Method and Apparatus for Trusted Federated Identity Management and Data Access Authorization
Abstract
Systems, methods, and instrumentalities are disclosed that may provide for integration of trusted OpenID (TOpenID) with OpenID. The authentication may be accomplished, in part, via communications between a trusted ticket server on a UE and a network application function. The UE may retrieve platform validation data (e.g., from a trusted platform module on the UE). The UE may receive a platform verification in response to the platform validation data. The platform verification may indicate that the network application function has verified the platform validation data and the user. The platform verification may indicate that the platform validation data matches a previously generated reference value.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A wireless device comprising a processor, a trusted ticket server, a memory, and communication circuitry, the wireless device being connected to a communications network via its communication circuitry, the wireless device including computer-executable instructions stored in the memory of the wireless device which, when executed by the processor of the wireless device, perform operations comprising:
receiving an authentication request from a network application function, the authentication request comprising an identity that corresponds to a user of the wireless device; based on the authentication request, retrieving, by the trusted ticket server, authentication data and platform validation data using a storage root key, wherein the platform validation data includes a measure of trustworthiness of the wireless device and a measure of trustworthiness of the trusted ticket server, and the authentication data is associated with the identity that corresponds to the user; sending the platform validation data and the authentication data associated with the identity that corresponds to the user to the network application function; and receiving verification data indicating that the network application function has verified the platform validation data and the identity that corresponds to the user.
2 . The wireless device of claim 1 , wherein the verification data indicates that a system state indicated by the platform validation data matches a previously generated reference value.
3 . The wireless device of claim 1 , wherein the platform validation data is signed.
4 . The wireless device of claim 1 , wherein the platform validation data includes a user identification parameter.
5 . The wireless device of claim 1 , wherein the platform validation data includes attestation data.
6 . The wireless device of claim 5 , wherein the attestation data a platform configuration register quote signed with an attestation identity key.
7 . The wireless device of claim 1 , the operations further comprising receiving a ticket comprising the verification data, wherein the ticket is capable of being reused to perform a subsequent authorization without revalidation of the wireless device.
8 . The wireless device of claim 7 , wherein the ticket includes a timestamp.
9 . The wireless device of claim 7 , wherein the ticket includes an origination timestamp.
10 . The wireless device of claim 7 , wherein the ticket includes a lifetime limit.
11 . The wireless device of claim 7 , wherein the ticket includes an end date.
12 . The wireless device of claim 7 , wherein the ticket includes a usage parameter limit.
13 . The wireless device of claim 7 , the operations further comprising receiving a ticket reference from a network entity.
14 . The wireless device of claim 13 , wherein the ticket reference is capable of being used to obtain the ticket from the network application function, and wherein the verification data is capable of being reused to perform a subsequent authorization without revalidation of the wireless device.
15 . The wireless device of claim 1 , the operations further comprising:
establishing a connection to a relying party; receiving a browser redirection to the network application function; and sending an authentication request to the network application function.
16 . The wireless device of claim 1 , wherein the verification data indicates access granted to a relying party.Join the waitlist — get patent alerts
Track US2015067813A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.