Cellular device authentication

US9699655B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9699655-B1
Application numberUS-201615051447-A
CountryUS
Kind codeB1
Filing dateFeb 23, 2016
Priority dateFeb 23, 2016
Publication dateJul 4, 2017
Grant dateJul 4, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

When manufacturing, distributing, or selling mobile phones, each phone is associated with an asymmetric cryptographic key pair, comprising a public key and a private key. The private key is stored on the phone, and the public key is stored in a public key repository. When connecting to a cellular network, a phone provides its device ID to the network. The cellular network queries the public key repository to determine the public key of the phone and authenticates the phone using the phone's public key. The cellular network also provides a digital identity certificate to the phone, allowing the phone to authenticate the cellular network using a public key infrastructure (PKI).

First claim

Opening claim text (preview).

What is claimed is: 1. A method performed by a cellular communications network server, the method comprising: receiving a device identifier from a cellular communication device, the cellular communication device being associated with an asymmetric cryptographic key pair comprising a private key and a public key; accessing a key repository using the device identifier to determine the public key of the cellular communication device, the key repository cross-referencing device identifiers to respectively corresponding public keys; authenticating the cellular communication device using the public key of the cellular communication device; sending a digital identity certificate to the cellular communication device for authentication by the cellular communication device of the cellular communications network server; exchanging one or more session keys with the cellular communication device; and encrypting communications between the cellular communications network server and the cellular communication device using the one or more session keys. 2. The method of claim 1 , further comprising storing the private key on the cellular communication device prior to selling the cellular communication device to a consumer. 3. The method of claim 1 , wherein: the private key is stored on the cellular communication device by a seller of the cellular communication device; and the key repository is maintained at least in part by the seller of the cellular communication device. 4. The method of claim 1 , wherein authenticating the cellular communication device comprises: sending a first value to the cellular communication device; receiving a second value from the cellular communication device; decrypting the second value; and determining that the second value is the same as the first value. 5. The method of claim 1 , further comprising: sending configuration information to the cellular communication device; generating a digital signature of the configuration information; and sending the digital signature to the cellular communication device. 6. The method of claim 1 , further comprising: encrypting the one or more session keys; wherein exchanging the one or more session keys with the cellular communication device comprises sending one or more encrypted session keys to the cellular communication device. 7. The method of claim 1 , wherein exchanging the one or more session keys with the cellular communication device comprises receiving one or more encrypted session keys from the cellular communication device; the method further comprising decrypting the one or more encrypted session keys. 8. A cellular communications network server comprising: a processor; and executable instructions that, when executed by the processor, cause the cellular communications network server to perform operations including: receiving a device identifier from a cellular communication device, the cellular communication device being associated with an asymmetric cryptographic key pair comprising a private key and a public key; accessing a key repository using the device identifier to determine the public key of the cellular communication device, the key repository cross-referencing device identifiers to respectively corresponding public keys; authenticating the cellular communication device using the public key of the cellular communication device; sending a digital identity certificate to the cellular communication device for authentication by the cellular communication device of the cellular communications network server; exchanging one or more session keys with the cellular communication device; and encrypting communications between the cellular communications network server and the cellular communication device using the one or more session keys. 9. The cellular communications network server of claim 8 , wherein the operations further include storing the private key on the cellular communication device prior to selling the cellular communication device to a consumer. 10. The cellular communications network server of claim 8 , wherein: the private key is stored on the cellular communication device by a seller of the cellular communication device; and the key repository is maintained at least in part by the seller of the cellular communication device. 11. The cellular communications network server of claim 8 , wherein authenticating the cellular communication device comprises: sending a first value to the cellular communication device; receiving a second value from the cellular communication device; decrypting the second value; and determining that the second value is the same as the first value. 12. The cellular communications network server of claim 8 , wherein the operations further include: sending configuration information to the cellular communication device; generating a digital signature of the configuration information; and sending the digital signature to the cellular communication device. 13. The cellular communications network server of claim 8 , wherein the operations further include: encrypting the one or more session keys; wherein exchanging the one or more session keys with the cellular communication device comprises sending one or more encrypted session keys to the cellular communication device. 14. The cellular communications network server of claim 8 , wherein exchanging the one or more session keys with the cellular communication device comprises receiving one or more encrypted session keys from the cellular communication device; the operations further comprising decrypting the one or more encrypted session keys. 15. A non-transitory computer-readable medium having instructions stored thereon that, when executed by a processor of a cellular communications network server, cause the cellular communications network server to perform operations comprising: receiving a device identifier from a cellular communication device, the cellular communication device being associated with an asymmetric cryptographic key pair comprising a private key and a public key; accessing a key repository using the device identifier to determine the public key of the cellular communication device, the key repository cross-referencing device identifiers to respectively corresponding public keys; authenticating the cellular communication device using the public key of the cellular communication device; sending a digital identity certificate to the cellular communication device for authentication by the cellular communication device of the cellular communications network server; exchanging one or more session keys with the cellular communication device; and encrypting communications between the cellular communications network server and the cellular communication device using the one or more session keys. 16. The non-transitory computer-readable medium of claim 15 , wherein the operations further include storing the private key on the cellular communication device prior to selling the cellular communication device to a consumer. 17. The non-transitory computer-readable medium of claim 15 , wherein authenticating the cellular communication device comprises: sending a first value to the cellular communication device; receiving a second value from the cellular communication device; decrypting the second value; and determining that the second value is the same as the first value. 18. The non-transitory computer-readable medium of claim 15 , wherein the operations further include: sending configuration information to the cellular communica

Assignees

Inventors

Classifications

  • wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption (cryptographic mechanisms or cryptographic arrangements for public-key encryption H04L9/30) · CPC title

  • involving digital signatures · CPC title

  • H04L9/006Primary

    involving public key infrastructure [PKI] trust models (network architecture or network communication protocol for supporting authentication of entities using certificates in a packet data network H04L63/0823) · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • Wireless · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9699655B1 cover?
When manufacturing, distributing, or selling mobile phones, each phone is associated with an asymmetric cryptographic key pair, comprising a public key and a private key. The private key is stored on the phone, and the public key is stored in a public key repository. When connecting to a cellular network, a phone provides its device ID to the network. The cellular network queries the public key…
Who is the assignee on this patent?
T Mobile Usa Inc
What technology area does this patent fall under?
Primary CPC classification H04L9/006. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 04 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).