Method and apparatus for access credential provisioning

US9137662B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9137662-B2
Application numberUS-201013879698-A
CountryUS
Kind codeB2
Filing dateOct 21, 2010
Priority dateOct 21, 2010
Publication dateSep 15, 2015
Grant dateSep 15, 2015

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method and apparatus are provided for access credential provisioning. A method may include receiving, at a first mobile apparatus, information about a second mobile apparatus. The first mobile apparatus may be provisioned with network access credential information to be transferred from the first mobile apparatus to the second mobile apparatus. The method may further include causing the information about the second mobile apparatus to be provided to a provisioning apparatus for the network. The method may additionally include receiving authorization form the provisioning apparatus to transfer the network access credential information from the first mobile apparatus to the second mobile apparatus. The method may also include, in response to receipt of the authorization, causing the network access credential information to be provided to the second mobile apparatus. A corresponding apparatus is also provided.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: receiving, at a first mobile apparatus, information about a second mobile apparatus, wherein the first mobile apparatus is provisioned with network access credential information for a network, and wherein the network access credential information is to be transferred from the first mobile apparatus to the second mobile apparatus; causing the information about the second mobile apparatus to be provided from the first mobile apparatus to a provisioning apparatus for the network; receiving, at the first mobile apparatus, authorization from the provisioning apparatus to transfer the network access credential information from the first mobile apparatus to the second mobile apparatus; and in response to receipt of the authorization, causing the network access credential information to be provided to the second mobile apparatus. 2. The method of claim 1 , further comprising: receiving, at the first mobile apparatus, a confirmation from the second mobile apparatus that the network access credential information was received successfully by the second mobile apparatus; and in response to the confirmation, causing deletion of the network access credential information from a memory of the first mobile apparatus. 3. The method of claim 1 , further comprising: causing a permission message to be sent from the first mobile apparatus to the second mobile apparatus, the permission message providing permission to the second mobile apparatus to use the network access credential information to access the network. 4. The method of claim 3 , further comprising: encrypting at least a portion of the network access credential information with a locking key prior to causing the network access credential information to be sent to the second mobile apparatus; and wherein the permission message comprises the locking key, thereby enabling the second mobile apparatus to unlock and use the network access credential information. 5. The method of claim 1 , wherein: receiving, at the first mobile apparatus, information about the second mobile apparatus comprises receiving the information via a local connection between the first mobile apparatus and the second mobile apparatus; and causing the network access credential information to be sent to the second mobile apparatus comprises causing the network access credential information to be sent via the local connection. 6. The method of claim 5 , further comprising: causing establishment of the local connection based at least in part on a code associated with the network access credential information. 7. The method of claim 1 , wherein: receiving authorization from the provisioning apparatus comprises receiving a provisioning package comprising a version of the network access credential information provisioned to the second mobile apparatus by the provisioning apparatus; and wherein causing the network access credential information to be provided to the second mobile apparatus comprises causing the provisioning package to be provided to the second mobile apparatus. 8. The method of claim 1 , wherein the information about the second mobile apparatus comprises a unique assigned identifier of the second mobile apparatus, and wherein receiving authorization from the provisioning apparatus comprises receiving authorization in an instance in which the provisioning apparatus has verified based at least in part on the unique assigned identifier that the second mobile apparatus is not registered as stolen. 9. The method of claim 1 , wherein the information about the second mobile apparatus comprises protection information indicating protection offered by the second mobile apparatus, and wherein receiving authorization from the provisioning apparatus comprises receiving authorization in an instance in which the provisioning apparatus determines that the protection offered by the second mobile apparatus satisfies a predefined protection requirement. 10. An apparatus comprising at least one processor and at least one memory storing computer program code, wherein the at least one memory and stored computer program code are configured, with the at least one processor, to cause the apparatus to at least: receive information about a mobile apparatus, wherein the apparatus is provisioned with network access credential information for a network, and wherein the network access credential information is to be transferred from the apparatus to the mobile apparatus; cause the information about the mobile apparatus to be provided to a provisioning apparatus for the network; receive authorization from the provisioning apparatus to transfer the network access credential information from the apparatus to the mobile apparatus; and in response to receipt of the authorization, cause the network access credential information to be provided to the mobile apparatus. 11. The apparatus of claim 10 , wherein the at least one memory and stored computer program code are configured, with the at least one processor, to further cause the apparatus to: receive a confirmation from the mobile apparatus that the network access credential information was received successfully by the mobile apparatus; and in response to the confirmation, cause deletion of a locally-stored copy of the network access credential information. 12. The apparatus of claim 10 , wherein the at least one memory and stored computer program code are configured, with the at least one processor, to further cause the apparatus to: cause a permission message to be sent to the mobile apparatus, the permission message providing permission to the mobile apparatus to use the network access credential information to access the network. 13. The apparatus of claim 12 , wherein the at least one memory and stored computer program code are configured, with the at least one processor, to further cause the apparatus to: encrypt at least a portion of the network access credential information with a locking key prior to causing the network access credential information to be sent to the mobile apparatus; and wherein the permission message comprises the locking key, thereby enabling the mobile apparatus to unlock and use the network access credential information. 14. The apparatus of claim 10 , wherein the at least one memory and stored computer program code are configured, with the at least one processor, to cause the apparatus to: receive information about the mobile apparatus via a local connection between the apparatus and the mobile apparatus; and cause the network access credential information to be sent to the mobile apparatus via the local connection. 15. The apparatus of claim 10 , the authorization comprises a provisioning package comprising a version of the network access credential information provisioned to the mobile apparatus by the provisioning apparatus, and wherein the at least one memory and stored computer program code are configured, with the at least one processor, to cause the apparatus to cause the network access credential information to be provided to the mobile apparatus by causing the provisioning package to be provided to the mobile apparatus. 16. The apparatus of claim 10 , wherein the information about the mobile apparatus comprises a unique assigned identifier of the mobile apparatus, and wherein the at least one memory and stored computer program code are configured, with the at least one processor, to cause the apparatus to receive authorization from the provisioning apparatus in an instance in which the provisioning apparatus has verified based at least in part on the u

Assignees

Inventors

Classifications

  • Transfer to or from user equipment or user record carrier · CPC title

  • by using authentication-authorization-accounting [AAA] servers or protocols · CPC title

  • by using a location-limited connection, e.g. near-field communication or limited proximity of entities · CPC title

  • for key exchange, e.g. in peer-to-peer networks (cryptographic mechanisms or cryptographic arrangements for key agreement H04L9/0838) · CPC title

  • H04W12/06Primary

    Authentication · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9137662B2 cover?
A method and apparatus are provided for access credential provisioning. A method may include receiving, at a first mobile apparatus, information about a second mobile apparatus. The first mobile apparatus may be provisioned with network access credential information to be transferred from the first mobile apparatus to the second mobile apparatus. The method may further include causing the infor…
Who is the assignee on this patent?
Holtmanns Silke, Dolenc André, Nokia Technologies Oy
What technology area does this patent fall under?
Primary CPC classification H04L63/0892. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 15 2015 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).