IP Library Granted Patent US 12689899
Granted Patent B2
US 12689899 · App. 18/547,295 · Granted Jul 21, 2026

Secure data collection via a messaging framework

Inventors: Andreas Kunz (Ladenburg, DE); Dimitrios Karampatsis (Ruislip, GB); Sheeba Backia Mary Baskaran (Friedrichsdorf, DE)
Assignee: Lenovo (Singapore) Pte. Ltd.
H04W12/106
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12689899
App. No.
18/547,295
Granted
Jul 21, 2026
Kind
B2
Abstract

Various aspects of the present disclosure relate to secure data collection via a messaging framework. An apparatus includes at least one memory and at least one processor that is configured to receive a subscription request from a data consumer function, the subscription request comprising a data tag associated with a data producer function, generate a security key for the data tag, generate a binding for the data tag between the security key, the data consumer function, and the data producer function, and transmit, for use in data transmissions between the data producer function and the data consumer function a service request message to the data producer function, the service request message comprising the data tag and the security key, and a data exposure response message to the data consumer function, the data exposure response message comprising the data tag and the security key.

Claims (38)

1 . A network equipment for wireless communication, comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the network equipment to:

receive a subscription request from a data consumer function, the subscription request comprising a data tag associated with a data producer function;

generate a security key for the data tag;

generate a binding for that associates the data tag, the security key, the data producer function, and the data consumer function, wherein the binding defines an end-to-end data protection relationship between the data producer function and the data consumer function;

transmit a service request message comprising the data tag and the security key to the data producer function; and

transmit a data exposure response comprising the data tag and the security key to the data consumer function.

2 . The network equipment of claim 1 , wherein the at least one processor is configured to cause the network equipment to:

receive a subscription request from one or more second data consumer functions, the subscription request comprising the data tag associated with the data producer function; and

initiate a key refresh procedure for the data tag in response to determining that a binding exists for the data tag between the security key, the data consumer function, and the data producer function.

3 . The network equipment of claim 2 , wherein the at least one processor is configured to cause the network equipment to, for the key refresh procedure:

generate a new security key for the data tag;

identify based on the data tag, the data consumer function, the one or more second data consumer functions, and the data producer function;

delete the binding for the data tag between the security key, the data consumer function, and the data producer function;

generate a new binding for the data tag between the new security key, the data consumer function, the one or more second data consumer functions, and the data producer function; and

transmit a key refresh request to the data consumer function, the one or more second data consumer functions, and the data producer function, the key refresh request comprising the new security key.

4 . The network equipment of claim 2 , wherein the at least one processor is configured to cause the network equipment to, for the key refresh procedure, generate asymmetric keys for the data consumer function, the one or more second data consumer functions, and the data producer function, the asymmetric keys comprising a public key provisioned for the data producer function and corresponding private keys provisioned for the data consumer function and the one or more second data consumer functions.

5 . The network equipment of claim 1 , wherein the data tag comprises one or more of data requested from the data producer function, identifying information for a device associated with the data consumer function, identifying information for the data producer function, and filtering information.

6 . The network equipment of claim 1 , wherein the at least one processor is configured to cause the network equipment to select a security algorithm for generating the security key and transmit the security algorithm, along with the security key, to the data consumer function and the data producer function.

7 . The network equipment of claim 1 , wherein the at least one processor is configured to cause the network equipment to register the data consumer function with a messaging framework for notifications related to the data tag.

8 . A method performed by a network equipment, comprising:

receiving a subscription request from a data consumer function, the subscription request comprising a data tag associated with a data producer function;

generating a security key for the data tag;

generating a binding that associates the data tag, the security key, the data producer function, and the data consumer function, wherein the binding defines an end-to-end data protection relationship between the data producer function and the data consumer function;

transmitting a service request message comprising the data tag and the security key to the data producer function; and

transmitting a data exposure response comprising the data tag and the security key to the data consumer function.

9 . The method of claim 8 , further comprising:

receiving a subscription request from one or more second data consumer functions, the subscription request comprising the data tag associated with the data producer function; and

initiating a key refresh procedure for the data tag in response to determining that a binding exists for the data tag between the security key, the data consumer function, and the data producer function.

10 . The method of claim 9 , further comprising, for the key refresh procedure:

generating a new security key for the data tag;

identifying based on the data tag, the data consumer function, the one or more second data consumer functions, and the data producer function;

deleting the binding for the data tag between the security key, the data consumer function, and the data producer function;

generating a new binding for the data tag between the new security key, the data consumer function, the one or more second data consumer functions, and the data producer function; and

transmitting a key refresh request to the data consumer function, the one or more second data consumer functions, and the data producer function, the key refresh request comprising the new security key.

11 . The method of claim 10 , further comprising, for the key refresh procedure, generating asymmetric keys for the data consumer function, the one or more second data consumer functions, and the data producer function, the asymmetric keys comprising a public key provisioned for the data producer function and corresponding private keys provisioned for the data consumer function and the one or more second data consumer functions.

12 . The method of claim 8 , wherein the data tag comprises one or more of data requested from the data producer function, identifying information for a device associated with the data consumer function, identifying information for the data producer function, and filtering information associated with the data.