IP Library Granted Patent US 11,456,870
Granted Patent B2
US 11,456,870 · App. 16/776,879 · Granted Sep 27, 2022

Authorization token including fine grain entitlements

Inventors: Komethagan Subramaniam (Redmond, WA); Michael Engan (Bellevue, WA); Ramkishan Sadasivam (Cummings, GA); Douglas McDorman (Sammamish, WA)
Assignee: T-Mobile USA, Inc.
H04L9/3213G06F9/30018H04L9/3247H04W8/18H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,456,870
App. No.
16/776,879
Granted
Sep 27, 2022
Kind
B2
Abstract

A method of interpreting an authorization token is described herein. The service can receive an authorization token from a client device, and validate a signature of the authorization token. The service can identify an allowed function value associated at least part of an entitlement representation contained in a body of the authorization token. The service can convert the allowed function value to an allowed function bitmask that includes bits at a plurality of bit positions that are set to values indicating whether the subscriber element has attributes associated with each of the plurality of bit positions on a predefined attribute list. The service can determine whether the allowed function bitmask indicates that the subscriber element has one or more qualifying attributes that entitle a user of the client device to access the service.

Claims (48)

1. A method of generating an authorization token, the method comprising:

generating an allowed function bitmask for a subscriber element, the allowed function bitmask comprising bits at a plurality of bit positions that are set to values indicating whether the subscriber element has attributes associated with each of the plurality of bit positions on a predefined attribute list;

converting the allowed function bitmask to an allowed function value;

adding the allowed function value in an entitlement representation;

adding the entitlement representation to a body of an authorization token; and

signing the authorization token.

2. The method of claim 1 , wherein the subscriber element is a user account, billing account, or subscription associated with a telecommunications provider.

3. The method of claim 1 , further comprising compressing the entitlement representation prior to adding the entitlement representation to the body of the authorization token.

4. The method of claim 1 , wherein whether the subscriber element has a particular attribute is determined based on information stored in a subscriber database.

5. The method of claim 1 , wherein the allowed function bitmask is generated by directly setting bits in the allowed function bitmask at each of the plurality of bit positions to “0” or “1” based on whether the subscriber element has a particular attribute corresponding to that bit position on the predefined attribute list.

6. The method of claim 1 , wherein the allowed function bitmask is generated by:

generating a separate binary value for each of the attributes on the predefined attribute list, the separate binary value including a leading bit set to “0” or “1” based on whether the subscriber element has the attribute, and zero or more trailing bits set to “0”; and

adding the separate binary values together to obtain the allowed function bitmask.

7. The method of claim 1 , wherein signing the authorization token comprises:

generating a signature using a cryptographic algorithm with a private key on the body and a header of the authorization token; and

adding the signature to the authorization token.

8. A method of generating an authorization token, the method comprising:

generating an allowed function bitmask used to identify allowed functions associated with subscriber elements, respectively, associated with a subscriber of a telecommunication provider, the allowed function bitmask comprising groups of bits in a plurality of bits, the groups of bits having values indicating whether telecommunication service attributes are included in the subscriber elements, respectively;

generating an entitlement representation based at least in part on the allowed function bitmask; and

adding the entitlement representation to a body of an authorization token.

9. The method of claim 8 , wherein generating the entitlement representation further comprises:

converting the allowed function bitmask to an allowed function value; and

adding the allowed function value in the entitlement representation.

10. The method of claim 8 , further comprising:

controlling access for a user to a service based on the telecommunication service attributes of the subscriber elements, respectively.

11. The method of claim 8 , wherein a subscriber element of the subscriber elements is a user account, billing account, or subscription associated with the telecommunications provider.

12. The method of claim 8 , wherein first bits of the plurality of bits in the allowed function bitmask are set to first values indicating that a subscriber entity has the telecommunication service attributes corresponding to the first bits, respectively, and

wherein second bits of the plurality of bits in the allowed function bitmask are set to second values indicating that a subscriber entity does not have the telecommunication service attributes corresponding to the second bits, respectively.

13. The method of claim 8 , further comprising:

signing the authorization token to indicate that an issuing entity generated the authorization token.

14. The method of claim 8 , further comprising:

inserting, into the authorization token, a signature generated with a cryptographic algorithm.

15. The method of claim 8 , wherein the telecommunication service attributes include a telecommunication service attribute indicating a function that a user has been permitted to perform in association with a subscriber element of the subscriber elements.

16. A server of a service, the server comprising:

one or more processors;

a communication connection; and

memory storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

generating an allowed function bitmask for a subscriber element, the allowed function bitmask comprising bits at a plurality of bit positions that are set to values indicating whether the subscriber element has attributes associated with each of the plurality of bit positions on a predefined attribute list;

converting the allowed function bitmask to an allowed function value;

adding the allowed function value in an entitlement representation;

adding the entitlement representation to a body of an authorization token; and

signing the authorization token.

17. The server of claim 16 , wherein the subscriber element is a user account, billing account, or subscription associated with a telecommunications provider.

18. The server of claim 16 , wherein whether the subscriber element has a particular attribute is determined based on information stored in a subscriber database.

19. The server of claim 16 , wherein the allowed function bitmask is generated by directly setting the bits in the allowed function bitmask at each of the plurality of bit positions to “0” or “1” based on whether the subscriber element has a particular attribute corresponding to that bit position on the predefined attribute list.

20. The server of claim 16 , wherein the allowed function bitmask is generated by:

generating a separate binary value for each of the attributes on the predefined attribute list, the separate binary value including a leading bit set to “0” or “1” based on whether the subscriber element has the attribute, and zero or more trailing bits set to “0”; and

adding the separate binary values together to obtain the allowed function bitmask.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2020
From: SUBRAMANIAM, KOMETHAGAN; ENGAN, MICHAEL; SADASIVAM, RAMKISHAN; MCDORMAN, DOUGLAS
To: T-MOBILE USA, INC.
Reel/Frame 051758/0291 →
Continuity (2)
Division 15828266 · Nov 30, 2017
Related Publication 20200169405A1 · May 28, 2020
Cited By (1)
US 12,388,645