- Number
- 11379574
- Published
- 2022-07-05
- Filed
- 2020-01-02
- Assignee
- Disney Enterprises, Inc.
- Inventors
- Watson; Scott F., Eaton; Steven C., Jarchafjian; Harout, Arthur; Thomas C., Moharil; Vinay, Gorin; Joshua B., Parish; Adam S., Prasad; Ajay M., Umstead; Joshua Caleb
- CPC
- H04W4/80; H04L67/53; H04L67/303; G06F21/6209; H04W12/50; H04L9/0825; H04L67/12; G06F21/44; H04L9/088; H04W12/06
- Verdict
- Set aside device authentication, security/business
- Source
- Google Patents · FreePatentsOnline
Abstract
Techniques for secure mobile device recognition are disclosed. An IOT edge device determines, based on a network message received at the IOT edge device, that a mobile device is not recognized. The IOT edge device transmits a token request to the mobile device. In response, the IOT edge device receives an encrypted token from the mobile device. The IOT edge device transmits the encrypted token to a server. The server is configured to determine an identifier corresponding with the mobile device, based on the encrypted token. A recognition task is initiated for the mobile device, based on the determined identifier.
Background
BACKGROUND Field of the Invention (1) Embodiments presented herein generally relate to techniques for secure permission-based recognition of a mobile device while protecting an identity of a user of the mobile device. More specifically, embodiments presented herein relate to techniques that allow a mobile device to be securely recognized by a trusted third-party while preventing a non-trusted third-party from recognizing the mobile device. Description of the Related Art (2) A variety of technologies can be used to recognize a mobile device using signals emitted from the device. These signals emitted by the device can include identifying data, such as a user ID, device ID and an address, that can be used to recognize the device. Some of these technologies, however, may allow an undesired non-trusted third-party to recognize the device if the non-trusted third party can receive and understand the transmitted data. For example, a mobile application may use a static encryption key that is common across all instances of the mobile application to encrypt a transmitted device ID. In that case, the device ID of each mobile device running the mobile application is encrypted using the same encryption key. While this technique may initially be secure, a non-trusted third-party could decompile the application to determine the encryption key. The third-party could then use the encryption key to decrypt any device ID related to that mobile application and recognize the mobile device or a u
Claims
1. A method for secure mobile device recognition, comprising: determining, based on a network message received at a first IOT edge device, that a mobile device is not recognized at the first IOT edge device; transmitting a token request from the first IOT edge device to the mobile device, and in response receiving at the first IOT edge device a first encrypted token from the mobile device, wherein the first encrypted token is one of a plurality of tokens received at the mobile device from a server different from the first IOT edge device; transmitting the first encrypted token from the first IOT edge device to the server, wherein the server is configured to determine an identifier corresponding with the mobile device, based on the first encrypted token; initiating a recognition task for the mobile device, based on the determined identifier; determining, based on a second network message received at a second IOT edge device different from the first IOT edge device, that the mobile device is not recognized at the second IOT edge device; transmitting a second token request from the second IOT edge device to the mobile device, and in response receiving at the second IOT edge device a second encrypted token from the mobile device, wherein the second encrypted token is different from the first encrypted token and is another of the plurality of tokens received at the mobile device from the server; transmitting the second encrypted token from the second IOT edge device to the server, wherein the server is configured to determine the identifier corresponding with the mobile device, based on the second encrypted token; and initiating a second recognition task for the mobile device, based on the determined identifier. ||
11. A non-transitory computer-readable medium containing computer program code that, when executed by operation of one or more computer processors, performs an operation comprising: determining, based on a network message received at a first IOT edge device, that a mobile device is not recognized at the first IOT edge device; transmitting a token request from the first IOT edge device to the mobile device, and in response receiving at the first IOT edge device a first encrypted token from the mobile device, wherein the first encrypted token is one of a plurality of tokens received at the mobile device from a server different from the first IOT edge device; transmitting the first encrypted token from the first IOT edge device to the server, wherein the server is configured to determine an identifier corresponding with the mobile device, based on the first encrypted token; initiating a recognition task for the mobile device, based on the determined identifier; determining, based on a second network message received at a second IOT edge device different from the first IOT edge device, that the mobile device is not recognized at the second IOT edge device; transmitting a second token request from the second IOT edge device to the mobile device, and in response receiving at the second IOT edge device a second encrypted token from the mobile device, wherein the second encrypted token is different from the first encrypted token and is another of the plurality of tokens received at the mobile device from the server; transmitting the second encrypted token from the second IOT edge device to the server, wherein the server is configured to determine the identifier corresponding with the mobile device, based on the second encrypted token; and initiating a second recognition task for the mobile device, based on the determined identifier. ||
15. A system, comprising: a processor; and a memory containing a program that, when executed on the processor, performs an operation, the operation comprising: determining, based on a network message received at a first IOT edge device, that a mobile device is not recognized at the first IOT edge device; transmitting a token request from the first IOT edge device to the mobile device, and in response receiving at the first IOT edge device a first encrypted token from the mobile device, wherein the first encrypted token is one of a plurality of tokens received at the mobile device from a server different from the first IOT edge device; transmitting the first encrypted token from the first IOT edge device to the server, wherein the server is configured to determine an identifier corresponding with the mobile device, based on the first encrypted token; initiating a recognition task for the mobile device, based on the determined identifier; determining, based on a second network message received at a second IOT edge device different from the first IOT edge device, that the mobile device is not recognized at the second IOT edge device; transmitting a second token request from the second IOT edge device to the mobile device, and in response receiving at the second IOT edge device a second encrypted token from the mobile device, wherein the second encrypted token is different from the first encrypted token and is another of the plurality of tokens received at the mobile device from the server; transmitting the second encrypted token from the second IOT edge device to the server, wherein the server is configured to determine the identifier corresponding with the mobile device, based on the second encrypted token; and initiating a second recognition task for the mobile device, based on the determined identifier.