IP Library › Granted Patent US 12,543,039
Granted Patent B2
US 12,543,039 · App. 18/336,948 · Granted Feb 3, 2026

Authentication management method for non-3GPP access of a UE device to a 5G network

Inventors: Marouane Balmakhtar (Fairfax, VA); Lyle W. Paczkowski (Mission Hills, KS)
H04W12/06H04W12/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,543,039
App. No.
18/336,948
Granted
Feb 3, 2026
Kind
B2
Abstract

A core network server for defining authentication credentials and authenticating a wireless communication device according to WIFI communication protocols includes a central processing unit (CPU) and a non-transitory memory comprising executable instructions that when executed by the CPU, causes the core network server to receive an encrypted authentication request from a wireless communication device; send the encrypted authentication request to an authentication server based on one or more attributes in the encrypted authentication request; receive an indicator of a specialized network slice associated with the wireless communication device based on sending the encrypted authentication request; communicate authentication messages to the wireless communication device according to one or more network functions of the specialized network slice; and authenticate the wireless communication device according to the specialized network slice responsive to communicating the authentication messages.

Claims (61)

1 . A method for defining authentication credentials and authenticating a wireless communication device according to WIFI communication protocols, comprising:

obtaining, at a wireless communication device, a decentralized identity (DID) from one or more of wireless communication-device attributes and user attributes;

sending, by the wireless communication device, the DID to a data registry;

sending, by the wireless communication device, an encrypted authentication request to a core network server, wherein the encrypted authentication request comprises one or more of the DID, a communication device identifier, and the domain name;

receiving, by the data registry, the DID from the wireless communication device;

storing, by the data registry, the DID;

receiving, by the core network server, the encrypted authentication request from the wireless communication device;

sending, by the core network server, the encrypted authentication request to an authentication server based on one or more attributes in the encrypted authentication request;

determining, by the authentication server, a specialized network slice associated with the wireless communication device responsive to receiving the encrypted authentication request;

communicating, by the authentication server, authentication messages to the wireless communication device according to one or more network functions of the specialized network slice; and

authenticating, by the authentication server, the wireless communication device according to the specialized network slice responsive to communicating the authentication messages.

2 . The method of claim 1 , further comprising:

receiving, by the wireless communication device, a software stack from an onboarding server, wherein the software stack comprises one or more software components;

establishing, by the wireless communication device, a secure connection between the wireless communication device and the core network server using one or more elements of the software stack; and

sending, by the wireless communication device, the encrypted authentication request using the secure connection.

3 . The method of claim 1 , further comprising:

obtaining, by the core network server, a domain name from the encrypted authentication request; and

sending, by the core network server, the encrypted authentication request to the authentication server of a cellular network operator associated with the core network server when the domain name indicates the wireless communication device is a subscriber to the cellular network operator.

4 . The method of claim 1 , further comprising:

obtaining, by the core network server, a domain name from the encrypted authentication request; and

sending, by the core network server, the encrypted authentication request to the authentication server of an enterprise associated with the wireless communication device when the domain name indicates the wireless communication device is provisioned by the enterprise.

5 . The method of claim 2 , further comprising sending, by the wireless communication device, the encrypted authentication request over a virtual private network (VPN) connection.

6 . The method of claim 2 , further comprising:

sending, by the authentication server, a client verification request comprising the DID to the data registry; and

receiving, by the authentication server, a client verification response from the data registry responsive to sending the client verification request.

7 . The method of claim 6 , wherein the client verification response indicates whether the wireless communication device is registered to an enterprise and the specialized network slice assigned to the wireless communication device.

8 . A system for defining authentication credentials and authenticating a wireless communication device according to WIFI communication protocols, comprising:

a wireless communication device configured to:

obtain a decentralized identity (DID) from one or more of communication-device attributes and user attributes,

send the DID to a data registry, and

send an encrypted authentication request to a core network server;

the data registry coupled to the wireless communication device and configured to:

receive the DID from the wireless communication device, and store the DID;

the core network server coupled to the wireless communication device and the data registry and configured to:

receive the encrypted authentication request, and

send the encrypted authentication request to an authentication server based on one or more attributes in the encrypted authentication request; and

the authentication server coupled to the core network server and to the data registry and configured to:

determine a specialized network slice associated with the wireless communication device based on the encrypted authentication request,

communicate authentication messages to the wireless communication device according to one or more network functions of the specialized network slice, and

authenticate the wireless communication device according to the specialized network slice responsive to communicating the authentication messages.

9 . The system of claim 8 , wherein the wireless communication device is further configured to:

receive a software stack from an onboarding server, wherein the software stack comprises one or more software components,

establish a secure connection between the wireless communication device and the core network server using one or more elements of the software stack, and

send the encrypted authentication request using the secure connection.

10 . The system of claim 8 , wherein the core network server is configured to:

obtain a domain name from the encrypted authentication request, and

send the encrypted authentication request to the authentication server of a cellular network operator associated with the core network server when the domain name indicates the wireless communication device is a subscriber to the cellular network operator.

11 . The system of claim 8 , wherein the core network server is configured to:

obtain a domain name from the encrypted authentication request, and

send the encrypted authentication request to the authentication server of an enterprise associated with the communication device when the domain name indicates the wireless communication device is provisioned by the enterprise.

12 . The system of claim 11 , wherein the encrypted authentication request comprises one or more of the DID, a communication device identifier, and the domain name.

13 . The system of claim 8 , wherein the wireless communication device is configured to send the encrypted authentication request over a virtual private network (VPN) connection.

14 . The system of claim 8 , wherein the authentication server is configured to:

send a client verification request comprising the DID to the data registry, and

receive a client verification response from the data registry responsive to sending the client verification request.

15 . The system of claim 14 , wherein the client verification response indicates whether the wireless communication device is registered to an enterprise and the specialized network slice assigned to the wireless communication device.

16 . The system of claim 8 , wherein the wireless communication device is without a subscriber identification module (SIM).

17 . The system of claim 8 , wherein the wireless communication device comprises an Internet of Things (IoT) device.

18 . The method of claim 1 , further comprising, in response to the authentication, receiving, by the wireless communication device, controlled non-3GPP access to a core network for communicating data between the wireless communication device and the core network as determined by the specialized network slice.

19 . The method of claim 1 , wherein the wireless communication device is without a subscriber identification module (SIM).

20 . The method of claim 1 , wherein the wireless communication device comprises an Internet of Things (IoT) device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2023
From: BALMAKHTAR, MAROUANE; PACZKOWSKI, LYLE W.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 064015/0944 →
Continuity (1)
Related Publication 20240422535A1 · Dec 19, 2024
References Cited (61)
US 5764765A · Phoenix et al. · 1998 [cited by applicant]
US 6748083B2 · Hughes et al. · 2004 [cited by applicant]
US 7437081B2 · Mitchell et al. · 2008 [cited by applicant]
US 8855316B2 · Wiseman et al. · 2014 [cited by applicant]
US 9960465B2 · Dudley et al. · 2018 [cited by applicant]
US 10057058B2 · Murakami et al. · 2018 [cited by applicant]
US 10924930B2 · Salkintzis · 2021 [cited by examiner]
US 11431510B1 · Stapleton · 2022 [cited by applicant]
US 20050138352A1 · Gauvreau et al. · 2005 [cited by applicant]
US 20050221759A1 · Spadafora et al. · 2005 [cited by applicant]
US 20070065154A1 · Luo et al. · 2007 [cited by applicant]
US 20070076884A1 · Wellbrock et al. · 2007 [cited by applicant]
US 20070195774A1 · Sherman et al. · 2007 [cited by applicant]
US 20110206204A1 · Sychev · 2011 [cited by applicant]
US 20110213979A1 · Wiseman et al. · 2011 [cited by applicant]
US 20120089666A1 · Goswami et al. · 2012 [cited by applicant]
US 20140010234A1 · Patel et al. · 2014 [cited by applicant]
US 20140068765A1 · Choi et al. · 2014 [cited by applicant]
US 20140133652A1 · Oshida et al. · 2014 [cited by applicant]
US 20160155327A1 · Schlienz et al. · 2016 [cited by applicant]
US 20160241396A1 · Fu et al. · 2016 [cited by applicant]
US 20160359626A1 · Fu et al. · 2016 [cited by applicant]
US 20160366094A1 · Mason et al. · 2016 [cited by applicant]
US 20170214525A1 · Zhao et al. · 2017 [cited by applicant]
US 20170230173A1 · Choi · 2017 [cited by applicant]
US 20170338952A1 · Hong et al. · 2017 [cited by applicant]
US 20180041494A1 · Quintero Cantero et al. · 2018 [cited by applicant]
US 20180060572A1 · Singleton et al. · 2018 [cited by applicant]
US 20180176091A1 · Yoon et al. · 2018 [cited by applicant]
US 20190036821A1 · Levy et al. · 2019 [cited by applicant]
US 20190260581A1 · Su et al. · 2019 [cited by applicant]
US 20190349392A1 · Wetterwald et al. · 2019 [cited by applicant]
US 20190387465A1 · Gandhewar et al. · 2019 [cited by applicant]
US 20200084222A1 · William et al. · 2020 [cited by applicant]
US 20200092095A1 · Yang et al. · 2020 [cited by applicant]
US 20200280854A1 · Kunz · 2020 [cited by examiner]
US 20210195689A1 · Pocha · 2021 [cited by examiner]
US 20210258787A1 · Bernsen · 2021 [cited by examiner]
US 20220046416A1 · Suzuki · 2022 [cited by examiner]
US 20220086145A1 · Lei · 2022 [cited by examiner]
US 20220330022A1 · Kolekar et al. · 2022 [cited by applicant]
US 20220360434A1 · Choi et al. · 2022 [cited by applicant]
US 20230236902A1 · Zhao et al. · 2023 [cited by applicant]
US 20230388289A1 · Li et al. · 2023 [cited by applicant]
US 20230388788A1 · Kunz · 2023 [cited by examiner]
US 20240292215A1 · Watfa · 2024 [cited by examiner]
US 20240333398A1 · Bush · 2024 [cited by applicant]
US 20240357349A1 · Balmakhtar · 2024 [cited by examiner]
US 20240373220A1 · Kweon · 2024 [cited by examiner]
US 20240381081A1 · Normann · 2024 [cited by examiner]
US 20250119734A1 · Balmakhtar et al. · 2025 [cited by applicant]
US 20250133487A1 · Targali · 2025 [cited by examiner]
EP 4478761A1 · 2024 [cited by applicant]
WO 2022009126A1 · 2022 [cited by applicant]
WO 2022175126A1 · 2022 [cited by applicant]
Foreign communication from related application—European Extended Search Report and Search Opinion dated Nov. 15, 2024 regarding EP Application No. 24178412.3 filed May 28, 2024, 11 pages. [cited by applicant]
Restriction Requirement dated May 21, 2025, U.S. Appl. No. 18/482,735, filed Oct. 6, 2023. [cited by applicant]
Balmakhtar, Marouane, et al., “Method for Device Security Gateway Function,” filed Oct. 6, 2023, U.S. Appl. No. 18/482,735. [cited by applicant]
Bertz, Lyle, et al., “Wireline Access Network Supporting User Equipment With Non-3rd Generation Partnership Project Inter-Working Function Interface,” filed Jul. 23, 2025, U.S. Appl. No. 19/278,649. [cited by applicant]
Bertz, Lyle, et al., “Virtual Private Network (VPN) Authentication for Devices,” filed Sep. 16, 2025, U.S. Appl. No. 19/330,602. [cited by applicant]
First Office Action dated Nov. 5, 2025, U.S. Appl. No. 18/482,735, filed Oct. 6, 2023. [cited by applicant]