Facilitating provisioning of an out-of-band pseudonym over a secure communication channel
Abstract
Facilitation of out-of-band pseudonym provisioning for a subscriber of a device is provided herein. In one embodiment, a method comprises: receiving, by a device comprising a processor, one way authentication data from a secure server; transmitting, by the device, to the secure server, via a secure communication channel, an identifier for a subscriber of the device, wherein the transmitting is performed based on the receiving the one way authentication data from the secure server; and receiving, by the device from the secure server, a pseudonym, wherein the pseudonym enables access by the device to an authentication device at a first time.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method, comprising:
receiving, by a device comprising a processor, one way authentication data from a secure server; transmitting, by the device, to the secure server, via a secure communication channel, an identifier for a subscriber of the device, wherein the transmitting is performed based on the receiving the one way authentication data from the secure server; and receiving, by the device from the secure server, a pseudonym for the subscriber of the device, wherein the pseudonym enables access by the device to an authentication device at a first time.
2 . The method of claim 1 , wherein the secure communication channel is a first secure communication channel, and wherein the pseudonym is generated by an authentication server communicatively coupled to the secure server via a second secure communication channel.
3 . The method of claim 2 , further comprising:
transmitting, by the device to the authentication device, the pseudonym to obtain the access to the authentication device, wherein the transmitting the pseudonym is via an in-band communication channel, and wherein the receiving the pseudonym is via an out-of-band communication channel; and authenticating, by the device, the subscriber, to the authentication device based on the pseudonym, wherein the authentication device is communicatively coupled to the authentication server.
4 . The method of claim 3 , wherein the pseudonym is a first pseudonym, and the method further comprising:
receiving, by the device from the authentication server, a second pseudonym after the authenticating, wherein the second pseudonym enables access to a second authentication device at a second time, and wherein the first time is prior to the second time.
5 . The method of claim 1 , wherein the secure communication channel is encrypted via a secure hypertext transfer protocol.
6 . The method of claim 1 , wherein the secure communication channel is encrypted via an Internet key exchange protocol.
7 . The method of claim 1 , wherein the secure server is a publicly accessible secure server.
8 . The method of claim 7 , wherein the publicly accessible secure server implements secure entitlement service.
9 . The method of claim 1 , wherein the identifier comprises an international mobile subscriber identifier.
10 . A machine-readable storage medium, comprising executable instructions that, when executed by a processor of a mobile device, facilitate performance of operations, comprising:
obtaining one way authentication data from a secure server; sending, to the secure server, via a secure communication channel, an identifier for a subscriber of the mobile device, wherein the sending is performed based on the obtaining the one way authentication data from the secure server; and obtaining, from the secure server, a pseudonym, wherein the pseudonym enables access by the mobile device to an authentication device at a first time.
11 . The machine-readable storage medium of claim 10 , wherein the secure communication channel is a first secure communication channel, and wherein the pseudonym is generated by an authentication server communicatively coupled to the secure server via a second secure communication channel.
12 . The machine-readable storage medium of claim 11 , wherein the operations further comprise:
sending, to the authentication device, the pseudonym to obtain the access to the authentication device, wherein the sending the pseudonym is via an in-band communication channel, and wherein the obtaining the pseudonym is via an out-of-band communication channel; and authenticating to the authentication device based on the pseudonym, wherein the authentication device is communicatively coupled to the authentication server.
13 . The machine-readable storage medium of claim 12 , wherein the pseudonym is a first pseudonym, and wherein the operations further comprise:
obtaining, from the authentication server, a second pseudonym after the authenticating, wherein the second pseudonym enables access to a second authentication device at a second time, and wherein the first time is prior to the second time.
14 . The machine-readable storage medium of claim 10 , wherein the secure communication channel is encrypted via a secure hypertext transfer protocol.
15 . The machine-readable storage medium of claim 10 , wherein the secure communication channel is encrypted via an Internet key exchange protocol.
16 . The machine-readable storage medium of claim 10 , wherein the secure server is a publicly accessible secure server.
17 . A first device, comprising:
a processor; and a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations, comprising:
receiving, from a second device, an identifier for a subscriber of the second device based on transmission to the second device of one way authentication data for the first device, wherein the receiving is performed via a secure communication channel; and
authenticating the subscriber of the second device employing the identifier, and receiving from a secure server a pseudonym for the second device, wherein the receiving from the secure server is performed via a second secure communication channel.
18 . The first device of claim 17 , wherein the operations further comprise:
transmitting, to the second device, the pseudonym, via the secure communication channel, and wherein the secure communication channel is encrypted with a secure hypertext transfer protocol or an Internet key exchange protocol.
19 . The first device of claim 18 , wherein the transmitting is performed as part of out-of-band communication for the second device and wherein the pseudonym is configured to be employed for in-band authentication by the second device with an authentication device.
20 . The first device of claim 17 , wherein the first device a publicly accessible secure server that implements secure entitlement service.Join the waitlist — get patent alerts
Track US2019014095A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.