Wireless network application access by a wireless communication device via an untrusted access node

US9560524B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9560524-B1
Application numberUS-201314095686-A
CountryUS
Kind codeB1
Filing dateDec 3, 2013
Priority dateDec 3, 2013
Publication dateJan 31, 2017
Grant dateJan 31, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Embodiments disclosed herein provide systems and methods to provide wireless network application access to a wireless device via an untrusted access node. In a particular embodiment, a method provides receiving communications directed to an application system within a wireless communication network from a wireless communication device via a wireless access node external to the wireless communication network. The method further provides determining whether the communications are authorized for the application system based on a signature included in the communications, wherein the signature comprises a unique identifier generated at the wireless communication device that corresponds to an identity of the wireless communication device and an identity of an integrated circuit within that wireless communication device that is associated with a subscriber of the wireless communication network. Upon determining that the communications are authorized, the method provides transferring the communications to the application system.

First claim

Opening claim text (preview).

What is claimed is: 1. A method of operating a wireless communication system to authorize communications, the method comprising: receiving communications directed to an application system in a wireless communication network from a wireless communication device via an untrusted wireless access node external to the wireless communication network, wherein the application system provides a communications service in the wireless communication network and the wireless communication device has been previously authenticated to access the wireless communication network via a trusted wireless access node; processing a signature included with the communications to determine when the communications are authorized for the communication service provided by the application system, wherein the communications comprise a plurality of data packets and the signature is included in a header of the data packets, the signature comprising a unique identifier generated at the wireless communication device corresponding to an identity of the wireless communication device and an identity of an integrated circuit within the wireless communication device that is associated with a subscriber of the wireless communication network; and when the communications are authorized for the communication service, replacing an IP address associated with the data packets with a private IP address that is trusted by the wireless communication network and transferring the communications to the application system. 2. The method of claim 1 , wherein the communications are authorized when the signature indicates that the communications are transferred from an authorized wireless communication device having an authorized integrated circuit therein. 3. The method of claim 1 , wherein the unique identifier comprises an output of a hash function using, as inputs, at least a device identifier for the wireless communication device, an identifier for the integrated circuit, and an application identifier that identifies an application associated with the communications. 4. The method of claim 3 , wherein the integrated circuit comprises a subscriber identity module (SIM). 5. The method of claim 3 , wherein the hash function further uses an authentication key (A-key) and shared secret data (SSD) information as input. 6. The method of claim 5 , wherein the A-key and SSD information is obtained from an ANSI IS-41 authentication of the wireless communication device. 7. The method of claim 1 , wherein, when the communications are authorized for the communication service, the application system treats the communications as though the communications were received via an access node of the wireless communication network. 8. A wireless communication system, comprising: a communication interface including electronic circuitry configured to receive communications directed to an application system within a wireless communication network from a wireless communication device via an untrusted wireless access node external to the wireless communication network, wherein the application system provides a communications service in the wireless communication network and the wireless communication device has been previously authenticated to access the wireless communication network via a trusted wireless access node; a processing system configured to determine when the communications are authorized for the communication service provided by the application system based on a signature included with the communications, wherein the communications comprise a plurality of data packets and the signature is included in a header of the data packets, the signature comprising a unique identifier generated at the wireless communication device that corresponds to an identity of the wireless communication device and an identity of an integrated circuit within the wireless communication device that is associated with a subscriber of the wireless communication network, and when the communications are authorized for the communication service, replace an IP address associated with the data packets with a private IP address that is trusted by the wireless communication network; and the communication interface further configured to transfer the communications to the application system when the communications are authorized for the communication service. 9. The wireless communication system of claim 8 , wherein the communications are authorized when the signature indicates that the communications are transferred from an authorized wireless communication device having an authorized integrated circuit therein. 10. The wireless communication system of claim 8 , wherein the unique identifier comprises an output of a hash function using, as inputs, at least a device identifier for the wireless communication device, an identifier for the integrated circuit, and an application identifier that identifies an application associated with the communications. 11. The wireless communication system of claim 10 , wherein the integrated circuit comprises a subscriber identity module (SIM). 12. The wireless communication system of claim 10 , wherein the hash function further uses an authentication key (A-key) and shared secret data (SSD) information as input. 13. The wireless communication system of claim 12 , wherein the A-key and SSD information is obtained from an ANSI IS-41 authentication of the wireless communication device. 14. The wireless communication system of claim 8 , wherein, when the communications are authorized for the communication service, the application system treats the communications as though the communications were received via an access node of the wireless communication network. 15. A wireless communication device, comprising: an integrated circuit that is associated with a subscriber of a wireless communication network; a processing system configured to generate a signature for inclusion with communications directed to an application system that provides a communications service on a wireless communication network, wherein the communications comprise a plurality of data packets and the signature is included in a header of the data packets, the signature comprising a unique identifier that corresponds to an identity of the wireless communication device and an identity of the integrated circuit, and wherein the wireless communication device has been previously authenticated to access the wireless communication network via a trusted wireless access node; a communication interface configured to transfer the communications via an untrusted wireless access node external to the wireless communication network, wherein an edge node of the wireless communication network receives the communications, determines whether the communications are authorized for the application system based on the signature, and when the communications are authorized, replaces an IP address associated with the data packets with a private IP address that is trusted by the wireless communication network when the communications are authorized and transfers the communications to the application system. 16. The wireless communication device of claim 15 , wherein the communications are authorized when the signature indicates that the communications are transferred from an authorized wireless communication device having an authorized integrated circuit therein.

Assignees

Inventors

Classifications

  • H04W12/06Primary

    Authentication · CPC title

  • H04W12/08Primary

    Access security · CPC title

  • Virtual private networks · CPC title

  • Filtering by address, protocol, port number or service, e.g. IP-address or URL · CPC title

  • Hardware identity · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9560524B1 cover?
Embodiments disclosed herein provide systems and methods to provide wireless network application access to a wireless device via an untrusted access node. In a particular embodiment, a method provides receiving communications directed to an application system within a wireless communication network from a wireless communication device via a wireless access node external to the wireless communic…
Who is the assignee on this patent?
Sprint Communications Co Lp
What technology area does this patent fall under?
Primary CPC classification H04W12/06. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 31 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).