Identity and access management

US9705871B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9705871-B2
Application numberUS-201414510698-A
CountryUS
Kind codeB2
Filing dateOct 9, 2014
Priority dateDec 13, 2013
Publication dateJul 11, 2017
Grant dateJul 11, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An access management account that includes an access identifier may be used to control access to telecommunications services or applications. An access identifier is designated for obtaining access to multiple telecommunications services or applications, in which the multiple telecommunications services or applications are accessible to a user through multiple user accounts that are protected by account credentials. Once the access credential is designated, the access credential may be used to determine whether access to the one or more telecommunications services or applications is to be granted instead of using the account credentials of the multiple user accounts.

First claim

Opening claim text (preview).

What is claimed is: 1. A method of providing access to services via a communications network, comprising: receiving, a request to access at least one telecommunications service or application at a user device, the request including a user device identifier that has been assigned to the user device by a wireless access network that provides cellular communication services to multiple user devices, the at least one telecommunications service or application being accessible through at least one user account that is protected by account credentials; determining that the user device identifier is associated with an access identifier stored in an access management account at the wireless access network, the access identifier providing access to the at least one telecommunications service or application via the at least one user account, the access identifier being different from the account credentials of the at least one user account; and determining whether to grant access to the at least one telecommunications service or application at the user device based on the access identifier. 2. The method of claim 1 , further comprising: accessing a portion of a user profile associated with the user device following a determination that the user device is granted access to the at least one telecommunications service or application, the portion of the user profile being less than an entirety of the user profile; and providing the at least one telecommunications service or application with access to the portion of the user profile. 3. The method of claim 2 , wherein determining that the portion of the user profile is accessible by the at least one telecommunications service or application is based at least in part on permissions associated with the access identifier or permissions associated with the at least one telecommunications service or application. 4. The method of claim 1 , further comprising updating a user profile associated with the user device to indicate that the user is logged in on the user device such that the user device is able to access the at least one a plurality of telecommunications service services or application applications via the user device. 5. The method of claim 1 , further comprising routing telephone calls to the user device based at least in part on a determination that the user device is granted access to the at least one telecommunications service or application. 6. The method of claim 1 , wherein the user device-identifier includes one of a token assigned to the user device, a subscriber identity module (SIM) secret, authentication and key agreement (AKA) authentication data, or generic bootstrap architecture (GBA) authentication data. 7. The method of claim 1 , wherein the user device-identifier is an International Mobile Subscriber Identity (IMSI) that is assigned to the user device by the wireless access network. 8. The method of claim 1 , wherein determining whether to grant access to the at least one telecommunications service or application is further based on a validation of the user device identifier and an additional login credential. 9. The method of claim 8 , further comprising: delegating the validation of the user device identifier and the additional login credential to a third party that is unaffiliated with the communications network. 10. A system, comprising: one or more processors; and memory having instructions stored therein, the instructions, when executed by the one or more processors, cause the one or more processors to implement components comprising: an access component configured to receive, from a user device, a request to access a telecommunications service or application, the telecommunications service or application being accessible through a user account that is protected by account credentials, the access component further configured to determine whether to grant the user device access to the telecommunications service or application at the user device based at least on an access identifier that is determined by the access component, the access identifier being associated with a user device identifier provided with the request, the access identifier further being used by the access component instead of the account credentials of the user account to determine whether to grant the user device access, the access identifier being different from the account credentials, the user device identifier being assigned to the user device by a wireless access network that provides cellular communication services to multiple user devices; and a service routing component configured to route the telecommunications service or application to the user device in response to the access identifier being validated by the access component. 11. The system of claim 10 , wherein the service routing component is further configured to route the telecommunications service or application based on a user profile, the user profile storing at least one of multiple mobile telecommunications network carrier subscription identifiers, a device identifier of the user device, or user identification information associated with the user device. 12. The system of claim 11 , further comprising a profile filter component that filters user information in the user profile that is provided to an application for the application to access a service from the user device, the user information being filtered by the profile filter component in response to an application level of the application that indicates whether the application is a background application installed on the user device, is preapproved for use on the user device, or an unapproved application that is downloaded from a network application store. 13. The system of claim 10 , wherein the access component is further configured to determine whether to grant the user device access to the telecommunications service or application based on an additional login credential that is requested in response to a risk analysis. 14. The system of claim 10 , wherein the access component is further configured to automatically populate a user authentication interface with identification information from a user profile associated with the user device, the user authentication interface being used by the access component to request additional login credential for determining whether to grant the user device access to the telecommunications service or application. 15. The system of claim 10 , wherein the access component is further configured to provide an access credential to a user device in response to determining that the user device is granted access to the telecommunications service or application at the user device, the access credential being used by one or more applications on the user device as an authenticator for accessing the telecommunications service or application. 16. A user device, comprising: one or more processors; and memory having instructions stored therein, the instructions, when executed by the one or more processors, cause the one or more processors to implement components comprising: a plurality of client applications, each client application configured to communicate with a corresponding service provider for providing a corresponding service of a plurality of telecommunications services or applications at the user device, the plurality of telecommunications services or applications being accessible using account credentials of a corresponding user for the plurality of telecommunications services or applications; a device agent configured to provide multiple access identifiers that identify multiple users that are concurrently l

Assignees

Inventors

Classifications

  • G06F21/41Primary

    where a single sign-on provides access to a plurality of computers · CPC title

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

  • One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key · CPC title

  • providing single-sign-on or federations · CPC title

  • Access security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9705871B2 cover?
An access management account that includes an access identifier may be used to control access to telecommunications services or applications. An access identifier is designated for obtaining access to multiple telecommunications services or applications, in which the multiple telecommunications services or applications are accessible to a user through multiple user accounts that are protected b…
Who is the assignee on this patent?
T Mobile Usa Inc, T-Mobile U S A Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/41. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jul 11 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).