US2014258710A1PendingUtilityA1

Mobile Handset Identification and Communication Authentication

Assignee: ENTERSECT INTERNAT LTDPriority: Sep 30, 2010Filed: Mar 14, 2014Published: Sep 11, 2014
Est. expirySep 30, 2030(~4.2 yrs left)· nominal 20-yr term from priority
H04L 63/061H04L 63/168H04L 9/3247H04W 88/02H04L 9/321H04L 63/0869H04W 12/0431H04L 9/3263H04L 9/0825H04L 63/0823H04W 12/06H04W 12/04H04L 2209/80
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Disclosed is a system and method for authenticating a communications channel between a mobile handset associated with a user and an application server for uniquely identifying the mobile handset and for encrypting communications between the mobile handset and the application server over the communication channel is provided. The system includes a certificate authority configured to issue digital certificates to the handset and the application server, as well as software applications operating on both the handset and application server. The digital certificates may be used by the handset and application server to uniquely identify one another as well as to exchange encryption keys by means of which further communication between them may be encrypted.

Claims

exact text as granted — not AI-modified
The invention claimed is: 
     
         1 . A method of enabling authentication of a communications channel between a mobile handset associated with a user and an application server and unique identification of the mobile handset by the application server, the method being carried out at a certificate authority and including the steps of:
 receiving a request for a digital user certificate from the mobile handset, the request having been sent from a user side software application installed on the mobile handset;   calculating a unique asymmetric key pair including a user private and public key on behalf of the mobile handset if the mobile handset does not have enough processing power to do so itself, and issuing the user certificate to the mobile handset, the user certificate including at least one identifier uniquely associated with the mobile handset by means of which the mobile handset may be uniquely identified and the user public key;   issuing a digital server certificate to the application server; and   including a digital signature in both the user certificate and the server certificate enabling the user side software application and the server side software application to exchange certificates and validate the respective certificates by using at least the digital signature and an encryption module provided by the certificate authority.   
     
     
         2 . The method as claimed in  claim 1 , further including the step of, upon receiving the request, securing a communication channel with the mobile handset by means of a suitable key exchange protocol and transmitting at least the user private key to the mobile handset over the secure communication channel.

Join the waitlist — get patent alerts

Track US2014258710A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.