Method and apparatus for managing subscription credentials in a wireless communication device
Abstract
This record has no abstract on file.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
14 claims: 9 independent, 5 dependent
- 1Patent claims Zastrzeżenia patentowe 1. The method of managing subscriber credentials in a wireless communication device (10), wherein the communication device is adapted to store preconfigured credentials for temporary access (30) to obtain temporary network access and to acquire new long-term subscriber credentials (26), and wherein said temporary access credentials (30) comprise a pre-assigned IMSI (preliminary International mobile subscriber identity) permanently stored in this wireless communication device (10), which method is adapted to:1. Sposób zarządzania abonenckimi danymi uwierzytelniającymi w bezprzewodowym urządzeniu komunikacyjnym (10), przy czym to urządzenie komunikacyjne jest przystosowane do przechowywania prekonfigurowanych danych uwierzytelniających do tymczasowego dostępu (30) do uzyskiwania tymczasowego dostępu do sieci oraz do pozyskiwania nowych długoterminowych abonenckich danych uwierzytelniających (26), oraz przy czym te dane uwierzytelniające do tymczasowego dostępu (30) zawierają wstępnie nadany identyfikator IMSI (ang. preliminary International mobile subscriber identity) trwale zapisany w tym bezprzewodowym urządzeniu komunikacyjnym (10), który to sposób jest przystosowany do: - obtaining long-term subscriber's credentials (26);- pozyskiwania długoterminowych abonenckich danych uwierzytelniających (26);powracania (102, 120) od długoterminowych abonenckich danych uwierzytelniających (26) do prekonfigurowanych danych uwierzytelniających do tymczasowego dostępu (30) przechowywanych w bezprzewodowym urządzeniu komunikacyjnym (10), przez podstawienie tych danych uwierzytelniających do tymczasowego dostępu (30) pre-konfigurowanych w bezprzewodowym urządzeniu komunikacyjnym (10) w returning (102, 120) from long-term subscriber credentials (26) to pre-configured temporary credentials (30) stored in the wireless communication device (10), by substituting these credentials for temporary access (30) pre-configured in the wireless device communication (10) in - 16miejsce tych długoterminowych abonenckich danych uwierzytelniających (26), przy jednoczesnym zachowaniu tych danych uwierzytelniających do tymczasowego dostępu (30) w tym bezprzewodowym urządzeniu komunikacyjnym (10) do przyszłego ich przywrócenia;- the location of these long-term subscriber credentials (26), while maintaining these credentials for temporary access (30) on this wireless communication device (10) for future restoration;determining (104) whether new long-term subscriber's credentials (26) are needed during temporary network access using temporary credentials (30);and to, if new long-term subscriber credentials (26) are needed (106), obtaining (108) new long-term subscriber credentials (26) for this wireless communication device (10) via temporary network access;stwierdzania (104), czy potrzebne są nowe długoterminowe abonenckie dane uwierzytelniające (26) podczas tymczasowego dostępu do sieci z użyciem danych uwierzytelniających do tymczasowego dostępu (30);oraz do, jeżeli nowe długoterminowe abonenckie dane uwierzytelniające (26) są potrzebne (106), pozyskiwania (108) nowych długoterminowych abonenckich danych uwierzytelniających (26) dla tego bezprzewodowego urządzenia komunikacyjnego (10) za pośrednictwem tymczasowego dostępu do sieci;characterized in that these long-term subscriber credentials (26) are associated with a preferred access network;wherein the method comprises steps znamienny tym, że te długoterminowe abonenckie dane uwierzytelniające (26) są powiązane z preferowaną siecią dostępową;przy czym sposób ten obejmuje etapy - detecting (100) failure when accessing the network using current long-term subscriber credentials (26) stored in this wireless communication device (10) by performing one or more initial access attempts (112) through the preferred access network using those current long-term subscriber's credentials (26), and - wykrywania (100) niepowodzenia przy uzyskiwaniu dostępu do sieci z użyciem aktualnych długoterminowych abonenckich danych uwierzytelniających (26) przechowywanych w tym bezprzewodowym urządzeniu komunikacyjnym (10) przez wykonywanie jednej lub większej liczby początkowych prób dostępu (112) przez preferowaną sieć dostępową z użyciem tych aktualnych długoterminowych abonenckich danych uwierzytelniających (26), oraz, - if these initial one or more access attempts (112) are unsuccessful, performing one or more subsequent access attempts (116) through one or more non-preferred access networks (116, 118) available for this wireless communication device (10) , also using these current long-term subscriber's credentials (26);- jeżeli te początkowe jedna lub większa liczba prób dostępu (112) są nieskuteczne, wykonywania jednej iub większej liczby kolejnych prób dostępu (116) przez jedną lub większą liczbę nie preferowanych sieci dostępowych (116, 118) dostępnych dia tego bezprzewodowego urządzenia komunikacyjnego (10), także z użyciem tych aktualnych długoterminowych abonenckich danych uwierzytelniających (26);- if still unsuccessful (116, 118, 104), -jeżeli nadal nieskutecznie (116,118,104), - powracania (102, 120) od aktualnych długoterminowych abonenckich danych uwierzytelniających (26) do danych uwierzytelniających do tymczasowego dostępu (30) przechowywanych w tym bezprzewodowym urządzeniu komunikacyjnym (10), w reakcji na wykrycie wspomnianego niepowodzenia;- returning (102, 120) from the current long-term subscriber credentials (26) to the temporary access credentials (30) stored in this wireless communication device (10) in response to detecting said failure;- poszukiwania dostępu (122), a po dostępie do pewnej sieci dostępowej;- seeking access (122), and after access to a certain access network;- obtaining (126) new long-term subscriber's credentials (26). - pozyskiwania (126) nowych długoterminowych abonenckich danych uwierzytelniających (26).
- 3The method according to claim Claim, wherein determining (104) whether new long-term subscriber credentials (26) are needed based on obtaining temporary network access using temporary access credentials (30) involves connecting to a registration service (54) via temporary network access (46) and communication with this registration service (54) to determine whether new long-term subscriber's credentials are needed (26). 3. Sposób według zastrz. 1, przy czym stwierdzanie (104), czy potrzebne są nowe długoterminowe abonenckie dane uwierzytelniające (26) w oparciu o uzyskiwanie tymczasowego dostępu do sieci z użyciem danych uwierzytelniających do tymczasowego dostępu (30) obejmuje łączenie się z usługą rejestracji (54) za pośrednictwem tymczasowego dostępu do sieci (46) oraz komunikowanie się z tą usługą rejestracji (54) dla stwierdzenia, czy potrzebne są nowe długoterminowe abonenckie dane uwierzytelniające (26). - 174. Sposób według zastrz. 3, przy czym komunikowanie się z usługą rejestracji (54) dia stwierdzenia (104), czy potrzebne są nowe długoterminowe abonenckie dane uwierzytelniające (26), obejmuje wysyłanie do tej usługi rejestracji (54) do oceny pierwszej informacji, która jest powiązana z aktualnymi długoterminowymi abonenckimi danymi uwierzytelniającymi (26) przechowywanymi przez bezprzewodowe urządzenie komunikacyjne (10), a także odbiór zwrotnego wskazania od tej usługi rejestracji (54). - 174. The method of claim 3, wherein communication with the registration service (54) for determining (104) whether new long-term subscriber's credentials are needed (26) involves sending to this registration service (54) for the assessment of the first information that is associated with current long-term the subscriber credentials (26) stored by the wireless communication device (10), as well as the receipt of a feedback indication from this registration service (54).
- 45. The method according to claim 3, wherein communicating with the registration service (54) to determine (104) whether new long-term subscriber's credentials are needed (26) includes determining whether the first information that is stored by the wireless communication device for current long-term subscriber's credentials (26) stored by this wireless communication device (10) matches the second information received from this registration service. 5. Sposób według zastrz. 3, przy czym komunikowanie się z usługą rejestracji (54) dia stwierdzenia (104), czy potrzebne są nowe długoterminowe abonenckie dane uwierzytelniające (26), obejmuje stwierdzenie, czy pierwsza informacja, która jest przechowywana przez bezprzewodowe urządzenie komunikacyjne dla aktualnych długoterminowych abonenckich danych uwierzytelniających (26) przechowywanych przez to bezprzewodowe urządzenie komunikacyjne (10), pasuje do drugiej informacji, otrzymanej od tej usługi rejestracji.
- 56. The method according to claim 3, wherein obtaining (108) new long-term subscriber credentials (26) for the wireless communication device (10) includes receiving from the registration service (54) information about the network address that identifies the credential data server from which the new long-term subscriber is to be obtained credentials (26), and also the use of temporary network access to connect to this credential server to obtain new long-term subscriber credentials (26), 6. Sposób według zastrz. 3, przy czym pozyskiwanie (108) nowych długoterminowych abonenckich danych uwierzytelniających (26) dla bezprzewodowego urządzenia komunikacyjnego (10) obejmuje odbiór od usługi rejestracji (54) informacji o adresie sieciowym, która identyfikuje serwer danych uwierzytelniających, z którego mają zostać pozyskane nowe długoterminowe abonenckie dane uwierzytelniające (26), a także użycie tymczasowego dostępu do sieci do połączenia się z tym serwerem danych uwierzytelniających dla pozyskania nowych długoterminowych abonenckich danych uwierzytelniających (26),
- 89. A wireless communication device (10), containing one or more processing circuits (20), adapted to:9. Bezprzewodowe urządzenie komunikacyjne (10), zawierające jeden lub większą liczbę obwodów przetwarzających (20), przystosowane do: przechowywania pre-konfigurowanych danych uwierzytelniających do tymczasowego dostępu (30) do uzyskiwania tymczasowego dostępu do sieci oraz do pozyskiwania nowych długoterminowych abonenckich danych uwierzytelniających (26), oraz przy czym te dane uwierzytelniające do tymczasowego dostępu (30) zawierają wstępnie nadany identyfikator IMSI (ang. preliminary international mobile subscriber identity) trwaie zapisany w tym bezprzewodowym urządzeniu komunikacyjnym (10), które to bezprzewodowe urządzenie storing pre-configured temporary access credentials (30) for obtaining temporary network access and for acquiring new long-term subscriber credentials (26), and wherein these temporary access credentials (30) include a pre-assigned IMSI ( preliminary international mobile subscriber identity) is permanently stored in this wireless communication device (10), which is a wireless device - 18communication is adapted to: - 18komunikacyjne jest przystosowane do: obtaining long-term subscriber's credentials (26);pozyskiwania długoterminowych abonenckich danych uwierzytelniających (26);powracania (102, 120) od długoterminowych abonenckich danych uwierzytelniających (26) do prekonfigurowanych danych uwierzytelniających do tymczasowego dostępu (30) przechowywanych w tym bezprzewodowym urządzeniu komunikacyjnym (10), przez podstawienie tych danych uwierzytelniających do tymczasowego dostępu (30) pre-konfigurowanych w tym bezprzewodowym urządzeniu komunikacyjnym (10) w miejsce tych długoterminowych abonenckich danych uwierzytelniających (26), przy jednoczesnym zachowaniu tych danych uwierzytelniających do tymczasowego dostępu (30) w tym bezprzewodowym urządzeniu komunikacyjnym (10) do przyszłego ich przywrócenia;returning (102, 120) from long-term subscriber credentials (26) to pre-configured temporary credentials (30) stored in this wireless communication device (10), by substituting these credentials for temporary access (30) pre-configured including wireless communication device (10) in place of these long-term subscriber's credentials (26), while maintaining this credentials for temporary access (30) on this wireless communication device (10) for future restoration;determining (104) whether new long-term subscriber's credentials (26) are needed during temporary network access using temporary credentials (30);and to, if new long-term subscriber credentials (26) are needed (106), obtaining (108) new long-term subscriber credentials (26) for this wireless communication device (10) via temporary network access;stwierdzania (104), czy potrzebne są nowe długoterminowe abonenckie dane uwierzytelniające (26) podczas tymczasowego dostępu do sieci z użyciem danych uwierzytelniających do tymczasowego dostępu (30);oraz do, jeżeli nowe długoterminowe abonenckie dane uwierzytelniające (26) są potrzebne (106), pozyskiwania (108) nowych długoterminowych abonenckich danych uwierzytelniających (26) dla tego bezprzewodowego urządzenia komunikacyjnego (10) za pośrednictwem tymczasowego dostępu do sieci;characterized in that these long-term subscriber credentials (26) are associated with a preferred access network;wherein the wireless communication device (10) is adapted to znamienne tym, że te długoterminowe abonenckie dane uwierzytelniające (26) są powiązane z preferowaną siecią dostępową;przy czym to bezprzewodowe urządzenie komunikacyjne (10) jest przystosowane do - detecting (100) failure in accessing the network using current long-term subscriber credentials (26) stored in this wireless communication device (10) by performing one or more initial access attempts (112) through the preferred access network using those current long-term subscriber's credentials (26) and, if these initial one or more access attempts (112) are unsuccessful, performing one or more subsequent access attempts (116) over one or more non-preferred access networks (116, 118) available for this wireless communication device (10), also using these current long-term subscriber credentials (26), if still unsuccessful (116, 118, 104), returns (102, 120) from current long-term subscriber credentials (26) to temporary credentials (30) stored in this wireless communication device (10) in response to detecting said failure;- wykrywania (100) niepowodzenia przy uzyskiwaniu dostępu do sieci z użyciem aktualnych długoterminowych abonenckich danych uwierzytelniających (26) przechowywanych w tym bezprzewodowym urządzeniu komunikacyjnym (10) przez wykonywanie jednej iub większej liczby początkowych prób dostępu (112) przez preferowaną sieć dostępową z użyciem tych aktualnych długoterminowych abonenckich danych uwierzytelniających (26) oraz, jeżeli te początkowe jedna lub większa liczba prób dostępu (112) są nieskuteczne, wykonywania jednej lub większej liczby kolejnych prób dostępu (116) przez jedną lub większą liczbę niepreferowanych sieci dostępowych (116, 118) dostępnych dla tego bezprzewodowego urządzenia komunikacyjnego (10), także z użyciem tych aktualnych długoterminowych abonenckich danych uwierzytelniających (26), jeżeli nadal nieskutecznie (116, 118, 104), powracania (102, 120) od aktualnych długoterminowych abonenckich danych uwierzytelniających (26) do danych uwierzytelniających do tymczasowego dostępu (30) przechowywanych w tym bezprzewodowym urządzeniu komunikacyjnym (10), w reakcji na wykrycie wspomnianego niepowodzenia;poszukiwania dostępu (122), a po dostępie do pewnej sieci dostępowej;seeking access (122), and after accessing a certain access network;obtaining (126) new long-term subscriber's credentials (26). pozyskiwania (126) nowych długoterminowych abonenckich danych uwierzytelniających (26).
- 910. A wireless communication device (10) according to claim 9, wherein the wireless communication device (10) is adapted to detect failure when accessing the network using current long-term subscriber credentials (26) stored in this wireless communication device (10) based on receiving a failure message in response to attempting to access the network using these current long-term subscriber credentials (26). 10. Bezprzewodowe urządzenie komunikacyjne (10) według zastrz. 9, przy czym to bezprzewodowe urządzenie komunikacyjne (10) jest przystosowane do wykrywania niepowodzenia przy uzyskiwaniu dostępu do sieci z użyciem aktualnych długoterminowych abonenckich danych uwierzytelniających (26) przechowywanych w tym bezprzewodowym urządzeniu komunikacyjnym (10) w oparciu o odbiór komunikatu o niepowodzeniu w reakcji na próbowanie uzyskania dostępu do sieci z użyciem tych aktualnych długoterminowych abonenckich danych uwierzytelniających (26). - 1911. A wireless communication device (10) according to claim 9, wherein the wireless communication device (10) is adapted to determine whether new long-term subscriber credentials (26) are needed based on obtaining temporary network access using temporary access credentials (30) by connecting to the service registration (54) via temporary network access (42) and communication with this registration service (54) to determine, whether new long-term subscriber's credentials are needed (26). - 1911. Bezprzewodowe urządzenie komunikacyjne (10) według zastrz. 9, przy czym to bezprzewodowe urządzenie komunikacyjne (10) jest przystosowane do stwierdzania, czy potrzebne są nowe długoterminowe abonenckie dane uwierzytelniające (26) w oparciu o uzyskiwanie tymczasowego dostępu do sieci z użyciem danych uwierzytelniających do tymczasowego dostępu (30) przez łączenie się z usługą rejestracji (54) za pośrednictwem tymczasowego dostępu do sieci (42) oraz komunikowanie się z tą usługą rejestracji (54) dia stwierdzenia, czy potrzebne są nowe długoterminowe abonenckie dane uwierzytelniające (26).
- 1012. A wireless communication device (10) according to claim 11, wherein the wireless communication device (10) is adapted to communicate with the registration service (54) to determine whether new long-term subscriber credentials (26) are needed by sending to this registration service (54) the first information that is associated with current long-term subscriber credentials (26) stored by this wireless communication device (10), and receiving a return indication from this registration service (54). 12. Bezprzewodowe urządzenie komunikacyjne (10) według zastrz. 11, przy czym to bezprzewodowe urządzenie komunikacyjne (10) jest przystosowane do komunikowania się z usługą rejestracji (54) dia stwierdzenia, czy potrzebne są nowe długoterminowe abonenckie dane uwierzytelniające (26), przez wysyłanie do tej usługi rejestracji (54) pierwszej informacji, która jest powiązana z aktualnymi długoterminowymi abonenckimi danymi uwierzytelniającymi (26) przechowywanymi przez to bezprzewodowe urządzenie komunikacyjne (10), a także odbiór zwrotnego wskazania od tej usługi rejestracji (54).
- 1113. A wireless communication device (10) according to claim 11, wherein the wireless communication device (10) is adapted to communicate with a registration service (54) to determine whether new long-term subscriber credentials (26) are needed, by determining whether the first information that is stored by this wireless communication device (10) for current long-term subscriber's credentials (26) stored by this wireless communication device (10), matches the second information received from this registration service (54). 13. Bezprzewodowe urządzenie komunikacyjne (10) według zastrz. 11, przy czym to bezprzewodowe urządzenie komunikacyjne (10) jest przystosowane do komunikowania się z usługą rejestracji (54) dla stwierdzenia, czy potrzebne są nowe długoterminowe abonenckie dane uwierzytelniające (26), przez stwierdzenie, czy pierwsza informacja, która jest przechowywana przez to bezprzewodowe urządzenie komunikacyjne (10) dla aktualnych długoterminowych abonenckich danych uwierzytelniających (26) przechowywanych przez to bezprzewodowe urządzenie komunikacyjne (10), pasuje do drugiej informacji, otrzymanej od tej usługi rejestracji (54).
- 1214. A wireless communication device (10) according to claim 11, wherein the wireless communication device (10) is adapted to acquire new long-term subscriber credentials (26) for this wireless communication device (10), which includes receiving from the registration service (54) network address information that identifies the data server credentials from which new long-term subscriber's credentials are to be obtained (26), and also using temporary network access to connect to this credential server (54) to obtain new long-term subscriber credentials (26). 14. Bezprzewodowe urządzenie komunikacyjne (10) według zastrz. 11, przy czym to bezprzewodowe urządzenie komunikacyjne (10) jest przystosowane do pozyskiwania nowych długoterminowych abonenckich danych uwierzytelniających (26) dla tego bezprzewodowego urządzenia komunikacyjnego (10), które obejmuje odbiór od usługi rejestracji (54) informacji o adresie sieciowym, która identyfikuje serwer danych uwierzytelniających, z którego mają zostać pozyskane nowe długoterminowe abonenckie dane uwierzytelniające (26), a także użycie tymczasowego dostępu do sieci do połączenia się z tym serwerem danych uwierzytelniających (54) dia pozyskania nowych długoterminowych abonenckich danych uwierzytelniających (26).
Independent claims9
79 paragraphs, as filed
TECHNICAL FIELD [0001] The present invention relates generally to wireless communication devices, e.g., mobile communication handsets and M2M (machine-to-machine) devices, and in particular to the management of subscriber's credentials in such devices.
BACKGROUND ART [0002] Secure and convenient management of subscriber's credentials is still a problem in the field of wireless communication. In some markets and for certain types of devices, device configuration is done at the point of sale, and the buyer of the device receives a fully configured device that is ready for activation and use on the network. In this sense, the configuration includes securely storing subscriber credentials on the device that bind the device to a given network service provider (home operator) and allow it to authenticate on the home operator's network, as well as on any number of networks visited, in accordance with roaming agreements e.t.c.
[0003] For conventional 3G cell phones, configuration is typically done using the Universal Subscriber Identity Module (USIM), an application installed on the UICC (Universal Integrated Circuit Card) provided by the wireless network operator. The USIM module / UICC card can be inserted into a mobile phone to link this phone to a specific subscription, thus enabling the user of this phone to access the services covered by the subscription, through his home provider's network and, in many cases, via cooperating partner networks. While this is convenient enough for individual customers, a configuration approach may be impractical in M2M applications where one entity can deploy hundreds of wireless devices in a large geographical area.
[0004] For example, in some cases, a wireless device may be pre-installed in a larger part of the device (e.g. car), which may make it impractical or impossible to insert the SIM card later. In other cases, M2M devices can be deployed over a wide geographical area, which means that no single wireless operator can provide the required coverage. In such cases, matching USIM-specific operators to the right devices can be problematic. Finally, it can be costly to reconfigure the M2M device, e.g. to transfer the device to a subscription with another operator, especially when the M2M device is in a remote location.
[0005] Other solutions for initial device configuration are known. Instead of delivering a fully configured device to the buyer, pre-configured devices are provided for sale and / or distribution in one configuration solution. The pre-configured device contains data
Limited access authorization, which are recognizable by one or more network operators and which enable the device to obtain temporary access to the network. Such credentials for temporary access can be entered e.g. by the device manufacturer.
[0006] Typically, the buyer of the device selects the parent operator for the device in a separate transaction and activates the subscription for it. This device obtains temporary access to the network using its credentials for temporary access to obtain long-term subscriber credentials from the selected home provider or from an associated service providing credentials. This solution allows devices to be sold before they are associated with specific network operators or with specific subscriptions and uses the following configuration of devices over the air (OTA) based on their adaptation to obtain temporary access to networks due to their limited credentials.
[0007] The use of temporary credentials offers potentially significant benefits to device purchasers, especially for certain types of devices. For example, an enterprise can buy many thousands of M2M devices, each containing credentials for temporary access. These devices can be stored in the warehouse without charging subscription fees and used as needed. In addition, the device owner can choose and activate a subscription for these devices massively or individually with one or more operators, in separate transactions independent of the possibility of connecting the device. After being sent to the field or otherwise disposed of, each such M2M device uses its subscriber's data for temporary access to obtain the initial connection to the network, which then allows it to contact the home operator or the general registration service having information about the identity of its home operator. With this access, the device retrieves long-term subscriber credentials for any subsequent network access. On the other hand, when devices are associated with subscriptions and operate with long-term subscriber credentials, device owners have potentially significant difficulties when changing subscription plans, and in particular when changing the affiliation to the parent operator. Eg. due to cost, size or both, M2M devices are generally free of user interfaces, and often have software / firmware with limited functionality adapted to their intended installations. Such minimalistic implementations may hinder interaction with M2M devices, and in particular may hinder the management of subscriber's credentials in such devices. Eg. easy exchange of subscriber credentials in used M2M devices can be difficult for an enterprise.
[0008] Document US 2006/0079219 A1 discloses a method and computer program for performing diagnostics of failed wireless communication. When the failed transmission status is established, a communication channel with a freely available number is established between the tefematics module and the service provider or service office responsible for the failed transmission state found. The identifier of the communication device is transferred to the service provider, and the communication parameter associated with this data, generated by the service provider, is provided for the telematics module.
[0009] 3GPP TR 33.812, v. 0.1.0 from January 2008, "Feasibility Study on Remote Management of
-3USIM Application on M2M Euipment ", is a technical report discussing issues related to providing remote management of the USIM / 1SIM application in a secure manner on a M2M device in a 3GPP system. This document suggests that the manufacturer's preliminary international subscriber identifier should be installed in the M2M device mobile, to allow this M2M device to register in a 3GPP network without yet being associated with any selected home provider.
[0010] Document US 2005/0037753 A1 discloses a method for a communication device to look for a service from an alternative public land mobile network (PLMN) when a certain PLMN network rejects the registration message from this communication device. The method includes roaming through this communication device to the visited PLMN network and sending a registration message to this PLMN network, and when this registration message is rejected, searching for a service from the alternative PLMN network. [0011] Document EP0778716A2 discloses a method for a mobile communication terminal device with an initial identifier of a mobile PMSID ( preliminary mobile station Identification) adapted to provide at least initial pre-restricted access to the selected operator's cellular network, but not sufficient to ensure continued use. The mobile teiefon manufacturer can assign a PMSID to the mobile station in any way. This assignment may result in redundant PMSIDs. When selling the device to the customer, the seller notifies the selected cellular service provider about the buyer's identity, serial number (ESN) and the PMSID of the module being sold. The client makes the first connection using this network. It is then determined whether there is a coincidence between the combination of ESN number and PMSID and the corresponding combination previously registered (decision block 58). If so, the process proceeds to determine if this PMSID and / or any other preliminary identification information is compatible with the network of the selected operator. If this PMSID is compatible with that operator's network, it can be saved; otherwise, the network operator sends a command to overwrite the PMSłD data with a new, appropriate and assignable MSID (mobile station Identification) mobile station identifier. The PMSID or new MSID provides network access at a level that is less limited than initial access. [0012] No user data transfer solutions for the given mobile station identifier / subscriber credentials were discussed when less restricted access was provided. Document "Changes to TR33.812, v.0.1.0, network architecture alternatives section, 3GPP DRAFT; S3-080014, 25-29 February 2008, BT et al. refers to the initial network configuration using the Universal Subscriber Identity Module (USIM) for the M2M (Machine-to-Machine) device. Two possible solutions are described in sections 5.2.2 and 5.2.3, respectively.
[0013] Chapter 5.2.3.4 describes an example of Preliminary IMS! constituting a temporary private identifier provided by CATNA (Credentiai Authority for Temporary Network Access), which uniquely identifies each device registered in CATNA with M2M functionality. When required, this initial IMSl must be installed on the M2M device by the provider to allow this M2M device to register on the 3GPP network when it is not yet associated with any particular Home Operator.
[0014] Chapter 5.2.3.4 of document S3-080014 explains that the owner of the device with M2M functionality
-4 notifies the registration service that there will be a change of subscription (change of long-term subscriber credentials) from the previous parent operator to the new parent operator [point 1) -5.2.3.5]. Before the new credentials are configured and before the first connection with the pre-configured credentials for temporary access (initial IMSI), the registration service prepares the M2M device [point 7) - 5.2.3.5].
[0015] There is no other provision to change the subscriber's credentials other than initiated at the owner's initiative in this document. Document S3-080014 forms the pre-characterizing part of the independent claims.
SUMMARY OF THE INVENTION [0016] As explained herein, a method of managing subscriber credentials in a wireless communication device, wherein the communication device is adapted to store preconfigured subscriber credentials for temporary access to obtain temporary access to the network and to receive further long-term subscriber access credentials and wherein said temporary access credentials contain a preliminary international mobile subscriber identifier, permanently stored in this wireless communication device, this method is adapted to:
returning from long-term subscriber credentials to these pre-configured temporary access credentials stored in this wireless communication device, replacing with these temporary access credentials pre-configured in this wireless communication device long-term subscriber credentials, while maintaining this credentials for temporary access on this wireless communication device for future return to them;
determining whether new long-term subscriber's credentials are needed during temporary network access using temporary credentials; and, if new subscriber credentials are needed, acquiring new subscriber credentials for this wireless communication device via temporary network access;
wherein these long-term subscriber credentials are associated with a preferred access network; which method comprises stages
- obtaining long-term subscriber's credentials;
- detecting failure in accessing the network using current long-term subscriber credentials stored in the wireless communication device, by making one or more initial access attempts via the preferred access network using current long-term subscriber credentials; and,
- if this initial one or more access attempts fail, one or more attempts
- the number of consecutive access attempts through one or more of the non-preferred access networks available to this wireless communication device, also using current long-term subscriber's credentials;
- if they are still not successful,
- returning from current long-term subscriber credentials for credentials for temporary access stored in this wireless communication device in response to detecting said failure;
- searching for access, and when accessing the access network;
- acquiring further updated long-term subscriber access credentials, [0017] A wireless communication device is also provided.
[0018] In one or more examples, the registration server is adapted to support such operations, e.g., ensuring validation of credentials and / or redirecting the device to a new home operator for obtaining new subscriber credentials.
[0019] Although not limited to devices with M2M (machine-to-machine) functionality, methods and devices for restoring authentication data as described herein are particularly advantageous in that they allow M2M devices to autonomously detect problems with their current subscriber credentials and use their credentials for temporary access to obtain new / crypted subscriber credentials. Thanks to this, the owner of several hundred or thousands M2M devices can change subscription contracts for some or all devices without the need to contact or interact with these devices. Due to the fact that any change to the subscription agreement invalidates the subscriber's credentials stored in the device, each such device will detect an access failure using its current subscriber's credentials t will return to the credentials for temporary access and will contact the registration service or other entity for confirmation whether new subscriber credentials are needed, [0020] In at least one embodiment, the subscriber's credentials are long-term credentials issued by the operator associated with the specific subscription contract / home provider. In the same or other examples, the credentials for temporary access are "general" credentials that allow temporary, limited access to the network. Eg. any number of network operators can configure their networks to allow temporary connectivity for devices that use credentials for temporary access. In at least one example, the credentials for temporary access considered herein include a PIMSI ( preliminary International mobile subscriber identity) or other identifier that allows a wireless communication device to authenticate with any number of network operators. These temporary access credentials may also contain other data elements, e.g. keys. In a non-limiting example, these temporary access credentials are permanently stored in the wireless communication device and are entered e.g. by the device manufacturer. In contrast, the present invention is not limited to the above summary of elements and benefits. In fact
Same, persons skilled in the field after reading the detailed description below and after viewing the figures of the attached drawing will notice additional elements and benefits.
BRIEF DESCRIPTION OF THE FIGURES [0021]
Fig. 1 is a block diagram of one embodiment of a wireless communication device adapted to perform restoration of credentials.
Fig. 2 is a logic diagram of one embodiment of the processing logic performing the restore of authentication data in a wireless communication device.
Fig. 3 is a block diagram of one example of a home and visited network as well as of a registration server that is adapted to support wireless communication devices in determining whether they need new subscriber credentials.
Fig. 4 is a logic diagram of one example of the detailed processing logic that performs the restoration of credentials in a wireless communication device.
Fig. 5 is a logic diagram of one example of processing logic in a registration server for implementing a method of supporting wireless communication devices in determining whether they need new subscriber credentials.
Fig. 6 is a logic diagram of one example of detailed processing in a registration server for implementing a method of supporting wireless communication devices in determining whether they need new subscriber credentials.
DETAILED DESCRIPTION [0022] Fig. 1 illustrates one embodiment of a wireless communication device 10 that is preferably adapted to perform restoration of authentication data according to the present explanation. Although such details are not limiting, the illustrated device includes one or more antennas 12, switch and / or dupfectser 14, wireless signal receiver 16, as well as wireless signal transmitter 18, one or more processing circuits 20, including the authentication data processor 22, security element 24 that can store subscriber's credentials (SC) subscription credentiais) 26, as well as a one-time-programmable (OTP) one-time programmable memory element 28 that can be used to store temporary access credentia (TAC) credentials 30 The device 10 also includes memory 32, which may include one or more memory devices for storing operating data, computer program commands and configuration information.
[0023] In non-limiting examples, the device 10 is a cellular communication device, e.g. a cellular radiotelephone, pager, PDA, computer or network card. In a specific example, device 10 is a device with M2M (machine-to-machine) functionality, e.g., a cellular communication module adapted to be built into other devices and systems, e.g. vending machines, gas meters, cars, etc.
[0024] During operation, the device 10 uses its subscriber credentials 26 to
Accessing the network, although this device 10 may have used its temporary access credentials 30 to obtain temporary access as a basis for acquiring subscriber credentials 26, via over-the-air configuration (OTA). In contrast, subscriber credentials 26 are considered "persistent" or at least long-term subscriber credentials because they generally remain valid as long as the owner of the device 10 maintains the corresponding subscription contract with the home network operator that issued the subscriber credentials 26. In at least one example, the subscriber the credentials 26 include the USIM module Universal Subscriber identity Module), which can contain an IMSI (International mobile subscriber identifier). In addition, in at least one example, the credentials for temporary access include a PI MSI ( preliminary international mobile subscriber identity) or other identifier that can be used by the device 10 to authenticate with any one or more network operators that accept the credentials for temporary access. The credentials for temporary access may e.g. be burned into secured fuse memory cells or other secured OTP memory in the device 10 during its production or initial configuration. Preferably, device 10 includes an "authentication data processor" 22 that is adapted to restore in place of subscriber credentials 26 credentials for temporary access 30 in response to detection of failed network access. Ie. in one or more examples, the device 10 uses its subscriber credentials 26 to access the network, unless it will no longer be able to access using these credentials. At this point, device 10 preferably returns to its credentials for temporary access 30. These credentials generally do not expire and are generally not void, except in exceptional cases of theft or other known security breaches.
[0025] The device 10 thus passes (automatically and autonomously) from its configured subscriber credentials 26 to its credentials for temporary access 30 and uses this credentials for temporary access 30 to obtain temporary network access. In turn, the device 10 uses its temporary access to determine whether it needs new subscriber credentials. If so, it uses its temporary access to acquire new subscriber credentials, which it can download e.g. to its secured element 24. If the device 10 does not state that it needs new subscriber credentials, it may return to its stored subscriber credentials 26 and continue access attempts.
[0026] Fig. 2 illustrates one example of processing logic that can be implemented in the credentials processor 22, which may include an actual processing system or functional processing element in the processing systems 22. E.g.authentication data processor 22 can be implemented using software performed in one or more microprocessor systems for the implementation of processing systems 20. Those skilled in the art will recognize that the sequential processing and processing order in Fig. 2 are shown for discussion, unless otherwise indicated. The order of processing can be changed at least under
For certain reasons, at least some of the processing may be performed concurrently, and at least some of the processing may be performed along with other processing tasks, and also looped or repeated as needed.
[0027] With the above in mind, the illustrated processing implements a method of managing subscriber's credentials in the device 10. With respect to the illustrated processing steps, this method includes detecting failure when accessing the network using current subscriber's credentials 26 stored in the wireless communication device 10 (block 100). The processing continues in response to the detection of such a failure, with the replacement of the current subscriber credentials 26 credentials for temporary access 30 (block 102), also stored in the wireless communication device 10. Further processing includes determining whether new subscriber credentials are needed, based on obtaining temporary network access using temporary credentials (block 104/106). If new subscriber credentials are needed, processing proceeds to acquiring new subscriber credentials for wireless communication device 10 using temporary network access (block 108). [0028] More detailed examples of the above method of restoring credentials may be better understood in the context of Fig. 3, which illustrates a home network 40 comprising a radio access network (RAN) 42 and a core network (CN) network) 44, and also illustrates the visited network 46, including the RAN 48 network and the CN 50 network. Home and home networks 46 may couple to each other and / or may provide communication to one or more additional networks 52, e.g., Internet. Of course, it should be understood that, in general, a number of operator networks may be involved in all or part of the information disclosed herein. Eg. assuming that the wireless communication device 10 states that it cannot access or otherwise cannot communicate using its current subscriber credentials, it restores its credentials to temporary access (initial credentials) for temporary access to acquire new ones subscriber's credentials. From the point of view of the wireless communication device 10, a given network through which it accesses, at least at the level of the radio access network, may or may not be the "home" network of that device. For example, the wireless communication device 10 may attempt to access through the visited network using its credentials for temporary access. Whenever the wireless communication device 10 authenticates to the network using its temporary access credentials (pre-credentials), there is in some sense a "pre-operator". This pre-operator is an operator that also has this pre-credential (or at least can authenticate it), thereby enabling this pre-operator to authenticate the wireless communication device 10 in any network to which the wireless communication device 10 attempts to connect. This "pre-operator" may be called "registration operator".
[0029] The registration operator may support the service / registration server discussed herein or this / this service / server may be provided elsewhere (e.g. in a third-party server accessible via the Internet). In every
In the case of, it should be understood that the registration operator's network may be as well a visited network as the home operator's network for a wireless communication device 10, but it is not necessary for that device to know which case is occurring; instead, the device simply presents its initial credentials for authentication, and the network to which the device attempted to connect will either authenticate these credentials or forward it to the registration operator's network for authentication. Thus, any number of operator networks may be involved in the authentication of the credentials for the temporary access of the device and the communication coupling of the device with the registration service for acquiring new subscriber credentials.
[0030] Returning to the illustrated details, external network connectivity allows to connect home network 40 and visited network 46 to registration server 54, which in one or more examples is implemented as a website server (or other system available through the IP protocol). This registration server 54 provides a registration service in which device owners and / or home network operators can "register" communication devices. Registration server 54 includes or is associated with registration processor 56, which may be a computer system, and associated memory / storage systems 58 for storing registration information. Additionally or alternatively, one or both of home network 40 and visited network 46 have direct communication links to registration server 54.
[0031] Home network 40 and visited network 46 may differ or not differ in any major respect, and the terms "home" and "visited" used in this context may mean no more than that the owner of the device 10 has a subscription contract with a service provider that owns or otherwise serves the home network 40. Thus, there may be a case in which the device 10 "sees" radio signals from the RAN network of the home network 42 and the RAN network of the visited network 48, and thus could use any of them to achieve network connectivity. However, given that the current subscriber credentials 26 of the device are issued by the home network operator, obtaining access to the network via RAN 42 / CN 44 is preferred when accessing the network via RAN 48 / CN 50.
[0032] In other contexts, e.g. when the device 10 is outside the service area of its home network, there may be a case where only visited networks are available to it. However, for roaming contracts, etc., the device 10 will continue to use its current subscriber credentials 26 issued by its home network operator. More generally, it should be understood that at any time the device 10 may operate in an area in which a number of RANs are available for access to the network. In general, however, one of these RANs is preferred, with the remaining or remaining ones not being preferred.
[0033] With the above in mind, Fig. 4 provides a more detailed illustration of the method of restoring the credentials outlined in Fig. 2. The "operational" state illustrated at the beginning of the processing in Fig. 4 means that the device 10 contains the current subscriber credentials 26 and successfully has gained access to the network using this credential, e.g. during its last connection. It can be seen that block 100 (from Fig. 2) may include a number of ways to detect failure when accessing the network. As the first example, the device 10 can detect the loss of access for
- your local (preferred) RAN (block 110). In the illustrated example, the device 10 is adapted to attempt to reconnect using its current subscriber credentials 26 - e.g. using the IMS identifier stored therein! - a certain number of times (blocks 112 and 114).
[0034] If these attempts are unsuccessful during a limited number of retries, the device 10 looks for alternative access (block 116). Thus, according to the logic of blocks 112 and 114, the authentication data processor 22 controls or otherwise causes the device 10 to make a limited number of re-attachments using its preferred network, and if it fails, make one or more attempts to rejoin or more non-preferred networks. These attempts to join a non-preferred network are also made using current device subscriber credentials 26 and are subject to some limitations in their number.
[0035] If the attachment based on the IMSI identifier turns out to be ineffective ("no" from block 118), the device 10 recognizes such circumstances as failure detection when accessing the network (i.e. "failure" detected in block 100, Fig. 2) In response to this failure detection, the device 10 restores instead of the current subscriber credentials 26, the credentials for temporary access 30 (block 120) and seeks network access (block 122). It can search for locally available RANs, both preferred and non-preferred (although it can try preferred RANs first). In any case, the device 10 gains temporary network access to the available network using its temporary access credentials (block 124), e.g., performs a temporary join based on the PIMSI identifier.
[0036] The device 10 then uses this temporary network access to acquire new subscriber credentials (block 126), which in one or more examples includes downloading a new or updated USIM module. When the device 10 acquires the new subscriber credentials, it replaces its previously valid subscriber credentials and the newly acquired subscriber credentials become the current subscriber's credentials 26 of the device. The device 10 uses this newly updated subscriber credentials 26 to gain access to the network (block 128), e.g. it performs an attachment based on the IMSI identifier. (Note that this illustration assumes that a network problem arises because device 10 needs new subscriber credentials, but device 10 may be able to explicitly determine whether this is true or not as soon as it gains temporary network access .) [0037] In another case of detecting network access failure, the device 10 experiences a loss of its home network (block 130), which may mean that the device 10 can communicate with the local RAN but is not recognized or otherwise is not authenticated by its home network. If this condition exists, device 10 performs processing from blocks 116 and 118 as described above. If this processing does not result in successful access using its current subscriber credentials 26, the device 10 determines that it has experienced a network access failure (block 100, Fig. 2). Thus, in accordance with the method of restoring the credentials explained here, detecting the failure when accessing the network using the current subscriber credentials 26 stored in the wireless device
- communication 10, includes performing one or more initial access attempts through the preferred access network, using current subscriber credentials 26. If this initial one or more access attempts prove unsuccessful, continue the method by performing one or more subsequent access attempts through one or more non-referenced access networks available to the wireless communication device 10, also using current subscriber credentials 26.
[0038] In yet another example of detecting failure on network access, device 10 is explicitly disconnected from its home network (block 132). In one example, the home network sends signaling - e.g., a message - to device 10, which indicates that the device's subscriber credentials have expired or otherwise become invalid. The device 10 recognizes such signaling as an explicitly indicated network access failure and therefore restores its credentials to temporary access 30. Thus, according to the method of restoring the credentials explained here, detecting the failure when accessing the network using the current subscriber credentials 26 stored in the wireless communication device 10 includes receiving a failure message in response to attempting to access the network using current subscribers credentials 26, [0039] As described, the device 10 is adapted to perform a return to its credentials for temporary access in response to detecting a network access failure as just discussed in detail. In at least one embodiment of the method, this restoration involves substitution of limited access credentials that are pre-configured in wireless communication device 10 in place of current subscriber credentials 26 for use in accessing the network. This restricted access credentials includes, in at least one example, a PIMSI identifier or other identifier permanently stored in the wireless communication device 10.
[0040] In the further details of the method explained here for at least one example, determining whether new subscriber credentials are needed based on obtaining temporary network access using temporary credentials 30 includes connecting to a registration service via temporary network access and communication with this registration service to determine if new subscriber credentials are needed. For example, the device 10 connects to the registration server 54 as shown in Fig. 3 or connects to another network-accessible unit having some knowledge of its current subscription status.
[0041] In at least one example, communicating with a registration service to determine if new subscriber credentials are needed includes receiving a hash value. hash) from the registration service, creating a hash value based on the current subscriber credentials stored by the wireless communication device 10 and determining that new subscriber credentials are needed when a mismatch between these hash values is detected. In another example, wireless communication device 10 receives a time stamp which it compares with a time stamp which it stores for current subscriber credentials as a basis for determining whether it needs new subscriber credentials.
[0042] In another example, communication with the registration service to determine if new subscriber credentials are needed includes sending a hash value to the registration service that is based on the current subscriber credentials stored by the wireless communication device 10 as well as receiving from this reverse registration service an indication that new subscriber credentials are needed. Similarly, in another example, communicating with the registration service to determine if new subscriber credentials are needed includes sending a time stamp to this registration service that is based on current subscriber credentials stored by the wireless communication device 10, and receiving from this feedback registration service indicates that new subscriber credentials are needed.
[0043] Generally, the wireless communication device 10, in one or more examples, implements a method in which it is adapted to communicate with a registration service to determine whether new subscriber credentials are needed. This statement is made by sending by this wireless communication device 10 to the registration service to evaluate the first information that is associated with the current subscriber credentials stored by this wireless communication device 10, as well as receiving a feedback from the registration service. For example, this feedback indicates whether new subscriber credentials are needed. This first information can be a timestamp for current subscriber credentials or a hash value derived from them.
[0044] Similarly, in another example, wireless communication device 10 implements a method in which it communicates with a registration service to determine whether new subscriber credentials are needed, based on a comparison by this wireless communication device 10 of the first information stored in this wireless communication device 10, with a second information received from the registration service. As before, the first information contains e.g. the time stamp or hash value for the current subscriber credentials stored by the wireless communication device 10. Similarly, the second information may include a time stamp or hash value for the subscriber credentials that the registration service considers valid for this wireless communication device 10.
[0045] In another aspect of such processing, acquiring new subscriber authentication data for the wireless communication device 10 includes, in at least one example, receiving from a network address information registration service that identifies the authentication data server from which new authentication data is to be obtained, and also using temporary network access to contact this credential server, to obtain new subscriber credentials. It should be noted that this credential server, in one or more examples, is a module working in the service provider's GN network that has issued new subscriber credentials, or under the control of that network.
[0046] Furthermore, in one or more examples, the method of restoring credentials includes, after acquiring new subscriber credentials, a change from the credentials for temporary access to these new subscriber credentials for the next access to the network while preserving these credentials to temporary
-13 access in wireless communication device 10, for future restoration as needed. That is, the device 10 may replace or deactivate its previously valid subscriber credentials and use the newly acquired subscriber credentials as its newly valid subscriber credentials 26 to be used for subsequent network access, while retaining its credentials for temporary access 30 in case they need more restorations.
[0047] Therefore, in one or more examples, the device 10 is adapted to return from the current subscriber credentials 26 to the credentials for temporary access without permanently deactivating or otherwise invalidating its subscriber credentials 30. In this way, the device 10 can perform a restore on failed access and use its credentials for temporary access to determining whether new subscriber credentials are needed. If the device 10 does not receive an indication that new subscriber credentials are needed, or cannot otherwise make such a statement, it returns to using its current subscriber credentials 26 and may continue periodic access attempts using them. Additionally or alternatively, it may alternate between using its credentials for temporary access in attempts to determine if there is a problem with its current subscriber credentials 26 and using these credentials crediting 26 in regular access attempts.
[0048] With respect to the operations of the registration server 54, as shown in Fig. 3, it implements a method of enabling automatic acquisition of new subscriber credentials by wireless communication devices. Fig. 5 illustrates the processing logic for implementing one variant of this method. As with other logic diagrams presented herein, the illustrated order of processing is not intended to be limiting, and at least some of the processing operations may be performed in different orders and / or concurrently or as part of other processing.
With this in mind, the illustrated processing "begins" by receiving the first information from a wireless communication device that has obtained temporary access to the network (block 140). This first information is contained in the current subscriber credentials stored by this wireless communication device or it is derived from them. device 10 returns to its credentials for temporary access 30, gains temporary network access, connects to registration server 54 and sends to this registration server 54 the first information for the subscriber's credentials 26 currently stored in the device.
[0050] The processing in the registration server 54 proceeds by comparing this first information with the second information stored by this registration server 54 (block 142). This second information is contained in or derived from current subscriber credentials associated with the current home network operator of the wireless communication device. The subscriber credentials considered by the subscription server 54 to be "up to date" may or may not match those considered "current" by the device. Indeed, one of the benefits considered here is that the device owner can change subscriptions without first updating device in question.
[0051] Generally, the first and second information are of the same type and format and are intended to match or otherwise indicate compliance if the subscriber credentials 26 stored in the device correspond to the subscriber credentials considered by the registration server 54 to be current for this device. As a non-limiting example, the first and second information include timestamp information, which e.g. can be compared to determine if the subscriber credentials 26 are no longer up to date. Ie. the current subscriber credentials stored by the wireless communication device 10 may include a first time stamp, and the subscriber credentials which the registration service considers valid for this wireless communication device 10 may include a second time stamp. Thus, the wireless communication device 10 may send the first time stamp to the registration service for evaluation or this registration service may send the second time stamp to the wireless communication device for assessment. Other types of data may be used in similar comparison-based statements as to whether new subscriber credentials are needed.
[0052] For example, in another variation, the first information is a hash value derived from the current subscriber credentials of the device, and the second information is a hash value derived in a similar way from the subscriber credentials deemed to be valid for this device by the registration server 54. Generally, registration server 54 compares or otherwise assesses this information first and second to determine whether this device needs to obtain new subscriber credentials. If the registration server 54 detects a mismatch between this first and second information ("no" from block 144), it sends an indication to the device that the device needs to acquire new subscriber credentials (block 146).
[0053] The above processing may be performed in the registration server 54, e.g. due to the corresponding hardware and / or software configuration of the registration processor 56, which is illustrated in Fig. 3. In this regard, the registration server 54 may be adapted to provide a certain range of registration services, and in one or more examples it provides communication interfaces to network operators and / or device owners to provide registration information to a number of devices. Such information may be removed or modified as needed to reflect changing subscription information, operator links, etc. Selected registration service information can be found in the 3GPP TR 33.812 V0.1.0 (2008-01) technical report.
[0054] Regarding the details of the registration service relevant to this discussion, Fig. 6 shows additional processing details for the registration service function provided by the registration server 54 and outlined in Fig. 5. This more detailed processing assumes that the registration server 54 is idle and receives the request "Initiating" (block 150), i.e. it is accessed by a device that has gained temporary access to the network by restoring its credentials to temporary access 30, which device is attempting to determine if its current subscriber credentials 26 are valid.
[0055] In response, the registration server 54 determines whether the abbreviation of the current (software) USIM device module (block 152) is correct, e.g. the device sends the hash value as the first information previously described, and the registration server 54 attempts to verify this hash value. If this hash value is verified, the registration server 54 decides that the current subscriber credentials 54 of the device are
-15 weight (block 154), e.g. it recognizes the current USIM device module as valid. Registration server 54 may return a validity indication of the credentials to the device that sent the request.
On the other hand, if the hash value turns out to be incorrect ("no" from block 152), the registration server 54 checks whether subscription information is available (block 156), and if so, sends the network address information to the device, to enable this device to acquire new subscriber credentials (block 158) Eg registration server 54 redirects this device to the new home network for acquiring the downloadable USIM module. Also, if the hash value turns out to be incorrect, but registration server 54 for some reason does not have access to subscription information, which allows it to redirect the device to acquire new subscriber's credentials ("no" from block 156), registration server 54 may send such indication for this device (blocks 60).
[0057] Thus, the authentication data recovery explained herein provides advantageous method and implementations of devices for wireless communication devices and / or registration servers providing registration services. These methods and devices can be implemented in systems and devices of various types. On the other hand, as a general proposal, they provide for a wireless communication device autonomous return from subscriber's credentials, e.g. long-term, provided by the operator, subscriber credentials for temporary access credentials and the use of these credentials for temporary access to obtain temporary access to the network to determine whether new subscriber credentials are needed. If so, this device uses this temporary network access to acquire new subscriber credentials, e.g. by downloading a new USIM module.
[0058] Accordingly, the present invention is not limited to the above discussion, nor by the accompanying drawing. Instead, the present invention is limited only by the following claims.
8 members in 5 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 3079908 | United States of America | P | |
| 14072808 | United States of America | A | |
| 09711770 | European Patent Office (EPO) | A | |
| 2009051355 | European Patent Office (EPO) | W | |
| EP20090711770 | – | – | – |
| US20080030799P | – | – | – |
| US20080140728 | – | – | – |
| WO2009EP51355 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| US2009217364A1 | United States of America | A1 | |
| WO2009103622A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2260653A1 | European Patent Office (EPO) | A1 | |
| CN101953192A | China | A | |
| US8553883B2 | United States of America | B2 | |
| EP2260653B1 | European Patent Office (EPO) | B1 | |
| CN101953192B | China | B | |
| PL2260653T3This record | Poland | T3 |
Numbers
- Publication, DOCDB
- 2260653
- Publication, EPODOC
- PL2260653T
- Application
- 711770
- Application, DOCDB
- 09711770
- Application, EPODOC
- PL20090711770T
Titles2
- English
- METHOD AND APPARATUS FOR MANAGING SUBSCRIPTION CREDENTIALS IN A WIRELESS COMMUNICATION DEVICE
- Polish
- Sposób i urzadzenie do zarzadzania abonenckimi danymi uwierzytelniajacymi w bezprzewodowym urzadzeniu komunikacyjnym
Classification
- CPC, 5
- H04L69/40
- H04L67/12
- H04W12/0608
- H04W88/02
- H04W88/18