Identity management on a wireless device
Abstract
A wireless device may perform a local authentication to reduce the traffic on a network. The local authentication may be performed using a local web server and/or a local OpenID provider (OP) associated with the wireless device. The local web server and/or local OP may be implemented on a security module, such as a smartcard or a trusted execution environment for example. The local OP and/or local web server may be used to implement a provisioning phase to derive a session key, associated with a service provider, from an authentication between the wireless device and the network. The session key may be reusable for subsequent local authentications to locally authenticate a user of the wireless device to the service provider.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A method for performing local user authentication by a local authentication entity on a user device, the method comprising:
requesting authentication information from a user of the user device; receiving authentication information associated with the user of the user device to authenticate the user; locally verifying the authentication information by the local authentication entity; and upon successful user authentication, initiating an authentication protocol with a network entity using a credential associated with the local authentication entity, wherein the credential enables the network entity to verify an authenticity of the local authentication entity.
2 . The method of claim 1 , wherein the authentication protocol comprises a shared secret-based authentication protocol.
3 . The method of claim 1 , wherein the user authentication comprises at least one of a biometric verification, a password verification, or a token verification.
4 . A user device comprising a local authentication entity, a processor, a memory, and communication circuitry, the user device configured to connect to a communications network via the communication circuitry, the user device comprising computer-executable instructions stored in the memory of the user device which, when executed by the processor of the user device, perform operations comprising:
requesting authentication information from a user of the user device; receiving authentication information associated with the user of the user device to authenticate the user; locally verifying the authentication information by the local authentication entity; and upon successful user authentication, initiating an authentication protocol with a network entity using a credential associated with the local authentication entity, wherein the credential enables the network entity to verify an authenticity of the local authentication entity.
5 . The user device of claim 4 , wherein the authentication protocol comprises a shared secret-based authentication protocol.
6 . The user device of claim 4 , wherein the user authentication comprises at least one of a biometric verification, a password verification, or a token verification.
7 . A computer-readable storage medium comprising executable instructions which, when executed by a processor, cause the processor to effectuate operations comprising:
requesting authentication information from a user of the user device; receiving authentication information associated with the user of the user device to authenticate the user; locally verifying the authentication information by the local authentication entity; and upon successful user authentication, initiating an authentication protocol with a network entity using a credential associated with the local authentication entity, wherein the credential enables the network entity to verify an authenticity of the local authentication entity.
8 . The computer-readable storage medium of claim 7 , wherein the authentication protocol comprises a shared secret-based authentication protocol.
9 . The computer readable storage medium of claim 7 , wherein the user authentication comprises at least one of a biometric verification, a password verification, or a token verification.Join the waitlist — get patent alerts
Track US2016073262A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.