IP Library › Granted Patent US 10,284,366
Granted Patent B2
US 10,284,366 · App. 14/347,663 · Granted May 7, 2019

Mobile communication system implementing integration of multiple logins of mobile device applications

Inventor: Yonathan Striem-Amit (Gedera, IL)
Assignee: ELTA SYSTEMS LTD.
H04L9/0844A63G31/16B66B3/008G06F21/32G09F19/22H04L9/006B64D2011/0061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,284,366
App. No.
14/347,663
Granted
May 7, 2019
Kind
B2
Abstract

In existing mobile implementations, there is a disconnect between the mobile device accessing the network and the applicative services inasmuch as the entity responsible for network access, such as the VPN Gateway, differs from the entity governing access to applications, such as email servers and SharePoint repositories. Therefore existing solutions typically employ two authentication methods. Of these, the first may be used to authenticate the mobile device to the VPN Gateway, while the second may be used to authenticate the mobile device towards the applications server. In order to facilitate strong authentication it is often desired to utilize a mechanism that uses or combines two different factors, e.g. “something you have” (such as but not limited to a smart card) and “something you know” (such as but not limited to a password). Most currently available mobile devices offer limited options to connect external devices to them, rendering most “Something you have” solutions irrelevant. For instance, there is no ability to connect a smart-card to a mobile phone.

Claims (50)

1. A mobile communication method including:

multiple login integration including secure integration of multiple login systems in mobile communication device applications; the integration including:

receiving, at an authentication broker, from an individual mobile application, a request to perform login to a corporate application,

using the authentication broker to verify user credentials; and using the authentication broker to send an encrypted authentication record to a login service running on the mobile device in a secure manner; and

in the mobile device, retrieving an encrypted authentication record sent by the authentication broker,

wherein the encrypted authentication record, once retrieved, is sent to a service dispatcher which decrypts the record to access a clear private key of the device,

wherein a basis for authentication is sent to the corporate application, and

wherein authentication is performed by software on the mobile device and wherein, when the application sends an authentication library a request to perform authentication, the Authentication Library responsively contacts the Authentication Broker which responsively sends the authentication record to the mobile device, encrypted using encryption coordinated between the mobile device and the Authentication Broker and wherein encryption of the Authentication record prevents unauthorized use of the authentication record because only the destined mobile device can decrypt the authentication record.

2. A method according to claim 1 , wherein the individual mobile application is defined by a user of an individual mobile communication device.

3. A method according to claim 1 , wherein the method is repeated for each application from among a plurality of such applications.

4. A method according to claim 3 , wherein said authentication record comprises username and password.

5. A method according to claim 1 , wherein the method is repeated for each authentication service from among a plurality of such authentication services.

6. A method according to claim 1 , wherein the authentication broker uses an encryption method coordinated with the mobile device to ensure only a destined mobile device can decrypt an encrypted authentication record sent by the authentication broker.

7. A method according to claim 1 , wherein architecture in the mobile device is configured to perform authentication, including: when a mobile communication device application requests to perform authentication, retrieving the encrypted authentication record sent by the authentication broker.

8. A method according to claim 7 , wherein the encrypted authentication record, once retrieved, is sent to a service dispatcher which decrypts the record to access a clear private key of the device.

9. A method according to claim 8 , wherein a basis for authentication is sent to the application.

10. A method according to claim 9 , wherein said basis for authentication comprises at least one mobile equipment hardware authentication parameter.

11. A method according to claim 9 , wherein, when the mobile device is created, a public key for the mobile device is sent to, and stored on, a Credential Management subsystem configured to introduce records into a Secure Repository of the Authentication Broker.

12. A method according to claim 11 , wherein a central server is provided that defines logic of authentication of each application in the cellular network being served by the server.

13. A method according to claim 11 , wherein, when the user is granted permissions to an application, the authentication information is encrypted by the user's public key and only the encrypted record is sent to the Authentication Broker.

14. A method according to claim 12 , wherein authentication process control comprises insertion of authentication records.

15. A method according to claim 12 , wherein authentication process control comprises enforcement of policies.

16. A method according to claim 11 , wherein a server is provided which has “single-sign on” functionality in conjunction with mobile authentication functionality.

17. A method according to claim 11 , wherein modules that control the authentication process reside in a central server, and are centrally managed.

18. A method according to claim 16 , wherein at least one secure mobile device includes functionality which uses PKI functionality as a basis for network authentication.

19. A method according to claim 18 , wherein said network authentication is compatible with smart-card authentication.

20. A method according to claim 11 , further comprising apparatus for managing sign-on and applicative authentication that utilizes strong encryption available in a secure smart-phone.

21. A method according to claim 11 , wherein the management of authentication for a plurality of applications in a manner is transparent to the user.

22. A method according to claim 10 , wherein said mobile equipment hardware authentication parameter comprises an IMEI parameter.

23. A method according to claim 12 , wherein authentication process control comprises modification of authentication records.

24. A method according to claim 17 , wherein an authentication record is maintained including application service for which the record is intended.

25. A method according to claim 11 , wherein a key from a mobile communication device is used to protect a completely different key used to authenticate the mobile communication device to an application server.

26. A method according to claim 10 , wherein said mobile equipment hardware authentication parameter comprises a SIM-card parameter.

27. A mobile communication system including:

a processor and memory configured for multiple login integration including secure integration of multiple login systems in mobile communication device applications;

the integration including:

receiving, at an authentication broker, from an individual mobile application, a request to perform login to a corporate application,

using the authentication broker to verify user credentials; and using the authentication broker to send an encrypted authentication record to a login service running on the mobile device in a secure manner; and

in the mobile device, retrieving an encrypted authentication record sent by the authentication broker,

wherein the encrypted authentication record, once retrieved, is sent to a service dispatcher which decrypts the record to access a clear private key of the device,

wherein a basis for authentication is sent to the corporate application, and

wherein authentication is performed by software on the mobile device and wherein, when the application sends an authentication library a request to perform authentication, the Authentication Library responsively contacts the Authentication Broker which responsively sends the authentication record to the mobile device, encrypted using encryption coordinated between the mobile device and the Authentication Broker and wherein encryption of the Authentication record prevents unauthorized use of the authentication record because only the destined mobile device can decrypt the authentication record.

28. A computer program product, comprising a non-transitory tangible computer readable medium having computer readable program code embodied therein, said computer readable program code adapted to be executed to implement a mobile communication method including:

multiple login integration including secure integration of multiple login systems in mobile communication device applications; the integration including:

receiving, at an authentication broker, from an individual mobile application, a request to perform login to a corporate application,

using the authentication broker to verify user credentials; and using the authentication broker to send an encrypted authentication record to a login service running on the mobile device in a secure manner; and

in the mobile device, retrieving an encrypted authentication record sent by the authentication broker,

wherein the encrypted authentication record, once retrieved, is sent to a service dispatcher which decrypts the record to access a clear private key of the device,

wherein a basis for authentication is sent to the corporate application, and

wherein authentication is performed by software on the mobile device and wherein, when the application sends an authentication library a request to perform authentication, the Authentication Library responsively contacts the Authentication Broker which responsively sends the authentication record to the mobile device, encrypted using encryption coordinated between the mobile device and the Authentication Broker and wherein encryption of the Authentication record prevents unauthorized use of the authentication record because only the destined mobile device can decrypt the authentication record.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER 14346663 PREVIOUSLY RECORDED ON REEL 036041 FRAME 0727. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 12, 2017
From: STRIEM-AMIT, YONATHAN
To: ELTA SYSTEMS LTD.
Reel/Frame 042234/0140 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2015
From: STRIEM-AMIT, YONATHAN
To: ELTA SYSTEMS LTD.
Reel/Frame 036041/0727 →
Priority Claims (1)
IL 215424 · Sep 27, 2011 · national
Continuity (1)
Related Publication 20140237248A1 · Aug 21, 2014
Cited By (1)
US 12,519,775