CN103096316A - Terminal, network side equipment system and method for authenticating user identification card - Google Patents

Terminal, network side equipment system and method for authenticating user identification card Download PDF

Info

Publication number
CN103096316A
CN103096316A CN201110345974.XA CN201110345974A CN103096316A CN 103096316 A CN103096316 A CN 103096316A CN 201110345974 A CN201110345974 A CN 201110345974A CN 103096316 A CN103096316 A CN 103096316A
Authority
CN
China
Prior art keywords
terminal
authentication
assistant authentification
server
instruction
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201110345974.XA
Other languages
Chinese (zh)
Inventor
张世伟
符涛
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
ZTE Corp
Original Assignee
ZTE Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ZTE Corp filed Critical ZTE Corp
Priority to CN201110345974.XA priority Critical patent/CN103096316A/en
Publication of CN103096316A publication Critical patent/CN103096316A/en
Pending legal-status Critical Current

Links

Images

Abstract

The invention provides a terminal, a network side equipment system and a method for authenticating a user identification card. One step of the method is that before the terminal is accessed to the network, one or more times of auxiliary certification between the terminal and network side are carried out except routine access authentication between the terminal and the network side, and the terminal can be accessed to the network only when the routine access authentication and auxiliary certification are passed. According to the technical scheme, swindle activities by other people through mobile phones can be prevented from happening when the mobile phones are stolen or lost.

Description

Terminal, network equipment system and method that Subscriber Identity Module is authenticated
Technical field
The present invention relates to communication field, be specifically related to a kind of terminal, network equipment system and method that Subscriber Identity Module is authenticated.
Background technology
The mobile terminal of existing communication network has had certain fail safe, but when the lost mobile phone of user A or when going adrift, even the mobile phone of A is provided with password, finding people B still can take out the SIM/USIM card in mobile phone to be put on other mobile phone and make a phone call, even pretend to be A to defraud of money, although A can arrive the telecommunication business Room and report the loss SIM/USIM, but due to from losing to reporting the loss, there is a time difference, make pilferage mobile phone person B have certain hour (even one day half an hour) to implement fraud, thereby encroached on the interests of user A.
Therefore must seek a kind of method, when preventing hand-set from stolen or loss, be usurped by other people and cause more serious loss.
Summary of the invention
The technical problem to be solved in the present invention is to provide a kind of terminal, network equipment system and method that Subscriber Identity Module is authenticated, and in the time of can preventing hand-set from stolen or loss, other people use mobile phone to carry out fraud.
The invention provides a kind of method that Subscriber Identity Module is authenticated, comprising:
Before accessing terminal to network, except carrying out conventional access authentication with network side, also carry out the assistant authentification of taking turns or taking turns more with network side, after described conventional access authentication and described assistant authentification all passed through, described terminal can access network.
Further, described conventional access authentication is before assistant authentification, and perhaps described conventional access authentication is after assistant authentification.
Further, after described terminal received that the instruction of assistant authentification is carried out in requirement, the assistant authentification type according in instruction was sent to network side with corresponding authentication information.
Further, described terminal sends after with described encrypted authentication information.
Further, described assistant authentification type comprises any one or more in following mode: cipher authentication, finger print identifying and gesture authentication.
The present invention also provides a kind of method that Subscriber Identity Module is authenticated, and comprising:
When the demanding terminal access service network, the server of network side is except carrying out conventional access authentication with terminal, also carry out taking turns or taking turns more assistant authentification with described terminal, after described conventional access authentication and described assistant authentification all pass through, allow described terminal access service network.
Further, described conventional access authentication is before assistant authentification, and perhaps described conventional access authentication is after assistant authentification.
Further, when described server requirement and terminal are carried out assistant authentification, send indication to described terminal and carry out the instruction of assistant authentification, the authentication information with storage after receiving the authentication information that terminal is sent compares, if unanimously assistant authentification pass through.
Further, described instruction comprises the assistant authentification type;
Described assistant authentification type comprises any one or more in following mode: cipher authentication, finger print identifying and gesture authentication.
Further, described authentication instruction is forwarded to terminal by intermediate NE, and described authentication information is forwarded to server by described intermediate NE;
In the WCDMA system, described intermediate NE is GGSN;
In the CDMA2000 system, described intermediate NE is PDSN;
In the LTE system, described intermediate NE is PGW;
In LISP system, described intermediate NE is ITR;
In the marked net system, described intermediate NE is ASR.
Further, be sent to server after the described encrypted authentication information that described intermediate NE will receive.
The present invention also provides a kind of network equipment that Subscriber Identity Module is authenticated, described network equipment comprises server, be used for carrying out conventional access authentication and assistant authentification with terminal, and after described conventional access authentication and described assistant authentification all pass through, allow described terminal access service network.
Further, when described server requirement and terminal are carried out assistant authentification, send indication to described terminal and carry out the instruction of assistant authentification, the authentication information with storage after receiving the authentication information that terminal is sent compares, if unanimously assistant authentification pass through.
Further, described server also is used for receiving and storing the assistant authentification type;
Described assistant authentification type comprises any one or more in following mode: cipher authentication, finger print identifying and gesture authentication.
Further, the described instruction of carrying out assistant authentification comprises the assistant authentification type.
Further, described network equipment also comprises intermediate NE, and the authentication instruction that is used for the server that will receive is forwarded to terminal, and the authentication information of the terminal that receives is forwarded to server;
In the WCDMA system, described intermediate NE is GGSN;
In the CDMA2000 system, described intermediate NE is PDSN;
In the LTE system, described intermediate NE is PGW;
In LISP system, described intermediate NE is ITR;
In the marked net system, described intermediate NE is ASR.
Further, described intermediate NE also is used for being sent to described server after the described encrypted authentication information that will receive.
The present invention also provides a kind of terminal that Subscriber Identity Module is authenticated, and described terminal comprises receiver module and sending module;
Described receiver module is used for the authentication instruction that reception server is sent;
Described sending module is used for according to described authentication instruction, the authentication information of correspondence being sent to described server;
Described authentication instruction comprises carries out conventional access authentication and assistant authentification.
Further, described terminal also comprises encrypting module, is used for sending after encrypted authentication information.
The present invention also provides a kind of system that Subscriber Identity Module is authenticated, and described system comprises as above arbitrary described network equipment, and as above arbitrary described terminal.
The present invention selects to implement assistant authentification by the user except mobile phone being implemented SIM card or usim card authentication, assistant authentification passes through, normally carry out business operation, assistant authentification does not pass through, and does not allow business operation, perhaps implements limited business operation (receiving calls as only allowing).
The present invention is in the certificate servers such as AAA, an assistant authentification type code will be increased in user property, this type sign can comprise: without multiple auth types such as assistant authentification, fingerprint assistant authentification, password assistant authentifications, be set to the types such as fingerprint assistant authentification or password assistant authentification when this sign, enable corresponding assistant authentification, by the flow process in the present invention, just can enable the assistant authentification function, thereby guarantee also can't operate after mobile phone or SIM card are usurped by others.
Need the support of terminal due to the assistant authentification in the present invention, therefore the assistant authentification sign in AAA can be set by user oneself, when the user possesses the mobile phone of assistant authentification, the user can pass through business hall or the direct assistant authentification sign of revising in aaa server in the WEB webpage, thereby enables assistant authentification.
Description of drawings
Fig. 1 is the execution mode of the assistant authentification as an example of WCDMA example;
Fig. 2 adopts the schematic diagram one of gesture authentication in application example of the present invention;
Fig. 3 adopts the schematic diagram two of gesture authentication in application example of the present invention.
Embodiment
The invention provides a kind of method, terminal, network equipment and system that Subscriber Identity Module is authenticated, can effectively improve existing authentication method, improve safety in utilization.
A kind of terminal that Subscriber Identity Module is authenticated of terminal embodiment comprises receiver module, sending module; Can further include encrypting module;
Receiver module is used for the authentication instruction that reception server is sent;
Sending module is used for according to described authentication instruction, the authentication information of correspondence being sent to server;
The authentication instruction comprises carries out conventional access authentication and assistant authentification.
Assistant authentification comprises any one or more in following mode: cipher authentication, finger print identifying and gesture authentication.
Encrypting module is used for and will sends after encrypted authentication information.
Network equipment embodiment
The present embodiment provides a kind of network equipment that Subscriber Identity Module is authenticated, and comprises server, also can further comprise intermediate NE;
Described server is used for carrying out conventional access authentication and assistant authentification with terminal, and after described conventional access authentication and described assistant authentification all pass through, allows described terminal access service network.
Further, when server requirement and terminal are carried out assistant authentification, send indication to terminal and carry out the instruction of assistant authentification, the authentication information with storage after receiving the authentication information that terminal is sent compares, if unanimously assistant authentification pass through.
Further, server also is used for receiving and storing the assistant authentification type; Described assistant authentification type comprises any one or more in following mode: cipher authentication, finger print identifying and gesture authentication.
Further, the described instruction of carrying out assistant authentification comprises the assistant authentification type.
Further, intermediate NE, the authentication instruction that is used for the server that will receive is forwarded to terminal, and the authentication information of the terminal that receives is forwarded to server;
In the WCDMA system, described intermediate NE is GGSN;
In the CDMA2000 system, described intermediate NE is PDSN;
In the LTE system, described intermediate NE is PGW;
In LISP system, described intermediate NE is ITR;
In the marked net system, described intermediate NE is ASR.
Further, intermediate NE also is used for being sent to described server after the described encrypted authentication information that will receive.
System embodiment
The present embodiment provides a kind of system that Subscriber Identity Module is authenticated, and comprises the described network equipment of above network equipment embodiment, and the described terminal of terminal embodiment.
Embodiment of the method
The present embodiment provides a kind of method that Subscriber Identity Module is authenticated, the present embodiment take first carry out conventional access authentication (as can but to be not limited to be AKA authentication) after carry out assistant authentification as example is described, as shown in Figure 1, comprising:
Step 101: terminal is first carried out original SIM/USIM card authentication, when by authentication, carry out step 102.
If by the authentication of SIM/USIM card, do not illustrate that SIM/USIM is invalid, refuse the terminal access, flow process finishes.
Step 102:HLR or aaa server are after authenticating by the SIM/USIM card, and the assistant authentification type code of inquiring user if this is masked as " without assistant authentification ", directly carries out regular traffic.Have the assistant authentification type if this is masked as, as finger print identifying, gesture authentication or cipher authentication etc., carry out step 103 according to the assistant authentification type.
Step 103:HLR or aaa server will need the message of assistant authentification information to issue GGSN;
Step 104:GGSN will need the message of assistant authentification information to be transmitted to terminal.
Step 105: terminal is according to the assistant authentification information of sending, and the prompting user inputs corresponding assistant authentification information, as requires the user to input password, perhaps requires the user that fingerprint or gesture etc. are provided.
Step 106: terminal through proper transformation, as after being encrypted, passes to GGSN with the assistant authentification information of user's input.
Step 107:GGSN passes to HLR/AAA with assistant authentification information.
The assistant authentification information that step 108:HLR/AAA contrast is returned, and if the data of storing in HLR/AAA through with the terminal same transitions after consistent, assistant authentification passes through, and notifies GGSN to carry out normal business operation.If inconsistent, illustrate that user's SIM card is stolen, notice GGSN termination business is carried out.
Step 109:GGSN if pass through, allows terminal to carry out regular traffic according to the assistant authentification result of the HLR/AAA that receives.If do not pass through, refuse terminal and carry out regular traffic (or only allow terminal to carry out urgent call or the business such as only allow to answer).Simultaneously with the notification terminal as a result of assistant authentification.
Step 110: after assistant authentification passed through, terminal can normally be carried out business.
Explanation is in addition, and step 101 and step 110 are the operation flows in original WCDMA, and the present invention has increased step 102~109, thereby has realized assistant authentification, has increased the anti-theft capability of SIM card/usim card.
The below illustrates the coding implementation of gesture authentication:
In Fig. 2 and Fig. 3, provided a kind of example of terminal gesture coding, Fig. 2 is divided into several zones with the mobile phone terminal screen, and each zone can be by specific code identification.
When the user slided by the gesture in Fig. 3, corresponding gesture can be encoded to " 012349EJIHGFKPUZ# $ * ﹠amp; VTSR ", this coding result is included in step 106 and step 107, returns to AAA by terminal, and aaa server is by comparing with the gesture that prestores, thereby can realize the assistant authentification based on gesture.
In the present invention, illustrate with WCDMA in specification, but the present invention is not limited to the flow process of WCDMA.The inventive method can be used in CDMA2000, LTE and identity and locator separation network (as marked net, LISP) easily, and the below is given in the implementation method in various systems
In CDMA2000, as long as GGSN is replaced with PDSN, above-mentioned flow process is still available.
In LTE, as long as GGSN is replaced with PGW, above-mentioned flow process is still available.
In LISP, as long as GGSN is replaced with ITR, above-mentioned flow process is still available.
In marked net, as long as GGSN is replaced with ASR, above-mentioned flow process is still available.
By above-mentioned method, when user's lost mobile phone, even find the directly start of people of mobile phone, also can't pass through assistant authentification, even find the people of mobile phone, the taking-up of SIM/USIM card is put in other mobile phones, can't carries out regular traffic too, wait harm to operate thereby can't usurp this number enforcement deception, avoided issuable fraudulent act, thereby avoided the user of lost mobile phone is caused further loss.

Claims (20)

1. method that Subscriber Identity Module is authenticated comprises:
Before accessing terminal to network, except carrying out conventional access authentication with network side, also carry out the assistant authentification of taking turns or taking turns more with network side, after described conventional access authentication and described assistant authentification all passed through, described terminal can access network.
2. the method for claim 1 is characterized in that:
Described conventional access authentication is before assistant authentification, and perhaps described conventional access authentication is after assistant authentification.
3. method as claimed in claim 1 or 2 is characterized in that:
After described terminal received that the instruction of assistant authentification is carried out in requirement, the assistant authentification type according in instruction was sent to network side with corresponding authentication information.
4. method as claimed in claim 3 is characterized in that:
Described terminal sends after with described encrypted authentication information.
5. method as claimed in claim 3 is characterized in that:
Described assistant authentification type comprises any one or more in following mode: cipher authentication, finger print identifying and gesture authentication.
6. method that Subscriber Identity Module is authenticated comprises:
When the demanding terminal access service network, the server of network side is except carrying out conventional access authentication with terminal, also carry out taking turns or taking turns more assistant authentification with described terminal, after described conventional access authentication and described assistant authentification all pass through, allow described terminal access service network.
7. method as claimed in claim 6 is characterized in that:
Described conventional access authentication is before assistant authentification, and perhaps described conventional access authentication is after assistant authentification.
8. method as described in claim 6 or 7 is characterized in that:
When described server requirement and terminal are carried out assistant authentification, send indication to described terminal and carry out the instruction of assistant authentification, the authentication information with storage after receiving the authentication information that terminal is sent compares, if unanimously assistant authentification pass through.
9. method as claimed in claim 8 is characterized in that:
Described instruction comprises the assistant authentification type;
Described assistant authentification type comprises any one or more in following mode: cipher authentication, finger print identifying and gesture authentication.
10. method as claimed in claim 7 is characterized in that:
Described authentication instruction is forwarded to terminal by intermediate NE, and described authentication information is forwarded to server by described intermediate NE;
In the WCDMA system, described intermediate NE is GGSN;
In the CDMA2000 system, described intermediate NE is PDSN;
In the LTE system, described intermediate NE is PGW;
In LISP system, described intermediate NE is ITR;
In the marked net system, described intermediate NE is ASR.
11. method as claimed in claim 10 is characterized in that:
Be sent to server after the described encrypted authentication information that described intermediate NE will receive.
12. the network equipment that Subscriber Identity Module is authenticated is characterized in that:
Described network equipment comprises server, is used for carrying out conventional access authentication and assistant authentification with terminal, and after described conventional access authentication and described assistant authentification all pass through, allows described terminal access service network.
13. network equipment as claimed in claim 12 is characterized in that:
When described server requirement and terminal are carried out assistant authentification, send indication to described terminal and carry out the instruction of assistant authentification, the authentication information with storage after receiving the authentication information that terminal is sent compares, if unanimously assistant authentification pass through.
14. network equipment as claimed in claim 13 is characterized in that:
Described server also is used for receiving and storing the assistant authentification type;
Described assistant authentification type comprises any one or more in following mode: cipher authentication, finger print identifying and gesture authentication.
15. network equipment as described in claim 13 or 14 is characterized in that:
The described instruction of carrying out assistant authentification comprises the assistant authentification type.
16. network equipment as claimed in claim 13 is characterized in that:
Described network equipment also comprises intermediate NE, and the authentication instruction that is used for the server that will receive is forwarded to terminal, and the authentication information of the terminal that receives is forwarded to server;
In the WCDMA system, described intermediate NE is GGSN;
In the CDMA2000 system, described intermediate NE is PDSN;
In the LTE system, described intermediate NE is PGW;
In LISP system, described intermediate NE is ITR;
In the marked net system, described intermediate NE is ASR.
17. network equipment as claimed in claim 16 is characterized in that:
Described intermediate NE also is used for being sent to described server after the described encrypted authentication information that will receive.
18. the terminal that Subscriber Identity Module is authenticated is characterized in that:
Described terminal comprises receiver module and sending module;
Described receiver module is used for the authentication instruction that reception server is sent;
Described sending module is used for according to described authentication instruction, the authentication information of correspondence being sent to described server;
Described authentication instruction comprises carries out conventional access authentication and assistant authentification.
19. terminal as claimed in claim 18 is characterized in that:
Described terminal also comprises encrypting module, is used for sending after encrypted authentication information.
20. the system that Subscriber Identity Module is authenticated is characterized in that:
Described system comprises described network equipment as arbitrary in claim 12 to 17, and described terminal as arbitrary in claim 18 or 19.
CN201110345974.XA 2011-11-04 2011-11-04 Terminal, network side equipment system and method for authenticating user identification card Pending CN103096316A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201110345974.XA CN103096316A (en) 2011-11-04 2011-11-04 Terminal, network side equipment system and method for authenticating user identification card

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201110345974.XA CN103096316A (en) 2011-11-04 2011-11-04 Terminal, network side equipment system and method for authenticating user identification card

Publications (1)

Publication Number Publication Date
CN103096316A true CN103096316A (en) 2013-05-08

Family

ID=48208331

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201110345974.XA Pending CN103096316A (en) 2011-11-04 2011-11-04 Terminal, network side equipment system and method for authenticating user identification card

Country Status (1)

Country Link
CN (1) CN103096316A (en)

Cited By (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104918241A (en) * 2014-03-12 2015-09-16 中国移动通信集团湖北有限公司 User authentication method and system
WO2017028138A1 (en) * 2015-08-16 2017-02-23 张焰焰 Method and mobile terminal for authenticating account login with number information and fingerprint
WO2017028139A1 (en) * 2015-08-16 2017-02-23 张焰焰 Method and mobile terminal for indicating information after authenticating account login with number information and fingerprint
WO2017031705A1 (en) * 2015-08-25 2017-03-02 张焰焰 Method and mobile terminal for authenticating account login via gesture and fingerprint
WO2017031733A1 (en) * 2015-08-26 2017-03-02 张焰焰 Method and mobile terminal for indicating information after authenticating account login via gesture and fingerprint
WO2017031656A1 (en) * 2015-08-22 2017-03-02 张焰焰 Method and mobile terminal for pushing information indication upon three-factor authentication of account login
WO2017031654A1 (en) * 2015-08-22 2017-03-02 张焰焰 Method and mobile terminal for indicating information after authenticating account login via gesture and number information
WO2017031653A1 (en) * 2015-08-22 2017-03-02 张焰焰 Method and mobile terminal for authenticating account login via gesture and number information
WO2017101571A1 (en) * 2015-12-16 2017-06-22 中兴通讯股份有限公司 User identity authentication method, apparatus and system thereof
CN108174354A (en) * 2017-12-26 2018-06-15 中国联合网络通信集团有限公司 NPO mobile phones fraud recourse method and system
CN110135229A (en) * 2018-10-30 2019-08-16 初速度(苏州)科技有限公司 A kind of driver identity identifying system using neural network

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104918241A (en) * 2014-03-12 2015-09-16 中国移动通信集团湖北有限公司 User authentication method and system
WO2017028138A1 (en) * 2015-08-16 2017-02-23 张焰焰 Method and mobile terminal for authenticating account login with number information and fingerprint
WO2017028139A1 (en) * 2015-08-16 2017-02-23 张焰焰 Method and mobile terminal for indicating information after authenticating account login with number information and fingerprint
WO2017031656A1 (en) * 2015-08-22 2017-03-02 张焰焰 Method and mobile terminal for pushing information indication upon three-factor authentication of account login
WO2017031654A1 (en) * 2015-08-22 2017-03-02 张焰焰 Method and mobile terminal for indicating information after authenticating account login via gesture and number information
WO2017031653A1 (en) * 2015-08-22 2017-03-02 张焰焰 Method and mobile terminal for authenticating account login via gesture and number information
WO2017031705A1 (en) * 2015-08-25 2017-03-02 张焰焰 Method and mobile terminal for authenticating account login via gesture and fingerprint
WO2017031733A1 (en) * 2015-08-26 2017-03-02 张焰焰 Method and mobile terminal for indicating information after authenticating account login via gesture and fingerprint
WO2017101571A1 (en) * 2015-12-16 2017-06-22 中兴通讯股份有限公司 User identity authentication method, apparatus and system thereof
CN106888193A (en) * 2015-12-16 2017-06-23 中兴通讯股份有限公司 A kind of method for authenticating user identity, device and its system
CN108174354A (en) * 2017-12-26 2018-06-15 中国联合网络通信集团有限公司 NPO mobile phones fraud recourse method and system
CN110135229A (en) * 2018-10-30 2019-08-16 初速度(苏州)科技有限公司 A kind of driver identity identifying system using neural network

Similar Documents

Publication Publication Date Title
CN103096316A (en) Terminal, network side equipment system and method for authenticating user identification card
EP3223549B1 (en) Wireless network access method and access apparatus, client and storage medium
US6427073B1 (en) Preventing misuse of a copied subscriber identity in a mobile communication system
US10743180B2 (en) Method, apparatus, and system for authenticating WIFI network
CN109347635A (en) A kind of Internet of Things security certification system and authentication method based on national secret algorithm
CN107113613B (en) Server, mobile terminal, network real-name authentication system and method
CN102598641A (en) Method of identity authentication and fraudulent phone call verification that utilizes an identification code of a communication device and a dynamic password
CN102056077B (en) Method and device for applying smart card by key
CN105472093B (en) Mobile terminal call answers method for authenticating and mobile terminal
CN103945374A (en) Method of mobile terminal equipment and user authentication based on PKI technology
CN101393434A (en) Stamp control device and system
CN1997188A (en) A recognition method of the user identity and its handset
CN107333263B (en) Improved SIM card and mobile communication identity recognition method and system
CN103037366A (en) Mobile terminal user authentication method and mobile terminal based on asymmetric cryptographic technique
KR101281099B1 (en) An Authentication method for preventing damages from lost and stolen smart phones
CN103686651A (en) Emergency call based authentication method, device and system
CN103401686B (en) A kind of user's OTP WEB Authentication System and application process thereof
KR101306074B1 (en) Method and system to prevent phishing
CN109587683A (en) Method and system, application program and the terminal information database of the anti-monitoring of short message
CN106211146B (en) Adding method, information communicating method and call method and system are recorded in safety communication
CN101364909B (en) Method, apparatus and system for personal network access by non-card equipment
CN102420852A (en) Server, mobile terminal and data synchronizing method
CN106686196A (en) Personal mobile phone safety management method
CN106412217B (en) A kind of connecting information management method, device and terminal
CN101771684A (en) Internet compuphone authentication method and service system thereof

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication

Application publication date: 20130508

RJ01 Rejection of invention patent application after publication