Message delivery in a cellular roaming scenario

CN115941234BActive Publication Date: 2026-08-21INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211009265.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-08-31
Filing Date
2022-08-22
Publication Date
2026-08-21
Estimated Expiration
2042-08-22

Smart Images

  • Figure CN115941234B_ABST
    Figure CN115941234B_ABST
Patent Text Reader

Abstract

The present invention relates to message delivery in a cellular roaming context. Message delivery in a cellular roaming scenario involves activating a user device with a home telecommunication service provider (TSP) that provides cellular service to the user device. The user device is located at a remote location and the user device is activated with a remote TSP that provides roaming cellular service to the user device at the remote location over a cellular network of the remote TSP. A process includes, based on a user initiating a transaction with a remote application server that requires user authentication for delivery of a transaction text message, receiving the transaction text message from the remote application server, encrypting the transaction text message to produce an encrypted transaction text message, and forwarding the encrypted transaction text message to the remote TSP for delivery as a short message service (SMS) text to the user device in the remote location via the cellular network of the remote TSP.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention generally relates to information technology, and more specifically, to message delivery in cellular roaming situations. Background Technology

[0002] Typically, when users execute sensitive online transactions (such as online financial transactions), enhanced security or additional authentication measures are required before the transaction is completed. The application server sends a transaction text message to the user's cellular phone, i.e., a Short Message Service (SMS) text message, to authenticate the user. Transaction text messages can be of various types. One common type is a one-time password (OTP) received by the user and provided to the web application to authenticate the user. Another type of transaction text message is a unique hyperlink, such as a hyperlink that allows the user to change their account password or click to approve the initiated transaction. Summary of the Invention

[0003] By providing a computer-implemented method, the shortcomings of existing technologies are overcome, and additional advantages are offered. A user initiates a transaction with a remote application server. The transaction requires user authentication based on the delivery of a transaction text message to the user's mobile device via a cellular network connection. Based on the user-initiated transaction, the method receives a transaction text message from the remote application server for delivery to the user equipment. The user equipment is activated using a Home Telecommunication Service Provider (TSP), which provides cellular service to the user equipment at its home location on the home TSP's cellular network using the home cellular number provided by the home TSP. The transaction text message is received by the home TSP and will be sent by the home TSP to the user equipment. The user equipment is located at a remote location and is activated using a remote TSP, which provides roaming cellular service to the user equipment at the remote location on the remote TSP's cellular network. The method encrypts the transaction text message to produce an encrypted transaction text message. Furthermore, the method forwards the encrypted transaction text message from the home TSP to the remote TSP for delivery as Short Message Service (SMS) text via the remote TSP's cellular network to the user equipment at the remote location.

[0004] Furthermore, a computer system is provided, including a memory and a processor communicating with the memory, wherein the computer system is configured to perform a method. A user initiates a transaction with a remote application server. The transaction requires user authentication based on a transaction text message delivered to a user's mobile device via a cellular network connection. Based on the user-initiated transaction, the method receives a transaction text message from the remote application server for provision to the user device. The user device is activated using a Home Telecommunication Service Provider (TSP), which provides cellular service to the user device at its home location on the cellular network of the Home TSP using a home cellular number provided by the Home TSP. The transaction text message is received by the Home TSP and will be sent by the Home TSP to the user device. The user device is located at a remote location and is activated using a remote TSP, which provides roaming cellular service to the user device at the remote location on the remote TSP's cellular network. The method encrypts the transaction text message to produce an encrypted transaction text message. Furthermore, the method forwards the encrypted transaction text message from the Home TSP to the remote TSP for delivery as Short Message Service (SMS) text via the remote TSP's cellular network to the user device at the remote location.

[0005] Furthermore, a computer program product is provided, comprising a computer-readable storage medium readable by processing circuitry, and storing instructions for execution by the processing circuitry to perform a method. A user initiates a transaction with a remote application server. The transaction requires user authentication based on a transaction text message delivered to a user's mobile device via a cellular network connection. Based on the user-initiated transaction, the method receives a transaction text message from the remote application server for delivery to the user device. The user device is activated using a Home Telecommunication Service Provider (TSP), which provides cellular service to the user device at its home location on the cellular network of the Home TSP using a home cellular number provided by the Home TSP. The transaction text message is received by the Home TSP and will be sent by the Home TSP to the user device. The user device is located at a remote location and is activated using a remote TSP, which provides roaming cellular service to the user device at the remote location on the remote TSP's cellular network. The method encrypts the transaction text message to produce an encrypted transaction text message. Furthermore, the method forwards the encrypted transaction text message from the Home TSP to the remote TSP for delivery as Short Message Service (SMS) text via the remote TSP's cellular network to the user device at the remote location.

[0006] Additional features and advantages are achieved through the concepts described in this article. Attached Figure Description

[0007] In the claims at the end of the specification, by way of example, the aspects described herein are specifically pointed out and clearly claimed. The foregoing and other objects, features, and advantages of this disclosure will become apparent from the following detailed description taken in conjunction with the accompanying drawings, in which:

[0008] Figure 1 An example of message non-delivery in a cellular roaming scenario is depicted;

[0009] Figure 2A-2B An example of message delivery in a cellular roaming scenario is depicted based on registering a roaming number with the home telecommunications service provider;

[0010] Figure 3 It depicts an example of message delivery in an international roaming scenario;

[0011] Figure 4 An example conceptual diagram depicts a system for message delivery in a cellular roaming scenario, based on the aspects described herein;

[0012] Figures 5A-5D An example process for message delivery in a cellular roaming scenario is described according to the aspects described herein;

[0013] Figure 6 An example of a computer system and associated devices for incorporating and / or using the aspects described herein is depicted;

[0014] Figure 7 A cloud computing environment according to embodiments of the present invention is described; and

[0015] Figure 8 An abstract model layer according to an embodiment of the present invention is described. Detailed Implementation

[0016] The aspects described herein relate to the delivery of text messages to a user's cellular device. Example text messages are transaction text messages relating to a transaction initiated by a user involving a web application. The terms "user" and "subscriber" are used interchangeably herein to refer to a subscriber of cellular services provided by a cellular telecommunications service provider (TSP). A user / subscriber using cellular services via a cellular device is referred to herein as a "user device" or "subscriber device." The terms "subscriber," "user," "subscriber device," and "user device" are used interchangeably herein, for example, when referring to actions performed by a subscriber or by a device on behalf of that subscriber.

[0017] A user's cellular device is activated by a cellular TSP. Typically, a given user will activate their device on a primary TSP, such as the TSP that provides cellular service to users in the user's home location (country, region, area, etc.). This TSP is referred to herein as the user's home TSP, which provides cellular service to the subscriber's device at their home location on the home TSP's cellular network. As part of this, the home TSP assigns a telephone number ("home cellular number") to the user / device for communication via telephone or text messaging. Sometimes, a user travels to a location outside the coverage area of ​​the home TSP's cellular infrastructure ("remote location"). In this case, the user / device is referred to as "roaming," and the user device may be registered / activated with a remote TSP, which provides (roaming) cellular service to the user device in the remote location on the remote TSP's cellular network.

[0018] One roaming scenario, referred to herein as subscription roaming, treats a user's subscription to a remote TSP, even a temporary subscription, as a user of the remote TSP's cellular service. In this case, the remote TSP assigns a phone number ("roaming cellular number") to the user's device, which is local to the remote location and used for roaming TSP cellular service. Another roaming scenario, referred to herein as international roaming, enables a user's home cellular number to function on the remote TSP's cellular network at the remote location. The home TSP offers international roaming service to subscribers so that the home cellular number can be extended internationally, i.e., extended to the remote TSP's cellular network, so that the home cellular number is available on the remote TSP's cellular network. Typically, both the home and remote TSPs have pre-defined terms to provide international roaming service to their users.

[0019] When a user / subscriber is roaming, message reception issues may arise. In roaming scenarios where a user is subscribing to a roaming cellular number, the home TSP must be aware of the roaming cellular number. Otherwise, text messages sent to the user's home cellular number will not reach the user's device at the remote location via the roaming cellular number. This is problematic for various reasons. In time-sensitive text messaging applications, such as when a message for authentication via OTP is sent to a user related to a financial transaction, the message will be sent to the user's home cellular number but will not reach the user's device using the roaming number. In this case, the user cannot authenticate via OTP and will not be able to complete the transaction.

[0020] Figure 1This problem scenario is illustrated. User equipment 104 is activated by a home TSP 106 that provides cellular coverage in home location 108, offering cellular service to the user equipment in home location 108 on the cellular network of home TSP 106. As part of this, the home TSP provides a home cellular number to user equipment 104. At some point, the user travels to a remote location 110 where a remote TSP 112 provides a cellular network. User equipment 104 at remote location 110 can be activated by remote TSP 112, which provides roaming cellular service to user equipment 104 at the remote location on the cellular network of remote TSP 112.

[0021] When a user is at a remote location, the user initiates (118) a transaction with a remote application server 122 via an e-commerce application 120 (in this example). In this example, application 120 and the backend application server 122 are hosted in a cloud environment 124. However, in other examples, the application 120, to which the user interacts and engages with application server 122, may be partially or wholly installed on the user device 104, for example, if the user uses a web browser or a locally installed mobile application on user device 104 to communicate with the cloud server to initiate a transaction. The cloud environment 124 may be located at a remote location 110, a home location 108, or another location.

[0022] In this scenario, the subscriber does not carry their local (home) cellular number, but instead subscribes to a roaming cellular number (i.e., local at a remote location). Based on the initiation 118 of a transaction conducted by e-commerce application 120, application server 122 interacts with the home TSP 130 to initiate (130) sending an SMS message with OTP to the home cellular / mobile number of the user registered to e-commerce application 120. The transaction SMS message is delivered to the user's home cellular number, but does not reach the user's device at this time because it is on roaming cellular service at a remote location. This results in messages sent by application server 122 to the subscriber via home TSP being unavailable when the user is at a remote location.

[0023] In these cases, a roaming cellular number can be registered with the home TSP so that the home TSP can forward messages to a remote TSP for delivery to the user equipment via the roaming cellular number assigned by the remote TSP. Figure 2A and 2B An example of this is shown.

[0024] Figure 2AThis also includes home location 208, home TSP 206, user equipment 204 using the home cellular number in home location 208, remote location 210, remote TSP 212, and cloud environment 224 with e-commerce application 220 and application server 222. At some point before traveling to remote location 210, the user establishes an SMS forwarding registration 250 with home TSP 206. This instructs home TSP 206 to forward messages / calls initially directed to the home cellular number to the roaming cellular number. The user has device 204 at remote location 210, where it obtains and uses the roaming cellular number in remote location 210. The user initiates 218 a transaction with e-commerce application 220, which communicates with application server 222 to initiate 230 a transaction whereby home TSP 206 sends an SMS message with OTP to the user's home cellular / mobile number registered with e-commerce application 220. Home TSP 206 delivers message 232 to the roaming cellular number according to the user's previously configured SMS forwarding registration.

[0025] like Figure 2A Pre-establishing an SMS forwarding registration is one example of registering a roaming cellular number with the home TSP as an active secondary number to establish a link between the home and roaming cellular numbers. Alternatively, sometimes users establish a registration after traveling to a remote location to establish a roaming number as an active secondary number. Figure 2B This describes an example of a user completing this operation via dial-up authentication. Figure 2B In this scenario, a user at remote location 210, while on the remote TSP 212 cellular network, uses device 204 at remote location 210 to dial (216) to home TSP 206 at home location 208, and authenticates the user / device using the home TSP. The user can explicitly specify a roaming number, and / or home TSP 206 identifies the roaming number via dialing to establish a link between the home cellular number provided by the home TSP and the roaming cellular number provided by the remote TSP 212. The user initiates (218) a transaction with e-commerce application 220 using device 204 at remote location 210. The e-commerce application communicates with application server 222 to initiate (230) home TSP 206 sending an SMS message with OTP to the user's home cellular / mobile number registered with e-commerce application 220. Home TSP 206 will deliver message 232 to the roaming cellular number due to previous dialing authentication and registration with the roaming number of home TSP 206.

[0026] Figure 2A and Figure 2BBoth scenarios involve registering a roaming cellular number as an active secondary number with the home TSP to establish a link between the home and roaming cellular numbers, and both scenarios rely on the user authenticating with the home TSP to securely register the roaming cellular number with the home TSP.

[0027] In international roaming scenarios, messages sent to the home number will be provided to the remote TSP, which knows the user equipment on the remote TSP's cellular network. Figure 3 This scenario is illustrated. When traveling to remote location 310, subscriber / user equipment 304 carries its home cellular number provided by home TSP 306 at home location 308 and utilizes the international roaming protocol between home TSP 306 and remote TSP 312 at the remote location. The user initiates a transaction 318 with e-commerce application 320 using equipment 304 at remote location 310. This e-commerce application communicates with application server 322 to initiate 330 that home TSP 306 sends an SMS message with OTP to the user's home cellular / mobile number registered to e-commerce application 320. Home TSP 306 delivers message 332 to the home cellular number used on the cellular network of remote TSP 312 at remote location 310. Therefore, the transaction message is available to the subscriber at the remote location.

[0028] Despite subscribing to roaming ( Figure 2A , 2B ) and international roaming ( Figure 3 In some cases, messages will be delivered to roaming users, but there are potential adverse consequences. One involves security: the transmission of messages from the home TSP to a remote TSP network can be considered a security risk because the message content (which is potentially sensitive information) will be available to the remote TSP and potentially compromised in flight. Another issue involves timing: the latency / lag time in the delivery of SMS messages from the home TSP to roaming devices on other TSP networks can be quite high, possibly so high that by the time the message is finally delivered to the user equipment at the remote location, the message content's expiration period has already passed. At this point, the OTP (as an example) has expired and can no longer be used to authenticate transactions.

[0029] This document describes a method for message delivery in cellular roaming scenarios. This method is particularly useful in the case of transaction message delivery, for example, when roaming at a remote location (outside the subscriber's home cellular network), delivering time- and security-sensitive messages to the cellular user for transaction authentication or other purposes to facilitate transaction completion. Therefore, a method is provided for securely delivering transactional (including private and confidential) communications to the roaming subscriber's registered number via the home / roaming cellular number while the roaming subscriber is in a roaming location. A method is provided for securely registering the roaming number provided by the remote TSP at the roaming location as an active secondary number for the user to the home TSP, and activating a seamless communication path for secure transaction message communication between the home TSP and the subscriber's device. This path can be pre-established, activated, and tested for transaction communication in roaming scenarios before the transaction is initiated. For security, when the user is roaming, the processor can encrypt received messages for transmission to the user device via the remote TSP, requiring the user to individually authenticate / provide a shared secret to correctly decrypt the messages. Shared secrets can facilitate the extraction of multi-level encryption / decryption security keys to obtain sensitive message data (such as OTPs) related to initiated financial or other types of transactions. Expiration timelines or other parameters can be established for roaming cellular numbers' registration with the home TSP and / or shared secrets to enhance security.

[0030] Figure 4 An example conceptual diagram depicts a system for message delivery in a cellular roaming scenario, based on the aspects described herein. The system is implemented by a collection of computer, telecommunications, and network system devices, such as user consumer electronics devices (e.g., cellular phones / smartphones), telecommunications equipment of the TSP, and computer / network devices providing wired / wireless networks for telecommunications and data communication between the various devices.

[0031] Home location 408 includes a home TSP 406 that provides cellular services (e.g., including telephone / voice communications and broadband data / Internet / messaging services) to subscribers / user equipment. One such subscriber providing cellular services through a home TSP is represented by user equipment 404. In this example, home location 408 is the subscriber's home country.

[0032] The home TSP 406 provides a set of web services available to the subscriber 404 via an HTTPS connection 403. A roaming number registration component 460 is used to register a roaming cellular number with the home TSP 406. As an example, registration can be completed manually by the subscriber via dial-up verification or via an interface provided to the user to specify the forwarding number to which calls / messages should be forwarded. The home TSP 406 also provides an end-to-end message channel authenticator 462 for activating / verifying / testing the communication channel 464 between the home TSP 406 and the remote TSP 412 to enable communication between them according to the message routing protocol between the two TSPs. Channel 464 enables calls / messages to be provided from the home TSP to the subscriber device 404 in a remote location 410 that is simultaneously connected to the remote TSP 412. In this example, the remote location 410 is a different (remote) country. Authenticator 462 can be triggered automatically or manually to send messages to the remote TSP 412. A useful application is to establish a communication channel 464 between the home TSP and the remote TSP, and ultimately establish it to the user equipment 404 when the user equipment 404 is located at the remote location 410. With the channel established, subsequent messages sent by the home TSP 406 to the remote TSP 412 for use with the user equipment 404 are expected to arrive more quickly.

[0033] The home TSP 406 also provides a shared secret component 466 for managing a shared secret, such as a Secure Personal Identifier (PIN), between the home TSP 406 and the subscriber 404. According to some embodiments, the home TSP 406 generates a shared secret (e.g., a 4-digit PIN) and shares it with the subscriber. The home TSP 406 uses this shared secret to generate an encryption key to encrypt messages to be sent to a remote TSP 412 for delivery to the subscriber 404 at a remote location 410. The user equipment 404 can use the same shared secret to generate a decryption key to decrypt encrypted messages received from the home TSP 406, which are received via the remote TSP 412. An encryption adapter 470 can use any desired technology to perform this encryption to encrypt messages that will be forwarded by the local TSP 406 to the remote TSP 412 for delivery to the user equipment 404 at the remote location 410. As a specific example, the encryption adapter 470 applies Feistel encryption, where a shared secret is used to generate subkeys, and those subkeys are used in "rounds" to produce encrypted messages.

[0034] The enabler / disabler component 468 enables and disables roaming services for subscribers based on any desired triggers or other parameters. Roaming services can be time-based, location-based, or based on other factors that will automatically enable or disable roaming services and messaging when the subscriber is in a cellular roaming scenario. As a concrete example, the regulatory cross-border query service 472 is used to query the location of user equipment 404 to determine whether the user equipment is located in a remote location outside the home TSP cellular network and / or the geographic boundaries (e.g., region, state, country, etc.) of the home TSP. Roaming services can be enabled / disabled based on the location of the user equipment. For example, roaming can be automatically disabled based on the detection that a user equipment previously located in a remote location 410 has left the geographic boundaries (such as country borders) of the remote location 410 where roaming services are being provided to user equipment 404.

[0035] Alternatively, or as an option, enabler / disabler 468 can be manually enabled (e.g., by a subscriber logging into the home TSP406 system) to enable / disable the user's roaming service.

[0036] When at remote location 410, subscriber device 404 can interact with remote TSP 412 via HTTPS connection 480. Remote TSP 412 provides roaming number lookup service 482, which provides any desired roaming number service. An example is verifying subscriber device 404 upon connection to the remote TSP and / or utilizing the home TSP to perform a lookup of the user's home cellular number. Additionally, service 482 enables home TSP 406 to look up roaming numbers assigned to the subscriber device by the remote TSP, for example, registering that roaming number with the home TSP.

[0037] The end-to-end message channel routing requester 484 is a corresponding component of the verifier 462 at the home TSP, enabling the activation / verification / testing of communication flowing between the home TSP and the subscriber equipment via the remote TSP on channels 464 and 480. In a specific example, the user can initiate a test between the remote and home locations. One such test involves the home TSP providing an encrypted message (encrypted using a secret shared between the home TSP and the user) to the remote TSP, which then delivers it to the user equipment 404 at the remote location. The user equipment subsequently decrypts the received message, and the user verifies that it has been correctly decrypted into a plaintext message sent by the home TSP. This is to test the communication channel between the home TSP and the subscriber equipment via the remote TSP and the shared secret.

[0038] The regulatory overreach query service 488 can be used by a remote TSP to query the location of user equipment 404 to determine whether the user equipment is within the geographical boundaries (e.g., region, state, country, etc.) of remote location 410 and / or remote TSP 412.

[0039] The secret generation component 486 can be used when a remote TSP participates in encrypting and / or decrypting messages flowing between the home TSP and the subscriber device. In one example, a first shared secret exists between the subscriber and the home TSP. Component 486 generates a second shared secret and provides it to the subscriber device 404 and the home TSP 406 (or the user generates the second shared secret and shares it with the remote TSP and the home TSP). When the home TSP wants to send a message to the user device in a remote location, it performs layered encryption by encrypting the message (such as a message with OTP) based on the first shared secret, for example, by generating a subkey using the first shared secret to encrypt the message and produce an intermediate encrypted message, and then encrypting the intermediate encrypted message based on the second shared secret, for example, by generating a subkey using the second shared secret to encrypt the intermediate encrypted message, to produce a final encrypted message. The home TSP sends this final encrypted message to the remote TSP 412, which uses a decryption mechanism to perform a certain level of decryption of the message, for example, using a subkey generated from the second shared secret known to it. This generates an intermediate encrypted message that, in terms of its content, cannot be read by the remote TSP and intermediate entities because the home TSP encrypts the message based on a first shared secret, which is unknown to the remote TSP or those intermediate entities. The intermediate encrypted message is sent to subscriber device 404 for decryption using the first shared secret, thereby generating the initial (e.g., plaintext) message.

[0040] In the modified example above, the home TSP does not perform layered encryption, but instead encrypts the initial message based solely on the first shared secret. In this case, the second shared secret does not need to be shared with the home TSP. When the remote TSP receives the encrypted message from the home TSP, the remote TSP encrypts the encrypted message based on the second shared secret and sends the double-encrypted message to the subscriber equipment. The subscriber equipment can decrypt the received encrypted message based on the first and second shared secrets (in the reverse order of the double encryption) to restore the message to its original plaintext form.

[0041] In another embodiment, the shared secret is shared only between the home TSP and the subscriber. In this case, the remote TSP is unaware of any shared secret and delivers the encrypted message as is (encrypted by layered encryption performed by the local TSP) to the subscriber device. The subscriber device then performs layered decryption again in reverse order based on the shared secret it shares with the home TSP to decrypt the received message sent via the remote TSP back to its original plaintext form.

[0042] A message decoding service 490 is provided to user equipment 404 to facilitate the decryption of received messages. This service may be provided as part of a mobile application installed on device 404, or as a remote web-based service provided by another component via a secure connection to user equipment 404. In the example using Feistel ciphers, service 490 may accept a shared secret and generate encryption or decryption subkeys. Service 490 may provide the subkey to the user equipment for decrypting received encrypted messages, or may use the subkey to perform decryption and provide the decrypted message to the user equipment / its application (e.g., a messaging application that displays plaintext messages from the home TSP to the user).

[0043] Figures 5A-5D An example process for message delivery in a cellular roaming scenario, according to the aspects described herein, is depicted. In some examples, aspects of the process are executed by one or more computer systems, such as those described herein, which may be user / subscriber cellular devices, one or more devices of a telecommunications service provider network, one or more cloud servers and / or one or more other computer systems, or may be incorporated into user / subscriber cellular devices, one or more devices of a telecommunications service provider network, one or more cloud servers and / or one or more other computer systems.

[0044] Figure 5A An exemplary process performed by a system belonging to a TSP according to the aspects described herein is depicted. This process can be invoked based on a transaction initiated by a user with a remote application server. The transaction may require user authentication based on a transaction text message, such as an SMS text message with a multi-factor authentication code (such as OTP or other authentication codes), delivered to the user's mobile / cellular device via a cellular network connection. An example of such a transaction is one using a credit / debit card from an issuing bank, where the bank requires the user to perform SMS-based multi-factor authentication to allow the transaction to complete.

[0045] In the example, the user equipment is activated by the home TSP, which provides cellular service to the user equipment at its home location on the home TSP's cellular network. The home cellular number is provided to the subscriber / user by the home TSP. A remote application server generates an authentication code, typically an n-bit OTP, as a time-sensitive one-time password, which the user provides to the remote application server for multi-factor authentication to execute transactions. Additionally, at some point, the home TSP performs the setup of a shared secret between the home TSP and the user. In one example, the home TSP randomly generates an n-bit secret PIN and provides it to the user or the user equipment's software. This process uses those shared secrets to obtain (502) one or more encryption keys. The shared secrets may include one or more encryption keys themselves. Alternatively, the home TSP uses the shared secrets to obtain / generate subkeys as encryption keys for message encryption.

[0046] Based on the user-initiated transaction, the process of the home TSP continues, receiving a (504) transaction text message from the remote application server to provide to the user equipment. The transaction text message is received by the home TSP and will be sent to the user equipment by the home TSP. The user equipment is located at a remote location and is activated using a remote TSP, which provides roaming cellular services to the user equipment at the remote location on the remote TSP's cellular network.

[0047] The process continues, with the home TSP encrypting (506) the transaction text message to produce an encrypted transaction text message. Encryption uses at least one encryption key to encrypt the transaction text message. In the example, the home TSP uses the Feistel cryptographic method for encryption to encrypt the message. For example, the home TSP possesses one or more shared secrets with the user. For each such shared secret, the home TSP (i) generates m subkeys for different rounds of Feistel network encryption, and (ii) uses the Feistel method to encrypt the message using m rounds of encryption, generating an encryption for each of the m subkeys generated from the shared secret. This can be done for each shared secret possessed. In the first iteration, the message received from the remote application server is encrypted. In each subsequent iteration, the message generated from the previous iteration of Feistel encryption is encrypted in the next iteration. In this way, the encryption layers applied to the initial message are layered.

[0048] Although the Feistel method is used in the example discussed here, any desired encryption scheme can be used to encrypt the message.

[0049] Once the message is encrypted, the process forwards (508) the encrypted transaction text message to the remote TSP for delivery as a Short Message Service (SMS) text via the remote TSP's cellular network to the user equipment at the remote location.

[0050] Furthermore, the validity of a shared secret can expire under any desired triggering condition. For example, expiration can be triggered by (i) a time-based trigger based on the elapsed time of a defined quantity of time, such as the duration of a user's access to a remote location or any other duration specified by the user or another entity, (ii) a location-based trigger based on the user equipment moving out of the geographical boundary of the remote location (e.g., the user leaving a foreign country where roaming services are provided), and / or (iii) a push-based trigger based on receiving an expiration indication from a trusted source. An example of a push-based trigger is an airline that pushes notifications to the home TSP of each aircraft passenger leaving the remote location / remote TSP service area.

[0051] to this end, Figure 5A The process continues, determining (510) whether the shared secret held between the home TSP and the user has expired. For example, a query is made to inquire whether an expiration trigger as described above has been received / generated. If yes (510, Yes), the process triggers (512) the expiration of the shared secret and ends. Based on this expiration, the home TSP at least temporarily prohibits the use of the shared secret in further encryption activities, such as encrypting subsequent messages to be forwarded to the user equipment. Otherwise (510, No), the process is temporarily idle or loops back to 510 to repeat the query. This loop can be interrupted by receiving another message from a remote application server or any other source to be sent to the user equipment at a remote location, in which case the process can return to 504 and repeat message encryption (506) and forwarding (508).

[0052] Figure 5B An example process is described for another aspect performed by the home TSP system in a roaming subscription scenario, where the remote TSP assigns a roaming cellular number to a user equipment. In this case, encrypted transaction text messages are forwarded by the home TSP to the remote TSP for delivery to the user equipment via the roaming cellular number assigned by the remote TSP. The process in this case includes registering (520) the roaming cellular number with the home TSP. In the example, the roaming cellular number is registered as an active secondary number to establish a link between the home cellular number and the roaming cellular number. Registration can be based on the user's authentication with the home TSP and the secure registration of the roaming cellular number with the home TSP. In this example, forwarding ( Figure 5A (508) includes sending encrypted transaction text messages to roaming cellular numbers.

[0053] Related to the registration of roaming cellular numbers, triggered upon startup. Figure 5APrior to the transaction in the process, the process also pre-establishes (522) a communication path for transaction message communication between the home TSP and the remote TSP, wherein the home TSP sends a test message to the remote TSP for delivery to the user equipment via the roaming cellular number.

[0054] Similar to the expiration of a shared secret at the home TSP, roaming cellular number registration can also expire at the home TSP. As mentioned above, expiration can be triggered by time-based, location-based, and / or push-based triggers. The process determines (524) whether the registration has expired, and if so (524, Yes), triggers (526) the expiration of the roaming cellular number (e.g., as an active secondary number of the home TSP), causing the roaming cellular number to be prohibited from use in forwarding messages to the user equipment, and ends. If the registration has expired, the home TSP will no longer send messages to the roaming number. Conversely, if it is determined that the registration has not expired (524, No), the process loops back to 524 to periodically / non-periodically check whether the registration has expired.

[0055] Additionally, in the case of roaming subscriptions, layered encryption can be applied at the home TSP using multiple shared secrets. Therefore, the home TSP can generate a first shared secret, provide it to the user, and receive a second shared secret from the user that will be used for double encryption. The home TSP can use the first shared secret to obtain a first or more encryption keys (e.g., a first subkey), and use the second shared secret to obtain a second or more encryption keys (e.g., a second subkey), and use these first or more encryption keys and second or more encryption keys to perform encryption. Figure 5A (506). When a user travels to a roaming location, they may want layered encryption as an additional security measure. In some examples, three or more shared secrets are used, and layered encryption includes three or more encryption layers based on corresponding sets of encryption keys. This can be useful if messages are expected to propagate through several TSPs or other services that require separate encryption layers.

[0056] As an enhancement when a user moves between roaming locations, the home TSP can perform two layers of encryption on received messages using two shared secrets: one shared secret for the home TSP and one shared secret for the remote TSP that provides roaming services to the user equipment upon receiving the message. When a user moves from a remote location on a first remote TSP to another remote location on a second remote TSP, the home TSP can expire the shared secret corresponding to the first remote TSP and activate the shared secret corresponding to the second remote TSP for use.

[0057] Figure 5CAn exemplary process with additional aspects, performed by a home TSP system in an international roaming scenario according to the aspects described herein, is described, wherein a user's home cellular number is registered with a remote TSP for international roaming, and the remote TSP uses the home cellular number when transmitting messages to a user equipment at a remote location. In this case, the process includes the home TSP generating (530) a shared secret and providing the shared secret to the user, and using (532) the shared secret to obtain at least one encryption key, such as generating a subkey for Feistel encryption. Encrypted transaction text messages ( Figure 5A (506) Use at least one encryption key to encrypt transaction text messages. Furthermore, in Figure 5B and 5C In this process, the shared secret can expire (for example, as mentioned above). Figure 5A (As discussed in sections 510 and 512).

[0058] Figure 5D An example process performed by a subscriber device according to the aspects described herein is depicted. This process includes receiving / generating (540) a shared secret. As an example, the device receives a shared secret from a home TSP and / or a remote TSP, and / or the device generates one or more shared secrets and shares them with the home TSP and / or the remote TSP. In the case of subscribed roaming, then whenever the user device roams to a remote location and registers with a remote TSP to receive a roaming cellular number, the device may generate a new shared secret and share it with the home TSP, for example, using dial-up authentication if the number is issued.

[0059] The process continues, and the user equipment initiates (542) a transaction with the remote application server, which triggers... Figure 5A The processing involves obtaining (544) a decryption key based on the shared secret currently in use at some point before or after the transaction is initiated. For example, the user equipment generates a subkey based on one or more shared secrets, which is the decryption key used when decrypting received encrypted messages. Ultimately, the user equipment receives and uses the decryption key to decrypt (546) the encrypted transaction text message. The ciphertext message can only be decrypted by the decryption key if the shared secret provided by the user as part of obtaining the decryption key is correct.

[0060] At this point, the user device can perform processing, possibly based on user input such as clicking a link or entering an OTP in the interface. Examples of such processing include loading a URL or transmitting the OTP to an application server or other remote entity to authenticate the user.

[0061] Although various examples are provided, various variations are possible without departing from the spirit of the aspects for which protection is sought.

[0062] The processes described herein may be performed individually or jointly by one or more computer systems. For example, the one or more computer systems may be user / subscriber cellular devices, one or more devices of a telecommunications service provider network, one or more cloud servers and / or one or more other computer systems, or may be incorporated into user / subscriber cellular devices, one or more devices of a telecommunications service provider network, one or more cloud servers and / or one or more other computer systems. Figure 6 An example of a computer system and associated devices for incorporating and / or using the aspects described herein is depicted. The computer system may also be referred to herein as a data processing device / system, a computing device / system / node, or simply a computer. The computer system may be based on one or more of various system architectures and / or instruction set architectures, such as those provided by International Business Machines Corporation (Armunk, New York, USA), Intel Corporation (Santa Clara, California, USA), or ARM Holdings Limited (Cambridge, England, United Kingdom).

[0063] Figure 6 A computer system 600 communicating with an external device 612 is illustrated. The computer system 600 includes one or more processors 602, such as a central processing unit (CPU). The processor may include functional components used in the execution of instructions, such as those for fetching program instructions from locations such as caches or main memory, decoding and executing program instructions, accessing memory for instruction execution, and writing the results of executed instructions. The processor 602 may also include registers used by one or more functional components. The computer system 600 also includes a memory 604, input / output (I / O) devices 608, and I / O interfaces 610, which may be coupled to and coupled to the processor 602 via one or more buses and / or other connections. Bus connections represent one or more of any of several types of bus architectures, including memory buses or memory controllers, peripheral buses, accelerated graphics ports, and processor or local buses using any of a variety of bus architectures. By way of example and not limitation, these architectures include Industry Standard Architecture (ISA), Micro Channel Architecture (MCA), Enhanced ISA (EISA), Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI).

[0064] Memory 604 may be or include main memory or system memory (e.g., random access memory), storage devices such as hard disk drives, flash memory, or optical media (as examples), and / or cache memory (as examples) used in the execution of program instructions. Memory 604 may include, for example, caches, such as shared caches, which may be coupled to the local cache of processor 602 (examples include L1 cache, L2 cache, etc.). Additionally, memory 604 may be or include at least one computer program product having a set (e.g., at least one) of program modules, instructions, code, etc., configured to perform the functions of the embodiments described herein when executed by one or more processors.

[0065] Memory 604 may store operating system 605 and other computer programs 606, such as one or more computer programs / applications that execute to perform the aspects described herein. Specifically, the program / application may include computer-readable program instructions that can be configured to perform the functionality of embodiments of the aspects described herein.

[0066] Examples of I / O devices 608 include, but are not limited to, microphones, speakers, GPS devices, cameras, lights, accelerometers, gyroscopes, magnetometers, sensor devices configured to sense light, proximity, heart rate, body and / or ambient temperature, blood pressure, and / or skin resistance, and activity monitors. As shown, I / O devices may be incorporated into a computer system, but in some embodiments, I / O devices may be considered as external devices (612) coupled to the computer system via one or more I / O interfaces 610.

[0067] Computer system 600 can communicate with one or more external devices 612 via one or more I / O interfaces 610. Example external devices include a keyboard, pointing device, display, and / or any other device that enables a user to interact with computer system 600. Other example external devices include any device that enables computer system 600 to communicate with one or more other computing systems or peripheral devices such as printers. A network interface / adapter is an exemplary I / O interface that enables computer system 600 to communicate with one or more networks, such as a local area network (LAN), a general wide area network (WAN), and / or a public network (e.g., the Internet), thereby providing communication with other computing devices or systems, storage devices, etc. Ethernet-based interfaces (e.g., Wi-Fi) and Bluetooth are also possible. The adapter is merely an example of the types of network adapters currently available for use in computer systems (BLUETOOTH is a registered trademark of the Bluetooth SIG, located in Kirkland, Washington, USA).

[0068] Communication between I / O interface 610 and external device 612 can occur across wired and / or wireless communication links 611 (such as wired or wireless connections based on Ethernet). Example wireless connections include cellular, Wi-Fi, proximity-based, near-field, or other types of wireless connections. More generally, one or more communication links 611 can be any suitable wireless and / or wired communication link used for transmitting data.

[0069] Specific external device 612 may include one or more data storage devices that can store one or more programs, one or more computer-readable program instructions, and / or data, etc. Computer system 600 may include and / or be coupled to and communicate with removable / non-removable, volatile / non-volatile computer system storage media (e.g., as an external device of the computer system). For example, it may include and / or be coupled to non-removable, non-volatile magnetic media (commonly referred to as a "hard disk drive"), a disk drive for reading from and writing to a removable, non-volatile magnetic disk (e.g., a "floppy disk"), and / or an optical disk drive for reading from or writing to a removable, non-volatile optical disk (such as a CD-ROM, DVD-ROM, or other optical media).

[0070] Computer system 600 can operate with many other general-purpose or special-purpose computing system environments or configurations. Computer system 600 can take any of a variety of forms, well-known examples of which include, but are not limited to, personal computer (PC) systems, server computer systems (such as message servers), thin clients, fat clients, workstations, laptop computers, handheld devices, mobile devices / computers such as smartphones, tablet computers, and wearable devices, multiprocessor systems, microprocessor-based systems, telephone equipment, network appliances (such as edge appliances), virtualization devices, storage controllers, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and distributed cloud computing environments that include any of the above systems or devices.

[0071] It should be understood that although this disclosure includes a detailed description of cloud computing, the implementation of the teachings set forth herein is not limited to a cloud computing environment. Rather, embodiments of the invention can be implemented in conjunction with any other type of computing environment now known or developed hereafter.

[0072] Cloud computing is a service delivery model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with service providers. This cloud model may include at least five features, at least three service models, and at least four deployment models.

[0073] The characteristics are as follows:

[0074] On-demand self-service: Cloud consumers can unilaterally and automatically provide computing power, such as server time and network storage, as needed, without requiring manual interaction with the service provider.

[0075] Wide Area Network (WAN) Access: Capabilities are available on the network and accessed through standard mechanisms that facilitate the use of heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs).

[0076] Resource pooling: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, where different physical and virtual resources are dynamically allocated and reallocated based on demand. Location independence has significance because consumers typically do not control or know the exact location of the resources provided, but can specify the location at a higher level of abstraction (e.g., country, state, or data center).

[0077] Rapid Flexibility: In some cases, the ability to scale outwards and inwards quickly and flexibly can be provided. For consumers, the available capacity often appears unlimited and can be purchased in any quantity at any time.

[0078] Measurement services: Cloud systems automatically control and optimize resource usage by leveraging metering capabilities at a level of abstraction appropriate to the service type (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both the providers and consumers of the services being utilized.

[0079] The service model is as follows:

[0080] Software as a Service (SaaS): The capability offered to consumers is the ability to use the provider's applications running on cloud infrastructure. Applications can be accessed from various client devices through thin client interfaces such as web browsers (e.g., web-based email). Consumers do not manage or control the underlying cloud infrastructure, including the network, servers, operating system, storage, or even individual application capabilities, with possible exceptions such as limited user-specific application configuration settings.

[0081] Platform as a Service (PaaS): This provides consumers with the ability to deploy consumer-created or acquired applications onto cloud infrastructure using programming languages ​​and tools supported by the provider. Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but they have control over the deployed applications and the configuration of any application hosting environments.

[0082] Infrastructure as a Service (IaaS): This provides consumers with the capability to deliver processing, storage, networking, and other basic computing resources that enable them to deploy and run arbitrary software, which may include operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but they do have control over the operating system, storage, deployed applications, and possibly limited control over selected networking components (e.g., host firewalls).

[0083] The deployment model is as follows:

[0084] Private cloud: Cloud infrastructure operated solely by an organization. It can be managed by the organization or a third party and can exist inside or outside a building.

[0085] Community cloud: Cloud infrastructure shared by several organizations and supporting a specific community with shared concerns (e.g., tasks, security requirements, policies, and compliance considerations). It can be managed by an organization or a third party and can exist on-site or off-site.

[0086] Public cloud: Cloud infrastructure available to the general public or large industrial groups and owned by organizations that sell cloud services.

[0087] Hybrid cloud: A cloud infrastructure is a combination of two or more clouds (private, community, or public) that remain a single entity but are bound together by standardized or proprietary technologies that enable data and applications to be ported together (e.g., cloud bursting for load balancing between clouds).

[0088] Cloud computing environments are service-oriented, focusing on statelessness, loose coupling, modularity, and semantic interoperability. At the heart of cloud computing is the infrastructure of a network of interconnected nodes.

[0089] Now for reference Figure 7The illustration depicts a cloud computing environment 50. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 that can communicate with local computing devices used by cloud consumers, such as personal digital assistants (PDAs) or cellular phones 54A, desktop computers 54B, laptop computers 54C, and / or automotive computer systems 54N. The nodes 10 can communicate with each other. They can be physically or virtually grouped (not shown) in one or more networks, such as private clouds, community clouds, public clouds, or hybrid clouds, or combinations thereof, as described above. This allows the cloud computing environment 50 to provide infrastructure, platform, and / or software as a service, without requiring cloud consumers to maintain resources on their local computing devices. It should be understood that... Figure 7 The types of computing devices 54A-N shown are for illustrative purposes only, and computing node 10 and cloud computing environment 50 can communicate with any type of computerized device on any type of network and / or network-addressable connection (e.g., using a web browser).

[0090] Now for reference Figure 8 This demonstrates a cloud computing environment of 50 ( Figure 7 This provides a set of functional abstractions. It should be understood beforehand that... Figure 8 The components, layers, and functions shown are for illustrative purposes only, and embodiments of the invention are not limited thereto. As depicted, the following layers and corresponding functions are provided:

[0091] The hardware and software layer 60 includes hardware and software components. Examples of hardware components include: a host 61; a server 62 based on a RISC (Reduced Instruction Set Computer) architecture; a server 63; a blade server 64; a storage device 65; and a network and network components 66. In some embodiments, software components include network application server software 67 and database software 68.

[0092] The virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual server 71; virtual storage 72; virtual network 73, including virtual private network; virtual application and operating system 74; and virtual client 75.

[0093] In one example, management layer 80 can provide the following functionalities: Resource Provisioning 81 provides dynamic procurement of computing resources and other resources used to perform tasks within the cloud computing environment. Metering and Pricing 82 provides cost tracking when utilizing resources in the cloud computing environment, as well as billing or invoicing for consuming these resources. In one example, these resources may include application software licenses. Security provides authentication for cloud consumers and tasks, and protection for data and other resources. User Portal 83 provides access to the cloud computing environment for consumers and system administrators. Service Level Management 84 provides cloud resource allocation and management to ensure that required service levels are met. Service Level Agreement (SLA) Planning and Fulfillment 85 provides pre-scheduling and procurement of cloud resources, where future needs are anticipated according to the SLA.

[0094] Workload layer 90 provides examples of functionalities that can be leveraged in a cloud computing environment. Examples of workloads and functionalities that can be provided from this layer include: mapping and navigation 91; software development and lifecycle management 92; virtual classroom education delivery 93; data analytics and processing 94; transaction processing 95; and messaging delivery in cellular roaming scenarios 96.

[0095] This invention can be a system, method, and / or computer program product at any possible level of technical detail integration. The computer program product may include a computer-readable storage medium (or media) having computer-readable program instructions thereon for causing a processor to perform aspects of the invention.

[0096] Computer-readable storage media can be tangible devices capable of retaining and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example, but not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable optical disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices such as punch cards or recessed structures with instructions recorded thereon, and any suitable combination of the foregoing. As used herein, computer-readable storage media should not be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.

[0097] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a suitable computing / processing device, or via a network, such as the Internet, a local area network (LAN), a wide area network (WAN), and / or a wireless network, to an external computer or external storage device. The network may include copper cables, optical fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to a computer-readable storage medium within the respective computing / processing device.

[0098] Computer-readable program instructions used to perform the operations of this invention may be assembly instructions, instruction set architecture (ISA) instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, integrated circuit configuration data, or source code or object code written in any combination of one or more programming languages ​​(including object-oriented programming languages ​​such as Smalltalk, C++, etc.) and procedural programming languages ​​(such as the "C" programming language or similar programming languages). The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, to perform aspects of this invention, electronic circuits, including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), may execute computer-readable program instructions to personalize the electronic circuits by utilizing the status information of the computer-readable program instructions.

[0099] Various aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0100] These computer-readable program instructions may be provided to a processor of a computer or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / actions specified in one or more blocks of a flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer, programmable data processing apparatus, and / or other devices to operate in a particular manner, such that the computer-readable storage medium in which the instructions are stored includes an article of writing comprising instructions for implementing aspects of the functions / actions specified in one or more blocks of a flowchart and / or block diagram.

[0101] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer-implemented process, such that the instructions, which execute on the computer, other programmable apparatus or other device, perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0102] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions comprising one or more executable instructions for implementing a specified logical function. In some alternative embodiments, the functions indicated in the blocks may occur in a different order than indicated in the figures. For example, two blocks shown consecutively may actually be implemented as a single step, executed simultaneously, substantially simultaneously, with partial or complete time overlap, or these blocks may sometimes be executed in reverse order, depending on the functions involved. It will also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by a dedicated hardware-based system that performs the specified function or action or executes a combination of dedicated hardware and computer instructions.

[0103] In addition to the above, one or more aspects such as providing customer environment management can be provided, deployed, managed, and serviced by a service provider. For example, a service provider can create, maintain, support, etc., the computer code and / or computer infrastructure that performs one or more aspects for one or more customers. In return, the service provider can receive payments from customers, for example, under subscription and / or fee agreements. Alternatively or alternatively, the service provider can receive payments from selling advertising content to one or more third parties.

[0104] In one aspect, an application can be deployed to execute one or more embodiments. As an example, application deployment includes providing computer infrastructure operable to execute one or more embodiments.

[0105] On the other hand, computing infrastructure can be deployed, including integrating computer-readable code into a computing system, wherein the code combined with the computing system is capable of executing one or more embodiments.

[0106] As another aspect, a process for integrating computing infrastructure can be provided, including integrating computer-readable code into a computer system. The computer system includes a computer-readable medium, wherein the computer medium includes one or more embodiments. The code integrated with the computer system is capable of executing one or more embodiments.

[0107] Although various embodiments have been described above, these are merely examples.

[0108] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting. As used herein, the singular forms “a,” “an,” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that the terms “comprising” and / or “including” as used in this specification specify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0109] If present, all means or steps plus functional elements in the following claims are intended to include corresponding structures, materials, actions, and equivalents for performing functions in combination with other claimed elements of the particular claim. Descriptions of one or more embodiments have been presented for purposes of illustration and description, but such description is not intended to be exhaustive or limited to the forms disclosed. Many modifications and variations will be apparent to those skilled in the art. The embodiments were chosen and described in order to best explain various aspects and practical applications, and to enable others skilled in the art to understand the various embodiments with various modifications suitable for the particular intended use.

Claims

1. A computer-implemented method, comprising: A transaction is initiated between a user equipment (UE) located at a remote location and activated by a remote telecommunications service provider (TSP) and a remote application server. The TSP provides roaming cellular service to the UE at the remote location via its cellular network. The transaction requires receiving a transaction text message from the remote application server for use with the UE, based on user authentication delivered to the user's mobile device via a cellular network connection. The UE is also activated using a home telecommunications service provider (TSP), which provides cellular service to the UE at its home location on the home TSP's cellular network using a home cellular number provided by the home TSP. The transaction text message is received by the home TSP from the remote application server and will be sent by the home TSP to the UE via the remote TSP. The attributing TSP encrypts the transaction text message received from the remote application server to generate an encrypted transaction text message; and The home TSP forwards the encrypted transaction text message to the remote TSP, so that it can be delivered as a Short Message Service (SMS) text message via the remote TSP's cellular network to the user equipment at the remote location.

2. The method of claim 1, further comprising using one or more shared secrets shared between the home TSP and the user to obtain at least one encryption key, wherein the transaction text message is encrypted using the at least one encryption key.

3. The method of claim 2, further comprising triggering the expiration of the one or more shared secrets, wherein, Based on the expiration date, the home TSP prohibits the use of the one or more shared secrets when encrypting subsequent messages to be forwarded to the user equipment.

4. The method of claim 3, wherein the expiration is triggered by at least one selected from the group consisting of: (i) a time-based triggering that causes the one or more shared secrets to expire based on the elapsed amount of a defined time, (ii) a location-based triggering that causes the one or more shared secrets to expire based on the user equipment moving out of a geographic boundary, and (iii) a push-based triggering that causes the one or more shared secrets to expire based on receiving an expiration indication from a trusted source.

5. The method of claim 1, wherein the user equipment is assigned a roaming cellular number by the remote TSP, and the encrypted transaction text message is forwarded by the home TSP to the remote TSP for delivery to the user equipment via the roaming cellular number assigned by the remote TSP.

6. The method of claim 5 further includes, prior to the initiation of the transaction, pre-establishing a communication path for transaction message communication between the home TSP and the remote TSP, wherein the home TSP sends a test message to the remote TSP for delivery to the user equipment via the roaming cellular number.

7. The method of claim 5, further comprising registering the roaming cellular number with the home TSP as an active secondary number to establish a link between the home cellular number and the roaming cellular number, wherein the registration is based on the user authenticating with the home TSP and securely registering the roaming cellular number thereto, and wherein the forwarding includes sending the encrypted transaction text message to the roaming cellular number.

8. The method of claim 7, further comprising triggering the expiration of the registration period for the roaming cellular number as an activated secondary number, wherein, Based on the expiration of this period, the roaming cellular number is prohibited from being used when forwarding messages to the user equipment.

9. The method of claim 8, wherein the expiration is triggered by at least one selected from the group consisting of: (i) a time-based triggering that causes the registration period to expire based on the elapsed amount of a defined time, (ii) a location-based triggering that causes the registration period to expire based on the user equipment moving out of a geographic boundary, and (iii) a push-based triggering that causes the registration period to expire based on receiving an expiration indication from a trusted source.

10. The method of claim 5, further comprising: Generate a first shared secret and provide the first shared secret to the user; Receive a second shared secret from the user; Use the first shared secret to obtain one or more first encryption keys; as well as The second shared secret is used to obtain a second or more encryption keys, wherein the transaction text message is encrypted using the first or more encryption keys and the second or more encryption keys to perform layered encryption on the transaction text message to produce an encrypted transaction text message for forwarding.

11. The method according to claim 1, wherein, The home cellular number is registered with the remote TSP for international roaming, wherein the remote TSP uses the home cellular number when transmitting messages to the user equipment at the remote location, and wherein the method further includes: Generate a shared secret and provide the shared secret to the user; and The shared secret is used to obtain at least one encryption key, wherein the transaction text message is encrypted using the at least one encryption key.

12. The method of claim 1, wherein the transaction text message includes a time-sensitive one-time password provided by the user to the remote application server for multi-factor authentication of the user to execute the transaction.

13. A computer system, comprising: Memory; as well as A processor communicating with the memory, wherein the computer system is configured to perform the method as described in any one of claims 1-12.

14. A computer program product comprising program code that can be read by and executed by a processing circuit to perform the method as claimed in any one of claims 1-12.

Citation Information

Patent Citations

  • Authenticating a wireless device in a visited network

    US20090282251A1

  • System and method for mobile telephone roaming

    US20200236549A1