Mobile communication system implementing integration of multiple logins of mobile device applications

US10284366B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10284366-B2
Application numberUS-201214347663-A
CountryUS
Kind codeB2
Filing dateSep 27, 2012
Priority dateJun 17, 2008
Publication dateMay 7, 2019
Grant dateMay 7, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In existing mobile implementations, there is a disconnect between the mobile device accessing the network and the applicative services inasmuch as the entity responsible for network access, such as the VPN Gateway, differs from the entity governing access to applications, such as email servers and SharePoint repositories. Therefore existing solutions typically employ two authentication methods. Of these, the first may be used to authenticate the mobile device to the VPN Gateway, while the second may be used to authenticate the mobile device towards the applications server. In order to facilitate strong authentication it is often desired to utilize a mechanism that uses or combines two different factors, e.g. “something you have” (such as but not limited to a smart card) and “something you know” (such as but not limited to a password). Most currently available mobile devices offer limited options to connect external devices to them, rendering most “Something you have” solutions irrelevant. For instance, there is no ability to connect a smart-card to a mobile phone.

First claim

Opening claim text (preview).

The invention claimed is: 1. A mobile communication method including: multiple login integration including secure integration of multiple login systems in mobile communication device applications; the integration including: receiving, at an authentication broker, from an individual mobile application, a request to perform login to a corporate application, using the authentication broker to verify user credentials; and using the authentication broker to send an encrypted authentication record to a login service running on the mobile device in a secure manner; and in the mobile device, retrieving an encrypted authentication record sent by the authentication broker, wherein the encrypted authentication record, once retrieved, is sent to a service dispatcher which decrypts the record to access a clear private key of the device, wherein a basis for authentication is sent to the corporate application, and wherein authentication is performed by software on the mobile device and wherein, when the application sends an authentication library a request to perform authentication, the Authentication Library responsively contacts the Authentication Broker which responsively sends the authentication record to the mobile device, encrypted using encryption coordinated between the mobile device and the Authentication Broker and wherein encryption of the Authentication record prevents unauthorized use of the authentication record because only the destined mobile device can decrypt the authentication record. 2. A method according to claim 1 , wherein the individual mobile application is defined by a user of an individual mobile communication device. 3. A method according to claim 1 , wherein the method is repeated for each application from among a plurality of such applications. 4. A method according to claim 3 , wherein said authentication record comprises username and password. 5. A method according to claim 1 , wherein the method is repeated for each authentication service from among a plurality of such authentication services. 6. A method according to claim 1 , wherein the authentication broker uses an encryption method coordinated with the mobile device to ensure only a destined mobile device can decrypt an encrypted authentication record sent by the authentication broker. 7. A method according to claim 1 , wherein architecture in the mobile device is configured to perform authentication, including: when a mobile communication device application requests to perform authentication, retrieving the encrypted authentication record sent by the authentication broker. 8. A method according to claim 7 , wherein the encrypted authentication record, once retrieved, is sent to a service dispatcher which decrypts the record to access a clear private key of the device. 9. A method according to claim 8 , wherein a basis for authentication is sent to the application. 10. A method according to claim 9 , wherein said basis for authentication comprises at least one mobile equipment hardware authentication parameter. 11. A method according to claim 9 , wherein, when the mobile device is created, a public key for the mobile device is sent to, and stored on, a Credential Management subsystem configured to introduce records into a Secure Repository of the Authentication Broker. 12. A method according to claim 11 , wherein a central server is provided that defines logic of authentication of each application in the cellular network being served by the server. 13. A method according to claim 11 , wherein, when the user is granted permissions to an application, the authentication information is encrypted by the user's public key and only the encrypted record is sent to the Authentication Broker. 14. A method according to claim 12 , wherein authentication process control comprises insertion of authentication records. 15. A method according to claim 12 , wherein authentication process control comprises enforcement of policies. 16. A method according to claim 11 , wherein a server is provided which has “single-sign on” functionality in conjunction with mobile authentication functionality. 17. A method according to claim 11 , wherein modules that control the authentication process reside in a central server, and are centrally managed. 18. A method according to claim 16 , wherein at least one secure mobile device includes functionality which uses PKI functionality as a basis for network authentication. 19. A method according to claim 18 , wherein said network authentication is compatible with smart-card authentication. 20. A method according to claim 11 , further comprising apparatus for managing sign-on and applicative authentication that utilizes strong encryption available in a secure smart-phone. 21. A method according to claim 11 , wherein the management of authentication for a plurality of applications in a manner is transparent to the user. 22. A method according to claim 10 , wherein said mobile equipment hardware authentication parameter comprises an IMEI parameter. 23. A method according to claim 12 , wherein authentication process control comprises modification of authentication records. 24. A method according to claim 17 , wherein an authentication record is maintained including application service for which the record is intended. 25. A method according to claim 11 , wherein a key from a mobile communication device is used to protect a completely different key used to authenticate the mobile communication device to an application server. 26. A method according to claim 10 , wherein said mobile equipment hardware authentication parameter comprises a SIM-card parameter. 27. A mobile communication system including: a processor and memory configured for multiple login integration including secure integration of multiple login systems in mobile communication device applications; the integration including: receiving, at an authentication broker, from an individual mobile application, a request to perform login to a corporate application, using the authentication broker to verify user credentials; and using the authentication broker to send an encrypted authentication record to a login service running on the mobile device in a secure manner; and in the mobile device, retrieving an encrypted authentication record sent by the authentication broker, wherein the encrypted authentication record, once retrieved, is sent to a service dispatcher which decrypts the record to access a clear private key of the device, wherein a basis for authentication is sent to the corporate application, and wherein authentication is performed by software on the mobile device and wherein, when the application sends an authentication library a request to perform authentication, the Authentication Library responsively contacts the Authentication Broker which responsively sends the authentication record to the mobile device, encrypted using encryption coordinated between the mobile device and the Authentication Broker and wherein encryption of the Authentication record prevents unauthorized use of the authentication record because only the destined mobile device can decrypt the authentication record. 28. A computer program product, comprising a non-transitory tangible computer readable medium having computer readable program code embodied therein, said computer readable program code adapted to be executed to implemen

Assignees

Inventors

Classifications

  • Advertising or display means on roads, walls or similar surfaces, e.g. illuminated · CPC title

  • A63G31/16Primary

    creating illusions of travel · CPC title

  • Windows displaying outside view, artificially generated · CPC title

  • using biometric data, e.g. fingerprints, iris scans or voiceprints · CPC title

  • Displaying information not related to the elevator, e.g. weather, publicity, internet or TV · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10284366B2 cover?
In existing mobile implementations, there is a disconnect between the mobile device accessing the network and the applicative services inasmuch as the entity responsible for network access, such as the VPN Gateway, differs from the entity governing access to applications, such as email servers and SharePoint repositories. Therefore existing solutions typically employ two authentication methods.…
Who is the assignee on this patent?
Elta Systems Ltd
What technology area does this patent fall under?
Primary CPC classification A63G31/16. Mapped technology areas include Human Necessities.
When was this patent published?
Publication date Tue May 07 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).