US2019007406A1PendingUtilityA1

Characteristics Of Security Associations

Assignee: INTERDIGITAL PATENT HOLDINGS INCPriority: Jul 13, 2012Filed: Jul 25, 2018Published: Jan 3, 2019
Est. expiryJul 13, 2032(~6 yrs left)· nominal 20-yr term from priority
H04L 2463/081H04W 12/06H04L 63/205H04L 63/0876H04L 63/102H04L 63/105H04L 63/0807H04L 63/08H04W 12/068
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Authentication of a user or a wireless transmit/receive unit may be based on an obtained measure of authentication strength, which may referred to as an assurance level. For example, a user, via a WTRU, may request access to a service controlled by an access control entity (ACE). The user may be authenticated with a user authenticator and assertion function (UAAF), producing a result. A user assertion may be provided that includes the user authentication result, a user assurance level, and/or a user freshness level. The WTRU may be authenticated with a device authenticator and assertion function (DAAF), producing an associated result. A device assertion may be provided that may include the device authentication result, a device assurance level, and/or a device freshness level. The assertions may be bound together to receive access to a service or resource.

Claims

exact text as granted — not AI-modified
What is claimed: 
     
         1 . A method of authenticating a subscription for access to a service from a service provider, the method comprising:
 sending an access request to the service provider from a user device;   receiving, from the service provider, a redirect request for a subscription authentication or an authentication of the user device;   generating and sending an authentication response to an identity provider;   receiving a redirect authentication response from the identity provider; and   sending the redirect authentication response to the service provider to receive access to the service via the user device, wherein the redirect authentication response enables the service provider to obtain an indication of a freshness of the subscription authentication, the indication of the freshness based on a time that the authentication of the subscription or user device occurred.   
     
     
         2 . The method as recited in  claim 1 , wherein the redirect authentication response further enables the service provider to obtain an indication of a strength of the subscription authentication or the authentication of the user device. 
     
     
         3 . The method as recited in  claim 1 , the method further comprising:
 upon receiving the redirect request, sending the redirect request for the subscription authentication or the authentication of the user device to the identity provider; and   receiving an authentication request from the identity provider.   
     
     
         4 . The method as recited in  claim 3 , the method further comprising:
 generating and sending the authentication response in response to receiving the authentication request.   
     
     
         5 . The method as recited in  claim 1 , wherein the user device comprises a universal integrated circuit card (UICC), and generating the authentication response further comprises:
 performing, by the UICC, an authentication of a user associated with the user device;   based on performing the authentication of the user, generating an assertion comprising a result of the authentication of the user; and   sending the assertion in the authentication response.   
     
     
         6 . The method as recited in  claim 1 , wherein the authentication response enables the subscription authentication. 
     
     
         7 . The method as recited in  claim 1 , wherein generating the authentication response comprises:
 the user device performing an authentication locally of a user of the user device;   generating an assertion comprising a result of the authentication of the user; and   sending the assertion in the authentication response to the identity provider.   
     
     
         8 . The method as recited in  claim 1 , the method further comprising:
 receiving an authentication assurance level required to access the service;   performing the subscription authentication of the authentication of the user device based on the received assurance level;   generating an assertion that includes a result of the subscription authentication or the authentication of the user device; and   sending the assertion in the authentication response.   
     
     
         9 . The method as recited in  claim 1 , the method further comprising:
 accessing the service on the user device; and   generating and sending the authentication response by a second device that is different than the user device, wherein   the user device and the second device both receive an identifier that binds the authentication response from the second device to the service access on the user device.   
     
     
         10 . A wireless transmit/receive unit (WTRU), the WTRU comprising:
 a memory comprising executable instructions; and   
       a processor in communications with the memory, the instructions, when executed by the processor, cause the processor to effectuate operations comprising:
 sending an access request to the service provider from a user device; 
 receiving, from the service provider, a redirect request for a subscription authentication or an authentication of the user device; 
 generating and sending an authentication response to an identity provider; 
 receiving a redirect authentication response from the identity provider; and 
 sending the redirect authentication response to the service provider to receive access to the service via the user device, wherein the redirect authentication response enables the service provider to obtain an indication of a freshness of the subscription authentication, the indication of the freshness based on a time that the authentication of the subscription or user device occurred. 
 
     
     
         11 . The WTRU as recited in  claim 10 , wherein the redirect authentication response further enables the service provider to obtain an indication of a strength of the subscription authentication. 
     
     
         12 . The WTRU as recited in  claim 10 , wherein the processor is further configured to execute the instructions to perform further operations comprising:
 upon receiving the redirect request, sending the redirect request for the subscription authentication to the identity provider; and   receiving an authentication request from the identity provider.   
     
     
         13 . The WTRU as recited in  claim 12 , wherein the processor is further configured to execute the instructions to perform further operations comprising:
 generating and sending the authentication response in response to receiving the authentication request.   
     
     
         14 . The method as recited in  claim 1 , wherein the WTRU further comprises a universal integrated circuit card (UICC), and generating the authentication response further comprises:
 performing, by the UICC, an authentication of a user associated with the WTRU;   based on performing the authentication of the user, generating an assertion comprising a result of the authentication of the user; and   sending the assertion in the authentication response.   
     
     
         15 . The WTRU as recited in  claim 11 , wherein the authentication response enables the subscription authentication. 
     
     
         16 . The WTRU as recited in  claim 16 , wherein generating the authentication response comprises:
 the WTRU performing an authentication locally of a user of the WTRU;   generating an assertion comprising a result of the authentication of the user; and   sending the assertion in the authentication response to the identity provider.

Join the waitlist — get patent alerts

Track US2019007406A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.