Provisioning a network subscription

US10455385B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10455385-B2
Application numberUS-201515304404-A
CountryUS
Kind codeB2
Filing dateApr 14, 2015
Priority dateApr 15, 2014
Publication dateOct 22, 2019
Grant dateOct 22, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Provisioning a subscriber in a network is provided by: receiving an initialisation request for access to a network on behalf of a subscriber, at an admission platform of a network operator associated with the subscriber, and assigning the subscriber limited access rights to the network, the limited access rights being configured for communication between the subscriber and a subscription manager, for reconfiguration of identity information associated with the subscriber.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for provisioning a subscriber in a network, comprising the steps of: receiving an initialisation request for access to a network on behalf of a subscriber linked to a subscription unit, at an admission platform of a network operator associated with the subscriber, the initialisation request indicating a subscriber identity and relating to a Visited Public Land Mobile Network (PLMN), wherein the admission platform is part of a Home PLMN of the subscriber; and assigning the subscriber limited access rights to the network in response to the received initialisation request, the limited access rights being configured for communication between the subscriber and at least one subscription manager, for reconfiguration of identity information associated with the subscriber, wherein the step of assigning the subscriber limited access rights comprises: creating an authentication vector that is generated using a placeholder authentication key in place of a real authentication key, the placeholder authentication key being either a fixed key or deterministically derived from values associated with a device of the subscriber; and communicating a location update acknowledgement message from the admission platform to the Visited PLMN subsequent to a location update message from the Visited PLMN, the location update acknowledgement message being transmitted using the placeholder authentication key and comprising an access instruction to the Visited PLMN to provide the subscriber with the limited access rights, wherein the access instruction comprises an indication of at least one Access Point Name (APN) and an instruction that the subscriber cannot obtain access other than through the indicated at least one APN, and wherein the at least one APN provides access only to the at least one subscription manager through a communication channel between the subscriber and the at least one subscription manager such that the limited access rights are provided by the access to the network being limited to access to the at least one subscription manager. 2. The method of claim 1 , wherein the subscriber identity indicates the network operator associated with the subscriber and wherein the admission platform is configured for receiving initialisation requests indicating the network operator associated with the subscriber. 3. The method of claim 1 , further comprising: provisioning the subscriber, by communication of instructions to reconfigure the subscriber identity from the subscription manager to the subscriber. 4. The method of claim 1 , wherein the subscriber identity is an International Mobile Subscriber Identity (IMSI) comprising a Mobile Subscriber Identification Number (MSIN) the MSIN comprising a predetermined code indicating that the IMSI is a subscriber identity. 5. The method of claim 1 , further comprising: generating a security vector at the admission platform, the security vector being based on the subscriber identity. 6. The method of claim 1 , wherein the access instruction restricts the subscriber to use only one or both of: Unstructured Supplementary Service Data (USSD) and Short Messaging Service (SMS). 7. The method of claim 1 , wherein the subscriber identity is based on one or more of: a random sequence; a fixed or predefined sequence; an International Mobile Station Equipment Identity (IMEI) for the device, which is associated with the subscriber or subscription unit; and a Media Access Control (MAC) address for the device, which is associated with the subscriber or subscription unit. 8. The method of claim 1 , further comprising: communicating a cancellation message from the admission platform to the Visited PLMN subsequent to reconfiguration of the subscriber identity, so that the Visited PLMN will detach the subscriber. 9. The method of claim 1 , wherein the admission platform comprises a Home Subscriber Server (HSS) or Home Location Register (HLR) of the Home PLMN. 10. The method of claim 1 , wherein the limited access rights are restricted in one or more of: data volume; data rate; access time duration; and a network or Quality of Service (QoS) parameter. 11. An admission platform for provisioning a subscriber in a network, the subscriber and admission platform being associated with a common network operator, the admission platform comprising: a network interface, configured to receive an initialisation request for access to a network on behalf of a subscriber linked to a subscription unit and to assign the subscriber limited access rights to the network, the limited access rights being configured for communication between the subscriber and at least one subscription manager, for reconfiguration of identity information associated with the subscriber; wherein the initialisation request indicates a subscriber identity and relates to access to a Visited Public Land Mobile Network (PLMN) wherein the admission platform is a part of a Home PLMN of the subscriber; and wherein assigning the subscriber the limited access rights comprises: creating an authentication vector that is generated using a placeholder authentication key in place of a real authentication key, the placeholder authentication key being either a fixed key or deterministically derived from values associated with a device of the subscriber; and communicating a location update acknowledgement message from the admission platform to the Visited PLMN subsequent to a location update message from the visited PLMN, the location update acknowledgement message being transmitted using the placeholder authentication key and comprising an access instruction to the Visited PLMN to provide the subscriber with limited access rights, wherein the access instruction comprises an indication of at least one Access Point Name (APN) and an instruction that the subscriber cannot obtain access other than through the indicated at least one APN, and wherein the at least one APN provides access only to the at least one subscription manager through a communication channel between the subscriber and the at least one subscription manager such that the limited access rights are provided by the access to the network being limited to access to the at least one subscription manager. 12. The method of claim 1 , wherein the admission platform includes both a home location register (HLR) and a specially configured HLR that operates in parallel with the HLR, and wherein the method further includes: after the admission platform receives the initialisation request, the admission platform determines a range of the subscriber identity; and based on the determined range, the admission platform routes the initialisation request to the specially configured HLR as opposed to the HLR, wherein only initialisation requests whose determined range is within a preselected range are routed to the specially configured HLR.

Assignees

Inventors

Classifications

  • Access security · CPC title

  • H04W12/06Primary

    Authentication · CPC title

  • H04W4/50Primary

    Service provisioning or reconfiguring · CPC title

  • where a single sign-on provides access to a plurality of computers · CPC title

  • Transfer to or from user equipment or user record carrier · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10455385B2 cover?
Provisioning a subscriber in a network is provided by: receiving an initialisation request for access to a network on behalf of a subscriber, at an admission platform of a network operator associated with the subscriber, and assigning the subscriber limited access rights to the network, the limited access rights being configured for communication between the subscriber and a subscription manage…
Who is the assignee on this patent?
Vodafone Ip Licensing Ltd
What technology area does this patent fall under?
Primary CPC classification H04W12/06. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 22 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).