Generating a device identification key from a base key for authentication with a network

US11882102B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11882102-B2
Application numberUS-202117306526-A
CountryUS
Kind codeB2
Filing dateMay 3, 2021
Priority dateAug 28, 2014
Publication dateJan 23, 2024
Grant dateJan 23, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A base key that is stored at a device may be received. A network identification may further be received. A device identification key may be generated based on a combination of the network identification and the base key. Furthermore, the device identification key may be used to authenticate the device with a network that corresponds to the network identification.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: receiving a base key being stored at a device; receiving a mobile communications network identification associated with a cellular or mobile network; generating, by a processing device, a device identification key based on a combination of the mobile communications network identification and the base key; and using the device identification key to authenticate the device with a mobile communications network corresponding to the mobile communications network identification. 2. The method of claim 1 , wherein the using of the device identification key to authenticate the device with the mobile communications network corresponding to the mobile communications network identification comprises: generating a device proof based on a combination of the device identification key and a value received from the mobile communications network corresponding to the mobile communications network identification; and transmitting the device proof to the mobile communications network corresponding to the mobile communications network identification. 3. The method of claim 1 , further comprising: receiving a cryptographic nonce value; and receiving a device identification, wherein the generating of the device identification key is further based on the device identification and the cryptographic nonce value. 4. The method of claim 1 , further comprising: transmitting the device identification key from the device to the mobile communications network via a side channel, wherein the device identification key is used by the mobile communications network to generate a mobile communications network proof that is compared with a device proof that is transmitted from the device to the mobile communications network. 5. The method of claim 1 , further comprising: in response to a request to authenticate the device with a second mobile communications network, receiving a second mobile communications network identification corresponding to the second mobile communications network; generating a second device identification key based on a combination of the second mobile communications network identification and the same base key that is used to generate the device identification key; and using the second device identification key to authenticate the device with the second mobile communications network corresponding to the second mobile communications network identification. 6. The method of claim 1 , wherein the device identification key is associated with a subscriber identity module (SIM) functionality. 7. The method of claim 1 , wherein the device identification key is not stored in memory. 8. A system comprising: a memory to store a base key; and a processing device coupled with the memory to: retrieve the base key being stored at the memory; receive an identification of a mobile communications network associated with a cellular or mobile network; and generate a device key based on the base key and the identification of the mobile communications network, wherein the device key is associated with authenticating the device for use with a mobile communications network corresponding to the mobile communications network identification. 9. The system of claim 8 , wherein the generating of the device key based on the base key and the identification of the mobile communications network comprises: generating a device proof based on a combination of the device key and a value received from the mobile communications network; and transmitting the device proof to the mobile communications network. 10. The system of claim 8 , wherein the processing device is further to: receive a nonce value; and receive an identification of the device, wherein the generating of the device key is further based on the identification of the device and the nonce value. 11. The system of claim 8 , wherein the processing device is further to: transmit the device key from the device to the mobile communications network via a side channel, wherein the device key is used by the mobile communications network to generate a mobile communications network proof that is compared with a device proof that is transmitted from the device to the mobile communications network. 12. The system of claim 8 , wherein the processing device is further to: transmit the device key from the device to the mobile communications network via a side channel; and receive, from the mobile communications network, a mobile communications network proof based on the transmitted device key, wherein the mobile communications network proof is compared with a device proof generated by the device to authenticate the mobile communications network. 13. The system of claim 8 , wherein the processing device is further to: in response to a request to authenticate the device for use with an additional mobile communications network, receive an identification of the additional mobile communications network; generate an additional device key based on a combination of the identification of the additional mobile communications network and the same base key that is used to generate the device key; and use the additional device key to authenticate the device for use with the additional mobile communications network. 14. The system of claim 8 , wherein the device key is associated with a subscriber identity module (SIM) functionality. 15. The system of claim 8 , wherein the device key is not stored in memory. 16. A non-transitory computer readable medium including data that, when accessed by a processing device, cause the processing device to perform operations comprising: receiving a base key being stored at a device; receiving a mobile communications network identification associated with a cellular or mobile network; generating a device identification key based on a combination of the mobile communications network identification and the base key; and using the device identification key to authenticate the device with a mobile communications network corresponding to the mobile communications network identification. 17. The non-transitory computer readable medium of claim 16 , wherein the using of the device identification key to authenticate the device with the mobile communications network corresponding to the mobile communications network identification comprises: generating a device proof based on a combination of the device identification key and a value received from the mobile communications network corresponding to the mobile communications network identification; and transmitting the device proof to the mobile communications network corresponding to the mobile communications network identification. 18. The non-transitory computer readable medium of claim 16 , the operations further comprising: receiving a cryptographic nonce value; and receiving a device identification, wherein the generating of the device identification key is further based on the cryptographic nonce value and the device identification. 19. The non-transitory computer readable medium of claim 16 , the operations further comprising: transmitting the device identification key from the device to the mobile communications network via a side channel, wherein the device identification key is used by the mobile communications network to generate a mobile communications network proof that is compared with a device proof that is transmitted from the device to the mobile communications network. 20. The non-transitory computer readable medium of claim 16 , the operations further comprising

Assignees

Inventors

Classifications

  • H04L63/061Primary

    for key exchange, e.g. in peer-to-peer networks (cryptographic mechanisms or cryptographic arrangements for key agreement H04L9/0838) · CPC title

  • involving user or device identifiers, e.g. serial number, physical or biometrical information, DNA, hand-signature or measurable physical characteristics · CPC title

  • involving random numbers or seeds · CPC title

  • using challenge-response · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11882102B2 cover?
A base key that is stored at a device may be received. A network identification may further be received. A device identification key may be generated based on a combination of the network identification and the base key. Furthermore, the device identification key may be used to authenticate the device with a network that corresponds to the network identification.
Who is the assignee on this patent?
Cryptography Res Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/061. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 23 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).