IP Library › Granted Patent US 12,028,342
Granted Patent B2
US 12,028,342 · App. 18/119,656 · Granted Jul 2, 2024

User authentication using connection information provided by a blockchain network

Inventor: Apostolis Salkintzis (Athens, GR)
Assignee: Lenovo (Singapore) Pte. Ltd.
H04L63/0892G06Q20/38215H04L65/1069
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,028,342
App. No.
18/119,656
Granted
Jul 2, 2024
Kind
B2
Abstract

Apparatuses, methods, and systems are disclosed for user authentication using a connection information package provided by a blockchain network. One apparatus includes a processor and a memory coupled to the processor, the memory comprising instructions executable by the processor to cause the apparatus to receive, from a smart contract, a set of connection information packages and to receive, from a first function, a request to authenticate a roaming user. The instructions are further executable by the processor to cause the apparatus to determine whether the first function is associated with a valid connection information package and to accept the request to authenticate the roaming user in response to the first function being associated with the valid connection information package.

Claims (30)

1. An apparatus comprising:

a processor; and

a memory coupled to the processor, the memory comprising instructions executable by the processor to cause the apparatus to:

receive, from a smart contract on a blockchain network corresponding to a home realm of a roaming user, a set of connection information packages, each connection information package comprising a respective validity parameter and respective information enabling a connection with an authentication server in the home realm;

receive, from a first function, a request to authenticate the roaming user;

determine whether the first function is associated with a valid connection information package; and

accept the request to authenticate the roaming user in response to the first function being associated with the valid connection information package.

2. The apparatus of claim 1 , wherein each respective connection information package further comprises a first network address of a corresponding function permitted to use the respective connection information package, the first network address being one of an IP address and a hostname of the corresponding function.

3. The apparatus of claim 2 , wherein the request to authenticate the roaming user is received from a second network address associated with the first function, wherein to determine whether the first function is associated with the valid connection information package, the instructions are further executable by the processor to cause the apparatus to determine whether the second network address matches the first network address in the valid connection information package.

4. The apparatus of claim 1 , wherein the blockchain network contains a shared single ledger for all nodes of the blockchain network, wherein the smart contract corresponds to a first address on the blockchain network, the smart contract comprising executable code stored in the shared single ledger of the blockchain network.

5. The apparatus of claim 1 , wherein a respective connection information package is created in response to a message sent to the smart contract comprising a payment and a first network address of a sender of the message.

6. The apparatus of claim 1 , wherein the instructions are further executable by the processor to cause the apparatus to reject the request to authenticate the roaming user in response to determining that no connection information package is associated with the first function.

7. The apparatus of claim 1 , wherein the respective validity parameter comprises an expiration time and date of a corresponding connection information package, wherein the corresponding connection information package becomes invalid after the expiration time and date.

8. The apparatus of claim 1 , wherein the respective validity parameter comprises an indicator of a permitted number of authentication requests using a corresponding connection information package, wherein the corresponding connection information package becomes invalid after being used the permitted number, and wherein to accept the request to authenticate the roaming user, the instructions are further executable by the processor to cause the apparatus to update the permitted number of authentication requests.

9. The apparatus of claim 1 , wherein the request to authenticate the roaming user comprises a package identifier and a message authentication code, wherein the package identifier indicates a particular one of the set of connection information packages, and wherein the message authentication code is computed based on a private key of the first function.

10. The apparatus of claim 9 , wherein each respective connection information package includes a public key of a corresponding first function permitted to use the respective connection information package, wherein to determine whether the first function is associated with a valid connection information package, the instructions are further executable by the processor to cause the apparatus to verify the message authentication code using the public key of a corresponding connection information package identified by the package identifier.

11. A method comprising:

receiving, from a smart contract on a blockchain network corresponding to a home realm of a roaming user, a set of connection information packages, each connection information package comprising a respective validity parameter and respective information enabling a connection with an authentication server in the home realm;

receiving, from a first function, a request to authenticate the roaming user;

determining whether the first function is associated with a valid connection information package; and

accepting, at an authentication function in the home realm, the request to authenticate the roaming user in response to the first function being associated with the valid connection information package.

12. The method of claim 11 , wherein each respective connection information package further comprises a first network address of a corresponding function permitted to use the respective connection information package, the first network address being one of an IP address and a hostname of the corresponding function.

13. The method of claim 12 , wherein the request to authenticate the roaming user is received from a second network address associated with the first function, wherein determining whether the first function is associated with the valid connection information package comprises determining whether the second network address matches the first network address in the valid connection information package.

14. The method of claim 11 , wherein the blockchain network contains a shared single ledger for all nodes of the blockchain network, wherein the smart contract corresponds to a first address on the blockchain network, the smart contract comprising executable code stored in the shared single ledger of the blockchain network.

15. The method of claim 11 , wherein a respective connection information package is created in response to a message sent to the smart contract comprising a payment and a first network address of a sender of the message.

16. The method of claim 11 , further comprising rejecting the request to authenticate the roaming user in response to determining that no connection information package is associated with the first function.

17. The method of claim 11 , wherein the respective validity parameter comprises an expiration time and date of a corresponding connection information package, wherein the corresponding connection information package becomes invalid after the expiration time and date.

18. The method of claim 11 , wherein the respective validity parameter comprises an indicator of a permitted number of authentication requests using a corresponding connection information package, wherein the corresponding connection information package becomes invalid after being used the permitted number, wherein accepting the request to authenticate the roaming user includes updating the permitted number of authentication requests.

19. The method of claim 11 , wherein the request to authenticate the roaming user comprises a package identifier and a message authentication code, wherein the package identifier indicates a particular one of the set of connection information packages, and wherein the message authentication code is computed based on a private key of first function.

20. The method of claim 19 , wherein each respective connection information package includes a public key of a corresponding first function permitted to use the respective connection information package, wherein determining whether the first function is associated with a valid connection information package comprises verifying the message authentication code using the public key of a corresponding connection information package identified by the package identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2023
From: SALKINTZIS, APOSTOLIS
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 062938/0039 →
Continuity (2)
Continuation 16645324
Related Publication 20230216852A1 · Jul 6, 2023