TWI433556B

Wireless network authentication apparatus and methods

Abstract

Equipment and methods used to authenticate and allow client devices (for example, mobile phones) to access the network. In one embodiment, a network service provider such as a mobile phone company can distribute user access (for example, Universal User Identity Module, or "USIM") credentials to the service manager via the USIM provider. This service manager can maintain a list of approved users. The user at the customer site can authenticate this service manager. Once authenticated, the service manager can provide the user with a set of USIM credentials. When the user wants to use the wireless network service, the user equipment can establish a wireless link between the user equipment and the network service provider. During the authentication operation, the user equipment can use these USIM certificates to authenticate the network service provider. After successful authentication, the network service provider can provide this user equipment wireless service.

TWI433556B, drawing sheet 1
Sheet 1 of 3

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Granted
  4. Today

20 claims: 8 independent, 12 dependent

  1. 1
    A method for user equipment to access wireless services, including:distributing access customer data to a first entity, wherein the first entity includes a virtual universal user identity module (USIM) provider, and the access customer data includes Virtual Universal User Identity Module (USIM);transmitting the access customer data from the first entity to the second entity through the first communication link, where the second entity includes a trusted service manager;At the trusted service manager, the user certificate is used to authenticate the user equipment, where the user equipment does not include a physical subscriber identity module (SIM) card slot, and it contains the user equipment for storing the access client Secure component replacement of data;after authenticating the user equipment, the access client data from the second entity is transferred to the user equipment through the second communication link, wherein the user equipment stores the access client The data is in the secure element;the user at the user equipment is given the following options: through the access client data stored in the secure element, access the first one in the wireless service, and through communication with the user equipment The physical subscriber identity module (SIM) card inserted into the subscriber identity module (SIM) card slot of the accessory device to access the second one of the wireless services;and access the first or the second one based on the choice provided by the user 2. The wireless service. 一種使用者裝備存取無線服務之方法,包含:將存取客戶資料散佈至第一實體,其中該第一實體包含虛擬通用型用戶身份模組(USIM)供應商,且該存取客戶資料包含虛擬通用型用戶身份模組(USIM);將來自該第一實體的該存取客戶資料透過第一通訊鏈結而傳送至第二實體,其中該第二實體包含受信任的服務管理者;於受信任的服務管理者處,使用使用者憑證,以認證該使用者裝備,其中,該使用者裝備不包含實體用戶身份模組(SIM)卡插槽,且以包含用以儲存該存取客戶資料的安全元件替代;在認證該使用者裝備之後,將來自該第二實體的該存取客戶資料透過第二通訊鏈結而轉移至該使用者裝備,其中該使用者裝備儲存該存取客戶資料於該安全元件中;給使用者裝備處的使用者以下的選擇:經由儲存於該安全元件的該存取客戶資料,存取無線服務中的第一個,及經由與該使用者裝備通訊的插在附屬裝置的用戶身份模組(SIM)卡插槽的實體用戶身份模組(SIM)卡,存取無線服務中的第二個;及基於使用者提供的選擇存取第一或第二該無線服務。
  2. 4
    For example, the method described in item 1 of the scope of patent application, wherein the user certificate contains the user's unique account information. 如申請專利範圍第1項之方法,其中,該使用者憑證包含該使用者之特有的帳戶資訊。
  3. 6
    A wireless device, including:one or more communication links, which are suitable for communicating with wireless service providers;secure elements, which are grouped to form a storage access client, where the access client includes a virtual universal user identity module (USIM) A processor;and a storage device for data communication with the processor, wherein the storage device stores computer-executable instructions, the computer-executable instruction set constitutes when the computer-executable instructions are executed by the processor, the wireless Equipment progress: use the account information established when purchasing the wireless device to authenticate the wireless device to a trusted service manager, where a successful authentication results in the provision of the service provider of the accessing client;in response to receiving the deposit Fetch the client, store the access client in the secure element;and give the user of the wireless equipment the following choice: access the first one of the wireless service providers via the access client stored in the secure element And plug in the accessory device via communication with the wireless device Access to the second one of the wireless service providers;and access the first or second one of the wireless service providers based on the selection provided by the user. service. 一種無線設備,包含:一個或多個通訊鏈結,係適用與無線服務提供者通訊;安全元件,係組構成儲存存取客戶,其中該存取客戶包含虛擬通用型用戶身份模組(USIM);處理器;以及儲存裝置,與該處理器資料通訊,其中該儲存裝置儲存電腦可執行指令,該電腦可執行指令組構成當該等電腦可執行指令被該處理器所執行時,使該無線設備進行:利用於購買該無線裝置時建立的帳戶資訊,對受信任的服務管理者認證該無線設備,其中,成功的認證導致由該存取客戶的該服務提供者之提供;回應接收該存取客戶,將該存取客戶儲存於該安全元件內;及給該無線裝備的使用者以下的選擇:經由儲存於該安全元件的該存取客戶,存取該無線服務提供者中的第一個,及經由與該無線設備通訊的插在附屬裝置的用 戶身份模組(SIM)卡插槽的實體用戶身份模組(SIM)卡,存取該無線服務提供者中的第二個;及基於使用者提供的選擇存取第一或第二該無線服務。
  4. 9
    Such as the wireless device of the 6th patent application, wherein the wireless device communicates with the accessory device via a near field communication (NFC) circuit. 如申請專利範圍第6項之無線設備,其中,該無線設備經由近場通訊(NFC)電路與該附屬裝置通訊。
  5. 10
    For example, the wireless device of item 6 of the scope of patent application, wherein the secure element is an anti-tampering integrated circuit permanently built in the device. 如申請專利範圍第6項之無線設備,其中,該安全元件為被永久地建構於該設備中的防竄改積體電路。
  6. 11
    A method for storing and accessing customer data securely in user equipment, including:sending user certificates, which are used to establish the purchase of user equipment in a trusted service manager, so that the trusted service can be managed The user equipment is authenticated based on at least a part of the user certificate, wherein the user equipment does not include a user identity module (SIM) card slot;after the user equipment is successfully authenticated by the trusted service manager , Through the communication interface to receive and access customer data, where the access customer data includes a virtual universal user identity module (USIM);store the access customer data in a secure component;and give the user at the user equipment department The following options: through the access customer data stored in the secure element, access The first wireless service, and access to the second wireless service via a physical subscriber identity module (SIM) card inserted in the subscriber identity module (SIM) card slot of the accessory device that communicates with the user equipment;and based on usage The user provides the option to access the first wireless service or the second wireless service. 一種將存取客戶資料安全地儲存在使用者裝備處之方法,包含:傳送使用者憑證,該使用這憑證建立於購買使用者裝備於受信任的服務管理者,以使該受信任的服務管理者基於至少該使用者憑證的一部分認證該使用者裝備,其中,該使用者裝備不包含用戶身份模組(SIM)卡插槽;在由該受信任的服務管理者成功認證該使用者裝備之後,透過通訊介面接收存取客戶資料,其中該存取客戶資料包含虛擬的通用型用戶身份模組(USIM);將該存取客戶資料儲存於安全元件內;及給使用者裝備處的使用者以下的選擇:經由儲存於該安全元件的該存取客戶資料,存取 第一無線服務,及經由與該使用者裝備通訊的插在附屬裝置的用戶身份模組(SIM)卡插槽的實體用戶身份模組(SIM)卡,存取第二無線服務;及基於使用者提供的選擇存取該第一無線服務或該第二無線服務。
  7. 18
    A service management device includes:a network interface group is configured to transmit a plurality of access clients to one or more wireless devices, wherein each access client of the plurality of access clients includes a virtual universal user identity module (USIM) ;The storage device group is configured to store the plurality of access clients;the processing logic communicates with the network interface and the storage device data, wherein the processing logic group is configured to receive an access request from one or more of the wireless devices;In response to the access request, authenticate individual one or more of the wireless devices and transmit at least one of the access clients among the plurality of access clients, wherein one of the individual one or more wireless devices enables the user Choose from the following: access the first wireless service via at least one of the access clients, and via a subscriber identity module (SIM) card inserted in an accessory device that communicates with one or more of the individual wireless devices The physical subscriber identity module (SIM) card in the slot accesses the second wireless service. 一種服務管理設備,包含:網路介面組構成傳送複數存取客戶至一或更多個無線裝置,其中該複數存取客戶中的每個存取客戶包含虛擬通用型用戶身份模組(USIM); 儲存裝置組構成儲存該複數存取客戶;處理邏輯與該網路介面及該儲存裝置資料通訊,其中該處理邏輯組構成:從個別的一或多個該無線裝置之一接收存取請求;回應該存取請求,認證個別的一或多個該無線裝置之一及傳送該複數存取客戶中的該存取客戶的至少之一,其中個別的一或多個該無線裝置之一使使用者從以下選擇:經由該存取客戶的至少之一存取該第一無線服務,及經由插在與個別的一或多個該無線裝置之一通訊的附屬裝置的用戶身份模組(SIM)卡插槽的實體用戶身份模組(SIM)卡,存取第二無線服務。
  8. 20
    For example, the service management device of the 18th patent application, wherein the network interface group is configured to transmit at least one of the access clients to one of the individual one or more wireless devices through a secure wireless connection. 如申請專利範圍第18項之服務管理設備,其中,該網路介面組構成透過安全無線連接傳送該存取客戶的至少之一至個別的一或多個該無線裝置之一。