IP Library Granted Patent US 12,495,037
Granted Patent B2
US 12,495,037 · App. 18/547,132 · Granted Dec 9, 2025

Authentication for a network service

Inventors: Dimitrios Karampatsis (Ruislip, GB); Andreas Kunz (Ladenburg, DE); Sheeba Backia Mary Baskaran (Friedrichsdorf, DE)
Assignee: Lenovo (Singapore) Pte. Ltd.
H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,495,037
App. No.
18/547,132
Granted
Dec 9, 2025
Kind
B2
Abstract

Apparatuses, methods, and systems are disclosed for authentication for a network service. One method includes receiving, at a first network device from a second network device, a network function service request to execute a service on a third network device. The request includes first credentials for authentication with a first network device and second credentials for authentication with the third network device. The method includes determining whether the first credentials provided are valid and execute the service request by determining the third network device to execute the service requested from the second network device. The method includes transmitting, to a fourth network device, a request for authentication with the third network device. The request includes an identifier of the third network device and second credentials of the second network device.

Claims (39)

1 . An apparatus for performing a network function (NF), the apparatus comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the apparatus to:

receive, from a second network device, a NF service request to execute a service on a third network device, wherein the request comprises first credentials for authentication with a first network device and second credentials for authentication with the third network device, wherein the first credentials comprise a first access token of the second network device assigned from the third network device and wherein the second credentials comprise a second access token generated from the second network device;

determine whether the first credentials provided are valid and execute the service request by determining the third network device to execute the service requested from the second network device;

transmit, to a fourth network device, a request for authentication with the third network device, wherein the request comprises an identifier of the third network device and second credentials of the second network device;

receive, from the fourth network device, third credentials for initiating the NF service with the third network device, wherein the third credentials comprise a third access token generated from the fourth network device; and

transmit, to the third network device, a request for initiation of the NF service, wherein the request comprises authentication credentials comprising the second credentials and the third credentials.

2 . The apparatus of claim 1 , wherein the apparatus comprises a data collection coordination function (DCCF).

3 . The apparatus of claim 1 , wherein the second network device comprises a NF service consumer.

4 . The apparatus of claim 1 , wherein the fourth network device comprises a network repository function (NRF).

5 . An apparatus for performing a network function (NF), the apparatus comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the apparatus to:

transmit, to a fourth network device, a request for authorization to access services of a first network device;

receive, from the fourth network device, first credentials comprising of an access token;

transmit, to the first network device, a NF service request to execute a service from a third network device, the NF service request comprising the first credentials for authentication with the first network device and second credentials for authentication with the third network device, wherein the first credentials comprise a first access token and second credentials comprise a second access token generated by a second network device, and wherein a third access token is generated based on the second access token; and

receive, from the first network device, a response to the NF service request.

6 . The apparatus of claim 5 , wherein the first network device comprises a data collection coordination function (DCCF).

7 . The apparatus of claim 5 , wherein the apparatus comprises a NF service consumer.

8 . The apparatus of claim 5 , wherein the fourth network device comprises a network repository function (NRF).

9 . An apparatus for performing a network function (NF), the apparatus comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the apparatus to:

receive, from a first network device, a request for authentication with a third network device, wherein the request comprises first credentials comprising an access token of a second network device and identifiers of the third network device;

determine whether the first network device and the second network device are allowed to access a service of the third network device; and in response to determining that the first network device and the second network device are allowed to access the service, generate second credentials comprising a second access token; and

transmit, to the first network device, the second credentials for initiating a NF service, wherein a third access token is generated based on the second access token.

10 . The apparatus of claim 9 , wherein the first network device comprises a data collection coordination function (DCCF).

11 . The apparatus of claim 9 , wherein the second network device comprises a NF service consumer.

12 . The apparatus of claim 9 , wherein the apparatus comprises a network repository function (NRF).

13 . A method of performing a network function (NF), the method comprising:

receiving, from a second network device, a NF service request to execute a service on a third network device, wherein the request comprises first credentials for authentication with a first network device and second credentials for authentication with the third network device, wherein the first credentials comprise a first access token of the second network device assigned from the third network device and wherein the second credentials comprise a second access token generated from the second network device;

determining whether the first credentials provided are valid and execute the service request by determining the third network device to execute the service requested from the second network device;

transmitting, to a fourth network device, a request for authentication with the third network device, wherein the request comprises an identifier of the third network device and second credentials of the second network device;

receiving, from the fourth network device, third credentials for initiating a NF service with the third network device, wherein the third credentials comprise a third access token generated from the fourth network device; and

transmitting, to the third network device, a request for initiation of the NF service, wherein the request comprises authentication credentials comprising the second credentials and the third credentials.

14 . The method of claim 13 , wherein the NF is performed by a data collection coordination function (DCCF).

15 . The method of claim 13 , wherein the second network device comprises a NF service consumer.

16 . The method of claim 13 , wherein the fourth network device comprises a network repository function (NRF).

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2025
From: LENOVO (SINGAPORE) PTE. LTD.
To: EDGEWOOD IP, LLC
Reel/Frame 074118/0091 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2023
From: KARAMPATSIS, DIMITRIOS; KUNZ, ANDREAS; BASKARAN, SHEEBA BACKIA MARY
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 064779/0228 →
Continuity (2)
Provisional Application 63151490 · Feb 19, 2021
Related Publication 20240154953A1 · May 9, 2024
References Cited (22)
US 20140090027A1 · Tamura · 2014 [cited by examiner]
US 20180278603A1 · Yabe · 2018 [cited by examiner]
US 20180337784A1 · Jain · 2018 [cited by examiner]
US 20190028485A1 · Baird · 2019 [cited by examiner]
US 20200023812A1 · Hassani · 2020 [cited by examiner]
US 20200305055A1 · Basu Mallick · 2020 [cited by examiner]
US 20210127265A1 · Chandramouli · 2021 [cited by examiner]
US 20210250344A1 · Qi · 2021 [cited by examiner]
US 20220116400A1 · Khare · 2022 [cited by examiner]
US 20230276509A1 · Karampatsis · 2023 [cited by examiner]
US 20240129729A1 · Baskaran · 2024 [cited by examiner]
US 20240154953A1 · Karampatsis · 2024 [cited by examiner]
US 20240163672A1 · Comak · 2024 [cited by examiner]
US 20240187856A1 · Atarius · 2024 [cited by examiner]
JP 2003249944A · 2003 [cited by applicant]
PCT/IB2022/051481, “International Search Report and the Written Opinion of the International Searching Authority, or the Declaration”, International Searching Authority, May 30, 2022, pp. 1-13. [cited by applicant]
Nokia et al., “KI#11, Updates to Solution #9”, SA WG2 Meeting #141E S2-2008057, Oct. 12-23, 2020, pp. 1-12. [cited by applicant]
Nokia et al., “KI on Authorization of consumers for data access via Dccf”, 3GPP TSG-SA3 Meeting #102-e S3-210116, Jan. 18-29, 2021, pp. 1-2. [cited by applicant]
Nokia et al., “Authorization of NF Service Consumers for data access via DCCF”, 3GPP TSG-SA3 Meeting #103-e S3-212161, May 17-28, pp. 1-5. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of enablers for Network Automation (eNA) for the 5G system (5GS) Phase 2; (Release 17)”, 3G… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 16)”, 3GPP TS 23.502 V16.7.1, Jan. 2021, pp. 1-603. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16)”, 3GPP TS 33.501 V16.4.0, Sep. 2020, pp. 1-250. [cited by applicant]