Application access control
By generating and verifying tokens on mobile terminals and using the mobile network as a secure access server, the complex and inconvenient existing application access methods are solved, and secure and convenient application access and data protection are achieved.
Patent Information
- Application Number
- CN202411964606.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2018-05-18
- Publication Date
- 2025-06-10
AI Technical Summary
The existing application access method is complex and inconvenient, requiring multiple authentication steps, relying on an Internet connection, username and password are easily leaked, and the one-time token device is not portable.
By generating and verifying tokens on mobile terminals, using the mobile network as a secure access server, deciding whether to allow access to applications is simplified to provide only the tokens generated by the device to reduce dependence on Internet connections and additional software.
It realizes secure and convenient application access, reduces user burden, is suitable for anywhere and time, and enhances the security and location-independent of application data.
Smart Images

Figure CN120128356A_ABST
Abstract
Description
Technical Field
[0001] This concept relates to nodes of a network and a method of operating such nodes to permit access to an application program. Background Art
[0002] There are currently many types of application programs (or "apps" or "applications"). Some examples of application programs include web applications, mobile applications, communication applications, database applications, word processing applications, drawing applications, and image editing applications. The demand for application programs is increasing, and since application programs often need to access data and also permit storage of data, application program security is important. Thus, most application programs require a user to log in to access the application program. There are currently various methods by which a user can log in to an application program to securely access and store data. These methods involve techniques for checking that the user is authenticated and authorized to access and / or store data via the application program.
[0003] In the simplest of these methods, a username and password are used together by the user to securely log in to an application program. However, the increase in digital crime has meant that there is an increasing need for more secure methods to permit access to an application program. Examples of more secure methods are methods that involve multi-factor authentication (e.g., two-factor authentication). Multi-factor authentication requires not only the use of a username and password during the login process, but also another piece of information that the user knows or is able to retrieve. The other piece of information is typically a one-time token, such as a one-time password (e.g., a random verification code) or a one-time password (OTP). In some cases, a mobile terminal is used to retrieve the other piece of information. For example, an application program can be used on a mobile terminal to generate a one-time token, which can then be presented directly to the user or sent to the user via short message service (SMS). The mobile terminal used during the authentication and authorization process is typically a mobile phone or a dedicated mobile authentication device (such as a random reader).
[0004] Thus, there are some authentication and authorization processes that combine the security of strong two-factor authentication with the convenience, simplicity, and ease of use of one-time passwords. However, while these existing processes can provide improved security, there are still various disadvantages associated with them. One disadvantage is that multiple authentication steps are required, since the user must first enter a username and password, and then also another piece of information. Thus, the existing processes can be complex or extensive, and are therefore inconvenient and time-consuming for the user. In addition, the fact that a username and password are still required can cause difficulties for users, since they need to remember and also update their username and password to maintain security. Usernames and passwords also have a tendency to be compromised or vulnerable, which means that security breaches are far more feasible.
[0005] In addition, in some existing processes, an Internet connection is required, which may not always be available or secure. Therefore, processes that require an Internet connection or involve Short Message Service (SMS) often fail when the user is roaming. Existing processes are also limited to the user rather than the combination of the user and the mobile terminal. In addition, in a multi-factor authentication process, a one-time token or a device capable of generating a one-time token is always required to be at hand. In some cases, additional software (such as a mobile application) is required to generate the one-time token.
[0006] Therefore, there is a need for an improved way of allowing access to an application that overcomes at least some of these disadvantages. SUMMARY OF THE INVENTION
[0007] The aim is to exclude or eliminate at least some of the above disadvantages associated with the existing methods and thus provide an improved way of allowing access to an application.
[0008] Accordingly, in one aspect, there is provided a method of operating a node of a network. The method includes: receiving, from a device in which an application is stored, a first token generated by the device in response to a request from a user to access the application; and receiving a second token, the second token being input by the user at a mobile terminal of a mobile network in response to a request for the user to input the first token generated by the device. The method further includes: determining whether to allow the user to access the application stored in the device based on a verification of whether the second token matches the first token and whether the user has a subscription to the application. The method further includes: transmitting an indication of the decision as to whether to allow the user to access the application to the device.
[0009] Thus, the concept provides an improved way of allowing access to an application. The concept advantageously provides a secure authorization system by leveraging the security of the mobile network. Effectively, the mobile network can be used as a secure access server to determine whether to allow access to an application. By using the mobile network, the concept provides authentication (through verification) and authorization (by determining whether to allow access based on the verification). In this way, access to the application will be limited to authenticated users, which improves the security of the data used or stored in the application.
[0010] In addition, the user can obtain access to an application to which the user has a subscription in a simple and efficient manner using the mobile terminal, because the user only needs to provide a token generated by the device in which the application is stored. In this way, the burden on the user is reduced as no username or password is required. In addition, the concept provides more convenience to the user as no Internet connection is required and thus the concept can be used anywhere and at any time (such as when the user is roaming). Moreover, the user does not have to install additional software or applications.
[0011] In some embodiments, the method may include: determining to allow a user to access an application if a second token matches a first token and the user has a subscription for the application. In some embodiments, the method may include: determining to deny the user access to the application if the second token does not match the first token and / or the user does not have a subscription for the application. In this way, it is possible to securely control access to the application. In this way, it is possible to accurately and reliably provide access to a particular application only to those users who are authorized to have such access to the particular application. Accordingly, data used in or stored by the application is more secure. Further, since access to the application is allowed by using a mobile network as a secure access server, it is possible for the application to be logged out also via the mobile network. As such, a user can log out of a particular application or all applications regardless of their location.
[0012] In some embodiments, verifying whether a user has a subscription for an application may include: verifying whether a user has a subscription for the application by using a database operable to store or retrieve subscription data of a mobile terminal. In this way, the full capabilities of the mobile network are advantageously used for verification. For example, by using a subscription database for verification (which is operable to store or retrieve subscription data of a mobile terminal), it is possible to securely and reliably check whether a user is allowed access to the application. Further, using a subscription database means it is possible to provide different levels of authorization to users for certain applications, and / or to give a user a temporary guest account (e.g., with basic rights) to access the application, all in a secure manner.
[0013] In some embodiments, the method may further include receiving a mobile number of a mobile terminal by which a user inputs a second token. In some embodiments, verification of whether a user has a subscription for an application may be based on the received mobile number of the mobile terminal.
[0014] In some embodiments, the method may further include receiving any one or more of the following: an identity of an application and an identity of a session running on the application, wherein a request from the user may be for access to a session running on the application. In this way, if a user is allowed access to the application, the user can later log out of the application and / or stop a session running on the application without the user being behind a device (e.g., a computer or an Internet terminal).
[0015] In some embodiments, the method may further include storing any one or more of the following in a database operable to store or retrieve subscription data of the mobile terminal: a first token, an identification of the application, and an identification of a session running on the application.
[0016] In some embodiments, a second token may be received via a mobile network and / or an application server.
[0017] In some embodiments, the second token may be input by the user at the mobile terminal while dialing a predefined number at the mobile terminal.
[0018] In some embodiments, the first token may be received as a Hypertext Transfer Protocol request.
[0019] In some embodiments, the first token may be randomly generated by the device. In this way, security can be further enhanced.
[0020] According to another aspect of the concept, a node of a network is provided. The node includes a processing circuit operable to: receive, from a device in which an application is stored, a first token generated by the device in response to a request from a user to access the application; and receive a second token, the second token being input by the user at a mobile terminal of the mobile network in response to a request for the user to input the first token generated by the device. The processing circuit is further operable to determine whether to allow the user to access the application stored in the device based on a verification of whether the second token matches the first token and whether the user has a subscription to the application. The processing circuit is further operable to convey an indication of the decision of whether to allow the user to access the application to the device. Thus, this aspect provides the advantages discussed above for the method of operating a node of a network.
[0021] According to another aspect of the concept, a method of operating a device in which an application is stored is provided. The method includes: generating a first token in response to a request from a user to access the application, and transmitting the first token to a node of a network for use by the node in determining whether to allow the user to access the application. The method further includes: receiving an indication of the decision of whether to allow the user to access the application from the node. Thus, this aspect provides the advantages discussed above for the method of operating a node of a network.
[0022] According to another aspect of the concept, there is provided an apparatus in which an application program is stored. The apparatus includes processing circuitry operable to generate a first token in response to a request from a user to access the application program. The processing circuitry is further operable to transmit the first token to a node of a network for use by the node in determining whether to permit the user to access the application program, and to receive an indication of a decision as to whether to permit the user to access the application program from the node. Thus, this aspect provides the advantages discussed above with respect to the method of operating a node of a network.
[0023] According to another aspect of the concept, there is provided a method of operating a mobile terminal of a mobile network. The method includes: receiving a second token, the second token being input at the mobile terminal by the user in response to a request for the user to input a first token generated by an apparatus in which an application program is stored; and transmitting the received second token to a node of the network for use by the node in determining whether to permit the user to access the application program. Thus, this aspect provides the advantages discussed above with respect to the method of operating a node of a network.
[0024] In some embodiments, the second token may be input by the user at the mobile terminal while dialing a predefined number at the mobile terminal. In this way, accessing the application program is faster and more convenient. Further, since the number to be dialed is predefined, any risk of providing an incorrect number is eliminated.
[0025] In some embodiments, the method may include transmitting the received second token to a node of the network via the mobile network and / or an application server.
[0026] According to another aspect of the concept, there is provided a mobile terminal of a mobile network. The mobile terminal includes processing circuitry operable to receive a second token, the second token being input at the mobile terminal by the user in response to a request for the user to input a first token generated by an apparatus in which an application program is stored; and to transmit the received second token to a node of the network for use by the node in determining whether to permit the user to access the application program. Thus, this aspect provides the advantages discussed above with respect to the method of operating a node of a network.
[0027] According to another aspect of the concept, there is provided a method of operating an application server of a network. The method includes receiving, from a mobile terminal of a mobile network, a second token input by the user at the mobile terminal, where the second token is input by the user in response to a request for the user to input a first token generated by an apparatus in which an application program is stored. The method further includes transmitting the second token to a node of the network for use by the node in determining whether to permit the user to access the application program. Thus, this aspect provides the advantages discussed above with respect to the method of operating a network node.
[0028] In some embodiments, the method may further include receiving a mobile number of a mobile terminal input by a user into a second token, and transmitting the mobile number of the mobile terminal to a node of the network. In some embodiments, the mobile number of the mobile terminal may be transmitted to a node of the network for use in verifying whether the user has a subscription to the application.
[0029] In some embodiments, the first token can be transmitted as a hypertext transfer protocol request. In this way, there is no need to obtain proprietary protocols or vendor-specific details, which allows faster access to applications in a simple manner.
[0030] According to another aspect of the concept, an application server of a network is provided. The application server includes a processing circuit operable to receive a second token input by a user at the mobile terminal from a mobile terminal of the mobile network, wherein the second token is input by the user in response to a request for the user to input a first token generated by a device in which an application is stored. The processing circuit is also operable to transmit the second token to a node of the network for use by the node in deciding whether to allow access to the application. Thus, this aspect provides the advantages discussed above with respect to the method of operating a network node.
[0031] According to another aspect of the concept, a network is provided, the network comprising any one or more of the node as described above, the application as described above, the mobile terminal as described above, the mobile network and the application server as described above. Therefore, this aspect provides the advantages discussed above for the method of operating a network node.
[0032] According to another aspect of the concept, there is provided a computer program product comprising a carrier containing instructions for causing a processing circuit to perform the aforementioned method. Hence, this aspect provides the advantages discussed above with respect to the method of operating a network node.
[0033] Thus, an improved method of allowing access to an application is provided. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] In order to better understand this concept, and to show how it may be put into effect, reference will now be made, by way of example, to the accompanying drawings, in which: Figure 1 is a block diagram illustrating an embodiment of an apparatus; Figure 2 is a flow chart illustrating a method of operating a device according to an embodiment; Figure 3 is a block diagram illustrating an embodiment of a mobile terminal; Figure 4 is a flowchart illustrating a method of operating a mobile terminal according to an embodiment; Figure 5 is a block diagram of an embodiment of an illustrated application server; Figure 6 is a flowchart of a method of operating an application server according to an embodiment; Figure 7 is a block diagram of an embodiment of an illustrated node; Figure 8 is a flowchart of a method of operating a node according to an embodiment; Figure 9 is a block diagram of an embodiment of an illustrated network; Figure 10 is a signaling diagram of signal exchange in an embodiment of an illustrated network; Figure 11 is a block diagram of an apparatus and a mobile terminal in use according to an embodiment; Figure 12 is a block diagram of an embodiment of an illustrated apparatus; Figure 13 is a block diagram of an embodiment of an illustrated mobile terminal; Figure 14 is a block diagram of an embodiment of an illustrated application server; and Figure 15 is a block diagram of an embodiment of an illustrated node. DETAILED DESCRIPTION
[0035] Accordingly, an improved way of allowing access to application programs is described herein. Herein, an application program can be any type of application program. For example, an application program can include any program operable to perform functions for a user of the application program. An application program may also be referred to as an "application" or an "app" in the art. Examples of application programs include, but are not limited to, World Wide Web (or Internet) application programs, mobile application programs, communication application programs, database application programs, word processing application programs, drawing application programs, image editing application programs, or any other application program.
[0036] Figure 1 Illustrates apparatus 10 according to an embodiment. As Figure 1As shown, the apparatus 10 stores an application program 12. The apparatus 10 can be any apparatus in which the application program 12 is stored. Examples of the apparatus 10 include but are not limited to a computer, a tablet, a smart phone, or any other apparatus 10 in which the application program 12 is stored. The application program 12 stored in the apparatus 10 can take the form of software that can be downloaded onto the apparatus 10 from a remote location (e.g., an application store accessible via the Internet) or pre-installed on the apparatus 10 (e.g., during the manufacture of the apparatus 10 or during the initial setup or configuration process of the apparatus 10). Alternatively, the functional performance of the application program 12 is implemented in hardware, or implemented as a hybrid of hardware and software / firmware. The application program 12 can alternatively be referred to as a software instance, a virtual appliance, a network function, a virtual node, a virtual network function, etc. In fact, the apparatus 10 is a virtualization environment of the application program 12, which provides hardware (e.g., processing circuitry and optional memory) to run the application.
[0037] As Figure 1 shown, the apparatus 10 includes processing circuitry (or logic) 14. The processing circuitry 14 of the apparatus 10 controls the operation of the apparatus 10 and can implement the methods described herein with respect to the apparatus 10. The processing circuitry 14 of the apparatus 10 can include one or more processors, processing units, multi-core processors, or modules configured or programmed to control the operation of the apparatus 10 in the manner described herein. In a particular implementation, the processing circuitry 14 of the apparatus 10 can include a plurality of software and / or hardware modules, each configured to perform or for performing respective or multiple steps of the methods disclosed herein with respect to the apparatus 10.
[0038] In short, the processing circuitry 14 of the apparatus is operable to generate a first token in response to a request from a user to access the application program 12, transmit the first token to a node of the network for use by the node in determining whether to allow the user to access the application program 12, and receive an indication of a decision as to whether to allow the user to access the application program 12 from the node. Herein, according to some embodiments, the first token can be a code. In some embodiments, the code can include one or more words, one or more letters, one or more numbers, and / or one or more symbols.
[0039] As Figure 1As shown, in some embodiments, device 10 may optionally include a memory 16. The memory 16 of device 10 can be connected to the processing circuit 14 of device 10. In some embodiments, the memory 16 of device 10 may be configured to store program code or instructions that can be executed by the processing circuit 14 of device 10 to perform the methods described herein with respect to device 10. Alternatively or additionally, the memory 16 of device 10 can be configured to store any requests, tokens, information, data, signals, etc. described herein. The processing circuit 14 of device 10 can be configured to control the memory 16 of device 10 to store any requests, tokens, information, data, signals, etc. described herein.
[0040] The memory 16 of device 10 can include volatile memory or non-volatile memory. In some embodiments, the memory 16 of device 10 may include non-transitory media. Examples of the memory 16 of device 10 include but are not limited to random access memory (RAM), read-only memory (ROM), mass storage media such as a hard disk, removable storage media such as a compact disc (CD) or a digital versatile disc (DVD), and / or any other memory.
[0041] In some embodiments, as Figure 1 shown, device 10 may optionally include a communication interface 18. The communication interface 18 of device 10 can be connected to the processing circuit 14 of device 10. The communication interface 18 of device 10 can be operable to communicate with other nodes (such as any one or more of the following: nodes of a network, one or more databases, one or more mobile terminals, one or more application servers, or any other nodes, or any combination of other nodes). For example, the communication interface 18 of device 10 can be configured to transmit to and / or receive from other nodes requests, tokens, information, data, signals, etc. The processing circuit 14 of device 10 can be configured to control the communication interface 18 of device 10 to transmit to and / or receive from other nodes requests, resources, information, data, signals, etc.
[0042] It will be understood that Figure 1 only the components necessary to illustrate an embodiment of device 10 are shown, and in an actual implementation, device 10 may include additional or alternative components to the shown components.
[0043] Figure 2 is a flowchart illustrating a method of operating device 10 in which an application program 12 is stored. Figure 2 The method of can be executed or performed under the control of the processing circuit 14 of device 10. Referring to Figure 2 , at block 102, a first token is generated in response to a request from a user to access the application program 12. In some embodiments, the first token can be randomly generated.
[0044] At block 104, a first token is transmitted to a node of the network for use by the node in determining whether to allow a user to access application 12. In some embodiments, the first token may be transmitted as a Hypertext Transfer Protocol (HTTP) request. In some embodiments, one or more of an identification of application 12 and an identification of a session running on application 12 may also be transmitted to the node of the network.
[0045] At block 106, an indication of a decision as to whether to allow the user to access application 12 is received from the node. The indication may be an indication of a decision to allow the user to access application 12. In this case, device 10 may be operable to allow the user to access application 12. On the other hand, the indication may be an indication of a decision to deny the user access to application 12. In this case, device 10 may be operable to deny the user access to application 12.
[0046] Figure 3 A mobile terminal 20 of a mobile network according to an embodiment is illustrated. Mobile terminal 20 may be any type of mobile terminal. Examples of mobile terminals include, but are not limited to, mobile devices (such as mobile phones, smart phones, smart watches, tablets, or any other mobile device) or any other mobile terminal.
[0047] As Figure 3 shown, mobile terminal 20 includes processing circuitry (or logic) 24. The processing circuitry 24 of mobile terminal 20 controls the operation of mobile terminal 20 and can implement the methods described herein with respect to mobile terminal 20. The processing circuitry 24 of mobile terminal 20 can include one or more processors, processing units, multi-core processors, or modules configured or programmed to control the operation of mobile terminal 20 in the manner described herein. In a particular implementation, the processing circuitry 24 of mobile terminal 20 can include multiple software and / or hardware modules, each configured to perform or for performing respective or multiple steps of the methods disclosed herein with respect to mobile terminal 20.
[0048] Briefly, the processing circuitry 24 of mobile terminal 20 is operable to receive a second token input at mobile terminal 20 by the user in response to a request for the first token generated by device 10 in which application 12 is stored; and transmit the received second token to a node of the network for use by the node in determining whether to allow the user to access application 12. Herein, according to some embodiments, the second token may be a code. In some embodiments, the code may include one or more words, one or more letters, one or more numbers, and / or one or more symbols.
[0049] As Figure 3As shown, in some embodiments, the mobile terminal 20 may optionally include a memory 26. The memory 26 of the mobile terminal 20 can be connected to the processing circuit 24 of the mobile terminal 20. In some embodiments, the memory 26 of the mobile terminal 20 can be configured to store program code that can be executed by the processing circuit 24 of the mobile terminal 20 to perform the methods described herein with respect to the mobile terminal 20. Alternatively or additionally, the memory 26 of the mobile terminal 20 can be configured to store any requests, tokens, information, data, signals, etc. described herein. The processing circuit 24 of the mobile terminal 20 can be configured to control the memory 26 of the mobile terminal 20 to store any requests, tokens, information, data, signals, etc. described herein.
[0050] The memory 26 of the mobile terminal 20 can include volatile memory or non-volatile memory. In some embodiments, the memory 26 of the mobile terminal 20 can include non-transitory media. Examples of the memory 26 of the mobile terminal 20 include but are not limited to random access memory (RAM), read-only memory (ROM), mass storage media such as a hard disk, removable storage media such as a compact disc (CD) or a digital versatile disc (DVD), and / or any other memory.
[0051] In some embodiments, as Figure 3 shown, the mobile terminal 20 may optionally include a communication interface 28. The communication interface 28 of the mobile terminal 20 can be connected to the processing circuit 24 of the mobile terminal 20. The communication interface 28 of the mobile terminal 20 can be operable to communicate with other nodes (such as any one or more of the following: the device 10 in which the application 12 is stored, nodes of a network, one or more databases, one or more other mobile terminals, one or more application servers, or any other node, or any combination of other nodes). For example, the communication interface 28 of the mobile terminal 20 can be configured to transmit to and / or receive from other nodes requests, tokens, information, data, signals, etc. The processing circuit 24 of the mobile terminal 20 can be configured to control the communication interface 28 of the mobile terminal 20 to transmit to and / or receive from other nodes requests, resources, information, data, signals, etc.
[0052] It should be understood that Figure 3 only the components necessary to illustrate the embodiments of the mobile terminal 20 are shown, and in an actual implementation, the mobile terminal 20 may include additional or alternative components to the shown components.
[0053] Figure 4 is a flowchart illustrating a method of operating a mobile terminal 20 of a mobile network according to an embodiment. Figure 4 The method of can be executed or performed under the control of the processing circuit 24 of the mobile terminal 20. Referring to Figure 4, at block 202, receive a second token input by the user on the mobile terminal 20. The second token is input by the user at the mobile terminal 20 in response to a request for the user to input a first token generated by the device 10 in which the application 12 is stored. In some embodiments, the second token may be input by the user at the mobile terminal 20 while dialing a predefined number at the mobile terminal 20.
[0054] At block 204, transmit the received second token to a node of the network for use by the node in determining whether to allow the user to access the application 12. The method of operating the mobile terminal 20 may include transmitting the received second token directly to a node of the network or indirectly to a node of the network. For example, in some embodiments, the method of operating the mobile terminal 20 may include transmitting the received second token via a mobile network and / or an application server.
[0055] Figure 5 Illustrates an application server 30 of a network according to an embodiment. As Figure 5 shown, the application server 30 includes processing circuitry (or logic) 34. The processing circuitry 34 of the application server 30 controls the operation of the application server 30 and can implement the methods described herein with respect to the application server 30. The processing circuitry 34 of the application server 30 can include one or more processors, processing units, multi-core processors, or modules configured or programmed to control the operation of the application server 30 in the manner described herein. In a particular implementation, the processing circuitry 34 of the application server 30 can include multiple software and / or hardware modules, each configured to perform or for performing each or multiple steps of the methods disclosed herein with respect to the application server.
[0056] In short, the processing circuitry 34 of the application server 30 is operable to receive, from the mobile terminal 20 of the mobile network, a second token input by the user at the mobile terminal 20. The second token is input by the user in response to a request for the user to input a first token generated by the device 10 in which the application 12 is stored. The first token is generated by the device 10 in which the application 12 is stored in response to a request from the user to access the application 12. The processing circuitry 34 of the application server 30 is also operable to transmit the second token to a node of the network for use by the node in determining whether to allow access to the application 12. The application server 30 can be provided in a mobile network (e.g., a mobile telephone network) domain. The application server 30 can be operable to connect the mobile network domain to an information technology (IT) domain.
[0057] As Figure 5As illustrated, in some embodiments, the application server 30 may optionally include a memory 36. The memory 36 of the application server 30 can be connected to the processing circuitry 34 of the application server 30. In some embodiments, the memory 36 of the application server 30 can be configured to store program code executable by the processing circuitry 34 of the application server 30 to perform the methods described herein with respect to the application server 30. Alternatively or additionally, the memory 36 of the application server 30 can be configured to store any requests, tokens, information, data, signals, etc. described herein. The processing circuitry 34 of the application server 30 can be configured to control the memory 36 of the application server 30 to store any requests, tokens, information, data, signals, etc. described herein.
[0058] The memory 36 of the application server 30 can include volatile memory or non-volatile memory. In some embodiments, the memory 36 of the application server 30 can include non-transitory media. Examples of the memory 36 of the application server 30 include, but are not limited to, random access memory (RAM), read-only memory (ROM), mass storage media such as a hard disk, removable storage media such as a compact disc (CD) or digital versatile disc (DVD), and / or any other memory.
[0059] In some embodiments, as Figure 5 illustrated, the application server 30 may optionally include a communication interface 38. The communication interface 38 of the application server 30 can be connected to the processing circuitry 34 of the application server 30. The communication interface 38 of the application server 30 can be operable to communicate with other nodes (such as any one or more of the following: the device 10 in which the application 12 is stored, nodes of a network, one or more databases, one or more mobile terminals 20, one or more other application servers, or any other nodes, or any combination of other nodes). For example, the communication interface 38 of the application server 30 can be configured to transmit to and / or receive from other nodes requests, tokens, information, data, signals, etc. The processing circuitry 34 of the application server 30 can be configured to control the communication interface 38 of the application server 30 to transmit to and / or receive from other nodes requests, resources, information, data, signals, etc.
[0060] It should be understood that Figure 5 only the components necessary to illustrate embodiments of the application server 30 are shown, and in an actual implementation, the application server 30 may include additional or alternative components to those shown.
[0061] Figure 6 is a flowchart illustrating a method of operating the application server 30 according to an embodiment. Figure 6 The method can be executed by or under the control of the processing circuitry 34 of the application server 30.
[0062] Reference Figure 6 , at block 302, receive a second token input by the user at the mobile terminal 20 in the mobile network. As previously described, the second token is input by the user at the mobile terminal 20 in response to a request for the user to input a first token generated by the device 10 storing the application 12 therein. Also as previously described, the first token is generated by the device 10 storing the application 12 therein in response to a request from the user to access the application 12. At block 304, transmit the second token to a node of the network for use by the node in determining whether to allow the user to access the application 12.
[0063] In some embodiments, the method of operating the application server 30 may further include receiving the mobile number of the mobile terminal 20 from which the user inputs the second token. In these embodiments, the method of operating the application server 30 may further include transmitting the mobile number of the mobile terminal 20 to a node of the network. In some embodiments, the mobile number of the mobile terminal 20 is transmitted to a node of the network for use in verifying whether the user has a subscription to the application 12.
[0064] In some embodiments, the application server 30 is operable to provide telecommunications services such as real-time charging, location- and / or time-based filtering, and / or any other telecommunications service(s).
[0065] Figure 7 Illustrates a node 40 of a network according to an embodiment. As Figure 7 shown, the node 40 includes processing circuitry (or logic) 44. The processing circuitry 44 of the node 40 controls the operation of the node 40 and can implement the methods described herein with respect to the node 40. The processing circuitry 44 of the node 40 can include one or more processors, processing units, multi-core processors, or modules configured or programmed to control the operation of the node 40 in the manner described herein. In a particular implementation, the processing circuitry 44 of the node 40 can include multiple software and / or hardware modules, each configured to perform or for performing each or multiple steps of the methods disclosed herein with respect to the node 40.
[0066] In short, the processing circuit 44 of node 40 is operable to receive a first token from device 10 in which application 12 is stored, the first token being generated by device 10 in response to a request from a user to access application 12. The processing circuit 44 of node 40 is further operable to receive a second token, the second token being input by the user at mobile terminal 20 of the mobile network in response to a request to input the first token generated by device 10 in which application 12 is stored. The processing circuit 44 of node 40 is also operable to determine whether to allow the user to access application 12 stored in device 10 based on whether the second token matches the first token and a verification of whether the user has a subscription to application 12. The processing circuit 44 of node 40 is further operable to convey an indication of the decision as to whether to allow the user to access application 12 to device 10.
[0067] Node 40 can be provided in the field of information technology (IT). Node 40 can be operable to connect an information technology (IT) domain to a mobile network domain (e.g., in a mobile telephone network). Thus, in some embodiments, node 40 in the information technology (IT) domain and application server 30 in the mobile network domain can be used to connect these two domains.
[0068] As Figure 7 shown, in some embodiments, node 40 can optionally include a memory 46. The memory 46 of node 40 can be connected to the processing circuit 44 of node 40. In some embodiments, the memory 46 of node 40 can be configured to store program code executable by the processing circuit 44 of node 40 to perform the methods described herein with respect to node 40. Alternatively or additionally, the memory 46 of node 40 can be configured to store any requests, tokens, information, data, signals, etc. described herein. The processing circuit 44 of node 40 can be configured to control the memory 46 of node 40 to store any requests, tokens, information, data, signals, etc. described herein.
[0069] The memory 46 of node 40 can include volatile memory or non-volatile memory. In some embodiments, the memory 46 of node 40 can include non-transitory media. Examples of the memory 46 of node 40 include but are not limited to random access memory (RAM), read only memory (ROM), mass storage media such as hard disks, removable storage media such as compact discs (CDs) or digital video discs (DVDs), and / or any other memory.
[0070] In some embodiments, as Figure 7As shown, node 40 may optionally include a communication interface 48. The communication interface 48 of node 40 can be connected to the processing circuit 44 of node 40. The communication interface 48 of node 40 can be operable to communicate with other nodes (such as any one or more of the following: device 10 in which application 12 is stored, one or more databases, one or more mobile terminals, one or more application servers, or any other node, or any combination of other nodes). For example, the communication interface 48 of node 40 can be configured to transmit to and / or receive from other nodes requests, tokens, information, data, signals, etc. The processing circuit 44 of node 40 can be configured to control the communication interface 48 of node 40 to transmit to and / or receive from other nodes requests, resources, information, data, signals, etc.
[0071] It should be understood that Figure 7 only the components required to illustrate the embodiment of node 40 are shown, and in an actual implementation, node 40 may include additional or alternative components to the shown components.
[0072] Figure 8 is a flowchart illustrating a method of operating node 40 according to an embodiment. Figure 8 The method can be executed or performed under the control of the processing circuit 44 of node 40.
[0073] Referring to Figure 8 , at block 402, a first token is received from device 10 in which application 12 is stored. The first token is generated by device 10 in response to a request from a user to access application 12. As previously described, in some embodiments, the first token may be randomly generated by device 10 in which application 12 is stored. In some embodiments, the first token may be received as a Hypertext Transfer Protocol (HTTP) request. Although not shown in Figure 8 , in some embodiments, the method can further include storing the received first token in a database operable to store or retrieve subscription data of a mobile terminal.
[0074] At block 404, a second token entered by the user at mobile terminal 20 of the mobile network is received. The second token is entered by the user at mobile terminal 20 in response to a request to enter the first token generated by device 10 in which application 12 is stored. According to some embodiments, the second token may be entered by the user at mobile terminal 20 while dialing a predefined number at mobile terminal 20. The second token can be received directly from mobile terminal 20 or indirectly from mobile terminal 20. For example, in some embodiments, the second token can be received from mobile terminal 20 via the mobile network and / or application server 30.
[0075] At block 406, it is determined whether to allow the user to access Application 12 stored in Device 10 based on verification of whether the second token matches the first token and whether the user has a subscription for Application 12.
[0076] In some embodiments, it may be initially verified whether the second token matches the first token, and subsequently verified whether the user has a subscription for Application 12. In some of these embodiments, the verification of whether the user has a subscription for Application 12 may be performed only if it is verified that the second token matches the first token. In a similar manner, in other embodiments, it may be initially verified whether the user has a subscription for Application 12, and subsequently verified whether the second token matches the first token. In some of these embodiments, the verification of whether the second token matches the first token may be performed only if it is verified that the user has a subscription for Application 12. In other embodiments, the verification of whether the second token matches the first token and the verification of whether the user has a subscription for Application 12 may be performed simultaneously, and / or the verification of whether the second token matches the first token and the verification of whether the user has a subscription for Application 12 may be independent of each other.
[0077] In some embodiments, verifying whether the user has a subscription for Application 12 may include: verifying whether the user has a subscription for Application 12 by using a database operable to store or retrieve subscription data of the mobile terminal. In some embodiments, if the second token matches the first token and the user has a subscription for Application 12, then at block 406, it can be determined to allow the user to access Application 12. On the other hand, in some embodiments, if the second token does not match the first token and / or the user does not have a subscription for Application 12, then at block 406, it can be determined to deny the user access to Application 12.
[0078] At block 408, an indication of the decision on whether to allow the user to access Application 12 is transmitted to Device 10.
[0079] Although not shown in Figure 8 In some embodiments, the method of operating Node 40 may further include receiving the mobile number of Mobile Terminal 20 through which the user inputs the second token. In some of these embodiments, the verification of whether the user has a subscription for Application 12 may be based on the received mobile number of Mobile Terminal 20.
[0080] Although in Figure 8Nor is it shown, but in some embodiments, the method of operating node 40 may further include receiving any one or more of an identification of application 12 and an identification of a session running on application 12. In embodiments where an identification of a session running on application 12 is received, the request from the user may be to access the session running on application 12. In some embodiments, as an alternative or addition to storing the received first token in a database operable to store or retrieve reservation data of the mobile terminal, the method of operating node 40 may include storing any one or more of an identification of application 12 and an identification of a session running on application 12.
[0081] Figure 9 FIG. illustrates network 500 according to an embodiment. As Figure 9 shown, network 500 can include device 10 in which application 12 is stored (as previously referenced Figure 1 and 2 described), mobile terminal 20 (as previously referenced Figure 3 and 4 described), mobile network 70 (as previously described), application server 30 (as previously referenced Figure 5 and 6 described) and node 40 (as previously referenced Figure 7 and 8 described), any one or more of them. According to some embodiments, the mobile network 70 mentioned herein may be, for example, a mobile access network.
[0082] As previously mentioned, node 40 can be provided in the information technology (IT) domain. Also as previously mentioned, application server 30 can be provided in the mobile network (e.g., mobile phone network) domain. Thus, in some embodiments, node 40 and application server 30 can be used to connect the information technology (IT) domain and the mobile network domain.
[0083] Figure 10 is a signaling diagram illustrating signal exchange in an embodiment of network 500. Now reference will be made to Figure 9 and 10 to describe the operation of network 500 according to an embodiment.
[0084] Referring to Figure 9 and 10 , as Figure 10 indicated by arrow 602, a first token is generated by device 10 in which application 12 is stored. The first token ("TOKEN 1") is generated by device 10 in response to a request from the user to access application 12. As previously mentioned, in some embodiments, the first token ("TOKEN 1") may be randomly generated. As Figure 9 indicated by arrow 502 and Figure 10As shown by arrow 604, a first token (“TOKEN 1”) is transmitted from device 10 in which application 12 is stored to node 40 of network 500. The first token (“TOKEN 1”) is transmitted for use by node 40 in determining whether to allow a user to access application 12. As previously described, in some embodiments, the first token (“TOKEN 1”) may be transmitted as a Hypertext Transfer Protocol (HTTP) request.
[0085] As Figure 10 shown by arrow 604, in some embodiments, one or more of the identification of application 12 (“ApplicationID”) and the identification of the session running on application 12 (“SessionID”) may also be transmitted from device 10 to node 40 of network 500. The identification of application 12 (“ApplicationID”) is unique to application 12. The identification of the session running on application 12 (“SessionID”) is unique to device 10 in which application 12 is stored.
[0086] As Figure 9 shown by arrows 502 and Figure 10 arrow 604, node 40 of network 500 receives the first token (“TOKEN 1”) from device 10 in which application 12 is stored. In some embodiments, as Figure 10 shown by arrow 604, node 40 of network 500 may also optionally receive one or more of the identification of application 12 (“ApplicationID”) and the identification of the session running on application 12 (“SessionID”) from device 10.
[0087] According to some embodiments, network 500 can include a first Internet Protocol (IP) 50. In these embodiments, as Figure 9 shown by arrow 502, the first token (“TOKEN 1”) and optionally also the identification of application 12 (“ApplicationID”) and / or the identification of the session running on application 12 (“SessionID”) may be transmitted from device 10 having application 12 to node 40 via first IP 50. Thus, in some embodiments, node 40 may receive the first token (“TOKEN 1”) and optionally also the identification of application 12 (“ApplicationID”) and / or the identification of the session running on application 12 (“SessionID”) from device 10 via first IP 50.
[0088] In some embodiments, network 500 may include a database 60 that is operable to store subscription data of a mobile terminal and / or subscription data of a mobile terminal accessible via a home subscriber server (HSS). The subscription data can include, for example, a service list associated with an authorization level of an application. In some of these embodiments, as Figure 9 indicated by arrow 504 of Figure 10 and arrow 606 of
[0089] In some embodiments, as Figure 10 indicated by arrow 608 of
[0090] a first token (“TOKEN 1”), and optionally also an identity of application 12 (“ApplicationID”) and / or an identity of a session running on application 12 (“SessionID”) may be transmitted by node 40 to database 60. Database 60 is operable to store the first token (“TOKEN 1”), and optionally also the identity of application 12 (“ApplicationID”) and / or the identity of a session running on application 12 (“SessionID”). Database 60 may provide a data storage identity (“dataStorageID”) to node 40 of network 500, which is assigned by database 60 to the first token (“TOKEN 1”), and optionally also provides the identity of application 12 (“ApplicationID”) and / or the identity of a session running on application 12 (“SessionID”). In this way, the first token (“TOKEN 1”), and optionally also the identity of application 12 (“ApplicationID”) and / or the identity of a session running on application 12 (“SessionID”) can subsequently be retrieved by node 40 from database 60.The mobile terminal 20 in the mobile network 70 receives a second token (“TOKEN 2”) input by the user. The second token (“TOKEN 2”) is input by the user at the mobile terminal 20 in response to a request for the user to input a first token (“TOKEN 1”) generated by the device 10 in which the application 12 is stored. In some embodiments, the second token (“TOKEN 2”) may be input by the user at the mobile terminal 20 while dialing a predefined number at the mobile terminal 20. For example, the predefined number may be dialed at the mobile terminal 20, and then the second token (“TOKEN 2”) may be input at the mobile terminal 20. In some embodiments, the predefined number may be a “service number”. Optionally, in some embodiments, a personal identification number (PIN) may also be input at the mobile terminal 20. As an alternative or addition to the personal identification number (PIN) mentioned herein, the mobile station international subscriber directory number (MSISDN) may be used. Alternatively or additionally, in some embodiments, biometric information (such as fingerprints) obtained from a biometric sensor and / or voice recognition performed on an audio signal obtained from an audio sensor may be used. In these ways, the security can be further enhanced advantageously.
[0091] As Figure 9 shown by the arrows 506 and 508 of Figure 10 and the arrows 612 and 614 of Figure 9 and 10 shown, the second token (“TOKEN 2”), and optionally also the personal identification number (PIN) and / or the mobile station international subscriber directory number (MSISDN), are transmitted from the mobile terminal 20 to the node 40 of the network 500. The second token (“TOKEN 2”), and optionally also the personal identification number (PIN) and / or the mobile station international subscriber directory number (MSISDN), are transmitted from the mobile terminal 20 to the node 40 for the node 40 to use when deciding whether to allow the user to access the application 12. As
[0092] As Figure 9 shown, according to some embodiments, the network 500 can include a second Internet Protocol (IP) 80. In these embodiments, as Figure 9As shown by arrow 508, a second token ("TOKEN 2"), and optionally a personal identification number (PIN) and / or a mobile station international subscriber directory number (MSISDN), can be transmitted from mobile terminal 20 to node 40 of network 500 via second IP 80. Thus, in some embodiments, node 40 of network 500 can receive the second token ("TOKEN 2"), and optionally also the personal identification number (PIN) and / or the mobile station international subscriber directory number (MSISDN), from mobile terminal 20 via any one or more of mobile network 70, application server 30, and second IP 80.
[0093] In embodiments involving application server 30, as Figure 9 shown by arrow 506 and Figure 10 shown by arrow 612, application server 30 receives the second token ("TOKEN 2") and optionally also the personal identification number (PIN) and / or the mobile station international subscriber directory number (MSISDN) input by the user (e.g., directly or via mobile network 70) from mobile terminal 20. As Figure 9 shown by arrow 508 and Figure 10 shown by arrow 614, the second token, and optionally also the personal identification number (PIN) and / or the mobile station international subscriber directory number (MSISDN), are transmitted by application server 30 to node 40 of network 500. The second token, and optionally also the personal identification number (PIN) and / or the mobile station international subscriber directory number (MSISDN), are transmitted to node 40 for use by node 40 in determining whether to allow the user to access application 12.
[0094] In some embodiments, as Figure 10 shown by arrow 612, application server 30 can also receive the mobile number ("CallingPartyNumber" or "CPN") and / or location information of mobile terminal 20 from which the user inputs the second token ("TOKEN 2"). As Figure 10 shown, application server 30 can receive the mobile number ("CPN") and / or location information from mobile network 70. In some of these embodiments, as Figure 10 shown by arrow 614, the mobile number ("CPN") and / or location information of mobile terminal 20 can be transmitted from application server 30 to node 40 of network 500. In some embodiments, the mobile number ("CPN") and / or location information of mobile terminal 20 can be transmitted to node 40 for verifying whether the user has a subscription to application 12. Thus, in some embodiments, node 40 of network 500 also receives the mobile number ("CPN") and / or location information of mobile terminal 20.
[0095] Thus, in this manner, node 40 of network 500 receives a first token ("TOKEN 1") from device 10 in which application 12 is stored, and a second token ("TOKEN 2") input by the user from mobile terminal 20. At node 40 of network 500, based on the verification of whether the second token ("TOKEN 2") matches the first token ("TOKEN 1") and whether the user has a subscription for application 12, it is determined whether to allow the user to access application 12 stored in device 10.
[0096] In some embodiments, as Figure 9 arrow 510 of Figure 10 and arrow 616 of Figure 10 shown, verifying whether the user has a subscription for application 12 may include: using database 60 operable to store or retrieve subscription data of the mobile terminal to verify whether the user has a subscription for application 12. In embodiments where node 40 of network 500 receives the mobile number ("CPN") of mobile terminal 20, as Figure 10 arrow 616 of
[0097] shown, the verification of whether the user has a subscription for application 12 may be based on the received mobile number ("CPN") of mobile terminal 20. Alternatively or additionally, in embodiments where node 40 of network 500 receives a personal identification number (PIN) and / or mobile station international subscriber directory number (MSISDN), as Figure 10 arrow 616 of
[0098] shown, the verification of whether the user has a subscription for application 12 may be based on the received personal identification number (PIN) and / or mobile station international subscriber directory number (MSISDN). Figure 10As shown by arrow 620, node 40 of network 500 can query database 60 using the previously received data storage identifier (“dataStorageID”) assigned to the first token (“TOKEN 1”) by database 60. In this way, as Figure 10 shown by arrow 622, node 40 can retrieve the first token (“TOKEN 1”) from database 60, and optionally also the identifier of application 12 (“ApplicationID”) and / or the identifier of the session running on application 12 (“SessionID”). In this way, node 40 itself does not need to store this information, but can retrieve it from database 60 for use in verifying whether the second token (“TOKEN 2”) matches the first token (“TOKEN 1”) and whether the user has a subscription to application 12.
[0099] Therefore, as Figure 10 shown by arrows 624 and 626 at node 40 of network 500, based on the verification of whether the second token (“TOKEN 2”) matches the first token (“TOKEN 1”) and whether the user has a subscription to application 12, a decision is made on whether to allow the user to access application 12 stored in device 10. For example, if the second token (“TOKEN 2”) matches the first token (“TOKEN 1”), and the user has a subscription to application 12, it can be decided to allow the user to access application 12. In some embodiments, the second token (“TOKEN 2”) matches the first token (“TOKEN 1”), where these tokens are the same or equal (i.e., where “TOKEN 2” == “TOKEN 1”). On the other hand, if the second token (“TOKEN 2”) does not match the first token (“TOKEN 1”) and / or the user does not have a subscription to application 12, it can be decided to deny the user access to application 12. In some embodiments, the second token (“TOKEN 2”) does not match the first token (“TOKEN 1”), where these tokens are different or not equal (i.e., where “TOKEN 2” ≠ “TOKEN 1”).
[0100] As Figure 9 shown by arrow 512 and Figure 10 shown by arrow 628, an indication of the decision on whether to allow the user to access application 12 is transmitted from node 40 of network 500 to device 10. As Figure 9As shown, in an embodiment where network 500 includes a first IP 50, an indication of a decision can be transmitted from node 40 of network 500 to device 10 via the first IP 50. Thus, at device 10, an indication of a decision on whether to allow a user to access application 12 is received from node 40 of network 500. If the indication is an indication of a decision to allow the user to access application 12, device 10 can be operable to allow the user to access application 12. On the other hand, if the indication is an indication of a decision to deny the user access to application 12, device 10 can be operable to deny the user access to application 12.
[0101] Figure 11 FIG. is a block diagram of device 10 storing application 12 and mobile terminal 20 for use by user 700 according to an embodiment. Device 10 storing application 12 and mobile terminal 20 operate in the manner described above. Now, a description will be given from the perspective of user 700 Figure 11 .
[0102] As Figure 11 shown in (a), at device 10 storing application 12, user 700 requests access to application 12. In the illustrated embodiment, the user requests access to application 12 via the user interface of device 10, or more specifically, via "Smart Login" option 702 displayed on the user interface of device 10. For example, in some embodiments, the user interface of device 10 can be a touch screen, and the user can select "Smart Login" option 702 by touching an option on the screen. In other embodiments, the user interface of device 10 can be a display, and the user can select "Smart Login" option 702 by clicking an option on the display (e.g., using a keyboard, mouse, etc.). In other embodiments, "Smart Login" option 702 can be provided as a button that the user can press.
[0103] Once the user requests access to application 12, as Figure 11 shown in (b), device 10 storing application 12 generates a first token in response to the request from user 700 to access application 12. The first token (and optionally also SessionID and / or ApplicationID) is transmitted from device 10 to node 40 of network 500 in the manner described above. In the illustrated embodiment, the first token is a code including a plurality of digits ("98765"). The plurality of digits can be randomly generated by device 10. As Figure 11 shown in (b), in the illustrated embodiment, the first token is displayed to the user on the user interface of device 10 storing application 12.
[0104] At the mobile terminal 20 of the mobile network 70, the user is requested to input a first token generated by the device 10 in which the application 12 is stored. As Figure 11 shown in (c) of , in response to the request for the user 700 to input the first token, the user 700 inputs a second token at the mobile terminal 20. In some embodiments, the user may directly input the second token at the user interface of the mobile terminal 20 (e.g., using a keyboard or a touch screen). In other embodiments, the user may initially call a predefined number at the mobile terminal 20 and then input the second token while calling the predefined number. For example, the user 700 may directly input the second token after calling the predefined number, or the user 700 may input the second token after being requested to input the first token generated by the device 10 during the call to the predefined number. In these embodiments, the user 700 may input the second token at the user interface of the mobile terminal 12 (e.g., using a keyboard or a touch screen). In other embodiments, the user 700 may input the second token at a mobile application running on the mobile terminal 20 via a QR code, via an interactive voice response (IVR), or any other input mechanism. Optionally, in some embodiments, the user may also input a personal identification number (PIN), which can provide additional security. The second token (and optionally also the PIN, CPN, and / or MSISDN) input by the user at the mobile terminal 20 is transmitted to the node 40 in the manner described above.
[0105] Once the node 40 receives the first token and the second token, the node 40 operates in the manner described above to decide whether to allow the user to access the application 12 stored in the device 10 and transmits an indication of the decision to the device 10.
[0106] As Figure 11 shown in (d) of , an indication 706 of the decision whether to allow the user to access the application 12 is displayed to the user at the device 10 in which the application 12 is stored. More specifically, in the illustrated embodiment, an indication 706 of the decision to allow the user to access the application 12 (via the statement "Login successful") is displayed to the user at the device 10. Thus, in the illustrated embodiment, the user 700 provides correct data at the mobile terminal 20 and the user has a subscription to the application 12. As such, the user logs in to the application 12 at the device 10.
[0107] Figure 12It is a block diagram of a device 800 that stores application programs. The device 800 includes: a generation module 802 configured to generate a first token in response to a request from a user to access an application program; and a transmission module 804 configured to transmit the first token to a node of a network for the node to use when determining whether to allow the user to access the application program. The device 800 further includes a reception module 806 configured to receive an indication of a decision on whether to allow the user to access the application program from the node.
[0108] Figure 13 It is a block diagram of a mobile network 900. The mobile terminal 900 includes a reception module 902 configured to receive a second token input by a user at the mobile terminal in response to a request to input the first token generated by a device that stores application programs. The mobile terminal 900 further includes a transmission module 904 configured to transmit the received second token to a node of the network for the node to use when determining whether to allow the user to access the application program.
[0109] Figure 14 It is a block diagram of an application server 1000 of a network. The application server includes a reception module 1002 configured to receive the second token input by a user at the mobile terminal from a mobile terminal of a mobile network. The second token is input by the user in response to a request to input the first token generated by a device that stores application programs. The application server 1000 further includes a transmission module 1004 configured to transmit the second token to a node of the network for the node to use when determining whether to allow the user to access the application program.
[0110] Figure 15 It is a block diagram of a node 1200 of a network. The node 1200 includes a first reception module 1202 configured to receive the first token generated by the device in response to a request from a user to access an application program from the device that stores application programs. The node 1200 further includes a second reception module 1204 configured to receive the second token, which is input by the user at a mobile terminal of a mobile network in response to a request to input the first token generated by the device. The node 1200 further includes a decision module 1206 configured to determine whether to allow the user to access the application program stored in the device based on whether the second token matches the first token and whether the user has a subscription verification for the application program. The node 1200 further includes a transmission module 1208 configured to transmit an indication of a decision on whether to allow the user to access the application program to the device.
[0111] There is also provided a computer program product including a carrier, the carrier containing instructions for causing a processing circuit to execute at least a part of the methods described herein. In some embodiments, the carrier may be any one of an electronic signal, an optical signal, an electromagnetic signal, an electrical signal, a radio signal, a microwave signal, or a computer-readable storage medium. In some embodiments, the device-readable storage medium is operable to store a computer program, software, an application including one or more of logic, rules, codes, tables, etc., and / or other instructions capable of being executed by the processing circuit described herein.
[0112] Accordingly, there is advantageously provided herein an improved way of allowing access to application programs.
[0113] It should be noted that the above-described embodiments illustrate rather than limit the concept, and those skilled in the art will be able to design many alternative embodiments without departing from the scope of the appended claims. The word "comprising" does not exclude the presence of elements or steps other than those listed in the claims, "a" or "an" does not exclude a plurality, and a single processor or other unit may implement the functions of several units recited in the claims. Any reference signs in the claims should not be construed as limiting their scope.
Claims
1. A method of operating a node (40) of a network (500), the method comprising: receiving (402, 604) a first token generated by the device (10) in response to a request from a user (700) to access the application (12), the first token being stored in the device (10) where the application (12) is stored; receiving (404, 614) a second token, the second token being input at a mobile terminal (20) of a mobile network (70) by the user (700) in response to a request to input the first token generated by the device (10); deciding (406, 624, 626) whether to allow the user to access the application (12) stored in the device (10) based on whether the second token matches the first token and a verification of whether the user (700) has a subscription for the application (12); and transmitting (408, 628) an indication of the decision as to whether to allow the user to access the application (12) to the device (10).
2. The method according to claim 1, wherein: if the second token matches the first token and the user (700) has a subscription for the application (12), it is decided to allow the user to access the application (12); and / or if the second token does not match the first token and / or the user (700) does not have a subscription for the application (12), it is decided to deny the user access to the application (12).
3. The method according to any one of claims 1 or 2, wherein the verification of whether the user (700) has a subscription for the application (12) comprises: verifying whether the user (700) has a subscription for the application (12) by using a database (60) operable to store or retrieve subscription data for the mobile terminal.
4. The method according to any one of the preceding claims, wherein the method further comprises: receiving (614) the mobile number of the mobile terminal (20) from which the user (700) inputs the second token.
5. The method according to claim 4, wherein the verification of whether the user (700) has a subscription for the application (12) is based on the received mobile number of the mobile terminal (20).
6. The method according to any one of the preceding claims, wherein the method further comprises: receiving (604) any one or more of the following: the identity of the application (12); and the identity of a session running on the application (12), wherein the request from the user (700) is to access the session running on the application (12).
7. The method according to claim 6, wherein the method further comprises: Store any one or more of the following in a database (60) operable to store or retrieve reservation data for a mobile terminal: the first token, the identity of the application (12), and the identity of a session running on the application (12).
8. The method according to any one of the preceding claims, wherein the second token is received via the mobile network (70) and / or the application server (30).
9. The method according to any one of the preceding claims, wherein when a predefined number is dialed at the mobile terminal (20), the user (700) inputs the second token at the mobile terminal (20).
10. The method according to any one of the preceding claims, wherein the first token is received as a Hypertext Transfer Protocol request.
11. The method according to any one of the preceding claims, wherein the first token is randomly generated by the device (10).
12. A node (40) of a network (500), the node (40) comprising: processing circuitry (44) operable to: receive, from a device (10) storing an application (12), a first token generated by the device (10) in response to a request from a user (700) to access the application (12); receive a second token, the second token being input by the user (700) at a mobile terminal (20) of a mobile network (70) in response to a request to input the first token generated by the device (10); decide whether to allow the user to access the application (12) stored in the device (10) based on a verification of whether the second token matches the first token and whether the user (700) has a reservation for the application (12); and transmit an indication of the decision as to whether to allow the user to access the application (12) to the device (10).
13. A method of operating a device (10) storing an application (12), the method comprising: generating (102, 602) a first token in response to a request from a user (700) to access the application (12); transmitting (104, 604) the first token to a node (40) of a network (500) for use by the node (40) in deciding whether to allow the user to access the application (12); and receiving (106, 628) an indication of the decision as to whether to allow the user to access the application (12) from the node (40).
14. A device (10) storing an application (12), the device (10) comprising: processing circuitry (14) operable to: generate a first token in response to a request from a user (700) to access the application (12); transmit the first token to a node (40) of a network (500) for use by the node (40) in deciding whether to allow the user to access the application (12); and Receive an indication of the decision on whether to allow the user to access the application (12) from the node (40).
15. A method of operating a mobile terminal (20) of a mobile network (70), the method comprising: Receiving (202, 610) a second token, which is input at the mobile terminal (20) by the user (700) in response to a request for the user (700) to input a first token generated by a device (10) storing the application (12); and Transmitting (204, 612, 614) the received second token to a node (40) of the network (500) for use by the node (40) in determining whether to allow the user to access the application (12).
16. The method according to claim 15, wherein the user (700) inputs the second token at the mobile terminal (20) when a predefined number is being dialed at the mobile terminal (20).
17. The method according to claim 15 or 16, wherein the method comprises: Transmitting (204, 612, 614) the received second token to the node (40) of the network (500) via the mobile network (70) and / or the application server (30).
18. A mobile terminal (20) of a mobile network (70), the mobile terminal (20) comprising: Processing circuitry (24), operable to: Receive a second token, which is input at the mobile terminal (20) by the user (700) in response to a request for the user (700) to input a first token generated by a device (10) storing the application (12); and Transmit the received second token to a node (40) of the network (500) for use by the node (40) in determining whether to allow the user to access the application (12).
19. A method of operating an application server (30) of a network (500), the method comprising: Receiving (302, 612) from a mobile terminal (20) of a mobile network (70) a second token input by a user (700) at the mobile terminal (20), wherein the second token is input by the user (700) in response to a request for the user (700) to input a first token generated by a device (10) storing the application (12); and Transmitting (304, 614) the second token to a node (40) of the network (500) for use by the node (40) in determining whether to allow the user to access the application (12).
20. The method according to claim 19, wherein the method further comprises: Receiving (612) the mobile number of the mobile terminal (20) at which the user (700) inputs the second token; and Transmitting (614) the mobile number of the mobile terminal (20) to the node (40) of the network (500).
21. The method according to claim 20, wherein the mobile number of the mobile terminal (20) is transmitted to the node (40) of the network (500) for use in the verification of whether the user (700) has a subscription to the application (12).
22. The method according to any one of claims 19 to 21, wherein the first token is transmitted as a Hypertext Transfer Protocol request.
23. An application server (30) of a network (500), the application server (30) comprising: processing circuitry (34) operable to: receive a second token input by a user (700) at a mobile terminal (20) of a mobile network (70), wherein the second token is input by the user (700) in response to a request for a first token generated by a device (10) storing an application (12); and transmit the second token to a node (40) of the network (500) for use by the node (40) in determining whether to allow access to the application (12).
24. A network (500) comprising any one or more of the following: the node (40) according to claim 12, the device (10) according to claim 14, the mobile terminal (20) according to claim 18, the mobile network (70); and the application server (30) according to claim 23.
25. A computer program product comprising a carrier containing instructions for causing processing circuitry to perform the method according to any one of claims 1 to 11, 13, 15 to 17 and 19 to 22.