US2019014095A1PendingUtilityA1

Facilitating provisioning of an out-of-band pseudonym over a secure communication channel

Assignee: AT & T IP I LPPriority: Jul 6, 2017Filed: Jul 6, 2017Published: Jan 10, 2019
Est. expiryJul 6, 2037(~10.9 yrs left)· nominal 20-yr term from priority
H04L 63/0442H04L 63/0281H04L 63/0478H04L 63/0853H04L 63/166H04L 63/18H04L 9/0662H04L 9/3263H04L 63/061H04W 12/72G06F 21/42H04L 63/08H04L 9/3228
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Facilitation of out-of-band pseudonym provisioning for a subscriber of a device is provided herein. In one embodiment, a method comprises: receiving, by a device comprising a processor, one way authentication data from a secure server; transmitting, by the device, to the secure server, via a secure communication channel, an identifier for a subscriber of the device, wherein the transmitting is performed based on the receiving the one way authentication data from the secure server; and receiving, by the device from the secure server, a pseudonym, wherein the pseudonym enables access by the device to an authentication device at a first time.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 receiving, by a device comprising a processor, one way authentication data from a secure server;   transmitting, by the device, to the secure server, via a secure communication channel, an identifier for a subscriber of the device, wherein the transmitting is performed based on the receiving the one way authentication data from the secure server; and   receiving, by the device from the secure server, a pseudonym for the subscriber of the device, wherein the pseudonym enables access by the device to an authentication device at a first time.   
     
     
         2 . The method of  claim 1 , wherein the secure communication channel is a first secure communication channel, and wherein the pseudonym is generated by an authentication server communicatively coupled to the secure server via a second secure communication channel. 
     
     
         3 . The method of  claim 2 , further comprising:
 transmitting, by the device to the authentication device, the pseudonym to obtain the access to the authentication device, wherein the transmitting the pseudonym is via an in-band communication channel, and wherein the receiving the pseudonym is via an out-of-band communication channel; and   authenticating, by the device, the subscriber, to the authentication device based on the pseudonym, wherein the authentication device is communicatively coupled to the authentication server.   
     
     
         4 . The method of  claim 3 , wherein the pseudonym is a first pseudonym, and the method further comprising:
 receiving, by the device from the authentication server, a second pseudonym after the authenticating, wherein the second pseudonym enables access to a second authentication device at a second time, and wherein the first time is prior to the second time.   
     
     
         5 . The method of  claim 1 , wherein the secure communication channel is encrypted via a secure hypertext transfer protocol. 
     
     
         6 . The method of  claim 1 , wherein the secure communication channel is encrypted via an Internet key exchange protocol. 
     
     
         7 . The method of  claim 1 , wherein the secure server is a publicly accessible secure server. 
     
     
         8 . The method of  claim 7 , wherein the publicly accessible secure server implements secure entitlement service. 
     
     
         9 . The method of  claim 1 , wherein the identifier comprises an international mobile subscriber identifier. 
     
     
         10 . A machine-readable storage medium, comprising executable instructions that, when executed by a processor of a mobile device, facilitate performance of operations, comprising:
 obtaining one way authentication data from a secure server;   sending, to the secure server, via a secure communication channel, an identifier for a subscriber of the mobile device, wherein the sending is performed based on the obtaining the one way authentication data from the secure server; and   obtaining, from the secure server, a pseudonym, wherein the pseudonym enables access by the mobile device to an authentication device at a first time.   
     
     
         11 . The machine-readable storage medium of  claim 10 , wherein the secure communication channel is a first secure communication channel, and wherein the pseudonym is generated by an authentication server communicatively coupled to the secure server via a second secure communication channel. 
     
     
         12 . The machine-readable storage medium of  claim 11 , wherein the operations further comprise:
 sending, to the authentication device, the pseudonym to obtain the access to the authentication device, wherein the sending the pseudonym is via an in-band communication channel, and wherein the obtaining the pseudonym is via an out-of-band communication channel; and   authenticating to the authentication device based on the pseudonym, wherein the authentication device is communicatively coupled to the authentication server.   
     
     
         13 . The machine-readable storage medium of  claim 12 , wherein the pseudonym is a first pseudonym, and wherein the operations further comprise:
 obtaining, from the authentication server, a second pseudonym after the authenticating, wherein the second pseudonym enables access to a second authentication device at a second time, and wherein the first time is prior to the second time.   
     
     
         14 . The machine-readable storage medium of  claim 10 , wherein the secure communication channel is encrypted via a secure hypertext transfer protocol. 
     
     
         15 . The machine-readable storage medium of  claim 10 , wherein the secure communication channel is encrypted via an Internet key exchange protocol. 
     
     
         16 . The machine-readable storage medium of  claim 10 , wherein the secure server is a publicly accessible secure server. 
     
     
         17 . A first device, comprising:
 a processor; and   a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations, comprising:
 receiving, from a second device, an identifier for a subscriber of the second device based on transmission to the second device of one way authentication data for the first device, wherein the receiving is performed via a secure communication channel; and 
 authenticating the subscriber of the second device employing the identifier, and receiving from a secure server a pseudonym for the second device, wherein the receiving from the secure server is performed via a second secure communication channel. 
   
     
     
         18 . The first device of  claim 17 , wherein the operations further comprise:
 transmitting, to the second device, the pseudonym, via the secure communication channel, and wherein the secure communication channel is encrypted with a secure hypertext transfer protocol or an Internet key exchange protocol.   
     
     
         19 . The first device of  claim 18 , wherein the transmitting is performed as part of out-of-band communication for the second device and wherein the pseudonym is configured to be employed for in-band authentication by the second device with an authentication device. 
     
     
         20 . The first device of  claim 17 , wherein the first device a publicly accessible secure server that implements secure entitlement service.

Join the waitlist — get patent alerts

Track US2019014095A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.