Charging record authentication for anonymized network service utilization

US10194033B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10194033-B2
Application numberUS-201515774023-A
CountryUS
Kind codeB2
Filing dateNov 24, 2015
Priority dateNov 24, 2015
Publication dateJan 29, 2019
Grant dateJan 29, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A user device (10) provides a subscriber with access to a network service. The user device (10) determines service-specific key material and charging-specific key material. The user device (10) determines a charging record indicating usage of the network service by the subscriber and associates the charging record with first authentication information based on the charging-specific key material. The user device (10) generates at least one message including the charging record and the associated first authentication information. The user device (10) associates the at least one message with second authentication information based on the service-specific key material. The user device (10) sends the at least one message to a first network node (150) which is incapable of relating the charging-specific key material or the service-specific key material to a subscriber identity of the subscriber. The first network node (150) receives the at least one message and the associated second authentication information from the user device (10) and authenticates the at least one message based on the service-specific key material and the second authentication information. In response to authenticating the at least one message, the first network node forwards the charging record and the associated first authentication information to a second network node (120). The second network node (120) is capable of relating the charging-specific key material to the subscriber identity of the subscriber. The second network node (120) receives the charging record and the associated first authentication information from the first network node (150) and authenticates the charging record based on the charging-specific key material and the first authentication information. In response to authenticating the charging record, the second network node (120) controls charging of the network service.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method of controlling utilization of a network service, the method comprising a user device: providing a subscriber with access to a network service; determining service-specific key material; determining charging-specific key material; determining a charging record indicating usage of the network service by the subscriber; associating the charging record with first authentication information based on the charging-specific key material; generating at least one message comprising the charging record and the associated first authentication information; associating the at least one message with second authentication information based on the service-specific key material; and sending the at least one message and the associated second authentication information to a network node which is incapable of relating any of the service-specific key material and the charging-specific key material to a subscriber identity of the subscriber. 2. The method of claim 1 , further comprising the user device deriving the charging-specific key material: from the subscriber identity; or from the subscriber identity and the service-specific key material. 3. The method of claim 1 , further comprising the user device receiving a response from the network node, the response indicating that usage of the network service by the subscriber is authorized. 4. The method of claim 1 , further comprising the user device: determining generic key material through interaction with another network node; and deriving the charging-specific key material and/or the service-specific key material from the generic key material. 5. A method of controlling utilization of a network service, the method comprising a network node: providing access to a network service through a user device connected to the network node; receiving, from the user device, at least one message and first authentication information associated with the at least one message, the first authentication information being based on service-specific key material, the at least one message comprising a charging record and second authentication information associated with the charging record, the charging record indicating usage of the network service by a subscriber, the second authentication information being based on charging-specific key material; wherein the network node is incapable of relating any of the service-specific key material and the charging-specific key material to a subscriber identity of the subscriber; authenticating the at least one message based on the service-specific key material and the first authentication information; and in response to authenticating the at least one message, forwarding the charging record and the associated second authentication information to a further network node which is capable of relating the charging-specific key material to a subscriber identity of the subscriber. 6. The method of claim 5 , wherein the charging-specific key material is derived: from the subscriber identity; from the subscriber identity and the service-specific key material. 7. The method of claim 5 , further comprising the network node receiving the service-specific key material from another network node. 8. The method of claim 5 , further comprising the network node receiving a response from the further network node, the response indicating whether the charging record was authenticated by the further network node. 9. A method of controlling utilization of a network service, the method comprising a network node: determining charging-specific key material related to a subscriber identity of a subscriber; receiving, from a further network node, a charging record and authentication information associated with the charging record, the charging record indicating usage of a network service by the subscriber and being based on the charging-specific key material; wherein the further network node is incapable of relating the charging-specific key material to the subscriber identity of the subscriber; authenticating the charging record based on the charging-specific key material and the associated authentication information; and controlling, in response to authenticating the charging record, charging of the network service. 10. The method of claim 9 , further comprising the network node deriving the charging-specific key material from the subscriber identity. 11. The method of claim 9 , further comprising the network node: receiving service-specific key material from another network node; and deriving the charging-specific key material from the subscriber identity and the service-specific key material. 12. The method of claim 9 , further comprising the network node sending a response to the further network node, the response indicating: whether the charging record was authenticated by the network node; or whether charging of the network service is authorized for the subscriber. 13. A user device, the user device comprising: processing circuitry; memory containing instructions executable by the processing circuitry whereby the user device is operative to: provide a subscriber with access to a network service; determine service-specific key material; determine charging-specific key material; determine a charging record indicating usage of the network service by the subscriber; associate the charging record with first authentication information based on the charging-specific key material; generate at least one message comprising the charging record and the associated first authentication information; associate the at least one message with second authentication information based on the service-specific key material; and send the at least one message and the associated second authentication information to a network node which is incapable of relating any of the charging-specific key material and the service-specific key material to a subscriber identity of the subscriber. 14. The user device of claim 13 , wherein the instructions are such that the user device is operative to derive the charging-specific key material from the subscriber identity. 15. The user device of claim 13 , wherein the instructions are such that the user device is operative to receive a response from the network node, the response indicating that usage of the network service by the subscriber is authorized. 16. The user device of claim 13 , wherein the instructions are such that the user device is operative to: determine generic key material through interaction with another network node; and derive the charging-specific key material and/or the service-specific key material from the generic key material. 17. The user device of claim 13 , wherein the at least one message includes an identifier associated with the charging-specific key material and the service-specific key material. 18. A network node, the network node, comprising: processing circuitry; memory containing instructions executable by the processing circuitry whereby the network node is operative to: provide access to a network service through a user device connected to the network node; receive, from the user device, a at least one message and first authentication information associated with the at least one message, the first authentication information being based on service-specific key material, the at least one message comprising a charging record and second authentication information associated with the charging record, the charging record indicating usage of the network service by a subscriber, the second auth

Assignees

Inventors

Classifications

  • Authentication · CPC title

  • H04M15/41Primary

    Billing record details, i.e. parameters, identifiers, structure of call data record [CDR] · CPC title

  • Recording calls {, or communications} in printed, perforated or other permanent form · CPC title

  • Secure or trusted billing, e.g. trusted elements or encryption · CPC title

  • Cumulative charges · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10194033B2 cover?
A user device (10) provides a subscriber with access to a network service. The user device (10) determines service-specific key material and charging-specific key material. The user device (10) determines a charging record indicating usage of the network service by the subscriber and associates the charging record with first authentication information based on the charging-specific key material…
Who is the assignee on this patent?
Ericsson Telefon Ab L M
What technology area does this patent fall under?
Primary CPC classification H04M15/41. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 29 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).