IP Library Granted Patent US 12,556,525
Granted Patent B2
US 12,556,525 · App. 18/558,317 · Granted Feb 17, 2026

Network supported authentication

Inventors: Miguel Angel Muñoz De La Torre Alonso (Madrid, ES); Alfonso De Jesus Perez Martinez (Madrid, ES); Rodrigo Alvarez Dominguez (Madrid, ES)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04L63/08H04L9/32H04W12/37
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,525
App. No.
18/558,317
Granted
Feb 17, 2026
Kind
B2
Abstract

Embodiments of the invention can relate to various methods for operating a network exposure entity ( 270 ) and/or a policy control entity in a wireless communications network ( 200 ), in which a data packet session can be provided between a service provider ( 300 ) and a user equipment ( 100 ), the methods comprising steps for enabling the wireless communications network ( 200 ) to take an active role in a multi-factor authentication procedure requested by the service provider ( 300 ). Further embodiments of the invention relate to respective network exposure entities ( 270 ) and/or policy control entities.

Claims (61)

1 . A method for operating a network exposure entity in a wireless communications network, the method comprising:

receiving, from a service provider, an external authentication request for the wireless communications network to execute an authentication of a user equipment with the service provider, wherein the external authentication request comprises:

an identifier of the user equipment, and

an authentication identifier indicating how to execute the authentication;

authorizing the external authentication request based on one or more external criteria, wherein the one or more external criteria comprise whether the user equipment is registered in the wireless communications network; and

transmitting to a policy control entity an internal authentication request configured to cause the wireless communications network to perform the authentication of the user equipment in accordance with the authentication identifier included in the external authentication request.

2 . The method of claim 1 , wherein:

the authentication identifier indicates an SMS-based authentication, and

the internal authentication request causes the wireless communications network to send an authentication SMS to the user equipment.

3 . The method of claim 2 , wherein each of the external authentication request, the internal authentication request, and the SMS also includes a security code for the authentication.

4 . The method of claim 2 further comprising:

receiving, from the policy control entity in response to the internal authentication request, an internal authentication response indicating successful delivery of the authentication SMS; and

transmitting, to the service provider in response to the external authentication request, an external authentication response indicating successful delivery of the authentication SMS.

5 . The method of claim 1 , wherein:

the external authentication request further comprises an identifier of the service provider;

the method further comprises, prior to receiving the external authentication request, receiving from the service provider a service registration request that includes a further identifier of a service provider; and

the one or more external criteria further comprise whether the identifier of the service provider received with the external authentication request corresponds to the further identifier of the service provider received with the service registration request.

6 . The method of claim 1 , wherein:

the method further comprises, prior to receiving the external authentication request, receiving from the service provider a user registration request that includes a further identifier of a user equipment; and

the one or more external criteria further comprise whether the identifier of the user equipment received with the external authentication request corresponds to the further identifier of a user equipment received with the user registration request.

7 . The method of claim 1 , wherein the identifier of the user equipment comprises one or more of the following: an IP address of the user equipment, and a phone number of the user equipment.

8 . A method for operating a network exposure entity in a wireless communications network, the method comprising:

receiving one or more of the following from a service provider, in association with an authentication of a user equipment:

a service registration request for registering with the wireless communications network, wherein the service registration request includes the following:

an identifier of the service provider, and

one or more application identifiers that identify respective one or more applications which can require authentication of the user equipment; and

a user registration request for registering one or more users with the wireless communications network, wherein the user registration request includes the following:

the identifier of the service provider, and

one or more identifiers of user equipment that can require authentication with the service provider,

wherein each identifier of a user equipment comprises one or more of the following: an IP address of the user equipment, and a phone number of the user equipment; and

transmitting one or more of the following to a subscriber database:

a service storage request that includes the following: the identifier of the service provider, and the one or more application identifiers; and

a user storage request that includes the following: the identifier of the service provider, and the one or more identifiers of user equipment.

9 . The method of claim 8 , wherein each of the user registration request and the user storage request also includes one or more application identifiers that identify respective applications which can require authentication of the user equipment.

10 . A method for operating a policy control entity in a wireless communications network, the method comprising:

receiving, from a network exposure entity, an internal authentication request for the wireless communications network to execute an authentication of the user equipment with the service provider;

authorizing the internal authentication request based on one or more internal criteria; and

based on authorizing the internal authentication request, transmitting to a message control entity a request to send an authentication message to the user equipment.

11 . The method of claim 10 , wherein the one or more internal criteria comprise whether the user equipment has an active data packet session in the wireless communications network.

12 . The method of claim 10 , wherein:

the internal authentication request comprises a phone number, and

the one or more internal criteria comprise whether the phone number corresponds to a phone number of the user equipment.

13 . The method of claim 10 , wherein:

the internal authentication request comprises an IP address, and

the one or more internal criteria comprise whether the IP address corresponds to an IP address of the user equipment.

14 . The method of claim 10 , wherein the one or more internal criteria comprise whether an association between at least two of the following has not changed with respect to a previous authentication:

International Mobile Equipment Identity of the user equipment, phone number of the user equipment, and

user equipment subscriber information for the wireless communications network.

15 . The method of claim 10 , wherein:

the method further comprises receiving, from a session control entity, an application identifier indicating execution of an application at the user equipment;

the internal authentication request comprises a further application identifier; and

the one or more internal criteria comprise whether the further application identifier received with the internal authentication request corresponds to the application identifier received from the session control entity.

16 . The method of claim 10 , wherein:

the method further comprises receiving, from a subscriber database, registration data comprising one or more application identifiers and one or more subscriber identifiers;

the internal authentication request comprises a further application identifier; and

the one or more internal criteria comprise whether the further application identifier received with the internal authentication request corresponds to any of the one or more application identifiers received from the subscriber database.

17 . The method of claim 10 , further comprising:

receiving from a session control entity a policy request associated with the user equipment;

retrieving from a subscriber database one or more application identifiers that identify respective one or more applications which can require authentication of the user equipment;

generating one or more policies for the user equipment, wherein the one or more indicate that execution of the one or more applications is to be notified to the wireless communications network; and

transmitting the one or more policies to a session control entity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2023
From: MUÑOZ DE LA TORRE, MIGUEL ANGEL; PEREZ MARTINEZ, ALFONSO DE JESUS; ALVAREZ DOMINGUEZ, RODRIGO
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 065408/0264 →
Priority Claims (1)
EP 21382470 · May 24, 2021 · regional
Continuity (1)
Related Publication 20240223547A1 · Jul 4, 2024
References Cited (17)
US 12204632B1 · Chauhan · 2025 [cited by examiner]
US 20150188907A1 · Khalid · 2015 [cited by examiner]
US 20190261260A1 · Dao · 2019 [cited by examiner]
US 20200068483A1 · Likar · 2020 [cited by examiner]
US 20210058784A1 · Kedalagudde · 2021 [cited by examiner]
US 20210273945A1 · Lakunishok · 2021 [cited by examiner]
US 20210329460A1 · Liao · 2021 [cited by examiner]
US 20220272538A1 · Christian · 2022 [cited by examiner]
US 20220360954A1 · Castellanos Zamora · 2022 [cited by examiner]
US 20230109272A1 · Ryu · 2023 [cited by examiner]
US 20240089710A1 · Rustagi · 2024 [cited by examiner]
WO 2020033905A1 · 2020 [cited by applicant]
“3GPP TS 23.203 V17.0.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Policy and charging control architecture (Release 17), Mar. 2021, pp. 1-267. [cited by applicant]
“3GPP TS 23.501 V17.0.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 17), Mar. 2021, pp. 1-489. [cited by applicant]
“3GPP TS 29.522 V17.0.0”, 3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Exposure Function Northbound APIs; Stage 3 (Release 17), Dec. 2020, pp. 1-168. [cited by applicant]
“3GPP TS 23.502 V17.1.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 17), Jun. 2021, pp. 1-692. [cited by applicant]
“3GPP TS 23.003 V17.1.0”, 3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Numbering, addressing and identification; (Release 17), Mar. 2021, pp. 1-143. [cited by applicant]