Registration And Credential Roll-out For Accessing A Subscription-based Service
Abstract
A user may access a subscription-based service via a system comprising one or more devices with one or more separate domains where each domain may be owned or controlled by one or more different local or remote owners. Each domain may have a different owner, and a remote owner offering a subscription-based service may have taken ownership of a domain, which may be referred to as a remote owner domain. Further, the user may have taken ownership of a domain, which may be referred to as a user domain. In order for the user to access the subscription-based service, registration and credential roll-out may be needed. An exemplary registration and credential roll-out process may comprise registration of the user, obtaining credentials from the remote owner and storing the credentials.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . In a device comprising a plurality of security domains, a method comprising:
obtaining consent and authorization from a user of the device to register credentials associated with a network entity; after the consent and authorization are obtained, generating a first message comprising a registration token; sending the first message to the network entity; in response to the first message, receiving a second message comprising profile data associated with the network entity; verifying the profile data; downloading and installing the profile data at a security domain associated with the network entity so as to define a profile data download transaction, the profile data comprising the credentials; and sending a result of the profile data download transaction to the network entity.
2 . The method as recited in claim 1 , wherein the first message comprises a process identifier, the second message indicates the process identifier, and the process identifier provides a reference to uniquely identify the profile data download transaction.
3 . The method as recited in claim 1 , wherein the device further comprises a domain manager that manages the plurality of security domains, and the method further comprises:
exchanging, between the device and network entity, a certificate associated with the domain manager and a certificate associated with the domain manager.
4 . The method as recited in claim 1 , the method further comprising:
sending a first challenge nonce to the network entity; receiving a second challenge nonce, the process identifier, and a first signature over the first and second challenge nonces; verifying the first signature over the first and the second challenge nonces; and sending a response comprising a second signature over the second challenge nonce, so as to perform a mutual authentication between the security domain and the network entity.
5 . The method as recited in claim 2 , wherein:
the process identifier is at least one of a process identifier associated with the network entity, the device, or a point of sale.
6 . The method as recited in claim 1 , wherein the credentials of the profile data comprise an international mobile subscriber identity and a secret key associated with the network entity.
7 . The method as recited in claim 1 , wherein the network entity comprises a network credential provisioning entity, a point of sale server, or a remote owner.
8 . The method as recited in claim 1 , wherein the domain manager provides a secure container for the profile data, such that the security domain associated with the network entity is and isolated from other security domains on the device.
9 . The method as recited in claim 1 , wherein:
the registration token is a ticket; and the registration token provides an authorization to request the profile data, and the registration token contains information so as to allow an address of the network entity to be determined from the information in the registration token.
10 . A device comprising one or more processors, a memory, and a security domain, the device further comprising computer-executable instructions stored in the memory of the device which, when executed by the one or more processors of the device, cause the device to perform operations comprising:
obtaining consent and authorization from a user of the device to register credentials associated with a network entity; after the consent and authorization are obtained, generating a first message comprising a registration token; sending the first message to the network entity; in response to the first message, receiving a second message comprising profile data associated with the network entity; verifying the profile data; downloading and installing the profile data at a security domain associated with the network entity so as to define a profile data download transaction, the profile data comprising the credentials; and sending a result of the profile data download transaction to the network entity.
11 . The device as recited in claim 10 , wherein the first message comprises a process identifier, the second message indicates the process identifier, and the process identifier provides a reference to uniquely identify the profile data download transaction.
12 . The device as recited in claim 10 , wherein the process identifier is at least one of a process identifier bound to the network entity, the user, or a point of sale.
13 . The device as recited in claim 10 , wherein the credentials of the profile data comprise an international mobile subscriber identity and a shared key associated with the network entity.
14 . The device as recited in claim 10 , wherein the network entity comprises a network credential provisioning entity, a point of sale server, or a remote owner.
15 . The device as recited in claim 10 , wherein the registration token is a ticket, the registration token provides an authorization to request the profile data, and the registration token contains information so as to allow an address of the network entity to be determined from the information in the registration ticket.Join the waitlist — get patent alerts
Track US2017353472A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.