granted Patent US 12,081,989
Granted Patent B2
US 12,081,989 · App. 17/583,561 · Granted Sep 3, 2024

Authentication method and terminal device

Inventors: Chris Loreskar (Cambridge, GB); Florent Joubert (Cambridge, GB)
Assignee: Trustonic Limited
H04W12/48H04L63/0442H04L63/104H04W8/183H04W12/037H04W12/0431H04W12/069H04W12/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,081,989
App. No.
17/583,561
Granted
Sep 3, 2024
Kind
B2
Abstract

An authentication method and terminal device obtain a device identifier associated with an electronic device and receive an Integrated Circuit Card Identifier (ICC ID) of a Subscriber Identity Module (SIM) of the electronic device. A group of IDs is cryptographically signed with a device key of the terminal device or a key derived from the device key. The group of IDs may comprise the device identifier and the ICC ID.

Claims (28)

1. A method comprising:

obtaining a device identifier associated with an electronic device;

receiving an Integrated Circuit Card Identifier (ICC ID) of a Subscriber Identity Module (SIM) of the electronic device;

cryptographically signing a group of IDs with a device key of the electronic device or a key derived from the device key, wherein the group of IDs comprises the device identifier and the ICC ID, wherein the device identifier comprises an identifier associated with a trusted execution environment (TEE) provided by the electronic device;

generating, within the TEE, a request to perform an action in relation to the electronic device and sending the request with the signed group of IDs;

wherein the device identifier associated with the electronic device comprises a media access control (MAC) address, and

wherein the group of IDs comprises at least one of an International Mobile Subscriber Identity (IMSI) and a Temporary Mobile Subscriber Identity (TMSI).

2. A method according to claim 1 , further comprising:

sending a signed group of IDs with at least one request for an action.

3. A method according to claim 2 , wherein the action in the at least one request for an action comprises setting a user selected authentication step for use in an action with user selected data.

4. A method according to claim 1 , further comprising:

sending the signed group of IDs to a database during a registration phase.

5. A method according to claim 1 , wherein the device key is a private key.

6. A method according to claim 1 , further comprising storing the cryptographically signed group of IDs within a secure memory protected by the TEE against access by untrusted code executed outside the TEE.

7. A terminal device comprising processing circuitry configured to:

obtain a device identifier associated with an electronic device;

receive an Integrated Circuit Card Identifier (ICC ID) of a Subscriber Identity Module (SIM) of the electronic device;

cryptographically sign a group of IDs with a device key of the electronic device, wherein the group of IDs comprises the device identifier and the ICC ID, wherein the device identifier comprises an identifier associated with a trusted execution environment (TEE) provided by the electronic device;

generate, within the TEE, a request to perform an action in relation to the electronic device and sending the request with the signed group of IDs;

wherein the device identifier associated with the electronic device comprises a media access control (MAC) address, and

wherein the group of IDs comprises at least one of an International Mobile Subscriber Identity (IMSI) and a Temporary Mobile Subscriber Identity (TMSI).

8. A terminal device according to claim 7 , wherein the processing circuitry is configured to:

send a signed group of IDs with at least one request for an action.

9. A terminal device according to claim 8 , wherein the action in the at least one request for an action comprises setting a user selected authentication step for use in an action with user selected data.

10. A terminal device according to claim 7 , wherein the processing circuitry is configured to:

send the signed group of IDs to a database during a registration phase.

11. A terminal device according to claim 7 , wherein the device key is a private key.

12. A terminal device according to claim 7 , wherein the processing circuitry is configured to store the cryptographically signed group of IDs within a secure memory protected by the TEE against access by untrusted code executed outside the TEE.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2026
From: TT SECURE PLATFORM LIMITED
To: QUALCOMM TECHNOLOGIES, INC.
Reel/Frame 075332/0723 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2026
From: TRUSTONIC LIMITED
To: TT SECURE PLATFORM LIMITED
Reel/Frame 075325/0627 →
CHANGE OF ASSIGNEE ADDRESS Recorded Apr 14, 2023
From: TRUSTONIC LIMITED
To: TRUSTONIC LIMITED
Reel/Frame 064025/0775 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2022
From: LORESKAR, CHRIS; JOUBERT, FLORENT
To: TRUSTONIC LIMITED
Reel/Frame 058759/0021 →
Priority Claims (1)
GB 1903449 · Mar 13, 2019 · national
Continuity (2)
Division 16816723 · Mar 12, 2020
Related Publication 20220150707A1 · May 12, 2022