IP Library Granted Patent US 10,284,555
Granted Patent B2
US 10,284,555 · App. 15/282,995 · Granted May 7, 2019

User equipment credential system

Inventors: Silke Holtmanns (Klaukkala, FI); Pekka Laitinen (Helsinki, FI)
Assignee: Nokia Technologies Oy
H04L63/0876H04L9/0825H04L9/3226H04L63/08H04W12/04H04W12/06H04L63/06H04L63/0823H04L63/0869H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,284,555
App. No.
15/282,995
Granted
May 7, 2019
Kind
B2
Abstract

A user equipment in a communications system, the user equipment comprising: a memory arranged to store at least one identifier associated with the user equipment; a transceiver arranged to communicate with a node in the communication system, wherein the transceiver is arranged to receive the at least one identifier from the node in the communications system, wherein the at least one identifier is used by the user equipment to authenticate the user equipment to at least one further node in the communications system.

Claims (43)

1. An apparatus comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the processor, cause the apparatus to at least:

receive, from a first node, a first identifier associated with the apparatus, the first identifier comprising at least a private identifier, wherein the private identifier is known only to the apparatus, the first node, and a second node;

store the first identifier and a user identifier associated with the apparatus;

transmit to the second node an authorization request comprising the user identifier, wherein the authorization request is configured to initiate authentication of the apparatus at the second node;

receive, from the second node, a message comprising a second identifier used by the apparatus to authenticate the apparatus to a third node; and

process the message to generate a cryptographic key configured to encrypt communications between the apparatus and the third node, the cryptographic key based on the processed message and the private identifier.

2. The apparatus of claim 1 , wherein the user identifier is at least one of:

a user name;

a public cryptographic key;

an IP address; and

a caller line identification value.

3. The apparatus of claim 1 , wherein the private identifier is at least one of:

a password value; and

a private cryptographic key.

4. A method comprising:

receiving, by a user equipment and from a first node, a first identifier associated with the user equipment, the first identifier comprising at least a private identifier, wherein the private identifier is known only to the user equipment, the first node, and a second node;

storing, at the user equipment, the first identifier and a user identifier associated with the user equipment;

transmitting, from the user equipment and to the second node, an authorization request comprising the user identifier, wherein the authorization request is configured to initiate authentication of the user equipment at the second node;

receiving, by the user equipment and from the second node, a message comprising a second identifier used by the user equipment to authenticate the user equipment to a third node; and

processing, by the user equipment, the message to generate a cryptographic key configured to encrypt communications between the user equipment and the third node, the cryptographic key based on the processed message and the private identifier.

5. The method of claim 4 , wherein the user identifier is at least one of:

a user name;

a public cryptographic key;

an IP address; and

a caller line identification value.

6. The method of claim 4 , wherein the private identifier is at least one of:

a password value; and

a private cryptographic key.

7. An apparatus comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the processor, cause the apparatus to at least:

receive, from a user equipment, an authorization request comprising a user identifier associated with the user equipment;

transmit, to a second apparatus and upon receipt of the authorization request, a request for a user profile associated with the user equipment and an authentication vector, the authentication vector comprising a private identifier known only to the user equipment, the apparatus, and the second apparatus;

receive, from the second apparatus, the user profile and the authentication vector;

transmit, to the user equipment, a message comprising a first identifier used by the user equipment to authenticate the user equipment to a third apparatus;

generate a cryptographic key configured to encrypt communications between the user equipment and the third apparatus, the cryptographic key based on the message and the private identifier; and

transmit, to the third apparatus and in response to an authentication message received from the third apparatus, the cryptographic key.

8. The apparatus of claim 7 , wherein the user identifier is at least one of:

a user name;

a public cryptographic key;

an IP address; and

a caller line identification value.

9. The apparatus of claim 7 , wherein the private identifier is at least one of:

a password value; and

a private cryptographic key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2016
From: HOLTMANNS, SILKE; LAITINEN, PEKKA
To: NOKIA TECHNOLOGIES OY
Reel/Frame 039922/0462 →
Continuity (3)
Continuation 11819733 · Jun 28, 2007
Provisional Application 60818517 · Jul 6, 2006
Related Publication 20170026371A1 · Jan 26, 2017