IP Library Granted Patent US 9,119,065
Granted Patent B2
US 9,119,065 · App. 14/097,077 · Granted Aug 25, 2015

Authentication in secure user plane location (SUPL) systems

Inventors: Philip Michael Hawkes (Warrimoo, AU); Andreas Klaus Wachter (Menlo Park, CA); Adrian Edward Escott (Reading, GB); Stephen William Edge (Escondido, CA)
Assignee: QUALCOMM Incorporated
H04W12/04H04L63/166H04W12/06H04L63/0823H04L63/205H04W4/02H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,119,065
App. No.
14/097,077
Granted
Aug 25, 2015
Kind
B2
Abstract

A particular method includes receiving, at a secure user plane location (SUPL) server, an indication from a mobile device of one or more transport layer security (TLS) cipher suites supported by the mobile device; determining whether the one or more TLS cipher suites include a TLS pre-shared key (TLS-PSK) cipher suite that is supported by the SUPL server; in response to determining whether the one or more TLS cipher suites include the TLS-PSK cipher suite that is supported by the SUPL server, performing a generic bootstrapping architecture (GBA)-based authentication process to authenticate the mobile device, or determining whether the SUPL server supports a certificate-based authentication method; and in response to determining that the SUPL server supports the certificate-based authentication method, performing the certificate-based authentication method that includes sending a server certificate to the mobile device and receiving a device certificate from the mobile device.

Claims (35)

1. A method comprising:

receiving, at a secure user plane location (SUPL) server, an indication from a mobile device of one or more transport layer security (TLS) cipher suites supported by the mobile device;

determining whether the one or more TLS cipher suites include a TLS pre-shared key (TLS-PSK) cipher suite that is supported by the SUPL server;

in response to determining that the one or more TLS cipher suites include the TLS-PSK cipher suite that is supported by the SUPL server, performing a generic bootstrapping architecture (GBA)-based authentication process to authenticate the mobile device; and

in response to determining that the one or more TLS cipher suites do not include a TLS-PSK cipher suite that is supported by the SUPL server, determining whether the SUPL server supports a certificate-based authentication method; and

in response to determining that the SUPL server supports the certificate-based authentication method, performing the certificate-based authentication method that includes sending a server certificate to the mobile device and receiving a device certificate from the mobile device.

2. The method of claim 1 , further comprising in response to determining that the SUPL server does not support the certificate-based authentication method, performing an alternative client authentication (ACA)-based authentication method when the mobile device is connected to a 3rd Generation Partnership Project (3GPP) network or a 3GPP2 network.

3. The method of claim 1 , wherein the certificate-based authentication method is independent of an access network used by the mobile device.

4. An apparatus comprising:

a processor; and

a memory coupled to the processor, wherein the memory is configured to store instructions; and

wherein the instructions are executable by the processor to:

receive, at a secure user plane location (SUPL) server, an indication from a mobile device of one or more transport layer security (TLS) cipher suites supported by the mobile device;

determine whether the one or more TLS cipher suites include a TLS pre-shared key (TLS-PSK) cipher suite that is supported by the SUPL server;

in response to determining that the one or more TLS cipher suites include the TLS-PSK cipher suite that is supported by the SUPL server, perform a generic bootstrapping architecture (GBA)-based authentication process to authenticate the mobile device; and

in response to determining that the one or more TLS cipher suites do not include a TLS-PSK cipher suite that is supported by the SUPL server, determine whether the SUPL server supports a certificate-based authentication method; and

in response to determining that the SUPL server supports the certificate-based authentication method, perform a certificate-based authentication process that includes sending a server certificate to the mobile device and receiving a device certificate from the mobile device.

5. The apparatus of claim 4 , wherein the instructions are further executable by the processor to, in response to determining that the SUPL server does not support the certificate-based authentication method, perform an alternative client authentication (ACA)-based authentication method when the mobile device is connected to a 3rd Generation Partnership Project (3GPP) network or a 3GPP2 network.

6. The apparatus of claim 4 , wherein the certificate-based authentication process is independent of an access network used by the mobile device

7. An apparatus comprising:

means for receiving, at a secure user plane location (SUPL) server, an indication from a mobile device of one or more transport layer security (TLS) cipher suites supported by the mobile device;

means for determining whether the one or more TLS cipher suites include a TLS pre-shared key (TLS-PSK) cipher suite that is supported by the SUPL server;

in response to determining that the one or more TLS cipher suites include the TLS-PSK cipher suite that is supported by the SUPL server, means for performing a generic bootstrapping architecture (GBA)-based authentication process to authenticate the mobile device; and

in response to determining that the one or more TLS cipher suites do not include a TLS-PSK cipher suite that is supported by the SUPL server, means for determining whether the SUPL server supports a certificate-based authentication method; and

in response to determining that the SUPL server supports the certificate-based authentication method, means for performing the certificate-based authentication method that includes sending a server certificate to the mobile device and receiving a device certificate from the mobile device.

8. The apparatus of claim 7 , further comprising in response to determining that the SUPL server does not support the certificate-based authentication method, means for performing an alternative client authentication (ACA)-based authentication method when the mobile device is connected to a 3rd Generation Partnership Project (3GPP) network or a 3GPP2 network.

9. The apparatus of claim 7 , wherein the certificate-based authentication method is independent of an access network used by the mobile device.

10. A non-transitory processor-readable medium comprising instructions that, when executed by a processor, cause the processor to:

receive, at a secure user plane location (SUPL) server, an indication from a mobile device of one or more transport layer security (TLS) cipher suites supported by the mobile device;

determine whether the one or more TLS cipher suites include a TLS pre-shared key (TLS-PSK) cipher suite that is supported by the SUPL server;

in response to determining that the one or more TLS cipher suites include the TLS-PSK cipher suite that is supported by the SUPL server, perform a generic bootstrapping architecture (GBA)-based authentication process to authenticate the mobile device; and

in response to determining that the one or more TLS cipher suites do not include a TLS-PSK cipher suite that is supported by the SUPL server, determine whether the SUPL server supports a certificate-based authentication method; and

in response to determining that the SUPL server supports the certificate-based authentication method, perform a certificate-based authentication process that includes sending a server certificate to the mobile device and receiving a device certificate from the mobile device.

11. The non-transitory processor-readable medium of claim 10 , wherein the instructions are further executable by the processor to, in response to determining that the SUPL server does not support the certificate-based authentication method, perform an alternative client authentication (ACA)-based authentication method when the mobile device is connected to a 3 rd Generation Partnership Project (3GPP) network or a 3GPP2 network.

12. The non-transitory processor-readable medium of claim 10 , wherein the certificate-based authentication process is independent of an access network used by the mobile device.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2015
From: HAWKES, PHILIP MICHAEL; WACHTER, ANDREAS; ESCOTT, ADRIAN EDWARD; EDGE, STEPHEN WILLIAM
To: QUALCOMM INCORPORATED
Reel/Frame 036099/0159 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2014
From: HAWKES, PHILIP MICHAEL; WACHTER, ANDRES; ESCOTT, ADRIAN EDWARD; EDGE, STEPHEN WILLIAM
To: QUALCOMM INCORPORATED
Reel/Frame 033275/0129 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2013
From: HAWKES, PHILIP MICHAEL; WACHTER, ANDREAS; ESCOTT, ADRIAN EDWARD; EDGE, STEPHEN WILLIAM
To: QUALCOMM INCORPORATED
Reel/Frame 031722/0877 →
Continuity (6)
Division 13288949 · Nov 3, 2011
Provisional Application 61410882 · Nov 6, 2010
Provisional Application 61437184 · Jan 28, 2011
Provisional Application 61471048 · Apr 1, 2011
Provisional Application 61527341 · Aug 25, 2011
Related Publication 20140093081A1 · Apr 3, 2014