Method and apparatus for protecting identities of mobile devices on a wireless network
Abstract
A method and apparatus for protecting the identities of mobile devices on a wireless network are described. A proxy gateway couples the wireless network to a wired network and maintains data associating a set of service initiators with a set of cryptographic keys. Upon receiving a request from a mobile client device directed to an origin server on the wired network, the proxy gateway identifies the cryptographic key for that origin server and sends to the origin server a proxy request. The proxy request includes an identifier of the mobile device, encrypted using the cryptographic key. When the proxy gateway receives a request from a service initiator on the wired network to push information to a mobile device, it uses the cryptographic key for that service initiator to decode a client identifier in the request and thereby determine whether the request is valid.
Claims
exact text as granted — not AI-modified1 . A method of operating a processing system on a network, the method comprising:
encrypting an identifier of a mobile device on a wireless network; and using the encrypted identifier to validate a request from a service initiator directed to the mobile device.
2 . A method as recited in claim 1 , further comprising maintaining a different cryptographic key for each of a plurality of service initiators.
3 . A method as recited in claim 2 , further comprising using the same cryptographic key for each service initiator in a second plurality of service initiators.
4 . A method as recited in claim 2 , wherein said encrypting comprises selecting and using one of the cryptographic keys to encrypt the identifier, the method further comprising including the encrypted identifier in a request to a remote processing system, based on a request from the mobile device.
5 . A method as recited in claim 4 , wherein said using the encrypted identifier to validate a request from a service initiator comprises selecting and using one of the cryptographic keys associated with said service initiator to validate the request.
6 . A method as recited in claim 5 , wherein said method is performed by a proxy server connected to the wireless network and to a wired network including the service initiator.
7 . A method as recited in claim 1 , wherein said encrypting comprises:
hashing the identifier with a cryptographic key; and including the encrypted identifier in a proxy request to a remote processing system based on an initial request received from the mobile device.
8 . A method as recited in claim 7 , wherein said using the encrypted identifier to validate a request from a service initiator comprises using the cryptographic key to decrypt an identifier included in the request from the service initiator; and
determining whether the identifier in the request from the service initiator corresponds to the mobile device.
9 . A method of operating a processing system on a network, the method comprising:
encrypting an identifier of a mobile device on a wireless network; including the encrypted identifier in a proxy request to a remote processing system on a network, based on a request from the mobile device; and using the encrypted identifier to control handling of requests by a plurality of remote processing systems on the network to provide information to the mobile device.
10 . A method as recited in claim 9 , further comprising maintaining a different cryptographic key for each of the plurality of remote processing systems.
11 . A method as recited in claim 10 , wherein said using the encrypted identifier to control handling of requests comprises, for each said request by a remote processing system, using one of the cryptographic keys corresponding to the remote processing system to validate the request.
12 . A method of operating a proxy on a network, the method comprising:
storing an association of service providers and cryptographic keys; receiving a request from a mobile device, the request directed to a remote server on the network; using the stored association to identify a cryptographic key associated with the remote server; using the identified cryptographic key to encode an identifier of the mobile device; incorporating the encoded identifier into a proxy request; and sending the proxy request to the remote server on behalf of the mobile device.
13 . A method as recited in claim 12 , wherein said storing an association of service providers and cryptographic keys comprises storing a unique cryptographic key for each of a plurality of service providers.
14 . A method as recited in claim 13 , wherein the stored association specifies a plurality of network addresses for at least one of the plurality of service providers, and wherein said using the stored association to identify a cryptographic key comprises identifying a cryptographic key associated with a network address to which the request is directed.
15 . A method as recited in claim 12 , wherein said using the identified cryptographic key to encode an identifier of the mobile device comprises hashing the cryptographic key with the identifier of the mobile device.
16 . A method of operating a proxy on a network, the method comprising:
storing an association of service providers and cryptographic keys, including a plurality of cryptographic keys and one or more network addresses associated with each of the cryptographic keys; receiving a request from a mobile client device, the request directed to a network address representing a remote server on the network; using the stored association to identify a cryptographic key associated with the remote server; generating a proxy request based on the request received from the mobile client device, by using the identified cryptographic key to encode an identifier of the mobile client device and incorporating the encoded identifier into the proxy request; and sending the proxy request to the remote server on behalf of the mobile client device.
17 . A method as recited in claim 16 , wherein said using the identified cryptographic key to encode an identifier of the mobile client device comprises hashing the cryptographic key with the identifier of the mobile client device.
18 . A processing system coupled to a wireless network and to a wired network, the processing system comprising:
a processor; and a storage facility coupled to the processor and storing instructions which configure the processing system to:
encrypt an identifier of a mobile device on the wireless network;
include the encrypted identifier in a proxy request to a remote processing system on the wired network, based on a request from the mobile device; and
use the encrypted identifier to control handling of requests by a plurality of remote processing systems on the wired network to provide information to the mobile device.
19 . A processing system as recited in claim 18 , wherein the processing system further stores a plurality of cryptographic keys, including a different cryptographic key for each of the plurality of remote processing systems.
20 . A processing system as recited in claim 19 , wherein said using the encrypted identifier to control handling of requests comprises, for each said request by a remote processing system, using one of the cryptographic keys corresponding to the remote processing system to validate the request.Join the waitlist — get patent alerts
Track US2005232191A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.