US2018242129A1PendingUtilityA1

Method and Apparatus for Enabling Machine To Machine Communication

Assignee: INTERDIGITAL PATENT HOLDINGS INCPriority: Jan 18, 2008Filed: Apr 17, 2018Published: Aug 23, 2018
Est. expiryJan 18, 2028(~1.5 yrs left)· nominal 20-yr term from priority
H04L 63/0823H04W 4/50H04L 63/12H04W 4/70H04W 84/22H04W 12/10H04L 9/3234H04W 12/08H04L 9/08H04W 12/06G06F 2221/2153G06F 2221/2151G06F 2221/2101G06F 21/575G06F 2221/2105H04L 67/10H04W 24/00H04L 63/062H04W 8/06H04L 67/125H04W 12/04H04W 8/26H04L 63/20G06F 21/57H04W 12/35H04W 12/75H04W 4/00
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and apparatus for performing secure Machine-to-Machine (M2M) provisioning and communication is disclosed. In particular a temporary private identifier, or provisional connectivity identification (PCID), for uniquely identifying machine-to-machine equipment (M2ME) is also disclosed. Additionally, methods and apparatus for use in validating, authenticating and provisioning a M2ME is also disclosed. The validation procedures disclosed include an autonomous, semi-autonomous, and remote validation are disclosed. The provisioning procedures include methods for re-provisioning the M2ME. Procedures for updating software, and detecting tampering with the M2ME are also disclosed.

Claims

exact text as granted — not AI-modified
1 - 14 . (canceled) 
     
     
         15 . A method performed by a wireless device, comprising:
 initiating secure communications with a first wireless network, using a provisional connectivity identifier (PCID), to obtain operational access to a desired wireless network;   establishing, via the first wireless network, a protected IP-based connection with a first functional entity reachable via the first wireless network;   establishing, over the protected IP-based connection, a security association with a second functional entity reachable via the first wireless network;   receiving, from the second functional entity via the protected IP-based connection, a profile, wherein the profile comprises an identity and at least one credential for use in authenticating with and operationally accessing the desired wireless network; and   provisioning the received profile on the wireless device.   
     
     
         16 . The method of  claim 15 , further comprising:
 activating the received profile;   initiating authentication with the desired wireless network using the identity and the at least one credential provided in the profile;   deriving a shared secret using the at least one credential provided in the profile; and   communicating with the desired wireless network using the derived shared secret.   
     
     
         17 . The method of  claim 15 , wherein the at least one credential comprises a public-private keyset associated with the desired wireless network. 
     
     
         18 . The method of  claim 15 , wherein the profile received from the second functional entity via the protected IP-based connection is securely protected by the second functional entity. 
     
     
         19 . The method of  claim 15 , wherein the profile is configured to enable the wireless device to operationally access the desired wireless network. 
     
     
         20 . The method of  claim 15 , wherein the first functional entity comprises a Discovery and Registration Function (DRF). 
     
     
         21 . The method of  claim 15 , wherein the second functional entity comprises a Downloading and Provisioning Function (DPF). 
     
     
         22 . The method of  claim 15 , further comprising updating connectivity parameters used for communications during receiving the profile and during any subsequent update of the profile. 
     
     
         23 . The method of  claim 15 , wherein the secure communications with the first wireless network are for the limited purpose of receiving the profile. 
     
     
         24 . The method of  claim 15 , wherein the desired wireless network is one of the first wireless network or another wireless network. 
     
     
         25 . The method of  claim 15 , wherein the PCID indicates an intent of the wireless device to obtain operational access to the desired wireless network. 
     
     
         26 . A wireless device comprising a processor, a transmitter, and a receiver, wherein the wireless device is configured to perform operations comprising:
 initiating secure communications with a first wireless network, using a provisional connectivity identifier (PCID), to obtain operational access to a desired wireless network;   establishing, via the first wireless network, a protected IP-based connection with a first functional entity reachable via the first wireless network;   establishing, over the protected IP-based connection, a security association with a second functional entity reachable via the first wireless network;   receiving, from the second functional entity via the protected IP-based connection, a profile, wherein the profile comprises an identity and at least one credential for use in authenticating with and operationally accessing the desired wireless network; and   provisioning the received profile on the wireless device.   
     
     
         27 . The wireless device of  claim 26 , where the wireless device is configured to perform further operations comprising:
 activating the received profile;   initiating authentication with the desired wireless network using the identity and the at least one credential provided in the profile;   deriving a shared secret using the at least one credential provided in the profile; and   communicating with the desired wireless network using the derived shared secret.   
     
     
         28 . The wireless device of  claim 26 , wherein the at least one credential comprises a public-private keyset associated with the desired wireless network. 
     
     
         29 . The wireless device of  claim 26 , wherein the wireless device comprises a trusted environment (TRE), and wherein the trusted environment performs the initiating, establishing, receiving, and provisioning. 
     
     
         30 . The wireless device of  claim 29 , where the wireless device is configured to perform further operations comprising verifying an integrity of the TRE and an integrity of the received profile. 
     
     
         31 . The wireless device of  claim 26 , wherein the first functional entity comprises a Discovery and Registration Function (DRF). 
     
     
         32 . The wireless device of  claim 26 , wherein the second functional entity comprises a Downloading and Provisioning Function (DPF). 
     
     
         33 . The wireless device of  claim 26 , wherein the secure communications with the first wireless network are for the limited purpose of receiving the profile. 
     
     
         34 . The wireless device of  claim 26 , wherein the desired wireless network is one of the first wireless network or another wireless network.

Join the waitlist — get patent alerts

Track US2018242129A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.