Authentication in a roaming environment
Abstract
One embodiment of the invention provides a mobile communication network architecture that includes a first base station (e.g., a first base station controller and/or a first transceiver station), a second base station a second base station controller and/or a second transceiver station), a mobile client, and a server coupled to the mobile client via either the first base station controller or the second base station. The first base station is coupled to an authentication center that authenticates an intended user so that the user can communicate a message between the mobile client and the server via the first base station. A credential (or status) of the authentication made at the authentication center is then transmitted from the first base station to the second base station when the mobile client moves to utilize the second base station to communicate with the server.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A mobile client configured to wirelessly communicate with a communication network, the mobile client comprising:
a hardware security module configured to transmit a cryptographic key; and a stateless module configured to securely receive the cryptographic key transmitted by the hardware security module and use the cryptographic key to perform a cryptographic service for the mobile client.
2 . The mobile client of claim 1 , further comprising:
a security boundary defining a secure usage environment of the cryptographic key, wherein the hardware security module and the stateless module are disposed in the security boundary.
3 . The mobile client of claim 1 , wherein the stateless module comprises a nonvolatile memory device configured to store an identity key, and the stateless module is further configured to establish a secure connection with the hardware security module using the identity key.
4 . The mobile client of claim 1 , wherein the hardware security module and the stateless module are configured to securely exchange the cryptographic key via a key transfer protocol.
5 . The mobile client of claim 1 , further comprising:
a cryptographic accelerator, coupled to the stateless module, configured to perform the cryptographic service with the stateless module.
6 . The mobile client of claim 5 , further comprising:
a security boundary defining a secure usage environment of the cryptographic key, wherein the hardware security module, the stateless module, and the cryptographic accelerator are disposed in the security boundary.
7 . The mobile client of claim 5 , wherein the stateless module and the cryptographic accelerator are implemented in hardware.
8 . The mobile client of claim 7 , wherein the stateless module and the cryptographic accelerator are implemented on a same integrated circuit.
9 . The mobile client of claim 1 , wherein the hardware security module is further configured to maintain state information associated with the cryptographic key.
10 . The mobile client of claim 1 , further comprising:
another stateless module, communicatively coupled to the hardware security module, and configured to securely receive, store, and use another cryptographic key transmitted by the hardware security module.
11 . The mobile client of claim 1 , wherein the hardware security module is a smartcard.
12 . The mobile client of claim 1 , wherein the hardware security module is a subscriber identification module (SIM).
13 . The mobile client of claim 1 , further comprising:
a processor configured to manage operation of the mobile client, wherein the stateless module is embedded in the processor.
14 . A mobile client configured to wirelessly communicate with a communication network, the mobile client comprising:
a hardware-implemented stateless module disposed in a security boundary defining a secure usage environment of a cryptographic key, wherein the stateless module is configured to establish a secure connection with a smartcard and securely receive the cryptographic key from the smartcard.
15 . The mobile client of claim 14 , wherein the stateless module comprises a nonvolatile memory device configured to store an identity key that is used to establish the secure connection with the smartcard.
16 . The mobile client of claim 14 , further comprising:
a cryptographic accelerator communicatively coupled to the stateless module and disposed in the security boundary, wherein the cryptographic accelerator is configured to perform a cryptographic service with the stateless module.
17 . The mobile client of claim 14 , wherein the stateless module and the cryptographic accelerator are implemented on a same integrated circuit.
18 . The mobile client of claim 14 , further comprising:
a processor configured to manage operation of the mobile client, wherein the stateless module is embedded in the processor.
19 . An integrated circuit comprising:
a stateless module configured to establish a secure connection with a smartcard and securely receive a cryptographic key from the smartcard; and a cryptographic accelerator, coupled to the stateless module, and configured to perform a cryptographic service with the stateless module, wherein the stateless module, smartcard, and cryptographic accelerator are disposed in a security boundary defining a secure usage environment of the cryptographic key, wherein the smartcard is remote from the integrated circuit.
20 . The integrated circuit of claim 19 , wherein the integrated circuit is disposed in a mobile client configured to wirelessly communicate with a communication network.Join the waitlist — get patent alerts
Track US2014050322A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.