IP Library Granted Patent US 12,739,633
Granted Patent B2
US 12,739,633 · App. 18/674,808 · Granted Sep 15, 2026

Attribute-based credentials for resource access

Inventors: Andreas Kunz (Ladenburg, DE); Sheeba Backia Mary Baskaran (Friedrichsdorf, DE)
Assignee: Lenovo (Singapore) Pte Ltd
H04W12/068H04L9/0825H04L63/18H04W60/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,633
App. No.
18/674,808
Granted
Sep 15, 2026
Kind
B2
Abstract

Various aspects of the present disclosure relate to attribute-based credentials for resource access. An apparatus, such as a UE, communicates a registration request message for registration of the apparatus to a wireless communication network, the registration request message including a credentials indication associated with a credential. The apparatus receives a response message including a presentation policy for registration to the wireless communication network, and communicates a presentation token generated based at least in part on the presentation policy, the presentation token including proof information for a private key. The apparatus receives an authentication challenge, and generates, based at least in part on the authentication challenge, an authentication result using a root key and a subscription identity from the credential.

Claims (48)

1 . A user equipment (UE) for wireless communication, comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the UE to:

communicate a registration request message for registration of the UE to a wireless communication network, the registration request message comprising a credentials indication associated with a credential;

receive a response message comprising a presentation policy for registration to the wireless communication network, the presentation policy comprising an indication to provide an encrypted subscription identifier, an encrypted root key, and a public key;

communicate a presentation token generated based at least in part on the presentation policy, the presentation token comprising proof information for a private key;

receive an authentication challenge;

generate, based at least in part on the authentication challenge, an authentication result using a root key and a subscription identity from the credential; and

perform a registration procedure with the wireless communication network based at least in part on the authentication result.

2 . The UE of claim 1 , wherein the registration request message comprises a non-access stratum (NAS) registration request message and the response message comprise a NAS response message.

3 . The UE of claim 1 , wherein the credentials indication comprises an anonymous subscription concealed identifier (SUCI) comprising a network access identifier (NAI) for the wireless communication network.

4 . The UE of claim 1 , wherein the private key is associated with a public key included in the presentation token.

5 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to communicate the presentation token via a non-access stratum (NAS) request.

6 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to receive a non-access stratum (NAS) response comprising the authentication challenge and a presentation token success indication.

7 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to derive the root key and the subscription identity.

8 . The UE of claim 1 , wherein the root key and the subscription identity are included in the credential in an encrypted form, and wherein the at least one processor is configured to cause the UE to decrypt the root key and the subscription identity using the private key.

9 . A processor for wireless communication, comprising:

at least one controller coupled with at least one memory and configured to cause the processor to:

communicate a registration request message for registration of a user equipment (UE) to a wireless communication network, the registration request message comprising a credentials indication associated with a credential;

receive a response message comprising a presentation policy for registration to the wireless communication network, the presentation policy comprising an indication to provide an encrypted subscription identifier, an encrypted root key, and a public key;

communicate a presentation token generated based at least in part on the presentation policy, the presentation token comprising proof information for a private key;

receive an authentication challenge;

generate, based at least in part on the authentication challenge, an authentication result using a root key and a subscription identity from the credential; and

perform a registration procedure for the UE with the wireless communication network based at least in part on the authentication result.

10 . The processor of claim 9 , wherein the registration request message comprises a non-access stratum (NAS) registration request message and the response message comprise a NAS response message.

11 . The processor of claim 9 , wherein the credentials indication comprises an anonymous subscription concealed identifier (SUCI) comprising a network access identifier (NAI) for the wireless communication network.

12 . The processor of claim 9 , wherein the private key is associated with a public key included in the presentation token.

13 . The processor of claim 9 , wherein the at least one controller is configured to cause the processor to communicate the presentation token via a non-access stratum (NAS) request, and receive a non-access stratum (NAS) response comprising the authentication challenge and a presentation token success indication.

14 . The processor of claim 9 , wherein the at least one controller is configured to cause the processor to derive the root key and the subscription identity.

15 . The processor of claim 9 , wherein the root key and the subscription identity are included in the credential in an encrypted form, and wherein the at least one controller is configured to cause the processor to decrypt the root key and the subscription identity using the private key.

16 . A network equipment for wireless communication, comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the network equipment to:

receive a registration request message for registration of a user equipment (UE) to a wireless communication network, the registration request message comprising a credentials indication associated with a credential;

communicate a response message, to the UE, comprising a presentation policy for registration to the wireless communication network, the presentation policy comprising an indication to provide an encrypted subscription identifier, an encrypted root key, and a public key;

receive a presentation token generated based at least in part on the presentation policy, the presentation token comprising proof information for a private key;

receive, based at least in part on the presentation token, an authentication challenge; and

communicate, to the UE, the authentication challenge associated with registration of the UE to the wireless communication network.

17 . A method performed by a user equipment (UE), the method comprising:

communicating a registration request message for registration of the UE to a wireless communication network, the registration request message comprising a credentials indication associated with a credential;

receiving a response message comprising a presentation policy for registration to the wireless communication network, the presentation policy comprising an indication to provide an encrypted subscription identifier, an encrypted root key, and a public key;

communicating a presentation token generated based at least in part on the presentation policy, the presentation token comprising proof information for a private key;

receiving an authentication challenge;

generating, based at least in part on the authentication challenge, an authentication result using a root key and a subscription identity from the credential; and

performing a registration procedure with the wireless communication network based at least in part on the authentication result.

18 . The method of claim 17 , wherein the registration request message comprises a non-access stratum (NAS) registration request message and the response message comprise a NAS response message.

19 . The method of claim 17 , wherein the credentials indication comprises an anonymous subscription concealed identifier (SUCI) comprising a network access identifier (NAI) for the wireless communication network.

20 . The method of claim 17 , wherein the root key and the subscription identity are included in the credential in an encrypted form, the method further comprising decrypting the root key and the subscription identity using the private key.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2024
From: LENOVO (UNITED STATES) INC.
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 069278/0867 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2024
From: KUNZ, ANDREAS; BASKARAN, SHEEBA BACKIA MARY
To: LENOVO (UNITED STATES) INC.
Reel/Frame 067666/0494 →
Continuity (1)
Related Publication 20250365576A1 · Nov 27, 2025
References Cited (53)
US 9240886B1 · Allen · 2016 [cited by examiner]
US 11076288B2 · Torvinen et al. · 2021 [cited by applicant]
US 12155781B1 · Helfgott et al. · 2024 [cited by applicant]
US 12647267B2 · Kunz et al. · 2026 [cited by applicant]
US 20060206932A1 · Chong · 2006 [cited by applicant]
US 20060235796A1 · Johnson et al. · 2006 [cited by applicant]
US 20170033934A1 · Camenisch · 2017 [cited by examiner]
US 20170034142A1 · Camenisch · 2017 [cited by examiner]
US 20190020480A1 · Camenisch · 2019 [cited by examiner]
US 20190295069A1 · Pala et al. · 2019 [cited by applicant]
US 20200014535A1 · Baskaran et al. · 2020 [cited by applicant]
US 20210320788A1 · Kang et al. · 2021 [cited by applicant]
US 20210385216A1 · Khalil · 2021 [cited by examiner]
US 20220122170A1 · Du · 2022 [cited by applicant]
US 20220191044A1 · Kurita · 2022 [cited by applicant]
US 20220225093A1 · Sasi et al. · 2022 [cited by applicant]
US 20230031804A1 · Shimizu et al. · 2023 [cited by applicant]
US 20230164143A1 · Richardson, IV et al. · 2023 [cited by applicant]
US 20230224704A1 · Atarius · 2023 [cited by examiner]
US 20230269095A1 · Yamaoka et al. · 2023 [cited by applicant]
US 20230412379A1 · Yanai · 2023 [cited by examiner]
US 20230413060A1 · Baskaran · 2023 [cited by examiner]
US 20240022433A1 · Asor et al. · 2024 [cited by applicant]
US 20240106834A1 · Yamaoka · 2024 [cited by applicant]
US 20240297798A1 · Shimizuike et al. · 2024 [cited by applicant]
US 20250131134A1 · Giffard-burley et al. · 2025 [cited by applicant]
US 20250159476A1 · Torvinen et al. · 2025 [cited by applicant]
US 20250217795A1 · Modadugu et al. · 2025 [cited by applicant]
US 20250365150A1 · Kunz et al. · 2025 [cited by applicant]
CN 112600850B · 2022 [cited by applicant]
CN 116318981A · 2023 [cited by applicant]
WO 2022096125A1 · 2022 [cited by applicant]
WO 2022096126A1 · 2022 [cited by applicant]
WO 2023212051A1 · 2023 [cited by applicant]
WO 2024162661A1 · 2024 [cited by applicant]
WO 2024236072A1 · 2024 [cited by applicant]
WO 2025099846A1 · 2025 [cited by applicant]
WO 2025099848A1 · 2025 [cited by applicant]
Bernabe et al. “Holistic Privacy-Preserving Identity Management System for the Internet of Things” [Online],Aug. 8, 2017[Retrieved on: Dec. 13, 2025], Hindawi MIS, Retrieved from: (Year: 2017), < https://www.researchgat… [cited by examiner]
3GPP , “Security architecture and procedures for 5G system (Release 16)”, 3GPP TS 33.501 V16.18.0, retrieved from the internet on May 20, 2024, <https://www.3gpp.org/ftp/Specs/archive/33_series/33.501/>, Mar. 2024, 257 … [cited by applicant]
ABC4TRUST , “Attribute-based Credentials for Trust”, retrieved from the internet on May 20, 2024, <https://abc4trust.eu/download/flyer/ABC4Trust-OnePager-About-ABC4Trust.pdf>, Sep. 2011, 2 pages. [cited by applicant]
Bischsel , et al., “D2.2—Architecture for Attribute-based Credential Technologies—Final Version”, retrieved from the internet on May 21, 2024, <https://abc4trust.eu/download/Deliverable_D2.2.pdf>, 2014, 149 pages. [cited by applicant]
Korenhof , et al., “The ABC of ABC: An analysis of attribute-based credentials in the light of data protection, privacy and identity”, In J. B. Padullés, A. C. i Martínez, M. P. Poch, I. P. López, M. J. P. de Moner, & M… [cited by applicant]
“Non-Final Office Action”, U.S. Appl. No. 18/674,804, filed Sep. 22, 2025, 14 pages. [cited by applicant]
“Security Architecture and Procedures for 5G System (Release 15)”, 3GPP TS 33.501 version 15.18.0, Apr. 2024, 196 pages. [cited by applicant]
Hampiholi, et al., “Trusted self-enrolment for attribute-based credentials on mobile phones”, Institute for Computing and Information Sciences, Proceedings of the IFIP Summer School, 2015, 13 pages. [cited by applicant]
Kakvi, et al., “SoK: Anonymous Credentials”, International Conference on Research in Security Standardisation, Springer Nature Switzerland, Apr. 7, 2023, 23 pages. [cited by applicant]
Sporny, et al., “Verifiable Credentials Data Model v2.0”, W3C Working Draft, [Retrieved Sep. 5, 2025]. Retrieved from the Internet: <https://www.w3.org/TR/2023/WD-vc-data-model-2.0-20230803/#dfn-verifiable-credential>, … [cited by applicant]
Yu, et al., “AAKA: An Anti-Tracking Cellular Authentication Scheme Leveraging Anonymous Credentials”, Network and Distributed System Security (NDSS) Symposium, Feb. 26, 2024, 18 pages. [cited by applicant]
Zeydan, et al., “Decentralizing Authentication for Mobile Networks: Opportunities and Challenges in Web 3.0 Era”, IEEE Wireless Communications, vol. 32, No. 1, Feb. 2025, 7 pages. [cited by applicant]
Corrected Notice of Allowability issued in U.S. Appl. No. 18/674,804, mailed Mar. 13, 2026, 2 pages. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 18/674,804, mailed Feb. 4, 2026, 9 pages. [cited by applicant]
Corrected Notice of Allowability issed in U.S. Appl. No. 18/674,804, mailed May 8, 2026, 2 pages. [cited by applicant]