IP Library Granted Patent US 11,968,531
Granted Patent B2
US 11,968,531 · App. 17/825,322 · Granted Apr 23, 2024

Token, particularly OTP, based authentication system and method

Inventor: Shreyas Sangai (Pune, IN)
Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
H04W12/068
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,968,531
App. No.
17/825,322
Granted
Apr 23, 2024
Kind
B2
Abstract

A method for authenticating a mobile device of a user versus a third-party such that instead of a mobile phone number MSISDN of the mobile device, a Universal Unique User Identifier, U3I, assigned to the mobile device is used, in combination with a secure routing service server constructed to communicate with a third-party server and with an MNO server. The secure routing service server and the MNO server interact to translate the Universal Unique User Identifier, U3I, to the mobile phone number MSISDN so as to enable sending the token to the mobile device.

Claims (112)

1. A system for authenticating a mobile device of a user versus a third-party, the mobile device being assigned to a Mobile Network Operator MNO by a set of mobile subscriber data comprising a mobile phone number, Mobile Station Integrated Services Digital Number (MSISDN);

the system comprising:

(a) a third-party server constructed to receive from a requesting device an authentication request (REQ), requesting to authenticate the mobile device;

in reaction, send an authentication token One Time Password (OTP) to be received at the mobile device;

receive back the authentication token; and

upon successful receipt back of the authentication token (OTP), acknowledge the mobile device as authenticated;

(b) the mobile device;

(c) an MNO server of the Mobile Network Operator MNO (MNO 1 ) to which the mobile device is assigned; wherein:

(d) a secure routing service server constructed to communicate with the third-party server and with the MNO server;

(e) a Universal Unique User Identifier, U3I, assigned to the mobile device;

(f) the U3I of (e) being registered at the MNO server and assigned to the registered mobile phone number (MSISDN) of the user;

(g) the U3I of (e) being registered at the secure routing service server and assigned to the Mobile Network Operator MNO, wherein the secure routing service server doesn't provide of the user's mobile phone number (MSISDN);

(h) the authentication request (REQ) received at the third-party server comprising the U3I of (e);

(i) the third-party server being constructed to send the authentication token (OTP) and the U3I to the secure routing service server;

(j) the secure routing service server being constructed to receive from the third-party server the authentication token (OTP) and the U3I;

retrieve the Mobile Network Operator MNO (MNO 1 ) to which the U3I is assigned; and

send the authentication token (OTP) and the U3I to the MNO server of the retrieved MNO (MNO 1 );

(k) the MNO server constructed to receive from the secure routing service server the authentication token (OTP) and the U3I;

retrieve the mobile phone number (MSISDN) assigned to the U3I; and

send the authentication token (OTP) to the mobile device using the retrieved mobile phone number (MSISDN).

2. The system according to claim 1 , wherein the requesting device is the same device as the mobile device, or a device different from the mobile device.

3. The system according to claim 1 , wherein the Universal Unique User Identifier, U3I, and/or the subscriber data and the mobile phone number (MSISDN) are assigned to an Embedded Universal Integrated Circuit Card (eUICC) hosted in the mobile device.

4. A method for authenticating a mobile device of a user versus a third-party, the mobile device being assigned to a Mobile Network Operator MNO by a set of mobile subscriber data comprising a mobile phone number, Mobile Station Integrated Services Digital Number (MSISDN);

the method comprising:

(a) providing a third-party server, and at the third-party server:

receive from a requesting device an authentication request (REQ), requesting to authenticate the mobile device;

in reaction, send an authentication token One Time Password (OTP) to be received at the mobile device;

receive back the authentication token (OTP); and

upon successful receipt back of the authentication token (OTP), acknowledge the mobile device as authenticated;

(b) providing the mobile device;

(c) providing an MNO server of the Mobile Network Operator MNO (MNO 1 ) to which the mobile device is assigned;

wherein:

(d) a secure routing service server constructed to communicate with the third-party server and with the MNO server;

(e) a Universal Unique User Identifier, U3I, assigned to the mobile device;

(f) the U3I being registered at the MNO server and assigned to the registered mobile phone number (MSISDN) of the user;

(g) the U3I being registered at the secure routing service server and assigned to the Mobile Network Operator MNO (MNO 1 ), wherein the secure routing service server doesn't provide of the user's mobile phone number (MSISDN);

(h) the authentication (a) request received at the third-party server comprising the U3I;

wherein:

(i) by the third-party server, send the authentication token (OTP) and the U3I of (e) to the secure routing service server;

(j) by the secure routing service server:

receive from the third-party server the authentication token (OTP) and the U3I of (e);

retrieve a Mobile Network Operator MNO (MNO 1 ) to which the U3I is assigned; and

send the authentication token and the U3I to the MNO server of the retrieved INO (MNO 1 );

(k) by the MNO server:

receive from the secure routing service server the authentication token (OTP) and the U3I;

retrieve the mobile phone number (MSISDN) assigned to the U3I; and

send the authentication token (OTP) to the mobile device using the retrieved mobile phone number (MSISDN).

5. The method according to claim 4 , further comprising: (i) at the third-party server or instructed by the third-party server, generate the authentication token (OTP).

6. The method according to claim 4 , further comprising the steps:

(l) registering the third-party server to the secure routing service server; and upon step (j):

(j) at the secure routing service server: verify that the third-party server from which the authentication token (OTP) and the U3I are received is registered to the secure routing service server; and proceed to retrieve a Mobile Network Operator MNO and send the authentication token and the U3I to the MNO server of the retrieved MNO (MNO 1 ) only under the condition that the third-party server is registered.

7. The method according to claim 4 , wherein step (i) by the third-party server, sending the authentication token (OTP) and the U3I of (e) to the secure routing service server, is performed via a secure communication channel, an Hypertext Transfer Protocol Secure HTTPs channel, between the third-party server and the secure routing service server.

8. The method according to claim 4 , wherein the authenticating is performed on the occasion of taking over a software element offered on the third-party server for use by the mobile phone, the taking over of the software element being performed by: either downloading of the software element, an app, from the third-party server to the mobile device, or logging in to the software element, constructed to be run on the third-party server, by the mobile device;

the method further comprising the steps:

(1) registering the software element offered at the third-party server to the secure routing service server; and

upon step (j):

(2) at the secure routing service server: verify that the software element offered on the third-party server for which the authentication token (OTP) and the U3I are received is registered to the secure routing service server; and

proceed to retrieve the Mobile Network Operator MNO and send the authentication token and the U3I to the MNO server of the retrieved MNO (MNO 1 ) only under the condition that the software element, the app, offered on the third-party server is registered.

9. The method according to claim 8 , further comprising the steps:

(1) for registering, providing a secret Application Programming Interface (API) API key to the software element;

(2) upon step (j), by the software element, providing the secret API key to the secure routing service server; and

by the secure routing service server, verifying the secret API key provided by the software element.

10. The method according to claim 4 , wherein in step (a), the sub-step to send an authentication token (OTP) to be received at the mobile device is performed via a mobile network, via Short Message Service SMS; and/or

in step (a), the sub-step to receive from the requesting device the authentication request (REQ), requesting to authenticate the mobile device, is performed via a communication channel different from the mobile network, such that the mobile phone number MSISDN is not required for use of the communication channel; and/or

the sub-step to receive back the authentication token (OTP) is performed via a communication channel different from the mobile network, such that the mobile phone number MSISDN is not required for use of the communication channel.

11. A system for sending requested data from a third-party to a mobile device of a user, the mobile device being assigned to a Mobile Network Operator MNO by a set of mobile subscriber data comprising a mobile phone number, Mobile Station Integrated Services Digital Number (MSISDN);

the system comprising:

(a) a third-party server constructed to receive from a requesting device a data transfer request (REQ), requesting to transfer data to the mobile device;

in reaction, send the requested data to be received at the mobile device;

(b) the mobile device;

(c) an MNO server of the Mobile Network Operator MNO (MNO 1 ) to which the mobile device is assigned;

wherein:

(d) a secure routing service server constructed to communicate with the third-party server and with the MNO server;

(e) a Universal Unique User Identifier, U3I, assigned to the mobile device;

(f) the U3I of (e) being registered at the MNO server and assigned to the registered mobile phone number (MSISDN) of the user;

(g) the U3I of (e) being registered at the secure routing service server and assigned to the Mobile Network Operator MNO, wherein the secure routing service server doesn't provide of the user's mobile phone number (MSISDN);

(h) the data transfer request (REQ) received at the third-party server comprising the U3I of (e);

(i) the third-party server being constructed to send the requested data and the U3I to the secure routing service server;

(j) the secure routing service server being constructed to receive from the third-party server the requested data and the U3I;

retrieve the Mobile Network Operator MNO (MNO 1 ) to which the U3I is assigned; and

send the requested data and the U3I to the MNO server of the retrieved MNO (MNO 1 );

(k) the MNO server constructed to:

receive from the secure routing service server the requested data and the U3I;

retrieve the mobile phone number (MSISDN) assigned to the U3I; and

send the requested data to the mobile device using the retrieved mobile phone number (MSISDN).

12. The system according to claim 11 , wherein the Universal Unique User Identifier, U3I, and/or the subscriber data and the mobile phone number (MSISDN) are assigned to an Embedded Universal Integrated Circuit Card (eUICC) hosted in the mobile device.

13. A method for sending requested data from a third-party to a mobile device of a user, the mobile device being assigned to a Mobile Network Operator MNO by a set of mobile subscriber data comprising a mobile phone number, Mobile Station Integrated Services Digital Number (MSISDN);

the method comprising:

(a) providing a third-party server, and at the third-party server:

receive from a requesting device a data transfer request (REQ), requesting to transfer data to the mobile device;

in reaction, send the requested data to be received at the mobile device;

(b) providing the mobile device;

(c) providing an MNO server of the Mobile Network Operator MNO (MNO 1 ) to which the mobile device is assigned;

wherein:

(d) a secure routing service server constructed to communicate with the third-party server and with the MNO server;

(e) a Universal Unique User Identifier, U3I, assigned to the mobile device;

(f) the U3I being registered at the MNO server and assigned to the registered mobile phone number (MSISDN) of the user;

(g) the U3I being registered at the secure routing service server and assigned to the Mobile Network Operator MNO (MNO 1 ), wherein the secure routing service server doesn't provide of the user's mobile phone number (MSISDN);

(h) the data transfer request received at the third-party server comprising the U3I;

wherein:

(i) by the third-party server, send the requested data and the U3I of (e) to the secure routing service server;

(j) by the secure routing service server:

receive from the third-party server the requested data and the U3I of (e);

retrieve the Mobile Network Operator MINO (MNO 1 ) to which the U3I is assigned; and

send the requested data and the U3I to the MNO server of the retrieved MINO (MNO 1 );

(k) by the MNO server:

receive from the secure routing service server the requested data and the U3I;

retrieve the mobile phone number (MSISDN) assigned to the U3I; and

send the requested data to the mobile device using the retrieved mobile phone number (MSISDN).

14. The method according to claim 13 , wherein (h) the authentication (a) request or data transfer request received at the third-party server comprising the U3I is received from the mobile device;

the U3I is provided from the mobile device to the third-party server;

wherein: either the user enters the U3I to the mobile device manually for its transfer to the third-party server; or the U3I is retrieved by the mobile device from the mobile device, from an Embedded Universal Integrated Circuit Card (eUICC) hosted in the mobile device, for its transfer to the third-party server.

Assignments (3)
CHANGE OF NAME Recorded Jul 21, 2024
From: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
To: GIESECKE+DEVRIENT EPAYMENTS GMBH
Reel/Frame 068465/0537 →
NUNC PRO TUNC ASSIGNMENT Recorded Jul 21, 2024
From: GIESECKE+DEVRIENT EPAYMENTS GMBH
To: GIESECKE+DEVRIENT MOBILE SECURITY GERMANY GMBH
Reel/Frame 068037/0735 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2022
From: SANGAI, SHREYAS
To: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Reel/Frame 060027/0020 →
Priority Claims (1)
EP 21020281 · May 27, 2021 · regional
Continuity (1)
Related Publication 20220386123A1 · Dec 1, 2022