IP Library › Granted Patent US 12,113,892
Granted Patent B2
US 12,113,892 · App. 17/456,585 · Granted Oct 8, 2024

Device access authorization via connected user equipment

Inventors: Julian Desvignes (Tokyo, JP); Luiz Guilherme Mesquita Kimel Dos Santos (Tokyo, JP)
Assignee: RAKUTEN MOBILE, INC.
H04L9/0825H04L9/0869H04L9/3247H04L9/3263H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,113,892
App. No.
17/456,585
Granted
Oct 8, 2024
Kind
B2
Abstract

Device access authorization via connected user equipment is performed with a device including a controller, a memory in communication with the controller, the memory storing a device identifier, a registration service, and a limited access service, and a secure element in communication with the controller, the secure element storing a device authentication key and a registry certificate. The controller includes circuitry configured to transmit an authorization request to the user equipment, the authorization request including a request for authorization from a registry server, the device identifier, the user identifier, and the registry server challenge, receive an authorization response from the user equipment, the authorization response including an authorization confirmation and a registry server signature, verify the registry server signature using the registry certificate, and notify the user equipment of a limited access service in response to receiving the authorization confirmation and successfully verifying the registry server signature.

Claims (95)

1. A device comprising:

a controller;

a memory in communication with the controller, the memory storing a device identifier, a registration service, and a limited access service; and

a secure element in communication with the controller, the secure element storing a device authentication key and a registry certificate;

wherein the controller includes circuitry configured to:

notify a user equipment of a registration service,

receive a registration request from the user equipment, the registration request for permission to access the limited access service, the registration request having a user identifier,

generate a challenge for a registry server based on the device authentication key,

transmit an authorization request to the user equipment, the authorization request including a request for authorization from the registry server, the device identifier, the user identifier, and the challenge,

receive an authorization response from the registry server via the user equipment, the authorization response including an authorization confirmation and a registry server signature,

verify the registry server signature using the registry certificate, and

notify the user equipment of a limited access service in response to receiving the authorization confirmation and successfully verifying the registry server signature.

2. The device of claim 1 ,

wherein the memory is further configured to store a whitelist; and

wherein the circuitry is further configured to, in response to receiving the authorization confirmation and successfully verifying the registry server signature:

generate an offline key in the secure element associated with the user equipment identifier,

transmit a copy of the offline key to the user equipment, and

add the user equipment identifier to the whitelist.

3. The device of claim 2 , wherein the circuitry is further configured to:

receive an access request from the user equipment for accessing the limited access service, the access request including the user equipment identifier,

verify the user equipment identifier using the whitelist,

transmit a randomly generated string to the user equipment,

receive an encrypted string from the user equipment,

verify the encrypted string using the offline key and the randomly generated string, and

grant the access request to access the limited access service in response to successfully verifying the user equipment identifier and the encrypted string.

4. The device of claim 3 ,

wherein, in order to verify the user equipment identifier, the circuitry is further configured to

determine whether the user equipment identifier is in the whitelist; and

transmit a denial of access in response to determining that the user equipment identifier is not in the whitelist.

5. The device of claim 3 ,

wherein, in order to verify the encrypted randomly generated string, the circuitry is further configured to:

encrypt the randomly generated string using the offline key, and

determine whether the encrypted string received from the application matches the result of encrypting the randomly generated string; and

transmit a denial of access in response to determining that the encrypted string does not match the result of encrypting the randomly generated string.

6. The device of claim 1 ,

wherein the secure element is further configured to store a pairing key, and

wherein the circuitry is further configured to establish a secure communication tunnel with the user equipment using the pairing key before the notifying of the registration service.

7. The device of claim 6 , wherein the circuitry is further configured to establish the secure communication tunnel using a peer-to-peer communication protocol.

8. A method comprising:

notifying a user equipment of a registration service;

receiving a registration request from the user equipment, the registration request for permission to access the limited access service, the registration request having a user identifier;

generating a challenge for a registry server based on a device authentication key, the device authentication key accessed from a secure element;

transmitting an authorization request to the user equipment, the authorization request including a request for authorization from the registry server, the device identifier, the user identifier, and the challenge, wherein the device identifier is retrieved from a memory;

receiving an authorization response from the registry server via the user equipment, the authorization response including an authorization confirmation and a registry server signature;

verifying the registry server signature using a registry certificate, the registry certificate accessed from the secure element; and

notifying the user equipment of a limited access service in response to receiving the authorization confirmation and successfully verifying the registry server signature.

9. The method of claim 8 , further comprising, in response to receiving the authorization confirmation and successfully verifying the registry server signature:

generating an offline key in the secure element associated with the user equipment identifier,

transmitting a copy of the offline key to the application, and

adding the user equipment identifier to a whitelist, the whitelist accessed from the memory.

10. The method of claim 9 , further comprising:

receiving an access request from the user equipment for accessing the limited access service, the access request including the user equipment identifier,

verifying the user equipment identifier using the whitelist,

transmitting a randomly generated string to the user equipment,

receiving an encrypted string from the user equipment,

verifying the encrypted string using the offline key and the randomly generated string, and

granting the access request to access the limited access service, in response to successfully verifying the user equipment identifier and the encrypted string.

11. The method of claim 10 , wherein the verifying the user equipment identifier includes

determining whether the user equipment identifier is in the whitelist, and

transmitting a denial of access in response to determining that the user equipment identifier is not in the whitelist.

12. The method of claim 10 , wherein the verifying the encrypted randomly generated string includes

encrypting the randomly generated string using the offline key, and

determining whether the encrypted string received from the user equipment matches the result of encrypting the randomly generated string, and

transmitting a denial of access in response to determining that the encrypted string does not match the result of encrypting the randomly generated string.

13. The method of claim 8 , further comprising:

establishing a secure communication tunnel with the user equipment using a pairing key before the notifying of the registration service, the pairing key accessed from the secure element.

14. The method of claim 13 , further comprising establishing the secure communication tunnel using a peer-to-peer communication protocol.

15. A computer-readable storage medium including instructions executable by a controller of a user equipment to cause the controller to perform operations comprising:

notifying a user equipment of a registration service;

receiving a registration request from the user equipment, the registration request for permission to access the limited access service, the registration request having a user identifier;

generating a challenge for a registry server based on a device authentication key, the device authentication key accessed from a secure element;

transmitting an authorization request to the user equipment, the authorization request including a request for authorization from the registry server, the device identifier, the user identifier, and the challenge, wherein the device identifier is retrieved from a memory;

receiving an authorization response from the registry server via the user equipment, the authorization response including an authorization confirmation and a registry server signature;

verifying the registry server signature using a registry certificate, the registry certificate accessed from the secure element; and

notifying the user equipment of a limited access service in response to receiving the authorization confirmation and successfully verifying the registry server signature.

16. The computer-readable storage medium of claim 15 , wherein the operations further comprise, in response to receiving the authorization confirmation and successfully verifying the registry server signature:

generating an offline key in the secure element associated with the user equipment identifier,

transmitting a copy of the offline key to the application, and

adding the user equipment identifier to a whitelist, the whitelist accessed from the memory.

17. The computer-readable storage medium of claim 16 , wherein the operations further comprise:

receiving an access request from the user equipment for accessing the limited access service, the access request including the user equipment identifier,

verifying the user equipment identifier using the whitelist,

transmitting a randomly generated string to the user equipment,

receiving an encrypted string from the user equipment,

verifying the encrypted string using the offline key and the randomly generated string, and

granting the access request to access the limited access service, in response to successfully verifying the user equipment identifier and the encrypted string.

18. The computer-readable storage medium of claim 17 , wherein the verifying the user equipment identifier includes

determining whether the user equipment identifier is in the whitelist, and

transmitting a denial of access in response to determining that the user equipment identifier is not in the whitelist.

19. The computer-readable storage medium of claim 17 , wherein the verifying the encrypted randomly generated string includes

encrypting the randomly generated string using the offline key, and

determining whether the encrypted string received from the user equipment matches the result of encrypting the randomly generated string, and

transmitting a denial of access in response to determining that the encrypted string does not match the result of encrypting the randomly generated string.

20. The computer-readable storage medium of claim 15 , further comprising:

establishing a secure communication tunnel with the user equipment using a pairing key before the notifying of the registration service, the pairing key accessed from the secure element.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2021
From: DESVIGNES, JULIAN; MESQUITA KIMEL DOS SANTOS, LUIZ GUILHERME
To: RAKUTEN MOBILE, INC.
Reel/Frame 058391/0738 →
Continuity (2)
Provisional Application 63210955 · Jun 15, 2021
Related Publication 20220399996A1 · Dec 15, 2022
Cited By (1)
US 12,627,644