Method and system for the provision of services for terminal devices

US9444814B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9444814-B2
Application numberUS-45020808-A
CountryUS
Kind codeB2
Filing dateMar 3, 2008
Priority dateMar 16, 2007
Publication dateSep 13, 2016
Grant dateSep 13, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Services are provided for terminal devices, each having a TPM module. The TPM module of a terminal device transmits a service request with an ID assertion signed by a configurable credential to a server for the purpose of accessing the services of the server.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for provision of services for terminal devices, each of which has a trusted platform module, comprising: configuring, by a network operator in a trusted platform module of a terminal device, an access control list containing credentials associated with different servers for different services; and sending, by the trusted platform module of the terminal device, a service request with an identification assertion, signed by a configurable credential, to a server for access to the services thereof, if the configurable credential exists as an entry in the access control list. 2. The method as claimed in claim 1 , further comprising by the server on receipt of the service request with the identification assertion, validating the credential; and verifying a signature included in the identification assertion. 3. The method as claimed in claim 1 , further comprising configuring the credential by the network operator in the trusted platform module of the terminal device. 4. The method as claimed in claim 1 , further comprising forming the credential using a certificate of the network operator. 5. The method as claimed in claim 1 , wherein the identification assertion includes user identity information data, a certificate of the network operator, a time stamp and service-specific access restrictions. 6. The method as claimed in claim 1 , further comprising the terminal device regularly sending a useful service usage report to a network operator. 7. The method as claimed in claim 1 , wherein the credential becomes invalid after a predetermined lifetime. 8. The method as claimed in claim 1 , further comprising forming the identification assertion based on a security assertion mark-up language identification assertion. 9. The method as claimed in claim 1 , further comprising initially registering the trusted platform module with the respective server. 10. A terminal device communicating with a server, comprising: a trusted platform module sending a service request with an identification assertion, signed by a configurable credential, to the server for access to services provided by the server, if the configurable credential exists as an entry in an access control list containing credentials associated with different servers for different services and being configured by a network operator in the trusted platform module of the terminal device. 11. The terminal device as claimed in claim 10 , further comprising a single sign-on module. 12. A server for provision of services for at least one terminal device having a trusted platform module, comprising: a receiver receiving from the at least one terminal device a service request with an identification assertion, signed by a configurable credential, for access to services provided by the server, if the configurable credential exists as an entry in an access control list containing credentials associated with different servers for different services and being configured by a network operator in the trusted platform module of the at least one terminal device; and a processor programmed to perform operations following receipt of the service request with the identification assertion signed by a configurable credential, including validating the credential for the provision of at least one service for the at least one terminal device and verifying a signature included in the identification assertion. 13. A system for provision of services, comprising: terminal devices, each having a trusted platform module with a network operator configuring credentials and sending service requests with identification assertions, signed by a configured credential, for access to a service if the configurable credential exists as an entry in an access control list containing credentials associated with different servers for different services and being configured by the network operator therein; and a server validating the credential for the provision of at least one service for one of the terminal devices and verifying a signature included in the identification assertion. 14. The method as claimed in claim 1 , wherein the identification assertion signed by the configurable credential obtained from the access control list by the trusted platform module of the terminal device is sent by the trusted platform module of the terminal device to the server to obtain access to the services provided by the server after verification of the configurable credential by the server. 15. The terminal device as claimed in claim 10 , wherein the identification assertion signed by the configurable credential obtained from the access control list by the trusted platform module of the terminal device is sent by the trusted platform module of the terminal device to the server to obtain access to the services provided by the server after verification of the configurable credential by the server. 16. The server as claimed in claim 12 , wherein the identification assertion signed by the configurable credential obtained from the access control list by the trusted platform module of the at least one terminal device is sent by the trusted platform module of the at least one terminal device to the server to obtain access to the services provided by the server after verification of the configurable credential by the server. 17. The system as claimed in claim 13 , wherein the identification assertion signed by the configurable credential obtained from the access control list by the trusted platform module of the one of the terminal devices is sent by the trusted platform module of the one of the terminal devices to the server to obtain access to the services provided by the server after verification of the configurable credential by the server.

Assignees

Inventors

Classifications

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • providing single-sign-on or federations · CPC title

  • Applying verification of the received information (cryptographic mechanisms or cryptographic arrangements for data integrity or data verification H04L9/32) · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

  • Access control lists [ACL] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9444814B2 cover?
Services are provided for terminal devices, each having a TPM module. The TPM module of a terminal device transmits a service request with an ID assertion signed by a configurable credential to a server for the purpose of accessing the services of the server.
Who is the assignee on this patent?
Moeller Wolf-Dietrich, Shanmugam Murugaraj, Tschofenig Hannes, and 1 more
What technology area does this patent fall under?
Primary CPC classification H04L63/0853. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 13 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).