IP Library › Granted Patent US 12,543,038
Granted Patent B2
US 12,543,038 · App. 18/512,457 · Granted Feb 3, 2026

Attestation process and system for wireless security

Inventors: James Leonard Mortensen (Lynnwood, WA); Boaz Kahana (Portland, OR); Kenneth Charles Taylor (Kirkland, WA); Sanket C. Pingle (Alpharetta, GA)
Assignee: Phoenix Technologies EMEA, Ltd.
H04W12/0431H04W12/041H04W12/10H04W12/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,543,038
App. No.
18/512,457
Granted
Feb 3, 2026
Kind
B2
Abstract

A method and system for providing a secured challenge and response for wireless/mobile/IOT network security that provides a secure provisioning of mobile equipment, a challenging of the mobile equipment and the verification of the mobile equipment by a network node to verify that mobile equipment is an authentic and secure device provisioned by the operator. The challenging including sealing a shared secret operator assigned symmetric equipment key in a secure enclave and transmitting the shared secret operator assigned symmetric equipment key to a subscriber identity module for generation of a cipher key and integrity for use in verification of the mobile equipment with a network node.

Claims (66)

1 . A non-transitory machine-readable storage medium storing one or more sequences of instructions for a secured challenge and response for wireless network security, which when executed by one or more processors, cause:

a mobile equipment to provision the mobile equipment with an operator, the provisioning comprising:

requesting, with a subscriber identity module associated with the mobile equipment, a shared secret operator assigned symmetric equipment key; and

providing, from the operator, the shared secret operator assigned symmetric equipment key, and storing the shared secret operator assigned symmetric equipment key within the subscriber identity module;

the subscriber identity module to challenge the mobile equipment, the challenging comprising:

generating an asymmetric key pair, the asymmetric key pair including an asymmetric encryption key and an asymmetric decryption key;

providing the shared secret operator assigned symmetric equipment key and the asymmetric encryption key to a secure enclave;

sealing the shared secret operator assigned symmetric equipment key and the asymmetric encryption key into the secure enclave;

generating a nonce with the subscriber identity module and transmitting the nonce to the secure enclave;

encrypting the shared secret operator assigned symmetric equipment key and the nonce with the asymmetric encryption key in the secure enclave to form a verification encryption package;

transmitting the verification encryption package to the subscriber identity module;

decrypting the verification encryption package with the asymmetric decryption key to release the shared secret operator assigned symmetric equipment key;

storing the shared secret operator assigned symmetric equipment key in the subscriber identity module;

generating, with the subscriber identity module, a cipher key and an integrity key from the shared secret operator assigned symmetric equipment key; and

storing the cipher key and an integrity key in the subscriber identity module.

2 . The non-transitory machine-readable storage medium of claim 1 , wherein the generating an asymmetric key pair is generating with the subscriber identity module.

3 . The non-transitory machine-readable storage medium of claim 2 , further comprising one or more sequences of instructions for a secured challenge and response for wireless network security, which when executed by one or more processors, cause:

verification of the mobile equipment, the verification comprising:

receiving, with the wireless module, a request for verification from a network node; and

in response to the request for verification, providing the cipher key and the integrity key from the subscriber identity module to the network node.

4 . The non-transitory machine-readable storage medium of claim 3 , wherein the cipher key and integrity key provided to the network node are encrypted.

5 . The non-transitory machine-readable storage medium of claim 3 , further comprising, permitting access by the mobile equipment to a wireless network associated with the network node upon verification of the cipher key and the integrity key from the subscriber identity module to the network node by the network node.

6 . The non-transitory machine-readable storage medium of claim 5 , wherein the access to the wireless network utilizes a 5G protocol.

7 . The non-transitory machine-readable storage medium of claim 3 , further comprising, restricting access to the wireless network by the mobile equipment to a wireless network associated with the network node if verification of the cipher key and the integrity key from the subscriber identity module to the network node is not verified by the network node.

8 . The non-transitory machine-readable storage medium of claim 3 , wherein the mobile equipment radio module includes a 5G radio access network driver.

9 . A computer system configured to provide a secured challenge and response for wireless network security, comprising:

a mobile equipment comprising one or more processors, the mobile equipment comprising one or more non-transitory computer-readable storage mediums storing one or more sequences of instructions, which when executed, cause:

a mobile equipment to provision the mobile equipment with an operator, the provisioning comprising:

requesting, with a subscriber identity module associated with the mobile equipment, a shared secret operator assigned symmetric equipment key;

and providing, from the operator, the shared secret operator assigned symmetric equipment key, and storing the shared secret operator assigned symmetric equipment key within the subscriber identity module; the subscriber identity module to challenge the mobile equipment, the challenging comprising: generating an asymmetric key pair, the asymmetric key pair including an asymmetric encryption key and an asymmetric decryption key; providing the shared secret operator assigned symmetric equipment key and the asymmetric encryption key to a secure enclave; sealing the shared secret operator assigned symmetric equipment key and the asymmetric encryption key into the secure enclave; generating a nonce with the subscriber identity module and transmitting the nonce to the secure enclave; encrypting the shared secret operator assigned symmetric equipment key and the nonce with the asymmetric encryption key in the secure enclave to form a verification encryption package; transmitting the verification encryption package to the subscriber identity module; decrypting the verification encryption package with the asymmetric decryption key to release the shared secret operator assigned symmetric equipment key; storing the shared secret operator assigned symmetric equipment key in the subscriber identity module; generating, with the subscriber identity module, a cipher key and an integrity key from the shared secret operator assigned symmetric equipment key; and

storing the cipher key and an integrity key in the subscriber identity module.

10 . The computer system of claim 9 , wherein the generating an asymmetric key pair is generating with the subscriber identity module.

11 . The computer system of claim 9 , further comprising one or more sequences of instructions for a secured challenge and response for wireless network security, which when executed, cause:

verification of the mobile equipment, the verification comprising:

receiving, with the wireless module, a request for verification from a network node; and

in response to the request for verification, providing the cipher key and the integrity key from the subscriber identity module to the network node.

12 . The computer system of claim 11 , wherein the cipher key and integrity key provided to the network node are encrypted.

13 . The computer system of claim 11 , further comprising, permitting access by the mobile equipment to a wireless network associated with the network node upon verification of the cipher key and the integrity key from the subscriber identity module to the network node by the network node.

14 . The computer system of claim 13 , wherein the access to the wireless network utilizes a 5G protocol.

15 . The computer system of claim 12 , further comprising, restricting access to the wireless network by the mobile equipment to a wireless network associated with the network node if verification of the cipher key and the integrity key from the subscriber identity module to the network node is not verified by the network node.

16 . The computer system of claim 11 , wherein the mobile equipment radio module includes a 5G radio access network driver.

17 . A method for providing a secured challenge and response for wireless/mobile/IOT network security, comprising:

provisioning a mobile equipment with an operator, the provisioning comprising:

requesting, with a subscriber identity module associated with the mobile equipment, a shared secret operator assigned symmetric equipment key; and

providing, from the operator, the shared secret operator assigned symmetric equipment key, and storing the shared secret operator assigned symmetric equipment key within the subscriber identity module;

challenging the mobile equipment with the subscriber identity module, the challenging comprising:

generating an asymmetric key pair, the asymmetric key pair including an asymmetric encryption key and an asymmetric decryption key;

providing the shared secret operator assigned symmetric equipment key and the asymmetric encryption key to a secure enclave;

sealing the shared secret operator assigned symmetric equipment key and the asymmetric encryption key into the secure enclave;

generating a nonce with the subscriber identity module and transmitting the nonce to the secure enclave;

encrypting the shared secret operator assigned symmetric equipment key and the nonce with the asymmetric encryption key in the secure enclave to form a verification encryption package;

transmitting the verification encryption package to the subscriber identity module;

decrypting the verification encryption package with the asymmetric decryption key to release the shared secret operator assigned symmetric equipment key;

storing the shared secret operator assigned symmetric equipment key in the subscriber identity module;

generating, with the subscriber identity module, a cipher key and an integrity key from the shared secret operator assigned symmetric equipment key; and

storing the cipher key and an integrity key in the subscriber identity module.

18 . The method of claim 17 , wherein the generating an asymmetric key pair is generating with the subscriber identity module.

19 . The method of claim 17 , wherein the provisioning further comprises:

verifying the mobile equipment, the verifying comprising:

receiving, with the wireless module, a request for verification from a network node; and

in response to the request for verification, providing the cipher key and the integrity key from the subscriber identity module to the network node.

20 . The method of claim 19 , wherein the cipher key and integrity key provided to the network node are encrypted.

21 . The method of claim 19 , further comprising, permitting access by the mobile equipment to a wireless network associated with the network node upon verification of the cipher key and the integrity key from the subscriber identity module to the network node by the network node.

22 . The method of claim 21 , wherein the access to the wireless network utilizes a 5G protocol.

23 . The method of claim 21 , further comprising, restricting access to the wireless network by the mobile equipment to a wireless network associated with the network node if verification of the cipher key and the integrity key from the subscriber identity module to the network node is not verified by the network node.

24 . The method of claim 21 , wherein the mobile equipment radio module includes a 5G radio access network driver.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2023
From: MORTENSEN, JAMES LEONARD; KAHANA, BOAZ; TAYLOR, KENNETH CHARLES; PINGLE, SANKET C.
To: PHOENIX TECHNOLOGIES EMEA LTD.
Reel/Frame 065598/0412 →
Continuity (1)
Related Publication 20250168629A1 · May 22, 2025
References Cited (23)
US 7957533B2 · Patel · 2011 [cited by examiner]
US 8296836B2 · Kolesnikov · 2012 [cited by examiner]
US 8379854B2 · Patel · 2013 [cited by examiner]
US 8645695B2 · Buckley · 2014 [cited by examiner]
US 10958631B2 · Fransen · 2021 [cited by examiner]
US 11405190B2 · Goller · 2022 [cited by examiner]
US 20070042754A1 · Bajikar · 2007 [cited by examiner]
US 20140219447A1 · Park · 2014 [cited by examiner]
US 20150341791A1 · Yang et al. · 2015 [cited by applicant]
US 20170093565A1 · Yang · 2017 [cited by examiner]
US 20190174313A1 · Fransen · 2019 [cited by examiner]
US 20220231840A1 · Yang et al. · 2022 [cited by applicant]
US 20220399993A1 · Yang et al. · 2022 [cited by applicant]
US 20250168629A1 · Mortensen · 2025 [cited by examiner]
CN 102150446A · 2011 [cited by examiner]
CN 112822018A · 2021 [cited by examiner]
CN 117527386A · 2024 [cited by examiner]
EP 4231189A1 · 2023 [cited by examiner]
WO 2017082966A1 · 2017 [cited by applicant]
WO WO2020148397A1 · 2020 [cited by examiner]
WO WO2025056431A1 · 2025 [cited by examiner]
PCT Written Opinion of the International Search Authority and International Search Report; 6 pgs., Mar. 7, 2025. [cited by applicant]
“5G; Security architecture and procedures for 5G System (3GPP TS 33.501 version 16.3.0 Release 16)”; ETSI TS 133 501 V16.3.0 (Aug. 2020); 251 pgs. [cited by applicant]