Secure registration of group of clients using single registration procedure

US9450928B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9450928-B2
Application numberUS-81315310-A
CountryUS
Kind codeB2
Filing dateJun 10, 2010
Priority dateJun 10, 2010
Publication dateSep 20, 2016
Grant dateSep 20, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Automated secure registration techniques for communication devices are provided which address the problem of allowing multiple clients to gain access to one system, and thus provide a solution to the “reverse single sign-on” problem. For example, a method for registering a group of two or more communication devices in a communication network comprises the following steps. A group challenge message is sent from a network device to the group of two or more communication devices. The network device receives one or more response messages to the group challenge respectively from one or more of the group of two or more communication devices, wherein the response message from each of the responding communication devices in the group comprises a group credential corresponding to the group.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for registering a group of two or more communication devices in a communication network, comprising: sending, from a network device, a group challenge message to the group of two or more communication devices; receiving, at the network device, two or more response messages to the group challenge respectively from two or more of the group of two or more communication devices, wherein the response message from each of the responding communication devices in the group comprises a same group credential corresponding to the group; aggregating, at the network device, the response messages to the group challenge received from the communication devices in the group; and sending, from the network device, an aggregate message to an authenticator in the communication network to mutually authenticate, as a group, at least two of the communication devices with the authenticator to establish an individual session key for each of said at least two communication devices. 2. The method of claim 1 , wherein the group challenge message is broadcast by the network device. 3. The method of claim 1 , wherein the network device comprises an authentication server. 4. The method of claim 1 , wherein the network device comprises a gateway entity. 5. The method of claim 1 , wherein the network device comprises a base station. 6. The method of claim 1 , wherein the group credential comprises a group key. 7. The method of claim 1 , wherein group registration is secure via mutual authentication between the communication devices of the group and the network device using an agreed upon key. 8. The method of claim 1 , wherein the group credentials are provisioned prior to the registration method being performed, and the group credentials are the same for each of the two or more communication devices in the group. 9. The method of claim 8 , wherein the group credentials are provisioned to each communication device or to the network device. 10. The method of claim 1 , wherein the two or more communication devices in the group are grouped together based on a given policy. 11. The method of claim 1 , further comprising performing a mutual authentication between the network device and the communication network prior to the registration of the two or more communication devices. 12. The method of claim 11 , wherein the mutual authentication comprises the network device performing an authentication and key agreement procedure with a gateway support node of the communication network. 13. The method of claim 1 , wherein the network device establishes a communication connection with each of the two or more communication devices in the group. 14. The method of claim 13 , wherein the step of establishing the communication connection between the network device and each of the two or more communication devices in the group further comprises the network device receiving an activation message for the group from an application server of the communication network such that the network device can identify the communication devices that belong to the given group and establish the communication connection therewith. 15. The method of claim 13 , wherein the step of establishing the communication connection between the network device and each of the two or more communication devices in the group further comprises each of the communication devices self-activating and establishing the communication connection with the network device. 16. The method of claim 13 , wherein one of the communication devices of the group establishes a communication connection with the network device and then deactivates such that reactivation and authentication can be performed at a later time. 17. The method of claim 13 , wherein the network device establishes the communication connection with a subset of the communication devices in the group and waits, for a given time period, to receive response messages from all the communication devices in the group before authentication proceeds. 18. The method of claim 13 , wherein the communication connection is established using an unlicensed communication spectrum. 19. The method of claim 1 , wherein all of the communication devices in the group are mutually authenticated with the authenticator, as a group. 20. The method of claim 1 , wherein the authenticator is a gateway support node in the communication network. 21. The method of claim 1 , wherein the authenticator is a subscriber server in the communication network. 22. The method of claim 1 , wherein the authenticator is an application server in the communication network. 23. The method of claim 1 , wherein the group credentials are unknown to the network device. 24. The method of claim 1 , wherein the network device authenticates the communication devices in the group. 25. The method of claim 1 , further comprising the step of the network device obtaining address assignments for the two or more communication devices in the group. 26. The method of claim 25 , wherein the address assignments comprise an individual network address for each communication device in the group and a multicast network address corresponding to the group. 27. The method of claim 1 , wherein, once each communication device of the group is authenticated, the communication device establishes a data session with an application server. 28. The method of claim 1 , wherein, once each communication device of the group is authenticated, the individual session key is established for that communication device of the group. 29. The method of claim 28 , wherein a group session key is established for the group. 30. The method of claim 29 , wherein respective application keys are generated from the session keys. 31. Apparatus for use in registering a group of two or more communication devices in a communication network, comprising: a memory associated with a network device; and a processor associated with the network device, coupled to the memory, and configured to: send a group challenge message to the group of two or more communication devices; receive two or more response messages to the group challenge respectively from two or more of the group of two or more communication devices, wherein the response message from each of the responding communication devices in the group comprises a same group credential corresponding to the group; aggregate the response messages to the group challenge received from the communication devices in the group; and send an aggregate message to an authenticator in the communication network to mutually authenticate, as a group, at least two of the communication devices with the authenticator to establish an individual session key for each of said at least two communication devices. 32. A method for registering a group of two or more communication devices in a communication network, comprising: receiving, at a given one of the communication devices of the group, a group challenge message sent by a network device to the group of two or more communication devices; sending, from the given one of the communication devices of the group to the network device, a response message to the group challenge, such that the network device receives respective response messages from two or more of the group of two or more communication devices, and w

Assignees

Inventors

Classifications

  • Services specially adapted for wireless communication networks; Facilities therefor · CPC title

  • H04L63/065Primary

    for group communications (cryptographic mechanisms or cryptographic arrangements for key management involving conference or group key H04L9/0833) · CPC title

  • providing single-sign-on or federations · CPC title

  • Services for machine-to-machine communication [M2M] or machine type communication [MTC] · CPC title

  • by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9450928B2 cover?
Automated secure registration techniques for communication devices are provided which address the problem of allowing multiple clients to gain access to one system, and thus provide a solution to the “reverse single sign-on” problem. For example, a method for registering a group of two or more communication devices in a communication network comprises the following steps. A group challenge mess…
Who is the assignee on this patent?
Broustis Ioannis, Sundaram Ganapathy S, Viswanathan Harish, and 1 more
What technology area does this patent fall under?
Primary CPC classification H04L63/065. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 20 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).