IP Library › Granted Patent US 12,375,911
Granted Patent B2
US 12,375,911 · App. 18/414,992 · Granted Jul 29, 2025

Secure provisioning for wireless local area network technologies

Inventors: Jordan Alexander (Kennesaw, GA); Robert Holden (Allen, TX); Jeffrey Martin Bartlett (Dallas, TX)
Assignees: AT&T Intellectual Property I, L.P.; AT&T Mobility II LLC
H04W12/0471H04W4/80H04W8/183H04W12/037H04W12/041H04W48/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,911
App. No.
18/414,992
Granted
Jul 29, 2025
Kind
B2
Abstract

Cellular connections can be used to provision non-cellular devices such as internet-of-things (IOT) devices. For example, IoT devices can comprise Bluetooth, Wi-Fi, and cellular capabilities. However, the cellular capability can be used to provision the IoT devices using non-internet protocol data delivery to prevent security vulnerabilities. Data can be transmitted to the IoT device using core elements without using an IP stack. Thus, IoT device configurations and the keys can be provisioned over-the-air without the use of internet protocol data.

Claims (36)

1. A method, comprising:

receiving, by a cellular network module of a user equipment, from network equipment via a cellular network, cryptographic data, wherein a service capability exposure function obtains the cryptographic data from a carrier provisioning server and transmits the cryptographic data to the network equipment for transmission to the cellular network module, wherein the carrier provisioning server provides an interface between the service capability exposure function and a device management server, transmits the cryptographic data also to the device management server, and purges the cryptographic data after transmission thereof to the service capability exposure function and the device management server, and wherein the user equipment comprises a wireless local area network (WLAN) module for communications over a non-cellular network;

based on a request from the WLAN module, generating, by the cellular network module, a session key using the cryptographic data received via the cellular network;

communicating, by the cellular network module, the session key to a processing system for transmission to the WLAN module to enable the WLAN module to use the session key for communications over the non-cellular network; and

establishing, by the WLAN module, via the non-cellular network, an internet connection using the session key.

2. The method of claim 1 , wherein the cryptographic data comprises a cryptographic key, wherein the network equipment comprises a Mobility Management Element (MME), and wherein the service capability exposure function instructs the MME to transmit the cryptographic data to the cellular network module via non-Internet Protocol (IP) data delivery by way of network attached storage (NAS).

3. The method of claim 1 , wherein the internet connection is a secured internet connection, and wherein the carrier provisioning service manages issuance and rotation of various cryptographic data for provisioning end devices and interfaces the service capability exposure function and the device management server over a virtual private network (VPN).

4. The method of claim 1 , wherein the cryptographic data comprises a service set identifier associated with the non-cellular network.

5. The method of claim 1 , wherein receiving of the cryptographic data comprises receiving the cryptographic data using non-internet protocol data delivery.

6. The method of claim 1 , wherein the non-cellular network employs internet protocol data delivery.

7. The method of claim 1 , wherein the WLAN module comprises a Wi-Fi module.

8. A user equipment, comprising:

a first network component configured to communicate via a cellular network;

a second network component configured to communicate via a non-cellular network;

a processor; and

a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations, comprising:

receiving, by the first network component, from network equipment via the cellular network, key data, wherein a service capability exposure function obtains the key data from a carrier provisioning server and transmits the key data to the network equipment for transmission to the first network component, and wherein the carrier provisioning server provides an interface between the service capability exposure function and a device management server, transmits the key data also to the device management server, and purges the key data after transmission thereof to the service capability exposure function and the device management server;

based on a request from the second network component, generating, by the first network component, an internet protocol session key using the key data received via the cellular network;

delivering, by the first network component, the internet protocol session key to an internal processing unit for forwarding to the second network component to enable the second network component to use the internet protocol session key for communications over the non-cellular network; and

establishing, by the second network component, via the non-cellular network, an internet connection using the internet protocol session key.

9. The user equipment of claim 8 , wherein the key data comprises a pre-shared key, wherein the network equipment comprises a Mobility Management Element (MME), and wherein the service capability exposure function instructs the MME to transmit the key data to the first network component via non-Internet Protocol (IP) data delivery by way of network attached storage (NAS).

10. The user equipment of claim 8 , wherein the internet connection is a secured internet connection.

11. The user equipment of claim 8 , wherein the key data comprises a service set identifier associated with the non-cellular network.

12. The user equipment of claim 8 , wherein receiving the key data comprises receiving the key data using non-internet protocol data delivery.

13. The user equipment of claim 8 , wherein the non-cellular network employs internet protocol data delivery.

14. The user equipment of claim 8 , wherein the second network component comprises a Wi-Fi component.

15. A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processor of an internet-of-things device, facilitate performance of operations, comprising:

receiving, by a first module component of the internet-of-things device, from network equipment via a cellular network, key data, wherein a service capability exposure function obtains the key data from a carrier provisioning server and transmits the key data to the network equipment for transmission to the first module component, wherein the carrier provisioning server provides an interface between the service capability exposure function and a device management server, transmits the key data also to the device management server, and purges the key data after transmission thereof to the service capability exposure function and the device management server, and wherein the internet-of-things device comprises a second module component for communications over a non-cellular network;

based on a request from the second module component, generating, by the first module component, a session key using the key data received via the cellular network;

supplying, by the first module component, the session key to a processing unit for transmission to the second module component to enable the second module component to use the session key for communications over the non-cellular network; and

establishing, by the second module component, via the non-cellular network, a secure connection to a server using the session key.

16. The non-transitory machine-readable medium of claim 15 , wherein the key data comprises an encrypted key, wherein the network equipment comprises a Mobility Management Element (MME), and wherein the service capability exposure function instructs the MME to transmit the key data to the first module component via non-Internet Protocol (IP) data delivery by way of network attached storage (NAS).

17. The non-transitory machine-readable medium of claim 15 , wherein the secure connection is a secure internet connection.

18. The non-transitory machine-readable medium of claim 15 , wherein the key data comprises a service set identifier associated with the non-cellular network.

19. The non-transitory machine-readable medium of claim 15 , wherein receiving the key data comprises receiving the key data using non-internet protocol data delivery.

20. The non-transitory machine-readable medium of claim 15 , wherein the non-cellular network employs internet protocol data delivery.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2024
From: ALEXANDER, JORDAN; HOLDEN, ROBERT
To: AT&T MOBILITY II LLC
Reel/Frame 066232/0284 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2024
From: BARTLETT, JEFFREY MARTIN
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 066232/0325 →
Continuity (3)
Continuation 17453360 · Nov 3, 2021
Continuation 16699956 · Dec 2, 2019
Related Publication 20240187851A1 · Jun 6, 2024
References Cited (21)
US 9838390B2 · Zakaria · 2017 [cited by applicant]
US 10046228B2 · Tran et al. · 2018 [cited by applicant]
US 10681072B2 · Alfano et al. · 2020 [cited by applicant]
US 20100016001A1 · Yang · 2010 [cited by applicant]
US 20100332832A1 · Wu et al. · 2010 [cited by applicant]
US 20140079217A1 · Bai et al. · 2014 [cited by applicant]
US 20160192287A1 · Yang et al. · 2016 [cited by applicant]
US 20160366707A1 · Sirotkin · 2016 [cited by examiner]
US 20180167811A1 · Shi et al. · 2018 [cited by applicant]
US 20180309786A1 · Apelewicz et al. · 2018 [cited by applicant]
US 20180338242A1 · Li et al. · 2018 [cited by applicant]
US 20190116499A1 · Wifvesson et al. · 2019 [cited by applicant]
US 20190124508A1 · Watfa et al. · 2019 [cited by applicant]
US 20190253870A1 · Rönneke · 2019 [cited by examiner]
US 20190280865A1 · Tobias et al. · 2019 [cited by applicant]
US 20190281116A1 · Yang · 2019 [cited by examiner]
US 20200137721A1 · Chen et al. · 2020 [cited by applicant]
US 20200329440A1 · Alpert et al. · 2020 [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/699,956 dated Aug. 4, 2021, 16 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/699,956 dated Mar. 30, 2021, 22 pages. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; General Packet Radio Service (GPRS) enhancements for Evolved Universal Terrestrial Radio Access Network (E-UTRAN) access (R… [cited by applicant]