Laterpay 5g secondary authentication

TWI934928BActive Publication Date: 2026-08-11SUPERTAB AG
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
TW110117138
Authority / Receiving Office
TW · TW
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-06-22
Filing Date
2021-05-12
Publication Date
2026-08-11
Estimated Expiration
2041-05-11

AI Technical Summary

Technical Problem

Existing payment systems for online content require user interaction or pre-registration, lacking reliable identification of the user without such interaction, and do not ensure accountable cost management for digital content consumption.

Method used

A method utilizing 5G secondary verification technology enhances payment systems by using a persistent ID to authenticate and authorize user equipment, enabling payment system interaction without pre-registration, and managing content access based on account status.

Benefits of technology

Provides reliable user identification and accountable content access without user interaction, ensuring secure and efficient payment processing for digital content.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure TWG2TB001904863_001
    Figure TWG2TB001904863_001
  • Figure TWG2TB001904863_002
    Figure TWG2TB001904863_002
  • Figure TWG2TB001904863_003
    Figure TWG2TB001904863_003
Patent Text Reader

Abstract

A method for providing paid access to online content is provided, the method comprising: a) sending a signal from a user device requesting online content from a content provider, preferably from a website server of the content provider; b) receiving a response signal from the user device having an address of a payment system; one object of the present invention is to provide a content payment verification with improved reliability without requiring pre-registration with a payment system. The objective is achieved by the following: c) The user equipment sends a first communication period request signal, preferably a PDU communication period setting request signal, to request a communication period with the payment system, preferably a PDU communication period; d) A policy function unit, preferably a policy control function unit of a public terrestrial mobile network of the user equipment, determines an address of an authentication server based on the address of the payment system, preferably a secondary authentication server and / or an AAA server, preferably located away from the public terrestrial mobile network; e) A core network management function unit determines a persistent ID of the user equipment and sends a second communication period request signal. The persistent ID is provided to the verification server, preferably in an SMF / AAA communication period request signal; f) the verification server determines the authenticity of the user device using the persistent ID; g) the payment system determines a payment status for the user device regarding the online content based on the persistent ID; and h) based on the payment status, preferably through a first communication period established in response to the first communication period request signal, at least one user option is enabled on the user device for the online content, preferably at least one option being access to the online content, payment for the online content, and / or donation to the content provider.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to secondary verification of online content access as described in claims 1, 13, 14 and 15 of the patent application. Prior Technology

[0002] (none) Summary of the Invention

[0003] payment system

[0004] For online shopping, there are various payment options available for ordered goods. Online stores typically require new users to register with their real name and email address. During the shopping process, before the purchase is ultimately accepted by the online store, a mailing address and credit card information will be requested for shipping non-digital goods. For digital goods such as audio or video media, the process is largely the same and does not require a mailing address.

[0005] An alternative to a credit card is various other types of bank accounts. Another alternative is to transfer money to the online store via Bitcoin, a globally accepted virtual currency.

[0006] Established payment systems exist that provide a payment service to both stores and customers, offering advantages over the simplified registration described above. Some services only require a registration process within the payment service itself, and these are generally trusted by customers. These services require an email address to the online store, or even none at all. The store then requests billing from the payment service, based on a mailing address, or even anonymously to the store, and finally provides the online store with its registered shipping address after the customer logs in.

[0007] What these and other payment services have in common is that they require not only a payment agreement before the actual completion of the purchase, but also payment that has already been made. For digital goods, this means that the credit card is debited or the payment service transfers the purchase amount to the online store before the digital data is delivered to the customer. Payment after

[0008] One exception to this basic mechanism is proposed in WO 2011 / 029560 (A2). This patent application describes a payment system and method for one of a plurality of payment procedures. This solution is further described at https: / / www2.laterpay.net and will be further referred to as the LaterPay functionality. These systems and methods are invoked when a buyer makes a purchase of a specific amount in an online store. The system: • Store the buyer's system identification number. • Store the purchase amount related to this identification number. • Monitor the total purchase amount of this buyer's system. • Receive a request from one of the online stores to be responsible for the purchase amount, and • A request to settle at least a portion of the total purchase amount will only be sent to a user of the buyer's system if the total purchase amount exceeds a predefined value and / or after a predefined period has elapsed.

[0009] In short, this patent application describes a system that allows a buyer to make online purchases without first settling the purchase amount using a buyer's system. The payment system accumulates the purchase amount from the buyer's system, and the buyer is only requested to settle the total amount or a portion thereof when the total amount payable exceeds a predefined value. The buyer's system can be a PC, a mobile phone, or the like. These purchases and purchase amounts are stored by the payment system associated with a buyer's system identifier, which does not include the buyer's identity and does not require registration or any other user interaction. In the absence of user login or any other user identification, the system relies on a reliable identifier of the buyer's system, such as a combination of a mobile phone and the browser used. This identification is becoming increasingly difficult because modern operating systems have mechanisms in place to prevent user tracking and therefore user identification. 5G secondary verification technology

[0010] The next-generation mobile communication system, commonly referred to as 5G, offers a wide range of new features. The architecture of the 5G system is described in [3GPP TS 23.501]. A Public Terrestrial Mobile Network (PLMN) based on the 5G architecture includes a core network that provides services to User Equipment (UE) devices and service providers outside the PLMN. These UE devices access the core network via one or more access networks, which can be: a 5G new radio access network, a traditional mobile radio network such as LTE or UMTS, or a wired or wireless LAN access network. UE devices accessing the core network are authenticated based on a shared secret stored in a user database within the PLMN and on the UE device's Subscriber Identity Module (SIM or USIM).

[0011] Recently, a new type of network has been developed, which is also based on a core network and one or more access networks, but it is not a public network (PLMN), but rather a non-public network (NPN) typically serving a specific purpose, such as human-machine communication in a factory. An NPN can apply an authentication mechanism different from that of a PLMN because it can use credentials other than those typically stored on a USIM, such as credentials stored in non-electrical memory. In this invention, we will use the term PLMN for any type of network: public or non-public, and will not consider credentials used for (primary) authentication.

[0012] A new feature of 5G systems is secondary authentication / authorization performed by an AAA server outside the PLMN. This feature allows a service provider outside the PLMN to authenticate and / or authorize a UE device's connection to that service provider's network. To this end, the PLMN has a policy store containing a service provider-specific policy that specifies that a connection to the service provider's network requires secondary authentication and / or authorization. When a UE device requests a connection to the service provider's network from the PLMN, a Communication Management Function (SMF) within the PLMN queries the policy and determines the specific requirements.

[0013] For secondary authentication, the UE device needs to provide authentication information to the SMF, such as a user identifier used with the service provider, i.e., a username, and specific credentials. This can be done in a request from the UE device to connect to the service provider's network. Alternatively, this can be initiated by the SMF after receiving such a connection request from the UE device. The SMF then acts as an EAP authenticator and transmits an EAP request for credentials to be sent subsequently by the UE device. In any case, the UE device provides credentials to the SMF as part of the requested connection setup to the service provider's network. These credentials are then transmitted by the SMF to an AAA server within the service provider's network, which is already known to the SMF. Based on this information, the AAA server verifies the UE device and responds to the SMF with a result. The connection is only established if the authentication is successful. This mechanism has several advantages, one of which is that if a UE device cannot authenticate with the service provider, a connection setup is prevented, thus saving the PLMN's resources and activities in that case.

[0014] If only authorization is required, the UE device can omit any authentication information, and the SMF can provide the AAA server with a Universal Public Subscription Identifier (GPSI), such as a Mobile Station International Subscriber Directory Number (MSISDN) or any other persistent identifier, to identify the user of the UE device. Based on the GPSI, the AAA server of the service provider network will provide authorization information to the SMF, that is, whether the UE device should be allowed to establish the requested connection and further attributes of the connection, such as QoS information.

[0015] Any combination of the above authentication and authorization can be used. The UE device can provide authentication information, and the SMF can transmit this information along with an additional GPSI to the AAA server. The determination of whether to allow the UE device to access the services provided by the provider can be based on the GPSI, a UE device user identification and / or a password or credential or similar. Details of the secondary authentication are described in [3GPP TS 23.501 §5.6.6].

[0016] The Extensible Authentication Protocol (EAP) mentioned is specified in IETF RFC 3748, which defines some messages and message exchanges used throughout the disclosure of this invention.

[0017] It is known that website-based payment systems are responsible for paid content based on user verification involving user interaction and registration, or on an automated and unreliable buyer identification system.

[0018] Prior art lacked a payment system that could reliably identify a device user without any user interaction or pre-registration, and allowed a user to purchase and consume digital content with minimal user interaction, while ensuring that the cost of the content was reliably covered.

[0019] This invention utilizes a modified two-factor authentication. The two-factor authentication / authorization defined in the 5G system architecture is enhanced, enabling it to work with a payment service provider network to establish a payment system that overcomes the shortcomings of the prior art.

[0020] WO 2018 / 137873 (A1) describes a user equipment apparatus that receives an EAP request from an SMF for secondary authentication of the UE apparatus. The UE apparatus responds with an EAP response. The secondary authentication is not only a primary authentication but also an authentication of the UE apparatus. This patent application describes at most the basic mechanism currently specified for 5G secondary authentication. Brief description

[0021] The objective of this invention is achieved by the objectives of claims 1, 13, 14, and 15. Specifically, the deficiency is overcome by a method for providing paid access to online content, the method comprising: a) A user device sends a signal requesting online content from a content provider, preferably from a website server of that content provider; b) The user equipment receives a response signal having an address of a payment system; c) The user equipment sends a first communication period request signal, preferably a PDU communication period setting request signal, to request a communication period with the payment system, preferably a PDU communication period. d) A policy function unit, preferably a policy control function unit of a public terrestrial mobile network of the user equipment, determines an address of an authentication server based on the address of the payment system. The authentication server is preferably a two-factor authentication server and / or an AAA server, preferably located remotely from the public terrestrial mobile network. e) A core network management function unit determines a persistent ID of the user equipment and provides the persistent ID to the authentication server in a second communication period request signal, preferably in an SMF / AAA communication period request signal; f) The verification server determines the authenticity of the user's device using the persistent ID; g) The payment system, based on the persistent ID, determines the payment status of the user's device for the online content; and h) Based on the payment status, preferably through a first communication period established in response to the first communication period request signal, enable at least one user option on the user device for the online content, preferably at least one option to obtain access to the online content, to pay for the online content, and / or to donate to the content provider.

[0022] Advantages include improved reliability of content payment verification without requiring prior registration with the payment system.

[0023] In one embodiment, step b) further includes the user device receiving a security token from one of the content providers / the website server; wherein step e) further includes providing the security token to the verification server as a credential for secondary verification; and wherein step f) includes using the security token to verify the content provider and / or the website server by the verification server.

[0024] In one embodiment, step b) includes the user device receiving an instruction file embedded in a webpage from one of the content providers / the website server. The instruction file includes an identification of one of the online contents and an instruction to set a first communication period with the address of the payment system. The user device connected to one of the 5G core networks / the public terrestrial mobile network is connected to the website server via the public terrestrial mobile network. When the instruction file is executed on the user device, information and further executable code are downloaded from the payment server of one of the payment systems.

[0025] In one embodiment, the instruction file contains information for accessing the online content, which is only presented on the user's device when the payment system determines that the online content has been purchased; otherwise, a purchase option is presented on the user's device. Furthermore, when the webpage of the content provider including the code is displayed, the user's device immediately or after user interaction establishes a connection to one of the payment systems for downloading the information and the further code.

[0026] In one embodiment, the user device receives a website communication identifier embedded in a webpage from one of the content providers / website servers, and some downloaded information, such as content providing access to paid content, is not immediately presented to the user.

[0027] In one embodiment, the public terrestrial mobile network is aware of the payment system, such as through a service level agreement between one operator of the public terrestrial mobile network and one operator of the payment system; and the 5G core network has a policy storage database attached to the policy function unit, which stores one or more policies related to the payment system.

[0028] In one embodiment, step g) includes the payment system determining, based on the persistent ID and one of the IDs of the online content, whether the user device has paid for the online content, and: if yes, providing the user device with access to the online content; if no, providing at least one payment option for the online content.

[0029] In one embodiment, in response to successful verification in step f), the method further includes: assigning an IP address to the user equipment for access to the payment system; providing the payment system with the IP address of the user equipment; and storing, by the payment system, a mapping between the IP address of the user equipment and the persistent ID; and wherein step g) further includes determining the persistent ID based on the IP address of the user equipment and the stored mapping.

[0030] In one embodiment, the persistent ID is a general public subscription identifier, preferably a mobile station international user directory number.

[0031] In one embodiment, the method further includes: in response to successful payment for the online content, the payment system stores a token or identifier indicating that a purchase has been completed in the user device; wherein in step a), the user device provides the token or identifier to the content provider; wherein the content provider uses the token or identifier to request authorization for the requested online content from the payment system; and wherein, in response to successful authorization, the content provider allows the user device to access the online content.

[0032] In one embodiment, the user device does not require further registration and / or credentials to access content.

[0033] In one embodiment, step g) further includes determining one of the user device's accounts based on the persistent ID; and step h) further includes monitoring the total outstanding debts of the user device's account, and requesting settlement of at least a portion of the total outstanding debts after a predetermined period and / or when the total outstanding debts exceed a predetermined value.

[0034] The objective is further achieved by a system comprising: a user device connected to a public terrestrial mobile network including a policy function unit and a core network management function unit; a content provider including a server such as a website server; and a payment system including an authentication server, such as an AAA server and / or a two-factor authentication server; wherein the system is configured to perform the methods described herein.

[0035] The objective is further achieved by means of a computer program containing instructions that cause a system such as the above-described system to perform the steps of the methods described herein.

[0036] The objective is to be achieved further by means of a computer-readable medium on which one of the aforementioned computer programs is stored. Simple Explanation of the Diagram

[0037] In the following description, embodiments of the present invention are illustrated with reference to the drawings, wherein: Figure 1 shows one of the systems in this application; Figures 2 and 3 illustrate a message sequence diagram showing the exchanged messages; Figures 4 to 6 show the user display of a user device of one of the present applications; Figures 7 and 8 illustrate a message sequence diagram showing the exchanged messages; Figure 9 shows the steps of an embodiment of the method described herein; Figure 10 illustrates the steps of the method in this application.

[0038] Starting with Figure 9, in a first step 901, code embedded in the content provider's webpage and downloaded to the UE device triggers a connection setup by the UE device to a server of the payment system to download information and / or executable code (also see Figures 2, 212, 214, and 220). This connection setup triggers a communication period establishment request to establish a Packet Data Unit (PDU) communication period between the UE devices, via the core network to an edge router of the core network, a so-called User Plane Function (UPF), which ultimately connects the UE device to a data network providing connectivity to the payment system. The PDU communication period establishment request is transmitted by the UE device to the core network, where a Communication Period Management Function (SMF) is triggered to set up the connection (also see Figures 2, 222 and 224).

[0039] The PDU communication period establishment request may include a website communication period identity and a security token. The SMF receives a publicly known user identity (GPSI) from a user database of the PLMN. The SMF receives information from the PCF requesting that the SMF perform two-factor authentication and / or authorization with an AAA server of the payment system before the requested connection can be established (see also Figure 2, 226). If certain policies require two-factor authentication, and the PDU communication period establishment request received from the UE device does not contain authentication credentials, such as a website communication period identity and a security token or similar information, the SMF may act as an EAP authenticator and transmit an EAP request to the UE device requesting these credentials. The UE device may then respond with an EAP response providing credentials such as a website communication period identity and the security token.

[0040] In a second step 902, the SMF transmits a request for verification and / or authorization to one of the AAA servers of the payment system, including the received GPSI (see also 228 of Figure 2). If the SMF receives the website communication period identity and / or the security token from the UE device, the SMF may additionally include these.

[0041] In a third step 903, the payment system receives the request for verification and / or authorization, and determines an account in one of the payment system's databases based on the received GPSI (see also 230 and 240 in Figure 2). If an account cannot be determined from the database, a new account is created. If the request includes a website communication period identity, the website communication period identity is stored by the payment system to associate the website communication period between the UE device and the content provider's website server with the determined or newly created account. If a security tag is embedded in the request, it can be used by the payment system to verify the content provider.

[0042] It should be understood that using the credentials provided by the UE device does not identify or verify the UE device, but rather the content provider and / or the website communication period between the UE device and the content provider. This is an enhancement of the current two-factor authentication.

[0043] In a fourth step 904, the payment system sends a response to the request for verification and / or authorization to the SMF, which includes an indication that the user has been verified and / or authorized to access the payment system (see also Figure 2, 242).

[0044] In a fifth step 905, the SMF establishes the PDU communication period upon request (see also Figure 2, 250). As part of the normal PDU communication period establishment, the PLMN assigns an IP address or IP header to the UE device for communication with the data network during the PDU communication period. The AAA server in the payment system can be notified of the new IP address or IP header by the SMF, and the AAA server stores the address associated with the GPSI or the determined or newly created account (see also Figures 2, 252 and 254). Now, the UE device can connect to the payment system via the newly established connection and request information and / or executable code for download and execution (see also Figure 3, 302). The payment system can identify any request or communication from the UE device by using the source IP address or IP prefix of the UE device, which is obtained from the SMF receiver by the AAA server, and associate the communication with a previously determined or newly created account based on the received GPSI. The request information and / or executable code may contain an identifier of payment content.

[0045] In a sixth step 906, the payment system determines information and / or code specific to the associated account and transmits this information and / or code as a response to the request for request information and / or executable code. In this step, "specific" means that the functionality, number, and appearance of the text elements and control elements transmitted to the UE device can be adapted to display information that is part of the account data, or that the control elements are presented only when applicable to the current state of the account. The payment system can, for example, determine from the account information whether the paid content should be accessible to the user because it has been purchased, or whether the option to purchase the content should be provided to the user (see also Figures 310, 320, 322, 330, 340, and 342).

[0046] In a seventh step 907, the UE device presents the user with information specific to the user's associated account and / or one or more control elements in the manner described above. Access to paid content may be provided, for example, if the paid content has been purchased based on account information. In that case, code demonstrating control elements for accessing the content (e.g., a play, read, or download button) may be transmitted to the UE device. Otherwise, code demonstrating control elements for purchasing the content using account-dependent purchase options may be transmitted to the UE device (see also Figure 3, 344). The purchase control elements may include: • An account balance associated with that user's account, • A control element for purchasing digital content by paying an amount through the payment system without immediately settling the account balance; • A control element for immediately settling at least a portion of the account balance by paying an amount through the payment system to purchase digital content; • A control element used to purchase digital content through the payment system by confirming that the payment system allows the submission of the user's personal information stored in one of the payment system's databases to a third party; • A control element for inputting the user's personal information and transmitting the personal data to the payment system for storage, and for purchasing digital content through the payment system by confirming that the payment system allows the user's personal information to be submitted to a third party; • A control element used to purchase digital content via one or more other systems, and then via the payment system.

[0047] Depending on the presented control element, the user of the UE device can select and activate one or more control elements to purchase digital content based on the purchase method associated with that control element (see also Figure 3, 346). Potentially, after the user confirms the selected purchase method, the activated control element can trigger the transmission of control information via a connection to the payment system, which notifies the payment system about the activated control (see also Figure 3, 348).

[0048] The payment system will then process the payment according to the selected purchase method, that is, add the amount to the account's total payable, settle the account (partially), or settle the purchase or a portion of the account for the right to send the personal information to a third party (see also Figure 3, 350). The payment system will then transmit code to the UE device providing the UE device with access to the paid content. This can be accomplished by redirecting the UE device's browser to the content provider's webpage, which essentially results in the reloading of the webpage and the restart of the process of using the payment system; this time, it is determined that the content has been purchased and that the content should be immediately accessible to the user (see also Figure 3, 352).

[0049] The website communication period identifier can be any kind of information associated with the following by the UE device: the content provider, the content provider's website service, or the connection between the UE device and the content provider's website server, for example, an address used by the UE device or the website server. The website communication period identifier can be received from the content provider's website server as a cookie or as information embedded in a command file related to the payment system, or can be determined by the UE device in any other way. In a preferred embodiment, the website communication period identifier can be an identifier of paid content that the user of the UE device can access or purchase. The website communication period identifier can then identify specific content provided to the user via the content provider's website server. This content is the subject of a purchase activity enabled by the present invention.

[0050] The security token can be any type of token, generated by the content provider (e.g., related to website communication period identification) based on a cryptographic algorithm and transmitted to the UE device to verify the website communication period with the payment system. Alternatively, the security token can be information generated by the payment system, provided to the content provider and transmitted to the UE device.

[0051] The innovative steps of the above method are mainly implemented by the payment system, which are explained below for better understanding of the method: A payment system that provides executable code and / or information for a UE device to download via a PLMN comprising a 5G core network, the payment system: • A request is received from the 5G core network to verify a connection between a user of the PLMN or to authorize a connection between the user's UE device and the payment system. This request includes: The UE device has an identifier for the user. A website communication period identification (optional), and A safety mark (optional) • Based on the user's identification in the UE device, an account stored in a database of the payment system is determined. If no account can be identified, a new account is created and associated with the user's identifier on the UE device. • Transmit confirmation of the user's authentication and / or authorization of the connection to the 5G core network. • Receive, from the 5G core network, an address (optional) associated with the connection between the user's UE device and the payment system. • A request to download executable code and / or information from the UE device via the connection, the request including identification of one type of paid content. • This connection is identified by the payment system based on this address information (optional). • Determine whether based on an account that has been identified or newly created: The paid content identified in the request should be accessible to the user. In this case, the payment system determines that the UE device should display information and / or executable code for accessing the paid content's control elements. The paid content needs to be purchased before it can be accessed by the user. In this case, the payment system determines account-specific information and / or executable code. ■ This information includes account-specific text or numbers of the user to be presented to the UE device, and / or ■ The executable code contains instructions for purchasing one or more control elements, where each control element represents an account-dependent purchase method. • And transmit the determined information and / or executable code to the UE device via the connection.

[0052] Furthermore, the payment system performs one or more of the following: • Through this connection, information regarding a selected purchase method is received from the UE device, or an activation control element indicates a selected purchase method, and based on the account and according to the selected method, a purchase is made, causing the UE device to demonstrate access to the paid content. • Identify the content provider who is at least partially associated with the purchase from the website's communications period. • Receive a security token from the SMF in the request to verify a connection between a user of the PLMN and / or an authorized UE device and the payment system, and verify the content provider associated with the request based on the token, at least a portion of the website communication period identification, and a cryptographic algorithm. • The UE device is identified from the website communication period identification and associated with the account, which is determined based on the identification of the user of the UE device received from the 5G core network. • Identify the UE device from the website communication period identification, determine an account-based website communication period identification, and associate this account with the identification of the user of the UE device received from the 5G core network (if the website communication period ID and 5G user ID of each of the two accounts determine an account, it may result in one of the two accounts being merged).

[0053] In a request to establish a PDU communication period, the UE device may send the website communication period identification and / or the security tag to the SMF, for example, as part of a message predicting the username and password, or as a container of authentication information passed to the SMF in the PDU communication period establishment message.

[0054] In all cases, the 5G core network subscriber identity (GPSI) is not generated or sent by the UE device. Instead, it is stored in a subscriber database, provided to the SMF, and sent from the SMF to the AAA server, so that the GPSI is trusted to identify one of the users of the PLMN provided by the payment system.

[0055] Figure 10 illustrates the steps of a method for providing paid access to online content according to the present invention, the method comprising: step 1001, a user device 101 sending a signal requesting online content from a content provider 120, preferably from a website server 121 of the content provider 120; step 1002, the user device 101 receiving a response signal having an address of a payment system 130; step 1003, the user device sending a first communication period request signal, preferably a PDU communication period setting request signal, requesting a communication period with the payment system 130, preferably a PDU communication period; step 1004, a policy function unit 117, preferably a policy control function unit of a public terrestrial mobile network 110 of the user device 101, determining an address of an authentication server 131 based on the address of the payment system 130, the authentication server preferably being a secondary authentication server and / or an AAA server, preferably located remotely. Public terrestrial mobile network 110; Step 1005, a core network management function unit 140 determines a persistent ID of user equipment 101 and provides the persistent ID to the verification server 131 in a second communication period request signal 228, the second communication period request signal being preferably an SMF / AAA communication period request signal; Step 1006, the verification server 131 determines the authenticity of user equipment 101 using the persistent ID; Step 1007, the payment system 130 determines a payment status of user equipment 101 for the online content based on the persistent ID; and Step 1008, based on the payment status, preferably through a first communication period established in response to the first communication period request signal, at least one user option for the online content is enabled on user equipment 101, preferably at least one option being access to the online content, payment for the online content, and / or donation to the content provider 120. Implementation

[0056] Figure 1 shows an architecture with a UE device (UE) 101 and three networks: a PLMN 110, a content provider network 120 and a payment system network 130.

[0057] UE device 101 is connected to PLMN 110 via an access network (AN) 111. This access network can be a 5G new radio network, an LTE network, a WLAN access network, or any other access network providing access to the PLMN's core network. The core network includes: • An Access and Mobility Function (AMF) 112 controls and manages the UE device. • A Communication Management Function (SMF) 113, which controls the setting, maintenance, and release of PDU communication periods. • A User Plane Function (UPF) 114, which is a router for arranging data routing between the access network and one or more data networks in the core network, is controlled by the SMF 113. • A database (DB) 119 that provides user-specific information, database network-specific policies, and other information. • A Policy Control Function (PCF) 117, connected to a Policy Database (PDB), provides rules and parameters, i.e., policies, to the AMF and SMF; and • Data networks (data networks 1:115 and data networks 2:116) are essentially the exit points of the core network to different external networks, in this example to a network containing a content provider and to a network containing a payment system.

[0058] The entities mentioned above can appear multiple times in a core network; for example, there can be multiple AMFs. However, each UE device typically selects a single AMF, and even a single UE device can have multiple SMFs and UPFs, for example, for different PDU communication periods. Figure 1 shows only one representation of each network element for readability.

[0059] A first data network (data network 1) 115 can connect a UE device 101 to a content provider network 120 that includes a content provider website server 121 and a media storage library (media) 122. The content provider offers a freely accessible webpage that provides information about content being provided. In this example, the content could be streaming music provided by the content provider. The UE device 101, connected to the content provider website server 121 via a PLMN 110, will first configure a PDU communication period with the core network of the PLMN to connect to the content provider website server. During this PDU communication period setup, the UE device will receive a first IP address, which may be specific to the data network and will be used by the UE device 101 when connecting to the content provider website server.

[0060] When a user of UE device 101 selects content to stream from content provided by the website server, a purchase mechanism according to the present invention will be implemented, which will charge for the content, and the website server will stream the purchased content from its media library, resulting in a fee. Clearly, the present invention supports similar setups, for example, where the media library is not necessarily part of the same network as the content provider website server, and the media can be streamed by another entity, not shown in Figure 1, different from the website server. The content can be any kind of digital media, such as music, audio (podcast), video, movie, text, images, or a combination thereof.

[0061] The second data network (data network 2) can connect a UE device to a payment system comprising a server, such as a website server, an information and command file server, an AAA server, and an account database (DB). The payment system may or may not be freely accessible, but when accessed via PLMN 110, an authorized connection is required, and the user connecting to the content provider may need to be authenticated. Similarly, to connect to the payment system via PLMN 110, the UE device 101 will configure a PDU communication period with data network 2 116 and receive a second IP address that may be different from the first IP address.

[0062] For primary and secondary authentication between PLMN 110 (specifically, one of the PLMNs, SMF 113) and the AAA server 131 of the payment system, the SMF and the AAA server establish a connection, which is maintained as long as the UE device still has a connection to the payment system server. This connection between SMF 113 and the AAA server 131 is shown as a dashed line because, logically, this direct connection may actually be established through the UPF and data network 2, and is omitted in Figure 1 for better readability.

[0063] Figure 2 illustrates a message sequence diagram showing the messages exchanged between the entities shown in Figure 1, namely: UE device (UE) 101; PLMN 110, which includes an access network (AN) 111; core network management functions (AMF 112 and SMF 113 in Figure 1, collectively referred to as CNMF 140 in Figure 2); a policy control function (PCF) 117, which includes a policy database (PDB) 118; a user plane function (UPF) 114 and two data networks (DN 1 115 and DN 2 116); a content provider (CP) network 120, which is not shown in detail in Figure 2; and a payment system (PS) 130, which has a payment server 133 and an AAA server 131 with an account database 132.

[0064] In a first embodiment of the present invention, the UE device may register in PLMN 110 (step 210) based on the fact that one of the main verifications of the credentials stored on one of the USIMs of the UE device has been performed, and a website communication period has been established between the UE device 101 and the content provider 120, that is, a PDU communication period has been established between the UE device 101 and DN 1115.

[0065] The UE device requests webpage or website content from the content provider, typically in an HTTP request 212, which includes a resource locator for the requested content. As part of an HTTP response 214 containing the webpage, a command file is downloaded, containing a link to or source information for a payment system. When executed on a mobile device, the command file loads further information, text, and / or executable code from a payment system server referenced by the link or source information. In the command file, or as part of the downloaded webpage content, the UE device receives a content identity (content ID) and a security tag for the media content that the user of the UE device is attempting to stream.

[0066] The content ID can be constructed, for example, from known address information, such as the IP address of either the content provider website server 121 or the UE device 101, or a URL of a content resource on the content provider network. The content ID can also identify more than one piece of content; for example, it can identify the content provider as a whole. Alternatively, it can be a random number generated by the content provider website server that identifies the content. In this example, the content ID could be a URL that provides access to the content on a content provider server.

[0067] In this example, the security token could be a cryptographic signature of one of the content IDs, calculated using one of the content provider's private keys. This security token could be used by the UE device to verify the content provider based on a publicly available key, for example, as part of a credential for additional downloads. In this embodiment, the security token would be used by the payment system in a later step to verify the content provider and / or the content.

[0068] When the downloaded webpage content is displayed, the command file is executed, and a link or source information in the command file triggers a connection setup for the payment system. This could be caused by a browser application triggering the modem of the UE device 101 to set up a new connection to the linked address via the API of the UE device 101's operating system (OS), providing the content ID and security token for the request. Alternatively, the code in the command file could contain information triggering the delivery of the content ID and security token. Alternatively, the browser application determines that these two parameters need to be delivered to the connection setup. The modem in the UE device then determines (step 220) that a new connection needs to be set up, requiring a new PDU communication period, which is targeted to the address of the payment system provided by the link information in the command file. The UE device, namely the cellular modem in the UE device, will transmit a PDU communication period setting request message 222 to the core network management function unit (CNMF) 140 via AN 111, which includes the content ID and the security tag.

[0069] One innovative aspect of this invention is that the UE device uses a content ID and a security token as authentication credentials provided to CNMF 140, because these parameters differ from those currently anticipated by the user. Currently known 5G two-factor authentication requires the UE device to provide credentials to a service provider, which identifies and verifies the user or the UE device. However, the content ID does not identify the UE device, and the security token does not verify the UE device in the payment system. Therefore, one innovative step in this invention is to base the authentication of the UE device 101 in the payment system 130 on GPSI received from the 5G core network, and to use the transmission of credentials in the two-factor authentication to identify the content provider, the website communication period of the content provider, or the paid content of the content provider, and to verify the content provider, the website communication period, or the content in the payment system.

[0070] When the message is received by SMF 113 (which is part of CNMF 140 in Figure 2), it determines the policy related to the target of the PDU communication period to be set. This target is given by the address of the payment system in the PDU communication period setting request from UE device 101. The PCF or another entity in the core network may have already provided the SMF with the policy related to the PDU communication period to be set; that is, the SMF can be configured to have a list of the target address and related policies. In an alternative example, AMF 112, which is another part of CNMF 140 in Figure 2, can be configured to have this list and notify the SMF of the policy regarding the PDU communication period currently to be set. In this embodiment, when the PDU communication period setting request is received, the SMF requests (step 224) the policy regarding the PDU communication period to be set from the PCF.

[0071] In an alternative embodiment, the UE device or its cellular modem requests a PDU communication period from the CNMF without providing the Content ID or the security token. In this alternative, after the SMF determines from a policy that secondary authentication is required before establishing a connection to the payment system, the SMF acts as an EAP verifier as described in the EAP specification and sends an EAP request to the UE device requesting missing credentials for verification of the UE device within the payment system. The UE device then provides these credentials in an EAP response. The method of this alternative embodiment is otherwise identical to the described method. These credentials, as described above, can be used to identify the content provider, rather than the UE device.

[0072] In yet another alternative embodiment, the UE device or its cellular modem requests a PDU communication period from the CNMF without providing the Content ID or the Security Mark, and the SMF determines from a policy that secondary authorization is required but not verification before connection to the payment system can be established. This results in the SMF not providing any authentication credentials to the AAA server, but only the GPSI.

[0073] PCF 117 will now look up and determine the relevant policy in its policy store (database 118). Assume that the operator of payment system 130 and the operator of PLMN 110 have a service level agreement, and that the PLMN has stored policies related to the PDU communication period targeting the payment system. One rule of such a policy could be: for the PDU communication period targeting the payment system, secondary authentication / authorization must be successfully performed before the PDU communication period can be set. The PCF will provide policy 226 to the SMF (CNMF), which includes the address of the AAA server of the payment system to which authentication / authorization must be performed.

[0074] The SMF will now request authentication and / or authorization from the AAA server specified in the policy. The SMF establishes a communication period with the AAA server, which is considered complete by sending an SMF / AAA communication period request message 228 to the AAA server. This message may include a request for authentication or authorization including a Globally Common User Identity (GPSI), the Content ID, and a security token. The GPSI may be an MSISDN or a similar identity for the user of the UE device. Alternatively, the GPSI may be a Target Specific User Identifier, i.e., a unique ID generated by the PLMN for each target network for the user, which the PLMN provides to the target network. This allows the target network to identify and recognize the user without receiving a globally unique number that allows tracking across multiple services. The unique ID may be a cryptographic hash of the GPSI and a target network ID, preferably a secret number large enough to prevent brute-force attacks.

[0075] The AAA server 131 in payment system 130 can first verify (step 230) the content provider to ensure that the connection requested and authorized by the SMF is configured to communicate with the website of the correct content provider. This can be done by verifying the signature of the content ID provided by the security token using a known (i.e., stored) credential or public key of one of the content providers.

[0076] After the website communication period between the content provider and therefore the UE device and the website server is verified, the AAA server of the payment system queries the GPSI in its database to determine an account 240 associated with the GPSI. If this account is found, it is associated with the connection to the SMF. If this account is not found, a new account is created, stored in the database, and associated with the GPSI and the connection to the SMF. The payment system AAA server 131 then sends an SMF / AAA communication period acceptance message 242 to the SMF to determine the user's authentication and / or the authorization of the connection. The AAA server may include the GPSI in the message to ensure that the SMF associates the message with the correct PDU communication period setup procedure. Obviously, in other embodiments, the communication period request and acceptance, as well as the authentication / authorization, may be performed in separate messages.

[0077] The core network then completes the PDU communication period setup and assigns an appropriate IP address to the PDU communication period to be used by the UE device 250. Further, it informs the AAA server of the payment system about the newly assigned IP address in an SMF / AAA communication period modification message 252, and the AAA server stores this address so that all communications to and from this address are associated with the determined or newly created account. A message can optionally be sent by the AAA server to the SMF to confirm the modification; this option is indicated by a dashed line 254 in Figure 2.

[0078] The SMF will now notify the UE device of the completed and accepted PDU communication period setup and associated IP address 256. This information may be sent to the UE device before or during the notification of the new IP address by the AAA server, or alternatively as part of the PDU communication period setup. Generally, the steps of the method do not necessarily need to be performed in the stated order; rather, any order that results in the same basic functionality will be one embodiment of the innovative method.

[0079] The message sequence diagram in Figure 2 continues in Figure 3. The UE device is now configured with a PDU communication period for connecting to the payment system, and therefore the UE device requests (step 302) information or executable code linked from the instruction file from the content provider website server from the payment system. This request is sent by the UE device in one or more messages, each potentially executed in mutual message exchange, wherein only one message is shown in Figure 3, the request using a newly established PDU communication period via the PLMN and a newly assigned IP address, which is associated with a determined or newly created account in the payment system. The request sent by the UE device may contain the content ID, especially in the other alternative embodiments described above where the content ID is not delivered by the SMF as part of the verification information to the AAA server. The request may also contain another content identifier, which differs from the various alternatives described above regarding the content ID.

[0080] The payment system will now determine (step 310) whether the user has access to the paid content from the account information. This is based on content identification, such as the content ID, and information stored as part of the account information in a database of the payment system. If the UE has access (state 320), the payment system will determine the information 322 to be transmitted to the UE device, which demonstrates the control elements for accessing the content; otherwise (state 330), it will determine (step 340) the account-specific information and code 342 to be transmitted to the UE device, which demonstrates (step 344) the purchase options as a response to the request.

[0081] We now turn to the description of Figures 4 and 5, which show a sketch of the user interface of two UE devices, UE 1 and UE 2. Figures 4 and 5 show an example of user device 101 in condition 330 without immediate access rights. These devices have an existing browser communication with a content provider, displaying a webpage as shown in the diagram. They show a music album on the screen, with the album art on the left, some metadata on the right, and a song list at the bottom. At the bottom of the webpage, two buttons are presented for two different purchase options. This bottom of the webpage is provided from the payment system rather than from the content provider, i.e., within an HTML iframe of the content provider's webpage.

[0082] These buttons differ for the two devices. UE 1 offers the option to purchase the album for 99 cents, including advertisements such as those between songs in the album, without immediate payment, displaying information that the total amount due is USD 1.98. Alternatively, the album is offered for USD 1.99 without advertisements and without immediate payment. Both options may involve the LaterPay functionality for deferred payment as described above. In another alternative, a purchase is offered to allow the payment system to provide personal information to a sponsor who pays for the purchase in return. This example may not include the LaterPay functionality. UE 2 offers the option to purchase at the same price, but requires immediate settlement of one-third of the total amount due because it exceeds a preset threshold (in this example, the total amount due is USD 5.73). The alternative purchase method for UE 2 is similar to that offered to users of UE 1, but with a different, UE-specific sponsor. The sponsor can be determined by the payment system based on account information, such as past purchases, payment methods, age, gender, or other personal information of the user on individual UE devices.

[0083] Figures 4 and 5 illustrate the results of the invention, which allow different UE devices connected to the same website service to be offered different purchase options via the PLMN based on a reliable identifier. The different purchase options are assumed to be implemented via different control buttons. These control buttons shown on each UE device are the result of executing run codes and demonstrating information received from the payment system. Figure 6 shows a third UE device, UE 3, which accesses the same webpage but receives direct access to the music album via separate buttons at the bottom, as it has previously purchased the content. This display can also be shown on UE 1 and UE 2 after the purchase is completed.

[0084] Switching back to Figure 3, based on the account information, the account-specific information determined by the payment system, and the code, including their respective titles and associated purchase methods, the number of control buttons is determined. After this determination, the code is provided to the UE device via the connection for demonstration, as part of the webpage displayed to the user. The demonstration of the code received by the UE device will result in the respective outcomes of the three example UE devices shown in Figures 4, 5, and 6.

[0085] When the user selects (step 346) one of the methods for purchasing the album, the user interacts with the individual control buttons, triggering a message 348 from the UE device to the payment system, which then performs payment according to the selected method (step 350). This process is not shown in detail in Figure 3 and will not be described herein; it may include pricing the purchase price based on the account balance, settling the balance, and / or requesting personal information from the user and providing that information to a third party. In any case, information regarding the purchase of the content associated with a content identifier is stored in the account in the database 132 of the payment system 130 to provide direct access to the content later. If the content provider has an associated LaterPay account, the amount can also be credited to the content provider's LaterPay account.

[0086] After payment is made, the UE device is granted access to the content. This can be done in several ways. One way is to redirect the UE device's browser to the content provider's webpage, which will then reload. In this case, the repeated check of the content ID for the account information will result in immediate access to the paid content (situation 320), as shown in UE 3 in Figure 6.

[0087] In an alternative embodiment not shown in the figures, after payment is made, the payment system provides the UE device with a replacement for the code and information previously transmitted to the UE device. For example, the provided control buttons are changed to: text elements confirming the purchase of the content and providing a new balance in the account, and / or control elements for playing the newly purchased content.

[0088] In an alternative embodiment, a website communication period identifier is transmitted from the content provider to the UE device in the information of the webpage (e.g., in the downloaded instruction file), and the website communication period identifier is used by the UE device to replace the content ID in the PDU communication period establishment request, and is used by the SMF in the request to verify the connection to the AAA server of the payment system. The payment system can use the identification of the website communication period rather than specific content to verify the content provider and ensure that the billing and purchase are for genuine content and that the user is not accessing a fake webpage. In some embodiments, a direct connection between the payment system and the content provider system is anticipated, and the website communication period identifier received from the UE device can be used by the payment system as a reference for communication with the content provider.

[0089] In one embodiment of the invention, a user accesses a social media platform via their UE device and a PLMN. An artist can provide information and / or content for the user to view, stream, or download. The social media platform can enable a contribution button on the website for artists who provide content for free. Users are provided with these buttons to make small donations to artists if they like their content.

[0090] This embodiment uses a similar setup and method as explained with respect to one of Figures 1 to 3, and is now explained with reference to the same figures, mainly illustrating the differences from the previous embodiment.

[0091] The UE registers in a PLMN that includes a 5G core network with one of the elements shown in Figure 1. The UE accesses a content provider network, which is currently a social media platform, via a first data network. The UE later accesses the payment system network via a second data network. The UE downloads the webpage content from the content provider, including a command file directing the user to the payment system and triggering a connection thereto. A PDU communication establishment request is sent by the UE to the 5G core network, which now includes an identifier of one of the social media platforms, or an identifier of one of the artists, or both, as the content ID. This security tag verifies the social media platform.

[0092] One of the policies in the core network will trigger the SMF to request verification and / or authorization from the AAA server of the payment system, based on a GPSI, and optionally taking into account the content ID and the security tag. The payment system will determine an account or create a new account and confirm the connection settings. The payment system will receive the IP address of the UE device to associate it with the account. The UE device will connect to the payment system via the newly established connection and request additional information and / or executable code.

[0093] The payment system then determines whether a donation can be made without immediate payment, and the amount of the amount owed, based on the total amount due in one of the accounts. The payment system then generates code and information to be transferred to the UE device for demonstrating control that offers a donation option without immediate payment. The payment system may additionally or alternatively generate code for demonstrating control that offers donation options combining the current amount due or a portion thereof. The payment system may additionally or alternatively generate code to present the user with information about the total amount the user has donated to the artist. This code and information are transmitted to the UE device and demonstrated, allowing the user to activate their selected donation button. In this embodiment, the payment system does not need to make a choice about whether the user should be given immediate access to the content, but account-specific control is based on the account information identified from the GPSI received from the 5G core network.

[0094] The user's selection and activation of one of the control buttons will cause the payment system to: execute a donation including a potential settlement, and redirect the browser back to the social media platform to reload the webpage and refresh the donation and account information.

[0095] Figures 7 and 8 show a message flow of one further embodiment. This embodiment is again similar to the previous embodiment and uses the same setup as described with reference to Figure 1. The difference between this embodiment and the previous embodiment is that the authorization for content access is performed directly between the content provider and the payment system, and the website content transmitted by the content provider to the UE device is adapted to include a direct content access option or one or more purchase options.

[0096] In this embodiment, a UE device 101 may have a connection to a content provider website server 120 via a PLMN (710 in FIG. 7). When the UE device requests website content from the website server, for example via an HTTP request 712, it includes a tag in the request, which may be contained in a file stored on the UE device, such as a cookie. This tag may have been stored on the UE device as a cookie during a previous website communication between the UE device and the payment system, and the tag identifies the user of the UE device. The content provider's website server therefore receives a user identification, which includes the website content requested by the device, before it sends an HTTP response to the UE device.

[0097] The content provider's website server then sends a request to the payment system AAA server 131, requesting authorization (step 714) for the content provided by the user identified by the identifier on the content provider's webpage. The payment system's AAA server determines an account based on the identifier and further determines whether the access to the identified content in the request has been previously purchased by the user (step 720). If purchased, the payment system authorizes access to the content by replying to the content provider with information indicating that the content should be accessible to the user. In that case, the content provider's website server can adapt the website content transmitted to the UE device to include components for accessing the content, such as a download, play, or read button. This is not shown in Figure 7.

[0098] If the payment system has not yet stored an account matching the user identification given by the tag, or determines from one of the identified user's accounts that the content has not yet been purchased, it provides a negative response in the verification response 722 to the content provider. This is illustrated in Figure 7. The content provider's website server then adapts the website content transmitted (step 732) to the UE device to include components for accessing the payment system and purchasing the content, such as a purchase button with one or more purchase options, as described in the previous embodiments. This also applies to the content provider's website server if there is no tag provided by the UE device in the HTTP request, i.e., because no cookie was previously stored or a cookie has been deleted. The content provider then does not request authorization from the payment system and directly adapts the website content with the purchase component.

[0099] When the user actuates the purchase button, it triggers a PDU communication period setting, including one of the two-factor authentication methods as described in the previous embodiment. The UE device sends a PDU communication period establishment request 742 to the core network and includes a tag identifying the UE device from the cookie. This tag may have been stored on the UE device by the payment system during a previous network communication period on another network outside the 5G core network. In that case, the tag is associated by the payment system with an account not yet associated with the user identity, which is provided to the payment system by the 5G core network during the two-factor authentication (GPSI). The transmission of the tag in the request from the UE device to the core network, and from the core network to the AAA server 131 of the payment system, along with a subsequent transmission 748 of the GPSI, thus allows the association of a previous account, which is not yet related to the 5G user identity, with the GPSI. This is an advantage of the present invention, which can also be used in the previous embodiment.

[0100] The payment system will determine (step 760) the account, whether it is associated with the provided GPSI (if it exists) or with an identity based on the provided tag or cookie, and if multiple accounts are found, they will be merged. If no account is found, a new account will be created. The payment system will verify and / or authorize the connection to the UE device, and the core network will complete (step 810) the PDU communication setup, and it may notify (step 812) the payment system about the newly assigned IP address (now continuing in Figure 8).

[0101] The UE device can now request (step 818) account-specific code and / or purchase options information, which is then presented to the user (step 830), similar to the previous embodiment, but there is no direct access option provided by the browser at this stage of the process, because this option was eliminated by the content provider website server during the initial webpage request.

[0102] All embodiments described herein illustrate how to use a browser on a UE device to access a website server on a content provider or social media platform. It should be understood that these embodiments essentially operate the same as or very similarly to a native application on the UE device accessing an application server on the content provider or social media platform. A redirect to the original webpage to refresh the presented information may then be replaced by a similar application-specific trigger to re-demonstrate the shown content, but the innovative steps remain essentially the same.

[0103] To further enhance security, an encrypted secret may be generated by the content provider. The payment system may have a key to decrypt this secret as proof of purchase. The user device may not have this key. The encrypted secret may be a random number. The encrypted secret may be encrypted using a symmetric key known to both the content provider and the payment system. The encrypted secret may also be encrypted using a public key of the payment system, for example, using credentials. The encrypted secret may be decrypted by the payment system, and may only be made available to the user device after the payment process is completed. The payment process may include an option to pay for the content later, or allow a third party to pay for the content, for example, as a reward for sharing information. The user device may provide the decrypted secret to the content provider as proof of payment or option for access to paid content. The user device may only be allowed access to the content when the successfully decrypted secret is provided to the content provider. The encrypted secret may be valid for a limited period of time. In this case, when the time limit expires, the user device may be redirected to the payment system to decrypt a new secret for the same content. The content provider can track the secret and the corresponding content access. The encrypted secret may be part of a security token or separate from it. The decrypted secret may be provided to the user's device along with the code that accesses the requested content.

[0104] 1,2,3:UE 101: User Equipment (UE), UE device 110: Public Land Mobile Network (PLMN) 111: Access Network (AN) 112: Mobility Functions (AMF), Access and Mobility Management Functions 113: Communication Management Function (SMF) 114: User Plane Function Unit (UPF) 115: Data Network 1 (DN 1) 116: Data Network 2 (DN 2) 117: Policy Function Department, Policy Control Function Department (PCF) 118: Policy Database (PDB), database, policy storage database 119: Database (DB), AMF / SMF Database 120: Content Provider (CP) Network, Content Provider 121: (Content Provider) Website Server 122: Media Repository (Media), Media 130: Payment System (PS), Payment System Network 131: Authentication server, AAA server, two-factor authentication / authorization server 132: Account database, database, payment system database (DB) 133: Payment Server 140: Core Network Management Function Unit (CNMF; a collective term for AMF 112 and SMF 113) 210: Step 1, UE has been registered in PLMN / Website communication period has been established 212: HTTP - Request [URL] 214: HTTP-Response [Website Content, Directive File, Content ID, Security Tags] Step 220: Requires Packet Data Unit (PDU) communication period 222: PDU Communication Period Setup Request Message, First Communication Period Request Signal (PDU Communication Period Setup Request) [PS-addr, Content ID, Security Tag] 224: Steps, request policy [PS-addr] 226: Policy [AAA-addr] 228: Second Communication Period Request Signal, SMF / AAA Communication Period Request Message, SMF / AAA Communication Period Request (including authentication / authorization request) [GPSI, Content ID, Security Mark] 230: Steps to verify CP 240: Account, Determine Account 242: Message reception during SMF / AAA communication period, SMF / AAA communication period reception (including authentication / authorization reception) [GPSI] 250: UE device, first communication period (PDU communication period) establishment, IP-addr assignment 252: SMF / AAA communication period modification message, SMF / AAA communication period modification [GPSI, IP-addr] 254: Dashed line, SMF / AAA communication period modification confirmation [GPSI] 256: IP address, first communication phase settings to receive signals (PDU communication phase settings to receive) [IP-addr] 302: Steps, Request Information / Code 310: Steps, access immediately? 320: Status, access immediately 322: Information / code used for access 330: Status, no immediate access. 340: Steps to determine account-specific information / code 342: Information / code used for purchasing 344: Steps, Demonstration Information / Code 346: Step 1, User selects payment method 348: Message: Control has been activated [Control ID] 350: Steps to implement payment 352: Redirecting to CP (reloading the webpage) 401: Content provider URL, such as www.contentprovider.com 402: Access Option 1 button, pay later with an advertisement, such as "Buy for 99 cents - with advertisement - pay later balance: $1.98 out of $5". 403: Access Option 2 button, pay later without ads, for example "Buy for $1.99 - No ads - Pay later balance: $1.98 out of $5". 404: Access Option 3 button, granting access in return for sharing personal information, such as "Get it for free! Let your sponsor pay for it." 502: Access Option 4 button: Once you reach your credit limit, pay later without ads, for example, "Buy for $1.99 -- No ads -- Your balance of $5.73 will be credited." 602: Play album button 710: UE has been registered in PLMN / Website communication period has been established 712: HTTP Request [URL, Tags] 714: Steps, Authorization Request [Tag, Content ID] 720: Steps to determine account & content 722: Validation response, authorization response [Authorization information] 730: Content not authorized 732: Steps, HTTP Response [Website Content, Command File, User ID, Security Marks] 740: Requires a separate communication period (e.g., PDU communication period) 742: PDU communication period establishment request, first communication period request (e.g., PDU communication period setup request) [PS-addr, Content ID, Security tag] 744: Request Policy [PS-addr] 746: Policy [AAA-addr] 748: Subsequent transmission, second communication period (e.g., SMF / AAA communication period) request (including authentication / authorization request) [GPSI, Content ID, Security Mark] 750: Verify CP 760: Steps to determine the account 762: Second communication period (e.g., SMF / AAA communication period) acceptance (including authentication / authorization acceptance) [GPSI] 810: Steps, First communication period (e.g., PDU communication period) establishment, IP-addr assignment 812: Step, Second Communication Period (e.g., SMF / AAA Communication Period) Modification [GPSI, IP-addr] 814: Second Communication Period (e.g., SMF / AAA Communication Period) Modification Confirmation [GPSI] 816: First communication period (e.g., PDU communication period) settings accept [IP-addr] 818: Steps, request information / code 820: Determine account-specific information / code 822: Information / code used for purchasing 830: Steps, Demonstration Information / Code 840: User selects payment method 842: Control has been activated [Control ID] 850: Implementation of payment 852: Redirect to CP (set cookie, redirect) 901: First step, initialization of the first communication period (e.g., PDU communication period). 902: Second step, second communication period (e.g., SMF / AAA communication period) request signal 903: The third step is to verify the content provider and determine the account. 904: Fourth step, second communication period (e.g., SMF / AAA) communication period acceptance 905: Step 5, First Communication Period (e.g., PDU Communication Period) Establishment and IP Address Allocation 906: Step Six, Deposit Now 907: Step Seven, Demonstration Information / Code and User Selection 1001: Step 1, a user device 101 sends a signal requesting online content from a content provider 120. 1002: Step 1, the user equipment 101 receives a response signal having an address of a payment system 130. 1003: Step 1, the user equipment sends a first communication period request signal, requesting a communication period with the payment system 130. 1004: Step 117, based on the address of the payment system 130, determines the address of a verification server 131. 1005: Step 140, a core network management function unit 140, determines a persistent ID of user equipment 101 and provides the persistent ID to the authentication server 131 in a second communication period request signal 228. 1006: Step, the verification server (131) determines the authenticity of the user device 101 using the persistent ID. 1007: Step 130, based on the persistent ID, determines the payment status of the user device 101 for online content. 1008: Step, based on the payment status, enable at least one user option for the online content on the user device 101.

Claims

1. A method for providing paid access to online content, the method comprising: a) sending a signal from a user device requesting the online content from a content provider; b) receiving a response signal from the user device having an address of a payment system; c) sending a first communication period request signal from the user device requesting a communication period with the payment system; d) determining, by a policy function unit, an address of an authentication server based on the address of the payment system, the authentication server being a secondary authentication server and / or an AAA server, located remotely from a public terrestrial mobile network and being part of the payment system; e) determining, by a core network management function unit, a persistent ID of the user device and providing the persistent ID to the authentication server in a second communication period request signal; f) using the persistent ID to determine the authenticity of the user device by the authentication server. g) The payment system determines a payment status of the user device for the online content based on the persistent ID; and h) Based on the payment status, enables at least one user option on the user device for the online content; The method further includes, in response to successful verification in step f): assigning an IP address to the user device for access to the payment system; providing the payment system with the IP address of the user device; and storing a mapping between the IP address of the user device and the persistent ID by the payment system; wherein step g) further includes determining the persistent ID based on the IP address of the user device and the stored mapping; wherein the policy function is a policy control function of the public terrestrial mobile network of the user device; and wherein the persistent ID is a generic public subscription identifier.

2. The method of claim 1, wherein step b) further includes the user device receiving a security token from a website server; wherein step e) further includes providing the security token to the verification server as a secondary verification credential; and wherein step f) includes using the security token to verify the content provider and / or the website server by the verification server.

3. The method of claim 1, wherein step b) includes the user device receiving an instruction file embedded in a webpage from a website server of one of the content providers, the instruction file including an identification of the online content and instructions for setting a first communication period with an address of the payment system; wherein the user device connected to the public terrestrial mobile network including a 5G core network is connected to the website server via the public terrestrial mobile network; and wherein when the instruction file is executed on the user device, information and further executable code are downloaded from a payment server of one of the payment systems.

4. The method of request 3, wherein the instruction file contains information for accessing the online content, which is presented on the user device only when the payment system determines that the online content has been purchased, otherwise a purchase option is presented on the user device; and wherein when the webpage of the content provider including the code is displayed, the user device will immediately or after user interaction establish a connection to one of the payment systems for downloading the information and the further code.

5. The method of claim 3, wherein the user device receives a website communication identifier embedded in a webpage from the website server of the content provider, and some information in the downloaded information, such as content providing access to paid content, is not immediately presented to the user.

6. The method of any one of claims 1 to 5, wherein the public terrestrial mobile network is aware of the payment system, such as through a service level agreement between one operator of the public terrestrial mobile network and one operator of the payment system; and wherein the 5G core network has a policy storage database attached to the policy function unit, wherein one or more policies related to the payment system are stored.

7. The method of any one of claims 1 to 5, wherein step g) includes the payment system determining, based on the persistent ID and one of the IDs of the online content, whether the user device has paid for the online content, and: if yes, providing the user device with access to the online content; if no, providing at least one option to pay for the online content.

8. The method of any one of claims 1 to 5, further comprising: in response to successful payment for the online content, the payment system storing a token or identifier of completed purchase in the user device; wherein in step a), the user device provides the token or identifier to the content provider; wherein the content provider uses the token or identifier to request authorization for the requested online content from the payment system; and wherein in response to successful authorization, the content provider allows the user device to access the online content.

9. The method of any of requests 1 to 5, wherein the user device does not require further registration and / or credentials to access the online content.

10. The method of any one of claims 1 to 5, wherein step g) further includes determining an account of the user device based on the persistent ID; and wherein step h) further includes monitoring the total outstanding debits of the account of the user device, and requesting settlement of at least a portion of the total outstanding debits after a predetermined time interval and / or when a predetermined total outstanding debit amount is exceeded.

11. A system for providing paid access to online content, the system comprising: a user equipment connected to a public terrestrial mobile network, including a policy function and a core network management function; a content provider including a server such as a website server; and a payment system including an authentication server, such as an AAA server; wherein the system is configured to perform the method of any one of claims 1 to 10.

12. A computer program containing instructions for causing a system to perform the steps of any one of claims 1 to 10.

13. A computer-readable medium having a computer program as described in claim 12 stored thereon.

Citation Information

Patent Citations

  • Connecting to virtualized mobile core networks

    CN109314887A

  • Session management with relaying and charging for indirect connection for internet of things appplications in 3gpp network

    CN109997334A

  • Pcocedure to update the parmeters related to unified access control

    CN111201809A

  • E-market cloud payment solution system

    TWM527995U

  • Mobile payment system and method

    US20170278095A1