Computer implementation methods, computer systems, and computer programs (message delivery in cellular roaming scenarios)

JP7909354B2Active Publication Date: 2026-08-21INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2022137235
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-08-31
Filing Date
2022-08-30
Publication Date
2026-08-21
Estimated Expiration
2042-08-30

Smart Images

  • Figure 0007909354000001
    Figure 0007909354000001
  • Figure 0007909354000002
    Figure 0007909354000002
  • Figure 0007909354000003
    Figure 0007909354000003
Patent Text Reader

Abstract

To solve a problem with message reception that occurs in a situation where a user / subscriber is roaming.SOLUTION: A process includes the steps of: receiving a transaction text message from a remote application server on the basis of a transaction with the remote application server that requires user authentication based on distribution of a transaction text message being started by a user; encrypting the transaction text message to generate an encrypted transaction text message; and transferring the encrypted transaction text message to a remote TSP in order to distribute it as a short message service (SMS) text to a user device at a remote location via a cellular network of the remote TSP.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] When a user performs a sensitive online transaction that requires enhanced security, such as an online financial transaction, or additional authentication measures before the completion of a transaction, often the application server sends a transaction text message, i.e., a Short Message Service (SMS) text message, to the user's mobile phone to authenticate the user. Transaction text messages can be of different types. A common type is a one-time password (OTP) that the user receives and provides to a web application to authenticate the user. Another type of transaction text message is a unique hyperlink, for example, one that enables the user to change the password of an account user or click to approve a transaction that has been initiated.

Summary of the Invention

Problems to be Solved by the Invention

[0002] In a situation where the user / subscriber is roaming, problems with message reception can occur.

Means for Solving the Problems

[0003] By providing a computer implementation method, the shortcomings of prior art are overcome and further advantages are provided. A user initiates a transaction with a remote application server. The transaction requires user authentication based on the delivery of a transaction text message to the user's mobile device via a cellular network connection. Based on the user-initiated transaction, the method receives a transaction text message from the remote application server for delivery to the user device. The user device is activated using a home TSP that provides cellular services to user devices located at home on the home TSP's cellular network, and has a home cellular number provided by the home telecommunications service provider (TSP). The transaction text message is received by the home TSP and sent to the user device by the home TSP. The user device is located at a remote location and is activated using a remote TSP that provides roaming cellular services to user devices at remote locations on the remote TSP's cellular network. The method encrypts the transaction text message to generate an encrypted transaction text message. Furthermore, the method forwards the encrypted transaction text message from the home TSP to the remote TSP for delivery as a Short Message Service (SMS) text to the remote TSP via the remote TSP's cellular network to the remote user device.

[0004] Furthermore, a computer system is provided, including memory and a processor that communicates with the memory, and the computer system is configured to perform the method. The user initiates a transaction with a remote application server. The transaction requires user authentication based on the delivery of a transaction text message to the user's mobile device via a cellular network connection. Based on the transaction initiated by the user, the method receives a transaction text message from the remote application server for delivery to the user device. The user device is activated using a home TSP that provides cellular services to user devices located at home on the home TSP's cellular network, and has a home cellular number provided by the home telecommunications service provider (TSP). The transaction text message is received by the home TSP and sent by the home TSP to the user device. The user device is located at a remote location and is activated using a remote TSP that provides roaming cellular services to user devices located at remote locations on the remote TSP's cellular network. The method encrypts the transaction text message to generate an encrypted transaction text message. Furthermore, this method forwards encrypted transactional text messages from the home TSP to a remote TSP via the remote TSP's cellular network for delivery as Short Message Service (SMS) text messages to a user device located at a remote location.

[0005] Furthermore, to perform the method, a computer program product is provided that includes a computer-readable storage medium that is readable by the processing circuit and stores instructions for execution by the processing circuit. The user initiates a transaction with a remote application server. The transaction requires user authentication based on the delivery of a transaction text message to the user's mobile device via a cellular network connection. Based on the transaction initiated by the user, the method receives a transaction text message from the remote application server for delivery to the user device. The user device is activated using a home TSP that provides cellular services to user devices located at home on the home TSP's cellular network, and has a home cellular number provided by the home telecommunications service provider (TSP). The transaction text message is received by the home TSP and sent to the user device by the home TSP. The user device is located at a remote location and is activated using a remote TSP that provides roaming cellular services to user devices located at remote locations on the remote TSP's cellular network. The method encrypts the transaction text message to generate an encrypted transaction text message. Furthermore, this method forwards encrypted transactional text messages from the home TSP to a remote TSP via the remote TSP's cellular network for delivery as Short Message Service (SMS) text messages to a user device located at a remote location.

[0006] Additional features and benefits are realized through the concepts described herein. [Brief explanation of the drawing]

[0007] The embodiments described herein are specifically cited and explicitly claimed in the claims at the end of the specification. The aforementioned and other purposes, features, and advantages of this disclosure will become apparent from the following detailed description in conjunction with the accompanying drawings.

[0008] [Figure 1] This shows an example of a message not being delivered in a cellular roaming scenario.

[0009] [Figure 2A] This example shows message delivery in a cellular roaming scenario based on registration of a roaming number with a home telecommunications service provider. [Figure 2B] This example shows message delivery in a cellular roaming scenario based on registration of a roaming number with a home telecommunications service provider.

[0010] [Figure 3] This shows an example of message delivery in an international roaming scenario.

[0011] [Figure 4] An exemplary conceptual diagram of a system for message delivery in a cellular roaming scenario, according to the embodiments described herein, is shown.

[0012] [Figure 5A] This specification describes an exemplary process for message delivery in a cellular roaming scenario according to the embodiments described herein. [Figure 5B] This specification describes an exemplary process for message delivery in a cellular roaming scenario according to the embodiments described herein. [Figure 5C] This specification describes an exemplary process for message delivery in a cellular roaming scenario according to the embodiments described herein. [Figure 5D] This specification describes an exemplary process for message delivery in a cellular roaming scenario according to the embodiments described herein.

[0013] [Figure 6]Examples of computer systems and associated devices for incorporating, using, or both, the embodiments described herein are shown.

[0014] [Figure 7] This document shows a cloud computing environment using one embodiment of the present invention.

[0015] [Figure 8] An abstract model layer according to one embodiment of the present invention is shown. [Modes for carrying out the invention]

[0016] The embodiments described herein relate to the provision of text messages to a user's cellular device. An exemplary text message is a transactional text message related to a user-initiated transaction involving a web application. The terms “user” and “subscriber” may be used synonymously herein to refer to a subscriber of cellular services provided by a cellular telecommunications service provider (TSP). The user / subscriber uses the cellular services through a cellular device referred to herein as “user device” or “subscriber device.” The terms “subscriber,” “user,” “subscriber device,” and “user device” may be used synonymously herein, for example, to refer to an action performed by or on behalf of a subscriber.

[0017] The user cellular device is activated using the cellular TSP. Typically, a given user activates a device on their home TSP which provides cellular service to the user, for example, at the user's home location (country region, area etc.). This TSP is referred to herein as the user's home TSP and provides cellular service to a subscriber device located at the home location within the cellular network of this home TSP. As part of this, the home TSP assigns a telephone number (the "home cellular number") to the user / device for user communication via telephone or text message. In some cases, the user moves to a location (remote location) outside the coverage area of the home TSP's cellular infrastructure. In this case, the user / device is said to be "roaming" and in this case, the user device may be registered / activated with a remote TSP that provides cellular service (roaming) to a user device located at the remote location on the cellular network of the remote TSP.

[0018] One roaming scenario, referred to herein as subscribed roaming, views a user who has subscribed to a remote TSP as a user of the remote TSP cellular service, even if only temporarily. In this case, the remote TSP assigns a telephone number (the "roaming cellular number") to the user device for use on the roaming TSP cellular service that is local to the remote location. Another roaming scenario, referred to herein as international roaming, enables the user's home cellular number to function at a remote location on the cellular network of the remote TSP. The home TSP provides international roaming service to the subscriber such that the home cellular number is extended at an international level, i.e., to the cellular network of the remote TSP, such that the home cellular number becomes available for use on the cellular network of the remote TSP. In many cases, the home TSP and the remote TSP have a preconfigured arrangement for providing international roaming service to their respective customers.

[0019] In a situation where a user / subscriber is roaming, problems with message reception can occur. In a subscribed roaming scenario where the user uses a roaming cellular number, the home TSP needs to recognize the roaming cellular number. Otherwise, a text message sent to the user's home cellular number will not reach the user's device at the remote location via the roaming cellular number. This is a problem for several reasons. In the case of the use of text messages that are time-dependent, for example, when a message such as an OTP for authentication related to a financial transaction is sent to the user, the message is sent to the user's home cellular number but does not reach the user device that is using the roaming number. In this case, the user cannot authenticate via means via the OTP and cannot complete the transaction.

[0020] Figure 1 shows a scenario of this problem. The user device 104 is activated using a home (TSP) 106 that provides cellular coverage at the home location 108, which provides cellular service to the user device at the home location 108 on the cellular network of the home TSP 106. As part of this, the home TSP provides the user device 104 with a home cellular number. At a certain point, the user moves to a remote location 110 where a remote TSP 112 provides the cellular network. The user device 104 at the remote location 110 can be activated using a remote TSP 112 that provides roaming cellular service to the user device 104 at the remote location on the cellular network of the remote TSP 112.

[0021] When the user is in a remote location, the user initiates a transaction with a remote application server 122 via an e-commerce application (in this example) 120 (118). In this example, the application 120 and the backend application server 122 are hosted in a cloud environment 124, but in other examples, for example, if the user communicates with the cloud server using a web browser or a mobile application installed locally on the user device 104 to initiate a transaction, then the application 120 that the user interacts with to engage with the application server 122 may be partially or entirely installed on the user device 104. The cloud environment 124 may be located at the remote location 110, the home location 108, or another location.

[0022] In this scenario, the subscriber does not have a local (home) cellular number and subscribes to a roaming cellular number (i.e., local to the remote location). Based on the commencement of a transaction with the e-commerce application 120 118, the application server 122 communicates with the home TSP 130 to initiate sending an SMS message containing an OTP to the user's home cellular / mobile number registered with the e-commerce application 120 (130). The transactional SMS message is delivered to the user's home cellular number, but does not reach the user device at that time because the user device is in the roaming cellular service at the remote location. This results in the message being unavailable to the subscriber via the home TSP by the application server 122 while the user is at the remote location.

[0023] In these situations, it may be possible to register the roaming cellular number with the home TSP so that messages are forwarded to the remote TSP by the home TSP for delivery to the user device via the roaming cellular number assigned by the remote TSP. Figures 2A and 2B illustrate this example.

[0024] Figure 2A again includes a home location 208, a home TSP 206, a user device 204 using a home cellular number at home location 208, a remote location 210, a remote TSP 212, and a cloud environment 224 having an e-commerce application 220 and an application server 222. At some point before moving to remote location 210, the user sets up an SMS forwarding registration 250 at home TSP 206. This instructs home TSP 206 to forward messages / calls initially addressed to the home cellular number to a roaming cellular number. The user initiates a transaction 218 with the e-commerce application 220 communicating with the application server 222 using a device 204 at remote location 210 that obtains and uses a roaming cellular number at remote location 210, and initiates sending an SMS message containing an OTP to the user's home cellular / mobile number registered with the e-commerce application 220 between home TSP 206 and home TSP 230. Home TSP206 delivers message 232 to the roaming cellular number due to an SMS forwarding registration previously set up by the user.

[0025] Setting up registration for SMS forwarding in advance, as shown in Figure 2A, is an example of registering a roaming cellular number as an active secondary phone number with the home TSP to establish a link between the home cellular number and the roaming cellular number. Alternatively, in some cases, the user may set up registration and establish the roaming number as an active secondary phone number after moving to a remote location. Figure 2B shows an example of a user achieving this through dial-in authentication. In Figure 2B, the user at remote location 210 uses device 204 at remote location 210 to dial (216) the home TSP 206 at home location 208 while on the remote TSP 212 cellular network, and authenticates the user / device using the home TSP. The user may explicitly specify the roaming number, or the home TSP 206 may recognize the roaming number through dial-in, which establishes a link between the home cellular number provided by the home TSP and the roaming cellular number provided by the remote TSP 212, or both. The user initiates a transaction with the e-commerce application 220 using device 204 at remote location 210 218, and the e-commerce application 220 communicates with application server 222 to initiate sending an SMS message to the user's home cellular / mobile number registered in the e-commerce application 220 via home TSP 206 using OTP 230. Home TSP 206 delivers message 232 to the roaming cellular number due to dial-in authentication and previous registration of the roaming number in home TSP 206.

[0026] Both scenarios in Figure 2A and Figure 2B are examples of registering a roaming cellular number as an active secondary telephone number in the home TSP to establish a link between the home cellular number and the roaming cellular number. In both cases, the secure registration of the roaming cellular number in the home TSP is based on user authentication in the home TSP.

[0027] In an international roaming scenario, a message sent to a home number is delivered to a remote TSP that recognizes the user device on the remote TSP's cellular network. Figure 3 illustrates this situation. When moving to a remote location 310, the subscriber / user device 304 has its home cellular number provided by the home TSP 306 at home location 308 and uses an international roaming agreement between home TSP 306 and remote TSP 312 at the remote location. The user initiates a transaction with the e-commerce application 320 using device 304 at remote location 310 318, and the e-commerce application 320 communicates with the application server 322 to initiate the sending of an SMS message by home TSP 306 using OTP to the user's home cellular / mobile number registered in the e-commerce application 320 330. Home TSP 306 delivers the message 332 to the home cellular number used on the remote TSP 312 cellular network at remote location 310. Thus, the transaction message becomes available to the subscriber at the remote location.

[0028] Several scenarios for subscribed roaming (Figures 2A, 2B) and international roaming (Figure 3) deliver messages to roaming users, but with potential drawbacks. One is security-related. Message content that may be confidential becomes available to remote TSPs, and the forwarding of messages by the home TSP to the remote TSP's network during flight can be considered a security risk. Another issue concerns timing. Latency / delay in the delivery of SMS messages from the home TSP to roaming devices on other TSP networks can be quite high, perhaps so high that by the time the message is finally delivered to the user device at the remote location, the expiration period of the message content has expired. At that point, the OTP (for example) has expired and can no longer be used to authenticate the transaction.

[0029] This specification describes methods for message delivery in cellular roaming scenarios. Such methods may be particularly useful in situations involving transactional message delivery while roaming at a remote location (outside the subscriber's home cellular network), e.g., for transactional authentication or other purposes, where time and security-dependent messages are delivered to cellular users. Therefore, a method is provided for securely delivering transactional (including private and confidential) communications to a registered number of a roaming subscriber while the subscriber is at a roaming location, via a home / roaming cellular number. A method is provided for securely registering a roaming number for a user provided by a remote TSP at the roaming location as an active secondary telephone number at the home TSP, thereby activating a seamless communication path for secure transactional message communication between the home TSP and the subscriber device. This path may be pre-established, activated, and tested for transactional communication in roaming situations before the transaction begins. For security, the process may apply encryption to messages received while the subscriber is roaming for delivery to the subscriber device via the remote TSP, which requires the user to separately authenticate / provide a shared secret for proper decryption of the message. A shared secret can facilitate the extraction of multi-level encryption / decryption security keys to obtain sensitive message data (e.g., OTP) related to initiated financial transactions or other types of transactions. To enhance security, an expiration timeline or other parameters may be established for either or both the registration of the roaming cellular number and the shared secret to the home TSP.

[0030] Figure 4 shows an exemplary conceptual diagram of a system for message delivery in a cellular roaming scenario according to the embodiments described herein. The system is implemented by a collection of computer, telecommunications, and network system equipment, such as the user's consumer electronics (e.g., mobile phones / smartphones), the TSP's telecommunications equipment, and computer / network equipment that provides wired / wireless networks for telecommunications and data communication between various devices.

[0031] Home location 408 includes a home TSP 406 that provides cellular services (e.g., telephone / voice communications and broadband data / Internet / messaging services) to subscriber / user devices. One such subscriber of the home TSP cellular services is represented by user device 404. In this example, home location 408 is the subscriber's home country.

[0032] The home TSP 406 provides a set of web services available to the subscriber 404 via an HTTPS connection 403. The roaming number registration component 460 is for registering a roaming cellular number with the home TSP 406. For example, registration can be performed manually by the subscriber via dial-in authentication or via a provided interface for the user to specify a forwarding number to which calls / messages should be forwarded. The home TSP 406 also provides an end-to-end message channel verifier 462 for activating / verifying / testing a communication channel 464 between the home TSP 406 and the remote TSP 412 for communication between them in accordance with a message routing agreement between the two TSPs. Channel 464 allows the delivery of calls / messages from the home TSP to the subscriber device 404 located at a remote location 410 while connected to the remote TSP 412. In this example, the remote location 410 is a different (remote) country. The verifier 462 can be automatically or manually triggered to send a message to the remote TSP 412. One useful application is to establish a communication channel 464 between the home TSP and the remote TSP, and ultimately between the user device 404 when it is located at the remote location 410. Once the channel is established, subsequent messages sent by the home TSP 406 to the remote TSP 412 for delivery to the user device 404 are expected to arrive faster because the channel has been established.

[0033] The home TSP 406 also provides a shared secret component 466 for managing shared secrets, such as a security personal identification number (PIN), between the home TSP 406 and the subscriber 404. According to some embodiments, the home TSP 406 generates a shared secret (e.g., a four-digit PIN) that is used by the home TSP 406 to generate an encryption key for encrypting messages to be sent to the remote TSP 412 for delivery to the subscriber 404 when it is at the remote location 410, and shares it with the subscriber. The same shared secret may be used by the user device 404 to generate a decryption key for decrypting encrypted messages received from the home TSP 406 via the remote TSP 412. The encryption adapter 470 may perform this encryption using any desired technique to encrypt messages to be forwarded by the home TSP 406 to the remote TSP 412 for delivery to the subscriber device 404 at the remote location 410. As a specific example, the encryption adapter 470 applies a Feister cipher, in which a shared secret is used to generate subkeys, and those subkeys are used in a "round" to generate an encrypted message.

[0034] The enabler / disabler component 468 enables and disables the subscriber's roaming service based on any desired trigger or other parameters. Roaming service may be based on time, location, or other factors that automatically enable or disable the provision of roaming service and messaging while the subscriber is in a cellular roaming scenario. As a specific example, a specified entry query service 472 is used to query the location of user device 404 to determine whether the user device is in a remote location outside the home TSP cellular network where the home TSP resides, or a geographical boundary (e.g., region, state, country, etc.), or both. Roaming service may be enabled / disabled based on the user device's location. For example, roaming may be automatically disabled based on the detection that a user device that was previously located in a remote location 410 has left the geographical boundary (e.g., national border) of that remote location 410 for which roaming service was provided to user device 404.

[0035] Furthermore, or alternatively, the enabler / disabler 468 can be manually activated / deactivated to enable / deactivate roaming services for subscribers (for example, by the subscriber logging into the home TSP 406 system).

[0036] While at the remote location 410, the subscriber device 404 can communicate with the remote TSP 412 via an HTTPS connection 480. The remote TSP 412 provides a roaming number lookup service 482 that provides any desired roaming number service. One example is verifying the subscriber device 404 when connected to the remote TSP, or performing a lookup of the subscriber's home cellular number at the home TSP, or both. Furthermore, service 482 may enable the home TSP 406 to look up the roaming number assigned to the subscriber device by the remote TSP, for example, in order to register its roaming number with the home TSP.

[0037] The end-to-end message channel routing requester 484 is a component corresponding to the verification device 462 in the home TSP, enabling activation / verification / testing of communications flowing between the home TSP and the subscriber device via the remote TSP across channels 464 and 480. In a specific example, a user may initiate a test between a remote location and a home location. One such test is provided to a user device 404 at the remote location, which then decrypts the received message. The user can then see the home TSP provide the remote TSP with an encrypted message (encrypted using a secret shared between the home TSP and the user) to verify that it was properly decrypted into a plain text message sent by the home TSP. This is to test the communication channel and shared secret between the home TSP and the subscriber device via the remote TSP.

[0038] A specified entry query service 488 may be used by a remote TSP to query the location of a user device 404 and to determine whether the user device is located within a remote location 410 or a geographical boundary (e.g., region, state, country, etc.) or both, where a remote TSP 412 resides.

[0039] The secret generation component 486 may be used in situations where a remote TSP is involved in the encryption, decryption, or both of the messages flowing between the home TSP and the subscriber device. For example, a first shared secret exists between the subscriber and the home TSP. Component 486 generates a second shared secret and provides it to the subscriber device 404 and the home TSP 406 (or the user generates the second shared secret and shares it with the remote TSP and the home TSP). When sending a message to a user device at a remote location, the home TSP performs layered encryption by, for example, using the first shared secret to generate a subkey for encrypting the message and generating an intermediate encrypted message, thereby encrypting the message (e.g., one including an OTP), and then, for example, using the second shared secret to generate a subkey for encrypting the intermediate encrypted message and generating a final encrypted message. The home TSP sends this final encrypted message to the remote TSP 412, which uses a decryption mechanism to perform a level of decryption of the message, for example, using a subkey generated from a second shared secret that it is aware of. This generates an intermediate encrypted message whose contents cannot be read by the remote TSP or the intervening entity because the home TSP encrypted the message based on a first shared secret that is not known to the remote TSP or the intervening entity. The intermediate encrypted message is sent to the subscriber device 404 to be decrypted using the first shared secret and to generate the original (e.g., plaintext) message.

[0040] In the above modified example, the home TSP does not perform layered encryption, but simply encrypts the original message based on the first shared secret. In this case, there is no need to share the second shared secret with the home TSP. When the remote TSP receives the encrypted message from the home TSP, the remote TSP encrypts the encrypted message based on the second shared secret and sends the doubly encrypted message to the subscriber device, which can then decrypt the received encrypted message based on the first and second shared secrets (in the reverse order of how the message was doubly encrypted) to decrypt the message back to its original plaintext format.

[0041] In yet another embodiment, the shared secret is shared only between the home TSP and the subscriber. In this case, the remote TSP is unaware of any shared secret and instead passes the encrypted message as is (still encrypted by the layered encryption performed by the home TSP) to the subscriber device. The subscriber device, based on the shared secret it shares with the home TSP, performs layered decryption (again, in reverse order) to decode the received message sent via the remote TSP back into its original plaintext form.

[0042] To facilitate the decryption of received messages, a message decoding service 490 is provided to the user device 404. The service may be provided as part of a mobile application installed on device 404, or as a remote web-based service provided by another component via a secure connection to the user device 404. In one example using Feistel ciphers, service 490 may accept a shared secret and generate an encryption or decryption subkey. Service 490 may provide the subkey to the user device for decrypting received encrypted messages, or may perform decryption using the subkey and provide the decrypted message to that user device / application, for example, a messaging application that displays plain text messages from the home TSP for the user.

[0043] Figures 5A–5D illustrate exemplary processes for message delivery in cellular roaming scenarios according to the embodiments described herein. In some examples, embodiments of the process are performed by one or more computer systems, such as those described herein, which may be user / subscriber cellular devices, one or more devices in a telecommunications service provider network, one or more cloud servers, or one or more other computer systems, or a combination thereof, or may be incorporated therein.

[0044] Figure 5A shows an exemplary process performed by a Home TSP system according to the embodiments described herein. The process may be invoked based on a user initiating a transaction with a remote application server. The transaction may require user authentication of the user based on the delivery of a transaction text message, e.g., an SMS text message containing a multi-factor authentication code (e.g., OTP or other authentication code), to the user's mobile / cellular device via a cellular network connection. An exemplary such transaction is one using a credit / debit card from an issuing bank, where the bank requires SMS-based multi-factor authentication by the user to enable the completion of the transaction.

[0045] In the example, the user device is activated using a home TSP that provides cellular services to the user device at its home location on the home TSP's cellular network, and the home cellular number is provided to the subscriber / user by the home TSP. The remote application server generates an authentication code, typically an n-digit OTP, as a time-dependent one-time password that the user provides to the remote application server for multi-factor authentication of the user in order to perform transactions. Furthermore, at some point, the home TSP performs the setup of a shared secret that is shared between the home TSP and the user. In one example, the home TSP randomly generates an n-digit secret PIN and provides this to the user or software on the user device. The process obtains one or more cryptographic keys based on those shared secrets (502). The shared secret may contain one or more cryptographic keys themselves. Alternatively, the home TSP uses the shared secret to obtain / generate subkeys as cryptographic keys used for message encryption.

[0046] Based on a transaction initiated by the user, the process on the home TSP continues by receiving a transaction text message from the remote application server to be delivered to the user device (504). The transaction text message is received by the home TSP and sent by the home TSP to the user device. The user device is located at a remote location and is activated using a remote TSP that provides roaming cellular services to user devices located at remote locations on the remote TSP's cellular network.

[0047] The process proceeds to the home TSP encrypting the transaction text message to produce an encrypted transaction text message (506). Encryption uses at least one cryptographic key to encrypt the transaction text message. For example, the home TSP encrypts the message using the Feister cryptographic methodology for encryption. For example, the home TSP holds one or more shared secrets with a user. For each of such shared secrets, the home TSP (i) generates m subkeys for different rounds of Feister network encryption, and (ii) encrypts the message using the Feister method with m rounds of encryption, one for each of the m subkeys generated from the shared secret. This can be done for each of the shared secrets it holds. In the first iteration, the message received as is from the remote application server is encrypted. In each subsequent iteration, the message generated in the previous iteration of Feister cipher is encrypted in the next iteration. In this way, the encryption applied to the original message is layered.

[0048] Although the Feister methodology is used in the examples described herein, messages may be encrypted using any desired encryption scheme.

[0049] Once the message is encrypted, the process forwards the encrypted transactional text message to the remote TSP in order to deliver the Short Message Service (SMS) text to the user device located at the remote location via the remote TSP's cellular network (508).

[0050] Furthermore, the validity of a shared secret can expire due to any desired trigger condition. For example, expiration can be triggered by (i) a time-based trigger that expires the shared secret based on the passage of a specified amount of time, e.g., the duration of a user's visit to the remote location or any other period specified by the user or another entity; (ii) a location-based trigger that expires the shared secret based on the user device moving outside the geographical boundaries of the remote location (e.g., the user leaving a foreign country where roaming service was provided); or (iii) a push-based trigger that expires the shared secret based on receiving an expiration indicator from a trusted source; or a combination thereof. An example of a push-based trigger is an airline pushing notifications to the respective home TSPs of passengers on an aircraft departing from a remote location / remote TSP service area.

[0051] For this purpose, the process in Figure 5A continues by determining (510) whether the shared secret held between the home TSP and the user should expire. For example, the query asks whether an expiration trigger, such as those described above, has been received / raised. If so (510, Y), the process triggers the expiration of the shared secret (512) and terminates. Based on the expiration, the home TSP at least temporarily disables the use of the shared secret in further encryption, e.g., in the encryption of subsequent messages to be forwarded to the user device. Otherwise (510, N), the process becomes temporarily idle and returns to 510 to repeat the query. This loop may be interrupted by receiving another message from a remote application server or any other source to be sent to a user device at a remote location, in which case the process may return to 504 and repeat the message encryption (506) and forwarding (508).

[0052] Figure 5B illustrates an exemplary process of an additional aspect performed by the home TSP system in a subscribed roaming scenario, where the user device is assigned a roaming cellular number by the remote TSP. In this scenario, encrypted transactional text messages are forwarded by the home TSP to the remote TSP for delivery to the user device via the roaming cellular number assigned by the remote TSP. The process in this scenario includes registering the roaming cellular number with the home TSP (520). In this example, the roaming cellular number is registered as an active secondary telephone number to establish a link between the home cellular number and the roaming cellular number. Registration may be based on the user authenticating the home TSP and securely registering the roaming cellular number with the home TSP. Forwarding (Figure 5A, 508) in this example includes sending encrypted transactional text messages to the roaming cellular number.

[0053] In connection with the registration of a roaming cellular number, the process also pre-establishes a communication path for transaction message communication between the home TSP and the remote TSP (522) before the start of a transaction that triggers the process in Figure 5A, in which the home TSP sends a test message to the remote TSP for delivery to the user device via the roaming cellular number.

[0054] Similar to the expiration of shared secrets in the home TSP, roaming cellular number registrations in the home TSP can also expire. Expiration can be triggered by time-based, location-based, or push-based triggers, or a combination thereof, as described above. The process determines whether to expire the registration (524), and if so (524, Y), triggers the expiration of the roaming cellular number registration (e.g., as an active secondary phone number in the home TSP) so that the use of the roaming cellular number in forwarding messages to the user device is disabled (526), ​​and then terminates. Once the registration expires, the home TSP can no longer send messages to the roaming number. Instead, if it is determined not to expire the registration (524, N), the process returns to 524 to periodically / aperiorally check whether to expire the registration.

[0055] Furthermore, in a subscribed roaming situation, layered encryption may be applied in a home TSP using multiple shared secrets. For example, the home TSP may generate a first shared secret, provide it to the user, and receive a second shared secret from the user to be used for double encryption. The home TSP may use the first shared secret to obtain one or more first cryptographic keys (e.g., first subkeys), use the second shared secret to obtain one or more second cryptographic keys (e.g., second subkeys), and perform encryption using those first and second cryptographic keys (Figure 5A, 506). Layered encryption may be desired by the user as an additional security measure when moving to a roaming location. In some examples, three or more shared secrets are used, and the layered encryption involves three or more layers of encryption based on a corresponding set of three or more cryptographic keys. This may be useful when it is anticipated that messages will be delivered through several TSPs or other services, where separate layers of encryption are desired.

[0056] As an enhancement when a user moves between roaming locations, the home TSP may perform two-tier encryption on incoming messages using two shared secrets (one for the home TSP and the other for the remote TSP that provides roaming services to the user device when the message is received). When a user moves outside of remote locations from the first remote TSP to another remote location on the second remote TSP, the home TSP may expire the shared secret corresponding to the first remote TSP and activate the shared secret corresponding to the second remote TSP for use.

[0057] Figure 5C shows an exemplary process including additional aspects performed by the home TSP system in an international roaming scenario according to the embodiments described herein, where the user's home cellular number is registered with a remote TSP for international roaming, and in international roaming, the remote TSP uses the home cellular number to communicate messages to the user device at a remote location. In this scenario, the process includes the home TSP generating a shared secret (530), providing the shared secret to the user, and using the shared secret (532) obtaining at least one cryptographic key to generate a subkey for, for example, a Feister cipher. Encryption of transactional text messages (Figure 5A, 506) uses at least one cryptographic key to encrypt transactional text messages. Also in both Figures 5B and 5C, the shared secret may expire (for example, as described above with respect to Figures 5A, 510, 512).

[0058] Figure 5D shows an exemplary process performed by a subscriber device according to the embodiments described herein. The process includes receiving / generating a shared secret (540). For example, the device may receive a shared secret from a home or remote TSP or both, or the device may generate one or more shared secrets and share them with a home or remote TSP or both, or a combination thereof. In a subscriber roaming situation, whenever the user device then roams to a remote location and registers with a remote TSP to receive a roaming cellular number, the device may generate a new shared secret and share it with the home TSP, for example, using dial-in authentication if a number has been issued.

[0059] The process continues when the user device initiates a transaction with the remote application server (542), which triggers the process shown in Figure 5A. At some point before or after the transaction initiation, the device obtains a decryption key based on the shared secrets being used (544). For example, the user device generates a subkey based on one or more shared secrets, which is the decryption key used to decrypt the received encrypted message. Finally, the user device receives the encrypted transaction text message and decrypts it using the decryption key (546). The encrypted message can only be decrypted by the decryption key if the shared secrets provided by the user as part of obtaining the decryption key are correct.

[0060] At that point, the user device can perform actions based on user input, such as clicking a link or entering an OTP on an interface. An example of such a process would include loading a URL or communicating the OTP to an application server or other remote entity to authenticate the user.

[0061] While various examples are provided, variations can be conceived without deviating from the spirit of the claimed embodiments.

[0062] The processes described herein are performed individually or in combination by one or more computer systems, which may, for example, be user / subscriber cellular devices, one or more devices in a telecommunications service provider network, one or more cloud servers, or one or more other computer systems, or a combination thereof, or may be incorporated into them. Figure 6 shows an example of such a computer system and associated devices for incorporating, using, or both, the embodiments described herein. Computer systems may also be referred to herein as data processing devices / systems, computing devices / systems / nodes, or simply computers. Computer systems may be based on one or more of various system architectures or instruction set architectures or combinations thereof, such as those provided by International Business Machines Corporation (Armonk, New York, USA), Intel Corporation (Santa Clara, California, USA), or ARM Holdings plc (Cambridge, UK, United Kingdom).

[0063] Figure 6 shows a computer system 600 communicating with an external device 612. The computer system 600 includes one or more processors 602, for example, a central processing unit (CPU). The processor may include functional components used to execute instructions, such as functional components for fetching program instructions from a location such as a cache or main memory, decoding program instructions, executing program instructions, accessing memory for instruction execution, and writing the results of executed instructions. The processor 602 may also include registers used by one or more of the functional components. The computer system 600 also includes memory 604, input / output (I / O) devices 608, and I / O interfaces 610, which may be connected to the processor 602 and each other via one or more buses or other types of connections or combinations thereof. Bus connections represent one or more of several types of bus structures, including memory buses or memory controllers, peripheral buses, accelerated graphics ports, and processor or local buses using any of the various bus architectures. Examples of such architectures, though not limited to them, include the Industry Standard Architecture (ISA) bus, Microchannel Architecture (MCA) bus, Enhanced ISA (EISA) bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.

[0064] Memory 604 may be or include main memory or system memory (e.g., random access memory) used for executing program instructions, storage devices such as hard drives, flash media, or optical media, or cache memory, or a combination thereof. Memory 604 may include a cache, such as a shared cache, which can be linked to the local cache of processor 602 (e.g., L1 cache, L2 cache, etc.). Furthermore, memory 604 may be or include at least one computer program product having a set (e.g., at least one) of program modules, instructions, code, etc., configured to perform the functions of the embodiments described herein when executed by one or more processors.

[0065] Memory 604 may store the operating system 605 and other computer programs 606, for example, one or more computer programs / applications that are executed to carry out embodiments described herein. Specifically, a program / application may include computer-readable program instructions that can be configured to perform the functions of embodiments of the embodiments described herein.

[0066] Examples of I / O devices 608 include, but are not limited to, microphones, speakers, Global Positioning System (GPS) devices, cameras, lights, accelerometers, gyroscopes, magnetometers, sensor devices configured to detect light, proximity, heart rate, body temperature or ambient temperature or both, blood pressure, or skin resistance, or a combination thereof, as well as activity monitors. While I / O devices may be integrated into a computer system as shown, in some embodiments, I / O devices may be considered as external devices (612) connected to the computer system through one or more I / O interfaces 610.

[0067] The computer system 600 may communicate with one or more external devices 612 via one or more I / O interfaces 610. Exemplary external devices include keyboards, pointing devices, displays, or any other devices, or combinations thereof, that enable a user to interact with the computer system 600. Other exemplary external devices include any devices that enable the computer system 600 to communicate with one or more other computing systems or peripheral devices, such as printers. Network interfaces / adapters are exemplary I / O interfaces that enable the computer system 600 to communicate with one or more networks, such as local area networks (LANs), common wide area networks (WANs), or public networks (e.g., the Internet), or combinations thereof, and provide communication with other computing devices or systems, storage devices, etc. Ethernet®-based interfaces (e.g., Wi-Fi®) and Bluetooth® adapters are simply examples of currently available types of network adapters used in computer systems (Bluetooth is a registered trademark of Bluetooth SIG, Inc., Kirkland, Washington, USA).

[0068] Communication between the I / O interface 610 and the external device 612 may occur over a wired or wireless communication link 611, or both, such as an Ethernet-based wired or wireless connection. Illustrative wireless connections include cellular, Wi-Fi, Bluetooth®, proximity-based, short-range, or other types of wireless connections. More generally, the communication link 611 may be any suitable wireless or wired communication link, or a combination thereof, for transmitting data.

[0069] A specific external device 612 may include one or more data storage devices capable of storing one or more programs, one or more computer-readable program instructions, or data, or a combination thereof. The computer system 600 may include, or be able to communicate with, removable / non-removable volatile / non-volatile computer system storage media (e.g., as external devices of the computer system), or both. For example, it may include, or be able to communicate with, a magnetic disk drive for reading from and writing to a non-removable non-volatile magnetic disk (e.g., a floppy disk), or an optical disk drive for reading from and writing to a removable non-volatile optical disk, e.g., a CD-ROM, DVD-ROM, or other optical media, or a combination thereof.

[0070] Computer system 600 may operate with a number of other general-purpose or dedicated computing system environments or configurations. Computer system 600 may take any of the following forms, and well-known examples include, but are not limited to, personal computer (PC) systems, server computer systems such as message servers, thin clients, thick clients, workstations, laptops, handheld devices, mobile devices / computers such as smartphones, tablets, and wearable devices, multiprocessor systems, microprocessor-based systems, telephone devices, network equipment (e.g., edge devices, virtualization devices, storage controllers, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and distributed cloud computing environments including any of the above systems or devices).

[0071] While this disclosure includes a detailed description of cloud computing, it should be understood that the implementation of the teachings described herein is not limited to cloud computing environments. Rather, embodiments of the present invention can be implemented in conjunction with any other type of computing environment currently known or to be developed in the future.

[0072] Cloud computing is a service delivery model that enables convenient on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processes, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and deployed with minimal management effort or interaction with service providers. This cloud model may include at least five characteristics, at least three service models, and at least four deployment models.

[0073] The characteristics are as follows:

[0074] On-demand self-service: Cloud consumers can unilaterally provision computing power, such as server time and network storage, automatically as needed, without requiring human interaction with service providers.

[0075] Broad network access: Capabilities are available over a network and accessed through standard mechanisms (e.g., mobile phones, laptops, and PDAs) that facilitate use by heterogeneous thin or thick client platforms.

[0076] Resource Pool: A provider's computing resources are pooled and served to multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically allocated and reallocated as needed. Generally, consumers have no control or knowledge of the exact location of the resources provided, but location independence is meaningful in that they may be able to specify location at a higher level of abstraction (e.g., country, state, or data center).

[0077] Rapid Flexibility: In some cases, capacity can be provisioned rapidly and flexibly for quick scale-out, and quickly released for rapid scale-in, automatically. To consumers, the capacity available for provisioning often appears unlimited and can be purchased in any quantity at any time.

[0078] Measured Services: Cloud systems automatically control and optimize resource usage by leveraging measurement capabilities at a level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both service providers and consumers of the services being used.

[0079] The service model is as follows:

[0080] Software as a Service (SaaS): The capability offered to consumers is the ability to use the provider's applications running on cloud infrastructure. These applications are accessible from various client devices through thin client interfaces such as web browsers (e.g., web-based email). Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, storage, or even individual application capabilities, with the exception of limited, user-specific application configuration settings.

[0081] Platform as a Service (PaaS): The capability offered to consumers is the ability to deploy applications created or acquired by the consumer, written using programming languages ​​and tools supported by the provider, onto a cloud infrastructure. Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but they have control over the deployed applications and, in some cases, the applications hosting the environment configuration.

[0082] Infrastructure as a Service (IaaS): The capability offered to consumers is the provisioning of processing, storage, networking, and other underlying computing resources that enable consumers to deploy and run any software, including operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but they have limited control over the operating system, storage, deployed applications, and, in some cases, selected networking components (e.g., host firewalls).

[0083] The deployment model is as follows:

[0084] Private Cloud: The cloud infrastructure operates solely for the organization. It can be managed by the organization or a third party and can reside on-premises or off-premises.

[0085] Community Cloud: Cloud infrastructure is shared by several organizations and supports a specific community with shared interests (e.g., mission, security requirements, policies, and compliance considerations). It can be managed by an organization or a third party and can reside on-premises or off-premises.

[0086] Public cloud: Cloud infrastructure is made available to the general public or large industry groups and is owned by organizations that sell cloud services.

[0087] Hybrid Cloud: Cloud infrastructure remains a distinct entity, but it is a composite of two or more clouds (private, community, or public) that are joined together by standardization or proprietary technologies (e.g., cloud bursting for load balancing between clouds) that enable data and application portability.

[0088] Cloud computing environments are services that prioritize statelessness, low coupling, modularity, and semantic interoperability. At the core of cloud computing lies an infrastructure that includes a network of interconnected nodes.

[0089] Referring here to Figure 7, an exemplary cloud computing environment 50 is shown. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 that can communicate with local computing devices used by cloud consumers, such as personal digital assistants (PDAs) or mobile phones 54A, desktop computers 54B, laptop computers 54C, or automotive computer systems 54N, or a combination thereof. The nodes 10 can communicate with each other. The nodes may be physically or virtually grouped (not shown) in one or more networks, such as private clouds, community clouds, public clouds, or hybrid clouds, or a combination thereof. This allows the cloud computing environment 50 to provide infrastructure as a service, platform as a service, or software as a service, or a combination thereof, without requiring cloud consumers to maintain resources on their local computing devices. The types of computing devices 54A-N shown in Figure 7 are for illustrative purposes only, and it should be understood that the computing nodes 10 and the cloud computing environment 50 can communicate with any type of computerized device through any type of network or network addressable connection (e.g., using a web browser) or both.

[0090] Referring now to Figure 8, a set of functional abstraction layers provided by the cloud computing environment 50 (Figure 7) is shown. It should be understood in advance that the components, layers, and functions shown in Figure 8 are for illustrative purposes only and that embodiments of the invention are not limited thereto. As shown in the figure, the following layers and corresponding functions are provided:

[0091] The hardware and software layer 60 includes hardware and software components. Examples of hardware components include a mainframe 61, a RISC (minimum instruction set computer) architecture-based server 62, a server 63, a blade server 64, a storage device 65, and network and networking components 66. In some embodiments, the software components include network application server software 67 and database software 68.

[0092] The virtualization layer 70 provides an abstraction layer from which the following example virtual entities may be provided: a virtual server 71, virtual storage 72, a virtual network 73 including a virtual private network, a virtual application and operating system 74, and a virtual client 75.

[0093] For example, the management layer 80 may provide the functions described below. Resource provisioning 81 provides dynamic procurement of computing resources and other resources used to perform tasks within the cloud computing environment. Measurement and pricing 82 provides cost tracking as resources are used within the cloud computing environment and billing or invoicing for the consumption of these resources. For example, these resources may include application software licenses. Security provides identity verification of cloud consumers and protection for tasks, data, and other resources. User portal 83 provides consumers and system administrators with access to the cloud computing environment. Service level management 84 provides cloud computing resource allocation and management to ensure that the required service levels are met. Service level agreement (SLA) planning and execution 85 provides pre-arrangements and procurement for cloud computing resources where future requirements are anticipated in accordance with the SLA.

[0094] The workload layer 90 provides examples of the functionality that can be utilized in a cloud computing environment. Examples of workloads and functions that can be provided from this layer include mapping and navigation 91, software development and lifecycle management 92, virtual classroom education delivery 93, data analytics processing 94, transaction processing 95, and message delivery 96 in cellular roaming scenarios.

[0095] The present invention may be a system, method, or computer program product, or a combination thereof, at any possible level of technical detail of integration. The computer program product may include a computer-readable storage medium having computer-readable program instructions for causing a processor to perform an aspect of the present invention.

[0096] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by instruction-executing devices. Computer-readable storage media may, but are not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any preferred combination thereof. A non-exhaustive list of more specific examples of computer-readable storage media includes, but is not limited to, portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital multipurpose disks (DVDs), memory sticks, floppy disks, mechanically encoded devices such as punched cards or grooved structures on which instructions are recorded, and any preferred combination thereof. As used herein, computer-readable storage media should not be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses passing through optical fiber cables), or electrical signals transmitted through wires.

[0097] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. The network adapter card or network interface of each computing / processing device receives computer-readable program instructions from the network and transfers the computer-readable program instructions for storage on a computer-readable storage medium within the individual computing / processing device.

[0098] The computer-readable program instructions for performing the operations of the present invention may be either source code or object code written in any combination of one or more programming languages, including assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, configuration data for integrated circuits, or object-oriented programming languages ​​such as Smalltalk®, C++, and procedural programming languages ​​such as the "C" programming language or similar programming languages. The computer-readable program instructions can be executed entirely on the user's computer, partially as a standalone software package on the user's computer, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or wide area network (WAN), or the connection may be to an external computer (e.g., via the Internet using an Internet Service Provider). In some embodiments, for example, an electronic circuit including a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA) can be personalized by executing computer-readable program instructions by utilizing state information of computer-readable program instructions in order to carry out aspects of the present invention.

[0099] Aspects of the present invention will be described herein with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It will be understood that each block in the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.

[0100] These computer-readable program instructions may be provided to a computer or other programmable data processing processor to create a machine, which is executed via the processor of the computer or other programmable data processing device, in order to create means for implementing functions / operations specified in one or more blocks of a flowchart and / or block diagram. These computer-readable program instructions may also be stored on a computer-readable storage medium on which the instructions are stored, which can be instructed to function in a particular way to provide a product containing instructions for implementing modes of functions / operations specified in one or more blocks of a flowchart and / or block diagram.

[0101] Computer-readable program instructions may also be instructions that are loaded onto a computer, other programmable data processing device, or other device to create a computer implementation process in order to implement a function / action specified in one or more blocks of a flowchart and / or block diagram, causing the computer, other programmable device, or other device to perform a series of operational steps.

[0102] The flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions, containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions shown in a block may occur in a different order than shown in the drawings. For example, two consecutively shown blocks may actually be implemented as a single substantially simultaneous step, executed concurrently in a partially or completely overlapping manner, or blocks may be executed in reverse order depending on the functionality involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in a block diagram and / or flowchart, may be implemented by an application-specific hardware-based system that performs a specified function or operation, or executes a combination of application-specific hardware and computer instructions.

[0103] In addition to the above, one or more aspects may be provided, given, deployed, managed, or serviced by a service provider that provides management of the customer's environment. For example, a service provider may create, maintain, and support computer code or computer infrastructure, or both, that runs one or more aspects for one or more customers. Conversely, a service provider may receive payments from customers, for example, under subscription fee or commission agreements or a combination thereof. Furthermore, or alternatively, a service provider may receive payments from the sale of advertising content to one or more third parties.

[0104] In one embodiment, an application may be deployed to perform one or more embodiments. For example, the deployment of the application includes providing a computer infrastructure capable of operating to perform one or more embodiments.

[0105] In a further embodiment, a computing infrastructure may be deployed that includes integrating computer-readable code into a computing system, where the code combined with the computing system is capable of performing one or more embodiments.

[0106] In yet another embodiment, a process for integrating a computing infrastructure may be provided, which includes integrating computer-readable code into a computer system. The computer system includes a computer-readable medium, the computer medium includes one or more embodiments. The code can be used in combination with the computer system to perform one or more embodiments.

[0107] Although various embodiments have been described above, these are merely examples.

[0108] The terms used herein are intended solely to describe and not to limit a particular embodiment. Where used herein, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context explicitly indicates otherwise. Where used herein, the terms “comprise” or “comprising” or both specify the presence of a described feature, integer, step, action, element, or component, or a combination thereof, but are further understood not to exclude the presence or addition of one or more other features, integers, steps, actions, elements, components, or groups thereof, or combinations thereof.

[0109] Any means or step-plus functional element in the following claims is intended to include, in particular claimed, a corresponding structure, material, movement, and, if there are equivalents thereto, a structure, material, or action for performing a function in combination with other claimed elements. For illustrative and descriptive purposes, descriptions of one or more embodiments have been presented, but are not intended to be exhaustive or limit to the disclosed forms. Many modifications and variations will be apparent to those skilled in the art. Embodiments have been selected and described in order to best illustrate various aspects and practical applications, and to enable those skilled in the art to understand various embodiments with various modifications suitable for a particular intended use.

Claims

1. A computer implementation method, The process includes the steps of: a user holding a user device receiving a transaction text message from a remote application server for provision to the user device, based on the user initiating a transaction with a remote application server, the transaction requesting user authentication based on the delivery of a transaction text message to the user device via a cellular network connection, wherein the user device is activated using a Home Telecommunications Service Provider (TSP) which provides cellular services to the user device located at a home location on the Home TSP's cellular network having a Home Cellular Number provided by the Home TSP, the transaction text message is received by the Home TSP and transmitted to the user device by the Home TSP, the user device is located at a remote location, and the user device is activated using a Remote TSP which provides roaming cellular services to the user device located at a remote location on the Remote TSP's cellular network; and receiving The steps include obtaining at least one encryption key using one or more shared secrets shared between the home TSP and the user, The steps include: the home TSP encrypting the transaction text message using the at least one encryption key and generating an encrypted transaction text message; The steps include: the home TSP forwarding the encrypted transaction text message to the remote TSP for delivery as a short message service (SMS) text to the user device located at the remote location via the cellular network of the remote TSP; Equipped with, method.

2. A step of triggering the expiration of one or more shared secrets, wherein, based on the expiration, the home TSP disables the use of the one or more shared secrets in encrypting subsequent messages to be transmitted to the user device, Furthermore, The expiration is triggered by at least one selected from the group consisting of (i) a time-based trigger that causes one or more shared secrets to expire based on the passage of a specified amount of time, (ii) a location-based trigger that causes one or more shared secrets to expire based on the user device moving outside a geographical boundary, and (iii) a push-based trigger that causes one or more shared secrets to expire based on the receipt of an expiration indicator from a trusted source. The method according to claim 1.

3. A computer implementation method, The process includes the steps of: a user holding a user device receiving a transaction text message from a remote application server for provision to the user device, based on the user initiating a transaction with a remote application server, the transaction requesting user authentication based on the delivery of a transaction text message to the user device via a cellular network connection, wherein the user device is activated using a Home Telecommunications Service Provider (TSP) which provides cellular services to the user device located at a home location on the Home TSP's cellular network having a Home Cellular Number provided by the Home TSP, the transaction text message is received by the Home TSP and transmitted to the user device by the Home TSP, the user device is located at a remote location, and the user device is activated using a Remote TSP which provides roaming cellular services to the user device located at a remote location on the Remote TSP's cellular network; and receiving The home TSP encrypts the transaction text message to generate an encrypted transaction text message, The steps include: the home TSP transferring the encrypted transaction text message to the remote TSP for delivery as a short message service (SMS) text to the user device located at the remote location via the cellular network of the remote TSP; Equipped with, The remote TSP assigns a roaming cellular number to the user device, and the encrypted transaction text message is forwarded by the home TSP to the remote TSP for delivery to the user device via the roaming cellular number assigned by the remote TSP. method.

4. The method according to claim 3, further comprising the step of establishing a communication path for transaction message communication between the home TSP and the remote TSP before initiating the transaction, wherein in the communication path, the home TSP sends a test message to the remote TSP for delivery to the user device via the roaming cellular number.

5. The method according to claim 3, further comprising the step of registering the roaming cellular number with the home TSP as an active secondary telephone number for establishing a link between the home cellular number and the roaming cellular number, wherein the registration step is based on the user authenticating using the home TSP and securely registering the roaming cellular number with the home TSP, and the forwarding step includes sending the encrypted transaction text message to the roaming cellular number.

6. The method according to claim 5, further comprising the step of triggering the expiration of the registration of the roaming cellular number as the active secondary telephone number, wherein, based on the expiration, the roaming cellular number is deactivated from use in forwarding messages to the user device.

7. The method according to claim 6, wherein the expiration is triggered by at least one selected from the group consisting of (i) a time-based trigger that expires the registration based on the passage of a specified amount of time, (ii) a location-based trigger that expires the registration based on the user device moving outside a geographical boundary, and (iii) a push-based trigger that expires the registration based on the receipt of an expiration indicator from a trusted source.

8. The steps include generating a first shared secret and providing the first shared secret to the user, The steps include receiving a second shared secret from the aforementioned user, The steps include obtaining one or more first cryptographic keys using the first shared secret, The steps include obtaining one or more second cryptographic keys using the second shared secret, and Furthermore, The step of encrypting the transaction text message involves generating the encrypted transaction text message for transfer using one or more first encryption keys and one or more second encryption keys for layered encryption of the transaction text message. The method according to claim 3.

9. A computer implementation method, The process includes the steps of: a user holding a user device receiving a transaction text message from a remote application server for provision to the user device, based on the user initiating a transaction with a remote application server, the transaction requesting user authentication based on the delivery of a transaction text message to the user device via a cellular network connection, wherein the user device is activated using a Home Telecommunications Service Provider (TSP) which provides cellular services to the user device located at a home location on the Home TSP's cellular network having a Home Cellular Number provided by the Home TSP, the transaction text message is received by the Home TSP and transmitted to the user device by the Home TSP, the user device is located at a remote location, and the user device is activated using a Remote TSP which provides roaming cellular services to the user device located at a remote location on the Remote TSP's cellular network; and receiving The home TSP encrypts the transaction text message to generate an encrypted transaction text message, The steps include: the home TSP transferring the encrypted transaction text message to the remote TSP for delivery as a short message service (SMS) text to the user device located at the remote location via the cellular network of the remote TSP; Equipped with, The transaction text message includes a time-dependent one-time password that the user provides to the remote application server for multi-factor authentication of the user for the execution of the transaction. method.

10. The home cellular number is registered with the remote TSP for international roaming, and in international roaming, the remote TSP uses the home cellular number to communicate messages to the user device located at the remote location, and the method is The steps include generating a shared secret and providing the shared secret to the user, The steps include obtaining at least one encryption key using the shared secret, and the encryption of the transaction text message, and obtaining the steps of encrypting the transaction text message using the at least one encryption key. The method according to any one of claims 1 to 9, further comprising:

11. A computer system, Memory and The system comprises a processor that communicates with the aforementioned memory, The aforementioned computer system A computer implementation method, The process includes the steps of: a user holding a user device receiving a transaction text message from a remote application server for provision to the user device, based on the user initiating a transaction with a remote application server, the transaction requesting user authentication based on the delivery of a transaction text message to the user device via a cellular network connection, wherein the user device is activated using a Home Telecommunications Service Provider (TSP) which provides cellular services to the user device located at a home location on the Home TSP's cellular network having a Home Cellular Number provided by the Home TSP, the transaction text message is received by the Home TSP and transmitted to the user device by the Home TSP, the user device is located at a remote location, and the user device is activated using a Remote TSP which provides roaming cellular services to the user device located at a remote location on the Remote TSP's cellular network; and receiving The steps include obtaining at least one encryption key using one or more shared secrets shared between the home TSP and the user, The steps include: the home TSP encrypting the transaction text message using the at least one encryption key and generating an encrypted transaction text message; The steps include: the home TSP forwarding the encrypted transaction text message to the remote TSP for delivery as a short message service (SMS) text to the user device located at the remote location via the cellular network of the remote TSP; The method is configured to perform, Computer system.

12. A step of triggering the expiration of one or more shared secrets, wherein, based on the expiration, the home TSP disables the use of the one or more shared secrets in the encryption of subsequent messages to be transmitted to the user device, It further includes, The expiration is triggered by at least one selected from the group consisting of (i) a time-based trigger that causes one or more shared secrets to expire based on the passage of a specified amount of time, (ii) a location-based trigger that causes one or more shared secrets to expire based on the user device moving outside a geographical boundary, and (iii) a push-based trigger that causes one or more shared secrets to expire based on the receipt of an expiration indicator from a trusted source. The computer system according to claim 11.

13. A computer system, Memory and The system comprises a processor that communicates with the aforementioned memory, The aforementioned computer system A computer implementation method, The process includes the steps of: a user holding a user device receiving a transaction text message from a remote application server for provision to the user device, based on the user initiating a transaction with a remote application server, the transaction requesting user authentication based on the delivery of a transaction text message to the user device via a cellular network connection, wherein the user device is activated using a Home Telecommunications Service Provider (TSP) which provides cellular services to the user device located at a home location on the Home TSP's cellular network having a Home Cellular Number provided by the Home TSP, the transaction text message is received by the Home TSP and transmitted to the user device by the Home TSP, the user device is located at a remote location, and the user device is activated using a Remote TSP which provides roaming cellular services to the user device located at a remote location on the Remote TSP's cellular network; and receiving The home TSP encrypts the transaction text message to generate an encrypted transaction text message, The steps include: the home TSP transferring the encrypted transaction text message to the remote TSP for delivery as a short message service (SMS) text to the user device located at the remote location via the cellular network of the remote TSP; It is configured to perform a method that includes, The remote TSP assigns a roaming cellular number to the user device, and the encrypted transaction text message is forwarded by the home TSP to the remote TSP for delivery to the user device via the roaming cellular number assigned by the remote TSP. Computer system.

14. A computer system, Memory and The system comprises a processor that communicates with the aforementioned memory, The aforementioned computer system A computer implementation method, The process includes the steps of: a user holding a user device receiving a transaction text message from a remote application server for provision to the user device, based on the user initiating a transaction with a remote application server, the transaction requesting user authentication based on the delivery of a transaction text message to the user device via a cellular network connection, wherein the user device is activated using a Home Telecommunications Service Provider (TSP) which provides cellular services to the user device located at a home location on the Home TSP's cellular network having a Home Cellular Number provided by the Home TSP, the transaction text message is received by the Home TSP and transmitted to the user device by the Home TSP, the user device is located at a remote location, and the user device is activated using a Remote TSP which provides roaming cellular services to the user device located at a remote location on the Remote TSP's cellular network; and receiving The home TSP encrypts the transaction text message to generate an encrypted transaction text message, The steps include: the home TSP transferring the encrypted transaction text message to the remote TSP for delivery as a short message service (SMS) text to the user device located at the remote location via the cellular network of the remote TSP; It is configured to perform a method that includes, The transaction text message includes a time-dependent one-time password that the user provides to the remote application server for multi-factor authentication of the user for the execution of the transaction. Computer system.

15. The method described above is The steps include obtaining at least one encryption key using one or more shared secrets shared between the home TSP and the user, wherein the encryption of the transaction text message encrypts and obtains the transaction text message using the at least one encryption key. A step of triggering the expiration of one or more shared secrets, wherein, based on the expiration, the home TSP disables the use of the one or more shared secrets in encrypting subsequent messages to be transferred to the user device. The computer system according to claim 13 or 14, further comprising:

16. A computer system according to any one of claims 11 to 14, wherein the remote TSP assigns a roaming cellular number to the user device, the encrypted transaction text message is forwarded by the home TSP to the remote TSP for delivery to the user device via the roaming cellular number assigned by the remote TSP, the method further comprising registering the roaming cellular number with the home TSP as an active secondary telephone number for establishing a link between the home cellular number and the roaming cellular number, the registration being based on the user authenticating using the home TSP and securely registering the roaming cellular number with the home TSP, and the forwarding being sending the encrypted transaction text message to the roaming cellular number.

17. The home cellular number is registered with the remote TSP for international roaming, and in international roaming, the remote TSP uses the home cellular number to communicate messages to the user device located at the remote location, and the method is The steps include generating a shared secret and providing the shared secret to the user, The steps include obtaining at least one encryption key using the shared secret, and the encryption of the transaction text message, and obtaining the steps of encrypting the transaction text message using the at least one encryption key. A computer system according to any one of claims 11 to 14, further comprising the above.

18. On the computer, A procedure for receiving a transaction text message from a remote application server for delivery to a user device, based on the user holding a user device initiating a transaction with a remote application server, the transaction requesting user authentication based on the delivery of a transaction text message to the user device via a cellular network connection, wherein the user device is activated using a Home Telecommunications Service Provider (TSP) which provides cellular services to the user device located at a home location on the Home TSP's cellular network having a Home Cellular Number provided by the Home TSP, the transaction text message is received by the Home TSP and transmitted to the user device by the Home TSP, the user device is located at a remote location, and the user device is activated using a Remote TSP which provides roaming cellular services to the user device located at a remote location on the Remote TSP's cellular network, and the procedure for receiving the transaction text message. A procedure for obtaining at least one encryption key using one or more shared secrets shared between the home TSP and the user, A procedure for the home TSP to encrypt the transaction text message using at least one of the aforementioned encryption keys and generate an encrypted transaction text message, A procedure for the home TSP to transfer the encrypted transaction text message to the remote TSP for delivery as a short message service (SMS) text to the user device located at the remote location via the cellular network of the remote TSP, To execute Computer program.

19. The computer, A procedure for triggering the expiration of one or more shared secrets, wherein, based on the expiration, the home TSP disables the use of the one or more shared secrets in encrypting subsequent messages to be forwarded to the user device, Let's execute it further, The expiration is triggered by at least one selected from the group consisting of (i) a time-based trigger that causes one or more shared secrets to expire based on the passage of a specified amount of time, (ii) a location-based trigger that causes one or more shared secrets to expire based on the user device moving outside a geographical boundary, and (iii) a push-based trigger that causes one or more shared secrets to expire based on the receipt of an expiration indicator from a trusted source. The computer program according to claim 18.

20. On the computer, A procedure for receiving a transaction text message from a remote application server for delivery to a user device, based on the user holding a user device initiating a transaction with a remote application server, the transaction requesting user authentication based on the delivery of a transaction text message to the user device via a cellular network connection, wherein the user device is activated using a Home Telecommunications Service Provider (TSP) which provides cellular services to the user device located at a home location on the Home TSP's cellular network having a Home Cellular Number provided by the Home TSP, the transaction text message is received by the Home TSP and transmitted to the user device by the Home TSP, the user device is located at a remote location, and the user device is activated using a Remote TSP which provides roaming cellular services to the user device located at a remote location on the Remote TSP's cellular network, and the procedure for receiving the transaction text message. The procedure involves the home TSP encrypting the transaction text message to generate an encrypted transaction text message, A procedure for the home TSP to transfer the encrypted transaction text message to the remote TSP for delivery as a short message service (SMS) text to the user device located at the remote location via the cellular network of the remote TSP, and Make it run, The remote TSP assigns a roaming cellular number to the user device, and the encrypted transaction text message is forwarded by the home TSP to the remote TSP for delivery to the user device via the roaming cellular number assigned by the remote TSP. Computer program.

21. On the computer, A procedure for receiving a transaction text message from a remote application server for delivery to a user device, based on the user holding a user device initiating a transaction with a remote application server, the transaction requesting user authentication based on the delivery of a transaction text message to the user device via a cellular network connection, wherein the user device is activated using a Home Telecommunications Service Provider (TSP) which provides cellular services to the user device located at a home location on the Home TSP's cellular network having a Home Cellular Number provided by the Home TSP, the transaction text message is received by the Home TSP and transmitted to the user device by the Home TSP, the user device is located at a remote location, and the user device is activated using a Remote TSP which provides roaming cellular services to the user device located at a remote location on the Remote TSP's cellular network, and the procedure for receiving the transaction text message. The procedure involves the home TSP encrypting the transaction text message to generate an encrypted transaction text message, A procedure for the home TSP to transfer the encrypted transaction text message to the remote TSP for delivery as a short message service (SMS) text to the user device located at the remote location via the cellular network of the remote TSP, and Make it run, The transaction text message includes a time-dependent one-time password that the user provides to the remote application server for multi-factor authentication of the user for the execution of the transaction. Computer program.

22. To the aforementioned computer, A procedure for obtaining at least one encryption key using one or more shared secrets shared between the home TSP and the user, wherein the encryption of the transaction text message is a procedure for obtaining the transaction text message by encrypting it using the at least one encryption key. A procedure for triggering the expiration of one or more shared secrets, wherein, based on the expiration, the home TSP disables the use of the one or more shared secrets in encrypting subsequent messages to be forwarded to the user device. A computer program according to claim 20 or 21, which further causes the execution of the above.

23. A computer program according to any one of claims 18 to 21, wherein the remote TSP assigns a roaming cellular number to the user device, the encrypted transaction text message is forwarded by the home TSP to the remote TSP for delivery to the user device via the roaming cellular number assigned by the remote TSP, and the computer further performs a step of registering the roaming cellular number with the home TSP as an active secondary telephone number for establishing a link between the home cellular number and the roaming cellular number, wherein the registration step is based on the user authenticating using the home TSP and securely registering the roaming cellular number with the home TSP, and the forwarding step includes sending the encrypted transaction text message to the roaming cellular number.

24. The home cellular number is registered with the remote TSP for international roaming, and in international roaming, the remote TSP uses the home cellular number to communicate messages to the user device located at the remote location, and to the computer, A procedure for generating a shared secret and providing the shared secret to the user, A procedure for obtaining at least one cryptographic key using the shared secret, wherein the encryption of the transaction text message is a procedure for obtaining the transaction text message by encrypting it using the at least one cryptographic key. A computer program according to any one of claims 18 to 21, which further performs the following:

Citation Information

Patent Citations

  • Inter-network authentication key generating method

    JP1995059154A

  • Authentication method and system, portable device, authentication server, and authentication requesting terminal

    JP2008197710A

  • Authentication in Secure User Plane Location (SUPL) systems

    JP2013546260A

  • Information processing system and program

    JP2021072557A

  • System and method for mobile telephone roaming

    US20200236549A1