IP Library › Granted Patent US 11,778,460
Granted Patent B2
US 11,778,460 · App. 16/604,714 · Granted Oct 3, 2023

Device and method for authenticating transport layer security communications

Inventor: Eric Johnson (Reston, VA)
Assignee: Giesecke+Devrient Mobile Security America, Inc.
H04W12/06H04L63/166H04W12/03H04W12/041H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,778,460
App. No.
16/604,714
Granted
Oct 3, 2023
Kind
B2
Abstract

A secure element of a mobile device receives a first authentication token, which may have an encrypted portion and a non-encrypted portion, from a network gateway device to which the mobile device is connected. The secure element determines whether the first authentication token is valid based on a sequence number included in the first authentication token. If the secure element determines that the first authentication token is valid, the secure element generates a second authentication token that indicates a result of an authentication operation performed by the secure element. The second authentication token is sent to the network gateway device. The secure element derives a pre-shared key using a key derivation function, where the pre-shared key is usable to establish a secure communication channel with the network gateway device.

Claims (70)

1. A system comprising:

a secure element of a mobile device; and

a network gateway device in communication with the mobile device via a first communication network,

wherein the secure element is configured to:

receive a first authentication token from the network gateway device,

determine whether the first authentication token is valid based on a sequence number included in an encrypted portion of the first authentication token, and

responsive to determining that the first authentication token is valid:

generate a second authentication token, wherein the second authentication token includes the sequence number from the first authentication token and indicates a status of an authentication operation performed by the secure element,

send the second authentication token to the network gateway device, and

derive a pre-shared key using a key derivation function, wherein the pre-shared key is usable to establish a secure communication channel with the network gateway device,

wherein the network gateway device is configured to generate the first authentication token to include the encrypted portion and a non-encrypted portion,

wherein the encrypted portion of the first authentication token includes a first text field, and

wherein the first text field in the encrypted portion of the first authentication token includes (i) an identity of the network gateway device, (ii) the sequence number, and (iii) a secret value.

2. The system of claim 1 , wherein the secure element is further configured to:

compare the sequence number included in the first authentication token to a current value of a sequence counter stored at the secure element; and

determine, based on the comparison, whether the sequence number is within a threshold difference from the current value of the sequence counter.

3. The system of claim 1 , wherein the secure element is further configured to:

responsive to determining, based on the sequence number, that the first authentication token is invalid:

generate a new sequence number, and

send a third authentication token to the network gateway device, the third authentication token including the new sequence number.

4. The system of claim 1 , wherein the secure element is further configured to:

derive the pre-shared key based on the secret value included in the first authentication token, an identity of the secure element, and the identity of the network gateway device.

5. The system of claim 1 ,

wherein the encrypted portion of the first authentication token includes (i) an identity of the secure element, (ii) the identity of the network gateway device, (iii) a random number generated by the network gateway device to bind the first authentication token to the second authentication token, (iv) the sequence number, and (v) the secret value.

6. The system of claim 5 , wherein the network gateway device is configured to:

generate the first authentication token to include the first text field and a second text field, the first text field included in the encrypted portion of the first authentication token, and the second text field included in the non-encrypted portion of the first authentication token.

7. The system of claim 1 , further comprising:

an authentication server in communication with the network gateway device via a second communication network, the authentication server configured to:

generate the first authentication token; and

send the first authentication token to the network gateway device.

8. A method comprising:

receiving, at a secure element of a mobile device, a first authentication token;

determining, at the secure element, whether the first authentication token is valid based on a sequence number included in an encrypted portion of the first authentication token;

responsive to determining that the first authentication token is valid:

generating, at the secure element, a second authentication token, wherein the second authentication token includes the sequence number from the first authentication token and indicates a result of an authentication operation performed by the secure element,

sending the second authentication token to a network gateway device, and

deriving, at the secure element, a pre-shared key using a key derivation function, wherein the pre-shared key is usable to establish a secure communication channel with the network gateway device,

wherein the first authentication token includes the encrypted portion and a non-encrypted portion,

wherein the encrypted portion of the first authentication token includes a first text field, and

wherein the first text field in the encrypted portion of the first authentication token includes (i) an identity of the network gateway device, (ii) the sequence number, and (iii) a secret value.

9. The method of claim 8 , wherein determining whether the first authentication token is valid based on the sequence number included in the first authentication token includes:

comparing the sequence number to a current value of a sequence counter stored at the secure element; and

determining, based on the comparison, whether the sequence number is within a threshold difference from the current value of the sequence counter.

10. The method of claim 8 , further comprising:

responsive to determining, based on the sequence number, that the first authentication token is invalid:

generating, at the secure element, a new sequence number; and

sending a third authentication token to the network gateway device, the third authentication token including the new sequence number.

11. The method of claim 8 , wherein the pre-shared key is derived at the secure element based on the secret value included in the first authentication token, an identity of the secure element, and the identity of the network gateway device.

12. The method of claim 8 , wherein the encrypted portion of the first authentication token includes (i) an identity of the secure element, (ii) the identity of the network gateway device, (iii) a random number generated by the network gateway device to bind the first authentication token to the second authentication token, (iv) the sequence number, and (v) the secret value.

13. The method of claim 12 , wherein the encrypted portion of the first authentication token includes the first text field and the non-encrypted portion of the first authentication device includes a second text field.

14. The method of claim 10 , wherein the new sequence number is included in an encrypted portion of the third authentication token.

15. A non-transitory, computer-readable medium or media storing computer-readable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving a first authentication token;

determining whether the first authentication token is valid based on a sequence number included in an encrypted portion of the first authentication token;

responsive to determining that the first authentication token is valid:

generating a second authentication token, wherein the second authentication token includes the sequence number from the first authentication token and indicates a result of an authentication operation performed by the one or more processors,

sending the second authentication token to a network gateway device, and

deriving a pre-shared key using a key derivation function, wherein the pre-shared key is usable to establish a secure communication channel with the network gateway device,

wherein the first authentication token includes the encrypted portion and a non-encrypted portion,

wherein the encrypted portion of the first authentication token includes a first text field, and

wherein the first text field in the encrypted portion of the first authentication token includes (i) an identity of the network gateway device, (ii) the sequence number, and (iii) a secret value.

16. The non-transitory, computer-readable medium or media of claim 15 , further storing computer-readable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

comparing the sequence number included in the first authentication token to a current value of a sequence counter; and

determining, based on the comparison, whether the sequence number is within a threshold difference from the current value of the sequence counter.

17. The non-transitory, computer-readable medium or media of claim 15 , further storing computer-readable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

responsive to determining, based on the sequence number, that the first authentication token is invalid:

generating a new sequence number; and

sending a third authentication token to the network gateway device, the third authentication token including the new sequence number.

18. The non-transitory, computer-readable medium or media of claim 15 , further storing computer-readable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

deriving the pre-shared key based on the secret value included in the first authentication token, an identity of the secure element, and the identity of the network gateway device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2019
From: JOHNSON, ERIC
To: GIESECKE+DEVRIENT MOBILE SECURITY AMERICA, INC.
Reel/Frame 050693/0309 →
Continuity (1)
Related Publication 20200382957A1 · Dec 3, 2020