Security protocols for mobile operator networks

US9270700B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9270700-B2
Application numberUS-48694609-A
CountryUS
Kind codeB2
Filing dateJun 18, 2009
Priority dateDec 12, 2008
Publication dateFeb 23, 2016
Grant dateFeb 23, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Security protocols for mobile operator networks are described. In embodiments, mobile communication link is established between a mobile phone and a media content provider via a communication service provider with which the mobile phone is registered for mobile communications, and via at least one roaming node network with which the communication service provider has a roaming service agreement. The media content provider receives a security policy request from the mobile phone to establish a security policy for end-to-end security of the mobile communication link between the media content provider and the mobile phone for data communication security. The media content provider then communicates a security policy response to the mobile phone to establish the security policy for the end-to-end security of the mobile communication link that is adaptable to security restrictions of the roaming node network.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method implemented by a computer device at a media content provider, the method comprising: establishing a mobile communication link with a mobile device via a communication service provider with which the mobile device is registered for mobile communications, and via at least one roaming node network with which the communication service provider has a roaming service agreement; receiving a security policy request from the mobile device to establish a security policy for end-to-end security of the mobile communication link between the media content provider and the mobile device for data communication security; communicating a security policy response to the mobile device to establish the security policy for the end-to-end security of the mobile communication link; communicating a challenge to the mobile device via the mobile communication link that is secure based on the security policy, the mobile communication link including the roaming node network and a mobile operator network that is managed by the communication service provider; and receiving the challenge back from the mobile device via the mobile operator network and the communication service provider, the challenge including data added by the communication service provider, the added data comprising a billing identifier that is associated with the mobile device, the billing identifier being securely received from the communication service provider via the mobile communication link. 2. A method as recited in claim 1 , wherein the security policy request that is received from the mobile device includes a region code corresponding to the roaming node network. 3. A method as recited in claim 2 , further comprising determining the encryption policy for the roaming node network based on the region code. 4. A method as recited in claim 1 , wherein the security policy request that is received from the mobile device is included with authentication data messages that are communicated between the mobile device and the media content provider. 5. A method as recited in claim 4 , wherein the security policy request includes a region code corresponding to the roaming node network, the region code being included with the authentication data messages. 6. A method as recited in claim 1 , further comprising: receiving an indication that the roaming node network is changing to a different roaming node network to maintain the mobile communication link; and adapting the security policy for the end-to-end security of the mobile communication link for alternative security restrictions of the different roaming node network. 7. A method implemented by a mobile device, the method comprising: establishing a mobile communication link with a media content provider via a communication service provider with which the mobile device is registered for mobile communications, and via at least one roaming node network with which the communication service provider has a roaming service agreement; communicating a security policy request to the media content provider to establish a security policy for end-to-end security of the mobile communication link between the media content provider and the mobile device for data communication security, the security policy request including an encryption policy for the roaming node network that is obtained from a cache stored locally on the mobile device; and receiving a security policy response from the media content provider to establish the security policy for the end-to-end security of the mobile communication link that is adaptable to security restrictions of the roaming node network; receive a challenge from the media content provider via the mobile communication link that is secure based on the security policy, the mobile communication link including the roaming node network and a mobile operator network that is managed by the communication service provider, and communicate the challenge back to the media content prover via the mobile operator network and the communication service provider, the challenge including data added by the communication service provider, the data comprising a billing identifier that is associated with the mobile device. 8. A method as recited in claim 7 , wherein the security policy request further includes a region code that corresponds to the roaming node network. 9. A method as recited in claim 7 , wherein the security policy request and the security policy response are included with authentication data messages that are communicated between the mobile device and the media content provider. 10. A mobile communication system, comprising: a media content provider configured to establish a mobile communication link with a mobile device via a communication service provider with which the mobile device is registered for mobile communications, and via at least one roaming node network with which the communication service provider has a roaming agreement; a security protocol service implemented by a computer device at the media content provider, the security protocol service configured to: receive a security policy request from the mobile device to establish a security policy for end-to-end security of the mobile communication link between the media content provider and the mobile device for data communication security; determine an encryption policy for the roaming node network based on a region code that corresponds to the roaming node network; and initiate communication of a security policy response to the mobile device, the security policy response including the encryption policy that is utilized to establish the security policy for the end-to-end security of the mobile communication link that is adaptable to security restrictions of the roaming node network; communicate a challenge to the mobile device via the mobile communication link that is secure based on the security policy, the mobile communication link including the roaming node network and a mobile operator network that is managed by the communication service provider; and receive the challenge back from the mobile device via the mobile operator network and the communication service provider, the challenge including data added by the communication service provider, the data comprising a billing identifier that is associated with the mobile device, the billing identifier being securely received from the communication service provider via the mobile communication link. 11. A mobile communication system as recited in claim 10 , wherein the security policy request and the security policy response are included with authentication data messages that are communicated between the mobile device and the media content provider. 12. A mobile communication system as recited in claim 10 , wherein the security protocol service is further configured to receive the encryption policy for the roaming node network from the mobile device that maintains a cache of encryption policies stored locally on the mobile device. 13. A mobile communication system as recited in claim 10 , wherein the security protocol service is further configured to receive the region code that corresponds to the roaming node network from the communication service provider. 14. A mobile communication system as recited in claim 10 , wherein the security protocol service is further configured to: receive an indication that the roaming node network is changing to a different roaming node network to maintain the mobile communication link; and adapt the security policy for the end-to-end security of the mobile communication link for alternative security restrictions of the different roaming node n

Assignees

Inventors

Classifications

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title

  • Electricity · mapped topic

  • Access security · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9270700B2 cover?
Security protocols for mobile operator networks are described. In embodiments, mobile communication link is established between a mobile phone and a media content provider via a communication service provider with which the mobile phone is registered for mobile communications, and via at least one roaming node network with which the communication service provider has a roaming service agreement…
Who is the assignee on this patent?
Medvinsky Gennady, Mercer David E W, Microsoft Technology Licensing Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 23 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).